Values for content-security-policy-report-only: script-src https: blob: 'unsafe-inline' 'unsafe-eval' 'self';base-uri 'self';report-uri https://reporting-api.gannettinnovation.com;report-to default 253 script-src 'self' 'unsafe-inline' 'unsafe-eval' https://www.gstatic.com https://www.awin1.com https://lantern.roeyecdn.com https://tagmanager.google.com https://cdn.trustcommander.net https://www.dwin1.com https://www.googletagmanager.com https://maps.googleapis.com https://www.google-analytics.com https://www.googleadservices.com https://bat.bing.com https://*.doubleclick.net https://www.axa-video.de *.visualwebsiteoptimizer.com app.vwo.com https://www.google.com https://platform.commandersact.com https://connect.facebook.net https://*.aklamio.com data.axa.de snap.licdn.com blob: https://ct.pinterest.com https://s.pinimg.com https://acdn.adnxs.com https://ib.adnxs.com ; ;style-src 'self' 'unsafe-inline' https://fonts.googleapis.com *.visualwebsiteoptimizer.com app.vwo.com s3.amazonaws.com https://googletagmanager.com https://www.googletagmanager.com ;frame-src https://www.awin1.com app.vwo.com *.visualwebsiteoptimizer.com https://entry.axa-de.intraxa/ https://entry.axa.de https://www.axa-video.de https://www.axa.de https://inte.axa.de https://*.doubleclick.net https://cdn.trustcommander.net https://www.dwin1.com https://connect.facebook.net https://www.facebook.com https://td.doubleclick.net https://googleads.g.doubleclick.net https://www.google.com https://ct.pinterest.com https://googletagmanager.com https://insight.adsrvr.org 'self' https://www.googletagmanager.com;base-uri 'self';object-src 'none';img-src 'self' data: https://ad.doubleclick.net https://*.ads.linkedin.com data.axa.de *.visualwebsiteoptimizer.com chart.googleapis.com wingify-assets.s3.amazonaws.com app.vwo.com https://track.adform.net https://ad.doubleclick.net https://www.facebook.com https://bat.bing.com https://www.google.com https://www.google.de https://www.google-analytics.com https://www.google https://www.googletagmanager.com https://*.google-analytics.com https://*.analytics.google.com https://googleads.g.doubleclick.net https://i.ytimg.com https://maps.gstatic.com https://maps.googleapis.com https://www.financeads.net https://www.aklamio.com/ https://ct.pinterest.com https://ib.adnxs.com;form-action 'self';default-src 'self' https://assets.faircado.com https://static.preply.com https://fonts.gstatic.com/ blob: data:;connect-src 'self' data.axa.de https://api.vid-adblocker.com https://ad.doubleclick.net/ https://*.google.de https://www.facebook.com/ https://*.ads.linkedin.com https://p.adsymptotic.com https://*.linkedin.oribi.io https://sjs.bizographics.com ad.doubleclick.net *.visualwebsiteoptimizer.com app.vwo.com https://*.googlesyndication.com https://*.google.com https://*.google-analytics.com https://*.analytics.google.com https://www.google.com https://www.googleanalytics.com https://stats.g.doubleclick.net https://googleads.g.doubleclick.net https://bat.bing.com https://privacy.trustcommander.net https://privacy.commander1.net https://privacy.commander1.com https://www.googletagmanager.com https://maps.googleapis.com https://fonts.googleapis.com https://*.axa.de https://cloud.service.aerzteversicherung.de https://mcdyr4395tgnrcnr8bt5wsrgh-11.pub.sfmc-content.com https://*.aklamio.com https://www.googleadservices.com https://ct.pinterest.com https://ib.adnxs.com https://acdn.adnxs.com https://google.com;;report-uri /site/axa-de/cspReportOnly 228 script-src 'self' 'unsafe-inline' https://www.googletagmanager.com https://connect.facebook.net; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; img-src 'self' data: *.mpsimg.com *.bdimg.xyz; font-src 'self' data: *.svcasino.art; 111 106 frame-ancestors 'self'; report-uri /csp_logger?path=/ 105 default-src https:; script-src https: 'unsafe-eval' 'unsafe-inline'; style-src https: 'unsafe-inline'; img-src https: data:; font-src https: data:; report-uri /csp-report 91 frame-ancestors 'self' 60 default-src 'self' 'unsafe-eval' 'unsafe-inline' https: blob:; frame-ancestors 'self'; style-src https: 'unsafe-inline'; connect-src https:; frame-src https:; script-src 'unsafe-eval' 'unsafe-inline' 'self' https: blob: data:; font-src https: data:; img-src https: data:; media-src https: blob:; object-src 'none'; report-uri https://o144486.ingest.sentry.io/api/5543380/security/?sentry_key=e66dfe54be8e47219dd8103b4deb2f1a&sentry_environment=policy_reports 58 script-src 'unsafe-inline' 'unsafe-eval' blob: data: https://ajax.googleapis.com/ajax/libs/jquery/3.6.4/jquery.min.js https://translate.google.com/translate_a/element.js https://www.google.com/recaptcha/api.js https://www.google.com/recaptcha/enterprise.js https://www.gstatic.com/recaptcha/ https://www.google.com/tools/feedback/chat_load.js https://www.google.com/tools/feedback/help_api.js https://www.google.com/tools/feedback/load.js https://www.google.com/tools/feedback/open.js https://www.google.com/tools/feedback/open_to_help_guide_lazy.js https://www.gstatic.com/feedback/js/ https://www.gstatic.com/feedback/js/help/prod/service/lazy.min.js https://www.gstatic.com/inproduct_help/api/main.min.js https://www.gstatic.com/inproduct_help/chatsupport/chatsupport_button_v2.js https://www.gstatic.com/inproduct_help/service/lazy.min.js https://www.gstatic.com/uservoice/feedback/client/web/live/ https://www.gstatic.com/uservoice/surveys/resources/prod/js/survey/ https://www.gstatic.com/_/mss/boq-one-google/_/ https://www.gstatic.com/og/_/js/ https://apis.google.com/js/api.js https://apis.google.com/js/client.js https://www.googletagmanager.com/gtag/js https://www.google-analytics.com/analytics.js https://www.googletagmanager.com/gtag/destination https://www.gstatic.com/_/mss/boq-identity/_/js/k=boq-identity.AccountsSignInUi.en_US.nGoZh2P_ZQc.es5.O/ https://apis.google.com/_/scs/abc-static/_/js/ https://translate.googleapis.com/_/translate_http/_/js/ https://www.gstatic.com/recaptcha/releases/;report-uri /v3/signin/_/AccountsSignInUi/cspreport/fine-allowlist 38 default-src https: blob: data: 'unsafe-inline' 'unsafe-eval'; report-to blogspot; report-uri https://www.blogger.com/cspreport 38 report-uri /report-csp-violation 35 default-src 'self' 'unsafe-eval' 'unsafe-hashes' 'unsafe-inline' data: blob: ; form-action 'none' ; frame-ancestors 'self' ; script-src 'unsafe-eval' 'unsafe-hashes' 'report-sample'; report-uri /csp_report; report-to /csp_report 35 frame-src 'self' servedbyadbutler.com *.authorize.net *.paypal.com *.google.com www.book2look.com; img-src 'self' images.booksense.com data: https://www.googletagmanager.com https://www.paypalobjects.com https://withfriends.co; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com https://www.google-analytics.com https://danjg53usxhfc.cloudfront.net code.jquery.com cdn.mxpnl.com https://www.paypal.com *.gstatic.com cdnjs.cloudflare.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com https://www.book2look.com https://www.google.com; style-src * 'report-sample' 'unsafe-inline'; base-uri 'self'; report-uri https://o4507465725640704.ingest.us.sentry.io/api/4510783202066432/security/?sentry_key=ea4d6ac5ddc8cc5a46f75f8ac24a565d 35 block-all-mixed-content; report-uri https://blog.hatena.ne.jp/api/csp_report 30 default-src https: wss: 'unsafe-inline' 'unsafe-eval'; font-src https: data: ; img-src https: data: blob: ; media-src https: blob: ; worker-src https: blob: ; report-uri https://www.netflix.com/log/www/csp/1; 27 default-src https:; script-src https: 'unsafe-eval' 'unsafe-inline'; style-src https: 'unsafe-inline'; img-src https: data:; font-src https: data:; report-uri /csp-report 22 script-src 'unsafe-inline' 'unsafe-eval' blob: data: https://www.google.com/recaptcha/enterprise.js https://www.gstatic.com/_/mss/boq-one-google/_/ https://www.gstatic.com/og/_/js/ https://apis.google.com/js/api.js https://apis.google.com/js/client.js https://www.googletagmanager.com/gtag/js https://www.google-analytics.com/analytics.js https://www.googletagmanager.com/gtag/destination https://www.gstatic.com/_/mss/boq-recaptcha/_/js/k=boq-recaptcha.RecaptchaChallengePageUi.en_US.b1aGfwUMUm4.2018.O/ https://apis.google.com/_/scs/abc-static/_/js/ https://www.gstatic.com/recaptcha/releases/;report-uri /recaptcha/challengepage/_/RecaptchaChallengePageUi/cspreport/fine-allowlist 21 frame-ancestors 'self' https://skybox.eskypartners.com; report-uri https://esky.report-uri.com/r/t/csp/enforce 19 default-src 'self' 17 object-src *.agriaffaires.pro *.machineryzone.pro *.agriaffaires.com *.machineryzone.fr *.machineryzone.com *.truckscorner.fr *.mbcore.io; frame-ancestors 'self' *.agriaffaires.pro *.machineryzone.pro *.agriaffaires.com *.machineryzone.fr *.machineryzone.com *.truckscorner.fr *.mbcore.io; report-uri https://api.leboncoin.fr/api/csp-report/v1/report/; 17 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com *.cloudflare.com https://*.usercentrics.eu *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com https://ss.kaffek.dk/ https://ss.kaffek.at/ https://ss.kaffek.be/ https://ss.kaffek.bg/ https://ss.kaffek.ch/ https://ss.kaffek.co.uk/ https://ss.kaffek.cz/ https://ss.kaffek.de/ https://ss.kaffek.es/ https://ss.kaffek.fi/ https://ss.kaffek.fr/ https://ss.kaffek.gr/ https://ss.kaffek.hu/ https://ss.kaffek.ie/ https://ss.kaffek.it/ https://ss.kaffek.nl/ https://ss.kaffek.no/ https://ss.kaffek.pl/ https://ss.kaffek.pt/ https://ss.kaffek.ro/ https://ss.kaffek.se/ https://ss.kaffek.sk/ https://stats.g.doubleclick.net https://scripts.clarity.ms https://e.clarity.ms data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.adyen.com pay.google.com payments-eu.amazon.com *.amazon.de https://www.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src https://www.youtube.com/ *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com *.youtube.com bid.g.doubleclick.net https://www.google.com/ *.braintreegateway.com *.paypal.com google.com *.google.com *.adyen.com pay.google.com www.google.com https://www.facebook.com https://googleads.g.doubleclick.net https://bid.g.doubleclick.net https://td.doubleclick.net/ https://www.google.com.ua/ https://www.google.bg/ https://ct.pinterest.com/ https://www.googletagmanager.com/ https://*.usercentrics.eu https://ss.kaffek.dk/ https://ss.kaffek.at/ https://ss.kaffek.be/ https://ss.kaffek.bg/ https://ss.kaffek.ch/ https://ss.kaffek.co.uk/ https://ss.kaffek.cz/ https://ss.kaffek.de/ https://ss.kaffek.es/ https://ss.kaffek.fi/ https://ss.kaffek.fr/ https://ss.kaffek.gr/ https://ss.kaffek.hu/ https://ss.kaffek.ie/ https://ss.kaffek.it/ https://ss.kaffek.nl/ https://ss.kaffek.no/ https://ss.kaffek.pl/ https://ss.kaffek.pt/ https://ss.kaffek.ro/ https://ss.kaffek.se/ https://ss.kaffek.sk/ https://stats.g.doubleclick.net https://scripts.clarity.ms https://e.clarity.ms 'self' 'unsafe-inline'; img-src data: widgets.magentocommerce.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com *.google-analytics.com *.analytics.google.com www.googletagmanager.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.adyen.com pay.google.com *.payments-amazon.com *.media-amazon.com *.paypalobjects.com https://images.unsplash.com *.googleapis.com https://www.google.com https://bat.bing.com/ https://www.facebook.com https://cdn.kaffekapslen.be https://www.google.com.ua/ https://www.google.bg/ https://www.google.dk/ https://googleads.g.doubleclick.net https://bid.g.doubleclick.net https://kaffekapslen.dk/ https://kaffekapslen.media https://www.googletagmanager.com/ https://app.usercentrics.eu/ https://*.usercentrics.eu https://connect.facebook.net/ https://firebasestorage.googleapis.com https://ss.kaffek.dk/ https://ss.kaffek.at/ https://ss.kaffek.be/ https://ss.kaffek.bg/ https://ss.kaffek.ch/ https://ss.kaffek.co.uk/ https://ss.kaffek.cz/ https://ss.kaffek.de/ https://ss.kaffek.es/ https://ss.kaffek.fi/ https://ss.kaffek.fr/ https://ss.kaffek.gr/ https://ss.kaffek.hu/ https://ss.kaffek.ie/ https://ss.kaffek.it/ https://ss.kaffek.nl/ https://ss.kaffek.no/ https://ss.kaffek.pl/ https://ss.kaffek.pt/ https://ss.kaffek.ro/ https://ss.kaffek.se/ https://ss.kaffek.sk/ https://stats.g.doubleclick.net https://scripts.clarity.ms https://e.clarity.ms data: 'self' 'unsafe-inline'; script-src *.commerce-payment-services.com commerce-payments-sdk.adobe.io www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com https://maps.googleapis.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ cdn.jsdelivr.net https://kaffekapslen.media/ https://app.usercentrics.eu/ https://connect.facebook.net/ https://*.usercentrics.eu https://bat.bing.com/ https://www.clarity.ms/ *.avada.io *.shopify.com https://ss.kaffek.dk/ https://ss.kaffek.at/ https://ss.kaffek.be/ https://ss.kaffek.bg/ https://ss.kaffek.ch/ https://ss.kaffek.co.uk/ https://ss.kaffek.cz/ https://ss.kaffek.de/ https://ss.kaffek.es/ https://ss.kaffek.fi/ https://ss.kaffek.fr/ https://ss.kaffek.gr/ https://ss.kaffek.hu/ https://ss.kaffek.ie/ https://ss.kaffek.it/ https://ss.kaffek.nl/ https://ss.kaffek.no/ https://ss.kaffek.pl/ https://ss.kaffek.pt/ https://ss.kaffek.ro/ https://ss.kaffek.se/ https://ss.kaffek.sk/ https://stats.g.doubleclick.net https://scripts.clarity.ms https://e.clarity.ms 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com cdn.jsdelivr.net *.cloudflare.com https://*.usercentrics.eu *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com https://ss.kaffek.dk/ https://ss.kaffek.at/ https://ss.kaffek.be/ https://ss.kaffek.bg/ https://ss.kaffek.ch/ https://ss.kaffek.co.uk/ https://ss.kaffek.cz/ https://ss.kaffek.de/ https://ss.kaffek.es/ https://ss.kaffek.fi/ https://ss.kaffek.fr/ https://ss.kaffek.gr/ https://ss.kaffek.hu/ https://ss.kaffek.ie/ https://ss.kaffek.it/ https://ss.kaffek.nl/ https://ss.kaffek.no/ https://ss.kaffek.pl/ https://ss.kaffek.pt/ https://ss.kaffek.ro/ https://ss.kaffek.se/ https://ss.kaffek.sk/ https://stats.g.doubleclick.net https://scripts.clarity.ms https://e.clarity.ms 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com www.googleadservices.com *.google-analytics.com *.analytics.google.com www.googletagmanager.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.adyen.com https://www.google.com payments-eu.amazon.com https://maps.googleapis.com https://player.vimeo.com *.googleapis.com https://www.facebook.com eu.playground.klarnaevt.com https://www.kaffekapslen.dk/ https://az-apim-st-kaffekapslen.azure-api.net/ api.kaffekapslen.com https://googleads.g.doubleclick.net https://bat.bing.com/ https://kaffekapslen.matomo.cloud/ https://api.usercentrics.eu/ https://*.usercentrics.eu https://pagead2.googlesyndication.com/ https://graphql.usercentrics.eu/graphql https://monitor.kaffekapslen.com/ https://google.com/pay https://region1.google-analytics.com https://www.google.bg/ https://capig.kaffekapslen.dk/ https://kaffekapslen.media https://get.geojs.io *.avada.io https://ss.kaffek.dk/ https://ss.kaffek.at/ https://ss.kaffek.be/ https://ss.kaffek.bg/ https://ss.kaffek.ch/ https://ss.kaffek.co.uk/ https://ss.kaffek.cz/ https://ss.kaffek.de/ https://ss.kaffek.es/ https://ss.kaffek.fi/ https://ss.kaffek.fr/ https://ss.kaffek.gr/ https://ss.kaffek.hu/ https://ss.kaffek.ie/ https://ss.kaffek.it/ https://ss.kaffek.nl/ https://ss.kaffek.no/ https://ss.kaffek.pl/ https://ss.kaffek.pt/ https://ss.kaffek.ro/ https://ss.kaffek.se/ https://ss.kaffek.sk/ https://stats.g.doubleclick.net https://scripts.clarity.ms https://e.clarity.ms 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 17 default-src 'self'; script-src 'self' acdn.adnxs.com analytics.tiktok.com bat.bing.com bat.bing.net cdn.cookielaw.org cdn.resonate.com ct.pinterest.com i.geistm.com js.hcaptcha.com lantern.roeyecdn.com pixel.byspotify.com pixels.spotify.com script.crazyegg.com s.pinimg.com tr.snapchat.com tr6.snapchat.com sc-static.net static.kyc.red unpkg.com/react-scan/ vuoriclothing.com www.googleadservices.com www.awin1.com www.dwin1.com www.youtube.com *.abtasty.com *.afterpay.com *.agentio.com *.amazon-adsystem.com *.attentivemobile.com *.attn.tv *.bglobale.com *.contentsquare.net *.cloudfront.net *.doubleclick.net *.facebook.com *.facebook.net *.forter.com *.global-e.com *.google.com *.google-analytics.com *.googleapis.com *.googletagmanager.com *.gstatic.com *.hotjar.com *.liadm.com *.lytics.io *.kargo.com *.klaviyo.com *.klarna.com *.kustomerapp.com *.medallia.com *.newrelic.com *.online-metrix.net *.powr.io *.rise-ai.com *.shopify.com *.signifyd.com *.yotpo.com 'unsafe-eval' 'unsafe-inline' blob:; style-src 'self' maxcdn.bootstrapcdn.com *.abtasty.com *.bglobale.com *.global-e.com *.googleapis.com *.klaviyo.com *.klarnacdn.net *.lytics.io *.medallia.com *.yotpo.com 'unsafe-inline'; img-src 'self' bat.bing.com bat.bing.net cdn.cookielaw.org cdn.kustomerhostedcontent.com cdnjs.cloudflare.com i.geistm.com ib.adnxs.com lantern.roeyecdn.com lantern.roeye.com s.pinimg.com s3.amazonaws.com tr.snapchat.com tr6.snapchat.com segment.prod.bidr.io verifi.podscribe.com vuoriclothing.com *.afterpay.com *.abtasty.com *.attentivemobile.com *.bfldr.com *.bglobale.com *.contentstack.io *.contentsquare.io *.contentsquare.net *.cloudfront.net *.doubleclick.net *.facebook.com *.facebook.net *.global-e.com *.googleapis.com *.googleadservices.com *.googletagmanager.com *.google.com *.google.com.au *.google.at *.google.be *.google.ca *.google.dk *.google.fi *.google.fr *.google.de *.google.com.hk *.google.ie *.google.it *.google.co.jp *.google.com.mx *.google.nl *.google.no *.google.pt *.google.com.sg *.google.es *.google.se *.google.ch *.google.ae *.google.co.uk *.google.co.in *.liadm.com *.lytics.io *.medallia.com *.online-metrix.net *.powrcdn.com *.rise-ai.com *.shopify.com *.signifyd.com *.s3.amazonaws.com *.yotpo.com *.ytimg.com data: blob:; font-src 'self' fonts.gstatic.com maxcdn.bootstrapcdn.com use.fontawesome.com *.cloudfront.net *.klaviyo.com *.klarnacdn.net *.kustomerapp.com *.medallia.com *.shopify.com data:; connect-src 'self' analytics.tiktok.com analytics-ipv6.tiktokw.us ara.paa-reporting-advertising.amazon bat.bing.com bat.bing.net cdn.cookielaw.org ct.pinterest.com ds.reson8.com google.com i.geistm.com ib.adnxs.com ipv4.podscribe.com pixel.byspotify.com pixels.spotify.com s3.amazonaws.com tr.snapchat.com tr6.snapchat.com static.kyc.red vuori.api.kustomerapp.com www.googleadservices.com www.awin1.com www.dwin1.com www.cloudflare.com/cdn-cgi/trace *.abtasty.com *.afterpay.com *.agentio.com *.algolia.io *.algolianet.com *.algolia.net *.amazon-adsystem.com *.attn.tv *.attentivemobile.com *.bglobale.com *.boldmetrics.io *.contentstack.com *.contentstack.io *.contentsquare.io *.crazyegg.com *.contentsquare.net *.cloudfront.net *.doubleclick.net *.facebook.com *.facebook.net *.forter.com *.global-e.com *.googleapis.com *.google-analytics.com *.googletagmanager.com *.google.com *.google.com.au *.google.at *.google.be *.google.ca *.google.dk *.google.fi *.google.fr *.google.de *.google.com.hk *.google.ie *.google.it *.google.co.jp *.google.com.mx *.google.nl *.google.no *.google.pt *.google.com.sg *.google.es *.google.se *.google.ch *.google.ae *.google.co.uk *.google.co.in *.hotjar.io *.hotjar.com *.kargo.com *.klaviyo.com *.klarna.com *.klarnaevt.com *.kustomerapp.com *.liadm.com *.medallia.com *.myshopify.com *.nosto.com *.newrelic.com *.nr-data.net *.onetrust.com *.online-metrix.net *.powr.io *.rise-ai.com *.s3.us-east-1.amazonaws.com *.s3.us-east-2.amazonaws.com *.s3.eu-west-1.amazonaws.com *.s3.eu-north-1.amazonaws.com *.s3.ap-south-1.amazonaws.com *.s3.ap-south-2.amazonaws.com *.shopify.com *.signifyd.com *.vaultdcr.com *.yotpo.com apple.com *.apple.com; media-src 'self' *.bfldr.com *.medallia.com *.s3.amazonaws.com data blob:; frame-src 'self' app.netlify.com ct.pinterest.com tr.snapchat.com tr6.snapchat.com www.youtube.com *.abtasty.com *.attn.tv *.doubleclick.net *.facebook.com *.facebook.net *.google.com *.googletagmanager.com *.klarnaevt.com *.medallia.com *.online-metrix.net *.powr.io *.rise-ai.com *.signifyd.com *.vuoriclothing.com; worker-src 'self' *.signifyd.com blob:; frame-ancestors 'self' app.contentstack.com; object-src 'none'; base-uri 'self' *.kampyle.com; report-uri /api/csp-report; 15 default-src 'self'; 14 default-src 'self' blob: https: data: mediastream: 'unsafe-eval' 'unsafe-inline';report-uri https://metrics.media-amazon.com/ 13 script-src 'unsafe-inline' 'unsafe-eval' blob: data: https://clients2.google.com/gr/gr_full_2.0.6.js https://clients2.google.com/gr/gr_sync.js https://payments.google.com/payments/v4/js/integrator.js https://payments.sandbox.google.com/payments/v4/js/integrator.js https://ssl.gstatic.com/external_hosted/lottie/lottie.js https://translate.google.com/translate_a/element.js https://www.google-analytics.com/analytics.js https://www.google.com/recaptcha/api.js https://www.googletagmanager.com/gtag/js https://www.googletagmanager.com/gtag/destination https://www.gstatic.com/_/mss/boq-one-google/_/ https://www.gstatic.com/og/_/js/ https://apis.google.com/js/api.js https://apis.google.com/js/client.js https://www.google.com/tools/feedback/chat_load.js https://www.google.com/tools/feedback/help_api.js https://www.google.com/tools/feedback/load.js https://www.google.com/tools/feedback/open.js https://www.google.com/tools/feedback/open_to_help_guide_lazy.js https://www.gstatic.com/feedback/js/ https://www.gstatic.com/feedback/js/help/prod/service/lazy.min.js https://www.gstatic.com/inproduct_help/api/main.min.js https://www.gstatic.com/inproduct_help/chatsupport/chatsupport_button_v2.js https://www.gstatic.com/inproduct_help/service/lazy.min.js https://www.gstatic.com/uservoice/feedback/client/web/live/ https://www.gstatic.com/uservoice/surveys/resources/prod/js/survey/ https://www.google.com/js/bg/ https://www.gstatic.com/_/boq-play/_/js/k=boq-play.PlayStoreUi.en_US.NOdE5Z-Ardc.2021.O/ https://apis.google.com/_/scs/abc-static/_/js/ https://translate.googleapis.com/_/translate_http/_/js/ https://www.gstatic.com/recaptcha/releases/ https://payments.youtube.com/payments/v4/js/integrator.js https://payments.cloud.google/payments/v4/js/integrator.js;report-uri /_/PlayStoreUi/cspreport/fine-allowlist 13 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://www.googletagmanager.com https://www.google-analytics.com https://connect.facebook.net https://static.hotjar.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; img-src 'self' data: https: blob:; font-src 'self' data: https://fonts.gstatic.com; connect-src 'self' https://www.google-analytics.com; frame-src 'self' https://www.youtube.com https://www.google.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'; 13 font-src *.typekit.net fonts.gstatic.com use.typekit.net *.googleapis.com *.gstatic.com data: maxcdn.bootstrapcdn.com 'self' data: *.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com testsecureacceptance.cybersource.com secureacceptance.cybersource.com 0merchantacsstag.cardinalcommerce.com merchantacs.cardinalcommerce.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.facebook.com *.facebook.net *.clarity.ms get.geojs.io stats.g.doubleclick.net *.zdassets.com *.zendesk.com rum-collector-2.pingdom.net bam.nr-data.net *.klaviyo.com *.xtento.com *.tiktok.com *.google.com *.sportline.com.pa *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.instagram.com www.google.com *.online-metrix.net testflex.cybersource.com flex.cybersource.com testsecureacceptance.cybersource.com secureacceptance.cybersource.com pay.google.com merchantacs.cardinalcommerce.com 0merchantacsstag.cardinalcommerce.com *.blob.core.windows.net/* *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.facebook.com *.facebook.net *.clarity.ms get.geojs.io stats.g.doubleclick.net *.zdassets.com *.zendesk.com rum-collector-2.pingdom.net bam.nr-data.net *.klaviyo.com *.xtento.com *.tiktok.com *.google.com *.sportline.com.pa *.weltpixel.com *.wesupply.xyz https://wesupplylabs.com c.paypal.com checkout.paypal.com assets.braintreegateway.com *.cardinalcommerce.com *.paypal.com * www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io *.ftcdn.net *.behance.net *.gstatic.com *.googleapis.com *.cdninstagram.com www.gstatic.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.facebook.com *.facebook.net *.clarity.ms get.geojs.io stats.g.doubleclick.net *.zdassets.com *.zendesk.com rum-collector-2.pingdom.net bam.nr-data.net *.klaviyo.com *.xtento.com *.tiktok.com *.google.com *.google.com.pa *.sportline.com.pa *.sportline.com.co *.magentosite.cloud 'self' data: *.google-analytics.com *.googleadservices.com *.googletagmanager.com *.paypal.com *.apptrian.com https://www.google.com https://www.google.com.co maps.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com beacon-qa.magento-datasolutions.com beacon-stage.magento-ds.com beacon.magento-ds.com beacon-audiences.magento-ds.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.googleapis.com *.gstatic.com *.instagram.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.online-metrix.net testflex.cybersource.com flex.cybersource.com pay.google.com x.klarnacdn.net centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com chimpstatic.com downloads.mailchimp.com *.list-manage.com *.compassmerchantsolutions.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.blob.core.windows.net/* *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.facebook.com *.facebook.net *.clarity.ms get.geojs.io stats.g.doubleclick.net *.zdassets.com *.zendesk.com rum-collector-2.pingdom.net bam.nr-data.net *.klaviyo.com *.hotjar.com *.xtento.com *.tiktok.com *.sportline.com.pa *.pangle-ads.com *.adobedtm.com *.googletagmanager.com *.google.com *.google-analytics.com *.cloudflare.com maps.googleapis.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://www.googletagmanager.com tagmanager.google.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com beacon-audiences.magento-ds.com fonts.googleapis.com downloads.mailchimp.com https://static.klaviyo.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com maxcdn.bootstrapcdn.com *.googletagmanager.com *.google.com *.typekit.net *.googleapis.com *.gstatic.com *.bootstrapcdn.com unsafe-inline assets.braintreegateway.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.cdninstagram.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.snplow.net commerce.adobedc.net p13n-mr.adobe.io beacon-audiences.magento-ds.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobedc.net *.demdex.net *.adobe.io performance.typekit.net *.sentry.io *.googleapis.com *.compassmerchantsolutions.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ telemetrics.klaviyo.com *.sistecredito.com/* *.blob.core.windows.net/* *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.facebook.com *.facebook.net *.clarity.ms get.geojs.io stats.g.doubleclick.net *.zdassets.com *.zendesk.com rum-collector-2.pingdom.net bam.nr-data.net *.klaviyo.com static-tracking.klaviyo.com fast.a.klaviyo.com a.klaviyo.com *.hotjar.com metrics.hotjar.io wss://ws.hotjar.com content.hotjar.io *.xtento.com *.tiktok.com *.google.com *.sportline.com.pa *.pangle-ads.com assets.adobedtm.com *.adobedtm.com api.mercadopago.com *.google-analytics.com *.paypal.com tm.filter:* maps.googleapis.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com google.com https://www.google-analytics.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 13 report-uri /report-csp-violation; upgrade-insecure-requests 12 script-src 'unsafe-inline' 'unsafe-eval' *.alicdn.com *.aliyun.com *.alyasset.com *.alcasset.com *.alipay.com log.mmstat.com ynuf.aliapp.org *.alipayobjects.com local.alipcsec.com:6691 appx appx-t2 oem-img.wanwang.xin; style-src 'unsafe-inline' *.alicdn.com *.aliyun.com *.alipay.com *.alipayobjects.com oem-img.wanwang.xin; font-src data: *.alicdn.com *.aliyun.com *.alipayobjects.com; frame-src *.aliyun.com *.alicdn.com *.aliyuncs.com *.alipay.com *.taobao.com *.alibabacloud.com *.1688.com xstore.insights.1688.com; report-uri //www.aliyun.com/api/log/csp-report 12 default-src * data: blob: filesystem: about: ws: wss: 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; 12 font-src fonts.gstatic.com use.typekit.net cash-f.squarecdn.com https://*.gstatic.com data: *.sodatech.com *.sodatech.net *.gstatic.com *.typekit.net cdn.livechatinc.com mediacdn.espssl.com viewer.byondxr.com use.fontawesome.com 'self' data: https://fonts.yieldify-production.com/fonts/100822/e6e8821f-e1ad-4601-aaed-5b3386a4580b.otf https://*.hotjar.io https://*.yieldify-production.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com * *.adyen.com api.bazaarvoice.com stg.api.bazaarvoice.com pal-test.adyen.com www.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com http://www.facebook.com/tr 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ * *.adyen.com *.sharethis.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com *.ehappify.com www.xtento.com *.vimeo.com *.jsctool.com *.pinterest.com *.mmcagentur.at *.doubleclick.net *.facebook.com *.facebook.net *.google.com *.demdex.net *.authorize.net *.paypal.com *.googletagmanager.com *.xtento.com *.app-wallee.com *.waltpixel.com *.equitystory.com offer.slgnt.us vars.hotjar.com *.pepperjamnetwork.com services.listrak.com *.serverdata.net *.livechatinc.com *.lindtusa.com *.russellstover.com *.ghirardelli.com https://*.ordergroove.com *.weltpixel.com app-wallee.com www.jsctool.com static.ogmystyle.com static2.ogmystyle.com www.mystyleplatform.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.trustpilot.com geowidget.inpost.pl sandbox-easy-geowidget-sdk.easypack24.net widget.packeta.com https://odr.promo.dev/ https://*.yieldify.com https://ohws.prospective.ch/ https://tpc.googlesyndication.com/ https://*.hotjar.io https://www.mainadv.com https://ad.ad-srv.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io * https://*.gstatic.com *.adyen.com *.sharethis.com display.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com network-a.bazaarvoice.com network-stg-a.bazaarvoice.com photos-uat-us.bazaarvoice.com img.youtube.com *.cloudfront.net *.amazonaws.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ www.xtento.com cdn.xtento.com blob: lindt.test *.lindt.test maps.googleapis.com *.pinterest.com *.postcodeanywhere.co.uk *.klarna.com *.invibes.com *.b26net.com https://www.google-analytics.com *.googletagmanager.com *.teads.tv *.videostep.com *.facebook.com *.google.com *.google.ad *.google.ae *.google.com.af *.google.com.ag *.google.com.ai *.google.al *.google.am *.google.co.ao *.google.com.ar *.google.as *.google.at *.google.com.au *.google.az *.google.ba *.google.com.bd *.google.be *.google.bf *.google.bg *.google.com.bh *.google.bi *.google.bj *.google.com.bn *.google.com.bo *.google.com.br *.google.bs *.google.bt *.google.co.bw *.google.by *.google.com.bz *.google.ca *.google.cd *.google.cf *.google.cg *.google.ch *.google.ci *.google.co.ck *.google.cl *.google.cm *.google.cn *.google.com.co *.google.co.cr *.google.com.cu *.google.cv *.google.com.cy *.google.cz *.google.de *.google.dj *.google.dk *.google.dm *.google.com.do *.google.dz *.google.com.ec *.google.ee *.google.com.eg *.google.es *.google.com.et *.google.fi *.google.com.fj *.google.fm *.google.fr *.google.ga *.google.ge *.google.gg *.google.com.gh *.google.com.gi *.google.gl *.google.gm *.google.gr *.google.com.gt *.google.gy *.google.com.hk *.google.hn *.google.hr *.google.ht *.google.hu *.google.co.id *.google.ie *.google.co.il *.google.im *.google.co.in *.google.iq *.google.is *.google.it *.google.je *.google.com.jm *.google.jo *.google.co.jp *.google.co.ke *.google.com.kh *.google.ki *.google.kg *.google.co.kr *.google.com.kw *.google.kz *.google.la *.google.com.lb *.google.li *.google.lk *.google.co.ls *.google.lt *.google.lu *.google.lv *.google.com.ly *.google.co.ma *.google.md *.google.me *.google.mg *.google.mk *.google.ml *.google.com.mm *.google.mn *.google.ms *.google.com.mt *.google.mu *.google.mv *.google.mw *.google.com.mx *.google.com.my *.google.co.mz *.google.com.na *.google.com.ng *.google.com.ni *.google.ne *.google.nl *.google.no *.google.com.np *.google.nr *.google.nu *.google.co.nz *.google.com.om *.google.com.pa *.google.com.pe *.google.com.pg *.google.com.ph *.google.com.pk *.google.pl *.google.pn *.google.com.pr *.google.ps *.google.pt *.google.com.py *.google.com.qa *.google.ro *.google.ru *.google.rw *.google.com.sa *.google.com.sb *.google.sc *.google.se *.google.com.sg *.google.sh *.google.si *.google.sk *.google.com.sl *.google.sn *.google.so *.google.sm *.google.sr *.google.st *.google.com.sv *.google.td *.google.tg *.google.co.th *.google.com.tj *.google.tl *.google.tm *.google.tn *.google.to *.google.com.tr *.google.tt *.google.com.tw *.google.co.tz *.google.com.ua *.google.co.ug *.google.co.uk *.google.com.uy *.google.co.uz *.google.com.vc *.google.co.ve *.google.vg *.google.co.vi *.google.com.vn *.google.vu *.google.ws *.google.rs *.google.co.za *.google.co.zm *.google.co.zw *.google.cat *.taboola.com *.doubleclick.net *.outbrain.com *.adobedtm.com *.omtrdc.net *.demdex.net *.everesttech.net *.magentocommerce.com *.sodatech.com *.sodatech.net api.official-deals.co.uk api.official-coupons.com *.adsymptotic.com cdn.livechat-files.com cp.official-coupons.com cookie-cdn.cookiepro.com cp.official-deals.co.uk site-azp.slgnt.us ct.pinterest.com *.ads.linkedin.com cdn.polyfill.io offer.slgnt.us *.blob.core.windows.net s.pinimg.com snap.licdn.com mediacdn.espssl.com *.clarity.ms *.bing.com *.serverdata.net lindtna.test *.lindtna.test *.livechatinc.com mageside.com app-wallee.com *.gstatic.com d.ratepay.com viewer.byondxr.com s3.us-west-2.amazonaws.com showroom-media.byondxr.com media-optimization-service.byondxr.com *.byondxr.com *.listrakbi.com www.mystyleplatform.com static.mystyleplatform.com static2.mystyleplatform.com static2.ogmystyle.com mystyleplatform.s3.us-west-2.amazonaws.com https://www.unifaunonline.se https://*.tile.openstreetmap.org/ www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com https://redchamps.com 'self' data: geowidget.inpost.pl sandbox-easy-geowidget-sdk.easypack24.net widget.packeta.com http://lindt-hg65tr.your-printq.com https://*.cookiepro.com https://assets-v2.yieldify.com/images/189494/2022/4/8/55c67825-1f9d-438d-815a-43a437f03af2.png https://assets-v2.yieldify.com/images/189494/2022/4/21/54125dc1-8b51-4175-bd53-7d33e427cc41.gif https://www.lindt-spruengli.com/ https://px.ads.linkedin.com/ https://*.seznam.cz https://*.hotjar.io https://*.yieldify.com https://i.cdn.nrholding.net https://*.sendtric.com network-eu-a.bazaarvoice.com assets-v2.yieldify.com *.cookiepro.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net amcglobal.sc.omtrdc.net *.adobe.io use.typekit.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com *.magento-ds.com *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com *.cash.app *.visa.com *.mastercard.com *.sharethis.com *.googleapis.com *.attn.tv events.attentivemobile.com apps.bazaarvoice.com apps.nexus.bazaarvoice.com apps-stg.nexus.bazaarvoice.com analytics-static.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com mpsnare.iesnare.com widget.freshworks.com m2epro.freshdesk.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ www.xtento.com cdn.xtento.com *.pcapredict.com lindt.slgnt.eu maps.googleapis.com *.pinterest.com *.postcodeanywhere.co.uk *.cloudflare.com *.teads.tv *.r66net.com *.facebook.net *.googleadservices.com *.doubleclick.net *.cookiepro.com *.cloudfront.net *.videostep.com *.mfgroup.ch *.taboola.com *.outbrain.com *.adobedtm.com *.authorize.net *.unpkg.com *.fontawesome.com *.sodatech.net *.sodatech.com www.clarity.ms bat.bing.com *.b2c.com bt.fraud0.com container.pepperjam.com www.googleoptimize.com *.hotjar.com *.pepperjamnetwork.com *.revlifter.io site-azp.slgnt.us ct.pinterest.com *.ads.linkedin.com cdn.polyfill.io offer.slgnt.us *.blob.core.windows.net s.pinimg.com snap.licdn.com acsbapp.com cdn.noibu.com www.youtube.com *.upsellit.com *.livechatinc.com *.serverdata.net *.tiktok.com *.ordergroove.com app-wallee.com https://www.googletagmanager.com tagmanager.google.com d.ratepay.com www.jsctool.com byondxr-viewer.byondxr.com web-apps.byondxr.com *.listrakbi.com *.listrak.com mystyleplatform.com www.mystyleplatform.com static.ogmystyle.com static2.ogmystyle.com d203yb14zlmxwn.cloudfront.net cdnjs.cloudflare.com cdn.jsdelivr.net use.fontawesome.com *.mczbf.com https://api.unifaun.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com songbird.cardinalcommerce.com *.google.com *.gstatic.com *.trustpilot.com geowidget.inpost.pl sandbox-easy-geowidget-sdk.easypack24.net widget.packeta.com https://static-eu.payments-amazon.com/checkout.js https://*.yieldify.com https://www.googleoptimize.com/optimize.js https://custom.yieldify.com/v1/100510/100822/3d9a49d0c2/bundle.js https://snap.licdn.com/li.lms-analytics/insight.min.js https://tpc.googlesyndication.com/sodar/1s9mPOHO.js https://*.adform.net https://*.seznam.cz https://analytics.tiktok.com/ https://*.hotjar.io https://*.pinimg.com https://*.daktela.com https://www.dwin1.com maps.google.com https://www.gstatic.com/recaptcha static.r66net.net https://unbxd.s3.amazonaws.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com *.cash.app https://fonts.googleapis.com/ *.sharethis.com display.ugc.bazaarvoice.com *.amazonaws.com widget.freshworks.com m2epro.freshdesk.com https://static.klaviyo.com *.fonts.net *.postcodeanywhere.co.uk *.cloudfront.net *.cloudflare.com *.sodatech.com *.sodatech.net *.googleapis.com *.getfirebug.com cloud.typography.com *.serverdata.net *.myfonts.net *.russellstover.com tagmanager.google.com d.ratepay.com *.listrakbi.com *.listrak.com use.fontawesome.com www.mystyleplatform.com static.ogmystyle.com static2.ogmystyle.com unsafe-inline assets.braintreegateway.com *.gstatic.com *.trustpilot.com geowidget.inpost.pl widget.packeta.com https://*.hotjar.io 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.cloudfront.net *.serverdata.net *.livechatinc.com *.listrakbi.com www.lindt-spruengli.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io *.magento-datasolutions.com *.magento-ds.com *.sentry.io * *.adyen.com *.sharethis.com *.googleapis.com *.attn.tv events.attentivemobile.com api.bazaarvoice.com stg.api.bazaarvoice.com apps.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com widget.freshworks.com m2epro.freshdesk.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.paypal.com *.postcodeanywhere.co.uk *.ratepay.com *.luckyorange.net *.cookiepro.com *.mfgroup.ch *.doubleclick.net *.visitors.live wss://in.visitors.live wss://visitors.live wss://in.visitors.live/ wss://visitors.live/ visitors.live *.taboola.com *.demdex.net *.omtrdc.net *.magento.com *.adobe.net *.adobedtm.com *.adobedc.net *.typekit.net *.magedevteam.com *.sodatech.com *.sodatech.net *.teads.tv www.sjwoe.com input.noibu.com wss://input.noibu.com/pv_part in.hotjar.com www.facebook.com *.b2c.com bt.fraud0.com *.revlifter.com *.pepperjamnetwork.com *.revlifter.io site-azp.slgnt.us ct.pinterest.com *.ads.linkedin.com cdn.polyfill.io offer.slgnt.us s.pinimg.com snap.licdn.com *.acsbapp.com cdn.noibu.com https://maps.googleapis.com *.clarity.ms *.facebook.com *.serverdata.net *.livechatinc.com api.addressy.com *.listrakbi.com *.mczbf.com *.tiktok.com *.ordergroove.com https://www.google-analytics.com d.ratepay.com www.jsctool.com *.byondxr.com api.byondxr.com s3.us-west-2.amazonaws.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.google.com google.com t.elasticsuite.io *.google-analytics.com https://*.criteo.com https://*.hotjar.io https://cdn.stickyadstv.com https://*.ads.linkedin.com https://snap.licdn.com *.analytics.google.com https://*.r66net.com https://*.yieldify.com wss://*.hotjar.io https://geolocation.onetrust.com https://*.googleapis.com https://*.daktela.com https://cdn.tailwindcss.com https://sgtm.lindt.se sgtm.lindt.se sgtm.lindt.dk sgtm.lindt.cz sgtm.lindt.de sgtm.lindt.es sgtm.lindt.fr sgtm.lindt.it sgtm.lindt.hu sgtm.lindt.co.uk sgtm.lindt.com.nl sgtm.lindt.pl sgtm.lindt.at geolocation.onetrust.com sgtm.lindt.sk sgtm.lindt.fi 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.byondxr.com *.googleapis.com https://cdn.tailwindcss.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 12 default-src https: blob: data: 'unsafe-inline' 'unsafe-eval'; report-to blogspot; report-uri https://draft.blogger.com/cspreport 12 script-src https://www.google.com https://www.gstatic.com https://www.youtube.com https://maps.googleapis.com https://www.googletagmanager.com https://www.google-analytics.com https://static.ola-uat.pepcdn.com https://static.addtoany.com https://cdn.botframework.com https://unpkg.com https://static.ola.pepcdn.com/widget.js 'self'; style-src https://fonts.googleapis.com https://static.ola-uat.pepcdn.com https://static.ola.pepcdn.com 'self' 'unsafe-inline';report-uri https://b718b756d5c48844997d82c4ea809bfb.report-uri.com/r/d/csp/reportOnly;report-to csp-endpoint; 12 default-src 'self' f.vimeocdn.com; connect-src 'self' blob: data: ws: wss: *.6sc.co *.6sense.com *.agora.io *.akamaized.net clientassets.sightera.com.s3.amazonaws.com https://d263mgllkjh2k2.cloudfront.net http://d1ripsxh7es2qp.cloudfront.net https://d3fclmoge30w0w.cloudfront.net cognito-identity.us-east-1.amazonaws.com cognito-identity.us-west-1.amazonaws.com https://s3.amazonaws.com/beast.branding.sightera.com https://s3.amazonaws.com/beast.business.sightera.com https://s3.amazonaws.com/beast.business.sightera.com/ https://s3.amazonaws.com/beast.branding.sightera.com/ https://s3.amazonaws.com/test.sightera.com/ https://s3.amazonaws.com/business.sightera.com/ https://s3.amazonaws.com/sound.sightera.com/ sqs.us-east-1.amazonaws.com sqs.us-west-1.amazonaws.com wirewax.s3.eu-west-1.amazonaws.com *.amplitude.com vimeo.bynder.com bat.bing-int.com bat.bing.com bat.bing.net www.bing.com api.branch.io cdn.builder.io https://d1ripsxh7es2qp.cloudfront.net http://d1oca24q5dwo6d.cloudfront.net media.gettyimages.com d2by6sxflmuwyq.cloudfront.net duysrfiajusdh.cloudfront.net dv7a7fjpjy29e.cloudfront.net cdn.cookielaw.org browser-intake-datadoghq.com ad.doubleclick.net *.g.doubleclick.net *.elfsight.com fp.service.expressplay.com pr.service.expressplay.com wv.service.expressplay.com www.facebook.com api.figma.com *.firebaseio.com tracking-api.g2.com *.getsmartling.com *.google.ae *.google.com *.google.ca *.google.ch *.google.es *.google.fr *.google.ge *.google.iq *.google.is *.google.it *.google.pl *.google.se *.google.si *.google.rs *.google.co.jp *.google.co.kr *.google.co.nz *.google.co.th *.google.co.uk *.google.com.ar *.google.com.au *.google.com.br *.google.com.mx *.google.com.pk *.google.com.sa *.google.com.tr *.google.com.uk *.google.de *.analytics.google.com *.google-analytics.com www.googleadservices.com *.googleapis.com csi.gstatic.com pagead2.googlesyndication.com *.googletagmanager.com api.greenhouse.io *.hivestreaming.com 117151225.intellimizeio.com *.intellimize.co *.kollective.app *.kollective.app:31015 *.kollectivecd.com leatherback-dot-vimeo-prod.appspot.com snap.licdn.com px.ads.linkedin.com linkedin.com *.litix.io *.cdn.magisto.com vimeo.magisto.com *.maze.co 582-gou-684.mktoresp.com js-agent.newrelic.com t.paypal.com https://data.pendo.io *.pndsn.com privacyportal.onetrust.com privacyportal-cdn.onetrust.com app.qualified.com *.qualtrics.com pixel-config.reddit.com www.redditstatic.com *.riskified.com *.statscollector.ap.sd-rtn.com *.ap.sd-rtn.com *.sd-rtn.com o209747.ingest.us.sentry.io sierra.chat simonsignal.com static.simonsignal.com sdk-api-v1.singular.net web-sdk-cdn.singular.net telemetry.transcend.io transcend-cdn.com https://drm.vhx.com/v2/fairplay/cert collector.vhx.tv *.cloud.vimeo.com interactive.create.vimeo.com *.vimeo.com vimeo.com *.vimeo.work https://*.vimeocdn.com cdn.widerfunnel.com appds8093.blob.core.windows.net *.wirewax.com *.wirewax.tv *.zdassets.com vimeosupport.zendesk.com *.zoom.us zoom.us ws.zoominfo.com api.box.com public.boxcloud.com https://api.picox.bendingspoons.com https://orion.bendingspoons.com; font-src 'self' data: d2by6sxflmuwyq.cloudfront.net dv7a7fjpjy29e.cloudfront.net fonts.gstatic.com *.cdn.magisto.com privacyportal-cdn.onetrust.com www.paypalobjects.com cf-st.sc-cdn.net use.typekit.net f.vimeocdn.com edge-assets.wirewax.com cdn01.boxcdn.net; frame-src *; img-src * blob: data:; media-src 'self' blob: data: *.akamaized.net https://d263mgllkjh2k2.cloudfront.net http://d1oca24q5dwo6d.cloudfront.net duysrfiajusdh.cloudfront.net media.gettyimages.com *.gvt1.com *.cdn.magisto.com *.eu.cloud.vimeo.com live-api.cloud.vimeo.com player.vimeo.com *.vimeocdn.com app.qualified.com https://s3.amazonaws.com/sound.sightera.com/ https://s3.amazonaws.com/test.sightera.com/ https://s3.amazonaws.com/beast.business.sightera.com/ https://s3.amazonaws.com/beast.business.sightera.com https://s3.amazonaws.com/beast.branding.sightera.com/ https://storage.googleapis.com/vimeo-create-prod-files/ http://d1ripsxh7es2qp.cloudfront.net https://d3fclmoge30w0w.cloudfront.net https://storage.googleapis.com/vimeo-prod-upload-create-us-east1/ https://storage.googleapis.com/vimeo-prod-upload-create-europe-west1/ https://storage.googleapis.com/vimeo-storage-dev-upload-create-us-east1/ https://storage.googleapis.com/vimeo-storage-dev-upload-create-europe-west1/ https://captions.vimeo.com https://captions-eu.vimeo.com; object-src 'self' *.vimeocdn.com *.akamaized.net; script-src 'unsafe-inline' 'unsafe-eval' 'self' data: ws: wss: https://s0.2mdn.net/instream/video/ *.6sc.co wirewax.s3.eu-west-1.amazonaws.com app.link bat.bing-int.com bat.bing.com cdnjs.cloudflare.com challenges.cloudflare.com www.datadoghq-browser-agent.com *.g.doubleclick.net www.dropbox.com static.elfsight.com *.elfsightcdn.com connect.facebook.net *.firebaseio.com tracking.g2crowd.com *.google.com www.googleadservices.com www.gstatic.com *.google-analytics.com maps.googleapis.com pendo-io-static.storage.googleapis.com pendo-static-6633483048714240.storage.googleapis.com pagead2.googlesyndication.com www.googletagmanager.com www.googletagservices.com cdn.intellimize.co *.kollective.app snap.licdn.com src.litix.io lp.livestream.com munchkin.marketo.net snippet.maze.co privacyportal-cdn.onetrust.com www.paypalobjects.com cdn.pendo.io js.qualified.com https://data.pendo.io *.qualtrics.com www.redditstatic.com beacon.riskified.com secured-pixel.com sierra.chat static.simonsignal.com web-sdk-cdn.singular.net transcend-cdn.com vimeo.com *.vimeo.com https://*.vimeocdn.com cdn.widerfunnel.com edge-assets.wirewax.com embedder-sdk.wirewax.com embedder-sdk.wirewax.tv origin-4.xtlo.net static.zdassets.com *.zoom.us zoom.us ws.zoominfo.com static.zuora.com https://www.dropbox.com/static/api/2/dropins.js cdn01.boxcdn.net; style-src 'self' 'unsafe-inline' *.6sc.co cdn01.boxcdn.net cdnjs.cloudflare.com accounts.google.com fonts.googleapis.com pendo-static-6633483048714240.storage.googleapis.com www.gstatic.com lp.livestream.com privacyportal-cdn.onetrust.com www.paypalobjects.com sierra.chat *.vimeo.com https://*.vimeocdn.com vimeopro.com transcend-cdn.com cdn.widerfunnel.com edge-assets.wirewax.com edge-player5.wirewax.com origin-4.xtlo.net; worker-src 'self' blob:; report-to csp-endpoint; report-uri https://browser-intake-datadoghq.com/api/v2/logs?dd-api-key=puba92ed04ee7cceea44335c3d8c1ccc173&dd-evp-origin=content-security-policy&ddsource=csp-report&ddtags=service%3Acspreport%2Cenv%3Aproduction 11 default-src 'self' 'unsafe-inline' 'unsafe-eval' data: blob: *.akstat.io p11.techlab-cdn.com trial-eum-clientnsv4-s.akamaihd.net trial-eum-clienttons-s.akamaihd.net c.go-mpulse.net s.go-mpulse.net *.algolianet.com us5azow6i2-dsn.algolia.net xfoi9ebbhr-dsn.algolia.net secure.adnxs.com bat.bing.com bat.bing.net d.btttag.com pearson3283191z.btttag.com pearson.blueconic.net pearson.sb.blueconic.net api.company-target.com s.company-target.com tag-logger.demandbase.com tag.demandbase.com googleads.g.doubleclick.net ad.doubleclick.net td.doubleclick.net *.fls.doubleclick.net connect.facebook.net analytics.formassembly.com pearson.tfaforms.net ade.googlesyndication.com fonts.gstatic.com pagead2.googlesyndication.com fonts.googleapis.com region1.google-analytics.com static.hotjar.com utt.impactcdn.com cdn.jsdelivr.net app.launchdarkly.com px.ads.linkedin.com snap.licdn.com i.liadm.com cdn.cookielaw.org bam.nr-data.net js-agent.newrelic.com geolocation.onetrust.com privacyportal-de.onetrust.com *.pearson.com pearson.com cdn.pdst.fm a.quora.com q.quora.com tag.rmp.rakuten.com alb.reddit.com pixel-config.reddit.com www.redditstatic.com pi.pardot.com sc-static.sc-static.net tr.snapchat.com tr6.snapchat.com pixels.spotify.com analytics-ipv6.tiktokw.us analytics.tiktok.com insight.adsrvr.org js.adsrvr.org static.ads-twitter.com analytics.twitter.com t.t.co pearson.esaas.inmoment.eu pearson.mcxplatform.de *.visualwebsiteoptimizer.com img.youtube.com pearson--projects.sandbox.my.site.com; frame-ancestors 'none'; 11 default-src 'self';base-uri 'none';frame-ancestors 'self';frame-src 'self' 5164101.fls.doubleclick.net apps.rokt.com audible.demdex.net bs.serving-sys.com s.amazon-adsystem.com td.doubleclick.net tr.snapchat.com www.facebook.com;style-src 'self' 'unsafe-inline' images-na.ssl-images-amazon.com;script-src 'self' 'unsafe-inline' apps.rokt.com audible.sc.omtrdc.net bat.bing.com/bat.js bat.bing.com/p/action/4004590.js bat.bing.com/p/insights/s/0.7.20 bat.bing.com/p/insights/t/4004590 connect.facebook.net d.impactradius-event.com d1g3myji5lplsh.cloudfront.net d2nttevkh1mtzs.cloudfront.net googleads.g.doubleclick.net images-na.ssl-images-amazon.com sc-static.net siteintercept.qualtrics.com tr.snapchat.com www.googleadservices.com/pagead/conversion/ www.googletagmanager.com zn5ygnnjlk4oo0dy1-audible.siteintercept.qualtrics.com;media-src 'self' images-na.ssl-images-amazon.com/images/ m.media-amazon.com samples.audible.co.uk samples.audible.com;object-src 'none';connect-src 'self' adservice.google.com/pagead/regclk api.audible.com audible.sc.omtrdc.net/b/ss/ audible.tt.omtrdc.net/rest/v1/delivery bat.bing.com/p/insights/c/ dpm.demdex.net fls-na.amazon.com m.media-amazon.com pagead2.googlesyndication.com/pagead/buyside_topics/set/ siteintercept.qualtrics.com tr.snapchat.com unagi-na.amazon.com unagi.amazon.com www.audible.com www.facebook.com/tr/ www.google.com/pagead/landing;font-src www.audible.com m.media-amazon.com;img-src 'self' ad.doubleclick.net bat.bing.com/action/0 fls-na.amazon.com googleads.g.doubleclick.net/pagead/viewthroughconversion/ images-eu.ssl-images-amazon.com images-na.ssl-images-amazon.com m.media-amazon.com s.amazon-adsystem.com/iui3 www.facebook.com www.google.ca/pagead/1p-user-list/ www.google.ch/pagead/1p-user-list/ www.google.ee/pagead/1p-user-list/ www.google.pt/pagead/1p-user-list/ www.google.ro/pagead/1p-user-list/ www.google.se/pagead/1p-user-list/ www.google.co.cr/pagead/1p-user-list/ www.google.co.il/pagead/1p-user-list/ www.google.co.in/pagead/1p-user-list/ www.google.co.ke/pagead/1p-user-list/ www.google.co.kr/pagead/1p-user-list/ www.google.co.nz/pagead/1p-user-list/ www.google.co.th/pagead/1p-user-list/ www.google.co.uk/pagead/1p-user-list/ www.google.co.za/pagead/1p-user-list/ www.google.com.ar/pagead/1p-user-list/ www.google.com.br/pagead/1p-user-list/ www.google.com.co/pagead/1p-user-list/ www.google.com.do/pagead/1p-user-list/ www.google.com.ec/pagead/1p-user-list/ www.google.com.hk/pagead/1p-user-list/ www.google.com.jm/pagead/1p-user-list/ www.google.com.mx/pagead/1p-user-list/ www.google.com.my/pagead/1p-user-list/ www.google.com.ng/pagead/1p-user-list/ www.google.com.pa/pagead/1p-user-list/ www.google.com.pe/pagead/1p-user-list/ www.google.com.ph/pagead/1p-user-list/ www.google.com.pk/pagead/1p-user-list/ www.google.com.sg/pagead/1p-user-list/ www.google.com/pagead/1p-user-list/ www.google.de/pagead/1p-user-list/ www.google.dk/pagead/1p-user-list/ www.google.es/pagead/1p-user-list/ www.google.ie/pagead/1p-user-list/ www.google.no/pagead/1p-user-list/ www.googleadservices.com/pagead/conversion/ www.googletagmanager.com 10 default-src https: 'self' *.facebook.net *.googletagmanager.com *.bizibly.com *.doubleclick.net https://*.intercomcdn.com https://*.datadoghq-browser-agent.com; font-src 'self' https://*.intercomcdn.com *.fontawesome.com data:; base-uri 'none'; object-src data: 'unsafe-eval'; img-src 'self' data: * ; script-src https: 'self' 'unsafe-eval' 'unsafe-inline' http://*.google-analytics.com http://*.gstatic.com http://*.bing.com http://*.googleadservices.com http://*.hs-scripts.com http://*.bizible.com *.facebook.net *.googletagmanager.com http://*.fontawesome.com http://*.outbrain.com blob:; style-src https: 'self' *.fontawesome.com 'unsafe-inline'; report-uri /rest/trackers/csp; 10 report-uri https://cspr.app.rbb-cloud.de/cspr/;frame-ancestors 'self' https://www.rbb24.de https://*.rbb-online.de https://www.radioeins.de https://www.fritz.de https://www.antennebrandenburg.de https://www.inforadio.de https://www.rbb888.de; 10 default-src https: wss: data: blob:; script-src https: 'unsafe-eval' 'unsafe-inline'; style-src https: 'unsafe-inline'; img-src https: data: blob:; font-src https: data:; worker-src blob:; report-uri /csp-report 10 font-src cash-f.squarecdn.com data: *.gstatic.com *.photoslurp.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com * *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ * *.facebook.com *.mediquo.com *.hotjar.com *.criteo.com *.google.com *.clic2buy.com *.vimeo.com *.photoslurp.com *.sitescout.com *.criteo.net 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io * cdn.doofinder.com *.cloudfront.net *.amazonaws.com *.bing.com *.facebook.com widget-mediator.zopim.com *.swogo.net *.criteo.com *.googleapis.com *.google.com *.google.es *.google.com.br *.gstatic.com *.googletagmanager.com *.google-analytics.com *.g.doubleclick.net *.photoslurp.com *.googleusercontent.com *.clarity.ms *.smartadserver.com *.bidswitch.net *.adnxs.com *.casalemedia.com *.360yield.com *.media.net *.mediavine.com *.outbrain.com *.pubmatic.com *.rubiconproject.com *.sharethrough.com *.taboola.com *.teads.tv *.3lift.com *.yahoo.com *.adform.net *.omnitagjs.com id5-sync.com *.yieldlab.net *.yieldmo.com *.demdex.net *.krxd.net *.thebrighttag.com *.sitescout.com *.sanity.io cdn.flbx.io data: 'self' 'unsafe-inline'; script-src www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com *.cash.app *.visa.com *.mastercard.com cdn.doofinder.com *.naturitas.com naturitas.slgnt.eu static.zdassets.com bat.bing.com connect.facebook.net *.swogo.net *.hotjar.com *.mediquo.com static.criteo.net *.criteo.com *.typeform.com *.clic2buy.com polyfill.io *.googleapis.com *.google.com *.google.es *.google.com.br *.googleoptimize.com *.gstatic.com *.googletagmanager.com *.google-analytics.com *.g.doubleclick.net *.photoslurp.com *.clarity.ms *.pixel.ad *.dwin1.com *.getflowbox.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.cash.app *.doofinder.com *.googleapis.com *.photoslurp.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com * *.doofinder.com wss://*.doofinder.com *.naturitas.com *.naturitas.es naturitas-atc.zendesk.com ekr.zdassets.com wss://widget-mediator.zopim.com *.swogo.net *.googlesyndication.com *.hotjar.com *.google.com *.google.es *.google.com.br *.googletagmanager.com *.google-analytics.com *.g.doubleclick.net *.adyen.com *.photoslurp.com *.clarity.ms *.apicdn.sanity.io *.api.sanity.io *.getflowbox.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 10 child-src blob: data: https:; connect-src https: wss:; default-src blob: data: https: 'report-sample' 'unsafe-eval' 'unsafe-inline'; font-src data: https:; form-action https:; frame-src data: https:; img-src blob: data: https:; media-src blob: data: https:; object-src https:; script-src https: 'unsafe-eval' 'unsafe-inline'; style-src https: 'unsafe-inline'; report-uri https://csp.ffx.io/; report-to csp-endpoint 9 script-src 'self' 9 default-src 'self'; connect-src 'self' https://www.google-analytics.com https://*.newrelic.com https://*.nr-data.net https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://www.googletagmanager.com; font-src 'self' https://themes.googleusercontent.com fonts.gstatic.com https://cdn.jsdelivr.net data:; frame-src 'self' https://www.youtube.com https://www.vimeo.com; img-src 'self' https://translate.google.com https://www.googletagmanager.com https://www.google-analytics.com https://cdn.jsdelivr.net https://i.ytimg.com https://www.gstatic.com https://maps.gstatic.com https://maps.googleapis.com https://*.google-analytics.com https://*.googletagmanager.com data:; script-src 'self' https://www.googletagmanager.com https://www.google-analytics.com https://*.newrelic.com https://*.nr-data.net https://*.googletagmanager.com cdn.jsdelivr.net cdnjs.cloudflare.com https://cdn.ckeditor.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com maps.googleapis.com unpkg.com; script-src-attr 'self'; script-src-elem 'self' https://www.googletagmanager.com https://www.google-analytics.com https://*.newrelic.com https://*.nr-data.net cdn.jsdelivr.net cdnjs.cloudflare.com https://cdn.ckeditor.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com maps.googleapis.com unpkg.com; style-src 'self' cdn.jsdelivr.net cdnjs.cloudflare.com fonts.googleapis.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com unpkg.com; style-src-attr 'self' 'unsafe-inline'; style-src-elem 'self' 'unsafe-inline' cdn.jsdelivr.net cdnjs.cloudflare.com fonts.googleapis.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com unpkg.com; block-all-mixed-content 9 default-src https: data: 'unsafe-inline' 'unsafe-eval' 9 script-src 'unsafe-eval' blob: 'self' meta.wikimedia.org *.wikimedia.org *.wikipedia.org *.wikinews.org *.wiktionary.org *.wikibooks.org *.wikiversity.org *.wikisource.org wikisource.org *.wikiquote.org *.wikidata.org *.wikifunctions.org *.wikivoyage.org *.mediawiki.org 'unsafe-inline' auth.wikimedia.org; default-src 'self' data: blob: upload.wikimedia.org https://commons.wikimedia.org meta.wikimedia.org *.wikimedia.org *.wikipedia.org *.wikinews.org *.wiktionary.org *.wikibooks.org *.wikiversity.org *.wikisource.org wikisource.org *.wikiquote.org *.wikidata.org *.wikifunctions.org *.wikivoyage.org *.mediawiki.org wikimedia.org en.wikibooks.org en.wikinews.org en.wikiquote.org en.wikisource.org en.wikiversity.org en.wikivoyage.org en.wiktionary.org www.mediawiki.org api.wikimedia.org commons.wikimedia.org foundation.wikimedia.org incubator.wikimedia.org species.wikimedia.org wikimania.wikimedia.org www.wikidata.org www.wikifunctions.org auth.wikimedia.org; style-src 'self' data: blob: upload.wikimedia.org https://commons.wikimedia.org meta.wikimedia.org *.wikimedia.org *.wikipedia.org *.wikinews.org *.wiktionary.org *.wikibooks.org *.wikiversity.org *.wikisource.org wikisource.org *.wikiquote.org *.wikidata.org *.wikifunctions.org *.wikivoyage.org *.mediawiki.org wikimedia.org 'unsafe-inline'; object-src 'none'; report-uri /w/api.php?action=cspreport&format=json&reportonly=1 9 default-src * 'unsafe-inline' 'unsafe-eval'; style-src 'unsafe-inline'; script-src 'none' 'report-sample'; connect-src 'none'; form-action 'none'; frame-src 'none'; worker-src 'none'; frame-ancestors 'none'; upgrade-insecure-requests; block-all-mixed-content; report-uri https://csp.threatview.app/report; report-to threatview 9 default-src https:; connect-src https: wss:; script-src 'unsafe-inline' 'unsafe-eval' https:; style-src 'self' 'unsafe-inline' *.google.com fonts.googleapis.com static.pazaruvaj.com unpkg.com api.mapbox.com cdn.jsdelivr.net geowidget.easypack24.net maxcdn.bootstrapcdn.com ssl.ceneo.pl s.kk-resources.com elnino.daktela.com www.wiarygodneopinie.pl ts.tradetracker.net cdn.foxentry.cz www.parfemy-elnino.cz geowidget.inpost.pl www.googletagmanager.com smartsuppcdn.com *.demandware.net; object-src 'self'; img-src 'self' https: data:; font-src https: data:; frame-ancestors 'self' *.creativecdn.com *.hotjar.com *.googletagmanager.com; report-uri https://elnino.report-uri.com/r/d/csp/enforce 9 upgrade-insecure-requests; 9 default-src * 'self'; style-src * 'self' 'unsafe-inline'; img-src * 'self' data: blob:; script-src * 'self' about: 'unsafe-inline' 'unsafe-eval' data:; worker-src * 'self' data: blob: 'unsafe-eval' 'unsafe-inline'; frame-src * 'self'; media-src 'self' blob: *; font-src * 'self' data:; upgrade-insecure-requests; form-action 'self'; frame-ancestors 'self';report-uri /contentsecuritypolicy/report 8 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com *.cloudflare.com *.twitter.com *.twimg.com *.trustedshops.com *.googleapis.com *.zopim.com *.zopim.io *.cookielaw.org *.bs-distribution.com acc-shop.bs-distribution.com *.onetrust.com *.b2b-nfinity.com *.adobe.com *.bunny.net *.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.adyen.com pay.google.com payments-eu.amazon.com *.amazon.de *.twitter.com *.facebook.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.demdex.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.adyen.com pay.google.com https://www.youtube.com http://www.sandbox.paypal.com *.twitter.com *.facebook.com *.b2b-nfinity.com *.googleapis.com *.magentocommerce.com c.paypal.com checkout.paypal.com assets.braintreegateway.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net data: *.adyen.com pay.google.com *.payments-amazon.com *.media-amazon.com *.paypalobjects.com *.cloudflare.com *.klarna.com *.googleadservices.com *.google-analytics.com *.twitter.com *.twimg.com *.ytimg.com *.bing.com *.zopim.com *.zopim.io *.doubleclick.net *.google.com *.google.co.in *.mastercard.com *.cookielaw.org *.bs-distribution.com acc-shop.bs-distribution.com *.onetrust.com *.linkedin.com t.co *.b2b-nfinity.com *.googleapis.com *.magentocommerce.com *.clarity.ms *.facebook.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net assets.adobedtm.com *.adobe.io *.commerce-payment-services.com *.magento-ds.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.magento-datasolutions.com *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com https://rum.hlx.page *.cloudflare.com *.twitter.com *.google-analytics.com *.twimg.com *.gstatic.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.bing.com *.zopim.com *.zdassets.com *.cookielaw.org *.bs-distribution.com acc-shop.bs-distribution.com *.onetrust.com *.b2b-nfinity.com *.googleapis.com *.magentocommerce.com *.facebook.net *.licdn.com *.ads-twitter.com *.ads-x.com *.clarity.ms *.googletagmanager.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.magento-datasolutions.com *.magento-ds.com *.fontawesome.com *.cloudflare.com *.googleapis.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.bing.com *.cookielaw.org *.bs-distribution.com acc-shop.bs-distribution.com *.onetrust.com *.b2b-nfinity.com *.magentocommerce.com *.google.com assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.zopim.com *.zopim.io *.cookielaw.org *.bs-distribution.com acc-shop.bs-distribution.com *.onetrust.com *.b2b-nfinity.com *.googleapis.com *.gstatic.com *.magentocommerce.com 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.magento-datasolutions.com *.magento-ds.com *.adyen.com payments-eu.amazon.com *.cloudflare.com *.twitter.com *.ads-twitter.com *.ads-x.com *.twimg.com *.zdassets.com *.zopim.com *.zopim.io wss://widget-mediator.zopim.com *.google-analytics.com https://stats.g.doubleclick.net *.cookielaw.org *.bs-distribution.com acc-shop.bs-distribution.com *.onetrust.com *.b2b-nfinity.com *.googleapis.com *.adobe.com *.gstatic.com *.magentocommerce.com *.linkedin.com *.clarity.ms api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 8 require-trusted-types-for 'script'; report-uri https://csp.withgoogle.com/csp/uxe-owners-acl/marketing_platform 7 block-all-mixed-content; report-uri https://dmgm.report-uri.com/r/t/csp/reportOnly 7 default-src https: 'unsafe-inline' 'unsafe-eval' wss: ;img-src https: data: blob: ; font-src https: data:; form-action https: http://www.last.fm; report-uri https://cbsi.report-uri.io/r/default/csp/enforce 7 require-trusted-types-for 'script'; report-uri https://csp.withgoogle.com/csp/domain-registry 7 frame-ancestors 'self' https://*.yahooinc.com; object-src 'none'; script-src 'none'; report-uri https://csp.yahoo.com/beacon/csp?src=yahooinc; 7 script-src 'none'; form-action 'none'; frame-src 'none'; report-uri https://csp.withgoogle.com/csp/scaffolding/ntdsgswbsc:55:0 7 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.klarnacdn.net *.klevu.com *.ksearchnet.com https://www.gstatic.com https://fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.nosto.com *.nos.to 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.awin1.com *.zenaps.com *.fls.doubleclick.net c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.nosto.com *.nos.to *.klarna.com js.mollie.com https://www.google.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.payments-amazon.com *.awin1.com *.zenaps.com *.wepowerconnections.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.nosto.com *.nos.to *.klarna.com *.klarnaevt.com *.klarnacdn.net https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com https://www.mollie.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.awin1.com *.dwin1.com *.zenaps.com *.wepowerconnections.com https://the.sciencebehindecommerce.com lantern.roeyecdn.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.nosto.com *.nos.to *.klarna.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ js.klevu.com *.ksearchnet.com widget.freshworks.com m2epro.freshdesk.com js.mollie.com https://www.google.com https://www.gstatic.com https://js.klevu.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com assets.braintreegateway.com *.nosto.com *.nos.to *.klarnacdn.net https://static.klaviyo.com *.klevu.com *.ksearchnet.com widget.freshworks.com m2epro.freshdesk.com https://js.klevu.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.wepowerconnections.com https://the.sciencebehindecommerce.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.nosto.com *.nos.to *.klarnaevt.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.klarna.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com widget.freshworks.com m2epro.freshdesk.com 'self' 'unsafe-inline'; child-src *.awin1.com *.zenaps.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://20a27546-5165-4716-8e1c-c91dee6f68ae.sansec.watch/; report-to report-endpoint; 7 default-src * 'unsafe-inline' 'unsafe-eval' data: blob: 7 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com data: 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com *.fontawesome.com maxcdn.bootstrapcdn.com *.cloudflare.com *.twitter.com *.twimg.com *.trustedshops.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com *.googlesyndication.com *.tiktok.com *.twitter.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.multisafepay.com https://pay.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * www.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com *.multisafepay.com https://pay.google.com *.twitter.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.googleapis.com *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.googlesyndication.com *.roeye.com *.tiktok.com flagpedia.net *.multisafepay.com *.cloudflare.com *.klarna.com *.googleadservices.com *.google-analytics.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.cloudfront.net app.youshouldask.ai interface.mailcampaigns.nl data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.googlesyndication.com *.jsdelivr.net *.tiktok.com maps.googleapis.com *.multisafepay.com https://pay.google.com *.cloudflare.com *.twitter.com *.twimg.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com ka-p.fontawesome.com app.youshouldask.ai static.cloudflareinsights.com interface.mailcampaigns.nl static.usizy.es app.aiden.cx 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com assets.braintreegateway.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com *.tiktok.com *.fontawesome.com maxcdn.bootstrapcdn.com *.multisafepay.com *.cloudflare.com *.twitter.com *.twimg.com *.typekit.net *.trustedshops.com *.usercentrics.eu app.youshouldask.ai 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.googleapis.com *.google-analytics.com *.facebook.com *.facebook.net *.doubleclick.net *.googlesyndication.com *.tiktok.com www.gstatic.com maps.googleapis.com *.multisafepay.com *.cloudflare.com *.twitter.com *.twimg.com ka-p.fontawesome.com app.youshouldask.ai usizy.com app.aiden.cx 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' data: 'unsafe-inline' data: 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri http://csp-reporting-service.com/my-project/endpoint; report-to report-endpoint; 7 default-src data: blob: about: 'self' 'unsafe-inline' 'unsafe-eval' https: wss:; report-uri /csp/report?always; 6 script-src 'self' 'unsafe-inline' 'unsafe-eval' https://unpkg.com https://acsbapp.com https://snap.licdn.com https://sc-static.net https://tr.snapchat.com https://maps.googleapis.com https://static.ads-twitter.com https://analytics.twitter.com https://connect.facebook.net https://cdn.cookielaw.org https://www.youtube.com https://static.addtoany.com https://cdnjs.cloudflare.com https://www.googletagmanager.com https://js-agent.newrelic.com https://geolocation.onetrust.com https://bam-cell.nr-data.net https://cdnsecakmi.kaltura.com https://cdnapisec.kaltura.com http://cdnapi.kaltura.com https://cfvod.kaltura.com https://www.google-analytics.com https://cdn.jsdelivr.net https://script.crazyegg.com https://static.cloudflareinsights.com https://www.google.com https://www.gstatic.com https://bam.nr-data.net https://hm.baidu.com/hm.js https://www.clarity.ms https://www.googleadservices.com blob: https://vjs.zencdn.net/5.0/video.min.js https://analytics.tiktok.com; object-src 'self' 'unsafe-inline' 'unsafe-eval' https: data; style-src 'self' 'unsafe-inline' 'unsafe-eval' https://cdn.cookielaw.org https://acsbapp.com https://sc-static.net https://tr.snapchat.com https://maps.googleapis.com https://fonts.googleapis.com https://www.youtube.com https://static.addtoany.com https://cdnjs.cloudflare.com https://www.googletagmanager.com https://js-agent.newrelic.com https://geolocation.onetrust.com https://bam-cell.nr-data.net https://script.crazyegg.com https://static.cloudflareinsights.com https://cdnapisec.kaltura.com https://cfvod.kaltura.com https://vjs.zencdn.net/5.0/video-js.min.css https://analytics.tiktok.com; frame-ancestors 'self' 6 frame-ancestors 'self'; report-uri https://www.couriermail.com.au/csp-reports 6 default-src 'self' 'unsafe-inline' 'unsafe-eval' data: blob: ws: wss: https:; report-uri https://l.iplsc.com/logger/ 6 default-src 'self' 'unsafe-inline' 'unsafe-eval' https://snap.licdn.com *.willistowerswatson *.wtwco.com https://www.google-analytics.com https://cdn.cookielaw.org https://www.googletagmanager.com *.coveo.com https://players.brightcove.net *.doubleclick.net https://munchkin.marketo.net https://bat.bing.com *.facebook.net *.facebook.com https://siteimproveanalytics.com *.linkedin.com *.mktoresp.com *.siteimproveanalytics.io data: blob:;report-uri /custom/api/csp/logviolation 6 default-src 'self' 'unsafe-inline' 'unsafe-eval'; font-src 'self' data:; script-src 'self' 'unsafe-inline' 'unsafe-eval'; frame-src 'self' https://cdn.cohesionapps.com/ https://www.googletagmanager.com/; connect-src 'self' https://cdn.cookielaw.org/ https://www.google-analytics.com/ https://yg3l958nut-dsn.algolia.net https://www.google.com/ https://geolocation.onetrust.com/ https://bam.nr-data.net https://content.cmn.com https://api.mobius.highereducation.com https://www.googletagmanager.com/ https://cdn.cohesionapps.com/ https://www.edx.org/; img-src 'self' https://res.cloudinary.com https://navi.cohesionapps.com https://cms.psychology.org/ https://simple-storage-server.highereducation.com/ https://content.cmn.com data:; script-src-elem 'self' 'unsafe-inline' https://content.cmn.com/ https://js-agent.newrelic.com/ https://www.googletagmanager.com/ https://www.google-analytics.com/ https://sb.scorecardresearch.com https://www.edx.org/beam.js 6 default-src 'self'; connect-src 'self' https://region1.google-analytics.com https://connect.facebook.net https://pagead2.googlesyndication.com; https://region1.google-analytics.com https://connect.facebook.net https://pagead2.googlesyndication.com https://www.facebook.com; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com https://www.google-analytics.com https://consentcdn.cookiebot.com https://www.google.com https://www.gstatic.com https://connect.facebook.net https://cdn.jsdelivr.net; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://cdn.jsdelivr.net https://s1-staging-mundijuegos-com.s3.eu-west-1.amazonaws.com; https://cdnjs.cloudflare.com; frame-src 'self' 'unsafe-inline' https://www.google.com https://www.gstatic.com https://www.googletagmanager.com; font-src 'self' https://fonts.gstatic.com; img-src 'self' 'unsafe-inline' data: https://www.google-analytics.com https://connect.facebook.net https://cdn.jsdelivr.net; object-src 'none'; base-uri 'self'; frame-ancestors 'self'; 6 default-src 'self' fonts.gstatic.com; style-src-elem 'self' 'unsafe-inline' fonts.googleapis.com ctrack.trafficjunky.net geo-tracker.smadex.com 'self' https://newassets.hcaptcha.com;style-src 'self' 'unsafe-inline' fonts.googleapis.com;script-src 'self' 'unsafe-inline' *.trustpilot.com *.googletagmanager.com mc.yandex.ru *.google-analytics.com *.youtube.com mc.yandex.com mc.yandex.ru *.google.com *.gstatic.com *.mightytips.com my.rtmark.net *.hybrid.ai https://*.g.doubleclick.net ctrack.trafficjunky.net geo-tracker.smadex.com;img-src * data:;font-src 'self' fonts.gstatic.com;connect-src 'self' *.customer.io *.gist.build *.youtube.com mc.yandex.ru *.clariti.ws *.analytics.google.com *.google-analytics.com doubleclick.net *.googletagmanager.com mc.yandex.com mc.yandex.ru mc.yandex.md yandexmetrica.com *.mightytips.com https://*.g.doubleclick.net ctrack.trafficjunky.net geo-tracker.smadex.com https://analytics.google.com;frame-src 'self' *.trustpilot.com *.youtube.com *.instagram.com *.twitter.com *.yandex.com *.google.com my.rtmark.net *.hybrid.ai https://*.g.doubleclick.net ctrack.trafficjunky.net geo-tracker.smadex.com 'self' https://newassets.hcaptcha.com;script-src-elem 'self' 'unsafe-inline' *.trustpilot.com *.customer.io *.gist.build *.instagram.com *.googletagmanager.com *.yandex.ru *.google-analytics.com *.twitter.com *.youtube.com mc.yandex.com *.google.com *.gstatic.com mc.yandex.ru *.mightytips.com my.rtmark.net *.hybrid.ai https://*.g.doubleclick.net ctrack.trafficjunky.net geo-tracker.smadex.com track.trackingtraffo.com https://www.hcaptcha.com/1/api.js;frame-ancestors 'self';report-uri /cspreport.php 6 img-src https: blob: data:; script-src 'self' 'unsafe-eval' 'unsafe-inline' https://*.fcl.cloud https://*.flightcentre.com https://*.flightcentre.com.au https://*.flightcentre.co.nz https://*.flightcentre.co.za https://*.flightcentre.ca https://*.flightcentre.co.uk https://www.googletagmanager.com https://*.google-analytics.com https://www.youtube.com https://*.fullstory.com https://vxml4.plavxml.com https://*.nr-data.net https://*.usabilla.com http://*.usabilla.com https://*.newrelic.com https://d6tizftlrpuof.cloudfront.net https://cdnjs.cloudflare.com https://cdn.optimizely.com https://*.outbrain.com https://analytics.tiktok.com https://bat.bing.com https://cdn.abrankings.com https://connect.facebook.net https://edge.fullstory.com https://loader.wisepops.com https://wisepops.net https://s.pinimg.com https://snap.licdn.com https://googleads.g.doubleclick.net https://accounts.google.com https://*.pinterest.com https://*.evergage.com https://js.adsrvr.org https://static.criteo.net https://flightcentre-webchat.gotbot.co.za https://7226714.collect.igodigital.com https://cdn.pdst.fm https://*.hotjar.com https://tr.snapchat.com https://*.feefo.com https://koi-3qn5erhpry.marketingautomation.services https://cdn.jsdelivr.net https://*.stackla.com https://cdn.cookielaw.org https://sc-static.net https://developer.livehelpnow.net https://cdn.evgnet.com https://maps.googleapis.com https://sdk.joinsherpa.io https://cdn.wisepops.com https://*.quantserve.com https://*.livechatinc.com https://flightcentre.r-cubed.co.uk https://rules.quantcount.com https://*.criteo.com https://code.jquery.com https://*.creativecdn.com https://*.rokt.com https://*.mypurecloud.com.au https://s.yimg.com https://sp.analytics.yahoo.com *.feroot.com https://*.taboola.com https://*.redditstatic.com https://*.reddit.com; style-src 'unsafe-inline' 'self' https://fonts.googleapis.com https://register.feefo.com https://cdn.cookielaw.org https://d6tizftlrpuof.cloudfront.net; connect-src https://*.fcl.cloud wss://*.fcl.cloud https://*.flightcentre.com https://*.flightcentre.com.au https://*.flightcentre.co.nz https://*.flightcentre.co.za https://*.flightcentre.ca https://*.flightcentre.co.uk https://*.fclmedia.com https://fcl-sydney-geo-7.ent.ap-southeast-2.aws.found.io https://flowise-dev.dse.fctg.global https://*.launchdarkly.com https://*.optimizely.com *.nr-data.net https://*.fullstory.com https://*.google-analytics.com https://*.google.com https://*.google.com.au https://*.google.ca https://*.google.co.nz https://*.google.co.za https://*.google.co.uk https://*.evergage.com https://analytics.tiktok.com https://analytics-ipv6.tiktokw.us https://analytics.pangle-ads.com https://*.pinterest.com https://*.linkedin.com https://*.outbrain.com https://*.g.doubleclick.net https://wisepops.net https://*.wisepops.com https://*.feefo.com https://cdn.cookielaw.org https://developer.livehelpnow.net https://*.snapchat.com https://www.facebook.com https://bat.bing.com https://bat.bing.net https://*.onetrust.com https://flightcentre.r-cubed.co.uk https://adservice.google.com https://www.google.com https://analytics.google.com https://www.googleadservices.com https://*.browser-intake-datadoghq.com https://*.criteo.com https://*.usabilla.com https://*.creativecdn.com https://*.mypurecloud.com.au wss://*.mypurecloud.com.au https://*.salesforce.com https://d1nojfewl3tku3.cloudfront.net/assets https://maps.googleapis.com https://s.yimg.com *.feroot.com https://insight.adsrvr.org https://*.taboola.com https://*.reddit.com; default-src https: blob: 'unsafe-inline' 'unsafe-eval' wss://*.flightcentre.com.au:*; font-src https: blob: data:; frame-ancestors 'self'; report-uri /api/csp_report 6 default-src * data: blob: 'unsafe-inline' 'unsafe-eval'; script-src * data: blob: 'unsafe-inline' 'unsafe-eval'; style-src * data: blob: 'unsafe-inline'; img-src * data: blob: 'unsafe-inline'; connect-src * data: blob: 'unsafe-inline'; frame-src * data: blob: 'unsafe-inline'; font-src * data: blob: 'unsafe-inline'; media-src * data: blob: 'unsafe-inline'; object-src * data: blob: 'unsafe-inline'; 6 font-src fonts.gstatic.com use.typekit.net *.googleapis.com *.gstatic.com data: *.vimeo.com *.afip.gob.ar *.google.com *.doubleclick.net *.cloudfront.net *.getblue.io *.mercadopago.com.ar *.mercadopago.com.uy *.mercadopago.com.co *.mercadopago.com.pe *.mercadopago.cl *.zdassets.com https://www.google.com.ar https://analytics.tiktok.com https://www.google.com https://track-icommkt.com https://scripts.icommkt.online https://bam.nr-data.net https://event.getblue.io/ https://static-content-qas.vnforapps.com/ https://static-content.vnforapps.com/ *.google-analytics.com analytics.google.com https://www.googletagmanager.com https://externalassets.icommarketing.com https://www.prunenews.com https://www.clarity.ms *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * webpay3g.transbank.cl webpay3gint.transbank.cl *.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com www.google.com *.vimeo.com *.afip.gob.ar *.google.com *.doubleclick.net *.cloudfront.net *.getblue.io *.mercadopago.com.ar *.mercadopago.com.uy *.mercadopago.com.co *.mercadopago.com.pe *.mercadopago.cl *.zdassets.com https://www.google.com.ar https://analytics.tiktok.com https://www.google.com https://track-icommkt.com https://scripts.icommkt.online https://bam.nr-data.net https://event.getblue.io/ https://apitestenv.vnforapps.com/ https://apiprod.vnforapps.com/ https://static-content-qas.vnforapps.com/ https://static-content.vnforapps.com/ *.google-analytics.com analytics.google.com https://www.googletagmanager.com https://externalassets.icommarketing.com https://www.prunenews.com https://www.clarity.ms *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * https://live.decidir.com *.weltpixel.com *.googletagmanager.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net *.gstatic.com *.googleapis.com *.vimeo.com *.afip.gob.ar *.google.com *.doubleclick.net *.cloudfront.net *.getblue.io *.mercadopago.com.ar *.mercadopago.com.uy *.mercadopago.com.co *.mercadopago.com.pe *.mercadopago.cl *.zdassets.com https://www.google.com.ar https://analytics.tiktok.com https://www.google.com https://track-icommkt.com https://scripts.icommkt.online https://bam.nr-data.net https://event.getblue.io/ https://static-content-qas.vnforapps.com/ https://static-content.vnforapps.com/ *.google-analytics.com https://www.googletagmanager.com https://externalassets.icommarketing.com https://www.prunenews.com https://www.clarity.ms *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.facebook.com *.reddit.com *.ads-twitter.com t.co *.twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.googletagmanager.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net amcglobal.sc.omtrdc.net *.adobe.io use.typekit.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com *.magento-ds.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.vimeo.com *.afip.gob.ar *.google.com *.doubleclick.net *.cloudfront.net *.getblue.io *.mercadopago.com.ar *.mercadopago.com.uy *.mercadopago.com.co *.mercadopago.com.pe *.mercadopago.cl *.zdassets.com https://www.google.com.ar https://analytics.tiktok.com https://www.google.com https://track-icommkt.com https://scripts.icommkt.online https://bam.nr-data.net https://event.getblue.io/ https://apitestenv.vnforapps.com/ https://apiprod.vnforapps.com/ https://static-content-qas.vnforapps.com/ https://static-content.vnforapps.com/ *.google-analytics.com https://www.googletagmanager.com https://externalassets.icommarketing.com https://www.prunenews.com https://www.clarity.ms *.avada.io *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://live.decidir.com https://developers.decidir.com/ *.googletagmanager.com *.googleadservices.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.bing.com *.clarity.ms *.klaviyo.com unpkg.com https://merchants.playdigital.com.ar/ https://merchants.preprod.playdigital.com.ar/ https://ecommerce-modal.modo.com.ar/ https://ecommerce-modal.preprod.modo.com.ar/ 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com *.fontawesome.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com unsafe-inline assets.braintreegateway.com *.tagmanager.google.com *.googletagmanager.com https://ecommerce-modal.modo.com.ar/ https://ecommerce-modal.preprod.modo.com.ar/ 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io *.magento-datasolutions.com *.magento-ds.com *.sentry.io *.googleapis.com *.vimeo.com *.afip.gob.ar *.google.com *.doubleclick.net *.cloudfront.net *.getblue.io *.mercadopago.com.ar *.mercadopago.com.uy *.mercadopago.com.co *.mercadopago.com.pe *.mercadopago.cl *.zdassets.com https://www.google.com.ar https://analytics.tiktok.com https://www.google.com https://track-icommkt.com https://scripts.icommkt.online https://bam.nr-data.net https://event.getblue.io/ https://apitestenv.vnforapps.com/ https://apiprod.vnforapps.com/ https://static-content-qas.vnforapps.com/ https://static-content.vnforapps.com/ *.google-analytics.com https://www.googletagmanager.com https://externalassets.icommarketing.com https://www.prunenews.com https://www.clarity.ms https://get.geojs.io *.avada.io *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com google.com https://live.decidir.com https://developers.decidir.com/ *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.run.app https://merchants.playdigital.com.ar/ https://merchants.preprod.playdigital.com.ar/ https://ecommerce-modal.modo.com.ar/ https://ecommerce-modal.preprod.modo.com.ar/ 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 6 default-src 'self' https:; script-src 'self' https: blob: 'unsafe-inline' 'unsafe-eval'; style-src 'self' https: 'unsafe-inline'; img-src 'self' https: data:; frame-src https:; frame-ancestors 'self'; font-src 'self' https: data:; report-uri /report-csp-violation 6 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com *.googleapis.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com geowidget.easypack24.net https://widgets.trustedshops.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.paypal.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.sharethis.com accounts.google.com *.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com secure.payu.com merch-prod.snd.payu.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.doubleclick.net vars.hotjar.com m.goadservices.com apis.google.com www.google.com *.cookiebot.com ams.creativecdn.com ct.pinterest.com googletagmanager.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com *.sharethis.com *.salesmanago.pl *.salesmanago.es *.salesmanago.com data.imoje.pl https://firebasestorage.googleapis.com connect.facebook.net graph.facebook.com business.facebook.com static.payu.com trustmate.io www.google.pl csr.onet.pl bbnaut.ibillboard.com rm.em.nscontext.eu mc.yandex.ru rtb-csync.smartadserver.com *.tile.openstreetmap.org geowidget.easypack24.net maps.gstatic.com maps.googleapis.com *.doubleclick.net kodano.pl ade.googlesyndication.com bat.bing.com qon-csts3.quartic.com.pl c.seznam.cz payment.ecommerce.sebgroup.com imgsct.cookiebot.com *.facebook.net pixel.wp.pl *.pinimg.com *.pinterest.com *.bing.com simage2.pubmatic.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.sharethis.com *.salesmanago.pl *.salesmanago.es *.salesmanago.com paywall.imoje.pl sandbox.paywall.imoje.pl accounts.google.com *.fontawesome.com *.googleapis.com *.gstatic.com *.avada.io www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com secure.payu.com secure.snd.payu.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com trustmate.io *.hotjar.com mc.yandex.ru *.goadservices.com geowidget.easypack24.net maps.googleapis.com *.pushpushgo.com apis.google.com js-agent.newrelic.com *.cookiebot.com bat.bing.com *.tiktok.com *.smartsuppcdn.com www.smartsuppchat.com *.crazyegg.com bam.eu01.nr-data.net static.cloudflareinsights.com *.quarticon.it *.quarticon.com *.quartic.com.pl *.ar-labs.io tags.creativecdn.com c.imedia.cz c.seznam.cz *.pinimg.com *.facebook.net pixel.wp.pl *.pinterest.com nominatim.openstreetmap.org https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com https://accounts.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.sharethis.com *.fontawesome.com accounts.google.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.stripe.network *.stripecdn.com *.amazon.com trustmate.io geowidget.easypack24.net *.quartic.com.pl widget-v3.smartsuppcdn.com www.googletagmanager.com https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.sharethis.com *.salesmanago.pl *.salesmanago.es *.salesmanago.com accounts.google.com https://get.geojs.io *.avada.io www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com secure.payu.com merch-prod.snd.payu.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com trustmate.io mc.yandex.ru *.doubleclick.net *.analytics.google.com api-shipx-pl.easypack24.net pagead2.googlesyndication.com maps.googleapis.com *.cookiebot.com *.tiktok.com *.smartsupp.com *.smartsuppcdn.com *.smartsuppchat.com *.crazyegg.com bam.eu01.nr-data.net *.quarticon.it *.ar-labs.io www.google.com ams.creativecdn.com *.pinimg.com *.facebook.net pixel.wp.pl *.pinterest.com *.bing.com nominatim.openstreetmap.org region1.google-analytics.com *.trustedshops.com *.etrusted.com https://integrations.etrusted.site 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.salesmanago.pl *.salesmanago.es *.salesmanago.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://szkla0com.report-uri.com/r/d/csp/reportOnly; report-to report-endpoint; 6 default-src 'self' https: data: blob: 'unsafe-inline' 'unsafe-eval'; img-src 'self' https: data: blob: 'unsafe-inline'; script-src 'self' https: 'unsafe-inline' 'unsafe-eval'; style-src 'self' https: data: 'unsafe-inline'; font-src 'self' https: data: https:; connect-src 'self' https: wss:; frame-src 'self' https: data: blob:; media-src 'self' https: data: blob:; object-src 'self' https: data: blob:; base-uri 'self' https:; form-action 'self' https:; frame-ancestors 'self' https:; worker-src 'self' https: data: blob:; report-uri /csp-report 6 default-src *; script-src * 'unsafe-inline' 'unsafe-eval'; script-src-elem * 'unsafe-inline' https://www.googletagmanager.com blob: data:; style-src * 'unsafe-inline'; style-src-elem * 'unsafe-inline'; font-src * data: moz-extension:; img-src * data: blob:; media-src * data: blob:; connect-src * properties: data:; frame-src *; worker-src * blob:; report-uri https://sentry-new.public.mybestpro.com/api/8/security/?sentry_key=54be949d75fc07530648e0a189a26f35&sentry_environment=prod 6 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.facebook.com platform.twitter.com *.trustpilot.com *.weltpixel.com www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://d1pna5l3xsntoj.cloudfront.net https://helloretailcdn.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ magefan.com cm.magefan.com https://firebasestorage.googleapis.com https://resources.paytrail.com www.facebook.com pinterest.com assets.pinterest.com syndication.twitter.com flagpedia.net maps.googleapis.com maps.gstatic.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://core.helloretail.com https://d1pna5l3xsntoj.cloudfront.net https://helloretailcdn.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://scripts.luigisbox.com https://cdn.luigisbox.com https://live.luigisbox.com https://api.luigisbox.com *.avada.io connect.facebook.net twitter.com platform.twitter.com cdn.jsdelivr.net *.gstatic.com maps.googleapis.com applepay.cdn-apple.com *.trustpilot.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://d1pna5l3xsntoj.cloudfront.net https://helloretailcdn.com https://static.klaviyo.com https://scripts.luigisbox.com https://cdn.luigisbox.com https://live.luigisbox.com https://api.luigisbox.com *.fontawesome.com https://fonts.bunny.net cdn.jsdelivr.net maxcdn.bootstrapcdn.com *.gstatic.com applepay.cdn-apple.com *.trustpilot.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://core.helloretail.com https://helloretailcdn.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://scripts.luigisbox.com https://cdn.luigisbox.com https://live.luigisbox.com https://api.luigisbox.com https://get.geojs.io *.avada.io www.gstatic.com maps.googleapis.com places.googleapis.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 6 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.klarnacdn.net *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * https://plumrocket.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors https://www.youtube.com/ 'self' 'unsafe-inline'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net https://www.youtube.com/ *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com https://widget.trustpilot.com/ *.weltpixel.com *.klarna.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * https://plumrocket.com https://www.usaskateshop.com/ *.googletagmanager.com *.doubleclick.net *.typeform.com www.xtento.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com *.klarna.com *.klarnaevt.com *.klarnacdn.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com magefan.com cm.magefan.com maps.gstatic.com maps.googleapis.com https://usaskateshop-com.b-cdn.net/ *.facebook.com *.reddit.com *.googletagmanager.com *.doubleclick.net *.google.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com chimpstatic.com downloads.mailchimp.com *.list-manage.com https://static.hotjar.com https://static.zdassets.com https://payments.worldpay.com https://cdn.clerk.io https://api.clerk.io https://ss.euroskateshop.de https://ss.euroskateshop.nl https://ss.euroskateshop.ch *.klarna.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com applepay.cdn-apple.com maps.googleapis.com *.googletagmanager.com *.googleadservices.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com unpkg.com *.doubleclick.net *.typeform.com www.xtento.com cdn.xtento.com https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com downloads.mailchimp.com *.klarnacdn.net assets.braintreegateway.com *.fontawesome.com applepay.cdn-apple.com *.tagmanager.google.com *.googletagmanager.com *.typeform.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com https://cdn.usaskateshop.dk https://static.zdassets.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.klarnaevt.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.klarna.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com maps.googleapis.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.doubleclick.net *.run.app *.typeform.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 6 base-uri 'self'; form-action 'self'; frame-ancestors 'self'; object-src 'none'; report-uri /csp-report; script-src 'self' 'unsafe-inline' 'unsafe-eval' blob: data: ivi.ru *.ivi.ru ivi.tv *.ivi.tv turkdizi.com *.turkdizi.com turk.ivi.tv s3.pub.ivi.ru *.dfs.ivi.ru google.com *.google.com gstatic.com *.gstatic.com googletagmanager.com *.googletagmanager.com *.googleapis.com googlesyndication.com *.googlesyndication.com google-analytics.com *.google-analytics.com doubleclick.net *.doubleclick.net cm.g.doubleclick.net *.googleadservices.com www.googlecommerce.com yandex.ru *.yandex.ru yandex.net *.yandex.net yandex.st *.yandex.st yastat.net *.yastat.net yastatic.net *.yastatic.net yandex.com *.yandex.com yandexcloud.net *.yandexcloud.net yandex.by *.yandex.by yandex.kz *.yandex.kz impression.appmetrica.yandex.com mail.ru *.mail.ru tns-counter.ru *.tns-counter.ru doubleverify.com *.doubleverify.com s0.2mdn.net adriver.ru *.adriver.ru statad.ru *.statad.ru targetads.io *.targetads.io flocktory.com *.flocktory.com getshop.tv *.getshop.tv *.clarity.ms *.hotjar.com adfox.ru *.adfox.ru adsafeprotected.com *.adsafeprotected.com 5visions.com *.5visions.com adjust.com *.adjust.com ozon.ru *.ozon.ru bridgertb.tech *.bridgertb.tech serving-sys.ru *.serving-sys.ru cmediahub.ru *.cmediahub.ru weborama-tech.ru *.weborama-tech.ru digitaltarget.ru *.digitaltarget.ru mhverifier.ru *.mhverifier.ru adlooxtracking.ru *.adlooxtracking.ru adlooxtracking.com *.adlooxtracking.com telecid.ru *.telecid.ru tele2.ru *.tele2.ru telecomid.ru *.telecomid.ru teletarget.ru *.teletarget.ru cdnvideo.ru *.cdnvideo.ru beeline.ru *.beeline.ru moe.video *.moe.video otm-r.com *.otm-r.com punchmedia.ru *.punchmedia.ru skwstat.ru *.skwstat.ru stbid.ru *.stbid.ru videonow.ru *.videonow.ru utraff.com *.utraff.com acint.net *.acint.net betweendigital.com *.betweendigital.com betweendigital.ads.com lentainform.com *.lentainform.com code.moviead55.ru moviead55.ru cs-0.moevideo.biz moevideo.biz buzzoola.com *.buzzoola.com uma.media *.uma.media appsflyer.com *.appsflyer.com instreamvideo.ru *.instreamvideo.ru mobilebanner.ru *.mobilebanner.ru admetrica.ru *.admetrica.ru prodmp.ru *.prodmp.ru sync.adspend.space reichelcormier.bid *.reichelcormier.bid secure.adnxs.com adnxs.com ohmy.bid *.ohmy.bid ssl.hurra.com hurra.com bidvol.com *.bidvol.com adstreamer.ru *.adstreamer.ru adkernel.com *.adkernel.com sync.dmp.otm-r.com republer.com sync.republer.com sync.viadata.store viadata.store sync.viavideo.digital viavideo.digital wi-fi.ru *.wi-fi.ru tms.dmp.wi-fi.ru track.rutarget.ru rutarget.ru impressions.onelink.me onelink.me px170.mediahills.ru mediahills.ru mts.ru *.mts.ru sa.rtb.mts.ru digital-alliance.tech *.digital-alliance.tech admon.pro *.admon.pro adhight.net *.adhight.net getads.ru *.getads.ru vk.com *.vk.com connect.facebook.net facebook.com *.facebook.com *.skcrtxr.com api.mindbox.ru simbad.pro taglitics.com creatives.afp.ai cdn.al-adtech.com cdn.jsdelivr.net *.criteo.com image.sendsay.ru snap.licdn.com dap.digitalgov.gov bat.bing.com www.artfut.com cdn.cookielaw.org static.ads-twitter.com s.pinimg.com cdn-cookieyes.com cdn.taboola.com www.redditstatic.com; script-src-elem 'self' 'unsafe-inline' 'unsafe-eval' blob: data: ivi.ru *.ivi.ru ivi.tv *.ivi.tv turkdizi.com *.turkdizi.com turk.ivi.tv s3.pub.ivi.ru *.dfs.ivi.ru google.com *.google.com gstatic.com *.gstatic.com googletagmanager.com *.googletagmanager.com *.googleapis.com googlesyndication.com *.googlesyndication.com google-analytics.com *.google-analytics.com doubleclick.net *.doubleclick.net cm.g.doubleclick.net *.googleadservices.com www.googlecommerce.com yandex.ru *.yandex.ru yandex.net *.yandex.net yandex.st *.yandex.st yastat.net *.yastat.net yastatic.net *.yastatic.net yandex.com *.yandex.com yandexcloud.net *.yandexcloud.net yandex.by *.yandex.by yandex.kz *.yandex.kz impression.appmetrica.yandex.com mail.ru *.mail.ru tns-counter.ru *.tns-counter.ru doubleverify.com *.doubleverify.com s0.2mdn.net adriver.ru *.adriver.ru statad.ru *.statad.ru targetads.io *.targetads.io flocktory.com *.flocktory.com getshop.tv *.getshop.tv *.clarity.ms *.hotjar.com adfox.ru *.adfox.ru adsafeprotected.com *.adsafeprotected.com 5visions.com *.5visions.com adjust.com *.adjust.com ozon.ru *.ozon.ru bridgertb.tech *.bridgertb.tech serving-sys.ru *.serving-sys.ru cmediahub.ru *.cmediahub.ru weborama-tech.ru *.weborama-tech.ru digitaltarget.ru *.digitaltarget.ru mhverifier.ru *.mhverifier.ru adlooxtracking.ru *.adlooxtracking.ru adlooxtracking.com *.adlooxtracking.com telecid.ru *.telecid.ru tele2.ru *.tele2.ru telecomid.ru *.telecomid.ru teletarget.ru *.teletarget.ru cdnvideo.ru *.cdnvideo.ru beeline.ru *.beeline.ru moe.video *.moe.video otm-r.com *.otm-r.com punchmedia.ru *.punchmedia.ru skwstat.ru *.skwstat.ru stbid.ru *.stbid.ru videonow.ru *.videonow.ru utraff.com *.utraff.com acint.net *.acint.net betweendigital.com *.betweendigital.com betweendigital.ads.com lentainform.com *.lentainform.com code.moviead55.ru moviead55.ru cs-0.moevideo.biz moevideo.biz buzzoola.com *.buzzoola.com uma.media *.uma.media appsflyer.com *.appsflyer.com instreamvideo.ru *.instreamvideo.ru mobilebanner.ru *.mobilebanner.ru admetrica.ru *.admetrica.ru prodmp.ru *.prodmp.ru sync.adspend.space reichelcormier.bid *.reichelcormier.bid secure.adnxs.com adnxs.com ohmy.bid *.ohmy.bid ssl.hurra.com hurra.com bidvol.com *.bidvol.com adstreamer.ru *.adstreamer.ru adkernel.com *.adkernel.com sync.dmp.otm-r.com republer.com sync.republer.com sync.viadata.store viadata.store sync.viavideo.digital viavideo.digital wi-fi.ru *.wi-fi.ru tms.dmp.wi-fi.ru track.rutarget.ru rutarget.ru impressions.onelink.me onelink.me px170.mediahills.ru mediahills.ru mts.ru *.mts.ru sa.rtb.mts.ru digital-alliance.tech *.digital-alliance.tech admon.pro *.admon.pro adhight.net *.adhight.net getads.ru *.getads.ru vk.com *.vk.com connect.facebook.net facebook.com *.facebook.com *.skcrtxr.com api.mindbox.ru simbad.pro taglitics.com creatives.afp.ai cdn.al-adtech.com cdn.jsdelivr.net *.criteo.com image.sendsay.ru snap.licdn.com dap.digitalgov.gov bat.bing.com www.artfut.com cdn.cookielaw.org static.ads-twitter.com s.pinimg.com cdn-cookieyes.com cdn.taboola.com www.redditstatic.com *.ahrefs.com *.alicdn.com *.tiktok.com *.amazonaws.com *.cloudflare.com cdn.amplitude.com cdn.segment.com cdn.branch.io app.usercentrics.eu app.termly.io cdn.walkme.com s.go-mpulse.net cdn.moengage.com cdn.omniconvert.com siteimproveanalytics.com edge.fullstory.com cdn.rutarget.ru sb.scorecardresearch.com secure.quantserve.com c.amazon-adsystem.com cdn.mxpnl.com cdn.userway.org kp.apiget.ru static.pro-bm7.ru rus.glbbars.com api.cpatext.ru widgets.101apis.com images.uc.cn cdn.browsiprod.com unpkg.zhimg.com s.yimg.jp 5 frame-ancestors 'self'; object-src 'none'; report-uri /api/csp-reporting 5 default-src https:; script-src https: 'unsafe-eval' 'unsafe-inline'; style-src https: 'unsafe-inline'; img-src https: data:; font-src https: data: 5 frame-ancestors 'self'; 5 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' blob: https://*.everbridge.com https://*.everbridge.net https://*.site.com https://*.salesforce-sites.com https://*.force.com https://*.salesforce.com https://*.salesforceliveagent.com https://*.marketo.com https://*.marketo.net https://*.mktoresp.com https://*.mktoutil.com https://*.ziftsolutions.com https://*.ziftmarcom.com https://*.ziftone.com https://*.goconsensus.com https://*.metadata.io https://cdn.metadata.io https://*.folloze.com https://cdn.jsdelivr.net https://unpkg.com https://js.driftt.com https://*.driftt.com https://*.6sense.com https://*.6sc.co https://*.google.com https://*.googleapis.com https://*.gstatic.com https://www.googletagmanager.com https://tagmanager.google.com https://*.hotjar.com https://*.hotjar.io https://*.g2.com https://*.g2crowd.com https://*.linkedin.com https://snap.licdn.com https://analytics.twitter.com https://static.ads-twitter.com https://connect.facebook.net https://www.facebook.com https://*.facebook.com https://*.doubleclick.net https://*.clarity.ms https://*.adsrvr.org https://script.googleusercontent.com https://bat.bing.com https://c.bing.com https://cdn.linkedin.oribi.io https://api.ipify.org https://*.qualified.com; script-src-elem 'self' 'unsafe-inline' blob: https://*.everbridge.com https://*.everbridge.net https://*.site.com https://*.salesforce-sites.com https://*.force.com https://*.salesforce.com https://*.salesforceliveagent.com https://*.marketo.com https://*.marketo.net https://*.mktoresp.com https://*.mktoutil.com https://*.ziftsolutions.com https://*.ziftmarcom.com https://*.ziftone.com https://*.goconsensus.com https://*.metadata.io https://cdn.metadata.io https://*.folloze.com https://cdn.jsdelivr.net https://unpkg.com https://js.driftt.com https://*.driftt.com https://*.6sense.com https://*.6sc.co https://*.google.com https://*.googleapis.com https://*.gstatic.com https://www.googletagmanager.com https://tagmanager.google.com https://*.hotjar.com https://*.hotjar.io https://*.g2.com https://*.g2crowd.com https://*.linkedin.com https://snap.licdn.com https://analytics.twitter.com https://static.ads-twitter.com https://connect.facebook.net https://www.facebook.com https://*.facebook.com https://*.doubleclick.net https://*.clarity.ms https://*.adsrvr.org https://script.googleusercontent.com https://bat.bing.com https://c.bing.com https://cdn.linkedin.oribi.io https://api.ipify.org https://*.onetrust.com https://cdn.cookielaw.org https://cdn-uk.onetrust.com https://cdn-ap.onetrust.com https://cdn-us.onetrust.com https://*.qualified.com; style-src 'self' 'unsafe-inline' https://*.everbridge.com https://*.site.com https://*.force.com https://*.salesforce-sites.com https://fonts.googleapis.com https://translate.googleapis.com https://*.google.com https://*.googleapis.com https://*.gstatic.com https://www.googletagmanager.com https://tagmanager.google.com https://static.addtoany.com https://*.marketo.com https://*.ziftsolutions.com https://*.folloze.com https://cdn.jsdelivr.net; img-src 'self' data: blob: https://*.everbridge.com https://*.everbridge.net https://*.g2crowd.com https://*.site.com https://*.salesforce-sites.com https://*.force.com https://*.salesforce.com https://*.adsymptotic.com https://bestinenterpriseresilience.com https://*.bestinenterpriseresilience.com https://secure.adnxs.com https://*.cookiebot.com https://*.addtoany.com https://*.google.com https://*.googleapis.com https://*.gstatic.com https://*.hotjar.com https://*.hotjar.io https://*.g2.com https://*.linkedin.com https://snap.licdn.com https://*.marketo.net https://*.marketwire.com https://*.marketo.com https://*.mktoresp.com https://*.mktoutil.com https://analytics.twitter.com https://static.ads-twitter.com https://*.driftt.com https://*.6sense.com https://*.6sc.co https://connect.facebook.net https://www.facebook.com https://*.facebook.com https://*.doubleclick.net https://*.clarity.ms https://www.comparably.com https://*.itcentralstation.com https://www.peerspot.com https://cdn.amcharts.com https://*.gravatar.com https://*.cdninstagram.com https://*.instagram.com https://player.simplecast.com https://*.vimeo.com https://vpn.seminolecountyfl.gov/ https://*.youtube.com https://*.ytimg.com https://*.zoominfo.com https://t.co/i/adsct https://folloze-optimized.s3.amazonaws.com https://bat.bing.com https://c.bing.com https://www.google.co.in https://cdn.cookielaw.org https://www.googletagmanager.com https://www.google.ca; connect-src 'self' https://*.everbridge.com https://*.everbridge.net https://*.site.com https://*.salesforce-sites.com https://*.force.com https://*.salesforce.com https://*.salesforceliveagent.com https://*.marketo.com https://*.marketo.net https://*.mktoresp.com https://*.mktoutil.com https://*.ziftsolutions.com https://*.ziftmarcom.com https://*.ziftone.com https://*.goconsensus.com https://*.metadata.io https://cdn.metadata.io https://*.folloze.com https://js.driftt.com https://*.driftt.com https://*.6sense.com https://*.6sc.co https://*.google.com https://*.googleapis.com https://*.gstatic.com https://www.googletagmanager.com https://tagmanager.google.com https://*.hotjar.com https://*.hotjar.io https://*.g2.com https://*.g2crowd.com https://*.linkedin.com https://snap.licdn.com https://analytics.twitter.com https://static.ads-twitter.com https://connect.facebook.net https://www.facebook.com https://*.facebook.com https://*.doubleclick.net https://*.clarity.ms https://*.adsrvr.org https://script.googleusercontent.com https://bat.bing.com https://c.bing.com https://cdn.linkedin.oribi.io https://api.ipify.org https://*.onetrust.com https://cdn.cookielaw.org wss://*.qualified.com https://*.qualified.com https://www.google-analytics.com https://www.google.co.in; font-src 'self' data: https://fonts.gstatic.com https://fonts.googleapis.com https://cdnjs.cloudflare.com; media-src 'self' https://js.driftt.com https://*.vimeo.com https://*.youtube.com https://*.ytimg.com https://player.simplecast.com https://app.qualified.com; frame-src 'self' https://*.everbridge.com https://*.everbridge.net https://*.site.com https://*.salesforce-sites.com https://*.force.com https://*.salesforce.com https://www.googletagmanager.com https://tagmanager.google.com https://*.youtube.com https://*.vimeo.com https://*.marketo.com https://app.qualified.com https://www.google.com https://www.facebook.com; 5 default-src 'self' *; media-src 'self' * data: ; font-src 'self' * data: ; img-src 'self' data: blob: *; script-src * 'unsafe-inline' 'unsafe-eval' data: *; style-src 'self' 'unsafe-inline' *; worker-src 'self' * blob: ; report-uri /api/csp-violation 5 default-src * data: mediastream: blob: filesystem: about: ws: wss: 'unsafe-eval' 'wasm-unsafe-eval' 'unsafe-inline' 5 default-src 'self'; base-uri 'self'; object-src 'none'; frame-ancestors 'self'; form-action 'self'; img-src 'self' https://www.google-analytics.com data: blob:; script-src 'self' https://www.googletagmanager.com https://www.google-analytics.com https://www.google.com https://www.gstatic.com; style-src 'self' https://fonts.googleapis.com 'unsafe-inline'; font-src 'self' https://fonts.gstatic.com data:; connect-src 'self' https://www.google-analytics.com https://www.googletagmanager.com https://www.google.com https://www.gstatic.com; frame-src 'self' https://www.google.com; worker-src 'self' blob:; media-src 'self'; upgrade-insecure-requests 5 font-src *.fontawesome.com https://fonts.gstatic.com https://www.google.com https://www.gstatic.com fonts.gstatic.com fonts.googleapis.com data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net secure.authorize.net test.authorize.net www.googletagmanager.com www.google.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.vimeocdn.com s.ytimg.com bam.eu01.nr-data.net 'self' 'unsafe-inline'; script-src assets.adobedtm.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com s.ytimg.com video.google.com vimeo.com www.vimeo.com www.googletagmanager.com www.youtube.com maps.googleapis.com https://cdn.polyfill.io https://browser.sentry-cdn.com *.googleapis.com *.google.com *.gstatic.com *.avada.io www.google.com/recaptcha/ www.gstatic.com/recaptcha/ js-agent.newrelic.com bam.eu01.nr-data.net connect.facebook.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src getfirebug.com *.fontawesome.com *.googleapis.com *.google.com *.gstatic.com fonts.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net https://*.ingest.sentry.io http://dpm.demdex.net https://www.google.com https://www.gstatic.com https://get.geojs.io *.avada.io bam.eu01.nr-data.net region1.google-analytics.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 5 script-src 'self' https://static.hotjar.com https://script.hotjar.com https://www.googletagmanager.com https://www.google-analytics.com https://maps.googleapis.com; report-uri /csp-report; 5 default-src https: data:; script-src https: data: 'unsafe-inline' 'unsafe-eval'; style-src https: data: 'unsafe-inline'; frame-ancestors 'self'; report-uri https://stoklasa.report-uri.io/r/default/csp/reportOnly 5 default-src 'self' fonts.gstatic.com; style-src-elem 'self' 'unsafe-inline' fonts.googleapis.com ctrack.trafficjunky.net geo-tracker.smadex.com 'self' https://newassets.hcaptcha.com;style-src 'self' 'unsafe-inline' fonts.googleapis.com;script-src 'self' 'unsafe-inline' *.googletagmanager.com mc.yandex.ru *.google-analytics.com *.youtube.com mc.yandex.com mc.yandex.ru *.google.com *.gstatic.com *.mightytips.com my.rtmark.net *.hybrid.ai https://*.g.doubleclick.net ctrack.trafficjunky.net geo-tracker.smadex.com;img-src * data:;font-src 'self' fonts.gstatic.com;connect-src 'self' *.customer.io *.youtube.com mc.yandex.ru *.clariti.ws *.analytics.google.com *.google-analytics.com doubleclick.net *.googletagmanager.com mc.yandex.com mc.yandex.ru mc.yandex.md yandexmetrica.com *.mightytips.com https://*.g.doubleclick.net ctrack.trafficjunky.net geo-tracker.smadex.com https://analytics.google.com;frame-src 'self' *.youtube.com *.instagram.com *.twitter.com *.yandex.com *.google.com my.rtmark.net *.hybrid.ai https://*.g.doubleclick.net ctrack.trafficjunky.net geo-tracker.smadex.com 'self' https://newassets.hcaptcha.com;script-src-elem 'self' 'unsafe-inline' *.instagram.com *.googletagmanager.com *.yandex.ru *.google-analytics.com *.twitter.com *.youtube.com mc.yandex.com *.google.com *.gstatic.com mc.yandex.ru *.mightytips.com my.rtmark.net *.hybrid.ai https://*.g.doubleclick.net ctrack.trafficjunky.net geo-tracker.smadex.com track.trackingtraffo.com https://www.hcaptcha.com/1/api.js;frame-ancestors 'self';report-uri /cspreport.php 5 script-src 'self'; object-src 'self'; report-to csp-endpoint; 5 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com cash-f.squarecdn.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com * *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com * *.pinterest.com *.sendcloud.sc *.jsdelivr.net c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net * *.trustedshops.com cdn.cookielaw.org res.cloudinary.com www.b2c-nfinity.com t.squeezely.tech cdn-icons-png.flaticon.com docker.creative-serving.com trkr.shoppingminds.net bam.nr-data.net *.googleapis.com *.etrusted.com *.pinterest.com bat.bing.com *.adyen.com *.facebook.com img.youtube.com a.tile.openstreetmap.org b.tile.openstreetmap.org c.tile.openstreetmap.org cdn.doofinder.com *.google.com *.google.co.uk *.google.ca b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com ts.tradetracker.net *.amazonaws.com blob: www.google.ge magefan.com cm.magefan.com *.disqus.com https://img.youtube.com www.sandbox.paypal.com www.magmodules.eu data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net amcglobal.sc.omtrdc.net *.adobe.io use.typekit.net *.commerce-payment-services.com *.magento-ds.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.magento-datasolutions.com *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com *.cash.app *.visa.com *.mastercard.com https://rum.hlx.page *.trustedshops.com squeezely.tech bat.bing.com *.etrusted.com *.kk-resources.com *.googleoptimize.com cdn.cookielaw.org l.getsitecontrol.com script.shoppingminds.com script.shoppingminds.net js-agent.newrelic.com bam.nr-data.net static.hotjar.com script.hotjar.com s2.getsitecontrol.com *.pinterest.com s.pinimg.com analytics.topdrinks.nl analytics.topdrinks.fr analytics.topdrinks.dk analytics.topdrinks.de analytics.topdrinks.at analytics.topdrinks.be unpkg.com cdn.jsdelivr.net commerce.adobe.net *.googletagmanager.com cdn.doofinder.com analytics.tiktok.com *.google.co.uk *.google.ca s7.addthis.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com songbirdstag.cardinalcommerce.com tm.tradetracker.net *.trustpilot.com *.sendcloud.sc *.jsdelivr.net https://connect.facebook.net *.google.fr *.disqus.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com *.cash.app *.etrusted.com *.pinterest.com *.sendcloud.sc *.jsdelivr.net *.fontawesome.com assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.youtube.com youtu.be www.youtube-nocookie.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net *.sentry.io www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.magento-datasolutions.com *.magento-ds.com * *.google.lk analytics.topdrinks.nl ws.hotjar.com wss://ws.hotjar.com content.hotjar.io analytics.topdrinks.fr analytics.topdrinks.dk analytics.topdrinks.de analytics.topdrinks.at analytics.topdrinks.be cdn.cookielaw.org geolocation.onetrust.com *.g.doubleclick.net l.getsitecontrol.com *.shoppingminds.net *.googleapis.com bam.nr-data.net cdn1.api.trustedshops.com pay.google.com privacyportal-de.onetrust.com vc.hotjar.io events.getsitectrl.com *.etrusted.com *.pinterest.com *.adyen.com maps.googleapis.com nominatim.openstreetmap.org *.onyourmap.com *.mapbox.com *.doofinder.com wss://*.doofinder.com analytics.tiktok.com ekr.zdassets.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.google-analytics.com *.sendcloud.sc *.cdn.jsdelivr.net https://analytics.tiktok.com *.google.fr *.google.co.uk *.google.ca 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 5 default-src 'self' data: wss://enu3cdg6tvghrjuahpbe6c6w5i.appsync-api.eu-west-1.amazonaws.com/graphql wss://enu3cdg6tvghrjuahpbe6c6w5i.appsync-realtime-api.eu-west-1.amazonaws.com/graphql s3.eu-west-1.amazonaws.com/uploads.knowbe4.eu/ api-js.mixpanel.com app.pendo.io btb-glossary-bucket-production-us-east-1.s3.amazonaws.com https://browser-intake-datadoghq.com/ cdn.pendo.io data.pendo.io deepfake-content-write-production-eu-west-1.s3.eu-west-1.amazonaws.com deepfake-content-read-production-eu-west-1.s3.eu-west-1.amazonaws.com fonts.googleapis.com metrics.articulate.com modstore.knowbe4.com modstore-production-us-east-1.s3.amazonaws.com https://*.knowbe4.com https://*.kb4od.run https://*.ckeditor.com/ https://*.launchdarkly.com/ https://*.zopim.com/ https://api-js.mixpanel.com https://api.mixpanel.com/ https://cdnjs.cloudflare.com/ https://code.highcharts.com/ https://data.pendo.io/ https://ekr.zdassets.com/ https://ekr.zendesk.com/ https://knowbe4.zendesk.com/ https://knowbe4.zendesk.com/embeddable/config https://knowbe4.zendesk.com/embeddable_blip https://knowbe4.zendesk.com/frontendevents/dl https://knowbe4.zendesk.com/frontendevents/pv https://s3.amazonaws.com/development.uploads.knowbe4.com/ https://s3.amazonaws.com/kmsat-development.uploads.knowbe4.com/ https://s3.amazonaws.com/helpimg/ https://s3.amazonaws.com/helpimg-kmsat-development-us-east-1/ https://helpimg.s3.amazonaws.com/ https://static.zdassets.com/ https://zendesk-eu.my.sentry.io/ pendo-static-6167502888239104.storage.googleapis.com wss://*.zopim.com/ wss://knowbe4.zendesk.com/ ; child-src 'self' blob: ; connect-src 'self' data: blob: wss://enu3cdg6tvghrjuahpbe6c6w5i.appsync-api.eu-west-1.amazonaws.com/graphql wss://enu3cdg6tvghrjuahpbe6c6w5i.appsync-realtime-api.eu-west-1.amazonaws.com/graphql s3.eu-west-1.amazonaws.com/uploads.knowbe4.eu/ api-js.mixpanel.com app.pendo.io btb-glossary-bucket-production-us-east-1.s3.amazonaws.com https://browser-intake-datadoghq.com/ cdn.pendo.io data.pendo.io deepfake-content-write-production-eu-west-1.s3.eu-west-1.amazonaws.com deepfake-content-read-production-eu-west-1.s3.eu-west-1.amazonaws.com fonts.googleapis.com metrics.articulate.com modstore.knowbe4.com modstore-production-us-east-1.s3.amazonaws.com https://*.knowbe4.com https://*.kb4od.run https://*.ckeditor.com/ https://*.launchdarkly.com/ https://*.zopim.com/ https://api-js.mixpanel.com https://api.mixpanel.com/ https://cdnjs.cloudflare.com/ https://code.highcharts.com/ https://data.pendo.io/ https://ekr.zdassets.com/ https://ekr.zendesk.com/ https://knowbe4.zendesk.com/ https://knowbe4.zendesk.com/embeddable/config https://knowbe4.zendesk.com/embeddable_blip https://knowbe4.zendesk.com/frontendevents/dl https://knowbe4.zendesk.com/frontendevents/pv https://s3.amazonaws.com/development.uploads.knowbe4.com/ https://s3.amazonaws.com/kmsat-development.uploads.knowbe4.com/ https://s3.amazonaws.com/helpimg/ https://s3.amazonaws.com/helpimg-kmsat-development-us-east-1/ https://helpimg.s3.amazonaws.com/ https://static.zdassets.com/ https://zendesk-eu.my.sentry.io/ pendo-static-6167502888239104.storage.googleapis.com wss://*.zopim.com/ wss://knowbe4.zendesk.com/ ; frame-src 'self' blob: wss://enu3cdg6tvghrjuahpbe6c6w5i.appsync-api.eu-west-1.amazonaws.com/graphql wss://enu3cdg6tvghrjuahpbe6c6w5i.appsync-realtime-api.eu-west-1.amazonaws.com/graphql s3.eu-west-1.amazonaws.com/uploads.knowbe4.eu/ api-js.mixpanel.com app.pendo.io btb-glossary-bucket-production-us-east-1.s3.amazonaws.com https://browser-intake-datadoghq.com/ cdn.pendo.io data.pendo.io deepfake-content-write-production-eu-west-1.s3.eu-west-1.amazonaws.com deepfake-content-read-production-eu-west-1.s3.eu-west-1.amazonaws.com fonts.googleapis.com metrics.articulate.com modstore.knowbe4.com modstore-production-us-east-1.s3.amazonaws.com https://*.knowbe4.com https://*.kb4od.run https://*.ckeditor.com/ https://*.launchdarkly.com/ https://*.zopim.com/ https://api-js.mixpanel.com https://api.mixpanel.com/ https://cdnjs.cloudflare.com/ https://code.highcharts.com/ https://data.pendo.io/ https://ekr.zdassets.com/ https://ekr.zendesk.com/ https://knowbe4.zendesk.com/ https://knowbe4.zendesk.com/embeddable/config https://knowbe4.zendesk.com/embeddable_blip https://knowbe4.zendesk.com/frontendevents/dl https://knowbe4.zendesk.com/frontendevents/pv https://s3.amazonaws.com/development.uploads.knowbe4.com/ https://s3.amazonaws.com/kmsat-development.uploads.knowbe4.com/ https://s3.amazonaws.com/helpimg/ https://s3.amazonaws.com/helpimg-kmsat-development-us-east-1/ https://helpimg.s3.amazonaws.com/ https://static.zdassets.com/ https://zendesk-eu.my.sentry.io/ pendo-static-6167502888239104.storage.googleapis.com wss://*.zopim.com/ wss://knowbe4.zendesk.com/ android-webview-video-poster: https://player.vimeo.com https://*.ccm.knowbe4.com https://*.internal.knowbe4.com https://*.ccm.internal.knowbe4.com ; font-src 'self' data: fonts.gstatic.com helpimg.s3.amazonaws.com use.fontawesome.com use.typekit.net https://cdnjs.cloudflare.com/ajax/libs/twitter-bootstrap/ ; img-src * 'self' blob: cid: data: file: android-webview-video-poster: https://cdn.mxpnl.com/ https://v2assets.zopim.io/ https://static.zdassets.com/ app.pendo.io cdn.pendo.io data.pendo.io pendo-static-6167502888239104.storage.googleapis.com ; media-src 'self' about: blob: data: wss://enu3cdg6tvghrjuahpbe6c6w5i.appsync-api.eu-west-1.amazonaws.com/graphql wss://enu3cdg6tvghrjuahpbe6c6w5i.appsync-realtime-api.eu-west-1.amazonaws.com/graphql s3.eu-west-1.amazonaws.com/uploads.knowbe4.eu/ api-js.mixpanel.com app.pendo.io btb-glossary-bucket-production-us-east-1.s3.amazonaws.com https://browser-intake-datadoghq.com/ cdn.pendo.io data.pendo.io deepfake-content-write-production-eu-west-1.s3.eu-west-1.amazonaws.com deepfake-content-read-production-eu-west-1.s3.eu-west-1.amazonaws.com fonts.googleapis.com metrics.articulate.com modstore.knowbe4.com modstore-production-us-east-1.s3.amazonaws.com https://*.knowbe4.com https://*.kb4od.run https://*.ckeditor.com/ https://*.launchdarkly.com/ https://*.zopim.com/ https://api-js.mixpanel.com https://api.mixpanel.com/ https://cdnjs.cloudflare.com/ https://code.highcharts.com/ https://data.pendo.io/ https://ekr.zdassets.com/ https://ekr.zendesk.com/ https://knowbe4.zendesk.com/ https://knowbe4.zendesk.com/embeddable/config https://knowbe4.zendesk.com/embeddable_blip https://knowbe4.zendesk.com/frontendevents/dl https://knowbe4.zendesk.com/frontendevents/pv https://s3.amazonaws.com/development.uploads.knowbe4.com/ https://s3.amazonaws.com/kmsat-development.uploads.knowbe4.com/ https://s3.amazonaws.com/helpimg/ https://s3.amazonaws.com/helpimg-kmsat-development-us-east-1/ https://helpimg.s3.amazonaws.com/ https://static.zdassets.com/ https://zendesk-eu.my.sentry.io/ pendo-static-6167502888239104.storage.googleapis.com wss://*.zopim.com/ wss://knowbe4.zendesk.com/ ; object-src 'self' ; script-src 'self' 'unsafe-inline' 'unsafe-eval' blob: wss://enu3cdg6tvghrjuahpbe6c6w5i.appsync-api.eu-west-1.amazonaws.com/graphql wss://enu3cdg6tvghrjuahpbe6c6w5i.appsync-realtime-api.eu-west-1.amazonaws.com/graphql s3.eu-west-1.amazonaws.com/uploads.knowbe4.eu/ api-js.mixpanel.com app.pendo.io btb-glossary-bucket-production-us-east-1.s3.amazonaws.com https://browser-intake-datadoghq.com/ cdn.pendo.io data.pendo.io deepfake-content-write-production-eu-west-1.s3.eu-west-1.amazonaws.com deepfake-content-read-production-eu-west-1.s3.eu-west-1.amazonaws.com fonts.googleapis.com metrics.articulate.com modstore.knowbe4.com modstore-production-us-east-1.s3.amazonaws.com https://*.knowbe4.com https://*.kb4od.run https://*.ckeditor.com/ https://*.launchdarkly.com/ https://*.zopim.com/ https://api-js.mixpanel.com https://api.mixpanel.com/ https://cdnjs.cloudflare.com/ https://code.highcharts.com/ https://data.pendo.io/ https://ekr.zdassets.com/ https://ekr.zendesk.com/ https://knowbe4.zendesk.com/ https://knowbe4.zendesk.com/embeddable/config https://knowbe4.zendesk.com/embeddable_blip https://knowbe4.zendesk.com/frontendevents/dl https://knowbe4.zendesk.com/frontendevents/pv https://s3.amazonaws.com/development.uploads.knowbe4.com/ https://s3.amazonaws.com/kmsat-development.uploads.knowbe4.com/ https://s3.amazonaws.com/helpimg/ https://s3.amazonaws.com/helpimg-kmsat-development-us-east-1/ https://helpimg.s3.amazonaws.com/ https://static.zdassets.com/ https://zendesk-eu.my.sentry.io/ pendo-static-6167502888239104.storage.googleapis.com wss://*.zopim.com/ wss://knowbe4.zendesk.com/ pendo-io-static.storage.googleapis.com pendo-static-6167502888239104.storage.googleapis.com use.typekit.net ; script-src-elem 'self' 'unsafe-inline' 'unsafe-eval' blob: data: wss://enu3cdg6tvghrjuahpbe6c6w5i.appsync-api.eu-west-1.amazonaws.com/graphql wss://enu3cdg6tvghrjuahpbe6c6w5i.appsync-realtime-api.eu-west-1.amazonaws.com/graphql s3.eu-west-1.amazonaws.com/uploads.knowbe4.eu/ api-js.mixpanel.com app.pendo.io btb-glossary-bucket-production-us-east-1.s3.amazonaws.com https://browser-intake-datadoghq.com/ cdn.pendo.io data.pendo.io deepfake-content-write-production-eu-west-1.s3.eu-west-1.amazonaws.com deepfake-content-read-production-eu-west-1.s3.eu-west-1.amazonaws.com fonts.googleapis.com metrics.articulate.com modstore.knowbe4.com modstore-production-us-east-1.s3.amazonaws.com https://*.knowbe4.com https://*.kb4od.run https://*.ckeditor.com/ https://*.launchdarkly.com/ https://*.zopim.com/ https://api-js.mixpanel.com https://api.mixpanel.com/ https://cdnjs.cloudflare.com/ https://code.highcharts.com/ https://data.pendo.io/ https://ekr.zdassets.com/ https://ekr.zendesk.com/ https://knowbe4.zendesk.com/ https://knowbe4.zendesk.com/embeddable/config https://knowbe4.zendesk.com/embeddable_blip https://knowbe4.zendesk.com/frontendevents/dl https://knowbe4.zendesk.com/frontendevents/pv https://s3.amazonaws.com/development.uploads.knowbe4.com/ https://s3.amazonaws.com/kmsat-development.uploads.knowbe4.com/ https://s3.amazonaws.com/helpimg/ https://s3.amazonaws.com/helpimg-kmsat-development-us-east-1/ https://helpimg.s3.amazonaws.com/ https://static.zdassets.com/ https://zendesk-eu.my.sentry.io/ pendo-static-6167502888239104.storage.googleapis.com wss://*.zopim.com/ wss://knowbe4.zendesk.com/ https://unpkg.com/vue@2.6.14 pendo-io-static.storage.googleapis.com pendo-static-6167502888239104.storage.googleapis.com use.typekit.net https://cdn.pendo.io/agent/static/365392a9-6608-44ef-443b-572eef771b95/pendo.js ; style-src 'self' 'unsafe-inline' data: app.pendo.io cdn.pendo.io fonts.gstatic.com https://cdnjs.cloudflare.com/ajax/libs/twitter-bootstrap/ pendo-static-6167502888239104.storage.googleapis.com use.typekit.net ; style-src-elem 'self' 'unsafe-inline' data: app.pendo.io cdn.pendo.io fonts.googleapis.com fonts.gstatic.com helpimg.s3.amazonaws.com cdnjs.cloudflare.com/ajax/libs/font-awesome/ cdnjs.cloudflare.com/ajax/libs/twitter-bootstrap/ p.typekit.net pendo-static-6167502888239104.storage.googleapis.com s3.amazonaws.com/helpimg/ use.fontawesome.com use.typekit.net www.java.com/ga/css/print.css www.java.com/ga/css/screen.css ; report-uri https://csp-report.browser-intake-datadoghq.com/api/v2/logs?dd-api-key=pubf27996eb9977f34aa9f3376bd3939adc&dd-evp-origin=content-security-policy&ddsource=csp-report&app=kmsat&env=production-eu-west-1 ; worker-src 'self' blob: data: ; 5 connect-src 'self' wss: ws: consentcdn.cookiebot.eu consent.cookiebot.com urkwvzhzpc.execute-api.eu-west-1.amazonaws.com *.doubleclick.net *.googlesyndication.com *.klaviyo.com *.klarnacdn.net *.cookiebot.com *.termly.io cloudflareinsights.com *.facebook.com *.dojo.tech *.salesfire.co.uk *.onlinesizing.bike *.tawk.to cdn-cookieyes.com *.cookieyes.com *.klaviyo.com *.appspot-preview.com *.bing.com *.clarity.ms *.fontawesome.com *.google-analytics.com *.google.com *.google.co.uk *.googleapis.com *.googletagmanager.com *.hotjar.com *.iubenda.com *.klarna.com *.klarnaservices.com *.luckyorange.com *.luckyorange.net *.nr-data.net *.paymentsense.cloud *.pushsales.app *.salesfire.co.uk *.sharethis.com *.smartlook.cloud *.visitors.live api.getaddress.io bat.bing.com content.hotjar.io eu.klarnaevt.com js.klarna.com live.smartmetrics.co.uk manager.eu.smartlook.cloud maps.googleapis.com metrics.hotjar.io na.klarnaevt.com stats.g.doubleclick.net vc.hotjar.io www.google.se centinelapi.cardinalcommerce.com *.outfindo.com outfindo.com *.promofeatures.com js.stripe.com *.sandbox.paypal.com *.paypal.com consentprotect.com *.accounts.google.com *.googleadservices.com *.google.com; default-src 'self' *.klaviyo.com *.dojo.tech *.salesfire.co.uk *.googleapis.com *.trustpilot.com; font-src 'self' *.klaviyo.com *.dojo.tech *.pushsales.app *.tawk.to *.salesfire.co.uk *.klaviyo.com fonts.gstatic.com *.cloudflare.com *.fontawesome.com *.typekit.net x.klarnacdn.net js.stripe.com *.sandbox.paypal.com *.paypal.com consent.cookiebot.com; form-action 'self' *.list-manage.com translate.googleapis.com pay.realexpayments.com *.klaviyo.com *.dojo.tech *.facebook.com *.paypal.com *.sagepay.com *.worldpay.com eu-library.klarnaservices.com gateway.cardstream.com live.opayo.eu.elavon.com mdepayments.epdq.co.uk test.opayo.eu.elavon.com js.stripe.com *.sandbox.paypal.com *.paypal.com *.accounts.google.com; frame-ancestors 'self'; frame-src *.cookiebot.eu *.outfindo.com youtu.be *.klaviyo.com hubtiger.com app.bikerentalmanager.com connect.garmin.com widgets.sociablekit.com *.paypalobjects.com www.googletagmanager.com bikesizing.cube.eu www.paypal.com bookings.hubtiger.com challenges.cloudflare.com *.onlinesizing.bike consentcdn.cookiebot.com *.termly.io *.doubleclick.net *.facebook.com *.google.com *.google.co.uk *.greencommuteinitiative.uk greencommuteinitiative.uk *.instagram.com *.paymentsense.cloud *.sharethis.com *.strava.com *.trustpilot.com *.vimeo.com *.youtube-nocookie.com *.youtube.com www.komoot.com cdn.salesfire.co.uk jejames.checkfront.co.uk js.klarna.com td.doubleclick.net www.cyclescheme.co.uk osm.klarnaservices.com *.webmaps.co.uk centinelapi.cardinalcommerce.com js.stripe.com forms.office.com ridewithgps.com platform.twitter.com *.webgains.com *.recaptcha.net *.sandbox.paypal.com *.paypal.com consentprotect.com *.accounts.google.com consent.cookiebot.com *.googleadservices.com; img-src 'self' 'unsafe-inline' data: https: *.klaviyo.com *.dojo.tech *.google-analytics.com *.googletagmanager.com *.gravatar.com 0.gravatar.com l.sharethis.com www.gravatar.com www.specialized.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' player.vimeo.com platform.twitter.com *.consentprotect.com www.googletagmanager.com www.youtube.com *.livechatinc.com *.kaspersky-labs.com *.googlesyndication.com analytics.tiktok.com *.googleadservices.com *.paypal.com widget.privy.com *.list-manage.com *.amazonaws.com *.mailchimp.com *.klaviyo.com *.checkfront.co.uk *.klarnacdn.net *.pushsales.co.uk challenges.cloudflare.com static.cloudflareinsights.com ajax.cloudflare.com *.dojo.tech *.cube.eu *.klarnaservices.com *.clarity.ms *.hotjar.com *.bing.com *.salesfire.co.uk js.klarna.com *.onlinesizing.bike *.clarity.ms *.tawk.to *.avln.me *.bing.com *.webgains.io *.klaviyo.com cdn-cookieyes.com *.chimpstatic.com chimpstatic.com *.googleapis.com *.getaddress.io *.iubenda.com *.addthis.com *.cloudflare.com *.cloudfront.net *.doubleclick.net *.facebook.net *.google-analytics.com *.google.com *.googletagmanager.com *.gstatic.com *.instagram.com *.klarna.com *.klarnaservices.com *.luckyorange.com *.newrelic.com *.nr-data.net *.paymentsense.cloud *.pushsales.app *.salesfire.co.uk *.sharethis.com *.trustpilot.com *.typekit.net *.vimeo.com cdn.jsdelivr.net cdn.salesfire.co.uk cdnjs.cloudflare.com code.jquery.com *.cookiebot.com *.termly.io hit.salesfire.co.uk js.klarna.com kit.fontawesome.com maps.googleapis.com polyfill-fastly.io script.hotjar.com *.elfsight.com static.hotjar.com unpkg.com web-sdk.smartlook.com www.google.com www.gstatic.com x.klarnacdn.net osm.klarnaservices.com *.webmaps.co.uk centinelapi.cardinalcommerce.com *.outfindo.com outfindo.com *.promofeatures.com js.stripe.com *.sandbox.paypal.com *.paypal.com consentprotect.com *.accounts.google.com consent.cookiebot.com *.googleadservices.com; script-src-elem 'self' 'unsafe-inline' 'unsafe-eval' player.vimeo.com platform.twitter.com *.consentprotect.com www.googletagmanager.com www.youtube.com *.livechatinc.com *.kaspersky-labs.com *.googlesyndication.com analytics.tiktok.com *.googleadservices.com *.paypal.com widget.privy.com *.list-manage.com *.amazonaws.com *.mailchimp.com *.klaviyo.com *.checkfront.co.uk *.klarnacdn.net *.pushsales.co.uk challenges.cloudflare.com static.cloudflareinsights.com ajax.cloudflare.com *.dojo.tech *.cube.eu *.klarnaservices.com *.clarity.ms *.hotjar.com *.bing.com *.salesfire.co.uk js.klarna.com *.onlinesizing.bike *.clarity.ms *.tawk.to *.avln.me *.bing.com *.webgains.io *.klaviyo.com cdn-cookieyes.com *.chimpstatic.com chimpstatic.com *.googleapis.com *.getaddress.io *.iubenda.com *.addthis.com *.cloudflare.com *.cloudfront.net *.doubleclick.net *.facebook.net *.google-analytics.com *.google.com *.googletagmanager.com *.gstatic.com *.instagram.com *.klarna.com *.klarnaservices.com *.luckyorange.com *.newrelic.com *.nr-data.net *.paymentsense.cloud *.pushsales.app *.salesfire.co.uk *.sharethis.com *.trustpilot.com *.typekit.net *.vimeo.com cdn.jsdelivr.net cdn.salesfire.co.uk cdnjs.cloudflare.com code.jquery.com *.cookiebot.com *.termly.io hit.salesfire.co.uk js.klarna.com kit.fontawesome.com maps.googleapis.com polyfill-fastly.io script.hotjar.com *.elfsight.com static.hotjar.com unpkg.com web-sdk.smartlook.com www.google.com www.gstatic.com x.klarnacdn.net osm.klarnaservices.com *.webmaps.co.uk centinelapi.cardinalcommerce.com *.outfindo.com outfindo.com *.promofeatures.com js.stripe.com *.sandbox.paypal.com *.paypal.com consentprotect.com *.accounts.google.com consent.cookiebot.com *.googleadservices.com; style-src 'self' 'unsafe-inline' *.google.com www.google.com *.mailchimp.com *.klaviyo.com *.dojo.tech *.paymentsense.cloud *.tawk.to *.salesfire.co.uk *.klaviyo.com *.getaddress.io *.googleapis.com *.pushsales.app *.typekit.net cdn.jsdelivr.net cdnjs.cloudflare.com fonts.googleapis.com npkg.com x.klarnacdn.net js.stripe.com *.sandbox.paypal.com *.paypal.com consentprotect.com *.accounts.google.com; style-src-elem 'self' 'unsafe-inline' *.google.com www.google.com *.mailchimp.com *.klaviyo.com *.dojo.tech *.paymentsense.cloud *.tawk.to *.salesfire.co.uk *.klaviyo.com *.getaddress.io *.googleapis.com *.pushsales.app *.typekit.net cdn.jsdelivr.net cdnjs.cloudflare.com fonts.googleapis.com npkg.com x.klarnacdn.net js.stripe.com *.sandbox.paypal.com *.paypal.com consentprotect.com *.accounts.google.com; report-to csp-endpoint; 5 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://fonts.gstatic.com *.fontawesome.com *.googleapis.com *.klarnacdn.net https://fonts.bunny.net maxcdn.bootstrapcdn.com *.hotjar.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com sandbox.przelewy24.pl secure.przelewy24.pl facebook.com 'self' 'unsafe-inline'; frame-ancestors pay.google.com www.facebook.com *.kinderkraft.fr *.kinderkraft.pl kinderkraft.fr kinderkraft.pl *.trustpilot.com *.criteo.gum *.cookiebot.com kinderkraft.co.uk ecommscript-integrationapp.trustpilot.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com consentcdn.cookiebot.com consentcdn.cookiebot.eu pay.google.com apm.przelewy24.pl *.klarna.com secure.payu.com merch-prod.snd.payu.com *.trustpilot.com *.facebook.com *.instagram.com *.hotjar.com *.criteo.com *.criteo.net *.kinderkraft.fr kinderkraft.fr kinderkraft.pl *.pinterest.com td.doubleclick.net hal9000.redintelligence.net kinderkraft.co.uk ecommscript-integrationapp.trustpilot.com widget.trustpilot.com ecommplugins-trustboxpreview.trustpilot.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'unsafe-inline' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://images.unsplash.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com imgsct.cookiebot.com imgsct.cookiebot.eu *.googleapis.com *.ggpht static.przelewy24.pl www.gstatic.com gstatic.com *.klarna.com *.klarnaevt.com *.klarnacdn.net https://firebasestorage.googleapis.com static.payu.com *.ytimg.com www.google.pl kinderkraft.com pixel.wp.pl *.instagram.com *.payu.com *.hotjar.com *.criteo.com *.adobedtm.com *.doubleclick.net *.outbrain.com *.rubiconproject.com *.yahoo.com *.3lift.com *.smartadserver.com *.adnxs.com *.tapad.com *.casalemedia.com *.360yield.com *.taboola.com *.pubmatic.com *.media.net *.teads.tv *.adform.net *.bidswitch.net *.sharethrough.com *.smaato.net *.socdm.com *.adscale.de *.advertising.com *.dable.io *.co.kr *.stickyadstv.com *.twiago.com *.omnitagjs.com *.liadm.com *.yieldmo.com *.postrelease.com *.addthis.com *.revcontent.com *.mail.ru *.yieldlab.net *.rambler.ru *.bing.com *.openx.net *.nate.com *.mediawallahscript.com id5-sync.com *.rlcdn.com *.adingo.jp *.tremorhub.com *.yandex.ru *.aralego.com/ *.ad-stir.com *.adtdp.com *.meba.kr *.1rx.io *.toast.com *.turn.com *.dmxleo.com *.mediavine.com *.ivitrack.com *.smartclip.net *.krxd.net *.emxdgt.com *.pinterest.com *.bluekai.com *.thebrighttag.com kinderkraft.pl *.user.com *.trustpilot.com *.trustpilot.net *.metaffiliation.com region1.analytics.google.com developers.google.com trk.datnova.com *.facebook.net server-side-tagging-vqegoo7bda-uc.a.run.app bcw.kinderkraft.fr widget.trustpilot.com images-static.trustpilot.com adservice.google.com ade.googlesyndication.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com consent.cookiebot.com consent.cookiebot.eu https://browser.sentry-cdn.com *.googleapis.com *.gstatic.com sandbox.przelewy24.pl secure.przelewy24.pl pay.google.com apm.przelewy24.pl *.snrbox.com *.klarna.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.avada.io secure.payu.com secure.snd.payu.com consentcdn.cookiebot.com *.trustpilot.com *.googletagmanager.com kinderkraft-staging.user.com *.user.com *.g.doubleclick.net *.adyen.com *.facebook.net pixel.wp.pl *.hotjar.com *.criteo.com *.criteo.net *.cloudflare.com *.clickcease.com *.pinimg.com *.googleoptimize.com *.kinderkraft.pl *.kinderkraft.fr *.kinderkraft.de *.kinderkraft.it *.kinderkraft.co.uk *.kinderkraft.es *.metaffiliation.com *.bing.com *.clarity.ms *.cux.io *.taboola.com *.luigisbox.tech ct.pinterest.com kng.kinderkraft.at sha.kinderkraft.be tag.facemyads.co bbd-tag.de s.retargeted.co apptracker.stream *.sddan.com trk.datnova.com js.cookieless-data.com bcw.kinderkraft.fr ecommscript-integrationapp.trustpilot.com cdn.cookiehub.eu widget.trustpilot.com invitejs.trustpilot.com ecommplugins-trustboxpreview.trustpilot.com cdn.chatsimple.ai us-assets.i.posthog.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://fonts.googleapis.com *.fontawesome.com *.googleapis.com *.gstatic.com *.snrcdn.net *.klarnacdn.net https://fonts.bunny.net maxcdn.bootstrapcdn.com *.typekit.net *.trustpilot.com *.instagram.com *.cloudflare.com cdn.luigisbox.tech widget.trustpilot.com ecommplugins-trustboxpreview.trustpilot.com cdn.cookiehub.eu 'self' 'unsafe-inline'; object-src ecommscript-integrationapp.trustpilot.com 'self' 'unsafe-inline'; media-src *.adobe.com *.googlevideo.com cdn.chatsimple.ai 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com consentcdn.cookiebot.com consentcdn.cookiebot.eu https://*.ingest.sentry.io sandbox.przelewy24.pl secure.przelewy24.pl wss://sandbox-ws.przelewy24.pl wss://secure-ws.przelewy24.pl apple-pay-gateway.apple.com apm.przelewy24.pl www.google.com pay.google.com *.snrbox.com *.klarnaevt.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.klarna.com https://get.geojs.io *.avada.io secure.payu.com merch-prod.snd.payu.com ws: *.instagram.com kinderkraft-staging.user.com wss://kinderkraft-staging.user.com *.adyen.com yt2html5.com *.user.com googleads.g.doubleclick.net stats.g.doubleclick.net wss://kinderkraft.user.com *.hotjar.com wss://ws3.hotjar.com https://paypal.com paypal.com *.hotjar.io *.criteo.com wss://ws29.hotjar.com *.pinterest.com wss://ws11.hotjar.com google.pl *.kinderkraft.fr *.metaffiliation.com sentry.io *.clarity.ms *.cux.io *.facebook.com facebook.com *.google.pl wss://* *.openfpcdn.io *.google-analytics.com *.taboola.com *.luigisbox.tech *.bing.com server-side-tagging-vqegoo7bda-uc.a.run.app wdg.kinderkraft.pl *.googleapis.com tvw.kinderkraft.co.uk analytics.tiktok.com *.kinderkraft.at *.kinderkraft.be bcw.kinderkraft.fr ecommscript-integrationapp.trustpilot.com widget.trustpilot.com api.trustpilot.com ambcglobal.sc.omtrdc.net region1.analytics.google.com cdn.cookiehub.eu api.expertise.ai pagead2.googlesyndication.com us.i.posthog.com api.ipify.org 'self' 'unsafe-inline'; child-src *.instagram.com http: https: blob: 'self' 'unsafe-inline'; default-src *.adyen.com *.instagram.com *.googleoptimize.com *.bing.com kinderkraft.co.uk kinderkraft.pl ecommscript-integrationapp.trustpilot.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 5 default-src https: 'self' data: blob:; script-src https: 'self' data: 'unsafe-inline' 'unsafe-eval' blob:; style-src https: 'self' 'unsafe-inline' blob:; report-uri https://services.fandom.com/csp-logger/csp/f2 4 block-all-mixed-content; report-uri https://events.ocdn.eu/v2/csp-report?_ac=events&_fv=www.onet.pl::CPROD_4_6_9 4 require-trusted-types-for 'script';report-uri /_/Gstore/cspreport 4 default-src 'self' https: data: blob: gap: https://*.maersk.com; report-to reporting-endpoint; report-uri https://sescspreportcollector-prod.westeurope.prod.maersk.io/collect-data; 4 font-src *.googleapis.com *.gstatic.com fonts.googleapis.com maxcdn.bootstrapcdn.com https://fonts.gstatic.com 'self' data: *.solodeportes.com.ar use.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.solodeportes.com.ar *.solodeportes.com.ar:6081 *.solofutbol.com *.solourbano.com 'self' 'unsafe-inline'; frame-ancestors *.magerocket.com *.gocuotas.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.solodeportes.com.ar *.solodeportes.com.ar:6081 *.solofutbol.com *.solourbano.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.magerocket.com *.gocuotas.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com https://player.vimeo.com https://www.youtube-nocookie.com *.solodeportes.com.ar *.solodeportes.com.ar:6081 *.solofutbol.com *.solourbano.com *.retargetly.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.googleapis.com *.gstatic.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.magerocket.com *.gocuotas.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com blob: https://updates.themepunch.tools http://updates.themepunch.tools https://updates.themepunch-ext-a.tools http://updates.themepunch-ext-a.tools https://updates.themepunch-ext-b.tools http://updates.themepunch-ext-b.tools https://dev.sliderrevolution.com https://revolution.themepunch.com http://revolution5.themepunch.com http://pbs.twimg.com https://pbs.twimg.com http://scontent.cdninstagram.com https://img.youtube.com http://live.staticflickr.com https://live.staticflickr.com *.clarity.ms *.solodeportes.com.ar *.solodeportes.com.ar:6081 *.solofutbol.com *.solourbano.com *.powerreviews.com bat.bing.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.googleapis.com *.gstatic.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.magerocket.com *.gocuotas.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com https://player.vimeo.com https://www.youtube.com *.solodeportes.com.ar *.solodeportes.com.ar:6081 *.solofutbol.com *.solourbano.com *.newrelic.com *.powerreviews.com *.clarity.ms *.retargetly.com *.embluemail.com *.tiktokw.us *.tiktok.com *.ads-twitter.com bat.bing.com cdn.evgnet.com cdn.jsdelivr.net *.evergage.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com maxcdn.bootstrapcdn.com https://fonts.googleapis.com http://fonts.googleapis.com *.solodeportes.com.ar *.solodeportes.com.ar:6081 *.solofutbol.com *.solourbano.com use.fontawesome.com *.powerreviews.com *.evergage.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com blob: 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com *.googleapis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.magerocket.com *.gocuotas.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com https://fonts.googleapis.com https://fonts.gstatic.com https://api.weatherbit.io *.solodeportes.com.ar *.solodeportes.com.ar:6081 *.solofutbol.com *.solourbano.com *.nr-data.net *.powerreviews.com *.google.com *.doubleclick.net *.tiktokw.us *.tiktok.com *.clarity.ms *.evergage.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 4 object-src 'none'; connect-src 'self' https://*.canadapost.ca https://*.canadapost-postescanada.ca https://*.postescanada-canadapost.ca https://*.cpggpc.ca https://www.google-analytics.com https://siteintercept.qualtrics.com https://www.facebook.com https://sslstats.canadapost.ca https://*.wistia.com https://dpm.demdex.net https://csi.gstatic.com https://adservice.google.com https://*.googlesyndication.com https://*.g.doubleclick.net https://maps.googleapis.com https://vmss.boldchat.com https://www.linkedin.com https://canadapost.tt.omtrdc.net https://services.postcodeanywhere.co.uk https://embedwistia-a.akamaihd.net https://cdn.cookielaw.org https://geolocation.onetrust.com https://px.ads.linkedin.com https://google.com https://www.google.com; font-src 'self' https://*.canadapost.ca https://*.canadapost-postescanada.ca https://*.postescanada-canadapost.ca https://fonts.gstatic.com https://*.arcgis.com; form-action 'self' https://*.canadapost-postescanada.ca https://*.postescanada-canadapost.ca https://*.canadapost.ca https://*.epost.ca https://www.facebook.com https://google.com; frame-ancestors 'self' https://*.canadapost-postescanada.ca https://*.postescanada-canadapost.ca https://*.canadapost.ca; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://*.canadapost.ca https://*.canadapost-postescanada.ca https://*.postescanada-canadapost.ca https://*.epost.ca https://*.cpggpc.ca https://www.adobetag.com https://assets.adobedtm.com https://siteintercept.qualtrics.com https://zn0xleir6swszany9-canadapostdigital.siteintercept.qualtrics.com https://connect.facebook.net https://snap.licdn.com https://z.moatads.com https://static.ads-twitter.com https://www.googletagmanager.com https://www.google.com https://www.googletagservices.com https://*.google-analytics.com https://*.googleadservices.com https://www.gstatic.com https://*.googlesyndication.com https://adservice.google.com https://adservice.google.ca https://maps.googleapis.com https://cdn.ampproject.org https://*.doubleclick.net https://*.twitter.com https://cdn.syndication.twimg.com https://dpm.demdex.net https://*.wistia.com https://*.frontlinesvc.com https://*.arcgis.com https://www.linkedin.com https://vmss.boldchat.com https://sb.scorecardresearch.com https://www.rnengage.com https://sjs.bizographics.com https://www.instagram.com https://secure.adnxs.com https://app.five9.com https://cdn.cookielaw.org; style-src 'self' 'unsafe-inline' https://*.frontlinesvc.com https://fonts.googleapis.com https://translate.googleapis.com https://*.twitter.com https://*.canadapost.ca https://*.canadapost-postescanada.ca https://*.postescanada-canadapost.ca https://*.epost.ca https://*.arcgis.com https://*.arcgisonline.com https://app.five9.com; report-uri https://www.canadapost-postescanada.ca/cwc/components/rs/csp-reports; 4 default-src 'self' https: 'unsafe-inline' 'unsafe-eval'; script-src 'self' https: 'unsafe-inline' 'unsafe-eval' blob:; style-src 'self' https: 'unsafe-inline'; img-src 'self' https: data: blob:; font-src 'self' https: data:; connect-src 'self' https: wss:; media-src 'self' https: blob: data:; object-src https: blob:; worker-src 'self' https: blob:; frame-src 'self' https: blob:; form-action 'self' https:; block-all-mixed-content; report-uri /csp-violation-report 4 default-src 'self' disney.okta.com sso.myid.disney.com *.oktacdn.com; connect-src 'self' disney.okta.com disney-admin.okta.com sso.myid.disney.com *.oktacdn.com *.mixpanel.com *.mapbox.com disney.kerberos.okta.com disney.mtls.okta.com *.authenticatorlocalprod.com:8769 http://localhost:8769 http://127.0.0.1:8769 *.authenticatorlocalprod.com:65111 http://localhost:65111 http://127.0.0.1:65111 *.authenticatorlocalprod.com:65121 http://localhost:65121 http://127.0.0.1:65121 *.authenticatorlocalprod.com:65131 http://localhost:65131 http://127.0.0.1:65131 *.authenticatorlocalprod.com:65141 http://localhost:65141 http://127.0.0.1:65141 *.authenticatorlocalprod.com:65151 http://localhost:65151 http://127.0.0.1:65151 https://oinmanager.okta.com data: *.ingest.sentry.io; script-src 'unsafe-inline' 'unsafe-eval' 'self' 'report-sample' disney.okta.com sso.myid.disney.com *.oktacdn.com; style-src 'unsafe-inline' 'self' 'report-sample' disney.okta.com sso.myid.disney.com *.oktacdn.com; frame-src 'self' disney.okta.com disney-admin.okta.com sso.myid.disney.com login.okta.com *.vidyard.com com-okta-authenticator: api-5a45a87b.duosecurity.com; img-src 'self' disney.okta.com sso.myid.disney.com *.oktacdn.com *.tiles.mapbox.com *.mapbox.com *.vidyard.com data: blob:; font-src 'self' disney.okta.com sso.myid.disney.com data: *.oktacdn.com fonts.gstatic.com; frame-ancestors 'self' https://data.disneystreaming.com https://data-staging.disneystreaming.com https://data-dev.disneystreaming.com https://outlooksts.disney.com 4 require-trusted-types-for 'script';report-uri /cspreport 4 default-src 'self' *.roche.com *.roche.net *.gene.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.roche.com *.roche.net *.gene.com snap.licdn.com cdn.walkme.com apis.google.com tpc.googlesyndication.com api.html5media.info workdevapp.com cdn-js.net gdata.youtube.com twitter.com geolocation.onetrust.com api.flickr.com graph.facebook.com sharecdn.social9.com maps.googleapis.com use.typekit.com use.typekit.net munchkin.marketo.net img.en25.com w.likebtn.com cdn.mathjax.org sadmin.brightcove.com cdnjs.cloudflare.com releases.flowplayer.org script.crazyegg.com wi.likebtn.com pepperglobal.com analytics.twitter.com cdn.blueconic.net connect.facebook.net fullstory.com script.hotjar.com gnntch.blueconic.net rules.quantcount.com secure.quantserve.com static.hotjar.com www.youtube.com www.googletagmanager.com www.google-analytics.com google-analytics.com *.gstatic.com static.ads-twitter.com sjs.bizographics.com *.linkedin.com www.google.com w.soundcloud.com s.ytimg.com *.cloudflareaccess.com *.salesforceliveagent.com https://*.roche.com:8080 https://cdnjs.org https://service.force.com/* cdn.cookielaw.org static.cloudflareinsights.com googleads.g.doubleclick.net 7232514.collect.igodigital.com; style-src * 'self' 'unsafe-inline'; img-src * 'self' data:; font-src * 'self' data:; connect-src * 'self'; media-src * 'self' data:; object-src 'self'; child-src 'self' *.roche.com *.roche.net *.gene.com *.facebook.net qpcr.probefinder.com *.force.com *.hotjar.com www.facebook.com www.google.com www.googletagmanager.com www.youtube.com; frame-src 'self' *.roche.com *.roche.net *.gene.com www.youtube.com sites.google.com *.googleapis.com *.cloudfront.net *.facebook.net *.arcot.com live.sagepay.com player.vimeo.com tpc.googlesyndication.com players.brightcove.net qpcr.probefinder.com *.eloqua.com *.hotjar.com *.soundcloud.com *.facebook.com *.google.com *.googletagmanager.com *.youtube-nocookie.com *.youtube.com *.mendeley.com *.force.com https://cdn.walkme.com/*; worker-src 'self' *.roche.com *.roche.net *.gene.com; frame-ancestors 'self' *.roche.com *.roche.net *.gene.com datastudio.google.com sites.google.com content.bioclinicien.fr connect.facebook.net www.facebook.com s1691.t.eloqua.com *.cloudflareworkers.com; form-action 'self' *.roche.com *.roche.net *.gene.com content.bioclinicien.fr connect.facebook.net www.facebook.com s1691.t.eloqua.com; base-uri 'self' *.roche.com *.roche.net *.gene.com *.secure.roche.com 4 default-src 'self' 'unsafe-inline' 'unsafe-eval' data: blob: logger.scot.nhs.uk *.fontawesome.com use.typekit.net *.google.com *.google.co.uk *.googleapis.com themes.googleusercontent.com *.gstatic.com code.jquery.com yui.yahooapis.com *.bootstrapcdn.com cdnjs.cloudflare.com cdn.jsdelivr.net unpkg.com *.twitter.com *.twimg.com *.youtube.com youtu.be *.ytimg.com www.youtube-nocookie.com player.vimeo.com i.vimeocdn.com cdn.jwplayer.com content.jwplatform.com prd.jwpltx.com *.jwpcdn.com *.jwpsrv.com *.civiccomputing.com cc.cdn.civiccomputing.com secure.gravatar.com public.tableau.com www.openstreetmap.org browser-update.org s.w.org www.geoplugin.net *.wp.com hcaptcha.com *.hcaptcha.com www.careopinion.org.uk www.patientopinion.org.uk assets.nhs.uk www.travelinescotland.com; worker-src 'self' www.google.com; frame-ancestors 'self'; base-uri 'self'; report-to csp-endpoint; report-uri https://web-reports.scot.nhs.uk/api/v1/csp-report 4 script-src 'self' 'unsafe-inline' 'unsafe-eval' *.lytics.io *.customer.io www.googletagmanager.com www.googleoptimize.com maps.googleapis.com www.gstatic.com *.hotjar.com *.onetrust.com edge.marker.io *.swaven.com *.static-swaven.com *.mikmak.ai cdn.segment.com www.google.com *.clarity.ms js.adsrvr.org cdn.jsdelivr.net upload-widget.cloudinary.com lf16-tiktok-web.tiktokcdn-us.com www.tiktok.com connect.facebook.net *.ttwstatic.com destinilocators.com; worker-src 'self' blob:; connect-src 'self' *.mikmak.ai *.swaven.com *.ninetailed.co analytics.google.com *.clarity.ms; frame-src 'self' *.mikmak.ai *.swaven.com; style-src 'self' 'unsafe-inline' fonts.googleapis.com cdn.fonts.net; font-src 'self' *.mikmak.ai *.swaven.com *.static-swaven.com; img-src 'self' data: *.mikmak.ai *.swaven.com *.static-swaven.com 4 default-src 'self' blob: data: https://*.rerrkvifj.com https://*.ccchch.com https://*.lbank.com https://*.lbk.pub https://*.lbank.info https://*.lturkey.com https://*.lbkpro.net; script-src 'self' 'unsafe-eval' 'unsafe-inline' 'wasm-eval' https://cdn.jsdelivr.net https://*.alicdn.com https://*.livechatinc.com https://*.googletagmanager.com https://*.google-analytics.com https://analytics.google.com https://js.admediasales.com https://accounts.google.com https://appleid.cdn-apple.com https://*.gstatic.com https://*.googleapis.com https://*.geetest.com https://*.google.com https://sepolia.drpc.org https://*.cloudflareinsights.com https://*.geevisit.com https://*.adjust.com https://*.gsensebot.com https://*.facebook.net https://*.forter.com https://*.simplex.com https://telegram.org https://developers.kakao.com https://*.rerrkvifj.com https://*.lbank.com; style-src 'self' 'unsafe-inline' https://cdn.jsdelivr.net https://*.alicdn.com https://fonts.googleapis.com https://accounts.google.com https://*.gstatic.com https://*.geetest.com https://*.rerrkvifj.com https://*.lbank.com https://*.lbank.net https://*.lbank.zone; font-src 'self' data: https://*.alicdn.com https://fonts.gstatic.com https://accounts.google.com https://cdnjs.cloudflare.com https://migaku-public-data.migaku.com https://gw.alipayobjects.com https://use.typekit.net https://cdn.jsdelivr.net https://www.slant.co https://cdn.scite.ai https://*.aliyuncs.com https://cdn.megabonus.com https://cdn.fastdic.com https://*.rerrkvifj.com https://*.lbank.com https://*.rerrkvifj.com; img-src 'self' data: https: blob: android-webview-video-poster: https://*.google-analytics.com https://accounts.google.com https://*.googleapis.com https://cdn.jsdelivr.net https://*.geetest.com https://testqrc.bitgetapp.com https://*.lbank.com https://*.lbank.net https://*.lbank.zone https://*.ierpifvid.com https://*.rerrkvifj.com; connect-src 'self' blob: data: https://aladdin.lbkpro.net https://*.livechatinc.com wss://*.livechatinc.com https://*.google-analytics.com https://analytics.google.com https://sensors-data-access.lbkwork.com https://*.forter.com https://accounts.google.com https://appleid.cdn-apple.com https://stats.g.doubleclick.net https://*.googleapis.com https://eth.merkle.io https://region1.google-analytics.com https://region1.analytics.google.com https://*.geetest.com https://cdnjs.cloudflare.com https://*.alicdn.com https://binance.llamarpc.com https://js.admediasales.com https://track.uc.cn https://*.google.com https://gc.kis.v2.scr.kaspersky-labs.com https://*.oss-cn-hongkong.aliyuncs.com https://adscool.net https://api.trongrid.io https://arb1.arbitrum.io https://infragrid.v.network https://eth.llamarpc.com https://*.hongnuoyy.com https://*.bitunix.com https://*.okx.com https://mainnet.base.org https://rpc.genesys.network https://*.adjust.com https://*.adjust.world https://eth-mainnet.nodereal.io https://ethereum-rpc.publicnode.com https://go.getblock.io https://www.tradingview.com https://*.googletagmanager.com https://siteperformancetest.net https://flagcdn.com https://*.telegram.org https://mainnet.helius-rpc.com https://sentry-uit.line-apps.com https://1rpc.io https://*.lbkwork.com wss://*.lbkwork.com https://*.lbank.com wss://*.lbank.com https://*.lbank.zone https://*.rerrkvifj.com uuapi.rerrkvifj.com wss://*.rerrkvifj.com https://*.ierpifvid.com wss://*.ierpifvid.com https://*.lbank.zone https://*.rrrhhr.com https://*.ccchch.com; worker-src 'self' blob:; frame-src 'self' blob: https://secure.livechatinc.com https://tracking.nexxustrk.pro https://auctera.gotrackier.com https://www.youtube.com https://accounts.google.com https://appleid.cdn-apple.com https://cdn.jsdelivr.net https://*.google.com https://media.openxglobal.com https://api.sumsub.com https://social.rockettrack.pro https://playsala.com https://data.trckr.pro https://*.simplex.com https://*.simplexcc.com https://*.telegram.org https://*.lbank.com https://*.lbank.zone https://*.lbktech.com https://www.lbankwidgets.com; object-src 'none'; media-src 'self' blob: data: https://*.rerrkvifj.com https://*.ierpifvid.com https://*.lbank.com; base-uri 'self'; form-action 'self' https://checkout.simplexcc.com; report-uri https://aladdin.lbkpro.net/h5/submit/csp-report; 4 default-src 'self' *.unrealengine.com *.epicgames.com *.epicgames.net cdn.cookielaw.org *.hcaptcha.com sentry.io *.youtube-nocookie.com epicgames-privacy.my.onetrust.com cloudflare.epicgamescdn.com *.launchdarkly.com player.vimeo.com edc-cdn.net cdn2.unrealengine.com maps.googleapis.com us-west-2-epicgames.graphassets.com d1ap1mz92jnks1.cloudfront.net cdnjs.cloudflare.com d3kjluh73b9h9o.cloudfront.net img.edc-cdn.net cdn1.epicgames.com connect.facebook.net *.realityscan.com; style-src 'self' 'unsafe-inline' wasm-eval: fonts.googleapis.com *.unrealengine.com *.epicgames.com *.epicgames.net cdn.cookielaw.org *.hcaptcha.com sentry.io *.youtube-nocookie.com epicgames-privacy.my.onetrust.com cloudflare.epicgamescdn.com *.launchdarkly.com player.vimeo.com edc-cdn.net cdn2.unrealengine.com maps.googleapis.com us-west-2-epicgames.graphassets.com d1ap1mz92jnks1.cloudfront.net cdnjs.cloudflare.com d3kjluh73b9h9o.cloudfront.net img.edc-cdn.net cdn1.epicgames.com connect.facebook.net *.realityscan.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.unrealengine.com *.epicgames.com *.epicgames.net cdn.cookielaw.org *.hcaptcha.com sentry.io *.youtube-nocookie.com epicgames-privacy.my.onetrust.com cloudflare.epicgamescdn.com *.launchdarkly.com player.vimeo.com edc-cdn.net cdn2.unrealengine.com maps.googleapis.com us-west-2-epicgames.graphassets.com d1ap1mz92jnks1.cloudfront.net cdnjs.cloudflare.com d3kjluh73b9h9o.cloudfront.net img.edc-cdn.net cdn1.epicgames.com connect.facebook.net *.realityscan.com; script-src-elem 'self' 'unsafe-inline' blob: *.unrealengine.com *.epicgames.com *.epicgames.net cdn.cookielaw.org *.hcaptcha.com sentry.io *.youtube-nocookie.com epicgames-privacy.my.onetrust.com cloudflare.epicgamescdn.com *.launchdarkly.com player.vimeo.com edc-cdn.net cdn2.unrealengine.com maps.googleapis.com us-west-2-epicgames.graphassets.com d1ap1mz92jnks1.cloudfront.net cdnjs.cloudflare.com d3kjluh73b9h9o.cloudfront.net img.edc-cdn.net cdn1.epicgames.com connect.facebook.net *.realityscan.com; font-src 'self' data: fonts.gstatic.com *.unrealengine.com *.epicgames.com *.epicgames.net cdn.cookielaw.org *.hcaptcha.com sentry.io *.youtube-nocookie.com epicgames-privacy.my.onetrust.com cloudflare.epicgamescdn.com *.launchdarkly.com player.vimeo.com edc-cdn.net cdn2.unrealengine.com maps.googleapis.com us-west-2-epicgames.graphassets.com d1ap1mz92jnks1.cloudfront.net cdnjs.cloudflare.com d3kjluh73b9h9o.cloudfront.net img.edc-cdn.net cdn1.epicgames.com connect.facebook.net *.realityscan.com; connect-src 'self' data: maps.googleapis.com cdnml.global-cache.online *.unrealengine.com *.epicgames.com *.epicgames.net cdn.cookielaw.org *.hcaptcha.com sentry.io *.youtube-nocookie.com epicgames-privacy.my.onetrust.com cloudflare.epicgamescdn.com *.launchdarkly.com player.vimeo.com edc-cdn.net cdn2.unrealengine.com maps.googleapis.com us-west-2-epicgames.graphassets.com d1ap1mz92jnks1.cloudfront.net cdnjs.cloudflare.com d3kjluh73b9h9o.cloudfront.net img.edc-cdn.net cdn1.epicgames.com connect.facebook.net *.realityscan.com; frame-src 'self' data: *.unrealengine.com *.epicgames.com *.epicgames.net cdn.cookielaw.org *.hcaptcha.com sentry.io *.youtube-nocookie.com epicgames-privacy.my.onetrust.com cloudflare.epicgamescdn.com *.launchdarkly.com player.vimeo.com edc-cdn.net cdn2.unrealengine.com maps.googleapis.com us-west-2-epicgames.graphassets.com d1ap1mz92jnks1.cloudfront.net cdnjs.cloudflare.com d3kjluh73b9h9o.cloudfront.net img.edc-cdn.net cdn1.epicgames.com connect.facebook.net *.realityscan.com; frame-ancestors 'none'; img-src 'self' data: *.ytimg.com img.youtube.com maps.gstatic.com *.unrealengine.com *.epicgames.com *.epicgames.net cdn.cookielaw.org *.hcaptcha.com sentry.io *.youtube-nocookie.com epicgames-privacy.my.onetrust.com cloudflare.epicgamescdn.com *.launchdarkly.com player.vimeo.com edc-cdn.net cdn2.unrealengine.com maps.googleapis.com us-west-2-epicgames.graphassets.com d1ap1mz92jnks1.cloudfront.net cdnjs.cloudflare.com d3kjluh73b9h9o.cloudfront.net img.edc-cdn.net cdn1.epicgames.com connect.facebook.net *.realityscan.com; 4 default-src * data: blob: 'unsafe-inline' 'unsafe-eval'; 4 default-src 'self' https: data: blob: 'unsafe-inline' 'unsafe-eval'; base-uri 'self'; object-src 'none'; frame-ancestors 'self'; 4 default-src 'none'; base-uri 'self'; frame-ancestors 'self'; object-src 'none'; form-action 'self' https://accounts-*.cyberriskalliance.com https://188-UNZ-660.mktorest.com; script-src 'self' https://lytics.cyberriskalliance.com https://www.googletagmanager.com https://www.google-analytics.com https://www.google.com https://www.gstatic.com https://www.clarity.ms https://s.dpmsrv.com https://cdn.feathr.co https://*.g.doubleclick.net https://www.googletagservices.com https://www.googleadservices.com https://munchkin.marketo.net https://pages.cyberriskalliance.com https://connect.facebook.net https://snap.licdn.com https://player.vimeo.com https://platform.twitter.com https://cra.hum.works https://*.ml314.com https://ml314.com https://ib.adnxs.com https://js.zi-scripts.com https://a.usbrowserspeed.com https://renderer.visuel.ly; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; img-src 'self' data: blob: https://files.cyberriskalliance.com https://image-optimizer*.cyberriskalliance.com https://www.cyberriskalliance.com https://securepubads.g.doubleclick.net; font-src 'self' data: https://fonts.gstatic.com; connect-src 'self' https://api*.cyberriskalliance.com https://cms*.cyberriskalliance.com https://image-optimizer*.cyberriskalliance.com https://userapi*.cyberriskalliance.com https://*.hum.works https://7acfab725e3b6315db795ca16eb9966e.clients.hosted-elasticpress.io https://accounts-*.cyberriskalliance.com https://lytics.cyberriskalliance.com https://connect.facebook.net https://www.facebook.com https://snap.licdn.com https://www.google-analytics.com https://cdn.feathr.co https://s.dpmsrv.com https://munchkin.marketo.net https://pages.cyberriskalliance.com https://securepubads.g.doubleclick.net; frame-src 'self' https://www.youtube.com https://player.vimeo.com https://www.google.com https://html5-player.libsyn.com https://securepubads.g.doubleclick.net https://*.googlesyndication.com; media-src 'self' https://html5-player.libsyn.com; manifest-src 'self'; worker-src 'self'; report-uri /_csp; report-to default; 4 img-src https: data: blob:; script-src https: 'unsafe-inline'; style-src https: 'unsafe-inline'; 4 default-src 'self' 'unsafe-inline' data: *.hockeystack.com *.marianatek.com *.cookielaw.org *.chilipiper.com *.googletagmanager.com *.google.com *.gstatic.com *.cloudflare.com *.youtube.com *.youtube-nocookie.com *.vimeo.com *.licdn.com *.facebook.net *.clarity.ms *.google-analytics.com *.hs-scripts.com *.doubleclick.net unpkg.com *.wistia.net;upgrade-insecure-requests; 4 font-src www.paypalobjects.com 'self' smartphonehoesjes.nl handyhuellen.de ploonk.fr *.smartphonehoesjes.nl *.ploonk.fr *.brandcommerce.nl *.mopinion.com fonts.gstatic.com *.cm.com *.fontawesome.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ https://www.paypal.com https://www.sandbox.paypal.com https://hostedfields-externalapi.alpha.buckaroo.aws https://hostedfields-externalapi.prod-pci.buckaroo.io *.acc-smartphonehoesjes.nl *.acc-ploonk.fr *.acc-handyhuellen.de *.acc-brandcommerce.de *.smartphonehoesjes.nl *.ploonk.fr *.coquedetelephone.fr *.handyhuellen.de *.brandcommerce.nl *.doubleclick.net *.facebook.com *.tradedoubler.com *.sovendus-connect.com *.colorlab.io *.printlane.com metrics.smartphonehoesjes.nl metrics.handyhuellen.de metrics.ploonk.fr js.mollie.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.ftcdn.net *.behance.net https://portal.payconiq.com https://static.buckaroo.nl https://www.buckaroo.nl https://www.paypalobjects.com cdn.acc-smartphonehoesjes.nl cdn.acc-brandcommerce.nl cdn.acc-ploonk.fr cdn.acc-handyhuellen.de cdn.smartphonehoesjes.nl cdn.brandcommerce.nl cdn.ploonk.fr cdn.handyhuellen.de *.smartphonehoesjes.nl *.etrusted.com *.google.com *.google.nl *.googlesyndication.com *.facebook.com squeezely.tech *.squeezely.tech *.bing.com *.bing.net *.pointspay.com *.trustedshops.com *.roeyecdn.com *.roeye.com *.doubleclick.net *.zenaps.com *.awin1.com *.facebook.net *.cm.com magefan.com cm.magefan.com *.disqus.com https://img.youtube.com https://firebasestorage.googleapis.com https://www.mollie.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://static.buckaroo.nl https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl *.buckaroo.nl https://www.paypal.com https://www.sandbox.paypal.com https://applepay.cdn-apple.com https://hostedfields-externalapi.alpha.buckaroo.aws https://hostedfields-externalapi.prod-pci.buckaroo.io *.localhost *.acc-smartphonehoesjes.nl *.acc-ploonk.fr *.acc-handyhuellen.de *.acc-brandcommerce.nl smartphonehoesjes.nl *.smartphonehoesjes.nl *.ploonk.fr *.handyhuellen.de *.brandcommerce.nl *.analytics.google.com *.googlesyndication.com www.clarity.ms *.google.com *.google.nl *.facebook.net *.tiktok.com *.doubleclick.net *.bing.com *.etrusted.com *.elitechnology.com *.beslist.nl squeezely.tech *.squeezely.tech *.trustedshops.com *.mopinion.com *.dwin1.com *.aiden.cx *.kickbite.io *.colorlab.io *.printlane.com *.hotjar.com *.sovendus.com *.wurflcloud.com fonts.gstatic.com *.cloudfront.net *.roeyecdn.com *.disqus.com *.avada.io *.shopify.com js.mollie.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://static.buckaroo.nl https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl *.localhost *.googleapis.com *.etrusted.com *.mopinion.com *.fontawesome.com https://fonts.bunny.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.youtube.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com wss://websocketservice-externalapi.prod.buckaroo.io https://static.buckaroo.nl wss://websockets.buckaroo.io/ https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl https://hostedfields-externalapi.alpha.buckaroo.aws https://hostedfields-externalapi.prod-pci.buckaroo.io https://applepay.buckaroo.io https://www.paypal.com https://www.sandbox.paypal.com smartphonehoesjes.nl *.smartphonehoesjes.nl *.handyhuellen.de *.ploonk.fr *.brandcommerce.nl wss://*.azurewebsites.net *.wurflcloud.com *.clarity.ms https://get.geojs.io *.amazon.com *.etrusted.com *.demdex.net *.sc.omtrdc.net *.cardinalcommerce.com *.acc-smartphonehoesjes.nl *.acc-ploonk.fr *.acc-handyhuellen.de *.acc-brandcommerce.nl google.com *.google.com google.nl *.google.nl *.googlesyndication.com *.tiktok.com *.hotjar.com *.doubleclick.net *.aiden.cx *.sovendus.com *.trustedshops.com *.youtube.com *.plyr.io noembed.com *.amazonaws.com *.mopinion.com *.beslist.nl *.kickbite.io *.bing.com *.bing.net *.avada.io 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 4 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com cdn.jsdelivr.net cdn.almapay.com *.bglobale.com *.global-e.com *.fontawesome.com fonts.googleapis.com https://cdnjs.cloudflare.com 'self' data: *.onestock-retail.io *.sensefuel.live *.cdnfonts.com *.perplexity.ai *.isge49.com *.bocage.fr *.googleusercontent.com *.kameleoon.com *.abtasty.com s3-eu-west-1.amazonaws.com *.iadvize.com globale-prod.s3-eu-west-1.amazonaws.com ncspublicasset.s3.eu-west-3.amazonaws.com data: 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com *.getalma.eu *.almapay.com/ *.stripe.com/ *.checkout.com/ *.adyen.com/ *.bglobale.com *.global-e.com *.google.com/ *.onestock-retail.com/ payment.direct.worldline-solutions.com payment.preprod.direct.worldline-solutions.com payment.anzworldline-solutions.com.au payment.preprod.anzworldline-solutions.com.au payment.payone.com payment.preprod.payone.com *.effiliation.com *.doubleclick.net *.bing.com *.pinterest.com *.facebook.com *.criteo.com *.bocage.eu *.googletagmanager.com *.snapchat.com vimeo.com *.abtasty.com *.criteo.net *.vimeo.com *.goodays.co *.cookiebot.com *.cloudflare.com *.iadvize.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.bglobale.com *.global-e.com *.googleapis.com https://www.magezon.com *.openstreetmap.org maps.googleapis.com maps.gstatic.com https://www.google.fr https://api.mapbox.com *.tile.openstreetmap.org https://maps.googleapis.com https://maps.gstatic.com *.hsforms.net *.hsforms.com 'self' data: www.google.gg www.google.gl www.google.com.pg www.google.com.np www.google.com.pe www.google.co.il www.google.jo www.google.it www.google.co.zm *.facebook.net www.google.hu *.google.com www.google.com.pr *.eram.eu www.google.li www.google.am *.adform.net *.pinterest.com www.google.is www.google.bi *.batch.com *.criteo.com www.google.mn *.smartadserver.com www.google.com.ec www.google.me www.google.com.kh www.google.co.th www.google.com.vn www.google.ps www.google.com.hk *.advalo.com www.google.com.cy www.google.cv www.google.ge *.bing.net www.google.ro www.google.cd www.google.co.ve *.teads.tv www.google.ru www.google.com.bn *.abtasty.com www.google.com.cu *.kameleoon.eu www.google.com.vc www.google.com.ni *.mellowyellow.com *.adnxs.com www.google.com.eg www.google.com.gt www.google.com.jm *.contentsquare.net www.google.je us-central1-shopmyinfluens.cloudfunctions.net *.iadvize.com www.google.so www.google.com.af *.mmtro.com www.google.com.sl *.taboola.com www.google.gr *.bocage.fr www.google.tn www.google.co.in *.ggpht.com www.google.ad www.google.at www.google.al www.google.vu *.lgw.io www.google.cm www.google.mw www.google.ae www.google.pl www.google.pt www.google.be www.google.ee www.google.com.py www.google.iq www.google.ca www.google.sr www.google.de www.google.lt www.google.co.zw www.google.co.ug www.google.com.ph www.google.ga mmtro.com www.google.tg www.google.lv *.doubleclick.net *.sensefuel.live www.google.dj www.google.ci *.onestock-retail.io *.affilae.com www.google.com.ua www.google.com.gh *.bing.com www.google.com.my www.google.com.om www.google.nl www.google.ws www.google.com.sv www.google.com.tr www.google.se www.google.co.ao *.google-analytics.com www.google.sn www.google.cl www.google.sc bucket-ip-website.s3.eu-central-1.amazonaws.com www.google.co.nz www.google.com.bz www.google.co.uk www.google.com.bd www.google.tm *.googleadservices.com www.google.cf www.google.co.ck www.google.mk www.google.st *.isge49.com www.google.bf www.google.co.kr www.google.co.bw *.bocage.eu www.google.co.id www.google.com.qa www.google.com.co www.google.com.bh *.facebook.com www.google.lk www.google.by www.google.hr *.vimeo.com *.mellowyellow.eu www.google.com.et www.google.ch www.google.md www.google.im www.google.es www.google.td www.google.com.bo www.google.lu www.google.co.ma www.google.dm www.google.co.ls www.google.ba joko-mobile-app-media.s3.eu-west-1.amazonaws.com *.twiago.com www.google.rw *.kameleoon.com www.google.tt www.google.com.lb www.google.no www.google.dk www.google.mg www.google.hn *.ebuyclub.com www.google.ne www.google.ml d1oco4z2z1fhwp.cloudfront.net www.google.la www.google.com.br www.google.com.mt www.google.kg www.google.cn www.google.mv mellowyellow.com www.google.co.mz www.google.bg www.google.com.pk *.googletagmanager.com www.google.com.tw www.google.com.sg d3e54v103j8qbb.cloudfront.net www.google.rs www.google.ie www.google.co.ke www.google.com.pa google.com www.google.com.fj www.google.com.kw www.google.com.mx www.google.mu *.outbrain.com *.criteo.net www.google.co.cr www.google.gy www.google.co.jp www.google.com.do www.google.fi www.google.sk www.google.co.tz www.google.si www.google.com.sa www.google.bj *.eram.fr www.google.dz www.google.com.ar www.google.co.uz www.google.fr s3-eu-west-1.amazonaws.com www.google.com.ng *.xiti.com *.snapchat.com *.googleusercontent.com www.google.com.uy *.openx.net www.google.com.na www.google.com.mm *.cookiebot.com *.googlesyndication.com *.tiktok.com www.google.co.za www.google.gm www.google.cg www.google.ht www.google.kz www.google.com.au www.google.bs www.google.cz www.google.az www.google.com.ly www.google.com.gi data: 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com cdn.jsdelivr.net *.bglobale.com *.global-e.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com https://cdnjs.cloudflare.com https://maps.googleapis.com *.hsforms.net *.hsforms.com *.gstatic.com *.addthis.com payment.direct.worldline-solutions.com payment.preprod.direct.worldline-solutions.com payment.anzworldline-solutions.com.au payment.preprod.anzworldline-solutions.com.au payment.payone.com payment.preprod.payone.com *.criteo.com *.googleapis.com *.snapchat.com *.jquery.com *.iadvize.com critizr.com *.kameleoon.eu *.cloudflare.com *.taboola.com *.sensefuel.com *.contentsquare.com *.adform.net *.googlesyndication.com *.hotjar.com *.mmtro.com *.pinimg.com *.tiktok.com *.pinterest.com *.vimeo.com *.cookiebot.com *.googletagmanager.com *.batch.com translate.google.com.hk *.lgw.io *.sensefuel.live *.eram.fr dqfw2hlp4tfww.cloudfront.net *.facebook.net *.abtasty.com *.contentsquare.net *.kameleoon.com *.onestock-retail.io *.goodays.co *.doubleclick.net *.bing.com *.googleadservices.com mmtro.com *.aticdn.net *.criteo.net *.kameleoon.io *.affilae.com sc-static.net d3e54v103j8qbb.cloudfront.net 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; style-src *.adobe.com fonts.googleapis.com cdn.jsdelivr.net *.bglobale.com *.global-e.com *.gstatic.com *.googleapis.com *.fontawesome.com https://fonts.googleapis.com https://cdnjs.cloudflare.com *.abtasty.com *.iadvize.com *.typekit.net semji.github.io *.onestock-retail.io *.sensefuel.com *.goodays.co *.kameleoon.com *.sensefuel.live *.googletagmanager.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.vimeocdn.com *.fbcdn.net *.bing.com *.mellowyellow.com *.gstatic.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.getalma.eu *.almapay.com maps.googleapis.com https://nominatim.openstreetmap.org https://maps.googleapis.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com payment.direct.worldline-solutions.com payment.preprod.direct.worldline-solutions.com payment.anzworldline-solutions.com.au payment.preprod.anzworldline-solutions.com.au payment.payone.com payment.preprod.payone.com *.kameleoon.eu *.deebr.co *.openx.net *.kameleoon.com *.contentsquare.net *.abtasty.com *.doubleclick.net *.iadvize.com *.onestock-retail.io *.merchant-center-analytics.goog *.hotjar.io *.sensefuel.biz *.typekit.net www.google.it *.pinterest.com *.googleapis.com *.facebook.com *.aticdn.net *.sensefuel.live *.tiktok.com www.google.co.id *.instagram.com *.jquery.com www.google.ge *.bing.net www.google.fr www.google.ca *.snapchat.com *.adnxs.com *.advalo.com *.taboola.com www.google.cn *.cookiebot.com *.affilae.com *.cloudflare.com *.teads.tv *.hotjar.com *.goodays.co *.gstatic.com *.contentsquare.com *.batch.com *.criteo.com www.google.es www.google.be *.googlesyndication.com www.google.ch *.googleadservices.com *.facebook.net *.bing.com *.eram.fr *.kameleoon.io 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://ab48b69d-84be-485e-b94f-4ed50b3a5780.sansec.watch/; report-to report-endpoint; 4 default-src https:; script-src https: 'unsafe-eval' 'unsafe-inline'; style-src https: 'unsafe-inline'; img-src https: data:; font-src https: data:; report-uri https://csp-report.envytools.com 4 default-src https:;frame-ancestors about: 'self';frame-src https://optimize.google.com *;style-src https://optimize.google.com https://fonts.googleapis.com https: data: 'unsafe-inline' *;script-src https://www.googleanalytics.com https://www.google-analytics.com https://optimize.google.com * 'unsafe-inline' 'unsafe-eval';img-src https://www.google-analytics.com https://www.googletagmanager.com https://optimize.google.com https: data: *;font-src https://fonts.gstatic.com data: *;object-src 'none';connect-src * ws: wss:; report-uri https://res.destinia.com/web/csp-violation-report-endpoint; report-to default; 4 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com cash-f.squarecdn.com https://apretailer.com.br 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com * *.facebook.com *.facebook.net *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com 'self' 'unsafe-inline'; frame-ancestors *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com * *.us1.gigya.com *.openpay.mx *.openpay.co *.facebook.com *.facebook.net *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.opencontrol.mx *.kaptcha.com *.openpay.pe *.paynet.com.mx *.pagaleve.io *.pagaleve.com.br www.google-analytics.com unpkg.com googleads.g.doubleclick.net commerce.adobedtm.com magento-recs-sdk.adobe.net www.googleadservices.com www.gstatic.com *.google.com.br *.criteo.com *.doubleclick.net *.cloudfront.net *.nr-data.net *.enviou.com.br *.newrelic.com http://receiver.posclick.dinamize.com *.gigya-api.com *.panini.com.br https://apretailer.com.br c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net * ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com *.us1.gigya.com 'self' data: 'unsafe-inline' data: *.postimg.cc magefan.com cm.magefan.com *.facebook.com *.facebook.net *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.openpay.mx *.pagaleve.com.br unpkg.com commerce.adobedtm.com magento-recs-sdk.adobe.net www.gstatic.com *.google.com *.google.com.br *.panini.canto.global https://panini.canto.global *.cloudfront.net *.doubleclick.net *.g.doubleclick.net *.ivitrack.com *.bidswitch.net *.criteo.com *.nr-data.net *.enviou.com.br *.newrelic.com http://receiver.posclick.dinamize.com *.gigya-api.com *.panini.com.br https://www.gravatar.com *.googleusercontent.com https://apretailer.com.br https://cdn.aplazo.mx *.adobedtm.com *.clarity.ms https://smartbmc.com.br https://ib.adnxs.com https://r.casalemedia.com https://ads.stickyadstv.com https://ad.360yield.com https://i.liadm.com https://contextual.media.net https://exchange.mediavine.com *.bing.com https://jadserve.postrelease.com https://sync.outbrain.com https://simage2.pubmatic.com https://trends.revcontent.com https://pixel.rubiconproject.com https://rtb-csync.smartadserver.com https://sync-t1.taboola.com https://criteo-sync.teads.tv https://criteo-partners.tremorhub.com https://ade.clmbtech.com https://eb2.3lift.com https://sync.1rx.io https://gum.criteo.com https://public-prod-dspcookiematching.dmxleo.com https://www.mercadopago.cl *.agkn.com *.targeting.unrulymedia.com *.dnzdns.com *.adgrx.com *.bidr.io *.yahoo.com *.emkt.dinamize.com *.dinamize.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.hsforms.net *.hsforms.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net amcglobal.sc.omtrdc.net *.adobe.io use.typekit.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.magento-ds.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.magento-datasolutions.com *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com *.cash.app *.visa.com *.mastercard.com https://rum.hlx.page chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com *.us1.gigya.com *.facebook.com *.facebook.net *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.s3.amazonaws.com *.openpay.co *.openpay.pe *.google-analytics.com *.google.com/recaptcha/ *.gstatic.com/recaptcha/ *.pagaleve.com.br analytics.tiktok.com *.clarity.ms unpkg.com www.gstatic.com *.google.com.br *.vendavalida.com.br *.zdassets.com *.criteo.com *.enviou.com.br *.cloudfront.net aprtn.com http://receiver.posclick.dinamize.com *.gigya-api.com *.panini.com.br https://apretailer.com.br *.metricool.com *.hotjar.com *.bing.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com *.hsforms.net *.hsforms.com *.gstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com *.cash.app downloads.mailchimp.com 'unsafe-inline' data: *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com https://apretailer.com.br assets.braintreegateway.com *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.magento-datasolutions.com *.magento-ds.com * form-assets.mailchimp.com *.intuit.com *.amazonaws.com *.openpay.mx *.openpay.co *.facebook.com *.facebook.net *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.openpay.pe unpkg.com googleads.g.doubleclick.net commerce.adobedtm.com magento-recs-sdk.adobe.net www.gstatic.com *.google.com.br *.criteo.com *.vendavalida.com.br *.zendesk.com *.doubleclick.net *.us1.gigya.com *.cloudfront.net *.enviou.com.br http://receiver.posclick.dinamize.com *.gigya-api.com *.panini.com.br https://apretailer.com.br *.paniniadrenalyn.com pagead2.googlesyndication.com analytics.tiktok.com *.clarity.ms *.bing.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src bam.nr-data.net googleads.g.doubleclick.net csm.us5.us.criteo.net commerce.adobedc.net https://apretailer.com.br *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 4 block-all-mixed-content;default-src https:;script-src * 'self' https: 'unsafe-eval' 'unsafe-inline';style-src * 'self' https: 'unsafe-inline';connect-src * https: https://*.paynearme.com;manifest-src 'self';font-src * 'self' https:;form-action 'self' https://www.facebook.com https://accounts.google.com https://twitter.com https://login.microsoftonline.com;img-src * 'self' https: data:;media-src *;object-src 'none';frame-ancestors *;frame-src * https://*.paynearme.com;worker-src 'self';base-uri 'self';report-uri /csp-report 4 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://www.googletagmanager.com https://*.google.com https://*.google-analytics.com https://*.googleadservices.com https://*.g.doubleclick.net https://*.gstatic.com https://*.hs-scripts.com https://js-na2.hs-analytics.net https://js-na2.hs-banner.com https://*.hscollectedforms.net https://snap.licdn.com https://bat.bing.com https://sc.lfeeder.com https://plugins.flockler.com https://apibeta.iamgaia.com https://cdn.cookielaw.org https://cdn.onthe.io https://cdn.zingchart.com https://darkvisitors.com https://c.sproutvideo.com https://knownagents.com; connect-src 'self' data: https://www.googletagmanager.com https://*.google.com https://*.google-analytics.com https://*.googleadservices.com https://*.g.doubleclick.net https://*.hscollectedforms.net https://px.ads.linkedin.com https://tt.onthe.io https://listgrowth.ctctcdn.com https://apibeta.iamgaia.com https://privacyportal.onetrust.com https://geolocation.onetrust.com https://cdn.cookielaw.org https://api.flockler.app https://media-api.flockler.com https://stats-api.flockler.app https://darkvisitors.com https://bat.bing.com https://bat.bing.net https://*.algolia.net https://*.algolianet.com https://*.algolia.io https://www.googleadservices.com https://knownagents.com; img-src 'self' https: data: blob:; media-src 'self' blob: data: https://videos.sproutvideo.com https://dms.licdn.com; style-src 'self' 'unsafe-inline' https://cdn.cookielaw.org https://static.ctctcdn.com https://www.gstatic.com; style-src-elem 'self' 'unsafe-inline' https://www.gstatic.com https://static.ctctcdn.com; font-src 'self' https://fonts.gstatic.com https://s0.wp.com data:; frame-src 'self' https://www.googletagmanager.com https://www.google.com https://open.spotify.com https://player.vimeo.com https://videos.sproutvideo.com https://www.youtube.com https://www.youtube-nocookie.com; worker-src 'self' blob:; report-uri https://cspreport.kla.com/api/reports/csp; 4 default-src 'self'; script-src 'self' 'unsafe-eval' https://prototype.local.next.helmholtz-munich.de 'report-sample'; style-src-attr 'unsafe-inline' 'report-sample'; img-src 'self' https://*.dzd-ev.de https://images.admiralcloud.com https://prototype.local.next.helmholtz-munich.de; base-uri 'self'; frame-src 'self' https://player.vimeo.com https://www.youtube-nocookie.com; connect-src 'self' https://*.dzd-ev.de wss://*.dzd-ev.de/ https://sentry2.in2code.de/api/62/security/ wss://prototype.local.next.helmholtz-munich.de/ https://hmwa.helmholtz-munich.de; style-src 'self' 'unsafe-inline' 'report-sample'; style-src-elem 'self' 'unsafe-inline' https://prototype.local.next.helmholtz-munich.de 'report-sample'; script-src-elem 'self' https://*.dzd-ev.de https://prototype.local.next.helmholtz-munich.de https://hmwa.helmholtz-munich.de 'report-sample'; font-src 'self' https://*.dzd-ev.de https://prototype.local.next.helmholtz-munich.de; report-uri https://sentry2.in2code.de/api/62/security/?sentry_key=c8671bb1cf909cd134a5b859fc8d36e1 4 font-src fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com testsecureacceptance.cybersource.com secureacceptance.cybersource.com 0merchantacsstag.cardinalcommerce.com merchantacs.cardinalcommerce.com *.authorize.net *.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.authorize.net 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com www.google.com connect.bolt.com connect-sandbox.bolt.com account.bolt.com account-sandbox.bolt.com *.online-metrix.net testflex.cybersource.com flex.cybersource.com testsecureacceptance.cybersource.com secureacceptance.cybersource.com pay.google.com merchantacs.cardinalcommerce.com 0merchantacsstag.cardinalcommerce.com *.authorize.net *.weltpixel.com *.googletagmanager.com *.doubleclick.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io connect.bolt.com connect-sandbox.bolt.com s3-us-west-1.amazonaws.com www.gstatic.com magefan.com cm.magefan.com *.disqus.com https://img.youtube.com mageside.com *.gstatic.com *.facebook.com *.reddit.com *.ads-twitter.com t.co *.twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.google-analytics.com *.googletagmanager.com *.doubleclick.net *.google.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.google.com/recaptcha/ www.gstatic.com/recaptcha/ connect.bolt.com connect-sandbox.bolt.com account.bolt.com account-sandbox.bolt.com *.online-metrix.net testflex.cybersource.com flex.cybersource.com pay.google.com x.klarnacdn.net centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.kaptcha.com *.disqus.com *.authorize.net *.googletagmanager.com *.googleadservices.com *.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.bing.com *.clarity.ms *.klaviyo.com unpkg.com *.doubleclick.net https://scripts.ltv.ai 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.tagmanager.google.com *.googletagmanager.com fonts.googleapis.com 'self' 'unsafe-inline'; object-src connect.bolt.com connect-sandbox.bolt.com account.bolt.com account-sandbox.bolt.com 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com connect.bolt.com connect-sandbox.bolt.com account.bolt.com account-sandbox.bolt.com sessions.bugsnag.com *.kaptcha.com *.authorize.net www.googleapis.com *.google-analytics.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.doubleclick.net *.run.app 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 4 object-src 'none'; script-src 'self' cdn.jsdelivr.net cdnjs.cloudflare.com https://cse.google.com https://js.hsforms.net https://platform-api.sharethis.com https://rebilly.github.io https://unpkg.com https://use.fontawesome.com https://ws.sharethis.com platform.instagram.com platform.twitter.com; script-src-attr 'self'; style-src 'self' https://cloud.typography.com https://use.fontawesome.com; style-src-attr 'self'; frame-ancestors 'self' 4 style-src blob: https://880-tzc-395.mktoweb.com https://app.cdn.lookbookhq.com https://cdnjs.cloudflare.com https://fonts.googleapis.com https://tags.srv.stackadapt.com 'report-sample' 'self' 'unsafe-inline';child-src blob:;media-src blob: data: https://*.wistia.com https://*.wistia.net https://app.qualified.com https://cdn.commoninja.com 'self';worker-src blob: 'self';font-src data: https://*.wistia.com https://fonts.gstatic.com 'self';img-src data: https://*.wistia.com https://*.wistia.net https://adnxs.com https://b.6sc.co https://bat.bing.com https://c.bing.com https://c.clarity.ms https://cdn.bizible.com https://cdn.commoninja.com https://cdn.pathfactory.com https://googleads.g.doubleclick.net https://i.ytimg.com https://imgsct.cookiebot.com https://monitor.clickcease.com https://pbcdn1.podbean.com https://phosphor.utils.elfsightcdn.com https://prodmediusumbstorage.blob.core.windows.net https://px.ads.linkedin.com https://s.ml-attr.com https://ssl.gstatic.com https://static.licdn.com https://www.google.com https://yt3.ggpht.com 'self';connect-src https://*.algolia.net https://*.elfsight.com https://*.litix.io https://*.wistia.com https://*.wistia.net https://880-tzc-395.mktoresp.com https://adnxs.com https://analytics.google.com https://api-js.mixpanel.com https://app.cdn.lookbookhq.com https://app.qualified.com https://bat.bing.com https://cdn.commoninja.com https://cdn-app.pathfactory.com https://consentcdn.cookiebot.com https://content.hotjar.io https://core.service.elfsight.com https://eastus-8.in.applicationinsights.azure.com https://epsilon.6sense.com https://evnt.byspotify.com https://explore.medius.com https://googleads.g.doubleclick.net https://ipv6.6sc.co https://js.monitor.azure.com https://jukebox.pathfactory.com https://n.clarity.ms https://pi.pardot.com https://px.ads.linkedin.com https://tags.srv.stackadapt.com https://tracking.intentsify.io https://v.clarity.ms https://website-assets.commoninja.com https://widget-data.service.elfsight.com https://www.clarity.ms https://www.clickcease.com https://www.commoninja.com https://www.google.com https://www.googleadservices.com https://www.google-analytics.com 'self' wss://ws.hotjar.com wss://ws7.qualified.com;script-src https://*.elfsight.com https://*.elfsightcdn.com https://*.sentry-cdn.com https://*.wistia.com https://*.wistia.net https://880-tzc-395.mktoweb.com https://apis.google.com https://app.cdn.lookbookhq.com https://bat.bing.com https://cdn.bizible.com https://cdn.commoninja.com https://cdn.jsdelivr.net https://cdn.mxpnl.com https://cdn-app.pathfactory.com https://cdnjs.cloudflare.com https://consent.cookiebot.com https://consentcdn.cookiebot.com https://googleads.g.doubleclick.net https://j.6sc.co https://js.monitor.azure.com https://js.qualified.com https://munchkin.marketo.net https://pixel.byspotify.com https://script.hotjar.com https://scripts.clarity.ms https://snap.licdn.com https://src.litix.io https://static.hotjar.com https://tags.srv.stackadapt.com https://tracking.g2crowd.com https://www.clarity.ms https://www.clickcease.com https://www.google.com https://www.googleadservices.com https://www.googleoptimize.com https://www.googletagmanager.com https://www.gstatic.com https://www.youtube.com 'report-sample' 'self' 'unsafe-eval' 'unsafe-inline';default-src https://*.wistia.com https://*.wistia.net 'self';frame-src https://880-tzc-395.mktoweb.com https://accounts.google.com https://app.qualified.com https://consentcdn.cookiebot.com https://explore.medius.com https://fast.wistia.com https://fast.wistia.net https://open.spotify.com https://pi.pardot.com https://www.clarity.ms https://www.google.com https://www.gstatic.com https://www.medius.com https://www.podbean.com https://www.youtube.com 'self';object-src 'none';base-uri 'self';manifest-src 'self' 4 font-src maxcdn.bootstrapcdn.com fonts.googleapis.com fonts.gstatic.com *.paypal.com *.paypalobjects.com *.typekit.net *.gstatic.com applepay.cdn-apple.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de www.facebook.com *.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.youtube-nocookie.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de cdn.chatbot.com ct.pinterest.com *.criteo.com *.criteo.net www.facebook.com shop4runners.cr.rlvs.co.uk www.awin1.com d.c.cdnsrv.de mea.shop4runners.com mea.shop4runners.eu mea.shop4runners.at mea.shop4runners.ch mea.shop4runners.fr mea.runnershub.de mea.runnershub.bg mea.runnershub.eu *.attrxs.de *.getblue.io *.sovendus.com *.sovendus-connect.com bid.g.doubleclick.net td.doubleclick.net www.googletagmanager.com *.ad-srv.net *.paypal.com *.sandbox.paypal.com *.google.com js.mollie.com google.com https://c.paypal.com *.loadbee.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.payments-amazon.com *.salesmanago.pl *.salesmanago.es *.salesmanago.com magefan.com cm.magefan.com https: www.googleadservices.com *.g.doubleclick.net *.google-analytics.com *.analytics.google.com *.googletagmanager.com *.gstatic.com *.google.com *.google.de *.google.at *.google.ch *.google.eu *.google.fr https://images.unsplash.com *.paypal.com *.sandbox.paypal.com img.metaffiliation.com action.metaffiliation.com https://www.mollie.com https://api.mapbox.com https://c.paypal.com https://b.stats.paypal.com data: 'self' 'unsafe-inline'; script-src geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.salesmanago.pl *.salesmanago.es *.salesmanago.com *.chatarmin.com *.onefid.com maps.googleapis.com api.recova.ai assets.revlifter.io bat.bing.com cdn.chatbot.com *.consentmanager.net connect.facebook.net ct.pinterest.com s.pinimg.com *.criteo.com www.awin1.com www.dwin1.com the.sciencebehindecommerce.com www.ladenzeile.de tracking.s24.com d.c.cdnsrv.de smct.co s.uicdn.com *.attrxs.de *.gsitrix.com *.corporate-benefits.eu *.getblue.io *.wewomedia.com googleads.g.doubleclick.net www.google.com www.googleadservices.com www.google-analytics.com analytics.google.com *.googletagmanager.com tagmanager.google.com *.ad-srv.net *.paypal.com *.sandbox.paypal.com *.paypalobjects.com *.google.com *.cdn-apple.com action.metaffiliation.com img.metaffiliation.com s7.addthis.com js.mollie.com google.com https://c.paypal.com *.loadbee.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src maxcdn.bootstrapcdn.com fonts.googleapis.com *.googletagmanager.com tagmanager.google.com *.fontawesome.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com vimeo.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.salesmanago.pl *.salesmanago.es *.salesmanago.com https://api.batteryincluded.io *.chatarmin.com api.paypal.com maps.googleapis.com api.recova.ai devt.revlifter.com bat.bing.com bat.bing.net cdn.chatbot.com *.consentmanager.net www.facebook.com connect.facebook.net ct.pinterest.com www.pinterest.com *.criteo.com the.sciencebehindecommerce.com www.wepowerconnections.com tracking.s24.com mea.shop4runners.com mea.shop4runners.eu mea.shop4runners.at mea.shop4runners.ch mea.shop4runners.fr mea.runnershub.de mea.runnershub.bg mea.runnershub.eu r.nunami.ai *.gsitrix.com *.wewomedia.com *.sovendus.com *.sovendus-connect.com www.googleadservices.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com *.g.doubleclick.net *.google.com *.google.de *.google.at *.google.ch *.google.eu *.google.fr *.googlesyndication.com *.paypal.com *.sandbox.paypal.com action.metaffiliation.com img.metaffiliation.com ekr.zdassets.com/ google.com autocomplete2.postdirekt.de *.loadbee.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.salesmanago.pl *.salesmanago.es *.salesmanago.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 4 base-uri 'self' 'unsafe-inline'; report-uri https://8a41912f-2069-471c-8cfc-be803d04015d.sansec.watch/; report-to report-endpoint; 4 script-src 'unsafe-inline' 'unsafe-eval' blob: data: https://meet.google.com/_/scs/mss-static/_/js/ https://www.google.com/recaptcha/enterprise.js https://www.gstatic.com/hangouts_echo_detector/release/ https://www.gstatic.com/recaptcha/ https://www.gstatic.com/video_effects/effects/ https://www.gstatic.com/meetings_p2p/ https://www-onepick-opensocial.googleusercontent.com/gadgets/js/rpc.js https://www.gstatic.com/_/mss/boq-one-google/_/ https://www.gstatic.com/og/_/js/ https://apis.google.com/js/api.js https://apis.google.com/js/client.js https://www.google.com/tools/feedback/chat_load.js https://www.google.com/tools/feedback/help_api.js https://www.google.com/tools/feedback/load.js https://www.google.com/tools/feedback/open.js https://www.google.com/tools/feedback/open_to_help_guide_lazy.js https://www.gstatic.com/feedback/js/ https://www.gstatic.com/feedback/js/help/prod/service/lazy.min.js https://www.gstatic.com/inproduct_help/api/main.min.js https://www.gstatic.com/inproduct_help/chatsupport/chatsupport_button_v2.js https://www.gstatic.com/inproduct_help/service/lazy.min.js https://www.gstatic.com/uservoice/feedback/client/web/live/ https://www.gstatic.com/uservoice/surveys/resources/prod/js/survey/ https://meet.google.com/meetsw.js https://meet.google.com/devicesw.js https://meet.google.com/notrodsw.js https://www.googletagmanager.com/gtag/js https://www.google-analytics.com/analytics.js https://www.googletagmanager.com/gtag/destination https://meet.google.com/_/scs/mss-static/_/js/k=boq-rtc.MeetingsUi.en_US.ZU34hUF1L3o.2020.O/ https://apis.google.com/_/scs/abc-static/_/js/ https://www.gstatic.com/recaptcha/releases/;report-uri /_/MeetingsUi/cspreport/fine-allowlist 4 default-src https:; script-src https: 'unsafe-eval' 'unsafe-inline'; style-src https: 'unsafe-inline'; img-src https: data: blob:; font-src https: data:; report-uri /csp-report 4 script-src 'unsafe-eval' blob: 'self' https: 'self' data: 'unsafe-inline' 'unsafe-eval' blob: 'unsafe-inline' internal-soap.wikia.com internal-soap.fandom.com internal-soap.wikia.org internal-soap.gamepedia.com www.fandom.com www.wikia.com www.wikia.org www.gamepedia.com; default-src 'self' data: blob: https://images.wikia.com https://static.wikia.nocookie.net https: 'self' data: blob: internal-soap.wikia.com internal-soap.fandom.com internal-soap.wikia.org internal-soap.gamepedia.com www.fandom.com www.wikia.com www.wikia.org www.gamepedia.com; style-src 'self' data: blob: https://images.wikia.com https://static.wikia.nocookie.net https: 'self' data: blob: internal-soap.wikia.com internal-soap.fandom.com internal-soap.wikia.org internal-soap.gamepedia.com www.fandom.com www.wikia.com www.wikia.org www.gamepedia.com 'unsafe-inline'; img-src * data: blob:; object-src 'none'; report-uri https://services.fandom.com/csp-logger/csp/ucp; worker-src 'self' blob: 4 default-src 'self' data: wss://gruefbpuubghniw5iflbf2a6im.appsync-api.us-east-1.amazonaws.com/graphql wss://gruefbpuubghniw5iflbf2a6im.appsync-realtime-api.us-east-1.amazonaws.com/graphql s3.amazonaws.com/uploads.knowbe4.com/ api-js.mixpanel.com app.pendo.io btb-glossary-bucket-production-us-east-1.s3.amazonaws.com https://browser-intake-datadoghq.com/ cdn.pendo.io data.pendo.io deepfake-content-write-production-us-east-1.s3.amazonaws.com deepfake-content-read-production-us-east-1.s3.amazonaws.com fonts.googleapis.com metrics.articulate.com modstore.knowbe4.com modstore-production-us-east-1.s3.amazonaws.com https://*.knowbe4.com https://*.kb4od.run https://*.ckeditor.com/ https://*.launchdarkly.com/ https://*.zopim.com/ https://api-js.mixpanel.com https://api.mixpanel.com/ https://cdnjs.cloudflare.com/ https://code.highcharts.com/ https://data.pendo.io/ https://ekr.zdassets.com/ https://ekr.zendesk.com/ https://knowbe4.zendesk.com/ https://knowbe4.zendesk.com/embeddable/config https://knowbe4.zendesk.com/embeddable_blip https://knowbe4.zendesk.com/frontendevents/dl https://knowbe4.zendesk.com/frontendevents/pv https://s3.amazonaws.com/development.uploads.knowbe4.com/ https://s3.amazonaws.com/kmsat-development.uploads.knowbe4.com/ https://s3.amazonaws.com/helpimg/ https://s3.amazonaws.com/helpimg-kmsat-development-us-east-1/ https://helpimg.s3.amazonaws.com/ https://static.zdassets.com/ https://zendesk-eu.my.sentry.io/ pendo-static-6167502888239104.storage.googleapis.com wss://*.zopim.com/ wss://knowbe4.zendesk.com/ ; child-src 'self' blob: ; connect-src 'self' data: blob: wss://gruefbpuubghniw5iflbf2a6im.appsync-api.us-east-1.amazonaws.com/graphql wss://gruefbpuubghniw5iflbf2a6im.appsync-realtime-api.us-east-1.amazonaws.com/graphql s3.amazonaws.com/uploads.knowbe4.com/ api-js.mixpanel.com app.pendo.io btb-glossary-bucket-production-us-east-1.s3.amazonaws.com https://browser-intake-datadoghq.com/ cdn.pendo.io data.pendo.io deepfake-content-write-production-us-east-1.s3.amazonaws.com deepfake-content-read-production-us-east-1.s3.amazonaws.com fonts.googleapis.com metrics.articulate.com modstore.knowbe4.com modstore-production-us-east-1.s3.amazonaws.com https://*.knowbe4.com https://*.kb4od.run https://*.ckeditor.com/ https://*.launchdarkly.com/ https://*.zopim.com/ https://api-js.mixpanel.com https://api.mixpanel.com/ https://cdnjs.cloudflare.com/ https://code.highcharts.com/ https://data.pendo.io/ https://ekr.zdassets.com/ https://ekr.zendesk.com/ https://knowbe4.zendesk.com/ https://knowbe4.zendesk.com/embeddable/config https://knowbe4.zendesk.com/embeddable_blip https://knowbe4.zendesk.com/frontendevents/dl https://knowbe4.zendesk.com/frontendevents/pv https://s3.amazonaws.com/development.uploads.knowbe4.com/ https://s3.amazonaws.com/kmsat-development.uploads.knowbe4.com/ https://s3.amazonaws.com/helpimg/ https://s3.amazonaws.com/helpimg-kmsat-development-us-east-1/ https://helpimg.s3.amazonaws.com/ https://static.zdassets.com/ https://zendesk-eu.my.sentry.io/ pendo-static-6167502888239104.storage.googleapis.com wss://*.zopim.com/ wss://knowbe4.zendesk.com/ ; frame-src 'self' blob: wss://gruefbpuubghniw5iflbf2a6im.appsync-api.us-east-1.amazonaws.com/graphql wss://gruefbpuubghniw5iflbf2a6im.appsync-realtime-api.us-east-1.amazonaws.com/graphql s3.amazonaws.com/uploads.knowbe4.com/ api-js.mixpanel.com app.pendo.io btb-glossary-bucket-production-us-east-1.s3.amazonaws.com https://browser-intake-datadoghq.com/ cdn.pendo.io data.pendo.io deepfake-content-write-production-us-east-1.s3.amazonaws.com deepfake-content-read-production-us-east-1.s3.amazonaws.com fonts.googleapis.com metrics.articulate.com modstore.knowbe4.com modstore-production-us-east-1.s3.amazonaws.com https://*.knowbe4.com https://*.kb4od.run https://*.ckeditor.com/ https://*.launchdarkly.com/ https://*.zopim.com/ https://api-js.mixpanel.com https://api.mixpanel.com/ https://cdnjs.cloudflare.com/ https://code.highcharts.com/ https://data.pendo.io/ https://ekr.zdassets.com/ https://ekr.zendesk.com/ https://knowbe4.zendesk.com/ https://knowbe4.zendesk.com/embeddable/config https://knowbe4.zendesk.com/embeddable_blip https://knowbe4.zendesk.com/frontendevents/dl https://knowbe4.zendesk.com/frontendevents/pv https://s3.amazonaws.com/development.uploads.knowbe4.com/ https://s3.amazonaws.com/kmsat-development.uploads.knowbe4.com/ https://s3.amazonaws.com/helpimg/ https://s3.amazonaws.com/helpimg-kmsat-development-us-east-1/ https://helpimg.s3.amazonaws.com/ https://static.zdassets.com/ https://zendesk-eu.my.sentry.io/ pendo-static-6167502888239104.storage.googleapis.com wss://*.zopim.com/ wss://knowbe4.zendesk.com/ android-webview-video-poster: https://player.vimeo.com https://*.ccm.knowbe4.com https://*.internal.knowbe4.com https://*.ccm.internal.knowbe4.com ; font-src 'self' data: fonts.gstatic.com helpimg.s3.amazonaws.com use.fontawesome.com use.typekit.net https://cdnjs.cloudflare.com/ajax/libs/twitter-bootstrap/ ; img-src * 'self' blob: cid: data: file: android-webview-video-poster: https://cdn.mxpnl.com/ https://v2assets.zopim.io/ https://static.zdassets.com/ app.pendo.io cdn.pendo.io data.pendo.io pendo-static-6167502888239104.storage.googleapis.com ; media-src 'self' about: blob: data: wss://gruefbpuubghniw5iflbf2a6im.appsync-api.us-east-1.amazonaws.com/graphql wss://gruefbpuubghniw5iflbf2a6im.appsync-realtime-api.us-east-1.amazonaws.com/graphql s3.amazonaws.com/uploads.knowbe4.com/ api-js.mixpanel.com app.pendo.io btb-glossary-bucket-production-us-east-1.s3.amazonaws.com https://browser-intake-datadoghq.com/ cdn.pendo.io data.pendo.io deepfake-content-write-production-us-east-1.s3.amazonaws.com deepfake-content-read-production-us-east-1.s3.amazonaws.com fonts.googleapis.com metrics.articulate.com modstore.knowbe4.com modstore-production-us-east-1.s3.amazonaws.com https://*.knowbe4.com https://*.kb4od.run https://*.ckeditor.com/ https://*.launchdarkly.com/ https://*.zopim.com/ https://api-js.mixpanel.com https://api.mixpanel.com/ https://cdnjs.cloudflare.com/ https://code.highcharts.com/ https://data.pendo.io/ https://ekr.zdassets.com/ https://ekr.zendesk.com/ https://knowbe4.zendesk.com/ https://knowbe4.zendesk.com/embeddable/config https://knowbe4.zendesk.com/embeddable_blip https://knowbe4.zendesk.com/frontendevents/dl https://knowbe4.zendesk.com/frontendevents/pv https://s3.amazonaws.com/development.uploads.knowbe4.com/ https://s3.amazonaws.com/kmsat-development.uploads.knowbe4.com/ https://s3.amazonaws.com/helpimg/ https://s3.amazonaws.com/helpimg-kmsat-development-us-east-1/ https://helpimg.s3.amazonaws.com/ https://static.zdassets.com/ https://zendesk-eu.my.sentry.io/ pendo-static-6167502888239104.storage.googleapis.com wss://*.zopim.com/ wss://knowbe4.zendesk.com/ ; object-src 'self' ; script-src 'self' 'unsafe-inline' 'unsafe-eval' blob: wss://gruefbpuubghniw5iflbf2a6im.appsync-api.us-east-1.amazonaws.com/graphql wss://gruefbpuubghniw5iflbf2a6im.appsync-realtime-api.us-east-1.amazonaws.com/graphql s3.amazonaws.com/uploads.knowbe4.com/ api-js.mixpanel.com app.pendo.io btb-glossary-bucket-production-us-east-1.s3.amazonaws.com https://browser-intake-datadoghq.com/ cdn.pendo.io data.pendo.io deepfake-content-write-production-us-east-1.s3.amazonaws.com deepfake-content-read-production-us-east-1.s3.amazonaws.com fonts.googleapis.com metrics.articulate.com modstore.knowbe4.com modstore-production-us-east-1.s3.amazonaws.com https://*.knowbe4.com https://*.kb4od.run https://*.ckeditor.com/ https://*.launchdarkly.com/ https://*.zopim.com/ https://api-js.mixpanel.com https://api.mixpanel.com/ https://cdnjs.cloudflare.com/ https://code.highcharts.com/ https://data.pendo.io/ https://ekr.zdassets.com/ https://ekr.zendesk.com/ https://knowbe4.zendesk.com/ https://knowbe4.zendesk.com/embeddable/config https://knowbe4.zendesk.com/embeddable_blip https://knowbe4.zendesk.com/frontendevents/dl https://knowbe4.zendesk.com/frontendevents/pv https://s3.amazonaws.com/development.uploads.knowbe4.com/ https://s3.amazonaws.com/kmsat-development.uploads.knowbe4.com/ https://s3.amazonaws.com/helpimg/ https://s3.amazonaws.com/helpimg-kmsat-development-us-east-1/ https://helpimg.s3.amazonaws.com/ https://static.zdassets.com/ https://zendesk-eu.my.sentry.io/ pendo-static-6167502888239104.storage.googleapis.com wss://*.zopim.com/ wss://knowbe4.zendesk.com/ pendo-io-static.storage.googleapis.com pendo-static-6167502888239104.storage.googleapis.com use.typekit.net ; script-src-elem 'self' 'unsafe-inline' 'unsafe-eval' blob: data: wss://gruefbpuubghniw5iflbf2a6im.appsync-api.us-east-1.amazonaws.com/graphql wss://gruefbpuubghniw5iflbf2a6im.appsync-realtime-api.us-east-1.amazonaws.com/graphql s3.amazonaws.com/uploads.knowbe4.com/ api-js.mixpanel.com app.pendo.io btb-glossary-bucket-production-us-east-1.s3.amazonaws.com https://browser-intake-datadoghq.com/ cdn.pendo.io data.pendo.io deepfake-content-write-production-us-east-1.s3.amazonaws.com deepfake-content-read-production-us-east-1.s3.amazonaws.com fonts.googleapis.com metrics.articulate.com modstore.knowbe4.com modstore-production-us-east-1.s3.amazonaws.com https://*.knowbe4.com https://*.kb4od.run https://*.ckeditor.com/ https://*.launchdarkly.com/ https://*.zopim.com/ https://api-js.mixpanel.com https://api.mixpanel.com/ https://cdnjs.cloudflare.com/ https://code.highcharts.com/ https://data.pendo.io/ https://ekr.zdassets.com/ https://ekr.zendesk.com/ https://knowbe4.zendesk.com/ https://knowbe4.zendesk.com/embeddable/config https://knowbe4.zendesk.com/embeddable_blip https://knowbe4.zendesk.com/frontendevents/dl https://knowbe4.zendesk.com/frontendevents/pv https://s3.amazonaws.com/development.uploads.knowbe4.com/ https://s3.amazonaws.com/kmsat-development.uploads.knowbe4.com/ https://s3.amazonaws.com/helpimg/ https://s3.amazonaws.com/helpimg-kmsat-development-us-east-1/ https://helpimg.s3.amazonaws.com/ https://static.zdassets.com/ https://zendesk-eu.my.sentry.io/ pendo-static-6167502888239104.storage.googleapis.com wss://*.zopim.com/ wss://knowbe4.zendesk.com/ https://unpkg.com/vue@2.6.14 pendo-io-static.storage.googleapis.com pendo-static-6167502888239104.storage.googleapis.com use.typekit.net https://cdn.pendo.io/agent/static/365392a9-6608-44ef-443b-572eef771b95/pendo.js ; style-src 'self' 'unsafe-inline' data: app.pendo.io cdn.pendo.io fonts.gstatic.com https://cdnjs.cloudflare.com/ajax/libs/twitter-bootstrap/ pendo-static-6167502888239104.storage.googleapis.com use.typekit.net ; style-src-elem 'self' 'unsafe-inline' data: app.pendo.io cdn.pendo.io fonts.googleapis.com fonts.gstatic.com helpimg.s3.amazonaws.com cdnjs.cloudflare.com/ajax/libs/font-awesome/ cdnjs.cloudflare.com/ajax/libs/twitter-bootstrap/ p.typekit.net pendo-static-6167502888239104.storage.googleapis.com s3.amazonaws.com/helpimg/ use.fontawesome.com use.typekit.net www.java.com/ga/css/print.css www.java.com/ga/css/screen.css ; report-uri https://csp-report.browser-intake-datadoghq.com/api/v2/logs?dd-api-key=pubf27996eb9977f34aa9f3376bd3939adc&dd-evp-origin=content-security-policy&ddsource=csp-report&app=kmsat&env=production-us-east-1 ; worker-src 'self' blob: data: ; 4 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com *.hotjar.com https://static.dhlecommerce.nl https://fonts.gstatic.com https://widgets.trustedshops.com *.fontawesome.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com *.googlesyndication.com *.tiktok.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.multisafepay.com https://pay.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com *.googletagmanager.com contact.robinhq.com https://*.dpdconnect.nl *.multisafepay.com https://pay.google.com www.xtento.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://images.unsplash.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.googlesyndication.com *.roeye.com *.tiktok.com blackhole.lan:9000 bat.bing.com bat.bing.net https://maps.googleapis.com https://maps.gstatic.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com *.etrusted.com magefan.com cm.magefan.com *.disqus.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://firebasestorage.googleapis.com *.sooqr.com *.spotlersearch.com *.multisafepay.com www.xtento.com cdn.xtento.com maps.googleapis.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://maps.googleapis.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.google.bg *.googletagmanager.com/ *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com https://cdn.jsdelivr.net *.tiktok.com selfservice.robinhq.com robincontentdesktop.blob.core.windows.net az416426.vo.msecnd.net *.googleads.g.doubleclick.net *.googleadservices.com *.cloudfront.net spotlersearchanalytics.com *.hotjar.com bat.bing.com https://*.dpdconnect.nl https://static.dhlecommerce.nl https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.etrusted.com *.disqus.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.avada.io *.shopify.com *.sooqr.com *.spotlersearch.com *.multisafepay.com https://pay.google.com www.xtento.com cdn.xtento.com maps.googleapis.com maps.google.apis.com cdn-4.convertexperiments.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com *.tiktok.com https://static.dhlecommerce.nl https://maps.googleapis.com https://fonts.googleapis.com https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.etrusted.com https://static.klaviyo.com https://cdn.jsdelivr.net *.fontawesome.com https://fonts.bunny.net *.sooqr.com *.spotlersearch.com *.multisafepay.com maps.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://maps.googleapis.com https://player.vimeo.com *.facebook.com *.facebook.net *.doubleclick.net *.googlesyndication.com *.tiktok.com dc.services.visualstudio.com *.visualwebsiteoptimizer.com p2iqhncxyh.execute-api.eu-central-1.amazonaws.com bat.bing.com bat.bing.net *.hotjar.com https://api-gw.dhlparcel.nl https://static.dhlecommerce.nl *.trustedshops.com *.etrusted.com https://integrations.etrusted.site https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://get.geojs.io *.avada.io *.sooqr.com *.spotlersearch.com *.multisafepay.com maps.googleapis.com maps.google.apis.com cdn-4.convertexperiments.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 4 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com data: *.fontawesome.com maxcdn.bootstrapcdn.com *.cloudflare.com *.bootstrapcdn.com *.flixcar.com *.flixfacts.com https://ocular-prod.api.rocio.ai *.ocularsolution.com https://accvent.com *.accvent.com https://forzaups.com *.forzaups.com https://firalivepro.blob.core.windows.net *.firalivepro.blob.core.windows.net https://fira-live-player-pro.azurewebsites.net/ https://fira-live-management-api-pro.azurewebsites.net https://www.lg.com/cac https://analytics.tiktok.com *.firaonlive.com *.assets.adobedtm.com *.grupomonge.tt.omtrdc.net *.smetrics.tiendamonge.com *.grupomonge.demdex.net *.s7d1.scene7.com/ http://fonts.cdnfonts.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.facebook.com credomatic.compassmerchantsolutions.com https://www.tiendamonge.com/nps-check-out-tlv-guatemala https://www.tiendamonge.com/nps-entrega-tienda-en-linea-cr https://www.tiendamonge.com/nps-entrega-tienda-en-linea-el-salvador https://www.tiendamonge.com/nps-entrega-tienda-en-linea-guatemala https://www.tiendamonge.com/nps-entrega-tienda-en-linea-honduras https://www.tiendamonge.com/nps-entrega-tienda-en-linea-ni https://www.tiendamonge.com/nps-gracias-por-completar-la-encuesta https://www.tiendamonge.com/nps-gracias-por-completar-la-encuesta-monge-pay https://www.tiendamonge.com/nps-monge-pay-desembolso-cash https://www.tiendamonge.com/nps-monge-pay-liveness https://www.tiendamonge.com/nps-monge-pay-pago-a-tarjeta-monge https://www.tiendamonge.com/nps-monge-pay-pago-operaciones https://www.tiendamonge.com/nps-monge-pay-registro https://www.tiendamonge.com/nps-service-desk-ti-costa-rica https://ocular-prod.api.rocio.ai *.ocularsolution.com https://accvent.com *.accvent.com https://forzaups.com *.forzaups.com https://firalivepro.blob.core.windows.net *.firalivepro.blob.core.windows.net https://fira-live-player-pro.azurewebsites.net/ https://fira-live-management-api-pro.azurewebsites.net https://www.lg.com/cac https://analytics.tiktok.com *.firaonlive.com *.assets.adobedtm.com *.grupomonge.tt.omtrdc.net *.smetrics.tiendamonge.com *.grupomonge.demdex.net *.s7d1.scene7.com/ 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.youtube.com *.vimeo.com mongepay.com conway.ddev.site https://ocular-prod.api.rocio.ai *.ocularsolution.com https://accvent.com *.accvent.com https://forzaups.com *.forzaups.com https://firalivepro.blob.core.windows.net *.firalivepro.blob.core.windows.net https://fira-live-player-pro.azurewebsites.net/ https://fira-live-management-api-pro.azurewebsites.net https://www.lg.com/cac https://analytics.tiktok.com *.firaonlive.com *.assets.adobedtm.com *.grupomonge.tt.omtrdc.net *.smetrics.tiendamonge.com *.grupomonge.demdex.net *.s7d1.scene7.com/ 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com www.google.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://www.googletagmanager.com/ https://adobedtm.com assets.adobedtm.com dpm.demdex.net *.googleapis.com *.googletagmanager.com *.facebook.com *.google-analytics.com *.googleadservices.com *.facebook.net grupomongegrupomongedev.112.2o7.net grupomonge.tt.omtrdc.net *.demdex.net *.doubleclick.net bam-cell.nr-data.net smetrics.tiendamonge.com smetrics.elgallomasgallo.com.gt smetrics.elgallomasgallo.com.hn smetrics.prado.com.sv smetrics.elgallomasgallo.com.ni https://www.facebook.com https://www.google.com *.flixcar.com *.flixfacts.com *.cnetcontent.com *.vimeo.com https://widgetapp.ocularsolution.com *.getblue.io *.flipsnack.com https://heyzine.com https://promogallonic.com https://front-notrack.indexado.production.pmbox.cloud https://fichashppervasive.blob.core.windows.net https://www.tiendamonge.com/nps-check-out-tlv-guatemala https://www.tiendamonge.com/nps-entrega-tienda-en-linea-cr https://www.tiendamonge.com/nps-entrega-tienda-en-linea-el-salvador https://www.tiendamonge.com/nps-entrega-tienda-en-linea-guatemala https://www.tiendamonge.com/nps-entrega-tienda-en-linea-honduras https://www.tiendamonge.com/nps-entrega-tienda-en-linea-ni https://www.tiendamonge.com/nps-gracias-por-completar-la-encuesta https://www.tiendamonge.com/nps-gracias-por-completar-la-encuesta-monge-pay https://www.tiendamonge.com/nps-monge-pay-desembolso-cash https://www.tiendamonge.com/nps-monge-pay-liveness https://www.tiendamonge.com/nps-monge-pay-pago-a-tarjeta-monge https://www.tiendamonge.com/nps-monge-pay-pago-operaciones https://www.tiendamonge.com/nps-monge-pay-registro https://www.tiendamonge.com/nps-service-desk-ti-costa-rica https://notrack.indexado.pmbox.cloud https://emersya.com https://ocular-prod.api.rocio.ai *.ocularsolution.com *.mabeindex.com https://accvent.com *.accvent.com https://forzaups.com *.forzaups.com https://firalivepro.blob.core.windows.net *.firalivepro.blob.core.windows.net https://fira-live-player-pro.azurewebsites.net/ https://fira-live-management-api-pro.azurewebsites.net https://www.lg.com/cac https://sandbox.migopayments.com/ https://web.migopayments.com/ https://online.fliphtml5.com/ https://analytics.tiktok.com *.firaonlive.com *.assets.adobedtm.com *.grupomonge.tt.omtrdc.net *.smetrics.tiendamonge.com *.grupomonge.demdex.net *.s7d1.scene7.com/ https://fledge.teads.tv *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com *.grupomonge.tt.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.googleapis.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ *.cloudflare.com widget.ocularsolution.com *.newrelic.com https://bam.nr-data.net *.facebook.com *.connect.facebook.net *.google.com *.google-analytics.com *.googleadservices.com *.flixcar.com *.flixfacts.com *.flix360.com *.flix360.io *.syndigo.com *.syndigo.cloud https://www.google.com https://www.google.com.co https://www.tiendamonge.com https://www.elgallomasgallo.com.ni https://www.prado.com.sv https://www.elgallomasgallo.com.hn https://www.elgallomasgallo.com.gt https://www.verdugotienda.com *.teads.tv *.scene7.com https://fichashppervasive.blob.core.windows.net https://ocular-prod.api.rocio.ai *.ocularsolution.com *.mabeindex.com https://accvent.com *.accvent.com https://forzaups.com *.forzaups.com https://firalivepro.blob.core.windows.net *.firalivepro.blob.core.windows.net https://fira-live-player-pro.azurewebsites.net/ https://fira-live-management-api-pro.azurewebsites.net https://www.lg.com/cac https://gmgdocumentos.blob.core.windows.net/ https://gmgecommerceprd.blob.core.windows.net/ https://analytics.tiktok.com *.firaonlive.com *.assets.adobedtm.com *.smetrics.tiendamonge.com *.grupomonge.demdex.net *.s7d1.scene7.com https://www.google.com.ar data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com *.vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://rum.hlx.page *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ https://adobedtm.com fast.amc.demdex.net dpm.demdex.net *.googletagmanager.com *.facebook.com *.google-analytics.com *.googleadservices.com *.facebook.net grupomongegrupomongedev.112.2o7.net grupomonge.tt.omtrdc.net *.demdex.net *.doubleclick.net bam-cell.nr-data.net smetrics.tiendamonge.com smetrics.elgallomasgallo.com.gt smetrics.elgallomasgallo.com.hn smetrics.prado.com.sv smetrics.elgallomasgallo.com.ni 'unsafe-inline' widget.ocularsolution.com cdn.cs.1worldsync.com https://ws.cs.1worldsync.com *.cloudflare.com https://bam.nr-data.net *.connect.facebook.net *.paypal.com *.bootstrapcdn.com *.flixcar.com *.flixfacts.com *.flix360.com *.flix360.io *.pingdom.net *.woorank.com *.cnetcontent.com *.syndigo.com *.syndigo.cloud https://event.getblue.io *.getblue.io https://p.teads.tv https://smetrics.verdugotienda.com https://rocio.ocularsolution.com https://ocular-prod.api.rocio.ai *.ocularsolution.com *.mabeindex.com https://accvent.com *.accvent.com https://forzaups.com *.forzaups.com https://firalivepro.blob.core.windows.net *.firalivepro.blob.core.windows.net https://fira-live-player-pro.azurewebsites.net/ https://fira-live-management-api-pro.azurewebsites.net https://www.lg.com/cac https://analytics.tiktok.com *.firaonlive.com *.assets.adobedtm.com *.grupomonge.tt.omtrdc.net *.smetrics.tiendamonge.com *.grupomonge.demdex.net *.s7d1.scene7.com/ https://grupomongeecommerceprd.112.2o7.net http://fonts.cdnfonts.com maps.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com maxcdn.bootstrapcdn.com *.cloudflare.com widget.ocularsolution.com *.facebook.com *.google.com *.googleapis.com *.gstatic.com *.bootstrapcdn.com *.flixcar.com *.flixfacts.com rocio.ocularsolution.com https://ocular-prod.api.rocio.ai *.ocularsolution.com https://accvent.com *.accvent.com https://forzaups.com *.forzaups.com https://firalivepro.blob.core.windows.net *.firalivepro.blob.core.windows.net https://fira-live-player-pro.azurewebsites.net/ https://fira-live-management-api-pro.azurewebsites.net https://www.lg.com/cac https://analytics.tiktok.com *.firaonlive.com *.assets.adobedtm.com *.grupomonge.tt.omtrdc.net *.smetrics.tiendamonge.com *.grupomonge.demdex.net *.s7d1.scene7.com/ http://fonts.cdnfonts.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ *.flixcar.com widget.ocularsolution.com *.flixfacts.com *.flix360.com *.flix360.io *.syndigo.com *.syndigo.cloud https://emersya.com https://ocular-prod.api.rocio.ai *.ocularsolution.com *.mabeindex.com https://accvent.com *.accvent.com https://forzaups.com *.forzaups.com https://firalivepro.blob.core.windows.net *.firalivepro.blob.core.windows.net https://fira-live-player-pro.azurewebsites.net/ https://fira-live-management-api-pro.azurewebsites.net https://www.lg.com/cac https://gmgdocumentos.blob.core.windows.net/ https://gmgecommerceprd.blob.core.windows.net/ https://analytics.tiktok.com *.firaonlive.com *.assets.adobedtm.com *.grupomonge.tt.omtrdc.net *.smetrics.tiendamonge.com *.grupomonge.demdex.net *.s7d1.scene7.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net *.grupomonge.tt.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io *.googleapis.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ https://adobedtm.com assets.adobedtm.com *.adobe.com fast.amc.demdex.net *.googletagmanager.com *.facebook.com *.google-analytics.com *.googleadservices.com *.facebook.net grupomongegrupomongedev.112.2o7.net grupomonge.tt.omtrdc.net *.demdex.net *.doubleclick.net bam-cell.nr-data.net smetrics.tiendamonge.com smetrics.elgallomasgallo.com.gt smetrics.elgallomasgallo.com.hn smetrics.prado.com.sv smetrics.elgallomasgallo.com.ni wss://tm.filter:1502/ api.ocularsolution.com xml.ssreviewsportal.com *.cloudflare.com https://bam.nr-data.net *.pingdom.net *.woorank.com *.cnetcontent.com *.youtube.com *.syndigo.com *.syndigo.cloud product-feature-service.production.alquimio.cloud api.repositorio.production.alquimio.cloud orchestrator.production.aks.alquimio.cloud *.teads.tv https://ocular-prod.api.rocio.ai *.ocularsolution.com *.flixcar.com https://accvent.com *.accvent.com https://forzaups.com *.forzaups.com https://firalivepro.blob.core.windows.net *.firalivepro.blob.core.windows.net https://fira-live-player-pro.azurewebsites.net/ https://fira-live-management-api-pro.azurewebsites.net https://www.lg.com/cac https://sandbox.migopayments.com/ https://web.migopayments.com/ https://analytics.tiktok.com *.firaonlive.com https://smetrics.verdugotienda.com *.assets.adobedtm.com *.smetrics.tiendamonge.com *.grupomonge.demdex.net *.s7d1.scene7.com/ 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 4 frame-src 'self' td.doubleclick.net youtube.com *.youtube.com; report-uri /infra/monitoring/csp 4 font-src x.klarnacdn.net static.lipscore.com maxcdn.bootstrapcdn.com *.gstatic.com 'self' data: https://widgets.trustedshops.com *.cloudflare.com *.klarnacdn.net *.typekit.net data: 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; form-action *.facebook.com *.perfectview.nl *.visualwebsiteoptimizer.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; frame-ancestors *.multisafepay.com https://pay.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ osm.klarnaservices.com *.prismic.io sst.kitchenyeah.de ct.pinterest.com googletagmanager.com td.doubleclick.net *.multisafepay.com https://pay.google.com *.ad4m.at *.awin1.com deliverimages.com *.facebook.com *.formcrafts.com *.fotocadeau.nl *.google.com *.googletagmanager.com *.klarna.com *.mediacliphub.com *.noboringsuitcases.com *.opendns.com *.pinterest.com *.sleak.chat *.sovendus-connect.com *.visualwebsiteoptimizer.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com data: widgets.magentocommerce.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com *.google-analytics.com *.analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://images.unsplash.com bat.bing.com *.cdn.prismic.io www.facebook.com www.google.nl *.appspot.com images.prismic.io storage.googleapis.com raw.githubusercontent.com *.taggrs.io *.prism.app-us1.com *.prismic.io static.lipscore.com blob: img.youtube.com *.multisafepay.com *.hsforms.net *.hsforms.com 'self' data: https://widgets.trustedshops.com https://widgets-qa.trustedshops.com *.etrusted.com *.awin1.com *.bing.com *.bing.net bucket-ip-website.s3.eu-central-1.amazonaws.com *.clarity.ms deliverimages.com *.doubleclick.net *.facebook.com *.facebook.net *.fotocadeau.nl *.googleadservices.com *.googleapis.com www.google.ad www.google.ae www.google.al www.google.am www.google.at www.google.az www.google.ba www.google.be www.google.bg www.google.bi www.google.bj www.google.bs www.google.by www.google.ca www.google.cd www.google.ch www.google.ci www.google.cl www.google.cm www.google.co.cr www.google.co.id www.google.co.il www.google.co.in www.google.co.jp www.google.co.ke www.google.co.kr www.google.co.ma www.google.com.af www.google.com.ar www.google.com.au www.google.com.bd www.google.com.bo www.google.com.br www.google.com.co www.google.com.cy www.google.com.do www.google.com.ec www.google.com.eg www.google.com.et www.google.com.gh www.google.com.hk www.google.com.jm www.google.com.kh www.google.com.kw www.google.com.lb www.google.com.ly www.google.com.mt www.google.com.mx www.google.com.my www.google.com.na www.google.com.ng www.google.com.ni www.google.com.np www.google.com.om www.google.com.pa www.google.com.pe www.google.com.ph www.google.com.pk www.google.com.py www.google.com.qa www.google.com.sa www.google.com.sg www.google.com.tr www.google.com.tw www.google.com.ua www.google.com.vn www.google.co.mz www.google.co.nz www.google.co.th www.google.co.tz www.google.co.ug www.google.co.uk www.google.co.uz www.google.co.ve www.google.co.za www.google.co.zm www.google.co.zw www.google.cv www.google.cz www.google.de www.google.dk www.google.dm www.google.dz www.google.ee www.google.es www.google.fi www.google.fr www.google.ga www.google.ge www.google.gm www.google.gr www.google.hr www.google.ht www.google.hu www.google.ie www.google.im www.google.iq www.google.is www.google.it www.google.je www.google.jo www.google.kg www.google.kz www.google.la www.google.li www.google.lk www.google.lt www.google.lu www.google.lv www.google.md www.google.me www.google.mg www.google.mk www.google.mn www.google.mu www.google.mv www.google.no www.google.pl www.google.pt www.google.ro www.google.rs www.google.ru www.google.rw www.google.sc www.google.se www.google.si www.google.sk www.google.sm www.google.sn www.google.sr www.google.tn *.google.com google.com *.googlesyndication.com *.googletagmanager.com *.gstatic.com *.hscollectedforms.net *.hubspot.com *.klarnacdn.net *.klarnaevt.com *.linkedin.com *.lipscore.com *.mediacliphub.com noboringsuitcases.com *.noboringsuitcases.com *.perfectview.nl *.pinterest.com prismic-io.s3.amazonaws.com *.roeye.com *.sleak.chat *.tiktok.com *.tiktokw.us *.trustedshops.com *.visualwebsiteoptimizer.com *.webflow.com *.wepowerconnections.com data: 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; script-src assets.adobedtm.com *.adobe.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ js.klarna.com js.klarnaservices.com bat.bing.com ct.pinterest.com d5yoctgpv4cpx.cloudfront.net connect.facebook.net magento.fcdev metrics.fotoopaluminium.nl metrics.self s.pinimg.com *.appspot.com stapecdn.com static.cdn.prismic.io static.hotjar.com static.mediacliphub.com widgets.trustedshops.com www.clarity.ms *.taggrs.io *.prism.app-us1.com *.prismic.io https://widget-acc.paazl.com https://api-acc.paazl.com/ static.lipscore.com *.multisafepay.com https://pay.google.com *.hsforms.net *.hsforms.com *.google.com *.gstatic.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.etrusted.com *.awin1.com *.bing.com *.clarity.ms *.deployteq-cdp.net *.doubleclick.net *.dwin1.com *.facebook.net *.formcrafts.com *.googleapis.com translate.google.com.hk *.googlesyndication.com *.googletagmanager.com *.hotjar.com *.hsadspixel.net *.hs-analytics.net *.hs-banner.com *.hscollectedforms.net *.hs-scripts.com *.hubspot.com *.jsdelivr.net *.klarna.com *.leadinfo.net *.licdn.com *.lipscore.com *.mediacliphub.com *.pinimg.com *.pinterest.com prismic.io *.roeyecdn.com *.sleak.chat *.sovendus.com *.tiktok.com *.trustedshops.com *.visualwebsiteoptimizer.com *.zdassets.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; style-src *.adobe.com x.klarnacdn.net integrations.etrusted.com https://widget-acc.paazl.com https://api-acc.paazl.com/ static.lipscore.com maxcdn.bootstrapcdn.com *.multisafepay.com *.googleapis.com *.gstatic.com https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.etrusted.com *.cloudflare.com *.googletagmanager.com *.klarnacdn.net *.lipscore.com *.sleak.chat *.typekit.net 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; object-src deliverimages.com *.fotocadeau.nl *.googleapis.com *.mediacliphub.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; media-src *.adobe.com *.fotocadeau.nl *.gstatic.com noboringsuitcases.com *.noboringsuitcases.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.googleadservices.com *.google-analytics.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net js.klarnaservices.com js.klarna.com na.klarnaevt.com *.clarity.ms *.appspot.com ct.pinterest.com dc.services.visualstudio.com js.monitor.azure.com region1.analytics.google.com *.sentry.io *.prism.app-us1.com *.prismic.io https://widget-acc.paazl.com https://api-acc.paazl.com/ wapi.lipscore.com users.lipscore.com *.multisafepay.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.trustedshops.com *.etrusted.com https://integrations.etrusted.site *.algolia.io *.algolia.net *.algolianet.com *.azure.com *.bing.com *.bing.net deliverimages.com *.deployteq-cdp.net *.doubleclick.net *.facebook.com *.facebook.net *.fotoophout.nl *.googleadservices.com *.googleapis.com google.com *.google.com *.googlesyndication.com *.hotjar.com *.hotjar.io *.hscollectedforms.net *.hubapi.com *.klarna.com *.klarnaevt.com *.leadinfo.com *.leadinfo.net *.linkedin.com *.lipscore.com *.make.com *.mediacliphub.com *.noboringsuitcases.com p2iqhncxyh.execute-api.eu-central-1.amazonaws.com *.pinterest.com polyfilljs.org *.sleak.chat *.sovendus.com *.tiktok.com *.tiktokw.us *.visualwebsiteoptimizer.com *.wepowerconnections.com *.zdassets.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.mediacliphub.com *.appspot.com *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri *.leadinfo.com *.lipscore.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; report-uri https://0857a1ae-eb26-4f26-b573-76e7e6a78da5.sansec.watch/; report-to report-endpoint; 4 font-src https://cdn.checkout.com *.fontawesome.com maxcdn.bootstrapcdn.com fonts.gstatic.com https://fonts.gstatic.com *.typekit.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * sandbox.przelewy24.pl secure.przelewy24.pl 'self' 'unsafe-inline'; frame-ancestors 'self' *.maksekeskus.ee *.test.maksekeskus.ee localhost *.local *.scandipwa.cloud *.readymage.com sportland.com *.sportland.com sportland.lv *.sportland.lv sportland.ee *.sportland.ee sportland.lt *.sportland.lt sportland.fi *.sportland.fi sportland.pl *.sportland.pl sportland.de *.sportland.de 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com https://js.checkout.com *.klarna.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com 'self' *.maksekeskus.ee *.test.maksekeskus.ee c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.google.com https://optimize.google.com https://play.google.com localhost *.local *.scandipwa.cloud *.readymage.com sportland.com *.sportland.com sportland.lv *.sportland.lv sportland.ee *.sportland.ee sportland.lt *.sportland.lt sportland.fi *.sportland.fi sportland.pl *.sportland.pl sportland.de *.sportland.de js.driftt.com *.freshchat.com *.snapchat.com *.askly.me www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.openstreetmap.org https://map.plugins.itella.com magefan.com cm.magefan.com *.maksekeskus.ee *.test.maksekeskus.ee https://maps.omnivasiunta.lt www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com static.przelewy24.pl www.gstatic.com gstatic.com https://www.google-analytics.com https://optimize.google.com *.googleapis.com *.gstatic.com www.google.lv localhost *.local *.scandipwa.cloud *.readymage.com sportland.com *.sportland.com sportland.lv *.sportland.lv sportland.ee *.sportland.ee sportland.lt *.sportland.lt sportland.fi *.sportland.fi sportland.pl *.sportland.pl sportland.de *.sportland.de *.cloudfront.net *.snapchat.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://cdn.checkout.com *.klarnacdn.net www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://unpkg.com s7.addthis.com 'self' *.maksekeskus.ee *.test.maksekeskus.ee data: js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com sandbox.przelewy24.pl secure.przelewy24.pl *.google.com www.googleoptimize.com *.google-analytics.com *.googleapis.com js.driftt.com *.freshchat.com inte.searchnode.io *.sitescdn.net *.fibbl.com *.hotjar.com sc-static.net *.snapchat.com *.googlesyndication.com *.translatewise.com *.bloomreach.com *.exponea.com *.sizebay.technology www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://cdn.checkout.com https://unpkg.com *.fontawesome.com maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com fonts.googleapis.com *.google.com https://www.google-analytics.com https://fonts.googleapis.com *.typekit.net *.freshchat.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://js.checkout.com *.klarnaevt.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://geocode.arcgis.com ekr.zdassets.com/ 'self' *.maksekeskus.ee *.test.maksekeskus.ee api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com sandbox.przelewy24.pl secure.przelewy24.pl wss://sandbox-ws.przelewy24.pl wss://secure-ws.przelewy24.pl apple-pay-gateway.apple.com *.fibblar.com *.fibbl.com www.gstatic.com *.google-analytics.com *.googleapis.com *.g.doubleclick.net *.scandipwa.cloud *.readymage.com *.sportland.com *.sportland.lv *.sportland.ee *.sportland.lt *.sportland.fi *.sportland.pl *.sportland.de blob: *.hotjar.com *.googlesyndication.com *.translatewise.com https://play.google.com *.bloomreach.com *.exponea.com *.sizebay.technology 'self' 'unsafe-inline'; child-src 'self' *.maksekeskus.ee *.test.maksekeskus.ee assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 4 default-src 'self'; script-src 'report-sample' 'self' https://js.qualified.com/qualified.js https://www.googletagmanager.com/gtm.js; style-src 'report-sample' 'self'; object-src 'none'; base-uri 'self'; connect-src 'self' https://app.qualified.com wss://ws.qualified.com; font-src 'self'; frame-src 'self' https://app.qualified.com; img-src 'self' data: https://dms6j3xpg18d6.cloudfront.net https://d3s86tfxelgbdj.cloudfront.net https://huntscanlon.com https://images.cointelegraph.com https://mma.prnewswire.com https://s.yimg.com; manifest-src 'self'; media-src 'self'; worker-src 'none'; 4 font-src fonts.gstatic.com 'self' data: embed.tawk.to data: 'self' 'unsafe-inline'; form-action 'self' 'unsafe-inline'; frame-ancestors *.multisafepay.com https://pay.google.com 'self'; frame-src https://www.google.com/recaptcha/ *.multisafepay.com https://pay.google.com js.mollie.com 'self' data: www.googletagmanager.com ct.pinterest.com 'self' 'unsafe-inline'; img-src data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypalobjects.com *.multisafepay.com https://www.mollie.com 'self' data: integrations.etrusted.com interface.mailcampaigns.nl px.ads.linkedin.com www.facebook.com data: 'self' 'unsafe-inline'; script-src www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypalobjects.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.multisafepay.com https://pay.google.com js.mollie.com 'self' data: interface.mailcampaigns.nl connect.facebook.net s.pinimg.com embed.tawk.to snap.licdn.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com *.multisafepay.com 'self' data: integrations.etrusted.com interface.mailcampaigns.nl embed.tawk.to 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src embed.tawk.to 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com www.paypalobjects.com *.multisafepay.com 'self' data: ct.pinterest.com pagead2.googlesyndication.com *.tawk.to px.ads.linkedin.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://monitor.bigbridgedev.nl/csp; report-to report-endpoint; 4 script-src 'self' 'unsafe-inline' 'unsafe-eval' https://static.fixando.com/ https://cdn.fixando.com/ https://pics.fixando.com/ https://www.google-analytics.com/ https://www.googletagmanager.com/ https://www.googletagservices.com/ https://www.googleadservices.com/ https://fcm.googleapis.com/ https://tpc.googlesyndication.com/ https://pagead2.googlesyndication.com/ https://adservice.google.com.pk/ https://adservice.google.com.br/ https://adservice.google.com.py/ https://adservice.google.com.do/ https://adservice.google.com/ https://adservice.google.pt/ https://adservice.google.nl/ https://adservice.google.cl/ https://adservice.google.it/ https://adservice.google.pl/ https://adservice.google.no/ https://adservice.google.fr/ https://adservice.google.bg/ https://adservice.google.es/ https://adservice.google.se/ https://adservice.google.be/ https://adservice.google.de/ https://adservice.google.ch/ https://adservice.google.hu/ https://adservice.google.ie/ https://adservice.google.lu/ https://adservice.google.ru/ https://adservice.google.be/ https://adservice.google.co.uk/ https://adservice.google.co.ao/ https://adservice.google.co.in/ https://partner.googleadservices.com/ https://maps.googleapis.com/ https://optimize.google.com/ https://www.googleoptimize.com/ https://www.gstatic.com/ https://googleads.g.doubleclick.net/ https://pubads.g.doubleclick.net/ https://static.zdassets.com/ https://widget-mediator.zopim.com/ https://www.facebook.com/ https://connect.facebook.net/ https://static.hotjar.com/ https://script.hotjar.com/ https://cdn.jsdelivr.net/ https://static.zdassets.com/ https://d2wy8f7a9ursnm.cloudfront.net/ https://apis.google.com/ https://tagmanager.google.com/ https://accounts.google.com/ https://www.paypal.com/ https://cdn.socket.io/ https://widget.trustpilot.com https://*.hotjar.com https://*.hotjar.io wss://*.hotjar.com https://bucket.cdnwebcloud.com https://bat.bing.com https://www.clarity.ms https://www.google.com https://*.outbrain.com https://www.sandbox.paypal.com 4 font-src *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com https://fonts.gstatic.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.cloudflare.com *.twitter.com *.typekit.net *.twimg.com *.trustedshops.com *.googleapis.com v2.zopim.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.googlesyndication.com *.twitter.com https://www.facebook.com www.googletagmanager.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.google.com https://*.google.com *.doubleclick.net *.googlesyndication.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com *.twitter.com axi.maxiaxi.com *.pinterest.com *.addthis.com https://consentcdn.cookiebot.com *.fast.amc.demdex.net https://tr.snapchat.com https://www.facebook.com *.cookiebot.eu *.googletagmanager.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://*.google.com *.google.bg *.facebook.net *.doubleclick.net *.googletagmanager.com *.gstatic.com *.googlesyndication.com *.roeye.com https://static.buckaroo.nl validate.fishpig.co.uk https://*.gstatic.com https://*.googleapis.com https://*.googleusercontent.com magefan.com cm.magefan.com https://firebasestorage.googleapis.com https://redchamps.com ts.tradetracker.net www.magmodules.eu *.cloudflare.com *.klarna.com *.googleadservices.com *.google-analytics.com *.paypal.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.cloudfront.net *.maxiaxi.com bat.bing.com www.google.nl www.google.de www.google.fr www.google.es *.squeezely.tech squeezely.tech tm-tradetracker.net *.pinterest.com *.googleapis.com *.googleoptimize.com *.linkedin.com *.cookiebot.com *.etrusted.com *.adobedtm.com *.zendesk.com *.zdassets.com *.trustedshops.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ https://*.google.com *.google.bg *.googletagmanager.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com https://static.buckaroo.nl https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl https://buckaroo.nl https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com *.avada.io tm.tradetracker.net *.cloudflare.com *.twitter.com *.twimg.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.googleapis.com app.aiden.cx js-agent.newrelic.com bam.nr-data.net rum-static.pingdom.net *.trustpilot.com *.zopim.com static.sooqr.com *.zdassets.com bat.bing.com static.buckaroo.nl *.squeezely.tech squeezely.tech tm-tradetracker.net *.maxiaxi.com *.clarity.ms *.googleoptimize.com *.zendesk.com bam.eu01.nr-data.net *.pinimg.com *.addthis.com *.addthisedge.com *.moatads.com *.hotjar.com *.hotjar.io *.licdn.com *.beslist.nl *.tiktok.com *.stripe.com *.cookiebot.com *.etrusted.com *.smooch.io *.pinterest.com *.convertexperiments.com d5yoctgpv4cpx.cloudfront.net *.cookiebot.eu tr.kickbite.io 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl https://fonts.googleapis.com https://hcaptcha.com https://*.hcaptcha.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.cloudflare.com *.twitter.com *.twimg.com *.typekit.net *.trustedshops.com *.usercentrics.eu static.sooqr.com *.etrusted.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.zendesk.com *.zdassets.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.google-analytics.com *.facebook.net https://*.google.com *.doubleclick.net *.googlesyndication.com https://static.buckaroo.nl wss://websockets.buckaroo.io/ https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl https://applepay.buckaroo.io https://ipinfo.io https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com https://get.geojs.io *.avada.io *.cloudflare.com *.twitter.com *.paypal.com *.twimg.com bam.nr-data.net *.zdassets.com widget-mediator.zopim.com stats.g.doubleclick.net squeezely.tech cognito-identity.eu-central-1.amazonaws.com rum-collector-2.pingdom.net wss://widget-mediator.zopim.com *.maxiaxi.com *.clarity.ms *.googleapis.com *.googleoptimize.com *.googletagmanager.com *.pinterest.com measurement-api.criteo.com *.zendesk.com bam.eu01.nr-data.net *.addthis.com *.hotjar.com *.beslist.nl *.tiktok.com *.tiktokw.us app.aiden.cx *.hotjar.io wss://ws.hotjar.com analytics.pangle-ads.com googleads.g.doubleclick.net *.ads.linkedin.com *.cookiebot.com *.etrusted.com *.smooch.io *.convertexperiments.com p2iqhncxyh.execute-api.eu-central-1.amazonaws.com *.bing.com tr.kickbite.io wss://*.zendesk.com *.trustedshops.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.hotjar.com *.hotjar.io wss://*.hotjar.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 4 font-src fonts.gstatic.com *.biotus.ua *.biotus.kz *.biotus.md *.biotus.ru *.biotus.by *.biotus.az *.biotus.uz *.biotus.ge *.biotus.lt *.biotus.lv *.biotus.ee *.biotus.it *.biotus.ro *.biotusnew.pl portal.bulkgate.com *.gstatic.com *.fontawesome.com https://fonts.bunny.net *.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.facebook.com *.cloudflare.com portal.bulkgate.com *.wayforpay.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.google.com *.facebook.com *.doubleclick.net *.googletagmanager.com *.binotel.com lottie.host portal.bulkgate.com ipinfo.io *.wayforpay.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com *.youtube.com https://images.unsplash.com *.clarity.ms *.google.com.ua *.facebook.com blob: *.bing.com *.biotus.ua *.biotus.kz *.biotus.md *.biotus.ru *.biotus.by *.biotus.az *.biotus.uz *.biotus.ge *.biotus.lt *.biotus.lv *.biotus.ee *.biotus.it *.biotus.ro *.biotusnew.pl biotus.ua biotus.kz biotus.md biotus.ru biotus.by biotus.az biotus.uz biotus.ge biotus.lt biotus.lv biotus.ee biotus.it biotus.ro biotusnew.pl *.binotel.com *.binotel.ua *.esputnik.com portal.bulkgate.com *.gstatic.com *.googleapis.com *.rawgit.com *.jsdelivr.net https://firebasestorage.googleapis.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ cdn.ampproject.org raw.githubusercontent.com https://maps.googleapis.com https://player.vimeo.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.clarity.ms *.cloudflare.com *.facebook.net *.facebook.com *.google.com *.tiktok.com *.doubleclick.net *.biotus.ua *.biotus.kz *.biotus.md *.biotus.ru *.biotus.by *.biotus.az *.biotus.uz *.biotus.ge *.biotus.lt *.biotus.lv *.biotus.ee *.biotus.it *.biotus.ro *.biotusnew.pl *.googletagmanager.com *.binotel.com *.esputnik.com esputnik.com portal.bulkgate.com *.gstatic.com *.googleapis.com ipinfo.io analytics.tiktok.com/ *.avada.io *.shopify.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.biotus.ua *.biotus.kz *.biotus.md *.biotus.ru *.biotus.by *.biotus.az *.biotus.uz *.biotus.ge *.biotus.lt *.biotus.lv *.biotus.ee *.biotus.it *.biotus.ro *.biotusnew.pl *.esputnik.com portal.bulkgate.com *.gstatic.com *.fontawesome.com https://fonts.bunny.net *.bootstrapcdn.com 'self' 'unsafe-inline'; object-src ipinfo.io 'self' 'unsafe-inline'; media-src *.adobe.com *.biotus.ua *.biotus.kz *.biotus.md *.biotus.ru *.biotus.by *.biotus.az *.biotus.uz *.biotus.ge *.biotus.lt *.biotus.lv *.biotus.ee *.biotus.it *.biotus.ro *.biotusnew.pl *.binotel.com *.binotel.ua 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com cdn.ampproject.org https://maps.googleapis.com https://player.vimeo.com *.clarity.ms *.doubleclick.net *.google.com.ua/ads/* *.google.com/ccm/collect* adservice.google.com/pagead/* *.analytics.google.com/g/collect* *.google.com *.tiktok.com *.facebook.net *.facebook.com *.biotus.ua *.biotus.kz *.biotus.md *.biotus.ru *.biotus.by *.biotus.az *.biotus.uz *.biotus.ge *.biotus.lt *.biotus.lv *.biotus.ee *.biotus.it *.biotus.ro *.biotusnew.pl *.binotel.com wss://*.binotel.com:9028 *.esputnik.com esputnik.com portal.bulkgate.com *.gstatic.com wss://*.bulkgate.com *.googleapis.com ipinfo.io *.tiktokw.us https://get.geojs.io *.avada.io 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline' 'unsafe-eval' 'strict-dynamic'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 4 font-src fonts.gstatic.com fonts.googleapis.com *.fontawesome.com https://fonts.gstatic.com *.alothemes.com *.magepow.com maxcdn.bootstrapcdn.com *.petm2.com *.staging.petm2.com *.petiteamelie.nl *.petiteamelie.fr *.petiteamelie.de *.petiteamelie.co.uk *.petiteamelie.com *.petiteamelie.be *.gstatic.com 'self' data: https://widgets.trustedshops.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.monetico-services.com *.petm2.com *.staging.petm2.com *.petiteamelie.nl *.petiteamelie.fr *.petiteamelie.de *.petiteamelie.co.uk *.petiteamelie.com *.petiteamelie.be 'self' 'unsafe-inline'; frame-ancestors *.multisafepay.com https://pay.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.monetico-services.com https://www.googletagmanager.com/ *.addthis.com *.multisafepay.com https://pay.google.com static.addtoany.com *.cookiebot.com *.pinterest.com www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://images.unsplash.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ magefan.com cm.magefan.com *.alothemes.com *.magepow.com *.multisafepay.com *.petm2.com *.staging.petm2.com *.petiteamelie.nl *.petiteamelie.fr *.petiteamelie.de *.petiteamelie.co.uk *.petiteamelie.com *.petiteamelie.be *.facebook.com *.google.pl *.google.com *.bing.com *.cookiebot.com *.clarity.ms *.doubleclick.net www.xtento.com cdn.xtento.com *.hsforms.net *.hsforms.com 'self' data: https://widgets.trustedshops.com https://widgets-qa.trustedshops.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://cdn.jsdelivr.net/npm/@ryangjchandler/spruce@2.x.x/dist/spruce.umd.js https://scripts.luigisbox.tech https://cdn.luigisbox.tech https://live.luigisbox.tech https://api.luigisbox.tech http://www.googletagmanager.com/ https://www.googletagmanager.com/ *.addthis.com *.moatads.com *.addthisedge.com *.pinterest.com *.avada.io *.alothemes.com *.magepow.com *.multisafepay.com https://pay.google.com *.petm2.com *.staging.petm2.com *.petiteamelie.nl *.petiteamelie.fr *.petiteamelie.de *.petiteamelie.co.uk *.petiteamelie.com *.petiteamelie.be www.clarity.ms connect.getflowbox.com static.addtoany.com cdn-4.convertexperiments.com assets.voyado.com *.cookiebot.com *.beslist.nl *.pinimg.com *.bing.com www.xtento.com cdn.xtento.com *.hsforms.net *.hsforms.com *.google.com *.gstatic.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.gstatic.com fonts.googleapis.com https://scripts.luigisbox.tech https://cdn.luigisbox.tech https://live.luigisbox.tech https://api.luigisbox.tech *.fontawesome.com *.googleapis.com *.addtoany.com *.alothemes.com *.magepow.com maxcdn.bootstrapcdn.com *.multisafepay.com *.petm2.com *.staging.petm2.com *.petiteamelie.nl *.petiteamelie.fr *.petiteamelie.de *.petiteamelie.co.uk *.petiteamelie.com *.petiteamelie.be *.gstatic.com https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ *.petm2.com *.staging.petm2.com *.petiteamelie.nl *.petiteamelie.fr *.petiteamelie.de *.petiteamelie.co.uk *.petiteamelie.com *.petiteamelie.be 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.monetico-services.com https://scripts.luigisbox.tech https://cdn.luigisbox.tech https://live.luigisbox.tech https://api.luigisbox.tech http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ *.addthis.com https://get.geojs.io *.avada.io http://dpm.demdex.net *.alothemes.com *.magepow.com *.multisafepay.com *.petm2.com *.staging.petm2.com *.petiteamelie.nl *.petiteamelie.fr *.petiteamelie.de *.petiteamelie.co.uk *.petiteamelie.com *.petiteamelie.be testapi.multisafepay.com connect.facebook.net *.google-analytics.com *.google.com *.googlesyndication.com *.staging.voyado.com *.clarity.ms *.doubleclick.net *.pinterest.com *.cookiebot.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.trustedshops.com *.etrusted.com https://integrations.etrusted.site 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src www.google.com www.youtube.com js-agent.newrelic.com *.petm2.com *.staging.petm2.com *.petiteamelie.nl *.petiteamelie.fr *.petiteamelie.de *.petiteamelie.co.uk *.petiteamelie.com *.petiteamelie.be static.addtoany.com pay.multisafepay.com *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 4 font-src *.klevu.com *.ksearchnet.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.yotpo.com *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors 'self' 'unsafe-inline'; frame-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com player.vimeo.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de www.xtento.com *.hotjar.com cdn.dnky.co webchat.dotdigital.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.yotpo.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com www.googleadservices.com www.google-analytics.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com s.ytimg.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de https://maps.omnivasiunta.lt www.xtento.com cdn.xtento.com data: *.xsmanguasjad.ee *.google.com *.google.lv image-charts.com *.klevu.com *.ksearchnet.com https://omnisnippet1.com https://wt.soundestlink.com *.yotpo.com 'self' 'unsafe-inline'; script-src assets.adobedtm.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com video.google.com vimeo.com www.vimeo.com *.vimeocdn.com js.authorize.net jstest.authorize.net js.braintreegateway.com cdn-scripts.signifyd.com www.youtube.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de https://unpkg.com www.xtento.com cdn.xtento.com *.newrelic.com *.hotjar.com *.doubleclick.net *.googletagmanager.com *.nr-data.net *.zdassets.com r1-t.trackedlink.net r2-t.trackedlink.net r3-t.trackedlink.net r1.trackedweb.net r2.trackedweb.net r3.trackedweb.net static.trackedweb.net cdn.dnky.co api.comapi.com webchat.dotdigital.com *.klevu.com *.ksearchnet.com https://omnisnippet1.com https://forms.soundestlink.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src getfirebug.com cdn.dnky.co webchat.dotdigital.com *.klevu.com *.ksearchnet.com *.yotpo.com *.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.zdassets.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de https://geocode.arcgis.com *.hotjar.com *.doubleclick.net *.nr-data.net *.zdassets.com *.zendesk.com *.zopim.com r1-t.trackedlink.net r2-t.trackedlink.net r3-t.trackedlink.net r1.trackedweb.net r2.trackedweb.net r3.trackedweb.net static.trackedweb.net api.comapi.com webchat.dotdigital.com *.klevu.com *.ksearchnet.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.yotpo.com 'self' 'unsafe-inline'; child-src 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 4 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com *.fontawesome.com *.richpanel.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com https://static.addtoany.com/ connect.bolt.com connect-sandbox.bolt.com account.bolt.com account-sandbox.bolt.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.googleapis.com connect.bolt.com connect-sandbox.bolt.com s3-us-west-1.amazonaws.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com services.postcodeanywhere.co.uk www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.amazonaws.com *.richpanel.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://static.addtoany.com/ *.googleapis.com *.gstatic.com connect.bolt.com connect-sandbox.bolt.com account.bolt.com account-sandbox.bolt.com chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com widget.freshworks.com m2epro.freshdesk.com api.addressy.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.richpanel.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com downloads.mailchimp.com widget.freshworks.com m2epro.freshdesk.com api.addressy.com assets.braintreegateway.com *.richpanel.com *.googleapis.com *.fontawesome.com 'self' 'unsafe-inline'; object-src connect.bolt.com connect-sandbox.bolt.com account.bolt.com account-sandbox.bolt.com 'self' 'unsafe-inline'; media-src *.adobe.com *.amazonaws.com *.richpanel.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://stats.addtoany.com/menu *.googleapis.com connect.bolt.com connect-sandbox.bolt.com account.bolt.com account-sandbox.bolt.com sessions.bugsnag.com form-assets.mailchimp.com *.intuit.com *.amazonaws.com widget.freshworks.com m2epro.freshdesk.com api.addressy.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.richpanel.com wss://*.richpanel.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 4 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com https://fonts.gstatic.com *.klarnacdn.net *.fontawesome.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.adyen.com *.facebook.com *.googlesyndication.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors https://api.clerk.io https://cdn.clerk.io 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.adyen.com *.doubleclick.net *.facebook.com *.googlesyndication.com *.klarna.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.adyen.com https://images.unsplash.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.googlesyndication.com https://cdn.clerk.io *.klarna.com *.klarnaevt.com *.klarnacdn.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.adyen.com https://maps.googleapis.com https://player.vimeo.com https://cdn.jsdelivr.net/npm/@ryangjchandler/spruce@2.x.x/dist/spruce.umd.js *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com https://api.clerk.io https://cdn.clerk.io *.klarna.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com https://api.clerk.io https://cdn.clerk.io https://fonts.googleapis.com *.klarnacdn.net *.fontawesome.com maxcdn.bootstrapcdn.com assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.adyen.com https://maps.googleapis.com https://player.vimeo.com *.google-analytics.com *.facebook.com *.facebook.net *.doubleclick.net *.googlesyndication.com *.klarnaevt.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.klarna.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 4 script-src 'self' 'unsafe-inline' 'unsafe-eval' https://www.gstatic.com https://www.awin1.com https://lantern.roeyecdn.com https://tagmanager.google.com https://cdn.trustcommander.net https://www.dwin1.com https://www.googletagmanager.com https://maps.googleapis.com https://www.google-analytics.com https://www.googleadservices.com https://bat.bing.com https://*.doubleclick.net https://www.axa-video.de https://*.visualwebsiteoptimizer.com https://app.vwo.com https://www.google.com https://platform.commandersact.com https://connect.facebook.net https://*.aklamio.com blob: https://ct.pinterest.com https://s.pinimg.com https://acdn.adnxs.com https://ib.adnxs.com https://snap.licdn.com https://data.dbv.de ;style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://*.visualwebsiteoptimizer.com https://app.vwo.com https://s3.amazonaws.com https://googletagmanager.com https://www.googletagmanager.com ;base-uri 'self'; object-src 'none'; default-src 'self' blob: data: https://fonts.gstatic.com/; form-action 'self'; frame-src https://www.awin1.com https://app.vwo.com https://*.visualwebsiteoptimizer.com https://entry.axa-de.intraxa/ https://entry.axa.de https://www.axa-video.de https://www.axa.de https://inte.axa.de https://*.doubleclick.net https://cdn.trustcommander.net https://www.dwin1.com https://connect.facebook.net https://www.facebook.com https://td.doubleclick.net https://googleads.g.doubleclick.net https://www.google.com https://ct.pinterest.com https://googletagmanager.com https://insight.adsrvr.org 'self' https://www.googletagmanager.com https://data.dbv.de https://www.youtube.com; img-src 'self' data: https://*.visualwebsiteoptimizer.com https://chart.googleapis.com https://wingify-assets.s3.amazonaws.com https://app.vwo.com https://track.adform.net https://ad.doubleclick.net https://www.facebook.com https://bat.bing.com https://*.google.com https://www.google.de https://www.googletagmanager.com https://*.google-analytics.com https://*.analytics.google.com https://googleads.g.doubleclick.net *.doubleclick.net https://i.ytimg.com https://maps.gstatic.com https://maps.googleapis.com https://www.financeads.net https://www.aklamio.com/ https://ct.pinterest.com https://ib.adnxs.com https://*.ads.linkedin.com https://data.dbv.de; connect-src 'self' https://*.visualwebsiteoptimizer.com https://app.vwo.com https://*.googlesyndication.com https://*.google.com https://*.google.de https://*.google-analytics.com https://*.analytics.google.com https://www.google-analytics.com https://*.doubleclick.net https://bat.bing.com https://privacy.trustcommander.net https://privacy.commander1.net https://privacy.commander1.com https://www.googletagmanager.com https://maps.googleapis.com https://fonts.googleapis.com https://*.dbv.de https://cloud.service.aerzteversicherung.de https://mcdyr4395tgnrcnr8bt5wsrgh-11.pub.sfmc-content.com https://*.aklamio.com https://www.googleadservices.com https://ct.pinterest.com https://ib.adnxs.com https://acdn.adnxs.com https://www.facebook.com https://*.ads.linkedin.com https://p.adsymptotic.com https://*.linkedin.oribi.io https://sjs.bizographics.com;;report-uri /site/dbv-de/cspReportOnly 4 default-src https: data: 'unsafe-inline' 'unsafe-eval'; report-uri /csp_report; 4 default-src blob: https:; img-src data: https:; script-src 'unsafe-inline' 'unsafe-eval' blob: https:; style-src 'unsafe-inline' https:; font-src data: https:; frame-src https:; media-src data: https:; object-src 'none'; connect-src https:; frame-ancestors 'self'; 4 frame-src 'self' www.youtube.com www.google.com js.playground.klarna.com js.klarna.com https://checkoutshopper-test.adyen.com https://pay.google.com https://wchat.freshchat.com https://connect.getflowbox.com return.4sellers.de *.webpush.freshchat.com ct.pinterest.com vercel.live *.sovendus.com *.adyen.com gum.criteo.com fledge.eu.criteo.com *.cnstrc.com cnstrc.com graphical-editor.kameleoon.com *.vimeo.com vimeo.com www.googletagmanager.com *.chat.getzowie.com 4 default-src 'self' 'unsafe-inline' 'unsafe-eval' *.mythad.com https://*.kwai-pro.com http://*.kwai-pro.com http://*.kwai.net https://*.kwai.net *.kwai.com *.snackvideo.in *.kwai.me *.kwai.app *.kwimgs.com *.yximgs.com *.cloudfront.net *.kuaishou.com https://*.gifshow.com http://*.gifshow.com https://log-sdk.ksapisrv.com https://www.googletagmanager.com https://gifshow-static.download.ks-cdn.com https://static3.avast.com https://translate.google.com https://www.gstatic.com https://fonts.gstatic.com https://connect.facebook.net www.google-analytics.com hm.baidu.com m.snackvideo.com http://*.ap4r.com https://*.ap4r.com https://*.typekit.net http://*.typekit.net ak-sgp-pic.snackvideo.in tx-sgp-pic.snackvideo.in ws-sgp-pic.snackvideo.in g-us-kampic.golden49.net g-us-kamcdn.golden49.net m.kwai.com sentry.kuaishou.com https://cdn.jsdelivr.net https://at.alicdn.com https://www.facebook.com https://snap.licdn.com https://px.ads.linkedin.com https://cdn.linkedin.oribi.io https://www.linkedin.com https://*.google.com https://*.google-analytics.com https://*.doubleclick.net asset: data: blob: android-webview-video-poster: ikwai: chrome-extension:;img-src http: https: asset: data: blob: android-webview-video-poster: ikwai: chrome-extension:;connect-src http: https: asset: data: blob: android-webview-video-poster: ikwai: chrome-extension:;report-uri https://csplog.kwai-pro.com/log/kwai/wwwkwai 3 frame-ancestors gofundme.com *.gofundme.com *.hopin.com pillar.io *.pillar.io takethemameal.com *.takethemameal.com kudoboard.com *.kudoboard.com werememberdev.com *.werememberdev.com weremember.com *.weremember.com forevermissed.com *.forevermissed.com fm-stage.com *.fm-stage.com fm-qa.com *.fm-qa.com giftwhale.com *.giftwhale.com giftwhale.test; 3 default-src data: 'unsafe-inline' 'unsafe-eval' https: blob: http://*.files.wordpress.com wss://www.hollywoodreporter.com; report-uri https://pmcuri.report-uri.com/r/d/csp/reportOnly 3 default-src 'unsafe-inline' 'unsafe-eval' * data: blob: 3 default-src 'self'; report-uri https://csp.loopia.se; connect-src 'self' https://*.analytics.google.com https://*.loopia.com https://*.loopia.no https://*.loopia.rs https://*.loopia.se https://accesswidget-log-receiver.acsbapp.com https://adservice.google.com https://analytics.google.com https://api-eu1.hubapi.com https://api.exponea.com https://api.infinario.com https://bat.bing.com https://cdn.iubenda.com https://chat.puzzel.com https://consentcdn.cookiebot.com https://content.hotjar.io https://cta-eu1.hubspot.com https://eu-cdn.acsbapp.com https://eu.acsbapp.com https://idb.iubenda.com https://in.hotjar.com https://pagead2.googlesyndication.com https://px.ads.linkedin.com https://px4.ads.linkedin.com https://srv.motu-teamblue.services https://stats.g.doubleclick.net https://vc.hotjar.io https://www.facebook.com https://www.google.com https://www.googleadservices.com https://www.google.se; font-src 'self' https://*.loopia.com https://*.loopia.no https://*.loopia.rs https://*.loopia.se https://chat.puzzel.com https://fonts.gstatic.com; form-action 'self' https://*.loopia.com https://*.loopia.no https://*.loopia.rs https://*.loopia.se https://bib.eway2pay.com https://payment.architrade.com https://ticket.siriusit.net https://www.facebook.com; frame-src 'self' https://*.facebook.com https://*.loopia.com https://*.loopia.no https://*.loopia.rs https://*.loopia.se https://5.ec1.vbus.apps.ladesk.com https://active24.ladesk.com https://cdn.hub-prod.team.blue https://consentcdn.cookiebot.com https://vars.hotjar.com https://www.google.com https://www.googletagmanager.com; img-src 'self' data: https://*.loopia.com https://*.loopia.no https://*.loopia.rs https://*.loopia.se https://bat.bing.com https://chat.puzzel.com https://googleads.g.doubleclick.net https://imgsct.cookiebot.com https://perf-eu1.hsforms.com https://px.ads.linkedin.com https://px4.ads.linkedin.com https://region1.analytics.google.com https://region1.google-analytics.com https://srv.motu-teamblue.services https://stats.g.doubleclick.net https://tbs.tradedoubler.com https://track-eu1.hubspot.com https://www.facebook.com https://www.google.com https://www.google.se https://www.googletagmanager.com https://www.gstatic.com; media-src 'self' https://*.loopia.com https://*.loopia.no https://*.loopia.rs https://*.loopia.se https://chat.puzzel.com; object-src 'self'; script-src 'self' 'unsafe-eval' 'unsafe-inline' https://*.loopia.com https://*.loopia.no https://*.loopia.rs https://*.loopia.se https://api.exponea.com https://api.infinario.com https://chat.puzzel.com https://g.microsoft.com https://script.hotjar.com https://snap.licdn.com https://static.hotjar.com https://www.google.com https://www.google.se https://www.googletagmanager.com; script-src-elem 'self' 'unsafe-inline' https://script.hotjar.com https://*.loopia.com https://*.loopia.no https://*.loopia.rs https://*.loopia.se https://active24.ladesk.com https://api.exponea.com https://bat.bing.com https://cdn.iubenda.com https://chat.puzzel.com https://connect.facebook.net https://consent.cookiebot.com https://consentcdn.cookiebot.com https://cs.iubenda.com https://eu.acsbapp.com https://googleads.g.doubleclick.net https://js-eu1.hs-analytics.net https://js-eu1.hs-banner.com https://js-eu1.hs-scripts.com https://js-eu1.hsadspixel.net https://js-eu1.hubspot.com https://pagead2.googlesyndication.com https://snap.licdn.com https://srv.isy-teamblue.services https://srv.motu-teamblue.services https://static.hotjar.com https://widget.trustpilot.com https://www.google.com https://www.google.se https://www.googletagmanager.com https://www.gstatic.com; style-src 'self' 'unsafe-inline' https://*.loopia.com https://*.loopia.no https://*.loopia.rs https://*.loopia.se https://cdn.iubenda.com https://chat.puzzel.com https://fonts.googleapis.com 3 script-src 'self' cdn.robinhood.com cdn.pdst.fm/ping.min.js www.google-analytics.com www.googletagmanager.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ tagmanager.google.com ssl.google-analytics.com connect.facebook.net sc-static.net d.impactradius-event.com www.redditstatic.com analytics.tiktok.com boards.greenhouse.io bat.bing.com www.googleadservices.com static.ads-twitter.com s.yimg.com *.usercentrics.eu snap.licdn.com collector-47804.us.tvsquared.com/tv2track.js public.flourish.studio/resources/embed.js csi.gstatic.com cdn.parsely.com *.doubleclick.net *.googlesyndication.com *.googletagservices.com platform.twitter.com/ platform.instagram.com/ www.instagram.com/embed.js www.threads.net/embed.js www.tiktok.com/embed.js lf16-tiktok-web.tiktokcdn-us.com/ www.facebook.com/ www.youtube.com/ ak.sail-horizon.com *.celtra.com *.heapanalytics.com heapanalytics.com cdn.us.heap-api.com *.doubleverify.com *.infogram.com cdn.concert.io *.adtrafficquality.google hymnal-prod.vox-cdn.com www.documentcloud.org/notes/loader.js truthsocial.com/embed.js embed.reddit.com/widgets.js embed.bsky.app/static/embed.js *.permutive.app 'unsafe-eval'; report-uri https://o62437.ingest.us.sentry.io/api/4509232895361024/security/?sentry_key=98a8908d38fbd5ecdf8e976a1cb6b404 3 script-src 'self' 'unsafe-eval' 'unsafe-inline' *.byted-static.com *.bytedapm.com *.bytegoofy.com *.bytescm.com *.feishu-boe.cn *.feishu.cn *.feishucdn.com *.framer.com *.hubspot.com *.ibytedapm.com *.ibytedtos.com *.larksuite-boe.com *.larksuite.com *.larksuitecdn.com *.ocic-static.com *.snssdk.com *.yahoo.co.jp https://framer.com https://accounts.google.com https://app.factors.ai https://bat.bing.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://framerusercontent.com https://googleads.g.doubleclick.net https://googletagmanager.com https://hm.baidu.com https://js-na1.hs-scripts.com https://js.hs-analytics.net https://js.hs-banner.com https://js.intercomcdn.com https://s.yimg.jp https://scout-cdn.salesloft.com https://sf16-website-login.neutral.ttwstatic.com https://snap.licdn.com https://static.ads-twitter.com https://widget.intercom.io https://www.google-analytics.com https://www.googleoptimize.com https://www.googletagmanager.com https://zz.bdstatic.com; worker-src 'self' blob:; report-to csp-endpoint 3 default-src 'self'; script-src 'self' https://*.adobedtm.com https://*.onetrust.com https://siteimproveanalytics.com https://*.jsdelivr.net https://*.libcal.com https://*.libanswers.com https://*.google.com https://www.google.com https://www.gstatic.com https://googletagmanager.com https://*.googletagmanager.com https://www.googletagmanager.com https://*.google-analytics.com https://www.google-analytics.com https://*.googleapis.com https://*.gstatic.com https://*.facebook.net https://www.facebook.com https://*.youtube.com https://www.youtube.com https://*.instagram.com https://www.instagram.com https://*.contentsquare.net https://*.unsw.edu.au https://www.engineering.unsw.edu.au https://unsw.us6.list-manage.com https://*.tiqcdn.com https://*.eventbrite.com.au https://www.eventbrite.com.au https://*.twitter.com https://*.flickr.com https://*.hlx.page https://*.licdn.com https://www.tiktok.com https://*.tiktok.com https://www.googleadservices.com https://*.googleadservices.com https://googleadservices.com https://*.fouanalytics.com https://*.adsrvr.org https://*.doubleclick.net https://*.fls.doubleclick.net https://*.linkedin.com https://*.app-us1.com https://*.demdex.net https://*.hsforms.net https://*.hsforms.com https://*.dwcdn.net https://*.hs-scripts.com https://*.mapbox.com https://*.mazemap.com https://*.matterport.com https://*.scite.ai https://*.intercomcdn.com https://*.intercom.io https://*.b2c.com https://*.elfsight.com https://*.service.elfsight.com https://*.utils.elfsightcdn.com https://player.vimeo.com https://*.tableau.com https://*.cloudflare.com https://*.mathjax.org https://*.mailchimp.com https://*.amazonaws.com https://*.recaptcha.net https://www.recaptcha.net https://*.padlet.com https://scribehow.com https://*.flourish.studio wss://*.hotjar.com https://*.hotjar.com https://*.hotjar.io https://*.qcloud.com https://*.vod-qcloud.com https://pingjs.qq.com https://*.taboola.com https://api.disqometer.com https://apps.mypurecloud.com.au/webchat https://*.shorthand.com https://iframely.shorthand.com https://*.clickdimensions.com https://*.benchplatform.com https://*.yimg.com https://*.credly.com https://www.credly.com data: blob: 'unsafe-inline' 'unsafe-eval'; style-src 'self' https://*.unsw.edu.au https://www.engineering.unsw.edu.au https://*.fontawesome.com https://*.googletagmanager.com https://www.googletagmanager.com https://*.googleapis.com https://*.gstatic.com https://*.dwcdn.net https://*.mazemap.com https://*.scite.ai https://*.intercomcdn.com https://*.mailchimp.com data: blob: 'unsafe-inline'; font-src 'self' https://*.unsw.edu.au https://www.engineering.unsw.edu.au https://*.fontawesome.com https://*.gstatic.com https://*.dwcdn.net https://*.scite.ai https://*.intercomcdn.com https://*.fontshare.com https://*.alicdn.com https://*.cloudflare.com https://*.amazonaws.com data: blob:; connect-src 'self' https://*.funnelback.squiz.cloud https://*.adobedc.net https://*.unsw.edu.au https://www.engineering.unsw.edu.au https://unsw.us6.list-manage.com https://*.google-analytics.com https://www.google-analytics.com https://*.analytics.google.com https://analytics.google.com https://*.libcal.com https://*.libanswers.com https://*.onetrust.com https://*.google.com https://www.google.com https://*.doubleclick.net https://*.fls.doubleclick.net https://*.contentsquare.net https://*.linkedin.com https://*.ads.linkedin.com https://*.fouanalytics.com https://*.hlx.page https://*.demdex.net https://*.googleapis.com https://*.gstatic.com https://*.hsforms.net https://*.hsforms.com https://*.mapbox.com https://*.dwcdn.net https://*.b2c.com https://*.tiktok.com https://*.tiktokw.us https://*.facebook.net https://www.facebook.com https://www.googleadservices.com https://*.googleadservices.com https://googleadservices.com https://*.matterport.com https://*.hs-scripts.com https://*.licdn.com https://*.mazemap.com https://*.scite.ai https://*.intercomcdn.com https://*.intercom-messenger.com wss://*.intercom-messenger.com https://*.googletagmanager.com https://www.googletagmanager.com https://*.intercom.io wss://*.intercom.io https://*.elfsight.com https://*.service.elfsight.com https://*.utils.elfsightcdn.com https://polyfilljs.org https://*.scribehow.com wss://*.hotjar.com https://*.hotjar.com https://*.hotjar.io https://*.qcloud.com https://*.vod-qcloud.com https://*.taboola.com https://api.disqometer.com https://apps.mypurecloud.com.au/webchat wss://apps.mypurecloud.com.au/webchat https://*.adsrvr.org https://*.shorthand.com https://iframely.shorthand.com https://*.clickdimensions.com https://*.benchplatform.com https://*.yimg.com https://*.credly.com https://www.credly.com data: blob:; img-src * data: blob:; media-src * data: blob:; frame-ancestors 'self' https://*.telt.unsw.edu.au https://*.google.com https://www.google.com https://*.au.panopto.com; frame-src 'self' https://*.unsw.edu.au https://www.engineering.unsw.edu.au https://*.forms.unsw.edu.au https://www.fonts.unsw.edu.au https://www.hostfiles.unsw.edu.au https://www.coursearchive.unsw.edu.au https://*.linkedin.com https://www.linkedin.com https://www.wrike.com https://login.microsoftonline.com https://*.google.com https://www.google.com https://*.youtube.com https://www.youtube.com https://*.mazemap.com https://*.soundcloud.com https://*.facebook.net https://www.facebook.com https://*.twitter.com https://*.eventbrite.com.au https://www.eventbrite.com.au https://*.spotify.com https://*.doubleclick.net https://*.fls.doubleclick.net https://*.hsforms.net https://*.hsforms.com https://*.matterport.com https://joom.ag https://*.joomag.com https://www.joomag.com https://*.service.anz https://unsw.au1.qualtrics.com https://*.smartsheet.com https://player.vimeo.com https://www.figma.com https://www.googletagmanager.com https://*.cs.link https://*.syd-2.linewize.net https://*.fliphtml5.com https://*.opendns.com https://*.tableau.com https://omny.fm https://*.theconversation.com https://*.zscalerone.net https://*.uri.sh https://*.dwcdn.net https://*.nogginapp.io https://*.mwginternal.com https://*.matterportvr.cn https://*.instagram.com https://www.instagram.com https://unsw.sharepoint.com https://*.ascentone.com https://*.maps.arcgis.com https://*.data.ictinternational.com https://www.sketch.com https://*.knightlab.com https://*.cloudfront.net https://*.tikee.io https://*.regionalpropertymarkets.com https://padlet.com https://*.app.carto.com https://scribehow.com https://*.shinyapps.io https://*.powerbi.com https://*.media.tumblr.com https://www.recaptcha.net https://*.gettyimages.com https://*.brevo.com https://mailchi.mp https://www.arcgis.com https://*.github.io https://*.media.tumblr.com https://*.au.panopto.com https://unswlibrary.libanswers.com https://vemcount.app https://*.shorthand.com https://iframely.shorthand.com https://fliphtml5.com https://*.campaign-archive.com https://*.adsrvr.org https://*.credly.com https://www.credly.com data: blob:; worker-src 'self' data: blob:; object-src 'self' https://www.youtube.com data: blob:; form-action 'self' https://*.hsforms.net https://*.hsforms.com https://*.civeng.unsw.edu.au https://unsw.us6.list-manage.com https://login.microsoftonline.com https://www.facebook.com; report-uri /bin/unsw/common/csp-violation-report/endpoint 3 default-src 'self' https://pref.docusign.com https://apps.docusign.com https://events.docusign.com https://momentum.docusign.com https://dsucustomers.docusign.com https://account.docusign.com https://account-d.docusign.com https://ecom.docusign.com https://support.docusign.com https://developers.docusign.com https://community.docusign.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' blob: https://p.mdb.tools https://identity.mdb.tools https://sierra.chat:443 https://sierra.chat https://*.cloudfront.net https://cdn.jsdelivr.net https://cdn.prod.website-files.com https://cdnjs.cloudflare.com https://unpkg.com https://cdn4.mxpnl.com https://s.yimg.com https://tags.srv.stackadapt.com:443 https://cdn.yellowmessenger.com https://docusign-api.arkoselabs.com https://trk.techtarget.com https://cdn.optimizely.com https://www.googletagmanager.com https://players.brightcove.net https://cdn3.optimizely.com https://cdn.cookielaw.org https://vjs.zencdn.net https://cdn.sift.com https://tags.srv.stackadapt.com https://js.driftt.com https://connect.facebook.net https://snap.licdn.com https://bat.bing.com https://tag.demandbase.com https://www.knotch-cdn.com https://js.adsrvr.org https://rs.fullstory.com https://edge.fullstory.com https://googleads.g.doubleclick.net https://protect.docusign.net https://protect-d.docusign.net https://app.gatedcontent.com https://img.en25.com https://track.docusign.com https://www.google.com https://www.gstatic.com https://browser.sentry-cdn.com https://app.guideflow.com https://zn0oqzbba3l7g5ph4-docusign.siteintercept.qualtrics.com https://siteintercept.qualtrics.com https://80e3c780877f.cdn4.forter.com https://sadmin.brightcove.com https://platform.twitter.com https://bam.nr-data.net https://static.ads-twitter.com https://www.redditstatic.com https://chat.docusign.net https://sdk.inbenta.io https://apps.usw2.pure.cloud https://api-cdn.usw2.pure.cloud https://cdn.taboola.com https://trc.taboola.com https://www.influ2.com https://t.influ2.com/ https://hermes.docusign.com; script-src-elem 'self' 'unsafe-inline' 'unsafe-eval' blob: https://sierra.chat:443 https://sierra.chat https://*.cloudfront.net https://cdn.jsdelivr.net https://cdn.prod.website-files.com https://cdnjs.cloudflare.com https://cdn4.mxpnl.com https://s.yimg.com https://tags.srv.stackadapt.com:443 https://cdn.yellowmessenger.com https://docusign-api.arkoselabs.com https://trk.techtarget.com https://cdn.optimizely.com https://www.googletagmanager.com https://players.brightcove.net https://cdn3.optimizely.com https://cdn.cookielaw.org https://vjs.zencdn.net https://cdn.sift.com https://tags.srv.stackadapt.com https://tags.srv.stackadapt.com:443/events.js https://tags.srv.stackadapt.com/events.js https://js.driftt.com https://connect.facebook.net https://snap.licdn.com https://bat.bing.com https://tag.demandbase.com https://www.knotch-cdn.com https://js.adsrvr.org https://rs.fullstory.com https://edge.fullstory.com https://googleads.g.doubleclick.net https://protect.docusign.net https://protect-d.docusign.net https://app.gatedcontent.com https://img.en25.com https://track.docusign.com https://www.google.com https://www.gstatic.com https://browser.sentry-cdn.com https://app.guideflow.com https://zn0oqzbba3l7g5ph4-docusign.siteintercept.qualtrics.com https://siteintercept.qualtrics.com https://80e3c780877f.cdn4.forter.com https://sadmin.brightcove.com https://platform.twitter.com https://bam.nr-data.net https://static.ads-twitter.com https://www.redditstatic.com https://chat.docusign.net https://sdk.inbenta.io https://apps.usw2.pure.cloud https://api-cdn.usw2.pure.cloud https://cdn.taboola.com https://trc.taboola.com https://www.influ2.com https://t.influ2.com/ https://hermes.docusign.com https://identity.mdb.tools https://p.mdb.tools https://connect.facebook.net/en_US/fbevents.js https://cdn.yellowmessenger.com/plugin/widget-v2/latest/dist/main.min.js https://cdn.taboola.com/libtrc/unip/1790969/tfa.js https://cdn.sift.com/s.js https://bat.bing.com/bat.js https://www.influ2.com/tracker; style-src 'self' 'unsafe-inline' https://sierra.chat:443 https://sierra.chat https://cdn.prod.website-files.com https://cdn.yellowmessenger.com https://tags.srv.stackadapt.com https://app.gatedcontent.com https://www.gstatic.com https://app.guideflow.com https://sdk.inbenta.io; img-src 'self' data: blob: https://assets-global.website-files.com https://*.cloudfront.net https://sp.analytics.yahoo.com https://ecom.docusign.com https://cdn.prod.website-files.com https://connect.facebook.net https://r4-ym-uploads.s3-us-west-2.amazonaws.com https://r4.app.yellow.ai https://cdn.yellowmessenger.com https://www.google.com.ar https://www.google.co.kr https://www.google.co.nz https://www.google.com.hk https://www.google.com.pe https://translate.google.com https://www.google.co.id https://www.google.co.cr https://www.google.com.my https://www.google.cl https://www.googleadservices.com https://www.google.de https://www.google.it https://www.google.co.jp https://www.google.co.za https://www.google.es https://www.google.com.sg https://www.google.com.co https://www.google.co.uk https://www.google.co.in https://www.google.nl https://www.google.com.ph https://www.google.com.au https://www.google.ca https://www.google.com.br https://www.google.com https://www.google.com.mx https://www.google.fr https://secure.adnxs.com https://attr.ml-api.io https://attr-td.ml-api.io https://images.ctfassets.net https://cdn.bfldr.com https://metrics.brightcove.com https://cf-images.us-east-1.prod.boltdns.net https://hexagon-analytics.com https://s.ml-attr.com https://cdn.cookielaw.org https://id.rlcdn.com https://px.ads.linkedin.com https://frontdoor.knotch.it https://dsum-sec.casalemedia.com https://partners.tremorhub.com https://pixel.rubiconproject.com https://www.facebook.com https://segments.company-target.com https://www.linkedin.com https://px4.ads.linkedin.com https://bat.bing.com https://track.docusign.com https://www.gstatic.com https://storage.googleapis.com https://imagedelivery.net https://app.gatedcontent.com https://images.esign.docusign.com https://www.googletagmanager.com https://t.co https://analytics.twitter.com https://analytics.google.com https://alb.reddit.com https://googleads.g.doubleclick.net https://stats.g.doubleclick.net https://img-taboola.com https://trc.taboola.com https://t.influ2.com https://i.liadm.com https://match.adsrvr.org https://r4.app.yellow.ai; font-src 'self' data: https://sierra.chat:443 https://sierra.chat https://cdn.prod.website-files.com https://images.simplycodes.com https://stylesheets.pixiebrix.com https://cdn.jsdelivr.net https://cdn.yellowmessenger.com https://fonts.gstatic.com https://docucdn-a.akamaihd.net https://cdn.inbenta.io https://use.typekit.net https://api-cdn.usw2.pure.cloud https://api-cdn.usw2.pure.cloud; connect-src 'self' https://api.iterable.com https://api.sitelytics.tech https://p.mdb.tools https://sierra.chat:443 https://sierra.chat https://api-js.mixpanel.com https://api.mixpanel.com https://cdn.prod.website-files.com https://s.yimg.com https://cdn4.forter.com https://a9b3895076a445bdaf9a9aada0ab7287-80e3c780877f.cdn.forter.com https://31ff10b411e04c66a144663da6b34da5-80e3c780877f.cdn.forter.com https://3dcb810e88774d429c6dba71bbee8c34-80e3c780877f.cdn.forter.com https://tag.demandbase.com https://cdn.yellowmessenger.com https://autocomplete.demandbase.com https://segments.company-target.com https://ibc-flow.techtarget.com https://ingesteer.services-prod.nsvcs.net https://www.googletagmanager.com https://www.google.com.co https://www.google.com.mx https://www.google.co.uk https://www.google.es https://www.google.com.br https://www.google.com.sg https://www.google.com.in https://www.google.com.ph https://www.google.ca https://www.google.com.au https://rum.optimizely.com wss://r4.cloud.yellow.ai https://cdn8.forter.com https://12e748c623734740a09ab181abb7a3a1-80e3c780877f.cdn.forter.com https://cdn3.forter.com https://r4.cloud.yellow.ai https://siteperformancetest.net https://wtp.siteperformancetest.net https://privacyportal.onetrust.com https://region1.analytics.google.com https://stats.g.doubleclick.net https://telemetry-s.docusign.net https://telemetry.dev.docusign.net https://www.facebook.com https://www.google-analytics.com https://manifest.prod.boltdns.net https://frontdoor.knotch.it https://bat.bing.com https://bat.bing.net https://ingest.insights.ninetailed.co https://cdn.jsdelivr.net https://unpkg.com https://assets.ctfassets.net https://edge.api.brightcove.com https://house-fastly-signed-us-east-1-prod.brightcovecdn.com https://cdn.cookielaw.org https://telemetry.docusign.net https://geolocation.onetrust.com https://www.google.com https://experience.ninetailed.co https://edge.fullstory.com https://tags.srv.stackadapt.com https://api.company-target.com https://configs.knotch.com https://px.ads.linkedin.com https://rs.fullstory.com https://tag-logger.demandbase.com https://carddealer.knotch.com https://analytics.google.com https://insight.adsrvr.org https://logx.optimizely.com https://app.gatedcontent.com https://guideflow-api-eu-5cv4uu2lra-ew.a.run.app https://protect.docusign.net https://protect-d.docusign.net https://s566810826.t.eloqua.com https://insights.gatedcontent.com https://siteintercept.qualtrics.com https://cdn0.forter.com https://a.docusign.com https://datacollector.docusign.com https://datacollector-demo.docusign.com https://docusign-api.arkoselabs.com https://account.docusign.com https://account-d.docusign.com https://geo.docusign.com https://syndication.twitter.com https://pixel-config.reddit.com https://www.redditstatic.com https://www.googleadservices.com https://api.inbenta.io https://api-gcu1.inbenta.io https://apps.usw2.pure.cloud https://api-cdn.usw2.pure.cloud https://psb.taboola.com https://pips.taboola.com https://cds.taboola.com https://trc-events.taboola.com https://t.influ2.com https://www.influ2.com; frame-src 'self' https://www.youtube.com https://players.brightcove.net https://js.driftt.com https://www.googletagmanager.com https://s.company-target.com https://insight.adsrvr.org https://match.adsrvr.org https://pixel.rubiconproject.com https://cm.g.doubleclick.net https://ib.adnxs.com https://td.doubleclick.net https://www.google.com https://app.guideflow.com https://platform.twitter.com https://chat.docusign.net https://a275532918.cdn.optimizely.com https://app.netlify.com https://apps.usw2.pure.cloud https://api-cdn.usw2.pure.cloud https://hermes.docusign.com https://tsdtocl.com https://docusign-api.arkoselabs.com; media-src 'self' blob: https://manifest.prod.boltdns.net https://house-fastly-signed-us-east-1-prod.brightcovecdn.com https://videos.ctfassets.net https://house-fastly-signed-us-east-1-prod.brightcovecdn.com https://house-fastly-signed-us-east-1-prod.brightcovecdn.com:443 https://manifest.prod.boltdns.net; worker-src 'self' blob:; base-uri 'self'; form-action 'self' https://trial.docusign.com https://ecomservices.docusign.com https://na.account.docusign.com https://app.gatedcontent.com https://datacollector.docusign.com https://datacollector-demo.docusign.com https://docusign-api.arkoselabs.com https://account.docusign.com https://account-d.docusign.com https://protect.docusign.net https://protect-d.docusign.net https://track.docusign.com; object-src 'self' https://players.brightcove.net; report-to csp-endpoint 3 base-uri 'self'; default-src 'self' *.atl-paas.net; script-src 'self' 'unsafe-inline' *.atl-paas.net https://recaptcha.net https://www.recaptcha.net https://accounts.google.com https://www.gstatic.com; style-src 'self' 'unsafe-inline' *.atl-paas.net; img-src 'self' *.atl-paas.net; font-src 'self' *.atl-paas.net; frame-ancestors 'none'; form-action 'self'; report-uri https://web-security-reports.services.atlassian.com/csp-report/id-frontend; report-to csp-default-endpoint; connect-src 'self' *.atl-paas.net https://*.atlassian.com https://*.ingest.sentry.io; object-src 'none' 3 object-src https://players.brightcove.net https://www.realpage.com https://s.realpage.com https://vjs.zencdn.net;img-src * blob: data:; font-src https://acsbapp.com https://www.realpage.com https://s.realpage.com https://use.typekit.net https://fonts.gstatic.com https://vjs.zencdn.net https://www.slant.co data:; style-src *.typekit.net https://www.realpage.com https://s.realpage.com https://fonts.googleapis.com https://www.gstatic.com https://cdn.jsdelivr.net 'unsafe-inline'; frame-ancestors 'self' *.realpage.com *.seismic.com www.realpagelearning.com *.yieldstar.com *.mpfyieldstar.com; report-to csp-report-only; report-uri https://cspreports.realpage.com/api/reports/save/report-only; 3 script-src 'self' 'unsafe-inline' 'unsafe-eval' 'report-sample' https://www.googletagmanager.com https://cdn.jsdelivr.net https://tag.aticdn.net https://www.youtube.com https://www.instagram.com https://platform.linkedin.com https://platform.twitter.com https://connect.facebook.net https://bsky.app https://js-datadome.groupe-sncf.com https://sdk.privacy-center.org https://*.ubiplace.com https://*.aws.vsct.fr https://*.cdn.vsct.fr https://*.smartvigie.fr; worker-src 'self' blob:; report-uri /api/csp-report-only; 3 default-src * data: ; script-src * 'unsafe-inline' 'unsafe-eval' ; style-src * 'unsafe-inline' data: ; frame-ancestors 'none'; report-uri /csp-violation-report-endpoint/ 3 script-src 'unsafe-eval' blob: 'self' meta.wikimedia.org *.wikimedia.org *.wikipedia.org *.wikinews.org *.wiktionary.org *.wikibooks.org *.wikiversity.org *.wikisource.org wikisource.org *.wikiquote.org *.wikidata.org *.wikifunctions.org *.wikivoyage.org *.mediawiki.org 'unsafe-inline' auth.wikimedia.org; default-src 'self' data: blob: upload.wikimedia.org https://commons.wikimedia.org meta.wikimedia.org *.wikimedia.org *.wikipedia.org *.wikinews.org *.wiktionary.org *.wikibooks.org *.wikiversity.org *.wikisource.org wikisource.org *.wikiquote.org *.wikidata.org *.wikifunctions.org *.wikivoyage.org *.mediawiki.org wikimedia.org en.wikipedia.org en.wikibooks.org en.wikinews.org en.wikiquote.org en.wikisource.org en.wikiversity.org en.wikivoyage.org en.wiktionary.org www.mediawiki.org api.wikimedia.org commons.wikimedia.org foundation.wikimedia.org incubator.wikimedia.org species.wikimedia.org wikimania.wikimedia.org www.wikidata.org www.wikifunctions.org auth.wikimedia.org; style-src 'self' data: blob: upload.wikimedia.org https://commons.wikimedia.org meta.wikimedia.org *.wikimedia.org *.wikipedia.org *.wikinews.org *.wiktionary.org *.wikibooks.org *.wikiversity.org *.wikisource.org wikisource.org *.wikiquote.org *.wikidata.org *.wikifunctions.org *.wikivoyage.org *.mediawiki.org wikimedia.org 'unsafe-inline'; object-src 'none'; report-uri /w/api.php?action=cspreport&format=json&reportonly=1 3 default-src https: data: 'unsafe-eval' 'unsafe-inline'; object-src 'none'; report-uri /csp-violation-report-endpoint.php; report-to csp-endpoint 3 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://www.googletagmanager.com https://widget.trustpilot.com https://prod.spline.design; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; font-src 'self' https://fonts.gstatic.com; img-src 'self' data: blob: https:; connect-src 'self' https://www.google-analytics.com https://*.supabase.co https://*.upstash.io https://prod.spline.design; frame-src 'self' https://widget.trustpilot.com; media-src 'self'; object-src 'none'; base-uri 'self' 3 default-src 'self'; script-src 'self' 'unsafe-inline' https://cdn-ukwest.onetrust.com/scripttemplates/ https://websdk.appsflyer.com/ https://www.google.com/recaptcha/enterprise.js https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://cdn.segment.com https://static.moonpay.com https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; object-src 'none'; base-uri 'self'; connect-src 'self' https://www.moonpay.com https://api.moonpay.com https://api.coingecko.com https://cdn-ukwest.onetrust.com https://*.launchdarkly.com https://geolocation.onetrust.com https://vitals.vercel-insights.com https://*.google-analytics.com https://*.analytics.google.com https://logs.browser-intake-datadoghq.com https://cdn.segment.com https://otel-collector.moonpay.com https://otel-collector.moonpaycloud.com https://otel-collector.moonpay-staging.com; font-src 'self' https://static.moonpay.com; frame-src 'self' https://buy.moonpay.com https://sell.moonpay.com https://www.google.com https://www.google.com/recaptcha/ https://recaptcha.google.com/recaptcha/; img-src 'self' https://cdn-ukwest.onetrust.com https://images.ctfassets.net https://payload-marketing.moonpay.com https://staging.moonpay-marketing-c337344.payloadcms.app https://static.moonpay.com; manifest-src 'self'; media-src 'self' https://payload-marketing.moonpay.com https://staging.moonpay-marketing-c337344.payloadcms.app; worker-src 'self'; frame-ancestors 'none'; report-uri https://csp-report.browser-intake-datadoghq.com/api/v2/logs?dd-api-key=pub4f9819648cf6c369f00daa5b3a3a0ea7&dd-evp-origin=content-security-policy&ddsource=csp-report 3 default-src 'self'; img-src *; style-src 'unsafe-inline'; script-src 'unsafe-inline' 'unsafe-eval' 3 default-src 'self' https://*.ebizautos.com; img-src *; script-src 'self' 'unsafe-inline' *; font-src *; media-src *; frame-src *; manifest-src 'self'; style-src 'self' 'unsafe-inline' *; connect-src https://*; object-src 'none'; worker-src 'none'; base-uri 'self'; 3 default-src * 'unsafe-inline' 'unsafe-eval' blob:; frame-src *; img-src * data:; script-src * 'report-sample' 'unsafe-inline' 'unsafe-eval' blob:; style-src * 'report-sample' 'unsafe-inline'; base-uri *; form-action *; frame-ancestors 'self' 3 default-src 'self' 'unsafe-inline' 'unsafe-eval' data: cdn.privacy-mgmt.com maps.googleapis.com www.news.co.uk uk-script.dotmetrics.net *.google-analytics.com *.doubleclick.net; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.googleapis.com cdn.privacy-mgmt.com *.tiqcdn.com unpkg.com uk-script.dotmetrics.net *.scorecardresearch.com *.google-analytics.com *.googletagmanager.com *.brightcove.com; style-src 'self' 'unsafe-inline' data: use.fontawesome.com fonts.googleapis.com use.typekit.net maps.google.com unpkg.com; img-src 'self' data: *.googleapis.com *.gstatic.com *.google-analytics.com *.scorecardresearch.com *.news.co.uk www.news.co.uk *.dotmetrics.net newsuk.s3.amazonaws.com *.google.com s.w.org ps.w.org ts.w.org secure.gravatar.com www.gravatar.com; font-src 'self' data: fonts.gstatic.com; frame-src 'self' *.youtube.com *.vimeo.com *.brightcove.com cdn.privacy-mgmt.com; 3 default-src 'self' 'unsafe-inline' 'unsafe-eval' data: https://fonts.gstatic.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://*.greenhouse.io https://*.osano.com blob: https://pages.e2open.com https://cdn-cookieyes.com https://play.vidyard.com https://snap.licdn.com https://ws.zoominfo.com https://*.clarity.ms https://cdn.bizible.com https://www.googletagmanager.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://js-agent.newrelic.com https://*.6sc.co https://*.adsrvr.org https://*.abrankings.com https://*.google-analytics.com https://bat.bing.com https://*.hotjar.com https://*.crazyegg.com https://connect.facebook.net https://*.marketo.net https://*.demandbase.com https://*.ads-twitter.com; style-src 'self' 'unsafe-inline' data: https://*.greenhouse.io https://*.osano.com https://pages.e2open.com https://cdn.jsdelivr.net https://*.googleapis.com; img-src 'self' data: https://secure.gravatar.com https://www.gravatar.com https://*.bizible.com https://*.bizibly.com https://*.licdn.com https://*.clarity.ms https://*.googlesyndication.com https://*.doubleclick.net https://stats.g.doubleclick.net https://*.linkedin.com https://t.co https://analytics.twitter.com https://*.6sc.co https://*.bing.com https://*.facebook.com https://*.rlcdn.com https://*.company-target.com https://*.facebook.net https://cdn-cookieyes.com https://*.vidyard.com secure.gravatar.com www.gravatar.com; connect-src 'self' https://*.greenhouse.io https://*.osano.com https://*.linkedin.com https://*.licdn.com https://www.google.com https://*.google-analytics.com https://sheets.googleapis.com https://*.vidyard.com https://bam.nr-data.net https://*.linkedin.com https://*.licdn.com https://www.google-analytics.com https://region1.google-analytics.com https://secure.adnxs.com https://*.6sc.co https://*.6sense.com https://api.company-target.com https://script.crazyegg.com https://*.mktoresp.com https://*.clarity.ms https://*.abrankings.com https://insight.adsrvr.org https://*.demandbase.com https://*.facebook.com https://*.hotjar.io https://log.cookieyes.com https://cdn-cookieyes.com; frame-src 'self' https://*.greenhouse.io https://*.osano.com https://pages.e2open.com https://www.googletagmanager.com https://*.company-target.com https://*.adsrvr.org https://*.vidyard.com; worker-src 'self' https://*.osano.com blob:; 3 default-src 'self'; script-src 'self' https://cdnjs.cloudflare.com https://www.googletagmanager.com https://www.google.com https://www.gstatic.com https://googleads.g.doubleclick.net https://www.googleadservices.com https://www.google.fi https://connect.facebook.net https://support.hostaan.com https://widget.trustmary.com https://embed.trustmary.com 'unsafe-inline' 'unsafe-eval'; style-src 'self' https://fonts.googleapis.com https://www.gstatic.com https://cdnjs.cloudflare.com https://support.hostaan.com 'unsafe-inline' 'unsafe-eval'; font-src 'self' https://fonts.gstatic.com https://support.hostaan.com data:; connect-src 'self' https://region1.google-analytics.com https://embed.trustmary.io https://stats.g.doubleclick.net https://www.google-analytics.com https://*.facebook.com https://www.google.com https://www.googletagmanager.com https://region1.analytics.google.com https://googleads.g.doubleclick.net https://www.googleadservices.com https://www.google.fi https://support.hostaan.com; media-src 'self' https://support.hostaan.com; img-src 'self' blob: data: https://www.googletagmanager.com https://fonts.gstatic.com https://translate.google.com https://widget.trustmary.com/ https://d2nce6johdc51d.cloudfront.net https://lh3.googleusercontent.com https://www.google.se https://www.google.fi https://www.google.com https://stats.g.doubleclick.net https://www.google.fi https://www.googleadservices.com https://googleads.g.doubleclick.net https://www.facebook.com https://support.hostaan.com; frame-src 'self' https://www.youtube.com https://www.facebook.com https://www.googletagmanager.com https://www.google.com https://support.hostaan.com https://td.doubleclick.net; worker-src 'self' blob:; object-src 'none'; frame-ancestors 'self' https://www.hostaan.fi; report-uri https://n8n.ppweb.fi/webhook/da8630cf-3a65-402b-b95f-6fa58e667ed6; 3 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://www.googletagmanager.com https://www.google-analytics.com https://globalservices.conde.digital https://privacy.condenastdigital.com; style-src 'self' 'unsafe-inline'; img-src 'self' data: https: http:; font-src 'self' data:; connect-src 'self' https://strapi.gp-prod.conde.digital https://strapi-bus-eng.gp-prod-na-0.conde.digital https://www.google-analytics.com https://com-condenast-prod1.collector.snplow.net https://privacy.condenastdigital.com; frame-src 'self' https://vanityfair-poty.figma.site https://ion-jeep-01175370.figma.site https://bird-year-19865975.figma.site; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'none'; upgrade-insecure-requests 3 default-src 'none'; script-src 'self'; connect-src 'self'; img-src 'self'; style-src 'self'; frame-ancestors 'self'; form-action 'self'; 3 default-src https:; script-src https: 'unsafe-inline' 'unsafe-eval' https://*.googletagmanager.com https://www.googleadservices.com https://www.google.com https://www.googletagmanager.com https://*.googlesyndication.com https://*.googleapis.com https://*.doubleclick.net; style-src https: 'unsafe-inline'; img-src data: https: 'unsafe-inline'; font-src data: https: 'unsafe-inline'; worker-src blob: https:; 3 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://dock.ui.bosch.tech https://www.googletagmanager.com https://www.google-analytics.com https://btm.bosch.com https://www.youtube.com https://maps.google.com; style-src 'self' 'unsafe-inline'; object-src 'none'; base-uri 'self'; connect-src 'self' https://search.internet.bosch.com https://bosch-i3-caas-api.e-spirit.cloud https://*.google-analytics.com https://www.googletagmanager.com https://endpoint.chatbot-suite.bosch.tech https://maps.googleapis.com https://btm.bosch.com https://cx.bosch-so.com https://dock.ui.bosch.tech; font-src 'self' https://fonts.gstatic.com; frame-src 'self' https://www.youtube-nocookie.com https://www.youtube.com https://crdostaticwebsite337215.z6.web.core.windows.net https://crdopublicationswebsite.z6.web.core.windows.net; img-src 'self' data: https://assets.bosch.com https://www.googletagmanager.com https://www.google-analytics.com https://i.ytimg.com https://maps.google.com https://maps.gstatic.com; manifest-src 'self'; media-src 'self' https://assets.bosch.com; style-src-elem 'self' 'unsafe-inline' https://btm.bosch.com https://fonts.googleapis.com https://webchatplugins.blob.core.windows.net; worker-src 'none'; report-uri https://o4508243129991168.ingest.de.sentry.io/api/4508243155288144/security/?sentry_key=2f9480313f00b63a26560fd685315765; report-to csp-endpoint 3 default-src 'self' https://*.cit.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://*.cit.com https://snap.licdn.com https://munchkin.marketo.net https://www.googletagmanager.com https://googleads.g.doubleclick.net https://static.ads-twitter.com https://s.yimg.com https://bat.bing.com https://connect.facebook.net https://static.hotjar.com https://script.hotjar.com https://utt.impactcdn.com https://cdn.cookielaw.org https://www.fdic.gov https://assets.adobedtm.com https://siteintercept.qualtrics.com https://siteimproveanalytics.com https://www.everestjs.net https://zn780vxspp4zyl7dr-citcx.siteintercept.qualtrics.com https://citgroup.demdex.net https://pixel.everesttech.net https://sp.analytics.yahoo.com https://g.3gl.net https://cg-7ce3a684-2bed-464c-8d1c-1a0e4cba69c6.s3.us-gov-west-1.amazonaws.com; connect-src 'self' https://*.cit.com https://graphql.contentful.com https://cms-images.cit.com https://cdn.cookielaw.org https://privacyportal.onetrust.com https://geolocation.onetrust.com https://dpm.demdex.net https://edge.adobedc.net https://bat.bing.com https://lib-us-2.brilliantcollector.com https://stats.g.doubleclick.net https://analytics.google.com https://www.google.com https://lasteventf-tm.everesttech.net https://s.yimg.com https://px.ads.linkedin.com https://siteintercept.qualtrics.com https://151-fhs-046.mktoresp.com https://894-itd-344.mktoresp.com https://284-lbb-572.mktoresp.com https://022-ygl-099151-fhs-046284-lbb-572.mktoresp.com; worker-src 'self'; style-src 'self' 'unsafe-inline' https://*.cit.com https://cdn.cookielaw.org; style-src-elem 'self' 'unsafe-inline' https://fonts.googleapis.com https://cdn.cookielaw.org; img-src 'self' https://*.cit.com https://cms-images.cit.com https://2884.global.siteimproveanalytics.io https://dpm.demdex.net https://cdn.cookielaw.org https://px.ads.linkedin.com https://www.google.com https://www.googletagmanager.com https://googleads.g.doubleclick.net https://bat.bing.com https://sp.analytics.yahoo.com https://cm.everesttech.net https://www.linkedin.com; frame-src 'self' https://*.cit.com https://www.googletagmanager.com https://fast.wistia.net https://citgroup.demdex.net; frame-ancestors 'self' https://customerfinancing.directcapital-sit.com https://customerfinancing.directcapital2.com https://www.customerfinancing.com https://customerfinancing.directcapital-test1.com https://customerfinancing.directcapital-test2.com https://customerfinancing.directcapital-test3.com https://customerfinancing.directcapital-test4.com onlineapps-conv.readiness.ibanking-services.com onlineapps.ibanking-services.com ibanking-services.com https://*.fisglobal.com https://*.citbank.com https://citcom-dev.ase1-dev.citnet.cit.com https://*.firstcitizens.com; media-src 'self'; font-src 'self'; 3 default-src * data:; script-src * 'unsafe-eval'; script-src-elem * 'unsafe-inline'; script-src-attr *; style-src * 'unsafe-inline' blob:; style-src-elem * 'unsafe-inline'; style-src-attr * 'unsafe-inline'; img-src * 'self' data: blob:; font-src * 'self' data: blob:; connect-src * 'self' blob:; media-src * 'self' blob:; object-src * 'self' 'unsafe-inline' blob:; prefetch-src * 'self' blob:; child-src * 'self' blob:; frame-src * 'self' blob:; worker-src * 'self' blob:; frame-ancestors * 'self' blob:; form-action *; upgrade-insecure-requests; base-uri * 'self'; manifest-src * blob: sandbox allow-downloads allow-forms allow-modals allow-popups allow-same-origin allow-scripts allow-top-navigation allow-top-navigation-to-custom-protocols; 3 base-uri 'self'; connect-src 'self' https://*.google.com https://boards-api.greenhouse.io https://images.prismic.io https://o43253.ingest.sentry.io https://pagead2.googlesyndication.com https://www.gstatic.com https://bat.bing.com https://*.clarity.ms; default-src 'self'; font-src 'self'; form-action 'none'; frame-ancestors 'none'; frame-src https://*.enterprise.ada.com https://boards.greenhouse.io https://insight.adsrvr.org https://td.doubleclick.net https://tpc.googlesyndication.com https://www.youtube-nocookie.com; img-src 'self' data: https://adahealth.cdn.prismic.io https://assets.ada.com https://connect.facebook.net https://googleads.g.doubleclick.net https://images.prismic.io https://prismic-io.s3.amazonaws.com https://www.facebook.com https://pagead2.googlesyndication.com https://adservice.google.com https://www.google.com https://www.googletagmanager.com https://bat.bing.com https://*.clarity.ms; manifest-src 'self'; media-src 'self' https://adahealth.cdn.prismic.io; script-src 'self' 'unsafe-inline' https://boards.greenhouse.io https://connect.facebook.net https://googleads.g.doubleclick.net https://js.adsrvr.org https://tpc.googlesyndication.com https://www.google.com https://www.googleadservices.com https://www.googletagmanager.com https://www.youtube.com https://bat.bing.com https://www.clarity.ms; style-src 'self' 'unsafe-inline'; 3 default-src 'self'; img-src 'self' https://listafirme.ro https://*.ytimg.com https://flagcdn.com https://mdbootstrap.com https://img.youtube.com https://*.googleusercontent.com https://*.googleapis.com https://*.gstatic.com https://*.google.com https://cdn.jsdelivr.net https://www.googletagmanager.com data:; frame-src https://listafirme.ro https://www.youtube-nocookie.com https://www.youtube.com https://static.addtoany.com https://www.google.com https://accounts.google.com https://*.firebaseapp.com; script-src 'self' https://listafirme.ro https://www.googletagmanager.com https://*.google-analytics.com https://listafirme.eu https://static.addtoany.com https://platform.listafirme.eu https://platform.listafirme.ro https://cdn.jsdelivr.net https://*.cloudflare.com 'unsafe-inline' https://*.google.com https://*.googleapis.com https://*.gstatic.com https://static.cloudflareinsights.com; style-src 'self' 'unsafe-inline' https://listafirme.ro https://*.cloudflare.com https://*.google.com https://*.googleapis.com; font-src 'self' https://listafirme.ro https://*.cloudflare.com https://*.googleapis.com https://*.gstatic.com; connect-src 'self' https://listafirme.ro https://platform.listafirme.ro https://*.googlevideo.com https://*.google-analytics.com https://static.addtoany.com https://www.google.com https://accounts.google.com https://*.googleapis.com https://cloudflareinsights.com; object-src 'none'; base-uri 'self'; form-action 'self'; 3 default-src 'self'; script-src 'report-sample' 'self' 'unsafe-inline' 'unsafe-eval' *.hubspot.com *.cookielaw.org *.cdntwrk.com *.wistia.com *.wistia.net *.q2.com *.sentry-cdn.com *.clarity.ms *.google.com *.googletagmanager.com *.googleapis.com *.googleadservices.com *.gstatic.com *.hsappstatic.com *.hsappstatic.net *.hubspot.net *.hs-banner.com *.hsadspixel.net *.hs-analytics.com *.hs-analytics.net *.licdn.com *.marketo.net *.marketo.com *.zoominfo.com *.bizible.com *.6sc.co *.qualified.com *.segment.com *.bugcrowd.com *.bugcrowdusercontent.com bugcrowd.com *.jsdeliver.net *.jsdelivr.net *.cloudflare.com *.doubleclick.net *.youtube.com *.hubspotusercontent-na1.net *.pathfactory.com *.zuddl.com 8ab0a26cb0027939bcf5-49c99c3c0c9c98b3365b710757036e1b.ssl.cf5.rackcdn.com *.crazyegg.com *.callrail.com; style-src 'self' *.q2.com 'report-sample' 'unsafe-inline' *.cdntwrk.com *.googleapis.com *.hsappstatic.net *.hubspot.net *.jsdeliver.net *.jsdelivr.net *.marketo.com 7044196.fs1.hubspotusercontent-na1.net 7044196.fs2.hubspotusercontent-na1.net *.hubspotusercontent-na1.net *.pathfactory.com *.googletagmanager.com *.zuddl.com *.qualified.com; object-src 'none'; base-uri 'self'; connect-src 'self' *.mktoresp.com *.hubspotusercontent-na1.net *.google.com *.hubspot.com *.hs-banner.com *.onetrust.com *.cookielaw.org *.wistia.com *.embed-cloudfront.wistia.com *.wistia.net *.6sc.co *.6sense.com *.qualified.com wss://*.qualified.com *.segment.com *.segment.io *.linkedin.com *.google-analytics.com *.clarity.ms *.hubapi.com *.doubleclick.com https://stats.g.doubleclick.net *.zoominfo.com *.adnxs.com *.litix.io *.marketo.com *.doubleclick.net *.youtube.com *.pathfactory.com *.zuddl.com api.prod.zuddl.com *.crazyegg.com *.gonorth.io *.callrail.com *.googleadservices.com *.sentry-cdn.com *.hsappstatic.net; font-src 'self' data: *.gstatic.com *.cdntwrk.com *.wistia.com *.wistia.net 7044196.fs1.hubspotusercontent-na1.net *.pathfactory.com *.zuddl.com; frame-src 'self' *.q2.com *.qualified.com *.doubleclick.net *.wistia.net *.gstatic.com *.google.com *.googletagmanager.com *.bugcrowd.com bugcrowd.com *.hubspotvideo.com *.marketo.com *.youtube.com *.pathfactory.com *.uberflip.com *.zuddl.com *.on24.com *.qualified.com; img-src 'self' *.q2.com data: *.hubspotusercontent-na1.net *.hsappstatic.net *.6sc.co *.cdntwrk.com *.cookielaw.org *.wistia.com *.hsforms.com *.linkedin.com *.hubspot.com *.hubspot.net *.bizible.com *.cloudinary.com *.clarity.ms *.bing.com *.googletagmanager.com *.placeholder.com *.marketo.com googleads.g.doubleclick.net *.doubleclick.net *.google.com *.doubleclick.net *.youtube.com *.hubspotusercontent40.net *.pathfactory.com *.bizibly.com *.gstatic.com *.zuddl.com *.imgix.net *.wistia.net *.qualified.com; manifest-src 'self'; media-src 'self' *.q2.com 7044196.fs1.hubspotusercontent-na1.net 7044196.fs2.hubspotusercontent-na1.net 7044196.fs1.hubspotusercontent-eu1.net 7044196.fs2.hubspotusercontent-eu1.net *.marketo.com blob: *.doubleclick.net *.youtube.com *.pathfactory.com; form-action 'self' *.marketo.com *.mktoweb.com *.zuddl.com *.callrail.com *.googleadservices.com *.qualified.com; frame-ancestors 'self' *.q2.com *.pathfactory.com *.lookbookhq.com; report-to https://343747560e392f7a31ae9a0247c09302.report-uri.com/r/d/csp/reportOnly 3 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com bonialconnect.com *.oney.io assets.app.smart-tribune.com cdnjs.cloudflare.com api-gateway.app.smart-tribune.com polyfill-fastly.io https://epaync.nc/static/ 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.adyen.com pay.google.com payments-eu.amazon.com *.amazon.de secure.ogone.com v1-sim.preprod.psp-solutions.com v2-sim.preprod.psp-solutions.com www.facebook.com/tr/ bpcepaymentservices-3ds-vdm.wlp-acs.com bnpp-3ds-vdm.wlp-acs.com assets.app.smart-tribune.com cdnjs.cloudflare.com api-gateway.app.smart-tribune.com polyfill-fastly.io https://epaync.nc/vads-payment/ https://epaync.nc/api-payment/ https://epaync.nc/static/ https://connect-v2.fintecture.com https://connect-v2-sbx.fintecture.com 'self' 'unsafe-inline'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.adyen.com pay.google.com secure.ogone.com ogone.test.v-psp.com widget.trustpilot.com gum.criteo.com s.salecycle.com https://10766555.fls.doubleclick.net/ static.criteo.net/ www.facebook.com/ magasins.bureau-vallee.fr magasins.bureau-vallee.be magasins.bureau-vallee.nc magasins.bureau-vallee.re magasins.bureau-vallee.gf magasins.bureau-vallee.yt magasins.bureau-vallee.gp magasins.bureau-vallee.sx t.clic2buy.com bpcepaymentservices-3ds-vdm.wlp-acs.com assets.app.smart-tribune.com cdnjs.cloudflare.com api-gateway.app.smart-tribune.com polyfill-fastly.io td.doubleclick.net https://epaync.nc/vads-payment/ https://epaync.nc/static/ https://www.googletagmanager.com/ 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io *.paypal.com *.typekit.net *.gstatic.com *.adyen.com pay.google.com *.payments-amazon.com *.media-amazon.com *.paypalobjects.com *.salesmanago.pl *.salesmanago.es *.salesmanago.com a.tile.openstreetmap.org b.tile.openstreetmap.org c.tile.openstreetmap.org bva-preprod-fbi-fr-media-s3.s3.amazonaws.com bva-recette-fbi-fr-media-s3.s3.amazonaws.com bv-prd-fbi-fr-media.s3.eu-west-3.amazonaws.com bv-prd-fbi-fr-media.s3.amazonaws.com d2hlj6xfalexml.cloudfront.net d3n1o8ch79p937.cloudfront.net dxbyzx5id4chj.cloudfront.net bonialconnect.com content-media.bonial.biz rum-metrics.quanta.io bat.bing.com ib.adnxs.com www.facebook.com cm.g.doubleclick.net gum.criteo.com dis.criteo.com sync-t1.taboola.com x.bidswitch.net r.casalemedia.com ad.360yield.com contextual.media.net sync.outbrain.com pixel.rubiconproject.com match.sharethrough.com rtb-csync.smartadserver.com criteo-sync.teads.tv eb2.3lift.com ups.analytics.yahoo.com e1.emxdgt.com cm.adform.net visitor.omnitagjs.com id5-sync.com matching.ivitrack.com exchange.mediavine.com simage2.pubmatic.com criteo-partners.tremorhub.com ad.yieldlab.net sync-criteo.ads.yieldmo.com beacon.krxd.net s.thebrighttag.com www.bureau-vallee.fr www.google.fr bvci-e2.colop.com utypia.bureau-vallee.fr *.oney.io assets.app.smart-tribune.com cdnjs.cloudflare.com api-gateway.app.smart-tribune.com polyfill-fastly.io www.gstatic.com jadserve.postrelease.com ad.doubleclick.net public-prod-dspcookiematching.dmxleo.com https://epaync.nc/static/latest/images/type-carte/ https://epaync.nc/static/ https://epaync.nc/vads-payment/ http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ https://assets.fintecture.com 'self' data: data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com *.salesmanago.pl *.salesmanago.es *.salesmanago.com magasins.bureau-vallee.fr widget.trustpilot.com bonialconnect.com s3.amazonaws.com maps.googleapis.com/ d16fk4ms6rqz1v.cloudfront.net bat.bing.com appstatic.quanta.io try.abtasty.com acdn.adnxs.com static.criteo.net sslwidget.criteo.com connect.facebook.net cdn.jsdelivr.net static.target2sell.com js-agent.newrelic.com/ bam.eu01.nr-data.net *.oney.io magasins.bureau-vallee.be magasins.bureau-vallee.nc magasins.bureau-vallee.re magasins.bureau-vallee.gf magasins.bureau-vallee.yt magasins.bureau-vallee.gp magasins.bureau-vallee.sx rs.clic2buy.com assets.app.smart-tribune.com cdnjs.cloudflare.com api-gateway.app.smart-tribune.com polyfill-fastly.io pagead2.googlesyndication.com tpc.googlesyndication.com *.algolia.io https://epaync.nc/api-payment/ https://epaync.nc/static/ http://www.googletagmanager.com/ https://www.googletagmanager.com/ assets-staging.oney.io *.gstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com assets.app.smart-tribune.com cdnjs.cloudflare.com api-gateway.app.smart-tribune.com polyfill-fastly.io https://epaync.nc/static/ *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src pay.google.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.adyen.com payments-eu.amazon.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io *.salesmanago.pl *.salesmanago.es *.salesmanago.com s3.eu-west-1.amazonaws.com www.bonialserviceswidget.de maps.googleapis.com trackingapi.bonial.fr bonialconnect.com dcinfos-cache.abtasty.com ariane.abtasty.com c.salecycle.com api.ipify.org i.salecycle.com wss://ws.salecycle.com/ region1.analytics.google.com www.facebook.com serv-api.target2sell.com bat.bing.com/actionp/ rum-metrics.quanta.io reco.target2sell.com bam.eu01.nr-data.net www.google.fr *.oney.io autocomplete.geocoder.api.here.com assets.app.smart-tribune.com cdnjs.cloudflare.com api-gateway.app.smart-tribune.com polyfill-fastly.io try.abtasty.com pagead2.googlesyndication.com measurement-api.criteo.com apigw-cf.bva-integ-web.decade.fr https://epaync.nc/vads-payment/ https://epaync.nc/api-payment/ http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ bva-recette-impression-s3.s3.eu-west-3.amazonaws.com bva-preprod-impression-s3.s3.eu-west-3.amazonaws.com bva-prod-impression-s3.s3.eu-west-3.amazonaws.com *.google-analytics.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.salesmanago.pl *.salesmanago.es *.salesmanago.com https://epaync.nc/vads-payment/ https://epaync.nc/api-payment/ https://epaync.nc/static/ *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 3 default-src https: 'unsafe-inline' 'unsafe-eval' 3 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.modo.com.ar fonts.googleapis.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors *.magerocket.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.gocuotas.com 'self'; frame-src bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.mercadopago.com.ar mercadopago.com.ar *.getblue.io *.magerocket.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com https://mobbex.com *.gocuotas.com www.facebook.com *.weltpixel.com *.googletagmanager.com *.doubleclick.net 'self' 'unsafe-inline'; img-src data: widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io *.google.com.ar *.google.es *.google.com.uy *.mercadopago.com.ar *.modo.com.ar *.magerocket.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.mobbex.com *.gocuotas.com flagpedia.net *.gstatic.com *.facebook.com *.reddit.com *.ads-twitter.com t.co *.twitter.com *.bing.com *.clarity.ms *.googletagmanager.com *.doubleclick.net *.google.com data: 'self' 'unsafe-inline'; script-src www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.woowup.com *.hotjar.com *.pageimprove.io pageimprove.io *.getblue.io *.adidas.com *.modo.com.ar *.magerocket.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.mobbex.com *.gocuotas.com *.gstatic.com maps.googleapis.com cdn.ampproject.org www.gstatic.com connect.facebook.net *.googletagmanager.com *.googleadservices.com *.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.bing.com *.clarity.ms unpkg.com *.doubleclick.net https://merchants.playdigital.com.ar/ https://merchants.preprod.playdigital.com.ar/ https://ecommerce-modal.modo.com.ar/ https://ecommerce-modal.preprod.modo.com.ar/ 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com maxcdn.bootstrapcdn.com *.gstatic.com www.gstatic.com *.tagmanager.google.com *.googletagmanager.com https://ecommerce-modal.modo.com.ar/ https://ecommerce-modal.preprod.modo.com.ar/ 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.pangle-ads.com *.modo.com.ar *.google.com.ar *.google.com *.magerocket.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.mobbex.com *.gocuotas.com www.gstatic.com maps.googleapis.com cdn.ampproject.org www.googleapis.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.com *.clarity.ms *.doubleclick.net *.run.app https://merchants.playdigital.com.ar/ https://merchants.preprod.playdigital.com.ar/ https://ecommerce-modal.modo.com.ar/ https://ecommerce-modal.preprod.modo.com.ar/ 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 3 default-src 'self';form-action 'self'; object-src 'self'; frame-ancestors 'self'; connect-src 'self' ely-keskus.fi *.youtube.com *.tyomarkkinatori.fi *.ahtp.fi keha-matomo-sdg-qa-qa.azurewebsites.net *.cookiebot.com wss://*.tyomarkkinatori.fi *.elisa.fi wss://*.elisa.fi tetyomarkkinatori.boost.ai lukija.aimater.com fonts.gstatic.com data:; style-src 'self' 'unsafe-inline' *.elisa.fi fonts.googleapis.com *.youtube.com gstatic.com blob:; img-src * data: blob:; worker-src 'self' blob:; script-src 'self' 'unsafe-inline' *.tyomarkkinatori.fi *.ahtp.fi *.elisa.fi lukija.aimater.com tetyomarkkinatori.boost.ai *.cookiebot.com keha-matomo-sdg-qa-qa.azurewebsites.net youtube.com blob:; frame-src 'self' data: feed.mikle.com *.elisadesk.com *.cookiebot.com *.youtube.com; media-src 'self' data: blob:; font-src 'self' data: fonts.gstatic.com; report-uri https://csp-report-fa-prod.azurewebsites.net/api/csp-report; 3 font-src *.typekit.net data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com www.novaturas.lt dev-lt-novaturas.readymage.com * 'self'; frame-src fast.amc.demdex.net *.adobe.com secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.google.com www.novaturas.lt https://track.adform.net https://www.googletagmanager.com https://www.google.com https://master.d28zlv4dg2b2g7.amplifyapp.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com validator.swagger.io https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://img.youtube.com 'self' https://localhost https://novaturas-gwe-1661146907.readymage.com https://novaturas-gwe-1661146907.readymage-media.com https://prod-lt-novaturas.readymage.com https://www.google.com https://hatscripts.github.io https://www.google-analytics.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.google.com/recaptcha/ www.gstatic.com/recaptcha/ https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ s7.addthis.com 'unsafe-inline' 'unsafe-eval' https://static.hotjar.com https://googleads.g.doubleclick.net https://connect.facebook.net https://www.google.com https://s2.adform.net https://track.adform.net https://cdn.mxapis.com/service-worker.js https://www.googletagmanager.com https://www.google-analytics.com https://svht.tradedoubler.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com *.googletagmanager.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://static.klaviyo.com 'unsafe-inline' 'unsafe-eval' *.typekit.net unsafe-inline 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ ekr.zdassets.com/ 'self' https://bam.eu01.nr-data.net https://staging.nov.indvp.com https://pim.novatours.eu https://development.nov.indvp.com https://analytics.google.com https://stats.g.doubleclick.net https://www.googletagmanager.com https://www.google-analytics.com ws: api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' https://dev-lt-novaturas.readymage.com https://stage-lt-novaturas.readymage.com https://staging.nov.indvp.com https://pim.novatours.eu https://development.nov.indvp.com https://novaturas-gwe-1661146907.readymage-media.com https://use.typekit.net https://www.googletagmanager.com https://localhost 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 3 font-src data: *.gstatic.com *.tryggehandel.net tryggehandel.net *.googleapis.com googleapis.com *.adsrvr.org data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.collector.se *.cardinalcommerce.com *.jobylon.com *.doubleclick.net *.proffs.se *.walleydev.com *.walleypay.com doubleclick.net *.adsrvr.org *.dotdigital-pages.com *.dotdigital.com *.trustpilot.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://images.unsplash.com googleadservices.com google-analytics.com *.magentocommerce.com *.s.ytimg.com *.googleadservices.com *.google-analytics.com *.googleapis.com googleapis.com *.gstatic.com *.collector.se *.adnxs.com *.byggmax.se *.byggmax.no *.byggmax.fi *.byggmax.dk *.byggmax.com byggmax.se byggmax.no byggmax.fi byggmax.com byggmax.dk www.byggmax.se www.byggmax.no www.byggmax.fi www.byggmax.dk *.bing.com bing.com *.teads.tv teads.tv *.smartadserver.com smartadserver.com *.rubiconproject.com rubiconproject.com *.3lift.com 3lift.com *.smaato.net *.taboola.com taboola.com *.doubleclick.com *.360yield.com 360yield.com *.yahoo.com *.casalemedia.com casalemedia.com *.openx.net *.sharethrough.com sharethrough.com *.bidswitch.net *.pubmatic.com pubmatic.com *.omnitagjs.com omnitagjs.com *.yieldmo.com yieldmo.com *.ivitrack.com ivitrack.com *.advertising.com *.stickyadstv.com *.media.net media.net *.doubleclick.net *.e-planning.net *.clmbtech.com *.adform.net adform.net *.liadm.com *.postrelease.com postrelease.com *.smartclip.net *.krxd.net *.ad-stir.com *.outbrain.com outbrain.com *.tremorhub.com tremorhub.com *.demdex.net *.pingdom.net *.adscale.de *.twiago.com *.google.com *.google.se *.bluekai.com *.wisepops.com *.tapad.com *.mgid.com *.rambler.ru *.thebrighttag.com *.walleypay.com *.1rx.io 1rx.io id5-sync.com *.id5-sync.com *.mediavine.com mediavine.com *.yieldlab.net yieldlab.net *.emxdgt.com emxdgt.com *.unrulymedia.com unrulymedia.com *.tryggehandel.net tryggehandel.net adnxs.com cm.g.doubleclick.net bidswitch.net www.facebook.com *.quantserve.com quantserve.com *.adsrvr.org *.trackedlink.net https://cdn.flbx.io data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.google-analytics.com *.collector.se *.assets.adobedtm.com *.authorize.net *.geostag.cardinalcommerce.com *.paypal.com *.vimeo.com *.ccdc02.com google.com *.braintreegateway.com *.ytimg.com *.signifyd.com *.adnxs.com adnxs.com adtr.io *.googletagmanager.com *.trackedlink.net *.jobylon.com *.doubleclick.net doubleclick.net *.googleapis.com googleapis.com *.byggmax.se *.byggmax.no *.byggmax.fi *.byggmax.com *.byggmax.dk byggmax.se byggmax.no byggmax.fi byggmax.com byggmax.dk www.byggmax.se www.byggmax.no www.byggmax.fi www.byggmax.dk *.bing.com *.hotjar.com hotjar.com bing.com *.cloudflare.com *.wisepops.com *.facebook.net facebook.net *.quantserve.com quantserve.com *.quantcount.com *.cloudflareinsights.com *.pingdom.net pingdom.net *.getflowbox.net *.kuvio.io kuvio.io *.walleydev.com *.tryggehandel.net tryggehandel.net *.dynamicyield.com dynamicyield.com *.testfreaks.com testfreaks.com *.walleypay.com *.videoly.co dialogtrail.com *.dialogtrail.com wisepops.net *.wisepops.net *.adsrvr.org *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal *.trustpilot.com https://cdn.flbx.io https://connect.getflowbox.com http://connect.getflowbox.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.googleapis.com googleapis.com *.byggmax.se *.byggmax.no *.byggmax.fi *.byggmax.dk www.byggmax.se www.byggmax.no www.byggmax.fi www.byggmax.dk *.adsrvr.org *.trustpilot.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.flbx.io flbx.io *.adsrvr.org 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com *.wisepops.com *.google-analytics.com google-analytics.com *.collector.se *.pingdom.net pingdom.net *.adnxs.com adnxs.com *.walleydev.com *.walleypay.com *.dynamicyield.com dynamicyield.com www.google.com google.com *.google.com *.doubleclick.net doubleclick.net *.dialogtrail.com dialogtrail.com *.ebbot.app ebbot.app *.adsrvr.org *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com https://*.amazonaws.com https://cdn.flbx.io https://connect.getflowbox.com http://connect.getflowbox.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 3 default-src https: data:; script-src https: 'unsafe-inline'; style-src https: 'unsafe-inline'; form-action 'self'; object-src 'none'; frame-ancestors 'none'; base-uri 'self' 3 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com *.yotpo.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com webpay3g.transbank.cl webpay3gint.transbank.cl *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.google.com.ar *.google.com.uy *.hotjar.com *.doubleclick.net www.mercadolibre.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * www.xtento.com *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net https://sparta.cl/ https://newbalance.cl/ https://head.cl/ https://spyder.cl/ https://trekbikeschile.com/ https://www.dynamicyield.org/ku/ *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com gen.sendtric.com *.yotpo.com *.google.com *.google.com.ar *.google.com.uy *.facebook.com *.doubleclick.net sparta.cl newbalance.cl head.cl speedo.cl spyder.cl trekbikes.cl *.sparta.cl *.newbalance.cl *.head.cl *.speedo.cl *.spyder.cl *.trekbikes.cl www.mercadolibre.com www.mercadopago.cl 'self' data: *.googleapis.com *.yandex.ru *.retailrocket.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com widget.freshworks.com mcdn.retailrocket.net *.google.com.ar *.google.com.uy *.googleoptimize.com *.gstatic.com *.googletagmanager.com *.googleapis.com *.fanplayr.com *.facebook.net *.yotpo.com *.doubleclick.net *.magentosite.cloud *.freshworks.com *.hotjar.com *.retailrocket.net *.yandex.ru *.api.useinsider.com www.mercadopago.com www.mercadopago.cl sdk.mercadopago.com www.dynamicyield.org js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com www.xtento.com cdn.xtento.com analytics.tiktok.com www.tiktok.com business.tiktok.com https://cdnjs.cloudflare.com/ajax/libs/crypto-js/4.2.0/crypto-js.min.js 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com widget.freshworks.com *.googleapis.com sparta.cl newbalance.cl head.cl speedo.cl spyder.cl trekbikes.cl *.sparta.cl *.newbalance.cl *.head.cl *.speedo.cl *.spyder.cl *.trekbikes.cl *.yotpo.com *.fonts.net *.magentosite.cloud *.freshworks.com *.retailrocket.net assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com widget.freshworks.com mcdn.retailrocket.net *.google-analytics.com *.yotpo.com *.freshworks.com *.googleapis.com stats.g.doubleclick.net *.yandex.ru api.mercadopago.com events.mercadopago.com www.mercadolibre.com *.retailrocket.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com analytics.tiktok.com www.tiktok.com business.tiktok.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://spartacl.report-uri.com/r/d/csp/reportOnly; report-to report-endpoint; 3 default-src 'self' *.smartschool.be widgets.wp.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' maps.googleapis.com *.wp.com https://ssl.p.jwpcdn.com *.wp.com use.typekit.net p.jwpcdn.com; script-src-attr 'none'; style-src 'self' *.smartschool.be 'unsafe-inline' *.wp.com; font-src 'self' *.smartschool.be *.typekit.net wordpress.com c0.wp.com s0.wp.com data:; img-src 'self' http://www.smartschool.be pixel.wp.com *.typekit.net data:; connect-src maps.googleapis.com 'self' performance.typekit.net stats.g.doubleclick.net *.google-analytics.com; frame-src player.vimeo.com 'self'; report-uri /csp-violation.php 3 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com fonts.googleapis.com *.fontawesome.com data: https://fonts.gstatic.com https://fonts.googleapis.com https://*.sovendus.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.adyen.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.adyen.com js.mollie.com https://vars.hotjar.com https://www.pinterest.fr https://www.pinterest.com https://www.google.com https://*.sovendus.com https://www.sovendus-benefits.com https://www.sovendus-campaign.com https://www.sovendus-connect.com https://www.sovendus-network.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.adyen.com *.bird.eu a.tile.openstreetmap.org b.tile.openstreetmap.org c.tile.openstreetmap.org *.openstreetmap.org maps.googleapis.com maps.gstatic.com https://cdn.flbx.io magefan.com cm.magefan.com https://www.mollie.com https://www.google-analytics.com https://www.google.com https://www.google.fr *.ggpht.com *.googleapis.com https://maps.gstatic.com https://log.pinterest.com *.mondialtissus.fr *.mondialtissus.de *.mondialtissus.es *.mondialtissus.it *.mondialtissus.nl *.mondialtissus.se data: https://*.sovendus.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com https://www.vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.adyen.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com https://cdn.flbx.io *.getflowbox.com http://connect.getflowbox.com js.mollie.com https://sdk.privacy-center.org https://www.google-analytics.com https://www.analytics.google.com https://www.googleadservices.com https://www.googletagmanager.com https://wwww.paypalobjects.com https://s.ytimg.com https://maps.googleapis.com https://www.gstatic.com/recaptcha https://js.mollie.com https://france.mondialtissus.fr https://cdnjs.cloudflare.com https://assets.pinterest.com https://static.zdassets.com https://ekr.zdassets.com https://apis.google.com https://mondialtissus.zendesk.com https://admin.mondialtissus.fr 'unsafe-inline' https://*.sovendus.com https://cdn.jsdelivr.net https://static-sb.com https://social-sb.com https://cdn.jsdelivr.net js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com https://fonts.googleapis.com 'unsafe-inline' https://*.sovendus.com assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.adyen.com *.algolia.net https://*.algolia.net *.algolianet.com *.insights.algolia.io insights.algolia.io maps.googleapis.com https://*.amazonaws.com https://cdn.flbx.io https://connect.getflowbox.com http://connect.getflowbox.com https://www.google-analytics.com *.hotjar.com https://ekr.zdassets.com https://maps.googleapis.com https://mondialtissus.zendesk.com https://a.getflowbox.com https://*.sovendus.com https://www.sovendus-benefits.com https://www.sovendus-campaign.com https://www.sovendus-connect.com https://www.sovendus-network.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri https://d6tizftlrpuof.cloudfront.net 'self' 'unsafe-inline'; 3 font-src fonts.gstatic.com use.typekit.net maxcdn.bootstrapcdn.com *.fontawesome.com https://widgets.trustedshops.com https://www.gstatic.com https://fonts.gstatic.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com *.baktotaal.nl *.baktotaal.de *.baktotaal.com baktotaal.nl baktotaal.de baktotaal.com 'self' 'unsafe-inline'; frame-ancestors *.multisafepay.com https://pay.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.multisafepay.com https://pay.google.com https://*.google.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com challenges.cloudflare.com *.weltpixel.com *.googletagmanager.com *.doubleclick.net *.typeform.com *.criteo.com consentcdn.cookiebot.eu consentcdn.cookiebot.com *.facebook.com www.googletagmanager.com td.doubleclick.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io magefan.com cm.magefan.com *.multisafepay.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.googleusercontent.com https://firebasestorage.googleapis.com maps.gstatic.com ts.tradetracker.net www.magmodules.eu *.gstatic.com *.facebook.com *.reddit.com *.google-analytics.com *.googletagmanager.com *.doubleclick.net *.google.com *.cloudfront.net www.google.nl permalink.psinfoodservice.com www.facebook.com *.linkedin.com *.squeezely.tech *.bing.net *.criteo.com *.usercentrics.eu *.cookiebot.com *.bing.com *.etrusted.com *.clarity.ms pagead2.googlesyndication.com google.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.multisafepay.com https://pay.google.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com https://cdnjs.cloudflare.com cdnjs.cloudflare.com s7.addthis.com *.avada.io *.shopify.com challenges.cloudflare.com maps.googleapis.com www.gstatic.com tm.tradetracker.net *.googletagmanager.com *.googleadservices.com *.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com unpkg.com *.doubleclick.net *.typeform.com *.criteo.com *.criteo.net squeezely.tech instant.page *.licdn.com *.bing.com *.bing-int.com consent.cookiebot.com consent.cookiebot.eu consentcdn.cookiebot.com consentcdn.cookiebot.eu cdn.jsdelivr.net *.hotjar.com connect.facebook.net *.clarity.ms *.varify.io d5yoctgpv4cpx.cloudfront.net www.google.com pagead2.googlesyndication.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com maxcdn.bootstrapcdn.com *.fontawesome.com *.multisafepay.com https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com https://fonts.googleapis.com https://hcaptcha.com https://*.hcaptcha.com https://cdnjs.cloudflare.com cdnjs.cloudflare.com https://fonts.bunny.net www.gstatic.com *.tagmanager.google.com *.googletagmanager.com *.typeform.com *.etrusted.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io *.multisafepay.com *.trustedshops.com *.etrusted.com https://integrations.etrusted.site https://ipinfo.io https://*.google.com https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com ekr.zdassets.com/ https://get.geojs.io *.avada.io *.google-analytics.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.doubleclick.net *.run.app *.typeform.com *.criteo.com consentcdn.cookiebot.com consentcdn.cookiebot.eu *.bing.net *.bing.com *.varify.io *.clarity.ms www.facebook.com p2iqhncxyh.execute-api.eu-central-1.amazonaws.com pagead2.googlesyndication.com www.google.com google.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 3 frame-ancestors 'self' ; object-src 'none' ; report-uri https://cspreports.realpage.com/api/reports/save/report-only; 3 font-src fonts.gstatic.com *.fontawesome.com https://fonts.bunny.net *.gstatic.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.facebook.com https://torus-stage-halkbankmacedonia.asseco-see.com.tr/ https://epay.halkbank.mk/fim/est3Dgate form.wspay.biz formtest.wspay.biz https://ipgtest.monri.com/ https://ipg.monri.com/ https://formtest.wspay.biz/ https://form.wspay.biz/ 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com player.vimeo.com *.youtube.com www.google.com *.youtube-nocookie.com *.sharethis.com www.facebook.com www.googletagmanager.com bid.g.doubleclick.net td.doubleclick.net issuu.com e.issuu.com assets.pinterest.com *.hotjar.com https://ipgtest.monri.com/ https://ipg.monri.com/ 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.sharethis.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com www.facebook.com www.google.hr *.googletagmanager.com ssl.gstatic.com www.gstatic.com www.google-analytics.com *.analytics.google.com *.g.doubleclick.net *.google.com maps.gstatic.com maps.googleapis.com log.pinterest.com pinterest.com www.pinterest.com *.hotjar.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com analytics.google.com www.googletagmanager.com https://firebasestorage.googleapis.com *.hsforms.net *.hsforms.com 'self' data: data: 'self' 'unsafe-inline'; script-src *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ www.google.com *.sharethis.com chimpstatic.com downloads.mailchimp.com *.list-manage.com *.googletagmanager.com tagmanager.google.com www.google-analytics.com ssl.google-analytics.com www.googleadservices.com googleads.g.doubleclick.net maps.googleapis.com *.hotjar.com connect.facebook.net *.disqus.com assets.pinterest.com *.tiktok.com analytics.google.com www.googletagmanager.com *.avada.io *.shopify.com https://ipgtest.monri.com/ https://ipg.monri.com/ *.hsforms.net *.hsforms.com *.google.com *.gstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.sharethis.com downloads.mailchimp.com googletagmanager.com tagmanager.google.com fonts.googleapis.com *.hotjar.com *.fontawesome.com https://fonts.bunny.net https://ipgtest.monri.com/ https://ipg.monri.com/ *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com vimeo.com *.sharethis.com *.g.doubleclick.net *.google-analytics.com *.analytics.google.com *.googletagmanager.com *.google.com www.google.hr maps.googleapis.com *.hotjar.com *.hotjar.io wss://*.hotjar.com/ *.tiktok.com www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com https://get.geojs.io *.avada.io t.elasticsuite.io *.hsforms.net *.hsforms.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 3 font-src www.paypalobjects.com cash-f.squarecdn.com fonts.gstatic.com all4running.nl *.all4running.nl all4running.be *.all4running.be 21run.com *.21run.com *.dhlparcel.nl https://widgets.trustedshops.com *.gstatic.com 'self' data: data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com * all4running.nl *.all4running.nl all4running.be *.all4running.be 21run.com *.21run.com *.facebook.com *.facebook.net 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ * all4running.nl *.all4running.nl all4running.be *.all4running.be 21run.com *.21run.com *.doubleclick.net *.facebook.com *.facebook.net 'self' 'unsafe-inline'; img-src data: widgets.magentocommerce.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com *.google-analytics.com *.analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com * https://images.unsplash.com *.googletagmanager.com ssl.gstatic.com www.gstatic.com *.imgix.net all4running.nl *.all4running.nl all4running.be *.all4running.be 21run.com *.21run.com maps.gstatic.com *.googleapis.com *.bing.com *.google.nl *.facebook.com *.facebook.net *.hsforms.net *.hsforms.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com *.bazaarvoice.com widgets.trustedshops.com 'self' data: data: 'self' 'unsafe-inline'; script-src googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.hotjar.com *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com *.cash.app *.visa.com *.mastercard.com applepay.cdn-apple.com https://maps.googleapis.com *.googletagmanager.com tagmanager.google.com all4running.nl *.all4running.nl all4running.be *.all4running.be 21run.com *.21run.com *.dhlparcel.nl *.googleapis.com *.bing.com *.facebook.com *.facebook.net https://player.vimeo.com/api/player.js cdn.belco.io *.hsforms.net *.hsforms.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.bazaarvoice.com widgets.trustedshops.com *.google.com *.gstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.cash.app tagmanager.google.com fonts.google.com all4running.nl *.all4running.nl all4running.be *.all4running.be 21run.com *.21run.com *.dhlparcel.nl https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.googleadservices.com *.google-analytics.com *.analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com * https://maps.googleapis.com https://player.vimeo.com *.googletagmanager.com all4running.nl *.all4running.nl all4running.be *.all4running.be 21run.com *.21run.com *.dhlparcel.nl *.googleapis.com *.google.com *.doubleclick.net *.googlesyndication.com cdn.belco.io wss://chat.belco.io t.elasticsuite.io *.hsforms.net *.hsforms.com *.trustedshops.com *.etrusted.com https://integrations.etrusted.site *.bazaarvoice.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 3 default-src 'self'; script-src 'self' https://www.google-analytics.com https://www.googletagmanager.com https://cdnjs.cloudflare.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; img-src 'self' https://www.google-analytics.com https://brandcenter.flex.com; upgrade-insecure-requests; 3 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.klevu.com *.ksearchnet.com *.fontawesome.com https://d2izb4xeo5e3ln.cloudfront.net https://d13obdxb25x34a.cloudfront.net https://media.silhouettedesignstore.com https://mediacdn.silhouettedesignstore.com https://fonts.gstatic.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.adyen.com pay.google.com payments-eu.amazon.com *.amazon.de *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * self *.facebook.com 'self' 'unsafe-inline'; frame-ancestors https://www.silhouettedesignstore.com https://media.silhouettedesignstore.com https://mediacdn.silhouettedesignstore.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.adyen.com pay.google.com https://static.addtoany.com/ c.paypal.com checkout.paypal.com assets.braintreegateway.com *.cardinalcommerce.com * *.instagram.com js.stripe.com https://d2izb4xeo5e3ln.cloudfront.net https://d13obdxb25x34a.cloudfront.net https://media.silhouettedesignstore.com https://www.silhouettedesignstore.com https://mediacdn.silhouettedesignstore.com *.wesupply.xyz https://wesupplylabs.com *.weltpixel.com *.googletagmanager.com *.doubleclick.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'unsafe-inline' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.adyen.com pay.google.com *.payments-amazon.com *.media-amazon.com *.paypalobjects.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.cdninstagram.com *.klevu.com *.ksearchnet.com magefan.com cm.magefan.com https://d2izb4xeo5e3ln.cloudfront.net https://d13obdxb25x34a.cloudfront.net https://media.silhouettedesignstore.com https://mediacdn.silhouettedesignstore.com cdn.examplecdn.com s.pinimg.com in-automate.brevo.com cdn.by.wonderpush.com https://www.google.com https://cdn-int.safecharge.com https://cdn.safecharge.com https://secure.safecharge.com/ *.facebook.com *.reddit.com *.ads-twitter.com t.co *.twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.google-analytics.com *.googletagmanager.com *.doubleclick.net *.google.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com https://static.addtoany.com/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com *.instagram.com js.stripe.com js.klevu.com *.ksearchnet.com https://d2izb4xeo5e3ln.cloudfront.net https://d13obdxb25x34a.cloudfront.net https://media.silhouettedesignstore.com https://mediacdn.silhouettedesignstore.com https://cdn.webpushr.com https://cdn.brevo.com https://player.vimeo.com https://intljs.rmtag.com https://ut.rd.linksynergy.com https://js.klevu.com unpkg.com sibautomation.com cdn.by.wonderpush.com s.pinimg.com ct.pinterest.com in-automate.brevo.com https://magento.com https://cdn.safecharge.com https://cdn-int.safecharge.com https://play.google.com *.cloudflare.com *.googletagmanager.com *.googleadservices.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.bing.com *.clarity.ms *.klaviyo.com *.doubleclick.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com assets.braintreegateway.com *.klevu.com *.ksearchnet.com *.fontawesome.com https://d2izb4xeo5e3ln.cloudfront.net https://d13obdxb25x34a.cloudfront.net https://media.silhouettedesignstore.com https://mediacdn.silhouettedesignstore.com https://cdn.brevo.com https://magneto-staging.s3.us-west-2.amazonaws.com https://maxcdn.bootstrapcdn.com https://cdn.safecharge.com https://fonts.googleapis.com https://www.gstatic.com maxcdn.bootstrapcdn.com *.tagmanager.google.com *.googletagmanager.com https://statsjs.klevu.com https://js.klevu.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.cdninstagram.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.adyen.com payments-eu.amazon.com https://stats.addtoany.com/menu api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.klevu.com *.ksearchnet.com https://d2izb4xeo5e3ln.cloudfront.net https://d13obdxb25x34a.cloudfront.net https://media.silhouettedesignstore.com https://mediacdn.silhouettedesignstore.com https://bot.webpushr.com api.exampleconnect.com ct.pinterest.com in-automate.brevo.com cdn.by.wonderpush.com https://sdkmon.safecharge.com https://ppp-test.safecharge.com https://ppp-test.nuvei.com https://secure.safecharge.com https://play.google.com *.google-analytics.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.doubleclick.net *.run.app 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 3 script-src-elem payment-widget.avarda.com *.payment-widget.avarda.com payment-widget.stage.avarda.com *.payment-widget.stage.avarda.com data: 'self'; font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com cash-f.squarecdn.com 'self' data: *.doubleclick.net *.facebook.com payment-widget.avarda.com *.payment-widget.avarda.com payment-widget.stage.avarda.com *.payment-widget.stage.avarda.com static.runconverge.com *.facebook.net *.googletagmanager.com *.google-analytics.com *.analytics.google.com *.google.com *.pinimg.com ssl.gstatic.com www.gstatic.com *.cloudflare.com *.trustedshops.com *.googleapis.com *.klaviyo.com maxcdn.bootstrapcdn.com cdn1.stamped.io stamped.io *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com * *.runconverge.com *.facebook.net *.facebook.com *.googletagmanager.com *.google-analytics.com *.analytics.google.com *.google.com *.pinimg.com ssl.gstatic.com www.gstatic.com *.twitter.com services.paytrail.com paytrail.com *.paytrail.com epmt.nordea.fi *.nordea.com verkkopankki.danskebank.fi online.s-pankki.fi verkkomaksu.poppankki.fi verkkomaksu.omasp.fi auth.aktia.fi verkkomaksu.handelsbanken.fi verkkomaksu.saastopankki.fi online.alandsbanken.fi maksu.pivo.fi qa-maksu.pivo.fi v1-hub-staging.sph-test-solinor.com v1.api.paymenthighway.io *.paymenthighway.io *.mobilepay.fi *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src bid.g.doubleclick.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com * *.doubleclick.net *.facebook.com *.runconverge.com *.facebook.net *.googletagmanager.com *.google-analytics.com *.analytics.google.com *.pinimg.com ssl.gstatic.com www.gstatic.com *.freshchat.com *.twitter.com *.pinterest.com *.trustpilot.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com 'self' 'unsafe-inline'; img-src 'self' data: widgets.magentocommerce.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com *.google-analytics.com *.analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io * https://images.unsplash.com *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com payment-widget.avarda.com *.payment-widget.avarda.com payment-widget.stage.avarda.com *.payment-widget.stage.avarda.com static.runconverge.com *.pinimg.com ssl.gstatic.com www.gstatic.com *.cloudfront.net/ *.criteo.net *.stamped.io *.freshchat.com/ *.cloudflare.com *.ytimg.com *.bing.com/ *.clarity.ms/ *.google.al/ *.google.am/ *.google.at/ *.google.az/ *.google.ba/ *.google.be/ *.google.bg/ *.google.by/ *.google.ch/ *.google.cz/ *.google.de/ *.google.dk/ *.google.ee/ *.google.es/ *.google.fi/ *.google.fr/ *.google.ge/ *.google.gr/ *.google.hr/ *.google.hu/ *.google.ie/ *.google.is/ *.google.it/ *.google.kz/ *.google.li/ *.google.lt/ *.google.lu/ *.google.lv/ *.google.md/ *.google.me/ *.google.mk/ *.google.mt/ *.google.nl/ *.google.no/ *.google.pl/ *.google.pt/ *.google.ro/ *.google.rs/ *.google.ru/ *.google.se/ *.google.si/ *.google.sk/ *.google.sm/ *.google.tr/ *.google.ua/ *.google.uk/ *.google.com.ua/ *.google.com.tr/ *.google.com.gr/ *.google.com.pt/ *.google.com.pl/ cdn2.hubspot.net resources.paytrail.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ magefan.com cm.magefan.com https://img.youtube.com *.unifaun.com/ openstreetmap.org *.openstreetmap.org cdn1.stamped.io stamped.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: data: 'self' 'unsafe-inline'; script-src googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com *.cash.app *.visa.com *.mastercard.com https://maps.googleapis.com polyfill.io *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com payment-widget.avarda.com *.payment-widget.avarda.com payment-widget.stage.avarda.com *.payment-widget.stage.avarda.com *.runconverge.com *.analytics.google.com *.pinimg.com ssl.gstatic.com www.gstatic.com *.kk-resources.com/ *.shopalike.fi/ *.chatbotize.com/ qanuk-stage.vercel.app *.tradedoubler.com *.criteo.com *.cookiefirst.com *.omappapi.com *.googleoptimize.com *.klaviyo.com reviewsonmywebsite.com 'self' data: *.fontawesome.com *.videoly.co/ *.freshchat.com cdnjs.cloudflare.com/ *.googleapis.com/ *.noibu.com/ *.pinimg.com/ *.bing.com/ *.tiktok.com/ *.pinterest.com/ *.intercom.io/ *.intercomcdn.com/ *.clarity.ms/ polyfill-fastly.io/ services.paytrail.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ unpkg.com/ cdn1.stamped.io stamped.io *.trustpilot.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com s7.addthis.com https://cdn.jsdelivr.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com *.cash.app *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com static.runconverge.com *.facebook.net *.google-analytics.com *.analytics.google.com *.google.com *.pinimg.com ssl.gstatic.com www.gstatic.com *.cookiefirst.com *.omappapi.com reviewsonmywebsite.com *.typekit.net *.freshchat.com/ *.cloudflare.com/ *.klaviyo.com/ https://static.klaviyo.com maxcdn.bootstrapcdn.com unpkg.com/ cdn1.stamped.io stamped.io *.trustpilot.com assets.braintreegateway.com https://cdn.jsdelivr.net *.fontawesome.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src cdn1.stamped.io stamped.io 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.googleadservices.com *.google-analytics.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com * https://maps.googleapis.com https://player.vimeo.com *.algolia.net *.algolia.com/ *.algolianet.com *.facebook.com *.facebook.net *.google.com/ payment-widget.avarda.com *.payment-widget.avarda.com payment-widget.stage.avarda.com *.payment-widget.stage.avarda.com *.runconverge.com *.googletagmanager.com *.pinimg.com ssl.gstatic.com www.gstatic.com *.criteo.com *.kelkoogroup.net/ *.chatbotize.com *.doubleclick.net *.qanuk.app *.cookiefirst.com *.omappapi.com *.googlesyndication.com reviewsonmywebsite.com *.cloudflare.com *.pinterest.com *.tiktok.com/ *.clarity.ms/ *.noibu.com/ wss://input.noibu.com/ wss://nexus-websocket-a.intercom.io/ *.intercom.io/ *.bing.com/ *.algolia.io/ *.paytrail.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ cdn1.stamped.io stamped.io *.trustpilot.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com ekr.zdassets.com/ 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 3 font-src fonts.gstatic.com use.typekit.net https://cdn.riverty.design/ *.cloudfront.net https://fonts.gstatic.com https://maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com uc8.tv *.facebook.com *.facebook.net 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src bid.g.doubleclick.net *.demdex.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com uc8.tv https://documents.riverty.com/ *.dotdigital-pages.com *.dotdigital.com *.facebook.com *.facebook.net *.doubleclick.net *.paypal.com *.vimeo.com *.google.com *.googletagmanager.com https://documents.riverty.com https://documents.myafterpay.com https://tag.heylink.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.everesttech.net *.demdex.net searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com https://cdn.myafterpay.com/ uc8.tv https://cdn.riverty.design/ imgsct.cookiebot.com https://info.dibs.se *.trackedlink.net magefan.com cm.magefan.com *.facebook.com *.facebook.net *.cloudfront.net *.adobe.com *.adobe.net *.google.com *.googleapis.com *.gstatic.com https://bat.bing.com https://cdn.myafterpay.com https://instore.prisjakt.no https://pricerunner.dk https://pricerunner.se *.googleadservices.com *.google-analytics.com *.googletagmanager.com data: 'self' 'unsafe-inline'; script-src www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.adobedtm.com *.sentry.io *.sentry-cdn.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com *.vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com *.magento-datasolutions.com *.magento-ds.com uc8.tv https://cdn.myafterpay.com/ https://cdn.bnpl.riverty.io/ consent.cookiebot.com https://*.dibspayment.eu *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal *.facebook.com *.facebook.net *.cloudfront.net *.adobe.com *.adobe.net *.google.com *.googleapis.com *.gstatic.com https://cdn.cookie-script.com https://bat.bing.com *.clarity.ms *.doubleclick.net https://r1-t.trackedlink.net *.googletagmanager.com *.googleadservices.com *.google-analytics.com *.paypal.com https://tag.heylink.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.magento-datasolutions.com *.magento-ds.com https://*.dibspayment.eu *.cloudfront.net *.adobe.com *.adobe.net *.google.com *.facebook.com *.facebook.net *.googleapis.com *.gstatic.com https://bat.bing.com https://maxcdn.bootstrapcdn.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; connect-src www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io amcglobal.sc.omtrdc.net p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io *.snplow.net commerce.adobedc.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.magento.com performance.typekit.net *.magento-datasolutions.com *.magento-ds.com *.adobe.io uc8.tv https://cdn.myafterpay.com/ https://documents.myafterpay.com/ https://documents.riverty.com/ https://www.afterpay.nl/ https://cdn.bnpl.riverty.io/ https://trace-api.newrelic.com/ https://distributions.crowdin.net/ https://api.crowdin.com/ https://*.dibspayment.eu *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com *.facebook.com *.facebook.net *.cloudfront.net *.adobe.com *.adobe.net *.google.com *.googleapis.com *.gstatic.com https://bat.bing.com *.clarity.ms *.doubleclick.net https://fraktguide.bring.no *.google-analytics.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 3 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https:; style-src 'self' 'unsafe-inline'; img-src 'self' data: https:; font-src 'self' data: https:; connect-src 'self' https:; frame-src 'self' https:; media-src 'self' https:; 3 default-src 'self'; img-src 'self' https: data:; script-src 'self' https: 'unsafe-inline'; style-src 'self' https: 'unsafe-inline'; font-src 'self' https: data:; connect-src 'self' https:; media-src 'self' https: data:; object-src 'self'; base-uri 'self'; report-to go1-csp; 3 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com data: static.nacongaming.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.adyen.com pay.google.com payments-eu.amazon.com *.amazon.de api.bazaarvoice.com stg.api.bazaarvoice.com www.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.adyen.com pay.google.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com www.google.com www.youtube.com amc.demdex.net vars.hotjar.com www.facebook.com static.nacongaming.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.adyen.com pay.google.com *.payments-amazon.com *.media-amazon.com *.paypalobjects.com display.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com network-a.bazaarvoice.com network-stg-a.bazaarvoice.com photos-uat-us.bazaarvoice.com img.youtube.com network-eu-stg.bazaarvoice.com network-eu.bazaarvoice.com network-eu-a.bazaarvoice.com media.nacongaming.com scaleflex.ultrafast.io axeptio.imgix.net www.google.fr www.facebook.com static.nacongaming.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com commerce-payments-sdk.adobe.io www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com apps.bazaarvoice.com apps.nexus.bazaarvoice.com apps-stg.nexus.bazaarvoice.com analytics-static.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com mpsnare.iesnare.com network-eu.bazaarvoice.com network-eu-stg.bazaarvoice.com www.google.com www.gstatic.com script.hotjar.com static.hotjar.com connect.facebook.net anltc-v2.bigben.fr analytics.tiktok.com www.googleoptimize.com static.nacongaming.com static.axept.io anltc.bigben.fr 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com display.ugc.bazaarvoice.com *.fontawesome.com use.typekit.net p.typekit.net static.nacongaming.com 'self' 'unsafe-inline'; object-src static.nacongaming.com 'self' 'unsafe-inline'; media-src *.adobe.com static.nacongaming.com media.nacongaming.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.adyen.com payments-eu.amazon.com api.bazaarvoice.com stg.api.bazaarvoice.com apps.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com www.facebook.com in.hotjar.com stats.g.doubleclick.net anltc-v2.bigben.fr axeptio.imgix.net static.nacongaming.com client.axept.io api.axept.io anltc.bigben.fr 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 3 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://stats.afternorth.com https://maps.googleapis.com https://www.googletagmanager.com https://www.google-analytics.com; object-src 'none'; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; connect-src 'self' https://stats.afternorth.com https://maps.googleapis.com https://www.google-analytics.com; img-src 'self' data: https://i.realestatecreate.com https://maps1.dnr.state.mn.us https://maps.googleapis.com https://maps.gstatic.com https://www.googletagmanager.com https://www.google-analytics.com; font-src 'self' https://fonts.gstatic.com; 3 font-src https://www.googletagmanager.com *.googleapis.com *.gstatic.com *.bootstrapcdn.com *.cloudflare.com 'self' data: *.hotjar.com *.hotjar.io data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * www.facebook.com 'self' connect.facebook.net graph.facebook.com business.facebook.com test.saferpay.com www.saferpay.com saferpay.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.doubleclick.net *.googlesyndication.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com test.saferpay.com www.saferpay.com saferpay.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com 'self' data: *.paypal.com *.gstatic.com *.googleapis.com *.openstreetmap.org *.googlesyndication.com *.google.com *.google.rs *.google.hr *.google.ba *.google.si *.google.bg *.google.me *.google.mk *.google.nl *.google.de *.google.be *.google.fr *.googleadservices.com www.facebook.com trengo.s3.eu-central-1.amazonaws.com ecom-stage.iutecredit.mk ecom.iutecredit.mk ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com connect.facebook.net graph.facebook.com business.facebook.com *.cmi.co.ma yandex.com yandex.md *.yandex.md *.yandex.com yandex.ru *.yandex.ru *.yads.tech yads.tech *.yango.com *.doubleclick.net t.adx.opera.com test.saferpay.com www.saferpay.com saferpay.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com songbird.cardinalcommerce.com tagmanager.google.com https://www.googletagmanager.com *.googleapis.com *.gstatic.com https://widget-cdn.boxnow.hr *.googlesyndication.com *.googleadservices.com *.google.com *.google.rs *.google.hr *.google.ba *.google.si *.google.bg *.google.me *.google.mk www.facebook.com *.widget.trengo.eu map.gls-croatia.com map.gls-czech.com map.gls-hungary.com map.gls-romania.com map.gls-slovenia.com map.gls-slovakia.com map.gls-serbia.com *.openstreetmap.org ecom-stage.iutecredit.mk ecom.iutecredit.mk chimpstatic.com downloads.mailchimp.com *.list-manage.com s7.addthis.com connect.facebook.net graph.facebook.com business.facebook.com *.hotjar.com *.hotjar.io onesignal.com *.onesignal.com *.criteo.com *.adsmurai.com gateway.bankart.si yandex.com yandex.md *.yandex.md *.yandex.com yandex.ru *.yandex.ru *.yads.tech yads.tech *.yango.com *.doubleclick.net t.adx.opera.com test.saferpay.com www.saferpay.com saferpay.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com unsafe-inline assets.braintreegateway.com https://www.googletagmanager.com tagmanager.google.com *.googleapis.com fonts.googleapis.com *.bootstrapcdn.com ecom-stage.iutecredit.mk ecom.iutecredit.mk downloads.mailchimp.com onesignal.com *.onesignal.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com static.widget.trengo.eu 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com https://www.google-analytics.com *.googleapis.com https://widget-cdn.boxnow.hr *.google.com *.google.rs *.google.hr *.google.ba *.google.si *.google.bg *.google.me *.google.mk *.google.nl *.google.de *.google.be *.google.fr *.googlesyndication.com *.doubleclick.net www.facebook.com *.trengo.eu map.gls-croatia.com map.gls-czech.com map.gls-hungary.com map.gls-romania.com map.gls-slovenia.com map.gls-slovakia.com map.gls-serbia.com *.openstreetmap.org ecom-stage.iutecredit.mk ecom.iutecredit.mk ekr.zdassets.com/ connect.facebook.net graph.facebook.com business.facebook.com wss://ws.hotjar.com *.hotjar.io yandex.com *.yandex.md *.yandex.com yandex.ru *.yandex.ru *.yads.tech *.yango.com cm.g.doubleclick.net t.adx.opera.com test.saferpay.com www.saferpay.com saferpay.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src yandex.com yandex.md *.yandex.md *.yandex.com yandex.ru *.yandex.ru *.yads.tech yads.tech *.yango.com *.doubleclick.net t.adx.opera.com test.saferpay.com www.saferpay.com saferpay.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 3 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.klarnacdn.net *.fontawesome.com 'self' data: *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnaevt.com *.link.com *.amazon.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com *.awin1.com *.zenaps.com *.fls.doubleclick.net *.klarna.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.stripe.com klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.awin1.com *.zenaps.com *.wepowerconnections.com *.klarna.com *.klarnaevt.com *.klarnacdn.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.hsforms.net *.hsforms.com 'self' data: maps.gstatic.com *.flavedo.io data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.awin1.com *.dwin1.com *.zenaps.com *.wepowerconnections.com https://the.sciencebehindecommerce.com lantern.roeyecdn.com *.klarna.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com unpkg.com *.connectif.cloud *.privacy-center.org *.visualwebsiteoptimizer.com *.shippypro.com *.hsforms.net *.hsforms.com *.gstatic.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarnaevt.com *.amazon.com *.link.com maps.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.klarnacdn.net *.fontawesome.com assets.braintreegateway.com *.shippypro.com *.googleapis.com *.gstatic.com *.stripe.network *.stripecdn.com *.amazon.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.wepowerconnections.com https://the.sciencebehindecommerce.com *.klarnaevt.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.klarna.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.shippypro.com *.connectif.cloud t.elasticsuite.io *.hsforms.net *.hsforms.com *.stripe.com klarna.com *.link.com *.amazon.com *.citrusad.com 'self' 'unsafe-inline'; child-src *.awin1.com *.zenaps.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 3 default-src https: 3 base-uri 'self'; default-src 'self' https://*.google-analytics.com *.google-analytics.com https://*.analytics.google.com *.analytics.google.com https://stats.g.doubleclick.com stats.g.doubleclick.com https://*.googleapis.com *.googleapis.com https://*.cookielaw.com *.cookielaw.com https://*.cookielaw.org *.cookielaw.org https://*.cloudapi.de *.cloudapi.de https://*.onetrust.com *.onetrust.com 'unsafe-inline' 'unsafe-eval'; child-src; connect-src 'self' https://cdn.cookielaw.org cdn.cookielaw.org https://privacyportal-eu.onetrust.com privacyportal-eu.onetrust.com https://api.userway.org api.userway.org https://pagead2.googlesyndication.com pagead2.googlesyndication.com https://*.google.com *.google.com https://cdn.userway.org cdn.userway.org https://*.api.userway.org *.api.userway.org https://sessions.bugsnag.com sessions.bugsnag.com https://px.ads.linkedin.com px.ads.linkedin.com https://*.facebook.com *.facebook.com https://region1.google-analytics.com region1.google-analytics.com https://geolocation.onetrust.com geolocation.onetrust.com; font-src 'self' https://privacyportal-eu-cdn.onetrust.com privacyportal-eu-cdn.onetrust.com https://cdn.userway.org cdn.userway.org data:; form-action 'self'; frame-ancestors 'none'; frame-src 'self' https://sidebar.bugherd.com sidebar.bugherd.com https://*.googletagmanager.com *.googletagmanager.com https://challenges.cloudflare.com challenges.cloudflare.com https://cdn.userway.org cdn.userway.org; img-src 'self' https://*.google-analytics.com *.google-analytics.com https://*.analytics.google.com *.analytics.google.com https://*.googletagmanager.com *.googletagmanager.com https://googleads.g.doubleclick.net googleads.g.doubleclick.net https://stats.g.doubleclick.com stats.g.doubleclick.com https://stats.g.doubleclick.net stats.g.doubleclick.net https://*.google.com *.google.com https://*.google.co.uk *.google.co.uk https://*.cookielaw.org *.cookielaw.org https://px.ads.linkedin.com px.ads.linkedin.com https://*.linkedin.com *.linkedin.com https://*.facebook.com *.facebook.com https://cdn.userway.org cdn.userway.org https://d2iiunr5ws5ch1.cloudfront.net d2iiunr5ws5ch1.cloudfront.net blob: data:; media-src https://youtube.com youtube.com https://ddo8pjvnj55tt.cloudfront.net ddo8pjvnj55tt.cloudfront.net; object-src 'none'; manifest-src 'self'; script-src 'self' https://*.licdn.com *.licdn.com https://*.googleapis.com *.googleapis.com https://*.google.com *.google.com https://*.googletagmanager.com *.googletagmanager.com https://*.google-analytics.com *.google-analytics.com https://*.analytics.google.com *.analytics.google.com https://pagead2.googlesyndication.com pagead2.googlesyndication.com https://*.cookielaw.com *.cookielaw.com https://*.cookielaw.org *.cookielaw.org https://*.onetrust.com *.onetrust.com https://connect.facebook.net connect.facebook.net https://sidebar.bugherd.com sidebar.bugherd.com https://cdn.userway.org cdn.userway.org https://*.bugherd.com *.bugherd.com https://static.cloudflareinsights.com static.cloudflareinsights.com https://challenges.cloudflare.com challenges.cloudflare.com 'unsafe-inline' 'unsafe-eval'; style-src 'self' https://cdn.userway.org cdn.userway.org 'unsafe-inline'; upgrade-insecure-requests 3 font-src https://static.dhlecommerce.nl https://fonts.gstatic.com https://widgets.trustedshops.com fonts.gstatic.com widgets.trustedshops.com static.klaviyo.com cdn.brandfield.nl cdn.brandfield.fr cdn.brandfield.de cdn.brandfield.be cdn.brandfield.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' 'unsafe-inline'; frame-ancestors *.bolt.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.bolt.com https://www.google.com/recaptcha/ www.googletagmanager.com https://www.paypal.com https://hostedfields-externalapi.alpha.buckaroo.aws https://hostedfields-externalapi.prod-pci.buckaroo.io gum.criteo.com fledge.criteo.com fledge.eu.criteo.com bfsst.brandfield.nl bfsst.brandfield.be bfsst.brandfield.fr bfsst.brandfield.de bfsst.brandfield.com ct.pinterest.com www.google.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com https://portal.payconiq.com https://static.buckaroo.nl https://www.paypalobjects.com https://maps.googleapis.com https://maps.gstatic.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://widgets.trustedshops.com https://widgets-qa.trustedshops.com *.googletagmanager.com *.google-analytics.com ssl.gstatic.com www.gstatic.com cdn.brandfield.nl cdn.brandfield.fr cdn.brandfield.de cdn.brandfield.be cdn.brandfield.com www.acc-brandfield.com *.googlesyndication.com api.taggrs.io widgets.trustedshops.com www.facebook.com bat.bing.com sync-t1.taboola.com rtb-csync.smartadserver.com pixel.rubiconproject.com x.bidswitch.net simage2.pubmatic.com eb2.3lift.com ad.360yield.com ad.yieldlab.net id5-sync.com exchange.mediavine.com jadserve.postrelease.com criteo-sync.teads.tv r.casalemedia.com sync.targeting.unrulymedia.com criteo-partners.tremorhub.com sync.outbrain.com contextual.media.net aa.agkn.com cm.g.doubleclick.net bfsst.brandfield.nl bfsst.brandfield.be bfsst.brandfield.fr bfsst.brandfield.de bfsst.brandfield.com www.google.nl d3k81ch9hvuctc.cloudfront.net brandfield.work public-prod-dspcookiematching.dmxleo.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.bolt.com *.commerce-quick-checkout.com http://localhost:8082 https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://static.buckaroo.nl https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl https://buckaroo.nl https://www.paypal.com https://hostedfields-externalapi.alpha.buckaroo.aws https://hostedfields-externalapi.prod-pci.buckaroo.io https://static.dhlecommerce.nl https://maps.googleapis.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.googletagmanager.com tagmanager.google.com cdn.brandfield.nl cdn.brandfield.fr cdn.brandfield.de cdn.brandfield.be cdn.brandfield.com static.zdassets.com integrations.etrusted.com static.klaviyo.com widgets.trustedshops.com static-tracking.klaviyo.com bfsst.brandfield.nl bfsst.brandfield.be bfsst.brandfield.fr bfsst.brandfield.de bfsst.brandfield.com cdn.cookie-script.com s.pinimg.com connect.facebook.net dynamic.criteo.com bat.bing.com analytics.tiktok.com fledge.criteo.com sslwidget.criteo.com www.clarity.ms fledge.eu.criteo.com ct.pinterest.com www.google.com www.gstatic.com static.buckaroo.nl 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl https://static.dhlecommerce.nl https://maps.googleapis.com https://fonts.googleapis.com https://static.klaviyo.com https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com tagmanager.google.com fonts.google.com cdn.brandfield.nl cdn.brandfield.fr cdn.brandfield.de cdn.brandfield.be cdn.brandfield.com fonts.googleapis.com static.klaviyo.com www.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.bolt.com wss://websocketservice-externalapi.prod.buckaroo.io https://static.buckaroo.nl wss://websockets.buckaroo.io/ https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl https://hostedfields-externalapi.alpha.buckaroo.aws https://hostedfields-externalapi.prod-pci.buckaroo.io https://applepay.buckaroo.io https://www.paypal.com https://api-gw.dhlparcel.nl https://static.dhlecommerce.nl https://maps.googleapis.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.trustedshops.com *.etrusted.com https://integrations.etrusted.site *.google-analytics.com *.analytics.google.com *.googletagmanager.com ekr.zdassets.com bfsst.brandfield.nl bfsst.brandfield.be bfsst.brandfield.fr bfsst.brandfield.de bfsst.brandfield.com fast.a.klaviyo.com static-forms.klaviyo.com a.klaviyo.com cdn.brandfield.nl cdn.brandfield.fr cdn.brandfield.de cdn.brandfield.be cdn.brandfield.com ct.pinterest.com gum.criteo.com measurement-api.criteo.com *.clarity.ms ipinfo.io www.google.com *.googlesyndication.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src bat.bing.com l.clarity.ms www.google.com bat.bing.net analytics.tiktok.com csm.nl3.eu.criteo.net 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://8f7c9b71-bcff-463a-be0a-2ff1273b3e9d.sansec.watch/; report-to report-endpoint; 3 report-uri https://gfcorporate.report-uri.com/r/d/csp/reportOnly ; default-src 'self' www.gfms.com gfms.com www.gfps.com gfcorporate.report-uri.com *.google.at *.google.be *.google.cz *.google.dk *.google.fi *.google.fr *.google.de *.google.it *.google.nl *.google.no *.google.pl *.google.ro *.google.ru *.google.es *.google.se *.google.ch *.google.com.tr *.google.co.uk *.google.com.ar *.google.ca *.google.com *.google.com.br *.google.com.mx *.google.com.au *.google.cn *.google.co.in *.google.co.id *.google.co.jp *.google.com.my *.google.co.nz *.google.com.sg *.google.co.kr *.google.com.tw *.google.com.vn *.google.bg *.google.hr *.google.ee *.google.gr *.google.hu *.google.lv *.google.lu *.google.mk *.google.pt *.google.rs *.google.si *.google.com.ph *.google.co.th *.google.com.eg *.google.co.il *.google.co.za *.google.ae ; connect-src 'self' *.google-analytics.com apikeys.civiccomputing.com *.googleapis.com center.lon5.atomz.com clapi.civiccomputing.com sp1004e61f.guided.lon5.atomz.com sp1004e61a.guided.lon5.atomz.com sp1004e5dd.guided.lon5.atomz.com stats.g.doubleclick.net www.facebook.com uberall.com locator.uberall.com api.moin.ai www.gfps.com www.gfpstools.com neoflow.gfpstools.com cdn.linkedin.oribi.io assets.georgfischer.com google.com analytics.google.com *.analytics.google.com *.googletagmanager.com *.g.doubleclick.net *.google.com *.google.ad *.google.ae *.google.com.af *.google.com.ag *.google.com.ai *.google.al *.google.am *.google.co.ao *.google.com.ar *.google.as *.google.at *.google.com.au *.google.az *.google.ba *.google.com.bd *.google.be *.google.bf *.google.bg *.google.com.bh *.google.bi *.google.bj *.google.com.bn *.google.com.bo *.google.com.br *.google.bs *.google.bt *.google.co.bw *.google.by *.google.com.bz *.google.ca *.google.cd *.google.cf *.google.cg *.google.ch *.google.ci *.google.co.ck *.google.cl *.google.cm *.google.cn *.google.com.co *.google.co.cr *.google.com.cu *.google.cv *.google.com.cy *.google.cz *.google.de *.google.dj *.google.dk *.google.dm *.google.com.do *.google.dz *.google.com.ec *.google.ee *.google.com.eg *.google.es *.google.com.et *.google.fi *.google.com.fj *.google.fm *.google.fr *.google.ga *.google.ge *.google.gg *.google.com.gh *.google.com.gi *.google.gl *.google.gm *.google.gr *.google.com.gt *.google.gy *.google.com.hk *.google.hn *.google.hr *.google.ht *.google.hu *.google.co.id *.google.ie *.google.co.il *.google.im *.google.co.in *.google.iq *.google.is *.google.it *.google.je *.google.com.jm *.google.jo *.google.co.jp *.google.co.ke *.google.com.kh *.google.ki *.google.kg *.google.co.kr *.google.com.kw *.google.kz *.google.la *.google.com.lb *.google.li *.google.lk *.google.co.ls *.google.lt *.google.lu *.google.lv *.google.com.ly *.google.co.ma *.google.md *.google.me *.google.mg *.google.mk *.google.ml *.google.com.mm *.google.mn *.google.ms *.google.com.mt *.google.mu *.google.mv *.google.mw *.google.com.mx *.google.com.my *.google.co.mz *.google.com.na *.google.com.ng *.google.com.ni *.google.ne *.google.nl *.google.no *.google.com.np *.google.nr *.google.nu *.google.co.nz *.google.com.om *.google.com.pa *.google.com.pe *.google.com.pg *.google.com.ph *.google.com.pk *.google.pl *.google.pn *.google.com.pr *.google.ps *.google.pt *.google.com.py *.google.com.qa *.google.ro *.google.ru *.google.rw *.google.com.sa *.google.com.sb *.google.sc *.google.se *.google.com.sg *.google.sh *.google.si *.google.sk *.google.com.sl *.google.sn *.google.so *.google.sm *.google.sr *.google.st *.google.com.sv *.google.td *.google.tg *.google.co.th *.google.com.tj *.google.tl *.google.tm *.google.tn *.google.to *.google.com.tr *.google.tt *.google.com.tw *.google.co.tz *.google.com.ua *.google.co.ug *.google.co.uk *.google.com.uy *.google.co.uz *.google.com.vc *.google.co.ve *.google.vg *.google.co.vi *.google.com.vn *.google.vu *.google.ws *.google.rs *.google.co.za *.google.co.zm *.google.co.zw *.google.cat cdn.cookielaw.org *.onetrust.com *.svc.dynamics.com *.clarity.ms ad.doubleclick.net adservice.google.com assets-eur.mkt.dynamics.com public-eur.mkt.dynamics.com assets.adobedtm.com c-cdn.contentfry.com catalog.contentfry.com platform.contentfry.com code.jquery.com fbo-b.flippingbook.com online.flippingbook.com live.solique.ch polyfilljs.org s7e5a.scene7.com s7mbrstream-g1.scene7.com www.googleadservices.com ; font-src 'self' fonts.gstatic.com www.gfms.com widget.moin.ai static-prod.uberall.com static.prod.uberall.com ; script-src 'self' 'unsafe-inline' 'unsafe-eval' www.google.com *.google-analytics.com *.googletagmanager.com assets.adobedtm.com ajax.googleapis.com assets.georgfischer.com cc.cdn.civiccomputing.com connect.facebook.net cdnjs.cloudflare.com gstatic.com maps.googleapis.com siteimproveanalytics.com snap.licdn.com static-prod.uberall.com uberall.com locator.uberall.com www.youtube.com www.pagespeed-mod.com www.googleoptimize.com mktdplp102cdn.azureedge.net www.pagespeed-mod.com widget.moin.ai platform.contentfry.com cdn.cookielaw.org cookie-cdn.cookiepro.com privacyportal.onetrust.com geolocation.onetrust.com r1.dotdigital-pages.com r1-t.trackedlink.net r1.ddlnk.net www.googleadservices.com ; script-src-elem uberall.com www.googletagmanager.com 'self' assets.georgfischer.com blob: code.jquery.com locator.uberall.com maps.googleapis.com s7e5a.scene7.com www.clarity.ms www.google.com www.googleadservices.com www.youtube.com ; style-src 'self' 'unsafe-inline' 'unsafe-eval' fonts.googleapis.com assets.georgfischer.com errors.adobeaemcloud.com widget.moin.ai ; style-src-elem www.googletagmanager.com 'self' assets.georgfischer.com blob: s7e5a.scene7.com www.gstatic.com ; img-src 'self' 'unsafe-inline' 'unsafe-eval' data: *.georgfischer.com www.linkedin.com *.global.siteimproveanalytics.io nswow-imageresizer.azurewebsites.net px.ads.linkedin.com www.facebook.com connect.facebook.net *.google.com gfms.com www.gfms.com static-prod.uberall.com static.prod.uberall.com www.linkedin.com s7e5a.scene7.com *.g.doubleclick.net *.svc.dynamics.com i.ytimg.com maps.gstatic.com fonts.gstatic.com www.gfps.com www.gfpstools.com locator.uberall.com *.amazonaws.com *.googletagmanager.com *.googleapis.com *.google-analytics.com *.analytics.google.com *.google.ad *.google.ae *.google.com.af *.google.com.ag *.google.com.ai *.google.al *.google.am *.google.co.ao *.google.com.ar *.google.as *.google.at *.google.com.au *.google.az *.google.ba *.google.com.bd *.google.be *.google.bf *.google.bg *.google.com.bh *.google.bi *.google.bj *.google.com.bn *.google.com.bo *.google.com.br *.google.bs *.google.bt *.google.co.bw *.google.by *.google.com.bz *.google.ca *.google.cd *.google.cf *.google.cg *.google.ch *.google.ci *.google.co.ck *.google.cl *.google.cm *.google.cn *.google.com.co *.google.co.cr *.google.com.cu *.google.cv *.google.com.cy *.google.cz *.google.de *.google.dj *.google.dk *.google.dm *.google.com.do *.google.dz *.google.com.ec *.google.ee *.google.com.eg *.google.es *.google.com.et *.google.fi *.google.com.fj *.google.fm *.google.fr *.google.ga *.google.ge *.google.gg *.google.com.gh *.google.com.gi *.google.gl *.google.gm *.google.gr *.google.com.gt *.google.gy *.google.com.hk *.google.hn *.google.hr *.google.ht *.google.hu *.google.co.id *.google.ie *.google.co.il *.google.im *.google.co.in *.google.iq *.google.is *.google.it *.google.je *.google.com.jm *.google.jo *.google.co.jp *.google.co.ke *.google.com.kh *.google.ki *.google.kg *.google.co.kr *.google.com.kw *.google.kz *.google.la *.google.com.lb *.google.li *.google.lk *.google.co.ls *.google.lt *.google.lu *.google.lv *.google.com.ly *.google.co.ma *.google.md *.google.me *.google.mg *.google.mk *.google.ml *.google.com.mm *.google.mn *.google.ms *.google.com.mt *.google.mu *.google.mv *.google.mw *.google.com.mx *.google.com.my *.google.co.mz *.google.com.na *.google.com.ng *.google.com.ni *.google.ne *.google.nl *.google.no *.google.com.np *.google.nr *.google.nu *.google.co.nz *.google.com.om *.google.com.pa *.google.com.pe *.google.com.pg *.google.com.ph *.google.com.pk *.google.pl *.google.pn *.google.com.pr *.google.ps *.google.pt *.google.com.py *.google.com.qa *.google.ro *.google.ru *.google.rw *.google.com.sa *.google.com.sb *.google.sc *.google.se *.google.com.sg *.google.sh *.google.si *.google.sk *.google.com.sl *.google.sn *.google.so *.google.sm *.google.sr *.google.st *.google.com.sv *.google.td *.google.tg *.google.co.th *.google.com.tj *.google.tl *.google.tm *.google.tn *.google.to *.google.com.tr *.google.tt *.google.com.tw *.google.co.tz *.google.com.ua *.google.co.ug *.google.co.uk *.google.com.uy *.google.co.uz *.google.com.vc *.google.co.ve *.google.vg *.google.co.vi *.google.com.vn *.google.vu *.google.ws *.google.rs *.google.co.za *.google.co.zm *.google.co.zw *.google.cat cdn.cookielaw.org c.clarity.ms m.youtube.com *.onetrust.com ; child-src 'self' blob: analytics-eu.clickdimensions.com live.solique.ch www.youtube.com ; form-action www.facebook.com www.georgfischer.com 'self' ; frame-ancestors 'self' https://*.georgfischer.com; frame-src 'self' 'unsafe-inline' 'unsafe-eval' data: analytics-eu.clickdimensions.com google.com ir.tools.investis.com irs.tools.investis.com live.solique.ch recruitingapp-5505.de.umantis.com registration.gesevent.com six-swiss-exchange.com tools.google.com uberall.com widget.moin.ai *.svc.dynamics.com *.ep-mimecast.dynamics.com www.gfps.com bim.gfps.com ir2.flife.de www.youtube.com m.youtube.com *.ep-mimecast.youtube-nocookie.com www.youtube-nocookie.com.x.af435fba09eaa04ff30886e05784e20ddae5.d045227c.id.opendns.com r1.dotdigital-pages.com display.contentfry.com googletagmanager.com cad.georgfischer.com forms.office.com foundation-gf-dev.georgfischer.com online.flippingbook.com players.brightcove.net youtube.com ; manifest-src 'self' ; media-src 'self' assets.georgfischer.com gfms.com s7e5a.scene7.com s7mbrstream-g1.scene7.com www.gfps.com ; 3 font-src fonts.gstatic.com use.typekit.net *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.klarnacdn.net *.fontawesome.com https://fonts.bunny.net *.kalogirou.com *.adman.gr *.grxchange.gr http://trustmark.gr *.klarnaservices.com *.cloudflare.com *.twitter.com *.typekit.net *.twimg.com *.trustedshops.com *.googleapis.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com *.googlesyndication.com www.facebook.com www.youtube.com *.adman.gr *.grxchange.gr http://trustmark.gr *.klarnaservices.com *.twitter.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.google.com *.doubleclick.net www.facebook.com *.googlesyndication.com connect.facebook.net graph.facebook.com business.facebook.com *.klarna.com *.cookiebot.com www.youtube.com *.contactpigeon.com *.skroutz.gr *.netsteps.net *.trust-servers.net https://www.googletagmanager.com *.adman.gr *.grxchange.gr http://trustmark.gr *.klarnaservices.com *.twitter.com www.xtento.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com 'self' data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com www.youtube.com p.typekit.net validator.swagger.io *.gstatic.com *.google.com *.google.bg www.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.googlesyndication.com connect.facebook.net graph.facebook.com business.facebook.com *.klarna.com *.klarnaevt.com *.klarnacdn.net https://firebasestorage.googleapis.com www.google.gr *.cookiebot.com *.google-analytics.com maps.gstatic.com *.kalogirou.com *.contactpigeon.com *.sharethis.com *.klarnaservices.com *.netsteps.net *.trust-servers.net https://kalogirou.com https://kalogirou.com/pub/media/ *.adman.gr *.grxchange.gr http://trustmark.gr *.cloudflare.com *.googleadservices.com *.paypal.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.skroutz.gr www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com *.vimeo.com www.vimeo.com *.vimeocdn.com www.youtube.com https://www.gstatic.com/recaptcha/ *.google.com assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.googleapis.com *.google.bg *.googletagmanager.com www.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com connect.facebook.net graph.facebook.com business.facebook.com *.klarna.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.avada.io 'self' data: *.cookiebot.com *.googleadservices.com stats.g.doubleclick.net googleads.g.doubleclick.net *.kalogirou.com *.go-mpulse.net *.sharethis.com *.contactpigeon.com *.google.gr *.taboola.com *.skroutz.gr *.netsteps.net *.trust-servers.net *.adman.gr *.grxchange.gr http://trustmark.gr *.cloudflare.com *.twitter.com *.twimg.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com *.klarnacdn.net *.fontawesome.com https://fonts.bunny.net *.kalogirou.com www.youtube.com *.contactpigeon.com *.netsteps.net *.trust-servers.net *.adman.gr *.grxchange.gr http://trustmark.gr *.klarnaservices.com *.cloudflare.com *.twitter.com *.twimg.com *.typekit.net *.trustedshops.com *.usercentrics.eu 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.google-analytics.com www.facebook.com *.facebook.net *.google.com *.doubleclick.net *.googlesyndication.com connect.facebook.net graph.facebook.com business.facebook.com *.klarnaevt.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.klarna.com https://get.geojs.io *.avada.io maps.googleapis.com stats.g.doubleclick.net googleads.g.doubleclick.net *.cookiebot.com *.kalogirou.com www.youtube.com *.go-mpulse.net *.sharethis.com *.contactpigeon.com eu.klarnaevt.com *.taboola.com *.akstat.io *.skroutz.gr *.netsteps.net *.trust-servers.net *.adman.gr *.grxchange.gr http://trustmark.gr *.cloudflare.com *.twitter.com *.paypal.com *.twimg.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri *.contactpigeon.com *.googlesyndication.com *.netsteps.net *.trust-servers.net *.adman.gr *.grxchange.gr http://trustmark.gr *.klarnaservices.com 'self' 'unsafe-inline'; report-uri https://csp-reporting-service.com/my-project/endpoint; report-to report-endpoint; 3 font-src fonts.googleapis.com x.klarnacdn.net cdn.elev.io maxcdn.bootstrapcdn.com *.fontawesome.com *.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.ditur.dk *.ditur.no *.ditur.se *.ditur.de *.ditur.fi *.ditur.com *.ditur.fr *.ditur.pl *.avile.dk policy.app.cookieinformation.com ct.pinterest.com td.doubleclick.net tr.snapchat.com tr6.snapchat.com messenger-edge.dixa.io messenger.dixa.io www.googletagmanager.com facebook.com *.facebook.com *.klarna.com *.trustpilot.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com *.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.google.com *.google.dk *.facebook.com bat.bing.com bat.bing.net stats.g.doubleclick.net *.sleeknote.com parametre.online *.ditur.dk *.ditur.no *.ditur.se *.ditur.de *.ditur.fi *.ditur.com *.ditur.fr *.ditur.at *.ditur.co.uk *.ditur.ie *.ditur.be *.ditur.nl *.ditur.is *.ditur.it *.ditur.es *.ditur.pt *.klockia.se *.klockia.dk *.klockia.no *.avile.dk ditur.dk ditur.no ditur.se ditur.de ditur.fi ditur.com ditur.fr ditur.at ditur.co.uk ditur.ie ditur.be ditur.nl ditur.is ditur.it ditur.es ditur.pt klockia.se klockia.dk klockia.no avile.dk tr.snapchat.com tr6.snapchat.com *.etrusted.com *.trustedshops.com https://images.unsplash.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://www.magezon.com https://redchamps.com *.klarna.com *.klarnaevt.com *.klarnacdn.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com *.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.reaktion.com policy.app.cookieinformation.com policy.cookieinformation.com *.facebook.net script.parametre.online ct.pinterest.com s.pinimg.com bat.bing.com *.tiktok.com *.sleeknote.com *.getdrip.com *.cloudfront.net *.kameleoon.eu *.kameleoon.io *.fontawesome.com *.ditur.dk *.ditur.se *.ditur.no *.ditur.de *.ditur.fi *.ditur.com *.ditur.fr *.ditur.pl messenger.dixa.io sc-static.net tr.snapchat.com cdn.elev.io *.clarity.ms checkout.reepay.com static.cloudflareinsights.com *.trustedshops.com *.etrusted.com *.getzowie.com *.heylink.com *.posthog.com *.tangiblee.com *.impactcdn.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.avada.io *.klarnacdn.net *.klarna.com *.profitmetrics.io *.trustpilot.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com static.products.kameleoon.com x.klarnacdn.net fonts.googleapis.com *.etrusted.com https://static.klaviyo.com maxcdn.bootstrapcdn.com *.fontawesome.com *.trustpilot.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.reaktion.com *.cookieinformation.com google.com *.google.com googleads.g.doubleclick.net *.pinterest.com *.tiktok.com *.ditur.dk *.ditur.no *.ditur.se *.ditur.de *.ditur.fi *.ditur.com *.ditur.fr *.ditur.pl *.avile.dk api.products.kameleoon.com *.kameleoon.eu data.kameleoon.io *.fontawesome.com bat.bing.com bat.bing.net invitejs.trustpilot.com tr.snapchat.com tr6.snapchat.com messenger-edge.dixa.io region1.google-analytics.com cdn.elev.io ipa.elev.io events.elev.io *.clarity.ms pagead2.googlesyndication.com *.etrusted.com *.getzowie.com analytics.sleeknote.com/ *.posthog.com *.tangiblee.com *.impactcdn.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://get.geojs.io *.avada.io *.klarnacdn.net *.klarna.com *.klarnaevt.com *.profitmetrics.io 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 3 font-src *.fontawesome.com fonts.googleapis.com https://fonts.gstatic.com https://www.google.com https://www.gstatic.com fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net pilot-payflowlink.paypal.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com 'self' 'unsafe-inline'; frame-ancestors *.magerocket.com *.gocuotas.com 'self'; frame-src fast.amc.demdex.net *.adobe.com secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.dotdigital-pages.com *.dotdigital.com *.mercadolibre.com https://www.googletagmanager.com/ *.magerocket.com *.gocuotas.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com validator.swagger.io *.mlstatic.com *.mercadopago.com *.mercadolibre.com *.mercadolivre.com.br *.mercadolibre.com.mx *.mercadolibre.com.ar *.mercadolivre.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ www.googletagmanager.com *.magerocket.com *.gocuotas.com storage.googleapis.com *.google.com *.google.com.ar imgmp.mlstatic.com *.googletagmanager.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com maps.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com https://device.clearsale.com.br https://live.decidir.com *.mlstatic.com *.mercadopago.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ *.magerocket.com *.gocuotas.com *.googleapis.com *.google.com *.gstatic.com *.avada.io polyfill.io go.botmaker.com storage.googleapis.com https://assets-cdn.woowup.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com maps.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.fontawesome.com fonts.googleapis.com *.googleapis.com *.google.com *.gstatic.com storage.googleapis.com unsafe-inline 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ storage.googleapis.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com https://events.woowup.com https://developers.decidir.com/ https://developers-ventasonline.payway.com.ar/ *.mercadopago.com *.mercadolibre.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ *.magerocket.com *.gocuotas.com http://dpm.demdex.net https://www.google.com https://www.gstatic.com https://get.geojs.io *.avada.io go.botmaker.com stats.g.doubleclick.net maps.googleapis.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 3 default-src 'self' *.zdassets.com *.zopim.com *.zendesk.com wss://*.zendesk.com wss://*.zopim.com ; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.klaviyo.com cdn.qantasloyalty.com api-accent.bloomreach.co mpsnare.iesnare.com/snare.js api.smooch.io applepay.cdn-apple.com *.googleadservices.com assets.braintreegateway.com/web *.bazaarvoice.com *.doubleclick.net storage.googleapis.com/workbox-cdn www.google.com/recaptcha/ www.gstatic.com/recaptcha/ cfjump.vans.com.au cfjump.vans.co.nz *.fullstory.com www.googletagmanager.com analytics.tiktok.com cdn.unidays.world *.truefitcorp.com www.paypalobjects.com/api/checkout.min.js *.klaviyo.com t.cfjump.com *.zdassets.com connect.facebook.net maps.googleapis.com dma-cdn.staging.truefitcorp.com/fitrec/dma/js/tracker.js js-agent.newrelic.com js.datadome.co ct.captcha-delivery.com *.adobedtm.com *.afterpay.com *.demdex.net *.forter.com dlthst9q2beh8.cloudfront.net d2nww8zpyj5pk0.cloudfront.net *.google-analytics.com *.paypal.com afterpay.com foursixty.com *.useinsider.com *.roymorgan.com lantern.roeyecdn.com js-sandbox.squarecdn.com player.vimeo.com js.squarecdn.com *.stg.qantasloyalty.com/appcache/wid-redemptions-button/master/ ; style-src 'self' 'unsafe-inline' *.klaviyo.com/onsite/ display.ugc.bazaarvoice.com maxcdn.bootstrapcdn.com/font-awesome *.typekit.net fonts.googleapis.com assets.braintreegateway.com *.adobetm.com foursixty.com *.adobemc.com static.klaviyo.com/onsite/js static-tracking.klaviyo.com/onsite/js assets.api.useinsider.com/css *.klaviyo.com/onsite/ ; img-src data: 'self' api-accent.bloomreach.co *.zendesk.com dpm.demdex.net www.googleadservices.com/ccm www.magentocommerce.com/products/media *.vans.co.nz *.vans.com.au googleads.g.doubleclick.net ad.doubleclick.net www.google.com/ccm www.paypalobjects.com www.google.com www.google.com.au www.google.co.nz www.google.com.vn maps.gstatic.com/mapfiles scontent.cdninstagram.com *.afterpay.com *.accentgra.com www.googletagmanager.com www.facebook.com *.bazaarvoice.com t.paypal.com duuytoqss3gu4.cloudfront.net df45ay5pw60dy.cloudfront.net d3nocrch4qti4v.cloudfront.net *.google-analytics.com *.pinterest.com *.tiktok.com *.useinsider.com maps.googleapis.com/maps developers.google.com *.zopim.io *.zdassets.com adservice.google.com lantern.roeye.com d3k81ch9hvuctc.cloudfront.net ; object-src 'none' ; base-uri 'self' ; child-src 'self' blob: ; connect-src 'self' gateway.stg.qantasloyalty.com gateway.qantasloyalty.com api-accent.bloomreach.co analytics.google.com/g/collect iq.afterpay.com/us/v1 iq.afterpay-beta.com/us/v1 *.my.sentry.io wss://api.smooch.io *.accentgra.com www.facebook.com/tr google.com www.google.com collect-ap2.attraqt.io smetrics.vans.co.nz *.fullstory.com *.klaviyo.com smetrics.vans.com.au api-js.datadome.co *.adobedc.net *.afterpay.com *.bazaarvoice.com *.braintree-api.com *.braintreegateway.com *.demdex.net *.forter.com *.foursixty.com google.com/ccm www.google.com/ccm *.google-analytics.com *.googleapis.com *.nr-data.net *.paypal.com *.truefitcorp.com *.zdassets.com *.zendesk.com *.zopim.com accentgroupxpdev.112.2o7.net afterpay.com analytics.tiktok.com facebook.com foursixty.com kleber.datatoolscloud.net.au sentry.io smetrics.hypedc.com vimeo.com wss://widget-mediator.zopim.com d2o5idwacg3gyw.cloudfront.net dz8rit8v72mig.cloudfront.net d2lxqodqbpy7c2.cloudfront.net d6rak4b14t5gp.cloudfront.net d3k4bt74u9esq1.cloudfront.net wss://cdn0.forter.com api.myunidays.com o19233.ingest.sentry.io/api/1188273/store ct.pinterest.com opreq.observepoint.com *.useinsider.com stats.g.doubleclick.net/g/collect *.stg.qantasloyalty.com/redemptions/ ; font-src data: 'self' maxcdn.bootstrapcdn.com/font-awesome fonts.gstatic.com *.truefitcorp.com *.useinsider.com static.klaviyo.com use.typekit.net shopping.qantas.com/static/fonts ; frame-src 'self' checkout.qantas.com api-accent.bloomreach.co www.googletagmanager.com geo.captcha-delivery.com *.formstack.com *.afterpay.com *.bazaarvoice.com *.demdex.net *.doubleclick.net *.facebook.com *.myunidays.com *.omniparcelreturns.com *.paypal.com *.paypalobjects.com *.truefitcorp.com *.useinsider.com *.vimeo.com *.youtu.be *.youtube.com afterpay.com assets.braintreegateway.com facebook.com foursixty.com google.com www.google.com vimeo.com *.qlstg.qantas.com/ ; worker-src 'self' blob: *.accentgra.com *.vans.co.nz *.vans.com.au; 3 object-src 'none'; script-src 'self' https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://checkoutshopper-live.adyen.com https://checkoutshopper-test.cdn.adyen.com https://homologation-payment.cdn.payline.com https://payment.cdn.payline.com https://static.addtoany.com https://uberall.com https://unpkg.com https://www.google.com https://www.youtube.com; script-src-attr 'self'; style-src 'self' https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://checkoutshopper-live.adyen.com https://checkoutshopper-test.cdn.adyen.com https://homologation-payment.cdn.payline.com https://payment.cdn.payline.com https://unpkg.com; style-src-attr 'self'; frame-ancestors 'self' 3 font-src fonts.gstatic.com use.typekit.net *.yotpo.com *.googleapis.com *.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.demdex.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ connect.bolt.com connect-sandbox.bolt.com account.bolt.com account-sandbox.bolt.com *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net connect.bolt.com connect-sandbox.bolt.com s3-us-west-1.amazonaws.com *.yotpo.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net assets.adobedtm.com *.magento-ds.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com connect.bolt.com connect-sandbox.bolt.com account.bolt.com account-sandbox.bolt.com *.plugins.emarsys.net *.scarabresearch.com *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.magento-datasolutions.com *.magento-ds.com *.yotpo.com *.googleapis.com 'self' 'unsafe-inline'; object-src connect.bolt.com connect-sandbox.bolt.com account.bolt.com account-sandbox.bolt.com 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.magento.com *.magento-datasolutions.com *.magento-ds.com connect.bolt.com connect-sandbox.bolt.com account.bolt.com account-sandbox.bolt.com sessions.bugsnag.com *.scarabresearch.com *.eservice.emarsys.net *.yotpo.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 3 default-src 'self' data: 'unsafe-eval' 'unsafe-inline' *.shopmetrics.com *.gigspot.com *.research-cloud.com https://*.jsdelivr.net https://unpkg.com https://*.unpkg.com https://*.googleapis.com https://*.google-analytics.com https://*.gstatic.com https://*.search.windows.net https://cdnjs.cloudflare.com https://code.jquery.com *.facebook.net *.facebook.com *.doubleclick.net *.googletagmanager.com *.bootstrapcdn.com *.typekit.net https://rmvelocityfrontend.blob.core.windows.net https://rec.i-say.com https://vcdn.blob.core.windows.net/* https://cdn.vcdn.vc/*; script-src 'self' data: 'unsafe-eval' 'unsafe-inline' *.shopmetrics.com *.gigspot.com *.research-cloud.com https://*.jsdelivr.net https://unpkg.com https://*.unpkg.com https://*.googleapis.com https://*.google-analytics.com https://*.gstatic.com https://*.search.windows.net https://cdnjs.cloudflare.com https://code.jquery.com *.facebook.net *.facebook.com *.doubleclick.net *.googletagmanager.com *.bootstrapcdn.com *.typekit.net https://rmvelocityfrontend.blob.core.windows.net; frame-src 'self' blob: *.shopmetrics.com *.gigspot.com *.research-cloud.com *.velocity.online https://www.googletagmanager.com *.youtube.com *.youtu.be; base-uri 'self'; form-action 'self' *.shopmetrics.com *.gigspot.com *.velocity.online; img-src * data: about: blob: filesystem: ma-file:; object-src 'none'; font-src 'self' data: *.shopmetrics.com *.bootstrapcdn.com *.typekit.net *.gstatic.com *.jsdelivr.net *.pstatic.net *.github.com; 3 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com *.fontawesome.com https://fonts.gstatic.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com 'self' https://webpay3gint.transbank.cl https://webpay3g.transbank.cl https://www.facebook.com/* pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com 'self' 'unsafe-inline'; frame-ancestors *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com bytedance: sslocal: www.google.com https://player.vimeo.com https://www.youtube.com https://www.googletagmanager.com https://tagmanager.google.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com https://www.youtube-nocookie.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.googleapis.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com analytics.tiktok.com bat.bing.com *.bat.bing.com *.msn.com *.bing.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com blob: https://updates.themepunch.tools http://updates.themepunch.tools https://updates.themepunch-ext-a.tools http://updates.themepunch-ext-a.tools https://updates.themepunch-ext-b.tools http://updates.themepunch-ext-b.tools https://dev.sliderrevolution.com https://revolution.themepunch.com http://revolution5.themepunch.com http://pbs.twimg.com https://pbs.twimg.com http://scontent.cdninstagram.com https://img.youtube.com http://live.staticflickr.com https://live.staticflickr.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net amcglobal.sc.omtrdc.net commerce.adobe.net use.typekit.net *.commerce-payment-services.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-ds.com *.typekit.net google.com *.google.com *.cdn-apple.com *.googleapis.com *.gstatic.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com analytics.tiktok.com www.google.com www.gstatic.com *.avada.io https://www.googletagmanager.com https://tagmanager.google.com https://546002994.collect.igodigital.com https://assets.adobedtm.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com https://player.vimeo.com https://www.youtube.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com https://fonts.googleapis.com http://fonts.googleapis.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com static.zdassets.com blob: 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.snplow.net commerce.adobedc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net commerce.adobe.io commerce.adobe.net *.sentry.io *.paypal.com google.com *.google.com qa-api.magedevteam.com *.googleapis.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com analytics.tiktok.com https://dpm.demdex.net https://amcglobal.sc.omtrdc.net https://geostag.cardinalcommerce.com https://geo.cardinalcommerce.com https://1eafstag.cardinalcommerce.com https://1eaf.cardinalcommerce.com https://centinelapistag.cardinalcommerce.com https://centinelapi.cardinalcommerce.com https://commerce.adobedc.net https://analytics.google.com https://vimeo.com https://api.magento.com https://performance.typekit.net https://pilot-payflowlink.paypal.com https://commerce.adobe.io https://commerce.adobe.net https://google.com https://qa-api.magedevteam.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br *.mercadopago.com.br *.mlstatic.com 'self' 'unsafe-inline' https://mercadopago.com.br https://fonts.googleapis.com https://fonts.gstatic.com https://api.weatherbit.io https://www.google-analytics.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 3 default-src * blob: data: 'unsafe-inline' 'unsafe-eval'; script-src * blob: data: 'unsafe-inline' 'unsafe-eval'; style-src * 'unsafe-inline'; img-src * data: blob:; media-src * data: blob:; font-src * data: blob:; connect-src *; frame-src *; object-src * 3 font-src *.gstatic.com mcstaging.iochile.cl mcstaging.magriffe.cl mcstaging.ashchile.cl www.iochile.cl www.magriffe.cl www.ashchile.cl *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.transbank.cl *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net https://www.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.googletagmanager.com *.newrelic.com *.herokuapp.com *.doubleclick.net/ *.googleapis.com mcstaging.iochile.cl mcstaging.magriffe.cl mcstaging.ashchile.cl www.iochile.cl www.magriffe.cl www.ashchile.cl *.weltpixel.com *.google.com/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.google.com.ar *.instagram.com *.cdninstagram.com *.gstatic.com *.facebook.com *.newrelic.com *.clarity.ms *.bing.com *.googleapis.com mcstaging.iochile.cl mcstaging.magriffe.cl mcstaging.ashchile.cl www.iochile.cl www.magriffe.cl www.ashchile.cl https://www.magezon.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.googleapis.com https://*.woowup.com *.herokuapp.com *.instagram.com *.facebook.net *.newrelic.com *.nr-data.net *.clarity.ms mcstaging.iochile.cl mcstaging.magriffe.cl mcstaging.ashchile.cl www.iochile.cl www.magriffe.cl www.ashchile.cl *.google.com/ onesignal.com *.onesignal.com *.avada.io player.vimeo.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://www.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.googleapis.com *.herokuapp.com *.newrelic.com mcstaging.iochile.cl mcstaging.magriffe.cl mcstaging.ashchile.cl www.iochile.cl www.magriffe.cl www.ashchile.cl *.fontawesome.com unsafe-inline assets.braintreegateway.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.googleapis.com *.google.com.ar *.doubleclick.com *.doubleclick.net *.newrelic.com *.nr-data.net *.clarity.ms mcstaging.iochile.cl mcstaging.magriffe.cl mcstaging.ashchile.cl www.iochile.cl www.magriffe.cl www.ashchile.cl https://get.geojs.io *.avada.io https://*.woowup.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.google-analytics.com *.facebook.net 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src mcstaging.iochile.cl mcstaging.magriffe.cl mcstaging.ashchile.cl www.iochile.cl www.magriffe.cl www.ashchile.cl 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 3 default-src 'self' wss: *.gravatar.com *.civicplus.com *.civicplus.pro *.civic.place *.civicclerk.com engage6.azureedge.net *.audioeye.com *.pendo.io *.zdassets.com *.zendesk.com *.zopim.com *.arcgis.com *.arcgisonline.com *.services.visualstudio.com *.monitor.azure.com *.googleapis.com *.googletagmanager.com *.google-analytics.com use.fontawesome.com *.google.com *.gstatic.com gstatic.com cdnjs.cloudflare.com static.cloudflareinsights.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.publicstuff.com *.googletagmanager.com *.civicplus.com *.civicplus.pro *.civicclerk.com engage6.azureedge.net *.audioeye.com *.pendo.io *.zdassets.com *.zendesk.com *.zopim.com *.arcgis.com *.arcgisonline.com *.services.visualstudio.com *.monitor.azure.com *.googleapis.com *.googletagmanager.com *.google-analytics.com use.fontawesome.com *.google.com *.gstatic.com gstatic.com cdnjs.cloudflare.com static.cloudflareinsights.com connect.facebook.net static.addtoany.com https://widgets.nrel.gov *.openstreetmap.org cdn-images.mailchimp.com platform.twitter.com blob:; object-src 'self' 'unsafe-inline' 'unsafe-eval' translate.googleapis.com iframe.publicstuff.com; style-src 'self' 'unsafe-inline' iframe.publicstuff.com *.civicplus.com *.civicplus.pro *.civicclerk.com *.civic.place engage6.azureedge.net *.audioeye.com *.pendo.io *.zdassets.com *.zendesk.com *.zopim.com *.arcgis.com *.arcgisonline.com *.services.visualstudio.com *.monitor.azure.com *.googleapis.com *.googletagmanager.com *.google-analytics.com use.fontawesome.com *.google.com *.gstatic.com gstatic.com cdnjs.cloudflare.com static.cloudflareinsights.com *.ctctcdn.com cdn-images.mailchimp.com data:; img-src 'self' 'unsafe-inline' iframe.publicstuff.com *.civicplus.com *.civicplus.pro *.civicclerk.com *.civic.place engage6.azureedge.net *.audioeye.com *.pendo.io *.zdassets.com *.zendesk.com *.zopim.com *.arcgis.com *.arcgisonline.com *.services.visualstudio.com *.monitor.azure.com *.googleapis.com *.googletagmanager.com *.google-analytics.com use.fontawesome.com *.google.com *.gstatic.com gstatic.com cdnjs.cloudflare.com static.cloudflareinsights.com www.facebook.com https://widgets.nrel.gov www.facebook.com *.openstreetmap.org cdn-images.mailchimp.com i.ytimg.com data:; media-src 'self' translate.googleapis.com iframe.publicstuff.com data:; frame-src 'self' 'unsafe-inline' iframe.publicstuff.com *.youtube.com *.airtable.com *.swagit.com *.google.com *.civicplus.com *.novusagenda.com *.publicstuff.com *.audioeye.com acg.is *.maps.arcgis.com https://www.google.com/maps/embed *.googletagmanager.com https://www.youtube.com/embed https://www.youtube-nocookie.com/embed static.addtoany.com www.facebook.com m.facebook.com my.matterport.com ltfl.librarything.com player.vimeo.com *.granicus.com data:; frame-ancestors 'self' *.civicplus.com *.civicplus.pro *.civic.place *.civicclerk.com; child-src 'self' 'unsafe-inline' iframe.publicstuff.com *.youtube.com *.airtable.com *.swagit.com *.google.com *.civicplus.com *.novusagenda.com *.publicstuff.com *.audioeye.com acg.is *.maps.arcgis.com https://www.google.com/maps/embed *.googletagmanager.com https://www.youtube.com/embed https://www.youtube-nocookie.com/embed static.addtoany.com www.facebook.com m.facebook.com my.matterport.com ltfl.librarything.com player.vimeo.com *.granicus.com data:; font-src 'self' 'unsafe-inline' 'unsafe-eval' *.civicplus.com *.civicplus.pro *.civicclerk.com engage6.azureedge.net *.audioeye.com *.pendo.io *.zdassets.com *.zendesk.com *.zopim.com *.arcgis.com *.arcgisonline.com *.services.visualstudio.com *.monitor.azure.com *.googleapis.com *.googletagmanager.com *.google-analytics.com use.fontawesome.com *.google.com *.gstatic.com gstatic.com cdnjs.cloudflare.com static.cloudflareinsights.com user.govoutreach.com syndication.twitter.com data:; connect-src 'self' 'unsafe-inline' iframe.publicstuff.com *.civicplus.com *.civicplus.pro *.civic.place *.civicclerk.com engage6.azureedge.net *.audioeye.com *.pendo.io *.zdassets.com *.zendesk.com *.zopim.com *.arcgis.com *.arcgisonline.com *.services.visualstudio.com *.monitor.azure.com *.googleapis.com *.googletagmanager.com *.google-analytics.com use.fontawesome.com *.google.com *.gstatic.com gstatic.com cdnjs.cloudflare.com static.cloudflareinsights.com stats.g.doubleclick.net; report-uri /report-csp-violation 3 base-uri 'none'; frame-ancestors 'self'; img-src data: 'self' https://www.google-analytics.com https://cdn.rgfstaffing.be https://i.ytimg.com https://maps.googleapis.com https://vumbnail.com https://maps.gstatic.com https://img.youtube.com https://www.google.be https://cdn.startpeople.be; object-src 'none'; script-src 'unsafe-eval' 'unsafe-inline' 'self' 'unsafe-inline' 'unsafe-eval' https://use.fontawesome.coms https://code.jquery.com https://cdn.jsdelivr.net https://consentcdn.cookiebot.com https://*.google-analytics.com https://cdn.startpeople.be https://kit.fontawesome.com https://maps.googleapis.com https://js.monitor.azure.com https://www.googletagmanager.com https://consent.cookiebot.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://cdn.jsdelivr.net; report-to csp-endpoint; report-uri https://csp-dxp.rgfstaffing.be/csp 3 script-src-elem *.bestheating.com *.bestheating.ie *.bigbathroomshop.co.uk *.bigbathroomshop.ie *.hudsonreed.com *.magedev.co.uk *.magedev2.co.uk *.magedev3.co.uk *.magedev4.co.uk *.magedev5.co.uk *.magedev6.co.uk *.magestage.co.uk *.mageweb.co.uk *.localdev.com *.ldgdev.co.uk *.adalyser.com *.payments-amazon.com *.cdn-apple.com *.billiger.de billiger.de *.bing.com *.bing.net js.braintreegateway.com *.braintreegateway.com *.cardinalcommerce.com *.cloudfront.net *.digitalbridgehq.com *.doubleclick.net *.equalweb.com www.facebook.com connect.facebook.net *.avocet.io avocet.io *.gstatic.com *.google.com *.google.co.uk www.googleadservices.com www.google-analytics.com *.googleapis.com *.googlecommerce.com *.googlesyndication.com www.googletagmanager.com s.kk-resources.com *.klarna.com *.klarnacdn.net *.klaviyo.com *.klevu.com secure.cimg.leguide.com *.clarity.ms js-agent.newrelic.com bam.nr-data.net *.onetrust.com www.paypalobjects.com *.paypal.com services.postcodeanywhere.co.uk trues11114.pcapredict.com s.pinimg.com ct.pinterest.com *.salesforce.com *.force.com *.salesforceliveagent.com ldg.my.site.com ldg.my.salesforce-scrt.com host *.solutenetwork.com *.trustpilot.com unpkg.com 'unsafe-inline' app.vwo.com *.visualwebsiteoptimizer.com *.jsdelivr.net *.fabric-analytics.com *.growthbook.io *.gb-ingest.com *.appzi.io *.webgains.io *.webgains.com; font-src *.klarnacdn.net *.klevu.com *.ksearchnet.com *.bestheating.com *.bestheating.ie *.bigbathroomshop.co.uk *.bigbathroomshop.ie *.hudsonreed.com *.magedev.co.uk *.magedev2.co.uk *.magedev3.co.uk *.magedev4.co.uk *.magedev5.co.uk *.magedev6.co.uk *.magestage.co.uk *.mageweb.co.uk *.localdev.com *.ldgdev.co.uk w.appzi.io *.equalweb.com *.googleusercontent.com *.typekit.net fonts.gstatic.com *.sirv.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * https://hpp.worldpay.com/app/hpp-iframe/integration/wpg/corporate https://secure-test.worldpay.com/shopper/3ds/ddc.html https://secure.worldpay.com/shopper/3ds/ddc.html https://payments-test.worldpay.com/app/hpp-iframe/integration/wpg/corporate https://payments-live.hpp.apps.eu-west-1-7z55k.dev.msp.worldpay.io/app/hpp-iframe/integration/wpg/corporate https://payments.worldpay.com/app/hpp-iframe/integration/wpg/corporate 'self' 'unsafe-inline'; frame-ancestors https://pay.google.com/ 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.klarna.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.bestheating.com *.bestheating.ie *.bigbathroomshop.co.uk *.bigbathroomshop.ie *.hudsonreed.com *.magedev.co.uk *.magedev2.co.uk *.magedev3.co.uk *.magedev4.co.uk *.magedev5.co.uk *.magedev6.co.uk *.magestage.co.uk *.mageweb.co.uk *.localdev.com *.ldgdev.co.uk *.equalweb.com *.google.com *.google.co.uk *.googlecommerce.com *.salesforce.com *.force.com *.salesforceliveagent.com ldg.my.site.com ldg.my.salesforce-scrt.com *.visualwebsiteoptimizer.com app.vwo.com https://payments-test.worldpay.com/app/hpp-iframe/integration/wpg/corporate https://payments.worldpay.com/app/hpp-iframe/integration/wpg/corporate https://payments-live.hpp.apps.eu-west-1-7z55k.dev.msp.worldpay.io/app/hpp-iframe/integration/wpg/corporate https://pay.google.com https://secure-test.worldpay.com https://hpp.worldpay.com/ 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.payments-amazon.com osm.klarnaservices.com *.klarnaevt.com *.klarnacdn.net https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.bestheating.com *.bestheating.ie *.bigbathroomshop.co.uk *.bigbathroomshop.ie *.hudsonreed.com *.magedev.co.uk *.magedev2.co.uk *.magedev3.co.uk *.magedev4.co.uk *.magedev5.co.uk *.magedev6.co.uk *.magestage.co.uk *.mageweb.co.uk *.localdev.com *.ldgdev.co.uk *.adalyser.com *.s3.eu-west-1.amazonaws.com *.bing.com *.bing.net *.cloudfront.net *.doubleclick.net *.equalweb.com www.facebook.com connect.facebook.net *.google.com *.google.co.uk www.google.es www.google.it www.google.fr www.google.de www.google.nl www.google.be www.google.at www.google.ie *.googlesyndication.com *.googleusercontent.com *.gstatic.com *.clarity.ms *.onetrust.com www.paypalobjects.com *.paypal.com services.postcodeanywhere.co.uk s.pinimg.com ct.pinterest.com *.salesforce.com *.force.com *.salesforceliveagent.com ldg.my.site.com ldg.my.salesforce-scrt.com *.sirv.com *.visualwebsiteoptimizer.com app.vwo.com useruploads.vwo.io *.jsdelivr.net *.fabric-analytics.com *.growthbook.io *.gb-ingest.com *.appzi.io *.cloudflare.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.klarna.com *.klarnacdn.net *.klarnacdn.net *.klarnaservices.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ js.klevu.com *.ksearchnet.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com songbird.cardinalcommerce.com *.bestheating.com *.bestheating.ie *.bigbathroomshop.co.uk *.bigbathroomshop.ie *.hudsonreed.com *.magedev.co.uk *.magedev2.co.uk *.magedev3.co.uk *.magedev4.co.uk *.magedev5.co.uk *.magedev6.co.uk *.magestage.co.uk *.mageweb.co.uk *.localdev.com *.ldgdev.co.uk *.adalyser.com *.cdn-apple.com *.billiger.de billiger.de *.bing.com *.bing.net *.braintreegateway.com *.cardinalcommerce.com *.cloudfront.net *.digitalbridgehq.com *.doubleclick.net *.equalweb.com www.facebook.com connect.facebook.net *.avocet.io avocet.io *.google.com *.google.co.uk *.googleapis.com *.googlecommerce.com *.googlesyndication.com *.gstatic.com s.kk-resources.com *.klaviyo.com *.klevu.com secure.cimg.leguide.com *.clarity.ms js-agent.newrelic.com bam.nr-data.net *.onetrust.com www.paypalobjects.com *.paypal.com services.postcodeanywhere.co.uk trues11114.pcapredict.com s.pinimg.com ct.pinterest.com *.salesforce.com *.force.com *.salesforceliveagent.com ldg.my.site.com ldg.my.salesforce-scrt.com *.solutenetwork.com *.trustpilot.com unpkg.com app.vwo.com *.visualwebsiteoptimizer.com *.jsdelivr.net *.fabric-analytics.com *.growthbook.io *.gb-ingest.com *.appzi.io *.webgains.io *.webgains.com player.vimeo.com https://www.google.com/recaptcha/api.js *.cloudflare.com https://pay.google.com/gp/p/js/pay.js https://applepay.cdn-apple.com/jsapi/v1/apple-pay-sdk.js https://payments.worldpay.com/resources/cse/js/worldpay-cse-1.0.2.min.js https://payments.worldpay.com/resources/hpp/integrations/embedded/js/hpp-embedded-integration-library.js https://d35p4vvdul393k.cloudfront.net/sdk_library/us/stg/ops/pc_gsmpi_web_sdk.js https://d16i99j5zwwv51.cloudfront.net/sdk_library/us/prd/ops/pc_gsmpi_web_sdk.js *.sirv.com https://js.klevu.com https://service.force.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.klarnacdn.net https://static.klaviyo.com *.klevu.com *.ksearchnet.com unsafe-inline assets.braintreegateway.com *.bestheating.com *.bestheating.ie *.bigbathroomshop.co.uk *.bigbathroomshop.ie *.hudsonreed.com *.magedev.co.uk *.magedev2.co.uk *.magedev3.co.uk *.magedev4.co.uk *.magedev5.co.uk *.magedev6.co.uk *.magestage.co.uk *.mageweb.co.uk *.localdev.com *.ldgdev.co.uk *.equalweb.com fonts.googleapis.com www.googletagmanager.com *.gstatic.com *.klaviyo.com services.postcodeanywhere.co.uk *.salesforce.com *.force.com *.salesforceliveagent.com ldg.my.site.com ldg.my.salesforce-scrt.com *.typekit.net *.visualwebsiteoptimizer.com app.vwo.com useruploads.vwo.io *.jsdelivr.net *.fabric-analytics.com *.growthbook.io *.gb-ingest.com *.appzi.io *.cloudflare.com https://fonts.googleapis.com/css *.sirv.com https://statsjs.klevu.com https://js.klevu.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.bestheating.com *.bestheating.ie *.bigbathroomshop.co.uk *.bigbathroomshop.ie *.hudsonreed.com *.magedev.co.uk *.magedev2.co.uk *.magedev3.co.uk *.magedev4.co.uk *.magedev5.co.uk *.magedev6.co.uk *.magestage.co.uk *.mageweb.co.uk *.localdev.com *.ldgdev.co.uk *.bing.com *.bing.net *.equalweb.com *.gstatic.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.klarnaevt.com *.klarnacdn.net *.klarna.com *.klarnaservices.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.bestheating.com *.bestheating.ie *.bigbathroomshop.co.uk *.bigbathroomshop.ie *.hudsonreed.com *.magedev.co.uk *.magedev2.co.uk *.magedev3.co.uk *.magedev4.co.uk *.magedev5.co.uk *.magedev6.co.uk *.magestage.co.uk *.mageweb.co.uk *.localdev.com *.ldgdev.co.uk payments-eu.amazon.com *.s3.eu-west-1.amazonaws.com *.bing.com *.bing.net payments.braintree-api.com *.datadome.co *.digitalbridgehq.com eu.prd.impact.fixtuur.com *.doubleclick.net *.equalweb.com *.facebook.com *.google.com *.google.co.uk www.google.es www.google.it www.google.fr www.google.de www.google.nl www.google.be www.google.at www.google.ie *.googleapis.com *.googlesyndication.com *.clarity.ms js-agent.newrelic.com bam.nr-data.net *.onetrust.com www.paypalobjects.com *.paypal.com s.pinimg.com ct.pinterest.com www.pinterest.com services.postcodeanywhere.co.uk region1.google-analytics.com *.salesforce.com *.force.com *.salesforceliveagent.com ldg.my.site.com ldg.my.salesforce-scrt.com *.samsung.com *.typekit.net *.webgains.io *.visualwebsiteoptimizer.com app.vwo.com *.jsdelivr.net *.fabric-analytics.com *.growthbook.io *.gb-ingest.com *.appzi.io https://www.google.com/pay https://pay.google.com/gp/p/web_manifest.json https://pay.google.com/gp/p/payment_method_manifest.json https://pay.google.com/ https://google.com/pay *.worldpay.com https://hpp.worldpay.com/app/hpp/135-0/telemetry https://hpp.worldpay.com/app/hpp/135-0/payment/paypalsmartbutton/continue https://payments.worldpay.com/app/hpp/135-0/telemetry/iframe *.sirv.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri *.onetrust.com 'self' 'unsafe-inline'; report-uri https://f4ea971e-20d9-420f-b92f-973abc905556.sansec.watch/; report-to report-endpoint; 3 object-src 'none'; script-src 'self' 'unsafe-eval' fonts.googleapis translate.google.com translate.googleapis.com translate-pa.googleapis.com *.gstatic.com siteimproveanalytics.com *.siteimprove.com svc.webspellchecker.net js-agent.newrelic.com bam.nr-data.net assets.pinterest.com cdn.jsdelivr.net https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://rebilly.github.io https://unpkg.com maps.googleapis.com platform.instagram.com platform.twitter.com; script-src-attr 'self'; script-src-elem 'self' fonts.googleapis translate.google.com translate.googleapis.com translate-pa.googleapis.com *.gstatic.com siteimproveanalytics.com *.siteimprove.com svc.webspellchecker.net js-agent.newrelic.com bam.nr-data.net assets.pinterest.com cdn.jsdelivr.net https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://rebilly.github.io https://unpkg.com maps.googleapis.com platform.instagram.com platform.twitter.com; style-src 'self' fonts.googleapis translate.google.com translate.googleapis.com translate-pa.googleapis.com *.gstatic.com siteimproveanalytics.com *.siteimprove.com svc.webspellchecker.net js-agent.newrelic.com bam.nr-data.net cdn.jsdelivr.net fonts.googleapis.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com; style-src-attr 'self'; frame-ancestors 'self' 3 font-src *.afterpay.com/ *.afterpaycdn.com *.squarecdn.com *.cash.app *.googleapis.com *.gstatic.com data: *.klarnacdn.net *.fontawesome.com https://fonts.bunny.net *.cloudflare.com *.bootstrapcdn.com *.commerce-connector.com *.typekit.net */csp/report/uri/ *.hotjar.com *.hotjar.io *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnaevt.com *.link.com *.amazon.com *.wahl.com *.userway.org *.yotpo.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de api.bazaarvoice.com stg.api.bazaarvoice.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com 'self' *.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * https://plumrocket.com *.wahl.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.stripe.com stripe.com *.link.com *.amazon.com *.wahl.com; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.afterpay.com *.afterpaycdn.com *.squarecdn.com *.cash.app www.google.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com *.bluesnap.com *.cardinalcommerce.com *.kaptcha.com *.sentry.io *.google.com *.gstatic.com google.com sandbox.bluesnap.com sandbox1.bluesnap.com sandbox2.bluesnap.com sandpay.bluesnap.com ws.bluesnap.com ws1.bluesnap.com ws2.bluesnap.com pay.bluesnap.com *.klarna.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com *.adsrvr.org *.hotjar.com *.hotjar.io */csp/report/uri/ *.hubspot.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.paypal.com * https://plumrocket.com *.stripe.com klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.wahl.com www.xtento.com *.yotpo.com 'self' 'unsafe-inline'; style-src *.adobe.com *.afterpay.com/ *.afterpaycdn.com *.squarecdn.com *.cash.app fonts.googleapis.com display.ugc.bazaarvoice.com sandbox.bluesnap.com sandbox1.bluesnap.com sandbox2.bluesnap.com sandpay.bluesnap.com ws.bluesnap.com ws1.bluesnap.com ws2.bluesnap.com pay.bluesnap.com *.cardinalcommerce.com *.kaptcha.com *.sentry.io *.google.com *.gstatic.com google.com *.klarnacdn.net *.fontawesome.com https://fonts.bunny.net *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.googleapis.com *.powerreviews.com getfirebug.com cdn.dnky.co webchat.dotdigital.com *.yotpo.com *.cloudflare.com *.bootstrapcdn.com *.wahlclipper.com *.jsdelivr.net *.postcodeanywhere.co.uk *.commerce-connector.com *.typekit.net */csp/report/uri/ unsafe-inline assets.braintreegateway.com *.stripe.network *.stripecdn.com *.amazon.com www.gstatic.com cdn.weglot.com *.wahl.com *.userway.org 'self' 'unsafe-inline'; object-src *.wahl.com 'self' 'unsafe-inline'; media-src *.adobe.com *.wahl.com 'self' 'unsafe-inline'; manifest-src *.wahl.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.afterpay.com *.afterpay-beta.com *.afterpaycdn.com *.squarecdn.com *.cash.app *.googleapis.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de api.bazaarvoice.com stg.api.bazaarvoice.com apps.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com sandbox.bluesnap.com sandbox1.bluesnap.com sandbox2.bluesnap.com sandpay.bluesnap.com ws.bluesnap.com ws1.bluesnap.com ws2.bluesnap.com pay.bluesnap.com *.cardinalcommerce.com *.kaptcha.com *.sentry.io *.google.com *.gstatic.com *.amazonaws.com google.com *.klarnaevt.com *.klarnacdn.net *.klarna.com *.klarnaservices.com api.addressy.com https://get.geojs.io *.avada.io *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.facebook.com connect.facebook.net graph.facebook.com business.facebook.com stats.g.doubleclick.net ct.pinterest.com *.google-analytics.com *.whatcounts.com siteanalytics.whatcounts.com https://siteanalytics.whatcounts.com *.amazonaws.com/ *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com api.comapi.com webchat.dotdigital.com *.yotpo.com *.cloudflare.com *.powerreviews.com *.nr-data.net *.wahlclipper.com *.syndigo.com *.postcodeanywhere.co.uk wss://ws41.hotjar.com *.commerce-connector.com */csp/report/uri/ wss://*.hotjar.com *.hotjar.com *.hotjar.io *.hubspot.com *.hubapi.com *.hs-banner.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.stripe.com klarna.com *.link.com x.clarity.ms cdn.cookielaw.org forms.hscollectedforms.net geolocation.onetrust.com api.userway.org cdn77.api.userway.org cdn.userway.org api.weglot.com cdn.weglot.com https://cdn-api-weglot.com *.wahl.com *.hsforms.net *.hsforms.com *.clarity.ms *.pcapredict.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; base-uri *.wahl.com 'self' 'unsafe-inline'; script-src https://pxl.jivox.com https://secure.adnxs.com https://apps.bazaarvoice.com/ cdn.weglot.com 0409890c10.translations.weglot.io assets.adobedtm.com *.adobedtm.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.afterpay.com *.afterpaycdn.com *.squarecdn.com *.cash.app *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de apps.bazaarvoice.com apps.nexus.bazaarvoice.com apps-stg.nexus.bazaarvoice.com analytics-static.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com mpsnare.iesnare.com 'self' 'unsafe-inline' sandbox.bluesnap.com sandbox1.bluesnap.com sandbox2.bluesnap.com sandpay.bluesnap.com ws.bluesnap.com ws1.bluesnap.com ws2.bluesnap.com pay.bluesnap.com *.cardinalcommerce.com *.kaptcha.com *.sentry.io *.google.com static.cloudflareinsights.com cdnjs.cloudflare.com google.com *.klarna.com *.klarnacdn.net *.klarnaservices.com *.avada.io *.shopify.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com connect.facebook.net graph.facebook.com business.facebook.com *.powerreviews.com *.newrelic.com js-agent.newrelic.com *.googletagmanager.com https://www.googletagmanager.com/gtm.js bat.bing.com *.google-analytics.com *.googleoptimize.com https://www.googleoptimize.com/optimize.js *.trustedsite.com *.cloudflare.com *.twitter.com *.fontawesome.com *.nr-data.net *.wahlclipper.com *.googleapis.com *.jsdelivr.net *.bluesnap.com *.webcollage.net *.syndigo.com *.adsrvr.org *.hotjar.com *.hotjar.io *.pcapredict.com *.postcodeanywhere.co.uk *.commerce-connector.com *.amazonaws.com/ */csp/report/uri/ *.redditstatic.com *.hs-scripts.com *.hscollectedforms.net *.hs-banner.com *.usemessages.com *.hs-analytics.net *.hsadspixel.net *.hsleadflows.net js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com maps.googleapis.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarnaevt.com *.amazon.com *.link.com www.clarity.ms cdn.cookielaw.org js.hubspot.com cdn.userway.org svht.tradedoubler.com swrap.tradedoubler.com *.wahl.com *.hsforms.net *.hsforms.com www.xtento.com cdn.xtento.com *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; img-src static.hsappstatic.net https://ad.doubleclick.net assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobedtm.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.afterpay.com/ *.afterpaycdn.com *.squarecdn.com *.cash.app *.gstatic.com *.googleapis.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.payments-amazon.com display.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com network-a.bazaarvoice.com network-stg-a.bazaarvoice.com photos-uat-us.bazaarvoice.com img.youtube.com *.google.com google.com sandbox.bluesnap.com sandbox1.bluesnap.com sandbox2.bluesnap.com sandpay.bluesnap.com ws.bluesnap.com ws1.bluesnap.com ws2.bluesnap.com pay.bluesnap.com *.klarna.com *.klarnaevt.com *.klarnacdn.net https://firebasestorage.googleapis.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.essentialaccessibility.com *.wahlanimal.com s.ytimg.com *.google.com.mx *.google-analytics.com ct.pinterest.com bat.bing.com *.google.co.in *.cloudflare.com *.wahlclipper.com *.powerreviews.com *.googletagmanager.com *.cloudfront.net *.webcollage.net *.syndigo.cloud *.postcodeanywhere.co.uk */csp/report/uri/ *.reddit.com *.hsforms.com *.hubspot.com *.google.com.in *.payments-amazon.com/ www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com maps.gstatic.com c.clarity.ms cdn.cookielaw.org cdn.userway.org *.wahl.com *.magecomp.com *.google.com.ua www.xtento.com cdn.xtento.com *.yotpo.com data: 'self' 'unsafe-inline'; default-src https://de.wahl.com https://fr.wahl.com https://nl.wahl.com https://eu.wahl.com https://es.wahl.com https://jp.mcprod.wahl.com *.wahl.com 'self' 'unsafe-inline' 'unsafe-eval'; report-uri https://csp-reporting-service.com/my-project/endpoint; report-to report-endpoint; 3 font-src *.googleapis.com *.gstatic.com data: *.bootstrapcdn.com *.cloudflare.com *.klarnacdn.net *.trustedshops.com *.twimg.com *.twitter.com *.typekit.net 'self' data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.adyen.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com *.twitter.com 'self' 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.adyen.com www.google.com *.awin1.com *.zenaps.com *.fls.doubleclick.net *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com account.fetchify.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.facebook.com *.pinterest.com *.trustpilot.com *.twitter.com *.snapwidget.com 'self' www.googletagmanager.com 'self' 'unsafe-inline'; img-src *.adobedtm.com *.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.adyen.com *.gstatic.com *.googleapis.com *.awin1.com *.zenaps.com *.wepowerconnections.com maps.gstatic.com *.trackedlink.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.bing.com *.clarity.ms *.cloudflare.com craftyclicks.co.uk *.demdex.net *.facebook.com fetchify.com *.goldboutique.com *.google-analytics.com *.google.co.uk *.google.com *.googleadservices.com *.googletagmanager.com *.klarna.com *.lightemporium.com *.magentocommerce.com *.pinterest.com *.elfsightcdn.com *.qpj.de *.qpj.fr *.qpjewellers.com *.rubyandoscar.com *.scarletocean.com *.twimg.com *.twitter.com *.usercentrics.eu *.wisepops.com *.ytimg.com *.roeye.com *.roeyecdn.com *.bailandstone.com *.roxoa.com 'self' https://*.google-analytics.com https://*.googletagmanager.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com *.vimeocdn.com www.vimeo.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.adyen.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.awin1.com *.dwin1.com *.zenaps.com *.wepowerconnections.com https://the.sciencebehindecommerce.com lantern.roeyecdn.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com player.vimeo.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.bing.com *.clickcease.com *.cloudflare.com cc-cdn.com *.facebook.net *.fontawesome.com *.getdrip.com *.google-analytics.com *.pcapredict.com *.pinimg.com *.pinterest.com *.plerdy.com *.taboola.com *.termly.io *.tiktok.com *.trustedshops.com *.trustpilot.com *.twimg.com *.twitter.com *.usercentrics.eu *.wisepops.net *.wisepops.com https://wisepops.net https://wisepops.com *.zdassets.com *.klarnaservices.com *.klarna.com *.clarity.ms https://snapwidget.com *.elfsight.com *.elfsightcdn.com *.roeyecdn.com *.qpjewellers.com/connector/ajax/emailcapture *.rubyandoscar.com/connector/ajax/emailcapture *.goldboutique.com/connector/ajax/emailcapture *.bailandstone.com/connector/ajax/emailcapture https://*.googletagmanager.com *.dotdigital.com 'self' *.googletagmanager.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com cc-cdn.com assets.braintreegateway.com *.bootstrapcdn.com *.cloudflare.com *.fontawesome.com *.googleapis.com *.gstatic.com *.klarnacdn.net *.trustedshops.com *.twimg.com *.twitter.com *.typekit.net *.usercentrics.eu *.zdassets.com 'self' *.trustpilot.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.zdassets.com 'self' 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adyen.com *.googleapis.com *.wepowerconnections.com https://the.sciencebehindecommerce.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com api.craftyclicks.co.uk pcls1.craftyclicks.co.uk *.slack.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.analytics.google.com *.bootstrapcdn.com *.bing.com *.clarity.ms *.cloudflare.com *.doubleclick.net *.facebook.com *.google-analytics.com https://google.com/pay *.googleadservices.com *.klarna.com *.klarnaservices.com *.klarnaevt.com *.paypalobjects.com *.pcapredict.com *.pinterest.com *.plerdy.com *.sandbox.paypal.com *.termly.io *.tiktok.com *.trustpilot.com https://invitejs.trustpilot.com *.twimg.com *.twitter.com *.vimeocdn.com *.wisepops.net *.wisepops.com https://wisepops.net https://wisepops.com *.zdassets.com *.zendesk.com *.zopim.com wss://widget-mediator.zopim.com *.sentry.io *.elfsight.com 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com *.googletagmanager.com 'self' 'unsafe-inline'; child-src *.awin1.com *.zenaps.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://csp.threatview.app/report; report-to report-endpoint; 3 script-src 'self' 'unsafe-inline' 'unsafe-eval' *.hatraco-shop.de; 3 font-src fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action 'self' 'unsafe-inline'; frame-ancestors *.multisafepay.com https://pay.google.com 'self'; frame-src https://www.google.com/recaptcha/ *.multisafepay.com https://pay.google.com js.mollie.com 'self' 'unsafe-inline'; img-src data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypalobjects.com *.multisafepay.com https://www.mollie.com data: 'self' 'unsafe-inline'; script-src www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypalobjects.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.multisafepay.com https://pay.google.com js.mollie.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com *.multisafepay.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com www.paypalobjects.com *.multisafepay.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://monitor.bigbridgedev.nl/csp; report-to report-endpoint; 3 report-uri /es/Error/ReportCPS; 3 font-src *.googleapis.com *.gstatic.com 'self' data: *.salesfire.co.uk *.typekit.net *.klarnacdn.net fonts.gstatic.com *.finance-calculator.co.uk *.s3.eu-west-2.amazonaws.com *.dekopay.org *.deko-uat.com *.blackhorseflexpay.co.uk *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.cloudflare.com *.myfonts.net *.bootstrapcdn.com *.electromarket.co.uk *.tawk.to *.cloudfront.net *.reviews.io *.reviews.co.uk *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnaevt.com *.link.com *.amazon.com *.twitter.com *.twimg.com *.trustedshops.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.reviews.io *.reviews.co.uk *.twitter.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.google.com *.salesfire.co.uk *.finance-calculator.co.uk *.deko.finance *.dekopay.org *.deko-uat.com *.blackhorseflexpay.co.uk https://*.doubleclick.net https://*.google.com https://*.hotjar.com *.klarna.com *.google-analytics.com *.gstatic.com *.google.com *.trustpilot.com *.reviews.io *.reviews.co.uk *.stripe.com klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.twitter.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.gstatic.com *.googleapis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.salesfire.co.uk *.finance-calculator.co.uk *.dekopay.com *.dekopay.org *.deko-uat.com s3.eu-west-1.amazonaws.com *.blackhorseflexpay.co.uk https://*.doubleclick.net https://*.google.com https://*.google.co.uk *.cloudfront.net *.klarnacdn.net *.klarnaevt.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://firebasestorage.googleapis.com *.cloudflare.com *.googleadservices.com *.google-analytics.com *.google.com *.google.co.uk *.paypal.com *.doubleclick.net *.electromarket.co.uk destiny-files.com *.bronto.com *.tawk.to *.jsdelivr.net *.postcodeanywhere.co.uk *.reviews.io *.reviews.co.uk *.klarna.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.facebook.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.googleapis.com *.gstatic.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.salesfire.co.uk *.finance-calculator.co.uk *.dekopay.com *.dekopay.org *.deko-uat.com dekowallet-feature-assets.s3.eu-west-2.amazonaws.com *.blackhorseflexpay.co.uk/ *.postcodeanywhere.co.uk https://www.googletagmanager.com https://www.google.com https://*.hotjar.com https://*.doubleclick.net https://secure.leadforensics.com https://*.googleapis.com *.klarna.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.avada.io *.shopify.com *.cloudflare.com *.google-analytics.com *.googletagmanager.com *.google.com *.fontawesome.com *.divido.com *.electromarket.co.uk *.tawk.to *.pcapredict.com *.doubleclick.net *.trustpilot.com *.bronto.com *.jsdelivr.net *.reviews.io *.reviews.co.uk *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarnaevt.com *.amazon.com *.link.com *.twitter.com *.twimg.com *.trustedshops.com *.usercentrics.eu tagmanager.google.com *.facebook.net unpkg.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.salesfire.co.uk *.typekit.net *.finance-calculator.co.uk *.dekopay.com *.dekopay.org *.deko-uat.com *.blackhorseflexpay.co.uk https://*.googleapis.com *.klarnacdn.net https://static.klaviyo.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.cloudflare.com *.googleapis.com *.gstatic.com *.myfonts.net *.electromarket.co.uk *.bootstrapcdn.com *.jsdelivr.net *.postcodeanywhere.co.uk *.cloudfront.net *.reviews.io *.reviews.co.uk *.stripe.network *.stripecdn.com *.amazon.com *.twitter.com *.twimg.com *.trustedshops.com *.usercentrics.eu tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.googleapis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.salesfire.co.uk *.smartmetrics.co.uk *.finance-calculator.co.uk *.dekopay.com *.dekopay.org *.deko-uat.com *.blackhorseflexpay.co.uk https://*.hotjar.com https://*.adobedc.net https://*.nr-data.net *.klarnaevt.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://get.geojs.io *.avada.io *.cloudflare.com *.paypal.com *.electromarket.co.uk *.tawk.to wss://*.tawk.to *.google.com *.google-analytics.com *.doubleclick.net *.postcodeanywhere.co.uk *.brontops.com *.cloudfront.net *.reviews.io *.reviews.co.uk *.stripe.com klarna.com *.klarna.com *.link.com *.amazon.com *.twitter.com *.twimg.com *.facebook.net https://www.google-analytics.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://db392d55-be7f-4975-a832-ea6573ed064e.sansec.watch/; report-to report-endpoint; 3 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com cdn.jsdelivr.net cdn.almapay.com *.klarnacdn.net *.fontawesome.com https://fonts.gstatic.com *.almapay.com *.cloudflare.com *.trustpilot.com *.avis-verifies.com *.bing.com *.sc.omtrdc.net 'self' data: https://cdnjs.cloudflare.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.nootidev.com admin.nootica.fr *.nootica.fr *.nootica.com *.nootica.es *.nootica.de *.nootica.it *.bandeja-shop.com 'self'; frame-src bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.getalma.eu *.almapay.com/ *.stripe.com/ *.checkout.com/ *.adyen.com/ www.google.com *.hipay-tpp.com *.hipay.com *.googleapis.com *.klarna.com *.demdex.net *.hub-side.com *.nootidev.com admin.nootica.fr *.nootica.fr *.nootica.com *.nootica.es *.nootica.de *.nootica.it *.bandeja-shop.com *.sc.omtrdc.net 'self' data: *.addthis.com *.trustpilot.com sibautomation.com *.doubleclick.net *.weltpixel.com *.googletagmanager.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.hipay.com *.googleapis.com *.klarna.com *.klarnaevt.com *.klarnacdn.net *.google.com maps.googleapis.com *.google.fr *.doubleclick.net *.googletagmanager.com *.cloudflare.com https://cdn.klarna.com https://s.ytimg.com *.usercentrics.eu *.avis-verifies.com *.bing.com *.omtrdc.net *.demdex.net *.everesttech.net flagcdn.com *.nootidev.com *.nootica.fr *.nootica.com *.nootica.es *.nootica.de *.nootica.it *.bandeja-shop.com *.facebook.com *.reddit.com *.google-analytics.com data: 'self' 'unsafe-inline'; script-src www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com *.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com cdn.jsdelivr.net www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.hipay-tpp.com mpsnare.iesnare.com *.paypal.com *.klarna.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com http://127.0.0.1:35729 *.cloudflare.com *.google-analytics.com *.doubleclick.net *.google.fr *.googleapis.com *.googletagmanager.com *.googleoptimize.com *.trustpilot.com *.avis-verifies.com *.usercentrics.eu *.bing.com *.iesnare.com *.hipay.com 'self' data: *.addthis.com *.addthisedge.com *.moatads.com *.freshworks.com sibautomation.com *.skeepers.io umami.nootica.fr https://cdnjs.cloudflare.com *.googleadservices.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com unpkg.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com cdn.jsdelivr.net *.hipay.com *.googleapis.com *.klarnacdn.net https://use.fontawesome.com https://fonts.googleapis.com *.cloudflare.com *.typekit.net *.trustpilot.com *.avis-verifies.com *.usercentrics.eu *.bing.com *.sc.omtrdc.net 'self' data: https://cdnjs.cloudflare.com *.tagmanager.google.com *.googletagmanager.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src data: mpsnare.iesnare.com *.googleapis.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.getalma.eu *.almapay.com *.hipay-tpp.com wss://mpsnare.iesnare.com *.googleapis.com *.klarnaevt.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.klarna.com https://olegnax.com *.google-analytics.com *.googlesyndication.com *.analytics.google.com *.doubleclick.net *.cloudflare.com *.bing.com *.demdex.net *.sc.omtrdc.net *.hipay.com 'self' data: ws: *.addthis.com *.brevo.com *.skeepers.io *.nootidev.com search.nootica.com search.bandeja-shop.com umami.nootica.fr *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.run.app 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 3 default-src 'unsafe-eval' 'unsafe-inline' blob: data: https: ws: wss:; img-src 'unsafe-inline' blob: data: *; report-uri https://csp.test.orlo.tech/report; 3 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.klevu.com *.ksearchnet.com *.fontawesome.com *.cloudflare.com *.googleapis.com *.zopim.com *.tawk.to *.jsdelivr.net media.flixfacts.com 'unsafe-inline' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com oppwa.com *.oppwa.com peachpayments.com *.peachpayments.com *.facebook.com webchat.jdg.co.za *.jdg.co.za 'self' 'unsafe-inline'; frame-ancestors *.hana.ondemand.com 'self'; frame-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com oppwa.com *.oppwa.com peachpayments.com *.peachpayments.com *.nosto.com *.issuu.com *.hotjar.com *.hotjar.io *.googletagmanager.com *.criteo.net *.criteo.com *.addthis.com *.facebook.com webchat.jdg.co.za *.jdg.co.za map.pargo.co.za 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com 'unsafe-inline' data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com https://widgets.payflex.co.za oppwa.com *.oppwa.com *.peachpayments.com *.eu-west-1.amazonaws.com *.cloudflare.com *.google.com *.google.lv *.google.co.za *.google.com.na *.google.na *.zopim.com *.nosto.com *.hotjar.com *.hotjar.io *.googletagmanager.com *.zopim.io *.sfdr.co sfdr.co *.tawk.to tawk.link *.tawk.link *.addthis.com *.jsdelivr.net *.facebook.com *.azurewebsites.net maps.googleapis.com app.mobicredwidget.co.za amcglobal.sc.omtrdc.net media.flixcar.com rt.flix360.com assets.secure.checkout.visa.com data: 'self' 'unsafe-inline'; script-src geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://browser.sentry-cdn.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com https://widgets.payflex.co.za https://partpayassets.blob.core.windows.net *.oppwa.com oppwa.com *.peachpayments.com worldtimeapi.org *.zopim.com *.videoly.co sfdr.co *.cnetcontent.com *.cloudfront.net *.newrelic.com *.google.lv *.google.co.za *.google.com.na *.google.na *.cloudflare.com *.cloudflareinsights.com *.nosto.com *.hotjar.com *.googletagmanager.com *.criteo.net *.criteo.com *.sfdr.co *.tawk.to *.tawk.link *.jsdelivr.net *.addthis.com *.addthisedge.com *.moatads.com *.mouseflow.com *.nr-data.net *.facebook.com *.what3words.com maps.googleapis.com commerce.adobedtm.com magento-recs-sdk.adobe.net static.zdassets.com app.mobicredwidget.co.za www.gstatic.com bam.nr-data.net js.testfreaks.com media.flixfacts.com media.flixcar.com security-hub.vaimo.network https://js.klevu.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com https://static.klaviyo.com *.klevu.com *.ksearchnet.com *.fontawesome.com oppwa.com *.oppwa.com *.peachpayments.com *.cloudflare.com *.googleapis.com *.jsdelivr.net www.gstatic.com media.flixcar.com 'unsafe-inline' data: https://statsjs.klevu.com https://js.klevu.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.zdassets.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://*.ingest.sentry.io https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com oppwa.com *.oppwa.com *.peachpayments.com *.testfreaks.com *.nosto.com *.hotjar.io *.hotjar.com *.doubleclick.net *.zendesk.com *.tawk.to wss://*.tawk.to *.tawk.link *.addthis.com *.addthisedge.com *.nr-data.net *.what3words.com *.googleapis.com vsb111.tawk.to ekr.zdassets.com api.magento.com commerce.adobedc.net app.mobicredwidget.co.za wss://widget-mediator.zopim.com bam.nr-data.net *.googletagmanager.com security-hub.vaimo.network 'unsafe-eval' data: 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 3 worker-src https://helmonline-hyva.dev.localhost helmonline.nl; font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://www.googletagmanager.com *.googleapis.com https://www.gstatic.com https://fonts.gstatic.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.paypal.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com player.vimeo.com *.braintreegateway.com *.paypal.com google.com *.google.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.google.com consentcdn.cookiebot.com td.doubleclick.net www.googletagmanager.com *.criteo.com/ www.xtento.com https://*.google.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com js.mollie.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io *.paypal.com *.typekit.net *.gstatic.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://images.unsplash.com *.pon.bike images.pondigital.solutions *.google.nl *.google.com *.google.fr *.mailplus.nl imgsct.cookiebot.com *.bing.net *.bing.com pagead2.googlesyndication.com www.xtento.com cdn.xtento.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.googleusercontent.com magefan.com cm.magefan.com *.disqus.com https://img.youtube.com https://www.mollie.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com commerce-payments-sdk.adobe.io s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com connect.facebook.net graph.facebook.com business.facebook.com tagmanager.google.com https://www.googletagmanager.com https://maps.googleapis.com https://player.vimeo.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ www.facebook.com chimpstatic.com rum-static.pingdom.net rum-collector-2.pingdom.net consentcdn.cookiebot.com consent.cookiebot.com widget.thuiswinkel.org widget.thuiswinkel-cdn.org *.clarity.ms restapi.mailplus.nl www.googleoptimize.com googletagmanager.com *.googletagmanager.com *.bing.com *.criteo.com static.criteo.net *.mouseflow.com *.tiktok.com *.hotjar.com *.beslist.nl static.cloudflareinsights.com cdn.debugbear.com pagead2.googlesyndication.com static.widget.trengo.eu www.xtento.com cdn.xtento.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com *.disqus.com js.mollie.com https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://www.googletagmanager.com tagmanager.google.com *.googleapis.com *.typekit.net downloads.mailchimp.com https://fonts.googleapis.com https://hcaptcha.com https://*.hcaptcha.com *.fontawesome.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.widget.trengo.eu 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://www.google-analytics.com https://*.google-analytics.com https://*.analytics.google.com https://maps.googleapis.com https://player.vimeo.com devdocs.magento.com rum-collector-2.pingdom.net widgetcontent.thuiswinkel-cdn.org www.google.com *.clarity.ms consent.cookiebot.com consentcdn.cookiebot.com doubleclick.net *.bing.com *.criteo.com *.tiktok.com *.hotjar.com *.hotjar.io *.beslist.nl data.debugbear.com pagead2.googlesyndication.com api.widget.trengo.eu form-assets.mailchimp.com *.intuit.com *.amazonaws.com https://ipinfo.io https://*.google.com https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 3 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com cash-f.squarecdn.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com https://geowidget.easypack24.net 'self' data: https://widgets.trustedshops.com *.livechatinc.com https://td.doubleclick.net data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com * www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com *.braintreegateway.com *.paypal.com google.com *.google.com * www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.packeta.com secure.payu.com merch-prod.snd.payu.com https://geowidget-app.inpost.pl/ https://sandbox-easy-geowidget.easypack24.net/ *.weltpixel.com *.googletagmanager.com *.doubleclick.net *.livechatinc.com https://consentcdn.cookiebot.com/ api.ratingcaptain.com *.cookiebot.eu 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io * www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com magefan.com cm.magefan.com *.disqus.com https://firebasestorage.googleapis.com https://www.magezon.com static.payu.com https://geowidget.easypack24.net *.easypack24.net *.inpost.pl *.openstreetmap.org *.hsforms.net *.hsforms.com 'self' data: https://maps.googleapis.com/ https://maps.gstatic.com/ https://developers.google.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com *.etrusted.com *.facebook.com *.reddit.com *.ads-twitter.com t.co *.twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.google-analytics.com *.googletagmanager.com *.doubleclick.net *.google.com https://www.google.pl *.seznam.cz *.pricemania.sk https://imgsct.cookiebot.com data: 'self' 'unsafe-inline'; script-src www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com *.cash.app *.visa.com *.mastercard.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://scripts.luigisbox.tech https://cdn.luigisbox.tech https://live.luigisbox.tech https://api.luigisbox.tech *.disqus.com *.avada.io *.shopify.com *.packeta.com secure.payu.com secure.snd.payu.com https://geowidget.easypack24.net *.easypack24.net *.inpost.pl *.openstreetmap.org *.hsforms.net *.hsforms.com *.gstatic.com https://maps.googleapis.com/ https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.etrusted.com *.googletagmanager.com *.googleadservices.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.bing.com *.clarity.ms *.klaviyo.com unpkg.com *.doubleclick.net *.livechatinc.com https://www.googletagmanager.com *.seznam.cz https://pixel.biano.cz https://consent.cookiebot.com *.biano.sk *.biano.cz *.biano.ro https://consentcdn.cookiebot.com https://api.ratingcaptain.com *.absulo.ro *.sgtm.absulo.ro *.cookiebot.eu 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com *.cash.app https://scripts.luigisbox.tech https://cdn.luigisbox.tech https://live.luigisbox.tech https://api.luigisbox.tech *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.googleapis.com https://geowidget.easypack24.net https://geowidget.inpost.pl *.gstatic.com https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.etrusted.com *.tagmanager.google.com *.googletagmanager.com *.pricemania.sk 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://geowidget.easypack24.net *.livechatinc.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com *.adobe.io performance.typekit.net *.sentry.io www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com * www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://scripts.luigisbox.tech https://cdn.luigisbox.tech https://live.luigisbox.tech https://api.luigisbox.tech https://get.geojs.io *.avada.io *.packeta.com secure.payu.com merch-prod.snd.payu.com *.easypack24.net *.inpost.pl *.openstreetmap.org t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com https://maps.googleapis.com/ *.trustedshops.com *.etrusted.com https://integrations.etrusted.site *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.doubleclick.net *.run.app http://www.google-analytics.com *.livechatinc.com *.googlesyndication.com *.biano.cz *.biano.sk *.biano.ro https://consentcdn.cookiebot.com googleads.g.doubleclick.net api.ratingcaptain.com *.cookiebot.eu 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 3 font-src fonts.gstatic.com use.typekit.net *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.globalpay.com https://fonts.gstatic.com *.fontawesome.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com *.gpwebpay.com *.gpe.cz *.globalpay-ecommerce.com *.nosto.com *.nos.to 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.google.com *.doubleclick.net *.facebook.com *.americanexpress.com *.globalpay.com *.mastercard.com *.visa.com *.gpwebpay.com *.gpe.cz *.globalpay-ecommerce.com *.nosto.com *.nos.to *.trustpilot.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.gstatic.com www.feedoptimise.com cdn.feedoptimise.com *.globalpay.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.nosto.com *.nos.to *.googleapis.com data: 'self' 'unsafe-inline'; script-src unpkg.com commerce.adobedtm.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com assets.adobedtm.com amcglobal.sc.omtrdc.net commerce.adobe.net use.typekit.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com jquery.sellxed.com www.feedoptimise.com cdn.feedoptimise.com *.aexp-static.com https://ajax.aspnetcdn.com *.globalpay.com *.gpapiservices.com https://pay.google.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.nosto.com *.nos.to *.trustpilot.com *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com https://fonts.googleapis.com https://static.klaviyo.com *.fontawesome.com maxcdn.bootstrapcdn.com *.nosto.com *.nos.to *.trustpilot.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src api.magento.com commerce.adobe.io commerce.adobedtm.com commerce.adobedc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.net qa-api.magedevteam.com *.google-analytics.com *.facebook.com *.facebook.net *.google.com https://google.com/pay https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.nosto.com *.nos.to *.googleapis.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 3 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com https://play-widget.pepperfinance.es/ https://instantcredit.net/ *.googleapis.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.yotpo.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors https://instantcredit.net/ *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.braintreegateway.com *.paypal.com google.com *.google.com *.awin1.com *.zenaps.com *.fls.doubleclick.net 'self' https://*.uberall.com https://instantcredit.net/ *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com js.mollie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.yotpo.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.awin1.com *.zenaps.com *.wepowerconnections.com cdn.doofinder.com https://images.unsplash.com https://cdn.scarabresearch.com https://static.scarabresearch.com https://snippet.plugins.emarsys.net https://*.uberall.com * *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://www.mollie.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.yotpo.com data: 'self' 'unsafe-inline'; script-src geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.awin1.com *.dwin1.com *.zenaps.com *.wepowerconnections.com https://the.sciencebehindecommerce.com lantern.roeyecdn.com cdn.doofinder.com *.plugins.emarsys.net https://cdn.scarabresearch.com https://maps.googleapis.com https://snippet.plugins.emarsys.net https://static.scarabresearch.com https://locator.uberall.com https://*.uberall.com https://instantcredit.net/ https://code.jquery.com/ * *.fontawesome.com *.googleapis.com *.gstatic.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com js.mollie.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com *.fontawesome.com *.doofinder.com https://play-widget.pepperfinance.es/ https://instantcredit.net/ *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com unsafe-inline assets.braintreegateway.com *.stripe.network *.stripecdn.com *.amazon.com *.yotpo.com *.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.wepowerconnections.com https://the.sciencebehindecommerce.com *.doofinder.com wss://*.doofinder.com https://recommender.scarabresearch.com *.eservice.emarsys.net https://play-merchant-config.pepperfinance.es/ https://play-api.peppermoneytest.es/ https://maps.googleapis.com https://player.vimeo.com https://cdn.scarabresearch.com https://snippet.plugins.emarsys.net https://*.uberall.com https://instantcredit.net/ https://test.instantcredit.net/ *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://frontal-eu.oct8ne.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.yotpo.com 'self' 'unsafe-inline'; child-src *.awin1.com *.zenaps.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src https://api.itau.com.br/ https://api.itau.com.br:443/ https://sts.itau.com.br/ https://sts.itau.com.br:443/ https://secure.api.itau/ https://secure.api.itau:443/ https://apisandbox.redeecommerce.rede.com.br/ https://apiquerysandbox.redeecommerce.rede.com.br/ https://api.redeecommerce.rede.com.br/ https://apiquery.redeecommerce.rede.com.br/ 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 3 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://www.googletagmanager.com *.googleapis.com *.bootstrapcdn.com *.cloudflare.com 'self' data: *.hotjar.com *.hotjar.io data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * www.facebook.com 'self' connect.facebook.net graph.facebook.com business.facebook.com test.saferpay.com www.saferpay.com saferpay.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.doubleclick.net *.googlesyndication.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com test.saferpay.com www.saferpay.com saferpay.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com 'self' data: *.googleapis.com *.openstreetmap.org *.googlesyndication.com *.google.com *.google.rs *.google.hr *.google.ba *.google.si *.google.bg *.google.me *.google.mk *.google.nl *.google.de *.google.be *.google.fr *.googleadservices.com www.facebook.com trengo.s3.eu-central-1.amazonaws.com ecom-stage.iutecredit.mk ecom.iutecredit.mk ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com magefan.com cm.magefan.com *.disqus.com connect.facebook.net graph.facebook.com business.facebook.com *.cmi.co.ma yandex.com yandex.md *.yandex.md *.yandex.com yandex.ru *.yandex.ru *.yads.tech yads.tech *.yango.com *.doubleclick.net t.adx.opera.com test.saferpay.com www.saferpay.com saferpay.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com commerce-payments-sdk.adobe.io www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com songbird.cardinalcommerce.com tagmanager.google.com https://www.googletagmanager.com *.googleapis.com *.gstatic.com https://widget-cdn.boxnow.hr *.googlesyndication.com *.googleadservices.com *.google.com *.google.rs *.google.hr *.google.ba *.google.si *.google.bg *.google.me *.google.mk www.facebook.com *.widget.trengo.eu map.gls-croatia.com map.gls-czech.com map.gls-hungary.com map.gls-romania.com map.gls-slovenia.com map.gls-slovakia.com map.gls-serbia.com *.openstreetmap.org ecom-stage.iutecredit.mk ecom.iutecredit.mk chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com *.disqus.com connect.facebook.net graph.facebook.com business.facebook.com *.hotjar.com *.hotjar.io onesignal.com *.onesignal.com *.criteo.com *.adsmurai.com gateway.bankart.si yandex.com yandex.md *.yandex.md *.yandex.com yandex.ru *.yandex.ru *.yads.tech yads.tech *.yango.com *.doubleclick.net t.adx.opera.com test.saferpay.com www.saferpay.com saferpay.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com assets.braintreegateway.com https://www.googletagmanager.com tagmanager.google.com *.googleapis.com *.bootstrapcdn.com ecom-stage.iutecredit.mk ecom.iutecredit.mk downloads.mailchimp.com onesignal.com *.onesignal.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com static.widget.trengo.eu 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com https://www.google-analytics.com https://*.google-analytics.com https://*.analytics.google.com *.googleapis.com https://widget-cdn.boxnow.hr *.google.com *.google.rs *.google.hr *.google.ba *.google.si *.google.bg *.google.me *.google.mk *.google.nl *.google.de *.google.be *.google.fr *.googlesyndication.com *.doubleclick.net www.facebook.com *.trengo.eu map.gls-croatia.com map.gls-czech.com map.gls-hungary.com map.gls-romania.com map.gls-slovenia.com map.gls-slovakia.com map.gls-serbia.com *.openstreetmap.org ecom-stage.iutecredit.mk ecom.iutecredit.mk form-assets.mailchimp.com *.intuit.com *.amazonaws.com connect.facebook.net graph.facebook.com business.facebook.com wss://ws.hotjar.com *.hotjar.io yandex.com *.yandex.md *.yandex.com yandex.ru *.yandex.ru *.yads.tech *.yango.com cm.g.doubleclick.net t.adx.opera.com test.saferpay.com www.saferpay.com saferpay.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src yandex.com yandex.md *.yandex.md *.yandex.com yandex.ru *.yandex.ru *.yads.tech yads.tech *.yango.com *.doubleclick.net t.adx.opera.com test.saferpay.com www.saferpay.com saferpay.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 3 report-to sprd-report-only; frame-ancestors 'none'; 3 frame-ancestors 'self' *.volusion.com;default-src 'none' 3 default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com https://www.google-analytics.com https://www.google.com https://maps.googleapis.com https://maps.google.com https://googleads.g.doubleclick.net https://www.gstatic.com https://consent.cookiebot.com https://consentcdn.cookiebot.eu https://consent.cookiebot.eu https://bat.bing.com https://js-eu1.hs-scripts.com https://js-eu1.hscollectedforms.net https://js-eu1.hs-banner.com https://js-eu1.hubspot.com https://js-eu1.hsadspixel.net https://js-eu1.hs-analytics.net https://js-eu1.usemessages.com https://extend.vimeocdn.com https://connect.facebook.net https://snap.licdn.com https://bsqd.me; connect-src 'self' https://region1.google-analytics.com https://www.google-analytics.com https://www.google.com https://www.google.com/ccm https://maps.googleapis.com https://googleads.g.doubleclick.net https://bat.bing.com https://api-eu1.hubspot.com https://api-eu1.hubapi.com https://cta-eu1.hubspot.com https://track-eu1.hubspot.com https://consent.cookiebot.com https://consentcdn.cookiebot.eu https://js-eu1.hs-analytics.net https://px.ads.linkedin.com https://bsqd.me wss://bsqd.me; img-src 'self' data: https://www.google.com https://www.google.nl https://maps.gstatic.com https://maps.google.com https://www.gstatic.com https://www.googleadservices.com https://googleads.g.doubleclick.net https://bat.bing.com https://track-eu1.hubspot.com https://perf-eu1.hsforms.com https://img.sct.eu1.usercentrics.eu https://px.ads.linkedin.com https://www.googletagmanager.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; font-src 'self' https://fonts.gstatic.com data:; frame-src 'self' https://www.google.com https://www.googletagmanager.com https://consentcdn.cookiebot.eu https://player.vimeo.com https://www.youtube.com https://connect.facebook.net; 3 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com data: 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.cloudflare.com *.twitter.com *.twimg.com *.trustedshops.com *.fontawesome.com https://fonts.bunny.net *.google.com *.google.nl *.google.at *.google.de *.google.be *.google.it *.google.fr *.dhlparcel.nl *.klaviyo.com *.bing.com *.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com *.googlesyndication.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.twitter.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.cookiebot.eu *.youtube.com/ js.mollie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.google.nl *.google.at *.google.de *.google.be *.google.fr *.google.it www.googletagmanager.com *.trustpilot.com *.pinterest.com *.criteo.com *.criteo.net *.cookiebot.com https://squeezely.tech *.sendcloud.sc *.jsdelivr.net www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.googleapis.com *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.googlesyndication.com *.roeye.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://at19.net https://bdt9.net https://ds1.nl https://dt51.net https://dt61.net https://fr135.net https://glp8.net https://jdt8.net https://jf79.net https://hs82.net https://lt45.net https://mt74.net https://ndt5.net https://rkn3.net *.lutz.nl *.lutzfashion.com *.cloudflare.com *.klarna.com *.googleadservices.com *.google-analytics.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu https://firebasestorage.googleapis.com https://www.mollie.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: *.mailcampaigns.nl/ *.linkedin.com *.pinterest.com *.google.com.ua *.google.de *.google.nl *.google.at *.google.be *.google.fr *.google.it *.yahoo.com *.webwinkelkeur.nl *.cookiebot.com *.criteo.com *.criteo.net *.bing.com *.jmango360.com *.amazonaws.com ssl.gstatic.com www.gstatic.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com *.vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googlesyndication.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.lutz.nl *.lutzfashion.com *.getdrip.com *.tweakwise.com *.cookiebot.eu *.cloudflare.com *.twitter.com *.twimg.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.trackedlink.net *.avada.io js.mollie.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.google.nl *.google.at *.google.de *.google.be *.google.it *.google.fr chimpstatic.com *.criteo.net *.robinhq.com *.mailcampaigns.nl *.cloudflareinsights.com *.hotjar.com *.trustpilot.com *.dhlparcel.nl *.criteo.com *.cookiebot.com *.bing.com *.msecnd.net *.pinterest.com *.clarity.ms *.pinimg.com *.licdn.com *.sooqr.com https://squeezely.tech *.billygrace.com *.sendcloud.sc *.jsdelivr.net *.googletagmanager.com tagmanager.google.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com *.cloudflare.com *.twitter.com *.twimg.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.fontawesome.com https://fonts.bunny.net assets.braintreegateway.com *.mailcampaigns.nl *.google.com *.google.nl *.google.at *.google.de *.google.be *.google.it *.google.fr *.dhlparcel.nl *.klaviyo.com *.bing.com *.sooqr.com https://unpkg.com *.bootstrapcdn.com *.sendcloud.sc *.jsdelivr.net tagmanager.google.com fonts.google.com *.trustpilot.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.google.com *.google.nl *.google.at *.google.de *.google.be *.google.it *.google.fr 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.googleapis.com *.google-analytics.com *.facebook.com *.facebook.net *.doubleclick.net *.googlesyndication.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.lutz.nl *.lutzfashion.com *.tweakwise.com *.cloudflare.com *.twitter.com *.twimg.com *.googleadservices.com *.sandbox.paypal.com *.paypalobjects.com *.trackedlink.net *.ampproject.org https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.mailcampaigns.nl *.visualstudio.com *.pinterest.com *.google.nl *.google.at *.google.de *.google.be *.google.it *.google.fr *.bing.com *.linkedin.com *.hotjar.com *.hotjar.io *.trustpilot.com *.googletagmanager.com wss://ws.hotjar.com/ *.criteo.com *.criteo.net *.cookiebot.com *.clarity.ms *.amazonaws.com https://squeezely.tech *.jsdelivr.net *.billypx.com *.sendcloud.sc *.cdn.jsdelivr.net *.mapbox.com *.analytics.google.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 3 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com cash-f.squarecdn.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com * *.cleverreach.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src bid.g.doubleclick.net *.demdex.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com * *.trustpilot.com https://www.googletagmanager.com/ 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.everesttech.net *.demdex.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net * https://images.unsplash.com *.cloudfront.net http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ magefan.com cm.magefan.com data: 'self' 'unsafe-inline'; script-src googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.adobedtm.com *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net assets.adobedtm.com *.adobe.io *.commerce-payment-services.com *.magento-ds.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.magento-datasolutions.com *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com *.cash.app *.visa.com *.mastercard.com https://maps.googleapis.com *.trustpilot.com *.googleapis.com *.gstatic.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.magento-datasolutions.com *.magento-ds.com *.cash.app *.trustpilot.com https://static.klaviyo.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; connect-src www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io amcglobal.sc.omtrdc.net p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.magento-datasolutions.com *.magento-ds.com * https://maps.googleapis.com https://player.vimeo.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://66998dd5-b8bd-4cd3-98ce-5f467499faec.sansec.watch/; report-to report-endpoint; 3 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.cloudfront.net *.bootstrapcdn.com maxcdn.bootstrapcdn.com 'self' data: d1tz4u8bvomi43.cloudfront.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com d1tz4u8bvomi43.cloudfront.net *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com https://www.googletagmanager.com/ *.facebook.com secure.pay1.de payments.amazon.de jsctool.com www.jsctool.com js.playground.klarna.com *.usercentrics.eu www.xtento.com d1tz4u8bvomi43.cloudfront.net 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ *.cdninstagram.com maps.googleapis.com *.1rx.io *.3lift.com *.360yield.com *.adform.net *.adnxs.com *.adtriba.com *.amazonaws.com *.bidswitch.net *.bing.com *.casalemedia.com *.criteo.com *.demdex.net *.doubleclick.net *.emxdgt.com *.facebook.com id5-sync.com *.ivitrack.com *.juneapp.com *.media.net *.mediavine.com *.omnitagjs.com *.outbrain.com *.postrelease.com *.pubmatic.com *.roeye.com *.rubiconproject.com *.sharethrough.com *.smartadserver.com *.snapchat.com squarelovin.com *.squarelovin.com *.taboola.com *.teads.tv *.tremorhub.com *.unrulymedia.com *.usercentrics.eu *.yieldlab.net *.yieldmo.com flagpedia.net cdn.pay1.de x.klarnacdn.net *.cloudfront.net m.media-amazon.com static-eu.payments-amazon.com *.trustedshops.com *.hsforms.net *.hsforms.com 'self' data: www.xtento.com cdn.xtento.com d1tz4u8bvomi43.cloudfront.net *.google.de *.google.pl *.google.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.googleapis.com *.dynamicyield.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ http://www.googletagmanager.com/ https://www.googletagmanager.com/ player.vimeo.com connect.facebook.net cdnjs.cloudflare.com maps.googleapis.com *.adtriba.com dwin1.com *.bing.com clarity.ms *.cloudflareinsights.com *.cloudfront.net *.criteo.com *.doubleclick.net *.facebook.net *.pinimg.com *.pinterest.com *.roeyecdn.com *.sc-static.net *.snapchat.com squarelovin.com *.squarelovin.com *.survicate.com *.usercentrics.eu *.getzowie.com *.eyefitu.com *.gstatic.com secure.pay1.de d.ratepay.com static-eu.payments-amazon.com x.klarnacdn.net cdn.klarna.com jsctool.com d.payla.io *.trustedshops.com *.hsforms.net *.hsforms.com www.xtento.com cdn.xtento.com d1tz4u8bvomi43.cloudfront.net *.brevo.com sibautomation.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://static.klaviyo.com squarelovin.com *.squarelovin.com *.cloudfront.net *.bootstrapcdn.com *.googleapis.com *.adtriba.com maxcdn.bootstrapcdn.com *.gstatic.com d.ratepay.com d.payla.io dr.payla.io d1tz4u8bvomi43.cloudfront.net 'self' 'unsafe-inline'; object-src d1tz4u8bvomi43.cloudfront.net 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ *.cloudfront.net d1tz4u8bvomi43.cloudfront.net 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.googleapis.com *.dynamicyield.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ maps.googleapis.com *.amazonaws.com *.cloudfront.net *.squarelovin.com *.usercentrics.eu www.gstatic.com payments.amazon.de payments-eu.amazon.com d.ratepay.com jsctool.com eu.playground.klarnaevt.com t.elasticsuite.io *.hsforms.net *.hsforms.com d1tz4u8bvomi43.cloudfront.net region1.analytics.google.com *.brevo.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com d1tz4u8bvomi43.cloudfront.net 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 3 default-src 'self'; script-src 'self' https://www.googletagmanager.com https://www.google-analytics.com https://www.gstatic.com https://www.google.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://fonts.gstatic.com; img-src 'self' data: https://www.google.com https://www.gstatic.com https://secure.gravatar.com; font-src 'self' data: https://fonts.gstatic.com; connect-src 'self' https://www.google-analytics.com https://stats.g.doubleclick.net; frame-src 'self' https://www.google.com https://maps.google.com https://www.youtube.com; worker-src 'self' blob:; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'; report-uri https://www.tisda.nl/csp-report.php; 3 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com data: *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com www.googletagmanager.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.googleapis.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com magefan.com cm.magefan.com https://firebasestorage.googleapis.com https://www.magezon.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.google.com *.googleadservices.com *.google-analytics.com *.googletagmanager.com flagpedia.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.avada.io *.shopify.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.googletagmanager.com *.googleadservices.com *.google-analytics.com maps.googleapis.com www.gstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com https://fonts.bunny.net *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com maxcdn.bootstrapcdn.com *.gstatic.com www.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.googleapis.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://get.geojs.io *.avada.io *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com stats.g.doubleclick.net www.gstatic.com maps.googleapis.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://def9d71d-669f-4322-8f25-4ef099a2d33a.sansec.watch/; report-to report-endpoint; 3 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com cash-f.squarecdn.com *.fontawesome.com https://widgets.trustedshops.com https://integrations.etrusted.com typesense.c-833.maxcluster.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com * typesense.c-833.maxcluster.net 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com * https://cdn.consentmanager.net https://delivery.consentmanager.net *.trustpilot.com *.weltpixel.com typesense.c-833.maxcluster.net 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io * https://cdn.consentmanager.net https://delivery.consentmanager.net https://images.unsplash.com https://redchamps.com *.googletagmanager.com ssl.gstatic.com www.gstatic.com https://widgets.trustedshops.com https://integrations.etrusted.com maps.googleapis.com *.amazonaws.com typesense.c-833.maxcluster.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com *.cash.app *.visa.com *.mastercard.com applepay.cdn-apple.com https://cdn.consentmanager.net https://delivery.consentmanager.net https://maps.googleapis.com *.googletagmanager.com tagmanager.google.com *.trustpilot.com https://widgets.trustedshops.com https://integrations.etrusted.com maps.googleapis.com typesense.c-833.maxcluster.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.cash.app *.fontawesome.com tagmanager.google.com fonts.google.com *.trustpilot.com https://widgets.trustedshops.com https://integrations.etrusted.com typesense.c-833.maxcluster.net 'self' 'unsafe-inline'; object-src https://cdn.consentmanager.net https://delivery.consentmanager.net typesense.c-833.maxcluster.net 'self' 'unsafe-inline'; media-src *.adobe.com https://cdn.consentmanager.net https://delivery.consentmanager.net typesense.c-833.maxcluster.net 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com * https://cdn.consentmanager.net https://delivery.consentmanager.net https://maps.googleapis.com https://player.vimeo.com *.googletagmanager.com *.trustedshops.com *.etrusted.com typesense.c-833.maxcluster.net 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src https://cdn.consentmanager.net https://delivery.consentmanager.net typesense.c-833.maxcluster.net 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://667b8714-1464-4a69-9685-942a89db4a14.sansec.watch/; report-to report-endpoint; 3 default-src 'self'; img-src * 3 default-src 'self'; script-src 'self' 'unsafe-eval' *.osha.europa.eu www.gstatic.com www.google.com cdn.jsdelivr.net europa.eu platform.twitter.com www.youtube.com cdnjs.cloudflare.com webtools.europa.eu translate.googleapis.com translate-pa.googleapis.com static.addtoany.com; style-src 'self' 'unsafe-inline' www.gstatic.com europa.eu webtools.europa.eu fonts.googleapis.com; img-src 'self' *.osha.europa.eu abs.twimg.com pbs.twimg.com europa.eu syndication.twitter.com webtools.europa.eu *.google.com *.gstatic.com i.ytimg.com; connect-src 'self' translate.googleapis.com translate-pa.googleapis.com webtools.europa.eu europa.eu piwik.osha.europa.eu www.google.com; frame-src 'self' platform.twitter.com www.google.com syndication.twitter.com www.youtube.com www.youtube-nocookie.com euosha.gestmax.eu; worker-src 'none'; font-src 'self' fonts.gstatic.com cdnjs.cloudflare.com themes.googleusercontent.com use.typekit.net; report-uri https://stat.alberora.eu/stat/CSP.php; 3 font-src *.googleapis.com *.gstatic.com data: *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.reachout.global pos-kowzef.reachout.global 'self' 'unsafe-inline'; frame-ancestors *.bolt.com www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.bolt.com https://www.google.com/recaptcha/ www.googletagmanager.com www.google.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://static.addtoany.com/ *.doubleclick.net/ *.addthis.com *.doubleclick.com *.mercadolibre.com *.mercadolivre.com *.mlstatic.com *.mercadopago.com *.mercadopago.com.ar *.mercadopago.cl *.mercadopago.com.co *.mercadopago.com.br *.mercadopago.com.mx *.mercadopago.com.uy *.mercadopago.com.ve *.mercadopago.com.pe 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.gstatic.com *.googleapis.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.adobedtm.com *.afip.gob.ar *.cloudfront.net https://player.vimeo.com *.clarity.ms *.google.com.co *.bing.com *.kosiuko.com *.facebook.com *.metricool.com *.google.com.ar *.google.com *.mercadolibre.com *.mercadolivre.com *.mlstatic.com *.mercadopago.com *.mercadopago.com.ar *.mercadopago.cl *.mercadopago.com.co *.mercadopago.com.br *.mercadopago.com.mx *.mercadopago.com.uy *.mercadopago.com.ve *.mercadopago.com.pe data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.bolt.com *.commerce-quick-checkout.com http://localhost:8082 https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://maps.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.addtoany.com *.cloudfront.net *.doubleclick.net *.vimeo.com https://f.vimeocdn.com https://player.vimeo.com *.clarity.ms *.tiktok.com *.aptrinsic.com *.facebook.net *.facebook.com *.googleapis.com *.googletagmanager.com track-icommkt.com *.icommarketing.com *.reachout.global *.mercadolibre.com *.mercadolivre.com *.mlstatic.com *.mercadopago.com *.mercadopago.com.ar *.mercadopago.cl *.mercadopago.com.co *.mercadopago.com.br *.mercadopago.com.mx *.mercadopago.com.uy *.mercadopago.com.ve *.mercadopago.com.pe 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.fontawesome.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.bolt.com *.googleapis.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.doubleclick.net *.vimeo.com https://vimeo.com *.vimeocdn.com https://f.vimeocdn.com *.clarity.ms *.google.com *.tiktok.com *.facebook.net *.facebook.com *.googletagmanager.com track-icommkt.com *.notifications-icommkt.com https://notifications-icommkt.com pos-kowzef.reachout.global *.reachout.global *.mercadolibre.com *.mercadolivre.com *.mlstatic.com *.mercadopago.com *.mercadopago.com.ar *.mercadopago.cl *.mercadopago.com.co *.mercadopago.com.br *.mercadopago.com.mx *.mercadopago.com.uy *.mercadopago.com.ve *.mercadopago.com.pe 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.aptrinsic.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 3 font-src https://www.googletagmanager.com *.googleapis.com *.gstatic.com https://use.typekit.net https://geowidget.easypack24.net *.fontawesome.com fonts.gstatic.com webetech.pl webep1.com *.inpost.pl fonts.googleapis.com https://fonts.bunny.net *.gls.com *.szybkapaczka.pl *.gls-poland.com/ data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com *.facebook.net sandbox.przelewy24.pl secure.przelewy24.pl 'self' 'unsafe-inline'; frame-ancestors pay.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ https://www.googletagmanager.com https://td.doubleclick.net https://cookie.inpost.pl https://geowidget-app.inpost.pl/ https://sandbox-easy-geowidget.easypack24.net/ *.facebook.com *.facebook.net pay.google.com apm.przelewy24.pl webetech.pl webep1.com *.inpost.pl *.szybkapaczka.pl *.gls-poland.com/ 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.gstatic.com https://ekipatonosi.pl https://indeste.pl https://genzie.store https://influcenter.pl https://krakowkings.store https://hi-store.pl https://sklepbazy.pl https://sklepfazy.pl https://static.paynow.pl *.cloudfront.net https://player.vimeo.com https://www.google.pl https://www.facebook.com https://geowidget.easypack24.net *.easypack24.net *.inpost.pl *.openstreetmap.org *.facebook.com *.facebook.net static.przelewy24.pl www.gstatic.com gstatic.com track.webepartners.pl https://firebasestorage.googleapis.com https://api.mapbox.com *.szybkapaczka.pl *.gls-poland.com/ *.gls-poland.com.pl/ data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com https://player.vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ tagmanager.google.com https://www.googletagmanager.com https://ekipatonosi.pl https://indeste.pl https://genzie.store https://influcenter.pl https://krakowkings.store https://hi-store.pl https://sklepbazy.pl https://sklepfazy.pl https://static.paynow.pl https://developer.gls-poland.com https://geowidget.easypack24.net *.easypack24.net *.inpost.pl *.openstreetmap.org *.facebook.com *.facebook.net sandbox.przelewy24.pl secure.przelewy24.pl pay.google.com apm.przelewy24.pl webetech.pl webep1.com *.avada.io *.shopify.com *.szybkapaczka.pl *.gls-poland.com/ sandbox-global-geowidget-sdk.easypack24.net geowidget.inpost-group.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://www.googletagmanager.com tagmanager.google.com *.googleapis.com https://developer.gls-poland.com https://use.typekit.net https://geowidget.easypack24.net https://geowidget.inpost.pl *.fontawesome.com fonts.googleapis.com webetech.pl webep1.com *.inpost.pl https://fonts.bunny.net *.szybkapaczka.pl *.gls-poland.com/ sandbox-global-geowidget-sdk.easypack24.net geowidget.inpost-group.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com https://geowidget.easypack24.net *.szybkapaczka.pl *.gls-poland.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://www.google-analytics.com https://*.google-analytics.com https://*.analytics.google.com *.easypack24.net *.inpost.pl *.openstreetmap.org *.facebook.com *.facebook.net sandbox.przelewy24.pl secure.przelewy24.pl wss://sandbox-ws.przelewy24.pl wss://secure-ws.przelewy24.pl apple-pay-gateway.apple.com apm.przelewy24.pl google.com www.google.com pay.google.com webetech.pl webep1.com https://get.geojs.io *.avada.io *.szybkapaczka.pl *.gls-poland.com/ 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 3 font-src 'self' www.mozilla.org; form-action 'self' https://abdri3ttkb.execute-api.us-east-2.amazonaws.com https://accounts.firefox.com/ https://basket.mozilla.org; frame-ancestors 'none'; frame-src 'self' accounts.firefox.com js.stripe.com www.google-analytics.com www.googletagmanager.com www.youtube.com; base-uri 'none'; style-src 'self' 'unsafe-inline' cdn.transcend.io transcend-cdn.com www.mozilla.org; upgrade-insecure-requests; script-src 'self' 'unsafe-eval' 'unsafe-inline' cdn.transcend.io js.stripe.com s.ytimg.com tagmanager.google.com transcend-cdn.com www.google-analytics.com www.googletagmanager.com www.mozilla.org www.youtube.com; connect-src 'self' cdn.transcend.io https://abdri3ttkb.execute-api.us-east-2.amazonaws.com https://accounts.firefox.com/ https://basket.mozilla.org o1069899.ingest.sentry.io o1069899.sentry.io region1.google-analytics.com telemetry.transcend.io telemetry.us.transcend.io transcend-cdn.com www.google-analytics.com www.googletagmanager.com www.mozilla.org/submit/bedrock/; object-src 'none'; default-src 'self' *.mozilla.org; img-src 'self' blog.mozilla.org data: images.ctfassets.net www.google-analytics.com www.googletagmanager.com www.mozilla.org; media-src 'self' assets.mozilla.net videos.cdn.mozilla.net www.mozilla.org 2 require-trusted-types-for 'script'; report-uri https://csp.withgoogle.com/csp/uxe-owners-acl/android 2 style-src 'self' 'unsafe-inline' cdn.transcend.io transcend-cdn.com www.firefox.com; script-src 'self' 'unsafe-eval' 'unsafe-inline' cdn.transcend.io s.ytimg.com tagmanager.google.com transcend-cdn.com www.firefox.com www.google-analytics.com www.googletagmanager.com www.youtube.com; object-src 'none'; font-src 'self' www.firefox.com; default-src 'self' www.firefox.com; base-uri 'none'; frame-src 'self' accounts.firefox.com www.google-analytics.com www.googletagmanager.com www.youtube-nocookie.com www.youtube.com; frame-ancestors 'none'; connect-src 'self' basket.mozilla.org cdn.transcend.io https://accounts.firefox.com/ https://basket.mozilla.org o1069899.ingest.sentry.io o1069899.ingest.us.sentry.io o1069899.sentry.io region1.google-analytics.com telemetry.transcend.io telemetry.us.transcend.io transcend-cdn.com www.firefox.com www.google-analytics.com www.googletagmanager.com; upgrade-insecure-requests; media-src 'self' assets.mozilla.net videos.cdn.mozilla.net www.firefox.com www.mozilla.org; form-action 'self' https://accounts.firefox.com/ https://basket.mozilla.org; img-src 'self' data: www.firefox.com www.google-analytics.com www.googletagmanager.com www.mozilla.org 2 default-src data: 'self' blob: 'unsafe-inline' 'unsafe-eval' *.nesine.com wss://*.nesine.com *.google.com *.google.com.tr *.googletagmanager.com *.google-analytics.com *.support.google.com *.doubleclick.net *.googleadservices.com *.microsoft.com *.apple.com *.facebook.com *.facebook.net connect.facebook.net *.betsolutions.com *.ertgaming.com *.yahoo.com *.newrelic.com *.twitter.com *.instagram.com *.youtube.com *.ytimg.com *.aboutcookies.org *.mobilproses.com *.omnitagjs.com *.outbrain.com *.nr-data.net *.bidswitch.net wss://*.sportradar.com *.sportradar.com *.akamaized.net *.performfeeds.com *.betradar.com *.dge.imggaming.com tjktv.ercdn.net *.tjk.org *.broadage.com *.pubmatic.com *.mediavine.com *.demdex.net *.krxd.net *.thebrighttag.com *.tremorhub.com *.adnxs.com *.casalemedia.com *.360yield.com *.media.net *.rubiconproject.com *.sharethrough.com *.smartadserver.com *.teads.tv *.3lift.com *.emxdgt.com *.sync.com *.ivitrack.com *.yieldmo.com *.yieldlab.net *.imgarena.com *.liderform.com.tr *.googleapis.com *.googlevideo.com *.gstatic.com *.azureedge.net *.semasio.net *.7platform.net *.7platform.com *.7platform.live *.nsoft-cdn.com *.launchdigi.net *.106digital.com *.gameturboz.cloud *.turboexplorer.online *.1rx.io *.adsrvr.org aa.agkn.com *.postrelease.com *.revcontent.com *.rqtrk.eu *.bing.com *.smaato.net *.narrative.io *.socdm.com *.mediawallahscript.com *.liadm.com *.stickyadstv.com *.linkedin.com *.rlcdn.com *.dable.io *.adingo.jp *.twiago.com *.bluekai.com *.crwdcntrl.net *.hs.llnwd.net *.ucweb.com *.dengage.com *.playbetman.com *.turbolabs.online *.aleaplay.com *.turbogg4u.online *.turbodiscovery.xyz *.ofmicropod.com *.dengagecdn.com launchdigi.net *.eskimi.com *.tiktok.com *.rsc.cdn77.org *.igamemedia.com *.castr.net data.widgets.sir.sportradar.com *.inseincvirtuals.com wss://data.widgets.sir.sportradar.com wss://*.sportradar.com wss://*.akamaized.net cdn.alsgp0.fds.api.mi-img.com apm-rum-sgp.inf.miui.com infragrid.v.network metrics-dre.dt.dbankcloud.cn cdn-uicons.flaticon.com *.cloudfront.net *.mobilproses.com *.codezania.com https://106gamesgalaxsys.online https://www.millipiyangoonline.com/ www.google.de www.google.com.cy www.google.nl www.google.fr www.google.co.uk www.google.iq www.google.ca www.google.pt www.google.ch www.google.bg www.google.az www.google.it www.google.no www.google.se www.google.com.sa www.google.com.qa www.google.ru www.google.be www.google.com.kw www.google.co.tz www.google.ro www.google.hu www.google.ba www.google.at www.google.rs *.millipiyangoonline.com www.google.dk www.google.co.uz www.google.dz www.google.es www.google.pl www.google.com.ly www.googletagmanager.com digital.millipiyangoonline.com www.google.at www.google.hu www.google.ro www.google.ru www.google.be dbox1.sisalsanstech.com www.millipiyangoonline.com pagead2.googlesyndication.com https://bulten.sm.mncdn.com sisal.queue-it.net; img-src * data:; report-uri /csp/cspreport/ 2 default-src 'self';style-src 'self' 'unsafe-inline' https://use.typekit.net; object-src 'none'; base-uri 'self';worker-src 'none'; 2 default-src https: 'unsafe-inline' 'unsafe-eval' 'self' data:; img-src 'self' *.eff.org data:; report-uri https://sentry.eff.org/api/2/security/?sentry_key=f1118ad37b5e4afbabe3487ca42fe73e 2 default-src data: 'unsafe-inline' 'unsafe-eval' https: blob: http://*.files.wordpress.com wss://variety.com; report-uri https://pmcuri.report-uri.com/r/d/csp/reportOnly 2 script-src 'self' padlet.net maps.googleapis.com apis.google.com ta-echo.padlet.com api.commandbar.com cdn.commandbar.com app.getbeamer.com challenges.cloudflare.com embed.cloudflarestream.com cdn.usefathom.com blob: 'unsafe-inline' 'unsafe-eval'; style-src 'self' padlet.net fonts.googleapis.com cdn.commandbar.com app.getbeamer.com 'unsafe-inline'; font-src 'self' padlet.net fonts.gstatic.com data:; report-uri https://padlet.com/csp-report; 2 default-src 'self' data: blob: https://067-umd-991.mktoresp.com https://accounts.google.com https://analytics.google.com https://api.amplitude.com https://bi-beta.pst.tech https://bi.pst.tech https://bifrost-https-v4.gw.postman.com https://blog.postman.com https://dl.pstmn.io https://eo2kpuahxhuvgexlueall7gqzq0fihon.lambda-url.us-east-1.on.aws https://events.gw.postman.com https://events.rm-api.com https://googleads.g.doubleclick.net https://www.googleadservices.com https://identity.getpostman-beta.com https://identity.getpostman.com https://lp.postman.com https://munchkin.marketo.net https://pages.getpostman.com https://public.slidesharecdn.com https://px.ads.linkedin.com https://px4.ads.linkedin.com https://manifest.webmanifest https://ms1frkqnsp7r.statuspage.io https://run.pstmn.io https://script.hotjar.com https://skills-assets.pstmn.io https://st-ar.cdn.postman.com https://static.cloudflareinsights.com https://static.hotjar.com https://stats.g.doubleclick.net https://td.doubleclick.net https://vc.hotjar.io https://voyager.postman.com https://web.postman.com https://www.googletagmanager.com https://www.slideshare.net https://snap.licdn.com https://www.google.com https://www.youtube.com https://youtube.com https://www.linkedin.com/px/ https://www.postman.com https://snap.licdn.com/ https://i.ytimg.com https://worldtimeapi.org https://maps.google.com https://*.mountain.com https://dx.mountain.com https://px.mountain.com https://gs.mountain.com https://44.238.122.172 https://100.20.58.101 https://35.85.84.151 https://44.228.85.26 https://34.215.155.61 https://35.160.46.251 https://52.71.121.170 https://18.210.229.244 https://44.212.189.233 https://3.212.39.155 https://52.22.50.55 https://54.156.2.105 https://bam.nr-data.net https://js-agent.newrelic.com https://res.cloudinary.com https://mkt.cdn.postman.com https://api.mapbox.com https://events.mapbox.com https://api.fpjs.io https://cdn.amplitude.com https://api2.amplitude.com https://www.facebook.com https://connect.facebook.net https://bat.bing.com https://js.qualified.com wss://ws.qualified.com wss://ws2.qualified.com https://app.qualified.com https://api.company-target.com https://segments.company-target.com https://tag.demandbase.com https://tag-logger.demandbase.com https://s.company-target.com https://alb.reddit.com https://www.redditstatic.com https://pixel-config.reddit.com https://content.hotjar.io https://script.hotjar.com https://static.hotjar.com wss://ws.hotjar.com https://cdn.segment.com https://api.cdp.postman.com https://api.segment.io https://evs.cdp.postman.com https://www.influ2.com https://t.influ2.com https://*.usbrowserspeed.com https://pxl.growth-channel.net https://tags.srv.stackadapt.com https://job-boards.greenhouse.io https://transcend-cdn.com https://telemetry.us.transcend.io https://unpkg.com/launchdarkly-js-client-sdk@3.8.1 https://app.launchdarkly.com/ https://events.launchdarkly.com https://tally.so/ https://postman.outgrow.us/ https://api-n.outgrow.co https://t.co/ https://analytics.twitter.com https://static.ads-twitter.com/uwt.js https://id.rlcdn.com https://cdn.cr-relay.com https://api.cr-relay.com https://cdn.vector.co https://api.vector.co https://*.liadm.com/ https://*.ip-api.com https://accretivemedia.go2cloud.org https://fast.wistia.net https://fast.wistia.com https://embed-ssl.wistia.com https://distillery.wistia.com https://pipedream.wistia.com https://embed-cloudfront.wistia.com https://postman.cdn.prismic.io https://static.cdn.prismic.io https://postman.prismic.io https://browser.sentry-cdn.com https://o1224273.ingest.us.sentry.io 'unsafe-inline' 'unsafe-eval'; form-action 'self'; base-uri 'self'; 2 default-src data: 'unsafe-inline' 'unsafe-eval' https: blob: http://*.files.wordpress.com wss://www.billboard.com; report-uri https://pmcuri.report-uri.com/r/d/csp/reportOnly 2 default-src data: 'unsafe-inline' 'unsafe-eval' https: blob: http://*.files.wordpress.com wss://deadline.com; report-uri https://pmcuri.report-uri.com/r/d/csp/reportOnly 2 default-src 'self';base-uri 'self';connect-src 'self' data: https: wss://keepalive.gotinder.com;script-src 'nonce-DXDCAlde7Lo6YD5TSaTFRA==' 'strict-dynamic' 'unsafe-hashes' 'unsafe-eval' 'wasm-unsafe-eval' 'sha256-PLCxbpHSwAa8+W198R1KQQ9UDCexTvYy4z4YmCg21NM=' 'unsafe-inline';style-src 'self' 'unsafe-inline' blob: https://*.googleapis.com https://accounts.google.com;frame-src 'self' https://tinder-api.arkoselabs.com https://*.paypal.com https://accounts.google.com https://*.doubleclick.net https://*.adyen.com;frame-ancestors 'self';form-action 'self' https://*.tinder.com https://tinder.com https://*.adyen.com;object-src 'none';img-src 'self' data: blob: https:;media-src 'self' data: https:;report-to tinderweb-csp-reports;font-src 'self' data: https:;manifest-src 'self' https: 2 default-src 'self' *.wp.com; img-src data: https:; script-src 'unsafe-inline' 'unsafe-eval' blob: https:; style-src 'unsafe-inline' https:; font-src data: https:; media-src blob: https:; frame-src https:; object-src 'none'; connect-src https:; 2 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://cdn.cookielaw.org https://optly.heap.io https://www.googleoptimize.com https://www.googletagmanager.com https://cdn.us.heap-api.com https://marketo.clearbit.com https://*.wistia.net https://js.chilipiper.com https://js.driftt.com https://*.clearbit.com https://app-ab33.marketo.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://cdn.cookielaw.org https://*.ctfassets.net; img-src 'self' data: https://*.ctfassets.net https://www.google-analytics.com https://www.googletagmanager.com https://*.wistia.net https://heapanalytics.com https://*.clearbit.com https://*.doubleclick.net; connect-src 'self' https://*.contentful.com https://*.heap-api.com https://heapanalytics.com https://www.google-analytics.com https://*.wistia.net https://*.doubleclick.net https://*.cookielaw.org https://app-ab33.marketo.com; font-src 'self' data: https://fonts.gstatic.com; frame-src 'self' https://*.wistia.net https://*.marketo.com https://*.chilipiper.com; worker-src 'self' blob:; manifest-src 'self'; base-uri 'self'; form-action 'self' https://*.marketo.com; frame-ancestors 'self'; media-src 'self' https://*.wistia.net blob:; object-src 'none' 2 frame-ancestors 'self'; report-uri /csp_report 2 default-src 'self' *.pinduoduo.com *.pddpic.com *.yangkeduo.com *.pddugc.com *.pinduoduo.net *.v.smtcdns.net *.ourdvsss.com wss://*.pinduoduo.com wss://*.yangkeduo.com mapstyle.qpic.cn blob: data: 'unsafe-eval' 'unsafe-inline'; report-uri https://tc.pinduoduo.com/x.gif 2 default-src 'self' cdnweb.sbermobile.ru; frame-src https://cdn.rutarget.ru/ https://api.flocktory.com https://mc.yandex.ru https://tag.rutarget.ru/ ; style-src 'unsafe-inline' 'self' fonts.googleapis.com cdnweb.sbermobile.ru; font-src 'self' cdnweb.sbermobile.ru data: fonts.gstatic.com ; connect-src 'self' https://yandexmetrica.com:*/ *.sbermarketing.ru uaas.yandex.ru ad.adriver.ru api.flocktory.com kraken.rambler.ru https://*.mc.yandex.ru/ https://stats.g.doubleclick.net/ https://suggestions.dadata.ru/ https://suggest-maps.yandex.ru/ https://ymetrica1.com/ https://www.google-analytics.com/ https://unpkg.com/ https://stats.g.doubleclick.net/ https://mc.yandex.ru/ https://*.sberbank.ru/ https://sa.online.sberbank.ru:8098/; script-src 'self' 'unsafe-inline' 'unsafe-eval' cdnweb.sbermobile.ru *.yandex.net *.trbcdn.net top-fwz1.mail.ru api.flocktory.com *.top100.ru *.adriver.ru px.adhigh.net cdn.rutarget.ru yastatic.net *.maps.yandex.net suggest-maps.yandex.ru api-maps.yandex.ru *.otm-r.com www.google-analytics.com ajax.googleapis.com fonts.googleapis.com *.mc.yandex.ru mc.yandex.ru nlb-clickstream.sberbank.ru sp.otm-r.com stats.g.doubleclick.net www.google-analytics.com www.google.ru www.googletagmanager.com ; img-src 'self' data: www.gstatic.com cdnweb.sbermobile.ru adservings.ru api.flocktory.com top-fwz1.mail.ru kraken.rambler.ru api-maps.yandex.ru *.maps.yandex.net *.mc.yandex.com *.mc.yandex.ru mc.yandex.ru *.googleusercontent.com www.googletagmanager.com www.google.ru www.google.com www.google-analytics.com *.otm-r.com yandex.ru; base-uri 'self' cdnweb.sbermobile.ru; form-action 'self'; frame-ancestors 'none' 2 frame-ancestors 'self'; report-to csp-endpoint 2 frame-src 'self' syndicatedsearch.goog *.google.com *.youtube.com vimeo.com *.vimeo.com *.podbean.com static.addtoany.com *.blackbaudhosting.com js.createsend1.com *.createsend.com *.payments.blackbaud.com payments.blackbaud.com/Checkout/bbCheckout.2.0.js; object-src 'none'; script-src 'self' 'report-sample' 'unsafe-eval' *.googleadservices.com app.purechat.com app-script.monsido.com connect.facebook.net cdnjs.cloudflare.com static.addtoany.com polyfill.io *.googletagmanager.com *.google-analytics.com *.google.com www.gstatic.com cdn.jsdelivr.net *.hotjar.com *.gtranslate.net *.blackbaudhosting.com js.createsend1.com www.createsend.com *.googleapis.com *.payments.blackbaud.com payments.blackbaud.com/Checkout/bbCheckout.2.0.js https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com https://www.google.com; script-src-elem 'self' 'unsafe-inline' *.googleadservices.com app.purechat.com app-script.monsido.com connect.facebook.net cdnjs.cloudflare.com static.addtoany.com polyfill.io *.googletagmanager.com *.google-analytics.com *.google.com www.gstatic.com cdn.jsdelivr.net *.hotjar.com *.gtranslate.net *.blackbaudhosting.com js.createsend1.com *.createsend.com www.createsend.com *.googleapis.com *.payments.blackbaud.com payments.blackbaud.com/Checkout/bbCheckout.2.0.js *.simpli.fi https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com https://www.google.com; style-src 'self' 'report-sample' 'unsafe-inline' *.googleapis.com *.gstatic.com *.createsend1.com *.createsend.com *.blackbaudhosting.com *.payments.blackbaud.com payments.blackbaud.com/Checkout/bbCheckout.2.0.js cdnjs.cloudflare.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com; worker-src 'self'; base-uri 'self'; form-action 'self' www.createsend.com js.createsend1.com *.blackbaudhosting.com *.nla.gov.au *.payments.blackbaud.com payments.blackbaud.com/Checkout/bbCheckout.2.0.js; frame-ancestors 'self' 2 default-src 'none'; script-src icq.com c.icq.com cicq.org 1l-hit.mail.ru www.google-analytics.com buddyicon.foto.mail.ru www.googletagmanager.com top-fwz1.mail.ru 'sha256-DKOsdd00IXAHc7qK64HiC18YrB2K4SfiH8Sl6A9aFyg=' 'sha256-u4WiMVZhYDdCrFwB8Zn3gLba1EI3pqIlFYWFZfXJl2I=' 'sha256-ynzJCJTMBeZF6kbmzoI2rC+vDRozRAHxsPfAruxve88=' 'sha256-j51JRkq0bwz97Hd/1wJQsIy6/aX9cz16Xyp+M8FshTA=' 'self'; style-src c.icq.com icq.com cicq.org 'self' 'unsafe-inline'; img-src data: icq.com c.icq.com cicq.org api.icq.net www.google-analytics.com buddyicon.foto.mail.ru files.icq.com files.imgsmail.ru u.icq.net u.myteam.vmailru.net ub.icq.net ub.myteam.vmailru.net swa.icq.com stats.g.doubleclick.net 'self'; media-src data: icq.com c.icq.com cicq.org api.icq.net www.google-analytics.com files.icq.com api.icq.net files.imgsmail.ru u.icq.net u.myteam.vmailru.net ub.icq.net ub.myteam.vmailru.net 'self'; font-src icq.com c.icq.com cicq.org 'self'; connect-src privacy.icq.com icq.com top-fwz1.mail.ru 'self'; report-uri /system/error 2 default-src data: 'unsafe-inline' 'unsafe-eval' https: blob: http://*.files.wordpress.com wss://wwd.com; report-uri https://pmcuri.report-uri.com/r/d/csp/reportOnly 2 default-src 'self'; script-src 'self' https://vercel.live https://challenges.cloudflare.com https://cdnjs.cloudflare.com https://*.posthog.com https://www.googletagmanager.com https://static.cloudflareinsights.com https://clerk.arena.ai https://www.google.com https://www.gstatic.com 'unsafe-inline' 'unsafe-eval'; script-src-elem 'self' https://vercel.live https://challenges.cloudflare.com https://cdnjs.cloudflare.com https://*.posthog.com https://www.googletagmanager.com https://arena.ai https://static.cloudflareinsights.com/ https://clerk.arena.ai https://www.google.com https://www.gstatic.com 'unsafe-inline' 'unsafe-eval'; style-src 'self' 'unsafe-inline' https://challenges.cloudflare.com https://vercel.live https://us.posthog.com; img-src 'self' data: blob: https://challenges.cloudflare.com https://*.posthog.com https://vercel.live https://vercel.com https://*.27c852f3500f38c1e7786e2c9ff9e48f.r2.cloudflarestorage.com https://lh3.googleusercontent.com https://*.googletagmanager.com; connect-src 'self' https://arena.ai https://vercel.live wss://ws-us3.pusher.com https://*.posthog.com https://posthog.com https://challenges.cloudflare.com https://unpkg.com/@rive-app/ https://clerk.arena.ai https://www.google-analytics.com https://*.google-analytics.com https://www.google.com https://*.27c852f3500f38c1e7786e2c9ff9e48f.r2.cloudflarestorage.com; frame-src 'self' https://vercel.live https://challenges.cloudflare.com https://www.google.com https://*.arena.site https://*.staging.arena.site; font-src 'self' data: https://vercel.live https://assets.vercel.com https://*.gstatic.com; worker-src 'self' blob: 2 require-trusted-types-for 'script'; report-uri https://csp.withgoogle.com/csp/uxe-owners-acl/about_google 2 default-src 'self' 'unsafe-inline' https:; script-src 'self' 'unsafe-inline' 'unsafe-eval' https:; img-src 'self' https: data: image/*; frame-ancestors 'self' *.sunrise.ch; frame-src https: mailto:; connect-src https: wss: data:; font-src https: data:; media-src 'self' https:; worker-src blob:; report-uri https://www.sunrise.ch/csp-collector 2 frame-ancestors 'self'; report-uri https://www.theaustralian.com.au/csp-reports 2 frame-ancestors 'self' https://*.kit.edu; report-uri /global-cgi-bin/csp-report; report-to csp-report 2 connect-src https:; child-src https:; default-src https:; font-src data: https:; form-action https:; frame-ancestors 'self' *.ffxblue.com.au *.ffx.io *.afr.com *.cdn.ampproject.org *.platform.ink; frame-src https:; img-src https: data:; media-src blob: https:; object-src https:; script-src https: 'unsafe-eval' 'unsafe-inline'; script-src-attr https: 'unsafe-eval' 'unsafe-inline'; script-src-elem https: 'unsafe-eval' 'unsafe-inline'; style-src https:; style-src-attr 'unsafe-inline'; style-src-elem https: 'unsafe-inline'; worker-src blob:; report-uri https://csp.ffx.io/; report-to csp-endpoint 2 default-src data: 'unsafe-inline' 'unsafe-eval' https: http:; script-src data: 'unsafe-inline' 'unsafe-eval' https: http: blob:; style-src data: 'self' 'unsafe-inline' https:; img-src data: 'self' https: blob: android-webview-video-poster:; font-src 'self' https: data:; connect-src 'self' data: https: wss: blob:; media-src data: https: blob:; object-src https:; child-src https: data: blob:; form-action https:; report-uri https://prod.bhaskarapi.com/api/1.0/web-backend/csp-report; 2 frame-ancestors 'self'; report-uri /csp-report 2 default-src 'self' *.wargaming.net *.wgprod.net https://*.wgcdn.co https://*.gcdn.co https://www.youtube.com ; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.tvsquared.com *.wargaming.net *.wgprod.net *.cookielaw.org *.onetrust.com *.outbrain.com *.snapchat.com *.redditstatic.com https://sc-static.net https://ob.cheqzone.com https://analytics.google.com https://www.google.com https://www.google.com.cy https://*.teads.tv https://*.taboola.com https://*.adform.net https://partner.worldoftanks.com https://*.wgcdn.co https://*.gcdn.co https://www.googletagmanager.com https://*.google-analytics.com https://*.analytics.google.com https://www.googleadservices.com https://www.googleoptimize.com https://u360.d-bi.fr https://bat.bing.com https://connect.facebook.net https://googleads.g.doubleclick.net https://*.adroll.com https://*.addthis.com https://*.addthisedge.com https://tag.marinsm.com https://pixel-geo.prfct.co https://static.criteo.net https://*.creative-serving.com https://*.criteo.com https://*.cloudfront.net https://js.gleam.io https://a1.adform.net https://ajax.googleapis.com https://www.youtube.com https://animate.adobe.com https://*.stackadapt.com https://pagead2.googlesyndication.com https://secure.quantserve.com https://rules.quantcount.com https://*.clarity.ms cdn.taboola.com ; style-src 'self' 'unsafe-inline' *.wargaming.net *.wgprod.net https://fonts.googleapis.com https://*.wgcdn.co https://*.gcdn.co ; img-src 'self' data: android-webview-video-poster: * ; connect-src 'self' *.wargaming.net *.wgprod.net *.tvsquared.com *.taboola.com *.cookielaw.org *.onetrust.com *.outbrain.com *.snapchat.com *.yimg.com https://*.worldoftanks.com https://*.worldoftanks.eu https://*.worldoftanks.asia https://*.wgcdn.co https://sc-static.net https://ob.cheqzone.com https://analytics.google.com https://www.google.com wss://worldoftanks.eu wss://worldoftanks.asia wss://worldoftanks.com https://*.facebook.com https://www.googleoptimize.com https://*.addthis.com https://*.google-analytics.com https://*.analytics.google.com https://ymetrica1.com https://*.cloudfront.net https://google.com https://google.ru https://google.com.ua https://google.by https://google.pl https://www.google.com.cy https://*.googleapis.com https://stackadapt.com https://*.doubleclick.net https://pagead2.googlesyndication.com https://*.clarity.ms https://collect.worldoftanks.eu https://content-wg.gcdn.co https://bat.bing.com ; font-src 'self' *.wargaming.net *.wgprod.net https://fonts.gstatic.com https://*.wgcdn.co https://*.gcdn.co ; media-src 'self' *.wargaming.net *.wgprod.net https://*.wgcdn.co https://*.gcdn.co ; frame-src 'self' *.wargaming.net *.wgprod.net https://tr.snapchat.com https://creativecdn.com https://*.adform.net https://*.facebook.com https://ad3.adfarm1.adition.com https://connect.facebook.net https://www.youtube.com https://bid.g.doubleclick.net https://*.criteo.com https://*.addthis.com https://gleam.io https://*.gcdn.co https://*.wgcdn.co https://aax-eu.amazon-adsystem.com https://api.worldoftanks.eu ; object-src 'self' *.wargaming.net *.wgprod.net https://*.gcdn.co https://www.youtube.com ; report-uri https://cspreport.wargaming.net/cspreport 2 default-src 'self' https://n8n.io data: 'unsafe-inline'; script-src 'self' 'sha256-4pl9dZH8ght2nZ3AX1mV23mwuukxsklzULVnAeIEKbg=' https://cdn.jsdelivr.net/npm/@webcomponents/webcomponentsjs@2.0.0/webcomponents-loader.js https://www.unpkg.com/lit@2.0.0-rc.2/polyfill-support.js https://cdn.jsdelivr.net/npm/@n8n_io/n8n-demo-component@latest/n8n-demo.bundled.js https://*.googletagmanager.com https://www.gstatic.cn https://www.gstatic.com https://www.recaptcha.net https://static.cloudflareinsights.com/beacon.min.js/ static.cloudflareinsights.com https://script.tapfiliate.com/tapfiliate.js https://checkout.paddle.com/api/2.0/prices/; img-src 'self' data: https://*.google-analytics.com https://*.googletagmanager.com https://n8niostorageaccount.blob.core.windows.net https://www.gstatic.cn https://www.gstatic.com https://www.recaptcha.net https://gravatar.com/avatar/; media-src https://n8niostorageaccount.blob.core.windows.net; connect-src 'self' https://api.n8n.io/ https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://www.gstatic.cn https://www.gstatic.com https://www.recaptcha.net; frame-src https://jobs.ashbyhq.com https://n8n-preview-service.internal.n8n.cloud https://www.recaptcha.net https://challenges.cloudflare.com https://www.linkedin.com https://buy.paddle.com; frame-ancestors 'none'; object-src 'none' 2 img-src 'self' https://s3.amazonaws.com/media.nngroup.com/ https://media.nngroup.com; font-src 'self' https://s3.amazonaws.com/media.nngroup.com/ https://media.nngroup.com; style-src 'self' https://s3.amazonaws.com/media.nngroup.com/ https://media.nngroup.com; default-src 'self'; script-src 'self' https://s3.amazonaws.com/media.nngroup.com/ https://media.nngroup.com; connect-src 'self' 2 frame-ancestors 'self' *.pdffiller.com *.signnow.com *.airslate.com; report-uri https://www.pdffiller.com/api_v3/security_report/cspViolationsReport?appKey=rs3dwgboso31.apps.marketing_pages 2 default-src 'self'; script-src 'report-sample' 'self' https://7052064.fs1.hubspotusercontent-na1.net https://a.omappapi.com https://app.hubspot.com https://assets.apollo.io https://cdn.demio.com https://cdn.propensity.com https://cdnjs.cloudflare.com https://code.jquery.com https://googleads.g.doubleclick.net https://import-cdn.default.com https://js.hscollectedforms.net https://js.navattic.com https://platform.linkedin.com https://s3-us-west-2.amazonaws.com https://snap.licdn.com https://static.hsappstatic.net https://www.googleadservices.com https://www.googletagmanager.com https://www.redditstatic.com https://js.hs-analytics.net https://js.hs-scripts.com; style-src 'report-sample' 'self' https://7052064.fs1.hubspotusercontent-na1.net https://ajax.googleapis.com https://cdn.demio.com https://cdnjs.cloudflare.com https://fonts.googleapis.com https://kit-free.fontawesome.com https://static.hsappstatic.net; object-src 'none'; base-uri 'self'; connect-src 'self' https://a.omappapi.com https://analytics.google.com https://aplo-evnt.com https://app.hubspot.com https://cp.hubspot.com https://forms.default.com https://forms.hsforms.com https://geo.demio.com https://js.hs-banner.com https://nucleus.default.com https://pixel-config.reddit.com https://px.ads.linkedin.com https://www.cloudflare.com https://www.google.com https://www.redditstatic.com https://z.omappapi.com https://api.hsforms.com https://api.hubapi.com; font-src 'self' https://fonts.gstatic.com; frame-src 'self' https://forms.hsforms.com https://play.hubspotvideo.com https://scheduler.default.com https://td.doubleclick.net https://www.googletagmanager.com; img-src 'self' https://a.omappapi.com https://alb.reddit.com https://forms-na1.hsforms.com https://forms.hsforms.com https://forms.hubspot.com https://googleads.g.doubleclick.net https://px.ads.linkedin.com https://static.hsappstatic.net https://track.hubspot.com https://www.google.com; manifest-src 'self'; media-src 'self'; worker-src 'none'; report-uri https://6823595ee2a3634bf77e7bfe.endpoint.csper.io?builder=true&v=2; 2 default-src 'self'; script-src 'self' 'unsafe-eval' 'unsafe-inline' https://*.pie.org/ https://www.google.com/recaptcha/ https://accounts.google.com/ https://www.gstatic.com/ https://adblockforyoutube.com/ https://www.adblockforyoutube.com/; style-src 'self' 'unsafe-inline'; img-src 'self' blob: data: *; object-src 'none'; font-src 'self' https://fonts.gstatic.com; media-src 'self' https://cdn.pie.org; connect-src 'self' https://*.pie.org https://cdn.segment.com https://cdn.lottielab.com https://browser-intake-us5-datadoghq.com https://www.google.com/recaptcha/ https://adblockforyoutube.com https://www.adblockforyoutube.com; frame-src 'self' https://accounts.google.com/ https://www.google.com/recaptcha/ https://www.gstatic.com/ https://recaptcha.google.com/ https://adblockforyoutube.com/ https://www.adblockforyoutube.com/; base-uri 'self'; frame-ancestors 'none'; upgrade-insecure-requests 2 object-src 'none'; script-src * 'unsafe-inline' 'unsafe-eval'; style-src * 'unsafe-inline' 'unsafe-eval'; base-uri 'none'; frame-ancestors 'self' 2 default-src 'self' 'unsafe-eval' 'unsafe-inline' https: blob:;style-src 'self' 'unsafe-inline' https: data:;connect-src https: wss:;frame-src https:;script-src 'unsafe-eval' 'unsafe-inline' https: blob: data:;font-src https: data:;img-src https: data: blob:;media-src https: blob:; report-uri /csp_rep 2 default-src https: data: blob: wss: android-webview-video-poster: 'unsafe-inline' 'unsafe-eval'; form-action https:; report-to default; report-uri https://sentry.io/api/256178/csp-report/?sentry_key=c2fb05422b2242faaec1d6d8a2a000fc&sentry_environment=&sentry_release=1.2.46 2 base-uri 'self'; default-src 'self' data: https://*.emcd.io https://at.alicdn.com https://cdn.carrotquest.app https://cdn.fontshare.com https://cdn.megabonus.com https://fonts.googleapis.com https://fonts.gstatic.com https://fonts.intercomcdn.com https://js.intercomcdn.com https://maxcdn.bootstrapcdn.com https://mc.yandex.com https://pouch-global-font-assets.s3.eu-central-1.amazonaws.com https://telegram.org https://use.fontawesome.com https://use.typekit.net https://www.cdn-tinkoff.ru; object-src 'none'; worker-src 'none' blob:; manifest-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' 'report-sample' https://*.emcd.io https://accounts.google.com https://www.google-analytics.com https://www.google.com/recaptcha/api.js https://www.googletagmanager.com https://www.recaptcha.net https://www.gstatic.com https://www.gstatic.cn https://mc.webvisor.org https://mc.yandex.com https://mc.yandex.ru/ https://cdn.jsdelivr.net/npm/yandex-metrica-watch/tag.js https://js.intercomcdn.com https://widget.intercom.io https://telegram.org/js/pixel.js https://telegram.org/js/telegram-web-app.js https://telegram.org/js/telegram-widget.js?22 https://af.click.ru/ https://ajax.cloudflare.com https://analytics.dev.mind-dev.com https://cdn.carrotquest.app https://cdn.segment.com https://cloud.roistat.com https://connect.facebook.net https://edge.fullstory.com https://*.programmatica.com https://script.marquiz.io https://script.marquiz.ru https://snap.licdn.com/li.lms-analytics/insight.min.js https://v1.slise.xyz https://widgets.outbrain.com https://appleid.cdn-apple.com/appleauth/ https://snap.licdn.com; style-src 'self' 'unsafe-inline' 'report-sample' https://telegram.org https://fonts.googleapis.com https://accounts.google.com https://mc.yandex.ru; img-src 'self' data: https://*.emcd.io https://fonts.gstatic.com https://www.googletagmanager.com https://www.gstatic.com https://mc.webvisor.org https://mc.yandex.by https://mc.yandex.com https://mc.yandex.kz https://mc.yandex.ru https://mc.yandex.uz https://yastatic.net https://*.intercomcdn.com https://messenger-apps.intercom.io https://static.intercomassets.com https://app.getbeamer.com https://cdn4.telesco.pe https://px.ads.linkedin.com https://sync.programmatica.com https://www.facebook.com https://t.me/i/userpic; frame-src 'self' data: https://accounts.google.com https://www.google.com https://www.googletagmanager.com https://www.recaptcha.net https://mc.yandex.com https://mc.yandex.ru https://intercom-sheets.com https://www.intercom-reporting.com/ https://af.click.ru https://emet.live https://emet.news https://eu.id.group-ib.com https://oauth.telegram.org https://payments.mercuryo.io https://quiz.marquiz.io https://quiz.marquiz.ru https://www.youtube.com; connect-src 'self' data: https://*.emcd.io wss://*.emcd.io https://accounts.google.com https://play.google.com https://translate.googleapis.com https://www.google-analytics.com https://www.recaptcha.net https://mc.yandex.com https://mc.yandex.md https://mc.yandex.ru https://translate.yandex.net wss://mc.yandex.ru https://uploads.intercomcdn.com wss://nexus-websocket-a.intercom.io https://browser.sentry-cdn.com https://o1144246.ingest.sentry.io https://o1144246.ingest.us.sentry.io https://api.segment.io https://cdn.segment.com https://oauth.telegram.org https://telegram.org/pxl https://adtonus.com https://analytics.dev.mind-dev.com https://api.carrotquest.app https://code.jquery.com https://containers.programmatica.com https://endpoint.em-app.tech https://infragrid.v.network https://ipapi.co https://px.ads.linkedin.com https://rktds.net https://*.fullstory.com https://v1.slise.xyz https://www.facebook.com https://*.intercom.io/ https://www.google.com/recaptcha https://mpc-prod-1-1053047382554.us-central1.run.app; report-uri https://cspr.emcd.io/; 2 frame-ancestors 'self' https://*.jobcloud.ch https://*.jobs.ch https://*.jobup.ch; base-uri 'self'; connect-src * data: 'self'; default-src 'self' https:; font-src 'self' https: data:; form-action 'self'; frame-src 'self' https:; img-src * data: blob: 'self'; manifest-src 'self'; media-src 'self'; object-src 'self'; script-src 'self' https: * data: blob: 'unsafe-inline' 'unsafe-eval'; style-src 'self' 'unsafe-inline'; require-trusted-types-for 'script'; worker-src 'self' 2 default-src https: 'unsafe-inline' 'unsafe-eval'; report-uri https://b3ceba9babf02086c0dca962bbbd1cda.report-uri.io/r/default/csp/reportOnly 2 default-src 'self' https: data: blob:; script-src 'self' 'unsafe-inline' 'unsafe-eval' https: *.google.com *.gstatic.com *.googleapis.com *.googletagmanager.com *.google-analytics.com *.youtube.com *.vimeo.com; style-src 'self' 'unsafe-inline' https: *.google.com *.gstatic.com *.googleapis.com *.youtube.com *.vimeo.com; img-src 'self' data: blob: https: *; font-src 'self' data: https: *.gstatic.com kit.fontawesome.com; connect-src 'self' https: wss: *.google.com *.gstatic.com *.googleapis.com *.googletagmanager.com *.google-analytics.com; frame-src 'self' https: www.youtube.com player.vimeo.com *.google.com; media-src 'self' https:; worker-src 'self' blob:; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'; upgrade-insecure-requests; report-uri https://cspreports.desarrollotrevenque.com/api/csp-report/606018d5-b6db-426c-b949-d1cdd5e7e18c; 2 default-src 'self' https://whiteboard.cloud.dev.microsoft https://whiteboard.cloud.microsoft; frame-ancestors 'self' https://teams.microsoft.com https://retailservices.teams.microsoft.com https://retailservices-ppe.teams.microsoft.com https://tasks.teams.microsoft.com https://local.teams.office.com https://devspaces.skype.com https://ssauth.skype.com https://teams.microsoft.com.mcas.ms https://teams.microsoft.com.us3.cas.ms https://local.teams.office.com:8080 https://teams.live.com https://outlook-sdf.office.com https://outlook.office.com/ https://assignments.onenote.com https://assignments.edu.cloud.microsoft https://browser-sandbox.meshxp.net/ https://spoolclientsdk.skype.com https://acsinternal-cte-beta.azurewebsites.net https://acssample-beta.azurewebsites.net https://acssample-stable.azurewebsites.net https://loop.microsoft.com https://*.loop.microsoft.com https://loop.cloud.microsoft https://loop.cloud-dev.microsoft https://app.int.whiteboard.microsoft.com https://whiteboard.cloud-dev.microsoft https://whiteboard.cloud.dev.microsoft https://whiteboard.cloud.microsoft https://*.whiteboard.microsoft.com https://whiteboard.microsoft.com https://whiteboard.office.com https://teams.cloud.microsoft https://outlook.cloud.microsoft https://m365.cloud.microsoft https://res-sdf.cdn.office.net https://res.cdn.office.net https://mesh.public.onecdn.static.microsoft https://mesh.df.onecdn.static.microsoft https://m365.cloud.microsoft https://sbrprodprv.www.office.com https://scuprodprv.www.office.com https://fa000000174.resources.office.net https://outlook.office.com https://planner.cloud.microsoft; base-uri 'none'; manifest-src 'self' https://whiteboard.cloud.dev.microsoft https://whiteboard.cloud.microsoft; script-src 'self' 'wasm-unsafe-eval' 'report-sample' https://whiteboard.cloud.dev.microsoft https://whiteboard.cloud.microsoft http://amcdn.msftauth.net https://amcdn.msftauth.net https://*.office365.com https://shell.cdn.office.net https://cdn.fluidpreview.office.net https://js.monitor.azure.com https://res-1.cdn.office.net https://res.cdn.office.net https://ch5.fluidpreview.office.net https://cdn.dev.fluidpreview.office.net https://dev.loop.microsoft.com https://res-sdf.cdn.office.net 'sha256-VCkGe6AeV2B4vV7flXt9Dkkp04wMc8zq7faHdRwhOx0=' 'sha256-Wmg7miLkEVn5v393z4Ch7lbKnpNnLZhnVOk/iJN1miE='; style-src 'self' 'unsafe-inline' 'report-sample' https://whiteboard.cloud.dev.microsoft https://whiteboard.cloud.microsoft https://*.office.net https://res.cdn.office.net https://cdn.fluidpreview.office.net https://ch5.fluidpreview.office.net https://cdn.dev.fluidpreview.office.net https://dev.loop.microsoft.com https://res-sdf.cdn.office.net; font-src 'self' https://whiteboard.cloud.dev.microsoft https://whiteboard.cloud.microsoft data: https://*.office.net https://spoprod-a.akamaihd.net https://static2.sharepointonline.com fs.microsoft.com; img-src 'self' https://whiteboard.cloud.dev.microsoft https://whiteboard.cloud.microsoft blob: data: https://*.office.com https://*.office365.com https://outlook.live.com https://*.teams.microsoft.com https://*.officeapps.live.com https://web.vortex.data.microsoft.com https://shell.cdn.office.net https://urlp.asm.skype.com https://urlp.sfbassets.com https://login.live.com https://storage.live.com; connect-src 'self' blob: https://* wss://whiteboard.microsoft.com/sync wss://whiteboard.svc.cloud.microsoft/sync wss://whiteboard.svc.cloud.dev.microsoft/sync wss://*.whiteboard.microsoft.com wss://whiteboard.microsoft.com wss://*.svc.ms wss://dogfood.augloop.svc.cloud.microsoft wss://*.dogfood.augloop.svc.cloud.microsoft wss://*.augloop-dogfood.officeppe.com wss://augloop-dogfood.officeppe.com wss://augloop.svc.cloud.microsoft wss://*.augloop.svc.cloud.microsoft wss://*.augloop.office.com wss://augloop.office.com wss://augloop-gcc.office.com wss://*.augloop-gcc.office.com; worker-src 'self' https://whiteboard.cloud.dev.microsoft https://whiteboard.cloud.microsoft; frame-src 'self' https://* https://webshell.suite.office.com; media-src 'self' https://whiteboard.cloud.dev.microsoft https://whiteboard.cloud.microsoft; object-src 'none'; form-action 'self' https://*; report-uri https://csp.microsoft.com/report/WhiteboardWebClient-WhiteboardApp-PROD; report-to csp-endpoint; 2 default-src 'self' https://d3q9kdqrtloda.cloudfront.net/ https://i.ytimg.com/ https://www.youtube-nocookie.com/ https://noembed.com/ https://cdn.plyr.io/ https://cdn-ukwest.onetrust.com/ https://geolocation.onetrust.com/ https://www.google.com/ https://googleads.g.doubleclick.net/ https://www.google-analytics.com/ https://stats.g.doubleclick.net/ https://px.ads.linkedin.com/ https://api.hubapi.com/ https://cta-service-cms2.hubspot.com/ https://c1001.report.gbss.io/ https://analytics.tiktok.com/ https://forms.hubspot.com/ https://region1.analytics.google.com/ https://*.analytics.google.com/ https://region1.google-analytics.com/ https://*.google-analytics.com/ https://pagead2.googlesyndication.com https://privacyportal-uk.onetrust.com/ https://*.onetrust.com/ https://cambridgeenglish.formstack.com/forms/ieltstrf https://cambridgeenglish.formstack.com/forms/ielts_recognising_organisation https://cambridgeenglish.formstack.com/; style-src 'self' 'unsafe-inline' https://static.formstack.com/forms/css/ https://static.formstack.com/common/css/ https://cdn.craft.cloud; script-src 'self' https://www.youtube.com/ https://cambridgeenglish.formstack.com/forms/ 'sha256-5woGd/mZkUg7jRI9rPBZPHKC+LdyheFkTyKDMVNRNAs=' https://static.hotjar.com/c/ https://static.formstack.com/forms/js/ 'sha256-BEia3zQX2ZCFqcEfWBg9chT7nMc26YOr506FmhGqIfE=' 'sha256-z+rMOYNYmUbRI0OKIZH9HZneWmS3dJkEIDLisI+5LwI=' 'sha256-4QifgdTNZlur9Y/OOGOV3SggRLnQQR4peyehG9Y5buo=' https://www.google.com/ https://www.gstatic.com/ https://cdn-ukwest.onetrust.com/ https://www.googletagmanager.com/ 'sha256-rbMVlXlWb1FxlmTxqO6hQI+5VPCMoqHMqeyWMrzk9E4=' 'sha256-IgMQOOOedQeMPBl7lSreMVPmJvU62bc6l8HcsGXnbWc=' 'sha256-/6m2tVE+3ZAyrBnUps+rDpHpCwMi0VgW9mdVym2y2cE=' 'sha256-nanbr0ZSJrOvEvr6c5gV8UarYfjNXF+TAtmA9GjvyJ0=' 'sha256-ATpn7Ex50rRSNqmoA432bWfqvlsGB6CD/7fE2WtoU5A=' 'sha256-iXVjrS+TzaVqRdjZV8gecO6OkuAcobYu2OjiJVT8LYU=' 'sha256-+WTu64J4HVaiLZC0nSjR9XxbZZg1xX7cdNM/WA/pDcQ=' 'sha256-tOY0R/wVWZCxGQPtXP0ptphYuCKkCpgNHQy/ZkwhCCY=' 'sha256-xc61KVzUrz5aO4ACQyRqjH2fPpfIb/xoMmSSEiU+PWU=' 'sha256-wyNlDF2abbsDx6TZogcKckBQwZ4N8qFR3SAepboU7Sk=' 'sha256-tOY0R/wVWZCxGQPtXP0ptphYuCKkCpgNHQy/ZkwhCCY=' blob: 'unsafe-eval' https://www.google-analytics.com/ https://snap.licdn.com/ https://googleads.g.doubleclick.net/ https://static.ads-twitter.com https://www.googleadservices.com/ https://connect.facebook.net/ https://a.quora.com/ https://js.hs-scripts.com/ https://analytics.tiktok.com/ https://cdn.gbqofs.com/ https://cl.qualaroo.com/ https://assets.ubembed.com/ https://js.hs-analytics.net/ https://js.hsadspixel.net/ https://js.hsleadflows.net/ https://js.hs-banner.com/ https://js.hubspot.com/ https://cdn.gbqofs.com/ https://analytics.tiktok.com/ https://cdn.gbqofs.com/ https://snap.licdn.com/ https://14d7fb0767d540569b202283222297c0.js.ubembed.com/ 'sha256-1e5RR2OpHhuX2h0Bat19DsNTmqbo4M3T1pqfeTXCHaA='; object-src 'none'; font-src 'self' https://static.formstack.com/forms/fonts/; img-src 'self' data: https://d3q9kdqrtloda.cloudfront.net/ https://s3.eu-west-2.amazonaws.com/ielts-web-static/ www.googletagmanager.com https://i.ytimg.com/ https://cdn-ukwest.onetrust.com/ https://ad.doubleclick.net/ https://px.ads.linkedin.com/ https://googleads.g.doubleclick.net/ https://www.google.com/ https://t.co https://analytics.twitter.com/ https://www.facebook.com/ https://q.quora.com/ https://adservice.google.com/ https://perf-na1.hsforms.com/ https://*.google.ad/ https://*.google.ae/ https://*.google.com.af/ https://*.google.com.ag/ https://*.google.al/ https://*.google.am/ https://*.google.co.ao/ https://*.google.com.ar/ https://*.google.as/ https://*.google.at/ https://*.google.com.au/ https://*.google.az/ https://*.google.ba/ https://*.google.com.bd/ https://*.google.be/ https://*.google.bf/ https://*.google.bg/ https://*.google.com.bh/ https://*.google.bi/ https://*.google.bj/ https://*.google.com.bn/ https://*.google.com.bo/ https://*.google.com.br/ https://*.google.bs/ https://*.google.bt/ https://*.google.co.bw/ https://*.google.by/ https://*.google.com.bz/ https://*.google.ca/ https://*.google.cd/ https://*.google.cf/ https://*.google.cg/ https://*.google.ch/ https://*.google.ci/ https://*.google.co.ck/ https://*.google.cl/ https://*.google.cm/ https://*.google.cn/ https://*.google.com.co/ https://*.google.co.cr/ https://*.google.com.cu/ https://*.google.cv/ https://*.google.com.cy/ https://*.google.cz/ https://*.google.de/ https://*.google.dj/ https://*.google.dk/ https://*.google.dm/ https://*.google.com.do/ https://*.google.dz/ https://*.google.com.ec/ https://*.google.ee/ https://*.google.com.eg/ https://*.google.es/ https://*.google.com.et/ https://*.google.fi/ https://*.google.com.fj/ https://*.google.fm/ https://*.google.fr/ https://*.google.ga/ https://*.google.ge/ https://*.google.gg/ https://*.google.com.gh/ https://*.google.com.gi/ https://*.google.gl/ https://*.google.gm/ https://*.google.gr/ https://*.google.com.gt/ https://*.google.gy/ https://*.google.com.hk/ https://*.google.hn/ https://*.google.hr/ https://*.google.ht/ https://*.google.hu/ https://*.google.co.id/ https://*.google.ie/ https://*.google.co.il/ https://*.google.im/ https://*.google.co.in/ https://*.google.iq/ https://*.google.is/ https://*.google.it/ https://*.google.je/ https://*.google.com.jm/ https://*.google.jo/ https://*.google.co.jp/ https://*.google.co.ke/ https://*.google.com.kh/ https://*.google.ki/ https://*.google.kg/ https://*.google.co.kr/ https://*.google.com.kw/ https://*.google.kz/ https://*.google.la/ https://*.google.com.lb/ https://*.google.li/ https://*.google.lk/ https://*.google.co.ls/ https://*.google.lt/ https://*.google.lu/ https://*.google.lv/ https://*.google.com.ly/ https://*.google.co.ma/ https://*.google.md/ https://*.google.me/ https://*.google.mg/ https://*.google.mk/ https://*.google.ml/ https://*.google.com.mm/ https://*.google.mn/ https://*.google.com.mt/ https://*.google.mu/ https://*.google.mv/ https://*.google.mw/ https://*.google.com.mx/ https://*.google.com.my/ https://*.google.co.mz/ https://*.google.com.na/ https://*.google.com.ng/ https://*.google.com.ni/ https://*.google.ne/ https://*.google.nl/ https://*.google.no/ https://*.google.com.np/ https://*.google.nr/ https://*.google.nu/ https://*.google.co.nz/ https://*.google.com.om/ https://*.google.com.pa/ https://*.google.com.pe/ https://*.google.com.pg/ https://*.google.com.ph/ https://*.google.com.pk/ https://*.google.pl/ https://*.google.pn/ https://*.google.com.pr/ https://*.google.ps/ https://*.google.pt/ https://*.google.com.py/ https://*.google.com.qa/ https://*.google.ro/ https://*.google.ru/ https://*.google.rw/ https://*.google.com.sa/ https://*.google.com.sb/ https://*.google.sc/ https://*.google.se/ https://*.google.com.sg/ https://*.google.sh/ https://*.google.si/ https://*.google.sk/ https://*.google.com.sl/ https://*.google.sn/ https://*.google.so/ https://*.google.sm/ https://*.google.sr/ https://*.google.st/ https://*.google.com.sv/ https://*.google.td/ https://*.google.tg/ https://*.google.co.th/ https://*.google.com.tj/ https://*.google.tl/ https://*.google.tm/ https://*.google.tn/ https://*.google.to/ https://*.google.com.tr/ https://*.google.tt/ https://*.google.com.tw/ https://*.google.co.tz/ https://*.google.com.ua/ https://*.google.co.ug/ https://*.google.co.uk/ https://*.google.com.uy/ https://*.google.co.uz/ https://*.google.com.vc/ https://*.google.co.ve/ https://*.google.co.vi/ https://*.google.com.vn/ https://*.google.vu/ https://*.google.ws/ https://*.google.rs/ https://*.google.co.za/ https://*.google.co.zm/ https://*.google.co.zw/ https://*.google.cat/ https://www.google-analytics.com/ https://*.linkedin.com/ https://*.amazonaws.com/ielts-web-static/ https://adservice.google.co.uk/ https://cdn.craft.cloud; frame-src 'self' https://www.google.com/ https://www.youtube-nocookie.com/ https://www.youtube.com/ https://dntcl.qualaroo.com/ https://td.doubleclick.net/ https://cambridgeenglish.formstack.com/ https://*.formstack.com https://www.googletagmanager.com/; 2 default-src data: 'unsafe-inline' 'unsafe-eval' https: blob: http://*.files.wordpress.com wss://www.artnews.com; report-uri https://pmcuri.report-uri.com/r/d/csp/reportOnly 2 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.wellhub.com *.amplitude.com https://js.appboycdn.com/web-sdk/4.0/braze.no-amd.min.js https://widget-mediator.zopim.com https://js-na1.hs-scripts.com https://static.zdassets.com https://sdk.inbenta.io https://chatbot.backoffice.gympass-staging.com/chatbot-site-gympass-com.js https://cdn.optimizely.com https://maps.googleapis.com https://x.clearbitjs.com https://js.hscollectedforms.net *.googletagmanager.com *.googleadservices.com *.google-analytics.com *.google.com cdn.cookielaw.org/ cdn.segment.com bat.bing.com/bat.js cdn.jsdelivr.net/npm/jquery-validation@1.19.5/dist/jquery.validate.min.js cdn.optimizely.com/js/ cdn.segment.com/analytics.js/ cdnjs.cloudflare.com/ajax/libs/jquery.mask/1.14.16/jquery.mask.min.js code.jquery.com/jquery-3.6.0.min.js connect.facebook.net/en_US/fbevents.js googleads.g.doubleclick.net/pagead/viewthroughconversion/ j.6sc.co/6si.min.js js.driftt.com/include/ js.hs-analytics.net/analytics/ js.hs-banner.com/ js.hs-scripts.com/ js.hsadspixel.net/fb.js js.hsforms.net/forms/v2.js js.hsleadflows.net/leadflows.js js.usemessages.com/conversations-embed.js rum-static.pingdom.net/ s.yimg.com/wi/ytc.js script.hotjar.com/ snap.licdn.com/li.lms-analytics/ static.hotjar.com/c/ static.hsappstatic.net/MeetingsEmbed/ex/MeetingsEmbedCode.js tag.clearbitscripts.com/v1/ tpc.googlesyndication.com/ unpkg.com/blip-chat-widget https://js.qualified.com/ https://*.salesloft.com/ clarity.ms/tag/uet/ *.clarity.ms/tag/uet/ x.clearbitjs.com/v2/ https://s3.amazonaws.com/raichu-beta/ https://static.play.ht/playht-pageplayer-plugin.js https://bat.bing.com/p/action/ https://connect.facebook.net/signals/config/ https://js.hubspot.com/web-interactives-embed.js https://analytics.tiktok.com/ https://www.clarity.ms/s/ https://static.xingcdn.com/xingtrk/index.js; style-src 'self' 'unsafe-inline' https://sdk.inbenta.io fonts.googleapis.com https://www.googletagmanager.com/ https://s3.amazonaws.com/raichu-beta/ https://static.play.ht/playht-pageplayer-plugin.css; object-src 'none'; base-uri 'self'; connect-src 'self' *.wellhub.com https://app.qualified.com/ wss://*.qualified.com https://unleash-edge-mep.gympass.com https://unleash-edge-mep.gympass.com/api/frontend/ https://traces.observability.prd.us.gympass.cloud/collect https://ext-otel.mep.prd.us.gympass.cloud/collect https://sdk.iad-03.braze.com/api/v3/data cdn.cookielaw.org/ *.onetrust.com inbenta.io *.inbenta.io https://api.inbenta.io wss://widget-mediator.zopim.com https://zendesk-eu.my.sentry.io *.zendesk.com zendesk.com https://static.zdassets.com https://ekr.zdassets.com https://maps.googleapis.com https://unlogged.users.gympass-staging.com *.googletagmanager.com *.googleadservices.com *.google-analytics.com *.google.com google.com googleadservices.com https://www.google.com.br/ google.com.br api.hubapi.com hubspot.com *.hubspot.com api.segment.io app.clearbit.com bat.bing.com cdn.segment.com epsilon.6sense.com *.optimizely.com optimizely.com forms.hsforms.com in.hotjar.com ipv6.6sc.co js.hs-banner.com *.clarity.ms rum-collector-2.pingdom.net s.yimg.com stats.g.doubleclick.net unlogged.users.gympass.com https://play.ht/api/v2/ https://places.geo.us-east-1.amazonaws.com https://*.cloudfront.net https://px.ads.linkedin.com https://analytics.tiktok.com/ api.reclameaqui.com.br https://browser-intake-datadoghq.com/api/v2/ https://rum.browser-intake-datadoghq.com/api/v2/ https://www.facebook.com/ https://region1.analytics.google.com/ wss://*.hotjar.com/ https://*.hotjar.io/ https://o4504963224764416.ingest.us.sentry.io/api/ https://www.xing.com/xas/api/tracking_pixel_verification; font-src 'self' data: https://cdn.inbenta.io fonts.gstatic.com https://assets-cdn.gympass.com https://assets-cdn.wellhub.com https://script.hotjar.com/ https://s3.amazonaws.com/play-plugin/build/font; frame-src 'self' https://gympass.chat.blip.ai https://app.qualified.com/ optimizely.com *.cdn.optimizely.com googleadservices.com bid.g.doubleclick.net forms.hsforms.com js.driftt.com meetings.hubspot.com tpc.googlesyndication.com vars.hotjar.com facebook.com https://www.facebook.com/ www.googletagmanager.com/ https://www.youtube.com/ https://td.doubleclick.net; img-src 'self' data: https://s3.amazonaws.com/raichu-beta/ https://assets-cdn.gympass-staging.com https://assets-cdn.gympass.com https://assets-cdn.wellhub.com https://images.partners.gympass.com/ https://tmp-images.partners.gympass.com/ https://p.adsymptotic.com https://www.googletagmanager.com cdn.cookielaw.org/ *.inbenta.com inbenta.com https://gympass-staging-images-us.s3.amazonaws.com https://maps.googleapis.com https://maps.gstatic.com *.clarity.ms/ cloudfront.net *.cloudfront.net https://www.google.com/ads/ga-audiences https://www.google.com.br/ads/ga-audiences https://www.google.com/pagead/1p-user-list/ b.6sc.co bat.bing.com https://c.bing.com/ forms-na1.hsforms.com forms.hsforms.com googleads.g.doubleclick.net https://googleads.g.doubleclick.net/ px.ads.linkedin.com sp.analytics.yahoo.com track.hubspot.com facebook.com https://www.google-analytics.com google.com google.com.br www.google.com.br https://www.google.co.uk/ https://www.google.com.ar/ https://www.google.com.mx/ https://www.google.de/ https://www.google.es/ https://www.google.cl/ https://www.google.it/ https://www.facebook.com/ https://fonts.gstatic.com/ https://px4.ads.linkedin.com/collect https://www.linkedin.com/px/ https://ads01.groovinads.com/ https://perf-na1.hsforms.com/embed/v3/counters.gif; manifest-src 'self'; media-src 'self' https://static.zdassets.com; worker-src 'self' *.gympass-staging.com blob:; 2 default-src 'self' https://themes.googleusercontent.com/ https://apps.geodan.nl https://acc.apps.geodan.nl https://platform.twitter.com/ https://syndication.twitter.com/ http://www.rovid.nl https://geodata.rivm.nl https://statistiek.rijksoverheid.nl https://mebi.rivm.nl https://cstm.rivm.nl/ https://cgl-web-api.rivm.nl/ https://acceptatie-cgl-web-api.rivm.nl/ https://data.rivm.nl/ https://chemkap.rivm.nl https://app.powerbi.com/ https://api.pdok.nl/; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://statistiek.rijksoverheid.nl http://platform.twitter.com/ https://cdn.syndication.twimg.com https://mebi.rivm.nl https://cdnjs.cloudflare.com https://cdn.jsdelivr.net https://cstm.rivm.nl/ https://cgl-web-api.rivm.nl/ https://acceptatie-cgl-web-api.rivm.nl/ https://data.rivm.nl/ https://apps.rivm.nl https://chemkap.rivm.nl https://*.mopinion.com https://api.pdok.nl/; object-src https://cstm.rivm.nl/ https://cgl-web-api.rivm.nl/ https://acceptatie-cgl-web-api.rivm.nl/ https://app.powerbi.com/ https://api.pdok.nl/; style-src 'self' 'unsafe-inline' https://platform.twitter.com/ https://ton.twimg.com/ https://mebi.rivm.nl https://cdnjs.cloudflare.com https://cdn.jsdelivr.net https://cstm.rivm.nl/ https://cgl-web-api.rivm.nl/ https://acceptatie-cgl-web-api.rivm.nl/ https://*.mopinion.com https://data.rivm.nl/ https://api.pdok.nl/; img-src 'self' https://rivm.nl/ https://*.rivm.nl/ https://statistiek.rijksoverheid.nl/ https://geodata.nationaalgeoregister.nl/ https://syndication.twitter.com/ https://pbs.twimg.com/ https://ton.twimg.com/ https://abs.twimg.com/ https://platform.twitter.com/ http://abs.twimg.com/ data: http://www.rovid.nl https://cdnjs.cloudflare.com https://cdn.jsdelivr.net https://cstm.rivm.nl/ https://cgl-web-api.rivm.nl/ https://acceptatie-cgl-web-api.rivm.nl/ https://service.pdok.nl/ https://data.rivm.nl/ https://*.openstreetmap.org/ https://chemkap.rivm.nl https://api.pdok.nl/; frame-src 'self' https://cibrapportage.rivm.nl https://esp-ext.rivm.nl https://login-ext.rivm.nl https://chemkap.rivm.nl https://www.infectieradar.nl https://app.powerbi.com https://api.pdok.nl/; frame-ancestors 'self' https://www.atlasleefomgeving.nl https://*.gezondeleefomgeving.nl https://*.woondossier.nl/ https://roosendaal.incijfers.nl https://*.nhnieuws.nl https://chemkap.rivm.nl https://www.infectieradar.nl https://api.pdok.nl/*; child-src https://cstm.rivm.nl/ https://cgl-web-api.rivm.nl/ https://acceptatie-cgl-web-api.rivm.nl/ https://data.rivm.nl/ https://app.powerbi.com https://api.pdok.nl/; font-src 'self' https://rivm.nl/ https://*.rivm.nl/ https://themes.googleusercontent.com/ https://cstm.rivm.nl/ https://*.mopinion.com https://cgl-web-api.rivm.nl/ https://acceptatie-cgl-web-api.rivm.nl/ https://data.rivm.nl/ https://api.pdok.nl/; connect-src 'self' https://mebi.rivm.nl/ https://statistiek.rijksoverheid.nl/ https://statistiek.rijksoverheid.nl/* https://cstm.rivm.nl/ https://cstm.rivm.nl/* https://cgl-web-api.rivm.nl/ https://acceptatie-cgl-web-api.rivm.nl/ https://acc-api.rivm.nl https://api.rivm.nl/ https://api.pdok.nl/* https://*.mopinion.com; report-uri /report-csp-violation 2 default-src https: ; script-src https: 'unsafe-inline' 'unsafe-eval'; style-src https: 'unsafe-inline'; report-uri /csp/ 2 : default-src 'self'; report-uri https://mtsrs.report-uri.com/r/d/csp/reportOnly; 2 default-src 'self'; base-uri 'self'; object-src 'none'; frame-ancestors 'self' https://jadlog.com.br https://www.jadlog.com.b; script-src 'self' https://static.zdassets.com https://www.googletagmanager.com https://ssl.google-analytics.com https://www.google.com https://www.gstatic.com https://static.cloudflareinsights.com https://code.jquery.com https://cdnjs.cloudflare.com https://ajax.cloudflare.com https://pod-27-sunco-ws.zendesk.com; style-src 'self' https://fonts.googleapis.com https://maxcdn.bootstrapcdn.com https://code.jquery.com https://cdnjs.cloudflare.com https://static.zdassets.com https://cdn.cookielaw.org; img-src 'self' data: https://*.tile.openstreetmap.org https://ssl.google-analytics.com https://www.google-analytics.com https://www.google.com; font-src 'self' data: https://fonts.gstatic.com https://maxcdn.bootstrapcdn.com; connect-src 'self' https://cdn.cookielaw.org https://ekr.zdassets.com https://jadloglogsticahelp.zendesk.com https://pod-27-sunco-ws.zendesk.com https://www.googletagmanager.com https://www.google.com https://cloudflareinsights.com; frame-src 'self' https://www.google.com https://jadlog.force.com https://jadloglogsticahelp.zendesk.com; report-uri https://service.jadlog.com.br/csp-report-endpoint; report-to csp-endpoint 2 default-src 'self' 846-hel-222.mktoresp.com 173-dti-322.mktoresp.com 059-alg-683.mktoresp.com js.zi-scripts.com static.addtoany.com stats.g.doubleclick.net tracking-api.g2.com play.google.com www.google.com; connect-src 'self' 846-hel-222.mktoweb.com analytics.google.com c.6sc.co ipv6.6sc.co cdn.cookielaw.org distillery.wistia.com fast.wistia.com pipedream.wistia.com geolocation.onetrust.com epsilon.6sense.com secure.adnxs.com ws.zoominfo.com px.ads.linkedin.com www.google.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net jnn-pa.googleapis.com api.simplecast.com cdn.simplecast.com givebutter.com umsafoundation.org www.youtube.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com pagead2.googlesyndication.com google.com stats.g.doubleclick.net js.zi-scripts.com privacyportal-eu.onetrust.com 846-hel-222.mktoresp.com app.qualified.com tracking-api.g2.com tr.capterra.com 173-dti-322.mktoresp.com embed-cloudfront.wistia.com *.clarity.ms 173-dti-322.mktoutil.com www.google.com.co; font-src 'self' www.perforce.com www.blazemeter.com www.gliffy.com www.jrebel.com www.openlogic.com www.zend.com www.puppet.com www.perfecto.io fonts.gstatic.com cdn.simplecast.com data: fast.wistia.com use.typekit.net www.gartner.com; frame-src 'self' 846-hel-222.mktoweb.com 173-dti-322.mktoresp.com 059-alg-683.mktoresp.com resources.perforce.com static.addtoany.com www.googletagmanager.com www.perforce.com www.blazemeter.com www.gliffy.com www.jrebel.com www.openlogic.com www.zend.com www.puppet.com www.perfecto.io fast.wistia.net player.simplecast.com www.youtube.com umsafoundation.org live-totalview.pantheonsite.io live-imsl.pantheonsite.io www.google.com app.qualified.com fast.wistia.com player.vimeo.com player.captivate.fm 605957.extforms.netsuite.com www.gartner.com; img-src 'self' data: b.6sc.co c.bing.com bat.bing.com *.clarity.ms cdn.cookielaw.org cdn2.hubspot.net embed-ssl.wistia.com f.hubspotusercontent00.net pic.trendemon.com px.ads.linkedin.com trackingapi.trendemon.com analytics.twitter.com cdn.bizible.com cdn.bizibly.com googleads.g.doubleclick.net t.co track.hubspot.com www.facebook.com www.gliffy.com www.google.com www.linkedin.com www.perforce.com www.blazemeter.com www.jrebel.com www.openlogic.com www.zend.com www.puppet.com www.perfecto.io umsafoundation.org live-mondrian.pantheonsite.io i.ytimg.com image.simplecastcdn.com yt3.ggpht.com fast.wistia.net googletagmanager.com ssl.gstatic.com www.gstatic.com *.google-analytics.com *.googletagmanager.com www.googletagmanager.com pagead2.googlesyndication.com www.googleadservices.com google.com www.google.com.tw www.google.mn fast.wistia.com www.google.co.uk www.google.com.br www.google.no fonts.gstatic.com www.google.co.in www.google.com.ec www.google.pl; manifest-src 'self' 846-hel-222.mktoresp.com 173-dti-322.mktoresp.com 059-alg-683.mktoresp.com js.zi-scripts.com static.addtoany.com stats.g.doubleclick.net tracking-api.g2.com play.google.com www.google.com www.perforce.com www.blazemeter.com www.gliffy.com www.jrebel.com www.openlogic.com www.zend.com www.puppet.com www.perfecto.io; media-src 'self' blob: app.qualified.com fast.wistia.com embed-ssl.wistia.com data: embed-fastly.wistia.com embed-cloudfront.wistia.com; object-src 'self'; script-src 'self' 'report-sample' 'unsafe-eval' 846-hel-222.mktoweb.com assets.trendemon.com browser.sentry-cdn.com cdn.cookielaw.org cdn.jsdelivr.net cdnjs.cloudflare.com fast.wistia.com fast.wistia.net googleads.g.doubleclick.net j.6sc.co js.zi-scripts.com munchkin.marketo.net resources.perforce.com *.clarity.ms snap.licdn.com static.addtoany.com static.cloudflareinsights.com trackingapi.trendemon.com tracking.g2crowd.com ct.capterra.com cdn.bizible.com cdn.getmoreproof.com js.hs-analytics.net js.hs-banner.com js.hs-scripts.com connect.facebook.net static.ads-twitter.com p-js.s3.amazonaws.com player.simplecast.com widgets.givebutter.com www.google.com www.googletagmanager.com www.perforce.com www.blazemeter.com www.gliffy.com www.jrebel.com www.openlogic.com www.zend.com www.puppet.com www.perfecto.io umsafoundation.org www.youtube.com googletagmanager.com tagmanager.google.com *.googletagmanager.com www.googleadservices.com pagead2.googlesyndication.com https://cdn.ckeditor.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://code.highcharts.com https://fast.wistia.com https://resources.perforce.com https://resources.roguewave.com https://static.addtoany.com https://unpkg.com info.perforce.com 'nonce-RxD8eGWDWkN-GQval4RCbg'; script-src-elem 'self' feedback.perforce.com js.qualified.com cdn.cookielaw.org googleads.g.doubleclick.net ct.capterra.com gist.github.com j.6sc.co munchkin.marketo.net trackingapi.trendemon.com scripts.clarity.ms js.zi-scripts.com cdnjs.cloudflare.com https://cdn.ckeditor.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://code.highcharts.com https://fast.wistia.com https://resources.perforce.com https://resources.roguewave.com https://static.addtoany.com https://unpkg.com info.perforce.com resources.perforce.com 'nonce-RxD8eGWDWkN-GQval4RCbg'; style-src 'self' 'report-sample' 'unsafe-inline' 846-hel-222.mktoweb.com cdnjs.cloudflare.com resources.perforce.com www.perforce.com www.blazemeter.com www.gliffy.com www.jrebel.com www.openlogic.com www.zend.com www.puppet.com www.perfecto.io fonts.googleapis.com www.youtube.com googletagmanager.com tagmanager.google.com app-ab48.marketo.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://code.highcharts.com https://unpkg.com; style-src-elem 'self' feedback.perforce.com resources.perforce.com www.googletagmanager.com cdnjs.cloudflare.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://code.highcharts.com https://unpkg.com; webrtc 'block'; worker-src 'self' blob:; base-uri 'self'; form-action 'self' https://feedback.perforce.com; frame-ancestors 'self' www.perforce.com 2 img-src https:; script-src https: 'unsafe-inline'; style-src https: 'unsafe-inline'; 2 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://js.hsforms.net https://js.hs-scripts.com https://js.hs-analytics.net https://js-na2.hs-scripts.com https://js-na2.hubspot.com https://js-na2.hscollectedforms.net https://js-na2.hs-banner.com https://js-na2.hs-analytics.net https://www.googletagmanager.com https://*.googletagmanager.com https://www.google-analytics.com https://*.google-analytics.com https://analytics.google.com https://region1.analytics.google.com https://www.google.com https://www.gstatic.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://cdn-cookieyes.com https://*.cookieyes.com https://j.6sc.co https://snap.licdn.com https://connect.facebook.net; style-src 'self' 'unsafe-inline' https://use.typekit.net https://p.typekit.net https://fonts.googleapis.com https://cdn-cookieyes.com; img-src 'self' data: https: http:; font-src 'self' data: https://use.typekit.net https://p.typekit.net https://fonts.gstatic.com https://cdn.jsdelivr.net; connect-src 'self' https://forms.hsforms.com https://forms-na2.hsforms.com https://api.hsforms.com https://cta-na2.hubspot.com https://forms-na2.hscollectedforms.net https://www.googletagmanager.com https://*.googletagmanager.com https://www.google-analytics.com https://*.google-analytics.com https://analytics.google.com https://region1.analytics.google.com https://stats.g.doubleclick.net https://cdn-cookieyes.com https://*.cookieyes.com https://directory.cookieyes.com https://c.6sc.co https://ipv6.6sc.co https://epsilon.6sense.com https://secure.adnxs.com; frame-src 'self' https://www.youtube.com https://www.google.com https://www.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'; upgrade-insecure-requests 2 default-src https: 'unsafe-inline' 'unsafe-eval'; img-src https://* data: ; frame-src https://* about: javascript: 2 default-src 'self' *.commerzbank.de; script-src 'self' *.commerzbank.de 'unsafe-inline' 'unsafe-eval' https://*.googletagmanager.com https://googletagmanager.com https://tagmanager.google.com https://www.googleadservices.com https://www.google.com https://pagead2.googlesyndication.com https://googleads.g.doubleclick.net extend.vimeocdn.com www.facebook.com connect.facebook.net; style-src 'self' *.commerzbank.de 'unsafe-inline' 'unsafe-eval' https://googletagmanager.com https://tagmanager.google.com; frame-src 'self' *.commerzbank.de https://www.googletagmanager.com https://*.fls.doubleclick.net player.vimeo.com; worker-src 'self' *.commerzbank.de; connect-src 'self' *.commerzbank.de https://*.googletagmanager.com https://*.google.com https://google.com https://*.google-analytics.com https://*.analytics.google.com https://ad.doubleclick.net https://*.g.doubleclick.net https://*.google.de https://*.google.bg https://pagead2.googlesyndication.com https://www.googleadservices.com www.facebook.com connect.facebook.net; font-src 'self' *.commerzbank.de data:; img-src 'self' *.commerzbank.de https: data: https://*.googletagmanager.com https://googletagmanager.com https://*.google-analytics.com https://ad.doubleclick.net https://*.g.doubleclick.net https://google.com https://*.google.com https://*.google.de https://*.google.bg https://pagead2.googlesyndication.com https://www.googleadservices.com https://ade.googlesyndication.com https://adservice.google.com www.facebook.com connect.facebook.net; report-uri https://tp.commerzbank.de/csp; 2 default-src 'self' bard.edu www.bard.edu inside.bard.edu tools.bard.edu maps.bard.edu opensocietyuniversitynetwork.org ghea21.org; form-action 'self' bard.edu www.bard.edu tools.bard.edu connect.bard.edu opensocietyuniversitynetwork.org ghea21.org; base-uri 'self' bard.edu www.bard.edu tools.bard.edu opensocietyuniversitynetwork.org ghea21.org; font-src 'self' data: www.bard.edu opensocietyuniversitynetwork.org ghea21.org fonts.gstatic.com *.fontawesome.com cdnjs.cloudflare.com; style-src 'self' 'unsafe-inline' www.bard.edu tools.bard.edu opensocietyuniversitynetwork.org ghea21.org fonts.googleapis.com *.fontawesome.com tagmanager.google.com www.google.com *.technolutions.net static.ctctcdn.com cdnjs.cloudflare.com *.curator.io; script-src 'self' 'unsafe-inline' 'report-sample' www.bard.edu tools.bard.edu connect.bard.edu explore.bard.edu opensocietyuniversitynetwork.org ghea21.org code.jquery.com player.vimeo.com *.fontawesome.com www.google-analytics.com ssl.google-analytics.com *.googletagmanager.com tagmanager.google.com www.google.com cse.google.com googleads.g.doubleclick.net connect.facebook.net consent.cookiebot.com cdn.unibuddy.co www.youvisit.com *.technolutions.net analytics.tiktok.com *.curator.io; img-src 'self' data: bard.edu www.bard.edu inside.bard.edu tools.bard.edu opensocietyuniversitynetwork.org ghea21.org www.facebook.com trck.youvisit.com ssl.gstatic.com www.gstatic.com www.google.com *.google-analytics.com *.googletagmanager.com curator-assets.b-cdn.net; connect-src 'self' www.bard.edu tools.bard.edu opensocietyuniversitynetwork.org ghea21.org *.google-analytics.com *.analytics.google.com analytics.google.com www.google.com *.googletagmanager.com *.doubleclick.net *.technolutions.net analytics.tiktok.com *.curator.io; media-src 'self' www.bard.edu tools.bard.edu opensocietyuniversitynetwork.org ghea21.org player.vimeo.com *.vimeocdn.com www.buzzsprout.com curator-assets.b-cdn.net; object-src 'self' www.bard.edu tools.bard.edu maps.bard.edu opensocietyuniversitynetwork.org ghea21.org; child-src 'self' www.bard.edu tools.bard.edu maps.bard.edu opensocietyuniversitynetwork.org ghea21.org www.youtube.com www.youtube-nocookie.com player.vimeo.com unibuddy.co popcard.unibuddy.co cdn.youvisit.com e.issuu.com; frame-src 'self' www.bard.edu tools.bard.edu maps.bard.edu opensocietyuniversitynetwork.org ghea21.org www.youtube.com www.youtube-nocookie.com player.vimeo.com *.googletagmanager.com *.doubleclick.net unibuddy.co popcard.unibuddy.co cdn.youvisit.com e.issuu.com; frame-ancestors 'self' www.bard.edu tools.bard.edu opensocietyuniversitynetwork.org ghea21.org; 2 default-src 'self' *.adsrvr.org *.google.com *.doubleclick.net *.optimizely.com *.facebook.com *.cookielaw.org *.clarity.ms apps.usw2.pure.cloud www.googletagmanager.com;script-src 'self' 'unsafe-inline' 'unsafe-eval' cdnjs.cloudflare.com cdn.jsdelivr.net code.jquery.com embed.signalintent.com *.optimizely.com cdn.segment.com *.googleapis.com www.googletagmanager.com www.google.com www.gstatic.com *.btttag.com *.bing.com *.app-us1.com *.adsrvr.org *.doubleclick.net *.cookielaw.org www.google-analytics.com *.mypurecloud.com *.googleadservices.com *.pure.cloud *.aptrinsic.com *.bootstrapcdn.com js.monitor.azure.com *.facebook.net *.facebook.com trackcmp.net extractable-finalytics-storage.s3.us-west-2.amazonaws.com extractable-finalytics-stable.s3.us-west-2.amazonaws.com *.cloudfront.net snap.licdn.com www.redditstatic.com;style-src 'self' 'unsafe-inline' use.fontawesome.com use.typekit.net embed.signalintent.com p.typekit.net *.mypurecloud.com *.googleapis.com *.aptrinsic.com *.jsdelivr.net *.bootstrapcdn.com extractable-finalytics-storage.s3.us-west-2.amazonaws.com extractable-finalytics-stable.s3.us-west-2.amazonaws.com *.cloudfront.net;img-src 'self' data: bat.bing.com *.google.com www.google-analytics.com content-cdn.com *.gstatic.com *.googleapis.com www.googletagmanager.com *.facebook.net *.facebook.com *.adsrrvr.org *.doubleclick.net *.yahoo.com *.cookielaw.org *.googlesyndication.com *.ads.linkedin.com embed.signalintent.com insight.adsrvr.org ib.adnxs.com *.reddit.com;font-src 'self' use.fontawesome.com embed.signalintent.com use.typekit.net *.mypurecloud.com *.gstatic.com *.googleapis.com *.cloudfront.net data:;connect-src 'self' ws: wss: *.googlesyndication.com signal-intent-production-back.herokuapp.com cdn.segment.com *.optimizely.com *.cookielaw.org calc-backend-prod.herokuapp.com d.btttag.com *.googleapis.com www.google-analytics.com api.segment.io *.doubleclick.net *.alaskausa.org *.bing.com *.aptrinsic.com *.episerver.net *.visualstudio.com *.google.com *.facebook.com finalyticsdata.com devfinalyticsdata.com stgfinalyticsdata.com px.ads.linkedin.com api-cdn.usw2.pure.cloud pixel-config.reddit.com www.redditstatic.com;worker-src 'self' blob:;block-all-mixed-content 2 report-uri https://partnerize.com?gdsih-csp-report; 2 frame-ancestors 'self'; default-src 'self' https:; script-src 'self' https://checkoutcdn.adyen.com https://www.googletagmanager.com https://www.google-analytics.com https://cdn.jentis.de https://cdn.eye-able.com https://access.eye-able.com https://connect.facebook.net https://bat.bing.com https://p.teads.tv https://c.amazon-adsystem.com https://536002595.collect.igodigital.com https://cdn.evgnet.com https://*.clarity.ms https://c.bing.com https://geobra.my.onetrust.eu https://googleads.g.doubleclick.net https://e.cquotient.com https://cdn.cquotient.com https://*.playmobil.com 'unsafe-inline' 'unsafe-eval'; style-src 'self' https://checkoutcdn.adyen.com https://fonts.googleapis.com https://cdn.jentis.de https://cdn.eye-able.com 'unsafe-inline'; img-src 'self' data: https: blob: https://media.playmobil.com https://playmobil.a.bigcontent.io https://cdn.eye-able.com https://www.facebook.com https://bat.bing.com https://c.amazon-adsystem.com https://googleads.g.doubleclick.net; font-src 'self' data: https: https://fonts.gstatic.com https://cdn.eye-able.com; connect-src 'self' https: wss: https://www.google-analytics.com https://www.googletagmanager.com https://cdn.jentis.de https://access.eye-able.com https://*.clarity.ms https://c.bing.com https://googleads.g.doubleclick.net https://e.cquotient.com; frame-src 'self' https://www.googletagmanager.com https://vars.hotjar.com; object-src 'none'; base-uri 'self'; form-action 'self'; report-uri /_csp-report; report-to csp-endpoint; 2 script-src 'self' 'unsafe-eval' 'unsafe-inline' *.drip.com *.hsappstatic.net *.sleeknote.com *.zdassets.com *.zendesk.com *.hubspot.com *.hubspot.net *.hs-analytics.net *.hs-banner.com *.cloudflare.com *.zi-scripts.com *.g2crowd.com unpkg.com *.tiktok.com *.quora.com *.bing.com *.redditstatic.com *.ads-twitter.com *.licdn.com *.facebook.net *.snapchat.com sc-static.net *.clearbitscripts.com *.dreamdata.cloud *.g2.com ai.g2.com; connect-src 'self' *.drip.com ai.g2.com; 2 default-src 'none'; connect-src 'self' *.siteminder.com 123compareme.com *.123compareme.com *.ada-tray.com *.bookmebob.com *.flip.to *.gtsgapps.com *.hijiffy.com messenger-services.com *.sojern.com *.thehotelsnetwork.com *.triptease.io *.triptease.net *.userguest.com *.theguestbook.com connect.facebook.net *.facebook.com *.edge.sdk.awswaf.com *.paypal.com recaptcha.net *.launchdarkly.com *.newrelic.com bam.nr-data.net *.hotjar.com *.hotjar.io *.googletagmanager.com *.gstatic.com *.google-analytics.com *.google.com *.googlesyndication.com *.googleadservices.com *.g.doubleclick.net *.doubleclick.net *.imgix.net; script-src 'self' 123compareme.com *.123compareme.com *.ada-tray.com *.adatray.com *.bookmebob.com *.flip.to *.gtsgapps.com *.hijiffy.com *.sojern.com *.thehotelsnetwork.com *.triptease.io *.triptease.net *.userguest.com theguestbook.com *.theguestbook.com connect.facebook.net *.edge.sdk.awswaf.com *.paypal.com recaptcha.net *.launchdarkly.com *.newrelic.com bam.nr-data.net *.hotjar.com *.googletagmanager.com *.gstatic.com *.gstatic.cn *.google-analytics.com *.google.com *.googlesyndication.com *.googleadservices.com *.g.doubleclick.net *.doubleclick.net; frame-src 'self' recaptcha.net www.googletagmanager.com *.paypal.com *.triptease.io; img-src 'self' *.imgix.net *.siteminder.com *.paypalobjects.com *.googletagmanager.com *.openstreetmap.org *.adatray.com *.thehotelsnetwork.com data:; style-src 'self' 'unsafe-inline' *.adatray.com *.thehotelsnetwork.com *.userguest.com fonts.googleapis.com; font-src 'self' data: *.adatray.com *.thehotelsnetwork.com *.userguest.com fonts.gstatic.com; report-to cspendpoint; report-uri https://csp-report.siteminder.com/api/quokka/booking-engine/report; frame-ancestors 'self' 2 form-action *.facebook.com; default-src 'self' 'unsafe-eval' 'unsafe-hashes' 'unsafe-inline' data: blob: *.fls.doubleclick.net *.doubleclick.net *.hotjar.com *.hotjar.io wss://*.hotjar.com *.omtrdc.net *.twitter.com covers.odilo.io *.ads-twitter.com *.facebook.com *.facebook.net cdn.cookielaw.org *.googletagmanager.com *.googleadservices.com online.bancosantander.es a.omappapi.com *.googleapis.com extend.vimeocdn.com t.co adservice.google.com *.linkedin.com *.google-analytics.com *.santanderopenacademy.com *.universia.net fonts.gstatic.com in-automate.sendinblue.com z.omappapi.com api.omappapi.com snap.licdn.com images.findawayworld.com *.tiktok.com privacyportal-de.onetrust.com sibautomation.com use.typekit.net pro-becas-images-s3.s3.eu-west-1.amazonaws.com santander-privacy.my.onetrust.com; frame-ancestors 'self' *.santanderopenacademy.com *.googletagmanager.com; connect-src 'self' cdn.equalweb.com *.universia.net pro-becas-images-s3.s3.eu-west-1.amazonaws.com www.linkedin.com script.hotjar.com img.youtube.com px4.ads.linkedin.com t.co surveystats.hotjar.io analytics.twitter.com www.google.es mboxedge37.tt.omtrdc.net santanderuniversidad.tt.omtrdc.net www.googletagservices.com www.google.ie www.facebook.com cdn.cookielaw.org googleads.g.doubleclick.net stats.g.doubleclick.net www.google.com pagead2.googlesyndication.com *.analytics.google.com vc.hotjar.io metrics.hotjar.io wss://ws.hotjar.com ws.hotjar.com content.hotjar.io *.google-analytics.com px.ads.linkedin.com analytics.tiktok.com *.pangle-ads.com *.omappapi.com *.vimeo.com *.santanderopenacademy.com *.googlesyndication.com *.onetrust.com *.tiktokw.us sc-static.net *.sc-static.net snapchat.com *.snapchat.com onetrust.com *.onetrust.com omtrdc.net *.omtrdc.net analytics.google.com *.google.com *.adoberesources.net adoberesources.net *.adobedc.net adobedc.net *.demdex.net demdex.net; font-src 'self' script.hotjar.com fonts.gstatic.com data:; frame-src 'self' www.youtube.com www.google.com *.doubleclick.net track.adform.net www.facebook.com *.universia.net universia.net *.santanderopenacademy.com *.vimeo.com doubleclick.net *.doubleclick.net; img-src 'self' data: *.santanderopenacademy.com *.santanderx.com dss.hybrid.ai su-commons-documents.s3.eu-west-1.amazonaws.com pro-becas-images-s3.s3.eu-west-1.amazonaws.com i.ytimg.com non-productive-alfred-s3.s3.eu-west-1.amazonaws.com *.universia.net img.youtube.com cdn.cookielaw.org www.facebook.com fonts.gstatic.com www.google.ie www.google.com www.google.es *.googletagmanager.com *.google-analytics.com px.ads.linkedin.com px4.ads.linkedin.com t.co analytics.twitter.com covers.odilo.io images.findawayworld.com *.doubleclick.net *.odilotk.es *.googlesyndication.com snapchat.com *.snapchat.com; manifest-src 'self'; media-src 'self' data: *.santanderopenacademy.com *.santanderx.com; object-src 'none'; script-src 'self' 'unsafe-eval' 'unsafe-inline' emd.hybrid.ai *.hybrid.ai pixel.wp.pl www.google.com 'sha256-YSegCmpoY/9vy6z9Jp/wY5F+2CZOSO85IpkqRDamw6o=' 'sha256-8UQUF8T5SdG0xN7U0SziZK/tE7Mx20WlIEvrhPZS+5c=' 'sha256-ZC4Ihfl+1sv3E25DQh090ITQKwffxiocyA9C1vaePKU=' 'sha256-y+EdpRp7NGzuxDREjdSGXuM2ZRxY/zPRIps6hzHQOcU=' 'sha256-ZC4Ihfl+1sv3E25DQh090ITQKwffxiocyA9C1vaePKU=' 'sha256-HbtNuErO4Ji0X7sd59L8NfJYuQk3WllCWK3gVuRMpfM=' 'sha256-BBirXJiJdwXRuf4PKdCNfYQLT8mhwGu68gkk2lfCqN8=' 'sha256-9gh4m8bsTLdMvKZ358mYZY2d+f5k+bk+APY/b3jwy1o=' 'sha256-xeKH9HwGHVm84iWqrxisQix9T08PGSCZTxFIO4+ewWk=' 'sha256-DwzQ63XCPWPBU9VhenPaZeU1L0tiiqJkkaWArzaMA14=' 'sha256-5t573MY7H7LQK71Vf2b+RoOG9NlBxHctIHdMjVPJIE0=' 'sha256-ZxrnaNw21FtNs0hG3ejrGPJWMFqp2c2scn3dGBS7Xtk=' 'sha256-DaJ5+aVVCCwmIoJpsto8Q2FfkqVlML3utJdn4mDMGD0=' 'sha256-Fj/OzUbSCuycXsQO3rkxgJpOQcr0O4grKcZDUi0FIiU=' 'sha256-L89rOqVn3e1Yeav7YFzFH7bxGr1IyHtjhNxYvrcVL4E=' 'sha256-g2T0Peh4PkAjcTj+CFHeM0y83Uuh+6W/+Ay4nUyncSo=' 'sha256-BpTz1JC47PMe4NhdM7n0gmuvr+83Jo3c+LLXav8o+Wc=' 'sha256-+i46atGTJGrevoy/LaA/uxqfIvacu6J/34f4LYs4FLU=' 'sha256-NW1gvrymt4M+SBgRpB7GKpbvkiAcBF120jBugIgwTkY=' 'sha256-TCOS0LXlyOYGx+xlpfAYkRxyaOiYLTlRzHwI0YQSm3Q=' 'sha256-XdoX181xfRJT12LmChyU6l4zxvoIsaAHf4FxTHoJM+I=' 'sha256-NKT4ofJEPzU1gDi1WITFInJvz8potrsIe5i+LSnCKqo=' 'sha256-w6kdg/3YV4tBVkaDe4i2aktYPtaPLEHNIGHKOXJ7aZI=' 'sha256-7OI/iFnRHuxJU3EbXDhDFX6g3cZ0C1I8U6VTbbk7bPw=' 'sha256-VY8NVZZ8EZKkngWGPFlpnC0jlPPS4naDQeeIKqLpgUU=' 'sha256-3ThNsno0lln5H88qDcBDPljNxQaOgkPiulXpM/OsV1s=' 'sha256-8N1I80yqbb8/sRov2zmhZf1nwe9Hd8PifhnSJaDP664=' 'sha256-LG4xcV34tsaAdFNYuH8Lr84Ovn0ZnSV2GoIA+TiLP5s=' 'sha256-y36RoFUJWgc8gbl/5Pk2/0bsYv2bJ+bMa8Y4LV/Wz/k=' 'sha256-IgMQOOOedQeMPBl7lSreMVPmJvU62bc6l8HcsGXnbWc=' 'sha256-3FPxyKucOIUnwkis1jUlVWeg63ttBCdsnPZ7d1/U9vQ=' 'sha256-lBxE5qVCAIfADFr1+pdyVxAP7I/YVviosUAsCf3pZtU=' 'sha256-3iXpidN34sHSaOL+oY8lqqkqIs8qgMSZmmFOyyyJq5o=' 'sha256-TZjz12EnkJLarfuyWy8NqZ9HG8RpIuFAlQySbT4/4h8=' 'sha256-Y4y/Z3pJNei7wFfh20klvIrbZiajvE/JWO1KhI668Xo=' 'sha256-LigV2Z6/JVA57qW0q8wSx849ylkhI35JZTPqGObl9ks=' 'sha256-83sIN1kEH+EziQHRTaQiSWImOUtv0wFFfa74npfXyoE=' 'sha256-BMIPp0uCJPYMdHFyQdug09fBOv1yC4c3ATQ5HIB8lnU=' 'sha256-mkZ77JgvPSMOW/FuYQr4tf+Z2qIq0e/ozaNEcVp9eyc=' cdn.jsdelivr.net cdn.equalweb.com code.jquery.com track.adform.net s2.adform.net www.googletagservices.com cdn.cookielaw.org googleads.g.doubleclick.net connect.facebook.net static.hotjar.com metrics.hotjar.io script.hotjar.com *.googletagmanager.com *.google-analytics.com snap.licdn.com static.ads-twitter.com analytics.tiktok.com *.googleapis.com pro-becas-images-s3.s3.eu-west-1.amazonaws.com *.gstatic.com *.omappapi.com *.googleadservices.com *.santanderopenacademy.com *.googlesyndication.com sc-static.net *.sc-static.net snapchat.com *.snapchat.com onetrust.com *.onetrust.com omtrdc.net *.omtrdc.net analytics.google.com *.google.com *.adoberesources.net adoberesources.net *.adobedc.net adobedc.net *.demdex.net demdex.net st.hybrid.ai; style-src 'self' 'unsafe-inline' stackpath.bootstrapcdn.com *.googletagmanager.com fonts.googleapis.com *.omappapi.com; worker-src *.universia.net 2 default-src *; font-src 'self' https: data:; img-src * blob: data:; object-src 'none'; script-src * 'unsafe-inline' 'unsafe-eval'; script-src-attr 'self' 'unsafe-inline'; style-src * 'unsafe-inline'; base-uri 'self'; form-action 'self' http://*.enterprisedb.com http://enterprisedb.com http://enterprisedb.okta.com; frame-ancestors 'self'; report-uri https://www.enterprisedb.com/log-report-uri/reportOnly 2 worker-src https: 'unsafe-inline'; report-uri https://api.mp.pl/csp-violation/ 2 default-src 'self' 'unsafe-inline' 'unsafe-eval' data: blob: *.abtasty.com abtasty.com api-data-connector.abtasty.com ariane.abtasty.com assets-manager.abtasty.com common-fonts.abtasty.com dcinfos-cache.abtasty.com try.abtasty.com *.ipredictive.com ipredictive.com *.everesttech.net everesttech.net *.typekit.net typekit.net amazonaws.com execute-api.us-west-2.amazonaws.com us-east-2.amazonaws.com socialannex.com *.adnxs.com adnxs.com *.auryc.com auryc.com *.bidr.io prod.bidr.io *.bing.com *.bing.net bat.bing.net bing.com *.brxcdn.com brxcdn.com *.btttag.com btttag.com *.builder.io builder.io *.cloudflare.com cdnfonts.com cloudflare.com *.cloudfront.net cloudfront.net *.cloudinary.com cloudinary.com *.cnstrc.com cnstrc.com *.contentsquare.net bf.contentsquare.net contentsquare.net hj.contentsquare.net criteo.com g.doubleclick.net *.doubleclick.net doubleclick.net fls.doubleclick.net *.dstillery.com dstillery.com media6degrees.com *.facebook.com *.facebook.net facebook.com facebook.net *.getfastr.com getfastr.com *.iesnare.com iesnare.com *.google.com *.googlesyndication.com *.gstatic.com analytics.google.com google.bs google.ca google.co.cr google.co.il google.co.in google.co.jp google.co.th google.co.uk google.co.vi google.com google.com.ar google.com.br google.com.bz google.com.co google.com.hk google.com.mx google.com.my google.com.pa google.com.ph google.com.pk google.com.pr google.com.sa google.com.sv google.com.tr google.de google.fr google.hn google.hr google.ie google.it google.nl google.se google.sk google.tt googlesyndication.com gstatic.com googleadservices.com *.googleapis.com googleapis.com *.googletagmanager.com googletagmanager.com *.google-analytics.com google-analytics.com *.fsastore.com *.hsastore.com *.welldeservedhealth.com fsastore.com hsastore.com welldeservedhealth.com *.heapanalytics.com heapanalytics.com us.heap-api.com ip-api.com *.izooto.com izooto.com jquery.com listrak.com listrakbi.com liadm.com *.pcapredict.com pcapredict.com bing.net *.clarity.ms mountain.com *.northbeam.io northbeam.io *.oursprivacy.com oursprivacy.com *.pepperjam.com *.pepperjamnetwork.com pepperjam.com pepperjamnetwork.com *.pinimg.com *.pinterest.com pinimg.com pinterest.com *.pdst.fm *.powerreviews.com powerreviews.com *.riskified.com riskified.com disstg.commercecloud.salesforce.com *.segment.com *.segment.io segment.com segment.io ingest.sentry.io *.spotify.com *.mobify-storefront.com mobify-storefront.com alocdn.com *.adsrvr.org adsrvr.org *.trustarc.com trustarc.com acsbapp.com postcodeanywhere.co.uk zma.gs *.youtube.com *.ytimg.com youtube.com ytimg.com *.zdassets.com *.zendesk.com zdassets.com zendesk.com zopim.com *.zmags.com creator-prod.zmags.com zmags.com zmags.workers.dev adlucent.com deepsearch.adlucent.com delighted.com google.com.au google.com.pe google.com.sg heap-api.com *.paypalobjects.com paypalobjects.com; frame-ancestors capacitor://localhost; 2 default-src 'self'; script-src 'self' *.argenta.be argenta-aam.be *.argenta-aam.be *.googleapis.com *.adobedtm.com *.googletagmanager.com *.doubleclick.net *.adsrvr.org *.teads.tv *.facebook.net *.hotjar.com *.tiqcdn.com *.pingdom.net *.google.ie 'unsafe-inline' 'unsafe-eval' wasm-eval; style-src 'self' 'unsafe-inline'; object-src 'none'; base-uri 'self'; connect-src 'self' https://agentaspaarbank.tt.omtrdc.net *.googleapis.com *.simargenta.be *.argenta.be argenta-aam.be *.argenta-aam.be *.teads.tv *.googlesyndication.com *.pingdom.net *.google.com; font-src 'self'; frame-src 'self' *.tst-argenta.be *.argenta-aam.be *.adsrvr.org *.teads.tv *.doubleclick.net *.googletagmanager.com; img-src 'self' *.argenta.be *.simargenta.be argenta-aam.be *.argenta-aam.be *.facebook.com *.google.be *.google.com *.google.ie *.teads.tv *.gstatic.com; manifest-src 'self'; media-src 'self'; worker-src 'none'; 2 default-src 'self' 'unsafe-inline' data: *.squaretrade.com *.facebook.com *.outbound.io *.auth0.com *.launchdarkly.com *.pndsn.com *.googleapis.com *.google.com *.googletagmanager.com *.google-analytics.com https://api.segment.io https://api.amplitude.com https://privacyportal-eu.onetrust.com https://secure.shippingapis.com https://st-prod-enc-ship-usw-ca.s3.us-west-1.amazonaws.com https://st-prod-enc-ship-use-oh.s3.us-east-2.amazonaws.com https://st-stage-enc-cust-docs-use-oh-1.s3.us-east-2.amazonaws.com https://callback.vhtcx.com https://callback.virtualhold.com https://siteintercept.qualtrics.com https://squaretrade.my.site.com https://squaretrade--qa.sandbox.my.salesforce-scrt.com https://squaretrade--qa.sandbox.my.site.com; form-action 'self' data: *.squaretrade.com *.force.com *.salesforce.com *.auth0.com; frame-ancestors 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' data: *.squaretrade.com *.auth0.com https://cdn.segment.com *.bootstrapcdn.com *.force.com *.salesforce.com *.qualtrics.com https://platform.twitter.com; font-src 'self' data: *.squaretrade.com https://fonts.gstatic.com https://use.typekit.net; img-src 'self' data: *.squaretrade.com *.auth0.com *.facebook.com https://p.typekit.net *.google.com *.twitter.com https://st-prod-enc-ship-usw-ca.s3.us-west-1.amazonaws.com https://st-prod-enc-ship-use-oh.s3.us-east-2.amazonaws.com https://cdn.cookielaw.org https://www.googletagmanager.com https://fonts.gstatic.com https://pay.google.com https://checkoutshopper-test.cdn.adyen.com https://m.media-amazon.com https://bfasset.costcostatic.com https://maps.googleapis.com; style-src-elem 'self' 'unsafe-inline' *.squaretrade.com https://hello.myfonts.net https://service.force.com https://fonts.googleapis.com https://cdnjs.cloudflare.com https://static.smartrecruiters.com https://cdn.jsdelivr.net *.bootstrapcdn.com https://www.googletagmanager.com *.my.site.com https://www.gstatic.com; script-src-elem 'self' *.squaretrade.com 'unsafe-inline' *.salesforceliveagent.com https://cdn.segment.com https://cdn.amplitude.com https://cdn.outbound.io https://connect.facebook.net https://www.googletagmanager.com https://service.force.com https://use.typekit.net https://www.googleadservices.com https://googleads.g.doubleclick.net https://www.google.com https://www.gstatic.com https://code.jquery.com https://ajax.googleapis.com https://platform.twitter.com *.bootstrapcdn.com https://cdn.jsdelivr.net *.smartrecruiters.com https://player.vimeo.com https://zn8jglatqcy5dkma1-squaretrade.siteintercept.qualtrics.com https://*.siteintercept.qualtrics.com https://siteintercept.qualtrics.com https://cdn.cookielaw.org https://www.youtube.com https://uat-api.paylution.com https://api.paylution.com https://zingtree.com https://squaretrade--qa.sandbox.my.site.com https://maps.googleapis.com; frame-src 'self' *.squaretrade.com https://service.force.com https://squaretrade.az1.qualtrics.com/ https://www.google.com https://www.facebook.com https://platform.twitter.com *.doubleclick.net https://www.googletagmanager.com https://zingtree.com https://www.youtube.com https://checkoutshopper-test.adyen.com https://squaretrade--qa.sandbox.my.site.com https://squaretrade.my.salesforce-scrt.com; connect-src 'self' *.squaretrade.com *.auth0.com https://cdn.cookielaw.org https://www.google.com https://privacyportal-eu.onetrust.com https://cdn.segment.com https://cdn.segment.io https://api.segment.io https://uat-api.paylution.com https://checkoutshopper-test.adyen.com https://checkoutshopper-live.adyen.com https://checkoutanalytics-test.adyen.com https://siteintercept.qualtrics.com https://st-stage-enc-cust-docs-use-oh-1.s3.us-east-2.amazonaws.com https://www.googletagmanager.com https://geolocation.onetrust.com *.launchdarkly.com https://region1.google-analytics.com https://secure.shippingapis.com https://squaretrade.my.salesforce-scrt.com https://squaretrade--qa.sandbox.my.salesforce-scrt.com https://www.facebook.com https://svc-api-int-1.qa1.squaretrade.com:20000 https://svc-api-int-1.qa2.squaretrade.com:20000 https://svc-api-int-1.qa3.squaretrade.com:20000 https://svc-api-int-1.qa4.squaretrade.com:20000 https://svc-api-int-1.qa5.squaretrade.com:20000 https://svc-api-int-1.qa6.squaretrade.com:20000 https://svc-api-int-1.qa7.squaretrade.com:20000 https://svc-api-int-8.qa1.squaretrade.com:20000 https://svc-api-int-1.stage.squaretrade.com:20000 https://svc-api-int-1.production.squaretrade.com:20000 https://maps.googleapis.com; 2 default-src *; script-src * 'unsafe-inline' 'unsafe-eval'; style-src * 'unsafe-inline'; img-src * data: blob:; font-src * data:; media-src * blob:; worker-src * blob:; frame-src * data: blob:; connect-src *; frame-ancestors 'none'; report-uri /csp-violation-report 2 default-src 'self' 'unsafe-inline' 'unsafe-eval' data: ; img-src 'self' data: secure.gravatar.com www.gravatar.com; report-uri https://www.veracode.com?gdsih-csp-report; 2 base-uri 'self';connect-src 'self' https://www.google-analytics.com https://*.googleapis.com https://api.rudderlabs.com https://hosted.rudderlabs.com https://rudderstack.taskade.cloud https://api.stripe.com https://checkout.stripe.com https://sentry.io wss: https://cn2bi8ujy8.execute-api.us-east-1.amazonaws.com https://taskade-files.s3.us-east-1.amazonaws.com https://files.taskade.com https://vimeo.com https://fast.wistia.com https://*.loom.com https://www2.profitwell.com https://api.canny.io https://companion.taskade.com;default-src 'self';form-action 'self';media-src 'self' https://js.driftqa.com https://files.taskade.com;script-src 'self' 'unsafe-eval' 'unsafe-inline' https://ajax.cloudflare.com https://challenges.cloudflare.com https://js.driftt.com https://widget.drift.com https://www.googletagmanager.com https://www.google-analytics.com https://ssl.google-analytics.com https://checkout.stripe.com https://js.stripe.com https://www.youtube.com https://player.vimeo.com https://fast.wistia.com https://r.wdfl.co https://public.profitwell.com https://cdn.firstpromoter.com https://canny.io https://pa.taskade.com https://unicorn.taskade.workers.dev https://static.cloudflareinsights.com;object-src 'none';img-src 'self' data: https://www.googletagmanager.com https://www.google-analytics.com https://*.stripe.com https://files.taskade.com https://unpkg.com https://i.ytimg.com https://*.sndcdn.com https://i.vimeocdn.com https://*.wistia.com https://cdn.loom.com https://*.figma.com https://images.typeform.com https://*.whimsical.com https://companion.taskade.com;style-src 'self' 'unsafe-inline' https://cdnjs.cloudflare.com https://fonts.googleapis.com;font-src 'self' data: https://fonts.gstatic.com https://fonts.googleapis.com;frame-src https://js.driftt.com https://widget.drift.com https://checkout.stripe.com https://hooks.stripe.com https://js.stripe.com https://call.taskade.com https://docs.taskade.com https://*.youtube.com https://*.soundcloud.com https://player.vimeo.com https://*.loom.com https://*.figma.com https://*.invisionapp.com https://*.typeform.com https://*.whimsical.com;report-uri /webhooks/csp-report;report-to /webhooks/csp-report;frame-ancestors 'none' 2 default-src 'self'; script-src-elem 'self' 'unsafe-inline' https://saf-sc-protect.com https://hubspotonwebflow.com https://www.rentracks.jp https://b98.yahoo.co.jp https://ichisan.jp https://sc.lfeeder.com https://trc.taboola.com https://b99.yahoo.co.jp https://static.ads-twitter.com https://bat.bing.com https://s.yimg.jp https://platform.twitter.com https://d.line-scdn.net https://cdn.taboola.com https://m.vpadn.com https://funnel-assets.startappservice.com https://tools.refokus.com https://*.intercomcdn.com https://*.intercom.io https://*.jsdelivr.net https://js.hsforms.net https://*.visualwebsiteoptimizer.com https://snap.licdn.com https://connect.facebook.net https://tracking.g2crowd.com https://*.spideraf.com https://*.hscollectedforms.net https://*.hs-analytics.net https://*.hsadspixel.net https://*.hs-banner.com https://*.hubspot.com https://*.clarity.ms https://googleads.g.doubleclick.net https://*.hs-scripts.com https://*.webflow.com https://*.jetboost.io https://*.website-files.com https://www.googletagmanager.com https://*.googleapis.com https://*.jquery.com https://*.cloudfront.net https://cdn-cookieyes.com https://sp-trk.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://*.webflow.com https://www.googletagmanager.com https://*.googleapis.com https://*.jquery.com https://*.cloudfront.net https://cdn-cookieyes.com https://*.intercom.io https://sp-trk.com https://*.jetboost.io https://*.visualwebsiteoptimizer.com https://*.cloudflare.com; style-src 'self' 'unsafe-inline' https://*; font-src 'self' data: https://*; img-src 'self' data: blob: https://*; connect-src 'self' https://*; frame-src 'self' https://*; worker-src 'self' blob:; object-src 'none'; report-uri https://saf-sitescan.com/api/csp-report/4rjsitdq; 2 script-src 'self' https://challenges.cloudflare.com https://hcaptcha.com https://static.cloudflareinsights.com https://*.hcaptcha.com https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://www.recaptcha.net/recaptcha/ https://www.google-analytics.com/ https://www.googletagmanager.com/; base-uri 'self'; object-src 'self'; report-uri /cdn-cgi/script_monitor/report 2 default-src 'self' https://nexo.com *.nexo.com *.nexo.io cdn.segment.com https://cdn.cookielaw.org https://geolocation.onetrust.com https://nexoio.my.salesforce-scrt.com https://widget.trustpilot.com https://appleid.cdn-apple.com https://www.apple.com https://browser-intake-datadoghq.eu https://region1.analytics.google.com https://region1.google-analytics.com https://events.eu1.segmentapis.com https://www.googletagmanager.com https://accounts.google.com https://www.gstatic.com https://fonts.gstatic.com *.geetest.com wss://platform.nexo.com https://nexoio.my.site.com; frame-ancestors https://platform.nexo.io https://platform.nexo.com https://support.nexo.io https://support.nexo.com https://nexosurvey.force.com https://nexoio.lightning.force.com https://nexoio--c.visualforce.com; report-uri https://security-logging.nexo.com; 2 frame-ancestors https://*.walmart.com;report-uri https://csp-report.browser-intake-datadoghq.com/api/v2/logs?dd-api-key=pub4ebf0f2c2b22f7e232e33c048c5f3d2b&dd-evp-origin=content-security-policy&env=prod&ddsource=csp-report&ddtags=service:marketing-web 2 default-src https: wss: 'unsafe-inline' 'unsafe-eval'; img-src https: data: blob:; worker-src blob: 'self'; font-src https: data: 'unsafe-inline' 'unsafe-eval'; media-src https: wss: blob: data: 'unsafe-inline' 'unsafe-eval'; frame-ancestors 'none' 2 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://*.pike13.com https://cdnjs.cloudflare.com https://connect.facebook.net https://platform.linkedin.com https://platform.twitter.com https://snap.licdn.com https://tracking.g2crowd.com https://*.google.com https://*.gstatic.com https://www.google-analytics.com https://www.googletagmanager.com https://*.doubleclick.net https://*.hotjar.com https://*.hs-analytics.net https://*.hs-banner.com https://*.hs-scripts.com https://*.hsadspixel.net https://*.hscollectedforms.net https://*.hsforms.net https://*.hubspot.com https://*.hubspotusercontent-na1.net https://*.hsappstatic.net https://*.hubapi.com https://*.wufoo.com; style-src 'self' 'unsafe-inline'; style-src-elem 'self' 'unsafe-inline' https://*.pike13.com https://fonts.googleapis.com https://*.hsappstatic.net https://*.hsforms.net https://*.hubspotusercontent-na1.net; font-src 'self' https://*.pike13.com https://fonts.gstatic.com https://*.hubspotusercontent-na1.net https://www.google.com; img-src 'self' https://*.pike13.com https://*.hubspot.com https://*.hubspot.net https://*.hsforms.com https://*.hubspotusercontent-na1.net https://*.hsforms.com https://*.linkedin.com https://*.hsappstatic.net https://*.facebook.com https://*.facebook.net https://*.google.com https://*.googletagmanager.com https://*.twitter.com; connect-src 'self' https://*.pike13.com https://analytics.google.com https://hubspot-forms-static-embed.s3.amazonaws.com https://px.ads.linkedin.com https://www.google-analytics.com https://www.google.com https://*.hs-banner.com https://*.hscollectedforms.net https://*.hs-collectedforms.net https://*.hsforms.net https://*.hsforms.com https://*.hubapi.com https://*.hubspot.com https://*.doubleclick.net; frame-src 'self' https://*.pike13.com https://*.hs-sites.com https://*.googletagmanager.com https://*.google.com https://*.facebook.com https://*.twitter.com; object-src 'none'; worker-src 'none'; base-uri 'self'; manifest-src 'self'; media-src 'self'; report-uri https://pike13.report-uri.com/r/d/csp/wizard; 2 font-src fonts.gstatic.com use.typekit.net *.googleapis.com fonts.googleapis.com https://fonts.gstatic.com *.fontawesome.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com data: static.curations.bazaarvoice.com maxcdn.bootstrapcdn.com cdn.dynamicyield.com *.hotjar.com x.klarnacdn.net *.yotpo.com *.gstatic.com data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net pilot-payflowlink.paypal.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com api.bazaarvoice.com stg.api.bazaarvoice.com www.facebook.com *.wahooligan.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com 'self'; frame-src fast.amc.demdex.net *.adobe.com secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.googletagmanager.com js.stripe.com *.affirm.com *.affirm.ca *.certcapture.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com https://www.googletagmanager.com/ *.refersion.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com insight.adsrvr.org match.adsrvr.org www.affirm.com sandbox.affirm.com *.attn.tv bugcrowd.com imgs.cdn-btsg.com *.cloudfront.net consentag.eu track.cordial.io gum.criteo.com bid.g.doubleclick.net *.fls.doubleclick.net td.doubleclick.net www.facebook.com script.google.com *.googleapis.com *.hotjar.com *.iterable.com *.klarnaservices.com *.online-metrix.net privacyportal-cdn.onetrust.com imgs.signifyd.com *.vimeo.com vimeo.com *.wahooligan.com record.webeyez.com d.emails.wahoofitness.com wahoofitness.yonyx.com *.yotpo.com https://*.online-metrix.net https://imgs.signifyd.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com p.typekit.net *.googleapis.com *.gstatic.com maps.googleapis.com maps.gstatic.com *.affirm.com *.affirm.ca *.certcapture.com display.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com network-a.bazaarvoice.com network-stg-a.bazaarvoice.com photos-uat-us.bazaarvoice.com img.youtube.com https://helloextend-static-assets.s3.amazonaws.com https://extendcoreoffersdemo-offersthemelogobucketeb21afa-19jnurg0a0o17.s3.amazonaws.com https://s3.amazonaws.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ www.googletagmanager.com *.adnxs.com public.adobecc.com data.adxcel-ec2.com insight.adsrvr.org match.adsrvr.org *.amazonaws.com *.atdmt.com *.bing.com *.bazaarvoice.com imgs.cdn-btsg.com *.clarity.ms cdn.cookielaw.org dis.criteo.com gum.criteo.com *.ctnsnet.com ad.doubleclick.net cm.g.doubleclick.net stats.g.doubleclick.net cdn.dynamicyield.com www.facebook.com *.google.com *.googletagmanager.com *.hotjar.com humango.ai *.iterable.com kcc0.com www.kinomap.com *.klarnaevt.com *.klarnaservices.com *.klarnauserservices.com *.ktxlytics.io www.lightboxcdn.com simage2.pubmatic.com alb.reddit.com *.rudderstack.com imgs.signifyd.com image.simplecastcdn.com t.co tk0x1.com *.wahoofitness.com *.xg4ken.com ads.yahoo.com *.analytics.yahoo.com *.yotpo.com https://imgs.signifyd.com https://*.online-metrix.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com www.sandbox.paypal.com t.paypal.com s.ytimg.com *.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googletagmanager.com www.gstatic.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com js.stripe.com *.affirm.com *.affirm.ca *.certcapture.com apps.bazaarvoice.com apps.nexus.bazaarvoice.com apps-stg.nexus.bazaarvoice.com analytics-static.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com mpsnare.iesnare.com https://*.helloextend.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ *.avada.io *.refersion.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com unsafe-inline *.adnxs.com js.adsrvr.org cdn.jsdelivr.net lightboxapi.azurewebsites.net cdn.attn.tv bam-cell.nr-data.net *.bazaarvoice.com bat.bing.com bugcrowd.com assets.bugcrowdusercontent.com imgs.cdn-btsg.com *.clarity.ms static.curations.bazaarvoice.com consentag.eu cdn.cookielaw.org track.cordial.io script.crazyegg.com static.criteo.net sslwidget.criteo.com *.ctnsnet.com cdn.dynamicyield.com st.dynamicyield.com connect.facebook.net *.fontawesome.com *.getroster.com *.google.com googleads.g.doubleclick.net *.hotjar.com *.iterable.com *.ktxlytics.io www.lightboxcdn.com cdn.livesession.io i.loopme.me js-agent.newrelic.com bam.nr-data.net code.jquery.com eu-library.klarnaservices.com eu-library.playground.klarnaservices.com oc-library.klarnaservices.com oc-library.playground.klarnaservices.com x.klarnacdn.net geolocation.onetrust.com h64.online-metrix.net cdn.optimizely.com www.redditstatic.com www.refersion.com assets.reflow.tv *.rudderlabs.com *.rudderstack.com cdn.segment.com imgs.signifyd.com *.stackadapt.com static.ads-twitter.com analytics.twitter.com modelviewer.dev d.emails.wahoofitness.com forms.wahoofitness.com record.webeyez.com sec.webeyez.com *.xg4ken.com *.yotpo.com www.youtube.com https://cdn-scripts.signifyd.com https://imgs.signifyd.com https://h64.online-metrix.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.certcapture.com display.ugc.bazaarvoice.com https://fonts.googleapis.com *.fontawesome.com static.curations.bazaarvoice.com maxcdn.bootstrapcdn.com cdn.cookielaw.org cdn.dynamicyield.com *.hotjar.com www.lightboxcdn.com x.klarnacdn.net *.stackadapt.com forms.wahoofitness.com *.yotpo.com *.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ *.bazaarvoice.com data: mpsnare.iesnare.com www.wahoofitness.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com *.adobe.io performance.typekit.net *.sentry.io geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.googleapis.com *.affirm.com *.affirm.ca *.certcapture.com api.bazaarvoice.com stg.api.bazaarvoice.com apps.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com https://*.helloextend.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ *.refersion.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.attentivemobile.com *.attn.tv bam-cell.nr-data.net *.bing.com imgs.cdn-btsg.com *.clarity.ms cdn.cookielaw.org track.cordial.io script.crazyegg.com i.ctnsnet.com stats.g.doubleclick.net *.dynamicyield.com www.facebook.com *.getroster.com analytics.google.com *.analytics.google.com *.hotjar.com *.hotjar.io mpsnare.iesnare.com *.iterable.com wss: gdpr.loopme.com i.loopme.me *.klarnaservices.com *.klarnauserservices.com *.ktxlytics.io rs.livesession.io bam.nr-data.net *.onetrust.com insight.reflow.tv *.rollbar.com *.rudderstack.com api.segment.io cdn.segment.com imgs.signifyd.com bt.signifyd.com bt.signifyd.com:1103 bt.signifyd.com:11103 d.emails.wahoofitness.com vimeo.com record.webeyez.com send.webeyez.com *.yotpo.com https://imgs.signifyd.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://www.wahoofitness.com/nullreport/report/nullendpoint; report-to report-endpoint; 2 default-src 'self'; script-src 'self' 'unsafe-eval' 'unsafe-inline' unpkg.com fonts.googleapis.com cludo.com customer.cludo.com api.cludo.com *.cookiebot.com siteimprove.com *.siteimprove.com *.siteimproveanalytics.io *.google.com *.newrelic.com newrelic.com *.23video.com *.gstatic.com *.rm.dk *.analysefortegnelsen.dk connect.facebook.net/en_US/sdk.js *.rm.dk *.regionshospitalet-horsens.dk *.cpropslagqa.rm.dk *.cpropslagtest.rm.dk auh.intranet.rm.dk alvorligpatologi.dk auh.dk danishairambulance.dk danishneurosciencecenter.dk desikredeinstitutioner.dk diabetes.rm.dk godstrup.dk groennekompetencer.dk horsens.rm.dk human-first.org ikh.rm.dk innoccus-simply.dk klinik-almenmedicin-lemvig.dk landsbyviden.dk life-act.eu madsonline.dk mit.ikh.rm.dk move-interreg.eu psykiatrien.rm.dk randers.rm.dk regionaludvikling.intranet.rm.dk regionsklinikkenskive.dk regionsklinikkenskjern.dk regionsklinikkenthyholm.dk *.akutlaegehelikopter.dk *.antk.dk *.auh.dk *.c2ccc.eu *.cdss.dk *.cfbh.rm.dk *.coolgeoheat.eu *.danishairambulance.dk *.danishneurosciencecenter.dk *.dccc.dk *.defactum.dk *.desikredeinstitutioner.dk *.digi-lingo.eu *.dmcg.dk *.dok.rm.dk en.auh.dk *.faellesservicecenter.dk *.fagperson.auh.dk *.fagperson.hospitalsenhedmidt.dk *.fagperson.psykiatrien.rm.dk *.fagperson.regionshospitalet-goedstrup.dk *.fagperson.regionshospitalet-horsens.dk *.fagperson.regionshospitalet-randers.dk *.fagperson.sundhed.rm.dk *.godstrup.dk *.grenaasundhedshus.dk *.groennekompetencer.dk *.harts.dk *.hemidt.dk *.hemidt.intranet.rm.dk *.holmstrupgaard.rm.dk *.horsens.rm.dk *.hospitalsenhedmidt.dk *.human-first.org *.ikh.rm.dk *.klinik-almenmedicin-lemvig.dk *.kulturregion.dk *.laege-kvalitet.dk *.landsbyviden.rm.dk *.lemvigsundhedshus.dk *.life-bioscape.eu *.marselisborgcentret.dk *.medarbejder.rm.dk *.organdonation.dk *.pa.intra.rm.dk *.patientkommunikation.dk *.ph.rm.dk *.ps-horsens.intra.rm.dk *.ps-midt.intra.rm.dk *.ps-randers.intra.rm.dk *.ps-vest.intra.rm.dk *.psykiatriakademiet.rm.dk *.psykiatrien.rm.dk *.randers.intranet.rm.dk *.randers.rm.dk *.refer-cdr.eu *.regionshospitalet-goedstrup.dk *.regionshospitalet-horsens.dk *.regionshospitalet-randers.dk *.regionsklinikkenskive.dk *.regionsklinikkenskjern.dk *.regionsklinikkenthyholm.dk *.rehabiliteringsforum.dk *.rkkp.dk *.ru.rm.dk *.sau.rm.dk *.sbu.rm.dk *.sekretariatet.intra.rm.dk *.sektorovergang.rm.dk *.skivesundhedshus.dk *.sku.rm.dk *.social.rm.dk *.socialkvalitetsmodel.dk *.socialmedicin.rm.dk *.soh.rm.dk *.specialpsykologuddannelsen.dk *.specpsyksygeplejerske.dk *.stenoaarhus.dk *.sua.rm.dk *.sundhed.rm.dk *.sundhedsaftalen.rm.dk *.sundhedshusringkoebing.dk *.svo.rm.dk *.tvaerspor.dk *.videreuddannelsen-nord.dk *.voldtaegt.dk *.voresbaredygtighed.rm.dk *.windowstudiet.dk *.zgodkender.rm.dk *.ramazzini.dk; style-src 'self' 'unsafe-inline' unpkg.com fonts.googleapis.com cludo.com customer.cludo.com api.cludo.com *.cookiebot.com siteimprove.com *.siteimprove.com *.siteimproveanalytics.io *.google.com *.newrelic.com newrelic.com *.23video.com *.gstatic.com *.rm.dk *.analysefortegnelsen.dk connect.facebook.net/en_US/sdk.js *.rm.dk *.regionshospitalet-horsens.dk *.cpropslagqa.rm.dk *.cpropslagtest.rm.dk auh.intranet.rm.dk alvorligpatologi.dk auh.dk danishairambulance.dk danishneurosciencecenter.dk desikredeinstitutioner.dk diabetes.rm.dk godstrup.dk groennekompetencer.dk horsens.rm.dk human-first.org ikh.rm.dk innoccus-simply.dk klinik-almenmedicin-lemvig.dk landsbyviden.dk life-act.eu madsonline.dk mit.ikh.rm.dk move-interreg.eu psykiatrien.rm.dk randers.rm.dk regionaludvikling.intranet.rm.dk regionsklinikkenskive.dk regionsklinikkenskjern.dk regionsklinikkenthyholm.dk *.akutlaegehelikopter.dk *.antk.dk *.auh.dk *.c2ccc.eu *.cdss.dk *.cfbh.rm.dk *.coolgeoheat.eu *.danishairambulance.dk *.danishneurosciencecenter.dk *.dccc.dk *.defactum.dk *.desikredeinstitutioner.dk *.digi-lingo.eu *.dmcg.dk *.dok.rm.dk en.auh.dk *.faellesservicecenter.dk *.fagperson.auh.dk *.fagperson.hospitalsenhedmidt.dk *.fagperson.psykiatrien.rm.dk *.fagperson.regionshospitalet-goedstrup.dk *.fagperson.regionshospitalet-horsens.dk *.fagperson.regionshospitalet-randers.dk *.fagperson.sundhed.rm.dk *.godstrup.dk *.grenaasundhedshus.dk *.groennekompetencer.dk *.harts.dk *.hemidt.dk *.hemidt.intranet.rm.dk *.holmstrupgaard.rm.dk *.horsens.rm.dk *.hospitalsenhedmidt.dk *.human-first.org *.ikh.rm.dk *.klinik-almenmedicin-lemvig.dk *.kulturregion.dk *.laege-kvalitet.dk *.landsbyviden.rm.dk *.lemvigsundhedshus.dk *.life-bioscape.eu *.marselisborgcentret.dk *.medarbejder.rm.dk *.organdonation.dk *.pa.intra.rm.dk *.patientkommunikation.dk *.ph.rm.dk *.ps-horsens.intra.rm.dk *.ps-midt.intra.rm.dk *.ps-randers.intra.rm.dk *.ps-vest.intra.rm.dk *.psykiatriakademiet.rm.dk *.psykiatrien.rm.dk *.randers.intranet.rm.dk *.randers.rm.dk *.refer-cdr.eu *.regionshospitalet-goedstrup.dk *.regionshospitalet-horsens.dk *.regionshospitalet-randers.dk *.regionsklinikkenskive.dk *.regionsklinikkenskjern.dk *.regionsklinikkenthyholm.dk *.rehabiliteringsforum.dk *.rkkp.dk *.ru.rm.dk *.sau.rm.dk *.sbu.rm.dk *.sekretariatet.intra.rm.dk *.sektorovergang.rm.dk *.skivesundhedshus.dk *.sku.rm.dk *.social.rm.dk *.socialkvalitetsmodel.dk *.socialmedicin.rm.dk *.soh.rm.dk *.specialpsykologuddannelsen.dk *.specpsyksygeplejerske.dk *.stenoaarhus.dk *.sua.rm.dk *.sundhed.rm.dk *.sundhedsaftalen.rm.dk *.sundhedshusringkoebing.dk *.svo.rm.dk *.tvaerspor.dk *.videreuddannelsen-nord.dk *.voldtaegt.dk *.voresbaredygtighed.rm.dk *.windowstudiet.dk *.zgodkender.rm.dk *.ramazzini.dk; img-src 'self' data: 'unsafe-inline' unpkg.com fonts.googleapis.com cludo.com customer.cludo.com api.cludo.com *.cookiebot.com siteimprove.com *.siteimprove.com *.siteimproveanalytics.io *.google.com *.newrelic.com newrelic.com *.23video.com *.gstatic.com *.rm.dk *.analysefortegnelsen.dk connect.facebook.net/en_US/sdk.js *.rm.dk *.regionshospitalet-horsens.dk *.cpropslagqa.rm.dk *.cpropslagtest.rm.dk auh.intranet.rm.dk alvorligpatologi.dk auh.dk danishairambulance.dk danishneurosciencecenter.dk desikredeinstitutioner.dk diabetes.rm.dk godstrup.dk groennekompetencer.dk horsens.rm.dk human-first.org ikh.rm.dk innoccus-simply.dk klinik-almenmedicin-lemvig.dk landsbyviden.dk life-act.eu madsonline.dk mit.ikh.rm.dk move-interreg.eu psykiatrien.rm.dk randers.rm.dk regionaludvikling.intranet.rm.dk regionsklinikkenskive.dk regionsklinikkenskjern.dk regionsklinikkenthyholm.dk *.akutlaegehelikopter.dk *.antk.dk *.auh.dk *.c2ccc.eu *.cdss.dk *.cfbh.rm.dk *.coolgeoheat.eu *.danishairambulance.dk *.danishneurosciencecenter.dk *.dccc.dk *.defactum.dk *.desikredeinstitutioner.dk *.digi-lingo.eu *.dmcg.dk *.dok.rm.dk en.auh.dk *.faellesservicecenter.dk *.fagperson.auh.dk *.fagperson.hospitalsenhedmidt.dk *.fagperson.psykiatrien.rm.dk *.fagperson.regionshospitalet-goedstrup.dk *.fagperson.regionshospitalet-horsens.dk *.fagperson.regionshospitalet-randers.dk *.fagperson.sundhed.rm.dk *.godstrup.dk *.grenaasundhedshus.dk *.groennekompetencer.dk *.harts.dk *.hemidt.dk *.hemidt.intranet.rm.dk *.holmstrupgaard.rm.dk *.horsens.rm.dk *.hospitalsenhedmidt.dk *.human-first.org *.ikh.rm.dk *.klinik-almenmedicin-lemvig.dk *.kulturregion.dk *.laege-kvalitet.dk *.landsbyviden.rm.dk *.lemvigsundhedshus.dk *.life-bioscape.eu *.marselisborgcentret.dk *.medarbejder.rm.dk *.organdonation.dk *.pa.intra.rm.dk *.patientkommunikation.dk *.ph.rm.dk *.ps-horsens.intra.rm.dk *.ps-midt.intra.rm.dk *.ps-randers.intra.rm.dk *.ps-vest.intra.rm.dk *.psykiatriakademiet.rm.dk *.psykiatrien.rm.dk *.randers.intranet.rm.dk *.randers.rm.dk *.refer-cdr.eu *.regionshospitalet-goedstrup.dk *.regionshospitalet-horsens.dk *.regionshospitalet-randers.dk *.regionsklinikkenskive.dk *.regionsklinikkenskjern.dk *.regionsklinikkenthyholm.dk *.rehabiliteringsforum.dk *.rkkp.dk *.ru.rm.dk *.sau.rm.dk *.sbu.rm.dk *.sekretariatet.intra.rm.dk *.sektorovergang.rm.dk *.skivesundhedshus.dk *.sku.rm.dk *.social.rm.dk *.socialkvalitetsmodel.dk *.socialmedicin.rm.dk *.soh.rm.dk *.specialpsykologuddannelsen.dk *.specpsyksygeplejerske.dk *.stenoaarhus.dk *.sua.rm.dk *.sundhed.rm.dk *.sundhedsaftalen.rm.dk *.sundhedshusringkoebing.dk *.svo.rm.dk *.tvaerspor.dk *.videreuddannelsen-nord.dk *.voldtaegt.dk *.voresbaredygtighed.rm.dk *.windowstudiet.dk *.zgodkender.rm.dk *.ramazzini.dk; connect-src 'self' bam.eu01.nr-data.net sentry.io unpkg.com fonts.googleapis.com cludo.com customer.cludo.com api.cludo.com *.cookiebot.com siteimprove.com *.siteimprove.com *.siteimproveanalytics.io *.google.com *.newrelic.com newrelic.com *.23video.com *.gstatic.com *.rm.dk *.analysefortegnelsen.dk connect.facebook.net/en_US/sdk.js *.rm.dk *.regionshospitalet-horsens.dk *.cpropslagqa.rm.dk *.cpropslagtest.rm.dk auh.intranet.rm.dk alvorligpatologi.dk auh.dk danishairambulance.dk danishneurosciencecenter.dk desikredeinstitutioner.dk diabetes.rm.dk godstrup.dk groennekompetencer.dk horsens.rm.dk human-first.org ikh.rm.dk innoccus-simply.dk klinik-almenmedicin-lemvig.dk landsbyviden.dk life-act.eu madsonline.dk mit.ikh.rm.dk move-interreg.eu psykiatrien.rm.dk randers.rm.dk regionaludvikling.intranet.rm.dk regionsklinikkenskive.dk regionsklinikkenskjern.dk regionsklinikkenthyholm.dk *.akutlaegehelikopter.dk *.antk.dk *.auh.dk *.c2ccc.eu *.cdss.dk *.cfbh.rm.dk *.coolgeoheat.eu *.danishairambulance.dk *.danishneurosciencecenter.dk *.dccc.dk *.defactum.dk *.desikredeinstitutioner.dk *.digi-lingo.eu *.dmcg.dk *.dok.rm.dk en.auh.dk *.faellesservicecenter.dk *.fagperson.auh.dk *.fagperson.hospitalsenhedmidt.dk *.fagperson.psykiatrien.rm.dk *.fagperson.regionshospitalet-goedstrup.dk *.fagperson.regionshospitalet-horsens.dk *.fagperson.regionshospitalet-randers.dk *.fagperson.sundhed.rm.dk *.godstrup.dk *.grenaasundhedshus.dk *.groennekompetencer.dk *.harts.dk *.hemidt.dk *.hemidt.intranet.rm.dk *.holmstrupgaard.rm.dk *.horsens.rm.dk *.hospitalsenhedmidt.dk *.human-first.org *.ikh.rm.dk *.klinik-almenmedicin-lemvig.dk *.kulturregion.dk *.laege-kvalitet.dk *.landsbyviden.rm.dk *.lemvigsundhedshus.dk *.life-bioscape.eu *.marselisborgcentret.dk *.medarbejder.rm.dk *.organdonation.dk *.pa.intra.rm.dk *.patientkommunikation.dk *.ph.rm.dk *.ps-horsens.intra.rm.dk *.ps-midt.intra.rm.dk *.ps-randers.intra.rm.dk *.ps-vest.intra.rm.dk *.psykiatriakademiet.rm.dk *.psykiatrien.rm.dk *.randers.intranet.rm.dk *.randers.rm.dk *.refer-cdr.eu *.regionshospitalet-goedstrup.dk *.regionshospitalet-horsens.dk *.regionshospitalet-randers.dk *.regionsklinikkenskive.dk *.regionsklinikkenskjern.dk *.regionsklinikkenthyholm.dk *.rehabiliteringsforum.dk *.rkkp.dk *.ru.rm.dk *.sau.rm.dk *.sbu.rm.dk *.sekretariatet.intra.rm.dk *.sektorovergang.rm.dk *.skivesundhedshus.dk *.sku.rm.dk *.social.rm.dk *.socialkvalitetsmodel.dk *.socialmedicin.rm.dk *.soh.rm.dk *.specialpsykologuddannelsen.dk *.specpsyksygeplejerske.dk *.stenoaarhus.dk *.sua.rm.dk *.sundhed.rm.dk *.sundhedsaftalen.rm.dk *.sundhedshusringkoebing.dk *.svo.rm.dk *.tvaerspor.dk *.videreuddannelsen-nord.dk *.voldtaegt.dk *.voresbaredygtighed.rm.dk *.windowstudiet.dk *.zgodkender.rm.dk *.ramazzini.dk; font-src 'self' fonts.gstatic.com fonts.googleapis.com; frame-src 'self' unpkg.com fonts.googleapis.com cludo.com customer.cludo.com api.cludo.com *.cookiebot.com siteimprove.com *.siteimprove.com *.siteimproveanalytics.io *.google.com *.newrelic.com newrelic.com *.23video.com *.gstatic.com *.rm.dk *.analysefortegnelsen.dk connect.facebook.net/en_US/sdk.js *.rm.dk *.regionshospitalet-horsens.dk *.cpropslagqa.rm.dk *.cpropslagtest.rm.dk auh.intranet.rm.dk alvorligpatologi.dk auh.dk danishairambulance.dk danishneurosciencecenter.dk desikredeinstitutioner.dk diabetes.rm.dk godstrup.dk groennekompetencer.dk horsens.rm.dk human-first.org ikh.rm.dk innoccus-simply.dk klinik-almenmedicin-lemvig.dk landsbyviden.dk life-act.eu madsonline.dk mit.ikh.rm.dk move-interreg.eu psykiatrien.rm.dk randers.rm.dk regionaludvikling.intranet.rm.dk regionsklinikkenskive.dk regionsklinikkenskjern.dk regionsklinikkenthyholm.dk *.akutlaegehelikopter.dk *.antk.dk *.auh.dk *.c2ccc.eu *.cdss.dk *.cfbh.rm.dk *.coolgeoheat.eu *.danishairambulance.dk *.danishneurosciencecenter.dk *.dccc.dk *.defactum.dk *.desikredeinstitutioner.dk *.digi-lingo.eu *.dmcg.dk *.dok.rm.dk en.auh.dk *.faellesservicecenter.dk *.fagperson.auh.dk *.fagperson.hospitalsenhedmidt.dk *.fagperson.psykiatrien.rm.dk *.fagperson.regionshospitalet-goedstrup.dk *.fagperson.regionshospitalet-horsens.dk *.fagperson.regionshospitalet-randers.dk *.fagperson.sundhed.rm.dk *.godstrup.dk *.grenaasundhedshus.dk *.groennekompetencer.dk *.harts.dk *.hemidt.dk *.hemidt.intranet.rm.dk *.holmstrupgaard.rm.dk *.horsens.rm.dk *.hospitalsenhedmidt.dk *.human-first.org *.ikh.rm.dk *.klinik-almenmedicin-lemvig.dk *.kulturregion.dk *.laege-kvalitet.dk *.landsbyviden.rm.dk *.lemvigsundhedshus.dk *.life-bioscape.eu *.marselisborgcentret.dk *.medarbejder.rm.dk *.organdonation.dk *.pa.intra.rm.dk *.patientkommunikation.dk *.ph.rm.dk *.ps-horsens.intra.rm.dk *.ps-midt.intra.rm.dk *.ps-randers.intra.rm.dk *.ps-vest.intra.rm.dk *.psykiatriakademiet.rm.dk *.psykiatrien.rm.dk *.randers.intranet.rm.dk *.randers.rm.dk *.refer-cdr.eu *.regionshospitalet-goedstrup.dk *.regionshospitalet-horsens.dk *.regionshospitalet-randers.dk *.regionsklinikkenskive.dk *.regionsklinikkenskjern.dk *.regionsklinikkenthyholm.dk *.rehabiliteringsforum.dk *.rkkp.dk *.ru.rm.dk *.sau.rm.dk *.sbu.rm.dk *.sekretariatet.intra.rm.dk *.sektorovergang.rm.dk *.skivesundhedshus.dk *.sku.rm.dk *.social.rm.dk *.socialkvalitetsmodel.dk *.socialmedicin.rm.dk *.soh.rm.dk *.specialpsykologuddannelsen.dk *.specpsyksygeplejerske.dk *.stenoaarhus.dk *.sua.rm.dk *.sundhed.rm.dk *.sundhedsaftalen.rm.dk *.sundhedshusringkoebing.dk *.svo.rm.dk *.tvaerspor.dk *.videreuddannelsen-nord.dk *.voldtaegt.dk *.voresbaredygtighed.rm.dk *.windowstudiet.dk *.zgodkender.rm.dk *.ramazzini.dk; base-uri 'self'; frame-ancestors 'self'; report-uri https://o4504207644033024.ingest.us.sentry.io/api/4510300403204096/security/?sentry_key=0f83650c1c0c90a8ea22a527173f4833&sentry_environment=prod; report-to csp-endpoint 2 default-src 'self'; style-src 'self' https://*.typekit.net https://cdnjs.cloudflare.com; font-src https://*.typekit.net; script-src 'self' https://sparkplatform.com https://cdnjs.cloudflare.com 2 default-src 'self';img-src * blob: data: px.ads.linkedin.com www.facebook.com *.doubleclick.net *.clarity.ms;script-src 'self' 'unsafe-inline' 'unsafe-eval' *.bootstrapcdn.com *.typekit.net cdn.jsdelivr.net cdn.rlets.com cdnjs.cloudflare.com code.jquery.com js.hsforms.net www.googletagmanager.com *.mysanfordchart.org *.addthis.com *.adroll.com *.adsrvr.org *.ads-twitter.com *.clarity.ms *.cloudfront.net *.doubleclick.net *.fls.doubleclick.net formstack.com *.formstack.com *.formstack.io *.g.doubleclick.net *.google.com *.googleadservices.com *.google-analytics.com *.googleapis.com *.gstatic.com *.invocacdn.com *.liveperson.net *.lpsnmedia.net *.mpio.io onesignal.com *.onesignal.com *.qualtrics.com *.quantcount.com *.quantserve.com *.serving-sys.com *.simpli.fi *.siteintercept.qualtrics.com *.talentegy.com *.tvsquared.com *.twitter.com *.v.liveperson.net *.vimeo.com *.vimeocdn.com aa.agkn.com ajax.aspnetcdn.com assets.sitescdn.net az416426.vo.msecnd.net bat.bing.com cdn.mouseflow.com cdn.popt.in chimpstatic.com data.adxcel-ec2.com embed.typeform.com js.hsadspixel.net js.hs-analytics.net js.hs-banner.com js.hscollectedforms.net js.hsleadflows.net js.hs-scripts.com pixel.mathtag.com pixel.videohub.tv pnapi.invoca.net px.ads.linkedin.com s.amazon-adsystem.com s.pinimg.com s3.amazonaws.com/checkout.squadup.com/default/css/bootstrap-namespace.min.css script.crazyegg.com sc-static.net siteimproveanalytics.com snap.licdn.com static.addtoany.com static.cloud.coveo.com tags.srv.stackadapt.com tracking.logpostback.com transparency.nrchealth.com trkn.us v1.addthisedge.com www.buzzsprout.com www.groupexpro.com www.youtube.com www.ypo.education/js/jsembedcode.js z.moatads.com cdn.mxpnl.com js.hubspot.com *.snapchat.com *.instabot.io *.roobrik.com connect.facebook.net services.cattailsservices.com;style-src 'self' 'unsafe-inline' *.bootstrapcdn.com *.fontawesome.com *.googleapis.com *.typekit.net cdn.jsdelivr.net cdnjs.cloudflare.com cloud.typography.com code.jquery.com www.googletagmanager.com *.mysanfordchart.org *.formstack.com *.formstack.io *.gstatic.com *.vimeocdn.com cdn.thinglink.me checkout.stripe.com formsprod.azureedge.net onesignal.com static.cloud.coveo.com tags.srv.stackadapt.com www.groupexpro.com www.youtube.com *.instabot.io services.cattailsservices.com;font-src 'self' data: *.fontawesome.com *.typekit.com *.typekit.net cdn.jsdelivr.net cdnjs.cloudflare.com *.formstack.com *.gstatic.com *.googleusercontent.com static.cloud.coveo.com staticdev.cloud.coveo.com *.roobrik.com;frame-src 'self' cdn.jsdelivr.net cdn.rlets.com cdnjs.cloudflare.com www.googletagmanager.com tools.sanfordhealthplan.com *.mysanfordchart.org *.addthis.com *.adsrvr.org *.c.liveperson.net *.doubleclick.net *.fls.doubleclick.net *.formstack.com *.g.doubleclick.net *.google.com *.ipcamlive.com *.lpsnmedia.net *.snapchat.com *.soundcloud.com *.stripe.com *.twitter.com *.v.liveperson.net vimeo.com *.vimeo.com *.youtube.com cdn.onesignal.com e.issuu.com fast.wistia.net forms.hsforms.com host.visualcalc.com js.hsadspixel.net js.hsforms.net pixel.mathtag.com players.brightcove.net static.addtoany.com www.buzzsprout.com www.pinterest.ca www.pinterest.co.uk www.pinterest.com www.pinterest.fr www.pinterest.it www.pinterest.ph ct.pinterest.com www.thinglink.com forms.hubspot.com *.roobrik.com *.cloudfront.net sanford.az1.qualtrics.com www.groupexpro.com;frame-ancestors 'self' *.mysanfordchart.org *.snapchat.com;connect-src 'self' cdn.jsdelivr.net cdn.rlets.com cdnjs.cloudflare.com cloud.typography.com code.jquery.com www.googletagmanager.com *.addthis.com *.adroll.com *.clarity.ms *.doubleclick.net *.g.doubleclick.net *.gannettdigital.com *.google.com *.analytics.google.com *.google-analytics.com *.googleadservices.com *.googleapis.com *.gstatic.com *.linkedin.oribi.io onesignal.com *.onesignal.com *.pinterest.com *.quantcount.com *.reachlocalservices.com *.serving-sys.com *.snapchat.com *.squadup.com *.twitter.com *.vimeocdn.com *.z1.dca0.com api.hubapi.com az416426.vo.msecnd.net bat.bing.com dc.services.visualstudio.com *.hsforms.com *.hubspot.com js.hs-scripts.com hubspot-forms-static-embed.s3.amazonaws.com js.hsadspixel.net forms.hscollectedforms.net js.hscollectedforms.net n2.mouseflow.com pnapi.invoca.net sanfordhealth.formstack.com *.formstack.io usageanalytics.coveo.com *.cloud.coveo.com px.ads.linkedin.com snap.licdn.com sc-static.net api.sanfordhealth.org api-js.mixpanel.com *.instabot.io api.fbanalytics.org connect.facebook.net assets.sitescdn.net *.cloudfront.net siteimproveanalytics.com *.roobrik.com services.cattailsservices.com;form-action 'self' *.fontawesome.com cdnjs.cloudflare.com *.sanfordhealthfoundation.org *.adroll.com *.doubleclick.net *.google.com *.google-analytics.com *.googleapis.com *.gstatic.com *.pinterest.com *.serving-sys.com *.snapchat.com *.vimeocdn.com api.hubapi.com forms.hsforms.com forms.hubspot.com hubspot-forms-static-embed.s3.amazonaws.com;media-src * data:;object-src 'none';report-uri https://csp-reporting.sanfordhealth.org/; 2 default-src 'self' data: 'unsafe-inline' *.belden.com belden.com cdn.cookielaw.org fonts.googleapis.com fonts.gstatic.com go.alphawire.com pi.pardot.com static.cloud.coveo.com www.googletagmanager.com analytics.google.com siteintercept.qualtrics.com stats.g.doubleclick.net zn2avekmmkqwmhtco-belden.siteintercept.qualtrics.com beldencableproductionbugpvwoi.analytics.org.coveo.com beldencableproductionbugpvwoi.org.coveo.com code.jquery.com null; script-src 'unsafe-inline' 'unsafe-eval' bat.bing.com *.belden.com belden.com cdn.pardot.com cdn.cookielaw.org view.ceros.com cdn.evgnet.com code.jquery.com connect.facebook.net googleads.g.doubleclick.net j.6sc.co maps.googleapis.com pi.pardot.com siteintercept.qualtrics.com snap.licdn.com ssl.google-analytics.com static.cloud.coveo.com wasm-eval www.googletagmanager.com www.youtube.com znddv5x3kanrnsrdw-belden.siteintercept.qualtrics.com zn1jm0i9w5rbcjil6-belden.siteintercept.qualtrics.com go.alphawire.com cdnjs.cloudflare.com www.alphawire.com www.googleadservices.com pagead2.googlesyndication.com code.metalocator.com; script-src-elem 'self' 'unsafe-inline' analytics.convertlanguage.com bat.bing.com belden.com *.belden.com cdn.cookielaw.org view.ceros.com cdn.evgnet.com cdnjs.cloudflare.com code.jquery.com connect.facebook.net go.alphawire.com googleads.g.doubleclick.net j.6sc.co pi.pardot.com siteintercept.qualtrics.com snap.licdn.com ssl.google-analytics.com static.cloud.coveo.com www.googletagmanager.com www.youtube.com zn2avekmmkqwmhtco-belden.siteintercept.qualtrics.com zn1jm0i9w5rbcjil6-belden.siteintercept.qualtrics.com znddv5x3kanrnsrdw-belden.siteintercept.qualtrics.com html5.dcatalog.com www.google.com maps.googleapis.com pagead2.googlesyndication.com code.metalocator.com www.googleadservices.com; script-src-attr 'unsafe-inline'; style-src 'unsafe-inline' *.belden.com static.cloud.coveo.com fonts.googleapis.com www.alphawire.com www.gstatic.com; style-src-elem 'self' 'unsafe-inline' *.belden.com belden.com fonts.googleapis.com static.cloud.coveo.com cdnjs.cloudflare.com; style-src-attr 'unsafe-inline'; img-src 'self' data: ad.doubleclick.net ade.googlesyndication.com analytics.convertlanguage.com hm.baidu.com *.belden.com belden.com b.6sc.co bat.bing.com cdn.cookielaw.org px.ads.linkedin.com ssl.google-analytics.com www.facebook.com www.google.cl www.google.com www.googletagmanager.com www.google.com.gt www.google.hu googleads.g.doubleclick.net pagead2.googlesyndication.com www.google.ca iad1.qualtrics.com www.google.co.il www.google.com.mx siteintercept.qualtrics.com 61320.global.siteimproveanalytics.io www.google.com.tr www.google.es cts.businesswire.com dilp.netcomponents.com http://dilp.netcomponents.com/images/gocart.gif maps.googleapis.com maps.gstatic.com www.google.bf www.google.co.in www.google.co.jp www.google.co.uk www.google.com.au www.google.com.co www.google.fr www.google.nl www.google.no www.google.be www.google.se www.google.sk www.google.kz www.google.pl www.google.com.tw www.google.cz www.google.co.nz www.google.com.sa www.google.mv translate.google.com www.google.ru www.google.com.vn www.google.ee www.google.com.eg www.google.co.th www.google.co.ve www.google.fi www.google.ch www.google.ie www.google.ro www.google.bg www.google.com.tw google.com.ng www.google.co.ve fonts.gstatic.com google.com.ar www.google.com.hk www.google.com.eg adservice.google.com blob: cdn.metalocator.com connect.facebook.net px4.ads.linkedin.com www.google.co.cr www.google.co.id www.google.com.cu www.google.com.my www.google.com.pr www.google.com.sg www.google.de www.google.gr www.google.is www.google.it www.google.lk www.linkedin.com file; font-src 'self' data: *.belden.com fonts.gstatic.com null; connect-src 'self' www.googleadservices.com adservice.google.com *.belden.com analytics.google.com beldencableproductionbugpvwoi.analytics.org.coveo.com beldencableproductionbugpvwoi.org.coveo.com beldeninc.us-7.evergage.com c.6sc.co cdn.cookielaw.org ipv6.6sc.co pagead2.googlesyndication.com privacyportal.onetrust.com px.ads.linkedin.com siteintercept.qualtrics.com static.cloud.coveo.com stats.g.doubleclick.net www.google-analytics.com www.google.com bat.bing.com region1.google-analytics.com www.facebook.com region1.analytics.google.com maps.googleapis.com ssl.google-analytics.com googleads.g.doubleclick.net login.microsoftonline.com mozendaagent.ecoinsight.com www.google.ca www.google.com.mx localhost:12387 epsilon.6sense.com secure.adnxs.com; media-src 'self' belden.com *.belden.com bynder-media-us-east-1.s3.amazonaws.com data:; child-src 11330854.fls.doubleclick.net 14683840.fls.doubleclick.net; frame-src 'self' div.show 11330854.fls.doubleclick.net 14683840.fls.doubleclick.net belden.com *.belden.com *.alphawire.com td.doubleclick.net html5.dcatalog.com belden.prod01.logik.io view.ceros.com www.googletagmanager.com www.youtube.com block.opendns.com code.metalocator.com photos.productphoto.com td.doubleclick.net.x.caf244fb07dc70414c0a22903e52945843c7.d043db89.id.opendns.com td.doubleclick.net.x.f46a820d0d27604f490949006659b57240b8.d043db9c.id.opendns.com www.facebook.com; frame-ancestors 'self'; form-action 'self' https://www.facebook.com; report-uri https://bdnaw.report-uri.com/r/d/csp/reportOnly; report-to https://bdnaw.report-uri.com/r/d/csp/reportOnly; 2 child-src 'self' blob: *.adairs.com.au; connect-src 'self' *.aptrinsic.com *.braintreegateway.com *.braze.com *.clarity.ms *.creativecdn.com *.google-analytics.com *.google.com *.googleapis.com *.googletagmanager.com *.hotjar.com *.hotjar.io *.inside-graph.com *.paypal.com *.pinterest.com *.spotify.com *.unbxd.io *.unbxdapi.com *.yieldify-production.com *.yieldify.com cdn.jsdelivr.net cdnjs.cloudflare.com dc.services.visualstudio.com google.com js.monitor.azure.com payments.braintree-api.com wss://stellar-live.inside-graph.com wss://ws.hotjar.com www.facebook.com/tr/; font-src 'self' *.gstatic.com *.typekit.net/ *.yieldify-production.com *.yieldify.com https://*.cloudfront.net/graphik/ https://*.cloudfront.net/lato/; frame-src 'self' *.braintreegateway.com *.creativecdn.com *.criteo.com *.criteo.net *.googletagmanager.com *.paypal.com *.pinterest.com pay.google.com; img-src 'self' data: *.adairs.co.nz *.adairs.com.au *.afterpay.com *.bing.com *.creativecdn.com *.google-analytics.com *.googleapis.com *.googletagmanager.com *.gstatic.com *.idio.episerver.net *.inside-graph.com *.paypal.com *.yieldify.com c.clarity.ms ib.adnxs.com r.turn.com www.facebook.com www.google.com.au www.paypalobjects.com; media-src 'self' *.inside-graph.com; script-src 'self' 'unsafe-eval' 'unsafe-inline' *.afterpay.com *.aptrinsic.com *.bing.com *.braze.com *.cfjump.com *.clarity.ms *.creativecdn.com *.criteo.com *.criteo.net *.google-analytics.com *.googleapis.com *.googletagmanager.com *.hotjar.com *.idio.episerver.net *.inside-graph.com *.paypal.com *.pdst.fm *.pinimg.com *.pinterest.com *.rakuten.com *.unbxd.io *.unbxdapi.com *.wisepops.com *.yieldify.com applepay.cdn-apple.com cdn.datatables.net cdn.jsdelivr.net cdnjs.cloudflare.com code.jquery.com connect.facebook.net https://static.cloudflareinsights.com/ js.monitor.azure.com pay.google.com r.turn.com static.zip.co static.zipmoney.com.au unpkg.com wisepops.net; style-src 'self' 'unsafe-inline' *.afterpay.com *.aptrinsic.com *.googleapis.com *.inside-graph.com *.typekit.net/ *.unbxd.io *.unbxdapi.com applepay.cdn-apple.com cdn.datatables.net cdn.jsdelivr.net; default-src 'none'; report-to stott-security-endpoint; 2 upgrade-insecure-requests; base-uri 'self'; default-src 'self'; child-src 'self' https:; connect-src 'self' https:; font-src 'self' https: data:; frame-src 'self' https:; img-src 'self' blob: https: data:; media-src 'self' ssl.gstatic.com v.adsrvr.org data:; script-src 'self' ajax.cloudflare.com cdn.ampproject.org cdn.printfriendly.com choices.trustarc.com choices.truste.com ep2.adtrafficquality.google *.kaspersky-labs.com js.chargebee.com s.adroll.com s0.2mdn.net s3.amazonaws.com www.googletagservices.com www.gstatic.com www.scrible.com *.doubleverify.com *.doubleclick.net *.google *.google.com *.googleapis.com *.googlesyndication.com *.sentry-cdn.com 'unsafe-inline'; style-src 'self' js.chargebee.com pwm-image.trendmicro.com s3.amazonaws.com use.fontawesome.com www.gstatic.com *.googleapis.com *.kaspersky-labs.com *.public.law 'unsafe-inline'; worker-src 'self' https: blob:; report-uri https://www.public.law/csp-report 2 default-src 'self' 'unsafe-inline' 'unsafe-eval' tags.tiqcdn.com tags.tiqcdn.cn collect.tealiumiq.com *.criteo.com *.criteo.net *.omtrdc.net *.yimg.jp *.yahoo.co.jp prf.hn *.doubleclick.net *.line.me *.google.com *.google.it *.bing.com *.google-analytics.com *.licdn.com *.tiktok.com sc-static.net *.usehero.com *.contentsquare.net *.demdex.net *.facebook.com *.googletagmanager.com *.facebook.net *.googleadservices.com *.teads.tv zegna.d3.sc.omtrdc.net www.google.* *.zegna.com *.measmerize.com *.googlesyndication.com maps.gstatic.com *.riskified.com sandbox.gestpay.net ecomm.sella.it *.online-metrix.net amp.akamaized.net *.snapchat.com *.gstatic.com *.go-mpulse.net cm.everesttech.net *.googleapis.com *.akstat.io *.akamaihd.net *.line-scdn.net *.algolianet.com *.algolia.net *.algolia.com zegna-cloud-media.s3.amazonaws.com zegna-cloud-media.s3.eu-west-1.amazonaws.com zegna-cloud-media.s3-eu-west-1.amazonaws.com livechat.zegna.cn *.baidu.com blob: data: ; font-src 'self' data: *.googleapis.com *.gstatic.com; report-uri /cgi-bin/csp_report.cgi 2 default-src 'self' data: blob: *.armstrong.com *.armstrongceilings.com armstrongceilings.my.salesforce-sites.com d2qrdklrsxowl2.cloudfront.net player.interactivity.brightcove.com fonts.gstatic.com www.google-analytics.com;style-src 'self' 'unsafe-inline' fast.fonts.net d2qrdklrsxowl2.cloudfront.net *.s3.amazonaws.com fonts.googleapis.com display.ugc.bazaarvoice.com player.interactivity.brightcove.com;form-action 'self' *.armstrong.com *.armstrongceilings.com armstrongceilings.tfaforms.net *.salesforceliveagent.com armstrongceilings.my.site.com; frame-ancestors 'none';script-src 'self' 'unsafe-inline' 'unsafe-eval' blob: *.armstrong.com *.armstrongceilings.com www.gstatic.com js-na1.hs-scripts.com js.hs-banner.com js.hs-analytics.net js.hsforms.net *.bazaarvoice.com cdn-cookieyes.com *.outbrain.com *.salesforceliveagent.com *.ugc.bazaarvoice.com assets.adobedtm.com connect.facebook.net d2qrdklrsxowl2.cloudfront.net googleads.g.doubleclick.net lib-us-3.brilliantcollector.com players.brightcove.net siteintercept.qualtrics.com snap.licdn.com vjs.zencdn.net www.googleadservices.com www.googletagmanager.com znbmda84ti8npbglj-armstrong.siteintercept.qualtrics.com *.google.com *.google-analytics.com *.analytics.google.com www.googletagmanager.com *.mountain.com 100.20.58.101 18.210.229.244 3.212.39.155 34.215.155.61 35.160.46.251 35.85.84.151 44.212.189.233 44.228.85.26 44.238.122.172 52.22.50.55 52.71.121.170 54.156.2.105100.20.58.101 18.210.229.244 3.212.39.155 34.215.155.61 35.160.46.251 35.85.84.151 44.212.189.233 44.228.85.26 44.238.122.172 52.22.50.55 52.71.121.170 54.156.2.105 *.clearbitscripts.com;frame-src 'self' armstrongceilings.tfaforms.net bid.g.doubleclick.net d2qrdklrsxowl2.cloudfront.net armstrong.demdex.net www.google.com;img-src 'self' data: *.armstrong.com *.armstrongceilings.com *.bazaarvoice.com *.brightcove.com *.outbrain.com *.qualtrics.com armstrongceilings.my.salesforce-sites.com cdn-cookieyes.com cf-images.us-east-1.prod.boltdns.net cm.everesttech.net data.coremetrics.com dpm.demdex.net p.adsymptotic.com px.ads.linkedin.com s7d2.scene7.com www.google-analytics.com www.google.com www.googletagmanager.com track.hubspot.com www.facebook.com;connect-src 'self' *.akamaihd.net *.armstrong.com *.armstrongceilings.com cdn-cookieyes.com *.cookieyes.com edge.adobedc.net forms.hsforms.com *.brightcove.com *.qualtrics.com *.hapyak.com cdn.linkedin.oribi.io house-fastly-signed-us-east-1-prod.brightcovecdn.com armstrong.tt.omtrdc.net brightcove.hs.llnwd.net dpm.demdex.net edge.api.brightcove.com lib-us-3.brilliantcollector.com manifest.prod.boltdns.net stats.g.doubleclick.net *.google-analytics.com 100.20.58.101 18.210.229.244 3.212.39.155 34.215.155.61 35.160.46.251 35.85.84.151 44.212.189.233 44.228.85.26 44.238.122.172 52.22.50.55 52.71.121.170 54.156.2.105 *.clearbitscripts.com 2 default-src 'self' https://*.svc.dynamics.com https://*.mkt.dynamics.com https://*.azureedge.net https://*.cloudfront.net https://*.vattenfall.nl https://*.vattenfall.com https://*.azure-api.net/ https://*.mopinion.com; base-uri 'self' https://*.demdex.net https://*.cloudfront.net https://*.svtrd.com https://*.vattenfall.com; form-action 'self' https://*.demdex.net https://*.cloudfront.net https://*.svtrd.com https://*.vattenfall.com; connect-src 'self' 'unsafe-inline' 'unsafe-eval' wss://*.stt.speech.microsoft.com wss://*.cognigy.cloud https://endpoint-vattenfall.cognigy.cloud https://*.svc.dynamics.com https://*.mkt.dynamics.com https://*.azureedge.net https://nominatim.openstreetmap.org https://*.linkedin.com https://*.demdex.net https://*.www.google.nl/pagead https://*.pa-cd.com/ https://*.azure-api.net/ https://*.vattenfall.com https://*.googleapis.com https://*.blob.core.windows.net https://*.services.visualstudio.com https://*.adoberesources.net https://*.googlesyndication.com https://*.cloudfront.net https://*.idomoo.com https://*.queue-it.net https://*.mopinion.com https://*.piwik.pro https://siteimproveanalytics.com https://*.siteimproveanalytics.com https://*.googleads https://*.googleadservices.com https://*.cdn-0.d41.co https://*.w9shetvlr6.d41.co https://*.vattenfall.nl https://tdn.r42tag.com https://*.relay42.com https://w.usabilla.com https://api.usabilla.com https://*.googleapis.com https://*.gstatic.com https://dl.episerver.net https://www.youtube.com https://js.monitor.azure.com https://westeurope-5.in.applicationinsights.azure.com https://web.telemetric.dk https://vattenfalltesting.24sessions.com https://connect.facebook.net https://img06.en25.com r2eu01.visualwebsiteoptimizer.com https://t.svtrd.com https://businessspecificapimanglobal.azure-api.ne https://*.doubleclick.net https://googleads.g.doubleclick.net https://www.google.nl/pagead https://cep-api.vattenfall.com https://*.googleadservices.com https://*.bing.net https://*.bing.com https://*.lt45.net https://snap.licdn.com https://*.visualwebsiteoptimizer.com https://*.google.com https://*.google.co.uk https://pingvp.com https://*.pingvp.com https://*.clarity.ms; script-src 'self' 'unsafe-inline' 'unsafe-eval' blob: https://*.svc.dynamics.com https://*.mkt.dynamics.com https://*.azureedge.net https://*.adoberesources.net https://*.googlesyndication.com https://*.cloudfront.net https://*.idomoo.com https://*.queue-it.net https://*.mopinion.com https://*.piwik.pro https://siteimproveanalytics.com https://*.siteimproveanalytics.com https://*.googleadservices.com https://*.cdn-0.d41.co https://*.w9shetvlr6.d41.co https://*.vattenfall.nl https://tdn.r42tag.com https://admin.relay42.com https://w.usabilla.com https://api.usabilla.com https://www.googletagmanager.com https://*.google-analytics.com https://*.googleapis.com https://*.gstatic.com https://dl.episerver.net https://www.youtube.com https://js.monitor.azure.com https://westeurope-5.in.applicationinsights.azure.com https://web.telemetric.dk https://vattenfalltesting.24sessions.com https://connect.facebook.net https://img06.en25.com r2eu01.visualwebsiteoptimizer.com https://dc.services.visualstudio.com https://*.svtrd.com https://businessspecificapimanglobal.azure-api.ne https://*.doubleclick.net https://googleads.g.doubleclick.net https://*.www.google.nl/pagead https://cep-api.vattenfall.com https://td.doubleclick.net https://googleadservices.com https://*.bing.com https://*.bing.net https://*.lt45.net https://snap.licdn.com https://*.visualwebsiteoptimizer.com https://*.google.com https://*.google.co.uk https://pingvp.com https://*.pingvp.com https://*.clarity.ms; frame-src 'self' 'unsafe-inline' 'unsafe-eval' https://*.svc.dynamics.com https://*.mkt.dynamics.com https://*.azureedge.net https://*.googlesyndication.com https://datawrapper.dwcdn.net https://*.dwcdn.net https://*.bbvms.com https://*.idomoo.com https://*.zonatlas.nl https://*.spotify.com https://*.cloudfront.net https://*.queue-it.net https://*.vattenfall.nl https://tdn.r42tag.com https://admin.relay42.com https://w.usabilla.com https://api.usabilla.com https://*.google-analytics.com https://*.googleapis.com https://*.gstatic.com https://dl.episerver.net https://www.youtube.com https://js.monitor.azure.com https://web.telemetric.dk https://westeurope-5.in.applicationinsights.azure.com https://vattenfalltesting.24sessions.com https://connect.facebook.net https://img06.en25.com https://r2eu01.visualwebsiteoptimizer.com https://dc.services.visualstudio.com https://*.svtrd.com https://businessspecificapimanglobal.azure-api.ne https://googleads.g.doubleclick.net https://*.www.google.nl/pagead https://cep-api.vattenfall.com https://td.doubleclick.net https://*.doubleclick.net https://googleadservices.com https://*.cdn-0.d41.co https://*.w9shetvlr6.d41.co https://*.bing.com https://*.bing.net https://*.lt45.net https://snap.licdn.com https://*.visualwebsiteoptimizer.com https://*.google.com https://*.google.co.uk https://pingvp.com https://*.pingvp.com https://www.googletagmanager.com; media-src 'self' 'unsafe-inline' 'unsafe-eval' https://*.svc.dynamics.com https://*.mkt.dynamics.com https://*.azureedge.net https://*.googlesyndication.com https://*.bing.com https://*.bing.net https://*.idomoo.com https://*.queue-it.net https://*.vattenfall.nl https://tdn.r42tag.com https://admin.relay42.com https://w.usabilla.com https://api.usabilla.com https://www.googletagmanager.com https://www.googletagmanager.com/* https://*.googletagmanager.com https://*.google-analytics.com https://*.googleapis.com https://*.gstatic.com https://dl.episerver.net https://*.youtube.com https://js.monitor.azure.com https://westeurope-5.in.applicationinsights.azure.com https://web.telemetric.dk https://vattenfalltesting.24sessions.com https://connect.facebook.net https://img06.en25.com https://r2eu01.visualwebsiteoptimizer.com https://dc.services.visualstudio.com https://t.svtrd.com https://businessspecificapimanglobal.azure-api.ne https://googleads.g.doubleclick.net https://*.www.google.nl/pagead https://cep-api.vattenfall.com https://td.doubleclick.net https://googleadservices.com https://*.cdn-0.d41.co https://*.w9shetvlr6.d41.co https://*.bing.com https://*.bing.net https://*.lt45.net https://snap.licdn.com https://*.visualwebsiteoptimizer.com https://*.google.nl https://*.google.com https://*.google.co.uk https://pingvp.com https://*.pingvp.com; style-src 'self' 'unsafe-inline' https://*.svc.dynamics.com https://*.mkt.dynamics.com https://*.azureedge.net https://*.googlesyndication.com https://*.vattenfall.nl https://*.idomoo.com https://*.cloudfront.net https://web.telemetric.dk https://vattenfalltesting.24sessions.com https://connect.facebook.net https://img06.en25.com https://r2eu01.visualwebsiteoptimizer.com https://dc.services.visualstudio.com https://t.svtrd.com https://businessspecificapimanglobal.azure-api.ne https://googleads.g.doubleclick.net https://*.www.google.nl/pagead https://cep-api.vattenfall.com https://td.doubleclick.net https://googleadservices.com https://*.cdn-0.d41.co https://*.w9shetvlr6.d41.co https://*.bing.com https://*.bing.net https://*.lt45.net https://snap.licdn.com https://*.googleapis.com https://*.gstatic.com https://dl.episerver.net https://pingvp.com https://*.pingvp.com https://*.mopinion.com; img-src 'self' https://*.svc.dynamics.com https://*.mkt.dynamics.com https://*.azureedge.net https://*.googlesyndication.com https://*.vattenfall.nl https://*.google.nl https://*.siteimproveanalytics.com https://*.siteimproveanalytics.io https://*.linkedin.com https://tdn.r42tag.com https://admin.relay42.com https://cm.g.doubleclick.net https://ad.doubleclick.net https://*.piwik.pro https://*.facebook.com https://*.clarity.ms https://*.bing.com https://*.bing.net https://*.svtrd.com https://*.cloudfront.net https://w.usabilla.com https://web.telemetric.dk https://vattenfalltesting.24sessions.com https://connect.facebook.net https://img06.en25.com r2eu01.visualwebsiteoptimizer.com https://dc.services.visualstudio.com https://t.svtrd.com https://businessspecificapimanglobal.azure-api.ne https://googleads.g.doubleclick.net https://*.www.google.nl/pagead https://*.www.google.de/pagead https://cep-api.vattenfall.com https://td.doubleclick.net https://googleadservices.com https://*.cdn-0.d41.co https://*.w9shetvlr6.d41.co https://*.bing.com https://*.bing.net https://*.lt45.net https://snap.licdn.com https://*.visualwebsiteoptimizer.com https://*.google.com https://*.google.co.uk https://*.googleapis.com https://www.googletagmanager.com https://www.googletagmanager.com/* https://*.googletagmanager.com https://*.google-analytics.com https://*.gstatic.com https://dl.episerver.net https://pingvp.com https://*.pingvp.com https://*.openstreetmap.org https://*.mopinion.com data:; font-src 'self' https://*.svc.dynamics.com https://*.mkt.dynamics.com https://*.azureedge.net https://*.googlesyndication.com https://*.vattenfall.nl https://*.googleapis.com https://*.gstatic.com https://dl.episerver.net https://pingvp.com https://*.pingvp.com https://*.mopinion.com data:; frame-ancestors 'self' https://*.svc.dynamics.com https://*.mkt.dynamics.com https://*.azureedge.net https://*.vattenfall.nl https://pingvp.com https://*.pingvp.com; worker-src 'self' data: https://*.svc.dynamics.com https://*.mkt.dynamics.com https://*.azureedge.net https://*.googlesyndication.com https://*.vattenfall.nl https://*.visualwebsiteoptimizer.com https://*.change.inc/ https://dl.episerver.net https://*.spotify.com https://www.google-analytics.com/* blob:; block-all-mixed-content 2 script-src 'self' https://ajax.googleapis.com https://f1000research.s3-eu-west-1.amazonaws.com https://cdnjs.cloudflare.com https://cdnjs.cloudflare.com https://js.hs-scripts.com 2 connect-src *; default-src *; font-src * data:; frame-src *; img-src data: *; script-src 'unsafe-inline' 'unsafe-eval' *; script-src-elem 'unsafe-inline' *; style-src 'unsafe-inline' *; style-src-elem 'unsafe-inline' *; 2 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https:; style-src 'self' 'unsafe-inline' https:; img-src 'self' data: https:; font-src 'self' https: data:; object-src 'none'; frame-ancestors 'none'; base-uri 'self'; form-action 'self'; report-uri /csp-report 2 default-src 'self'; script-src 'report-sample' 'self' https://bat.bing.com/bat.js https://cdn-4.convertexperiments.com/v1/js/10047604-10048796.js https://cdn.cookiehub.eu/c2/0d3e7b1f.js https://cdn.mxpnl.com/libs/mixpanel-2-latest.min.js https://cdnjs.cloudflare.com/polyfill/v3/polyfill.min.js https://public.our-trace.com/scripts/trace-badge.js https://recaptcha.net/recaptcha/api.js https://snap.licdn.com/li.lms-analytics/insight.min.js https://www.convert.com/current-convert-experiences-script/dist/bundle.js https://www.googletagmanager.com/gtm.js https://www.gstatic.com/recaptcha/releases/h7qt2xUGz2zqKEhSc8DD8baZ/recaptcha__en.js; style-src 'report-sample' 'self' 'unsafe-inline' https://cookiehub.net https://www.convert.com; object-src 'none'; base-uri 'self'; connect-src 'self' https://api.our-trace.com https://bat.bing.com https://cdn-4.convertexperiments.com https://px.ads.linkedin.com https://www.google-analytics.com https://www.google.com; font-src 'self' data:; frame-src 'self' https://recaptcha.net https://www.googletagmanager.com; frame-ancestors 'self' https://www.google.com https://recaptcha.net; img-src 'self' data: https://bat.bing.com https://public.our-trace.com https://px.ads.linkedin.com https://tracking.g2crowd.com; manifest-src 'self'; media-src 'self'; worker-src 'none'; 2 default-src https:; script-src https: 'unsafe-eval' 'unsafe-inline'; style-src https: 'unsafe-inline'; img-src https: data:; font-src https: data:; media-src https: http: rtsp: rtmp: data:; report-uri /csp-report 2 worker-src 'self' blob:; object-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' rum.hlx.page *.youtube.com *.gstatic.com *.licdn.com *.podigee-cdn.net static.xingcdn.com www.googleadservices.com *.google.com *.googlesyndication.com *.onetrust.com *.alida.com wave.outbrain.com *.outbrain.com *.taboola.com *.intelliad.de *.doubleclick.net platform.twitter.com cdn.mouseflow.com *.cnd-motionmedia.de *.facebook.net www.facebook.com *.bing.com *.googletagmanager.com cdn.scarabresearch.com *.spoteffects.net cdn.trackjs.com cdnjs.cloudflare.com *.realperson.de cdn.cookielaw.org *.ergodirekt.de *.ergo.com *.ergo.de *.ergocarbon.com *.ergo-reiseversicherung.de *.dkv.com *.cloudfirst.digital assets.adobedtm.com; frame-ancestors 'self' *.ergodirekt.de:* *.ergo.com:* *.ergo:* *.ergo.de *.ergocarbon.com *.ergo-reiseversicherung.de *.dkv.com *.erg.ravespace.cloud; report-uri https://csp-reporting.ergo.com/csp-reports?tenant=dospa; report-to csp-endpoint; 2 default-src https://*.cru.org; connect-src https://*.cru.org https://universal-editor-service.adobe.io https://*.adobeaemcloud.com https://*.adtrafficquality.google https://cru-content-based-filtering-prod.s3.amazonaws.com https://cru-content-based-filtering-stage.s3.amazonaws.com https://lq3-production.s3.amazonaws.com https://cru.oktapreview.com https://signon.okta.com https://browser-intake-datadoghq.com https://api.rollbar.com https://bat.bing.com https://bat.bing.net https://*.clarity.ms https://d3hb14vkzrxvla.cloudfront.net https://cdn.cookielaw.org https://*.doubleclick.net https://*.facebook.com https://www.googleadservices.com https://*.google-analytics.com https://*.googlesyndication.com https://www.googletagmanager.com https://maps.googleapis.com https://*.google.com https://csi.gstatic.com https://*.kommunicate.io https://api.leadquizzes.com https://px.ads.linkedin.com https://*.onetrust.com https://*.optimizely.com https://ct.pinterest.com https://*.scene7.com https://capig.stape.biz https://t.co https://analytics.twitter.com https://api.typeform.com; font-src data: https://*.cru.org https://maxcdn.bootstrapcdn.com https://fonts.gstatic.com https://use.typekit.net; frame-src https://*.cru.org https://static.addtoany.com https://*.adobeaemcloud.com https://*.adtrafficquality.google https://api.arclight.org https://bat.bing.com https://*.doubleclick.net https://*.facebook.com https://google.com https://*.google.com https://www.googletagmanager.com https://www.instagram.com https://content.leadquizzes.com https://cdn.lightwidget.com https://knowgod.com https://*.kommunicate.io https://your.nextstep.is https://*.spotify.com https://platform.twitter.com https://cru.oktapreview.com https://signon.okta.com https://*.optimizely.com https://ct.pinterest.com https://form.typeform.com https://player.vimeo.com https://my.visme.co https://www.youtube.com; img-src blob: data: *; media-src blob: data: *; object-src https://*.cru.org https://*.adobeaemcloud.com; script-src 'unsafe-eval' 'unsafe-inline' https://*.cru.org https://static.addtoany.com https://*.adtrafficquality.google https://static.ads-twitter.com/uwt.js https://universal-editor-service.adobe.io https://lq3-production.s3.amazonaws.com https://bat.bing.com https://maxcdn.bootstrapcdn.com https://*.clarity.ms https://cdnjs.cloudflare.com https://cdn.cookielaw.org https://*.doubleclick.net https://connect.facebook.com https://connect.facebook.net https://*.google.com https://www.googleadservices.com https://*.googleapis.com https://www.googletagmanager.com https://*.googlesyndication.com https://www.gstatic.com https://beacon-v2.helpscout.net https://www.instagram.com https://code.jquery.com https://cdn.jsdelivr.net https://snap.licdn.com https://cdn.lightwidget.com https://knowgod.com https://*.kommunicate.io https://global.oktacdn.com https://*.optimizely.com https://s.pinimg.com https://ct.pinterest.com https://cdn.parsely.com https://s7d2.scene7.com https://platform.twitter.com https://embed.typeform.com https://use.typekit.net https://unpkg.com/@cruglobal/recommendations-component@1.0.7/dist/index.js https://player.vimeo.com https://static-bundles.visme.co https://www.youtube.com; style-src 'unsafe-inline' https://*.cru.org https://s3-us-west-2.amazonaws.com/lq3-production01/lead_quizzes_3.0/tracking/css/global-tracking.css https://maxcdn.bootstrapcdn.com https://cdnjs.cloudflare.com https://fonts.googleapis.com https://*.kommunicate.io https://cdn-images.mailchimp.com https://s7d2.scene7.com https://*.typekit.net https://embed.typeform.com https://unpkg.com/@cruglobal/cru-content-designs@1.1.0/cruorg/styles.css https://unpkg.com/swiper/swiper-bundle.min.css; worker-src blob:; report-uri https://browser-intake-datadoghq.com/api/v2/logs?dd-api-key=pub78c844a77df2472307b237a306fd3ce4&dd-evp-origin=content-security-policy&ddsource=csp-report&ddtags=service%3Acru-dot-org%2Cenv%3Aproduction%2Ccsp-revision%3A3; report-to csp-endpoint 2 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' blob: https://www.googletagmanager.com https://connect.facebook.net https://www.google.com https://snap.licdn.com https://www.redditstatic.com https://policy.app.cookieinformation.com https://googleads.g.doubleclick.net https://secure.quantserve.com https://static.ads-twitter.com https://rules.quantcount.com https://analytics.tiktok.com https://tags.srv.stackadapt.com https://www.gstatic.com https://cdn.xsolla.net https://3001.scriptcdn.net https://infird.com; style-src 'self' 'unsafe-inline' https://tags.srv.stackadapt.com https://www.gstatic.com; img-src 'self' data: blob: https: https://cms.ioi.dk https://www.facebook.com https://px.ads.linkedin.com https://region1.google-analytics.com https://alb.reddit.com; font-src 'self' data: https://fonts.gstatic.com https://ioi.dk https://use.typekit.net https://r2cdn.perplexity.ai; connect-src 'self' data: https://cms.ioi.dk https://region1.google-analytics.com https://www.google-analytics.com https://www.google.com https://www.googletagmanager.com https://px.ads.linkedin.com https://alb.reddit.com https://pixel-config.reddit.com https://conversions-config.reddit.com https://www.redditstatic.com https://www.facebook.com https://policy.app.cookieinformation.com https://o4504207644033024.ingest.us.sentry.io https://vimeo.com https://prreqcroab.icu https://analytics.tiktok.com https://tags.srv.stackadapt.com https://www.googleadservices.com https://pixel.quantserve.com https://pixel.quantcount.com https://googleads.g.doubleclick.net https://analytics-ipv6.tiktokw.us https://consent.app.cookieinformation.com https://store.xsolla.com https://api.killadsapi.com https://overbridgenet.com; frame-src 'self' https://www.googletagmanager.com https://policy.app.cookieinformation.com https://www.youtube.com https://player.vimeo.com https://www.google.com https://www.facebook.com https://purchase.xsolla.com https://duertry.com https://access.workspace.google.com https://accounts.google.com; frame-ancestors 'self' https://dev-ioi-website.euwest01.umbraco.io https://stage-ioi-website.euwest01.umbraco.io https://ioi-website.euwest01.umbraco.io; media-src 'self' https://dev-ioi-website.euwest01.umbraco.io https://stage-ioi-website.euwest01.umbraco.io https://cms.ioi.dk; report-uri https://4ff80cf698c8fa08a42150e2d0fae142@o4504207644033024.ingest.us.sentry.io/4510260682948608; report-to csp-endpoint 2 default-src 'self' http: filesystem: https://*-c2es.pantheonsite.io/ https://c2es.ddev.site https://*.addthis.com https://*.youtube.com; script-src 'unsafe-inline' 'unsafe-eval' http: filesystem: https://*.google.com https://fonts.googleapis.com https://ajax.googleapis.com https://jnn-pa.googleapis.com https://*.googletagmanager.com https://*.youtube.com https://*.addthis.com https://*.google-analytics.com https://*.ytimg.com https://*.moatads.com https://*.doubleclick.net https://*.addthisedge.com https://cdnjs.cloudflare.com; style-src 'unsafe-inline' http: filesystem: https://*.google.com https://fonts.googleapis.com https://ajax.googleapis.com https://jnn-pa.googleapis.com https://*.youtube.com; img-src 'self' http: data: filesystem: https://*.ytimg.com https://*.ggpht.com https://*.gstatic.com https://*.google-analytics.com; connect-src 'self' filesystem: https://*.google-analytics.com https://*.bookingbug.com https://geolocation.onetrust.com https://*.cookielaw.org https://fonts.googleapis.com https://ajax.googleapis.com https://jnn-pa.googleapis.com *.addtoany.com; font-src 'self' data: filesystem: fonts.gstatic.com use.typekit.net use.fontawesome.com bespoke.bookingbug.com; media-src 'self' filesystem: *.youtube.com *.vimeo.com *.akamaized.net; report-uri 'self'; child-src 'self'; form-action 'self'; frame-ancestors 'self'; object-src 'self'; frame-src 'self'; worker-src 'self'; manifest-src 'self'; navigate-to 'self'; prefetch-src 'self'; upgrade-insecure-requests 2 font-src fonts.gstatic.com use.typekit.net *.googleapis.com *.gstatic.com https://fonts.gstatic.com data: https://fonts.intercomcdn.com https://*.yotpo.com https://*.typekit.net https://*.fontawesome.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.yotpo.com dhv2ziothpgrr.cloudfront.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * https://*.facebook.com https://plumrocket.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.affirm.com *.affirm.ca https://*.trustpilot.com http://*.trustpilot.com https://*.hotjar.com https://*.affirm.com *.auth0.com https://cdn.auth0.com https://*.auth0.com https://*.infusionsoft.app https://*.doubleclick.net/ https://*.facebook.com/ *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com www.xtento.com https://plumrocket.com *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io *.ftcdn.net *.behance.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.googleapis.com *.gstatic.com *.affirm.com *.affirm.ca https://www.google.com https://track.hubspot.com https://*.intercom.io https://static.intercomassets.com https://*.intercomcdn.com https://sp.analytics.yahoo.com https://*.facebook.com https://*.amazonaws.com https://*.infusionsoft.app https://www.googletagmanager.com https://*.akamaihd.net https://px.ads.linkedin.com https://p.adsymptotic.com https://ssl.gstatic.com https://www.gstatic.com https://*.bing.com https://*.hsforms.com https://*.clarity.ms https://*.wistia.com https://cdn.auth0.com https://p.adsymptotic.com https://www.google.co.uk https://heapanalytics.com https://*.yotpo.com https://content-faculty.blueprintprep.com https://redchamps.com www.xtento.com cdn.xtento.com maps.gstatic.com *.yotpo.com dhv2ziothpgrr.cloudfront.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com https://player.vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ beacon-qa.magento-datasolutions.com beacon-stage.magento-ds.com beacon.magento-ds.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googleapis.com https://*.gstatic.com *.affirm.com *.affirm.ca https://www.googletagmanager.com https://*.google-analytics.com https://tagmanager.google.com https://*.google.com https://googleads.g.doubleclick.net https://*.trustpilot.com http://*.trustpilot.com https://*.newrelic.com https://*.nr-data.net https://*.intercom.io https://*.intercomcdn.com https://*.hotjar.com https://*.bing.com https://*.licdn.com https://*.yimg.com https://sp.analytics.yahoo.com https://*.impactradius-event.com http://*.hs-scripts.com https://*.hscollectedforms.net https://*.hsleadflows.net https://*.hs-analytics.net https://js.hubspot.com https://*.hs-banner.com https://*.hs-scripts.com https://*.hsadspixel.net https://*.usemessages.com https://*.facebook.net https://app.convertful.com https://*.affirm.com https://*.pdst.fm *.auth0.com https://cdn.auth0.com https://*.auth0.com https://*.clarity.ms https://vision.duel.me/duel-analytics.js https://*.wistia.com https://*.hsforms.net https://*.hsforms.com https://*.jquery.com https://*.cloudflare.com https://*.yotpo.com https://*.heapanalytics.com https://*.greenhouse.io https://*.amplitude.com https://*.sentry-cdn.com https://unpkg.com/@lottiefiles/ *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com www.xtento.com cdn.xtento.com maps.googleapis.com *.yotpo.com dhv2ziothpgrr.cloudfront.net *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com d18eg7dreypte5.cloudfront.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com unsafe-inline assets.braintreegateway.com https://tagmanager.google.com https://fonts.googleapis.com https://*.yotpo.com https://*.typekit.net https://*.fontawesome.com *.stripe.network *.stripecdn.com *.amazon.com *.yotpo.com *.googleapis.com dhv2ziothpgrr.cloudfront.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com https://*.intercom.io https://*.intercomcdn.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.snplow.net commerce.adobedc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com p13n-mr.adobe.io *.adobedc.net *.demdex.net *.adobe.io performance.typekit.net *.sentry.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.googleapis.com *.affirm.com *.affirm.ca https://www.googletagmanager.com https://*.google-analytics.com https://*.yimg.com https://sp.analytics.yahoo.com https://*.hubspot.com https://*.hotjar.com https://app.convertful.com https://*.affirm.com https://*.intercom.io wss://*.intercom.io https://*.newrelic.com https://*.nr-data.net https://*.paypal.com https://us-central1-adaptive-growth.cloudfunctions.net *.auth0.com https://cdn.auth0.com https://*.auth0.com https://*.bing.com https://*.clarity.ms https://*.doubleclick.net/ https://*.hotjar.io/ https://*.hotjar.com/ https://*.wistia.com https://*.hsforms.net https://*.hsforms.com https://*.hubapi.com https://*.trustpilot.com https://*.litix.io wss://*.hotjar.com https://*.yotpo.com https://*.google.com https://*.hscollectedforms.net https://*.pfx.io https://edge.adobedc.net https://*.greenhouse.io https://smetrics.blueprintprep.com https://*.amplitude.com https://*.linkedin.com https://px.ads.linkedin.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com maps.googleapis.com *.yotpo.com dhv2ziothpgrr.cloudfront.net *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 default-src 'self' blob: *.senado.gov.br *.senado.leg.br;script-src 'self' 'unsafe-eval' 'unsafe-inline' *.senado.gov.br *.senado.leg.br *.youtube.com *.google-analytics.com www.googletagmanager.com vlibras.gov.br ajax.googleapis.com www.gstatic.com;img-src 'self' data: blob: *.senado.gov.br *.senado.leg.br *.ytimg.com *.google-analytics.com *.googletagmanager.com *.youtube.com *.gstatic.com vlibras.gov.br;connect-src 'self' *.senado.gov.br *.senado.leg.br vlibras.gov.br *.vlibras.gov.br www.google-analytics.com www.googletagmanager.com;font-src 'self' data: vlibras.gov.br cdnjs.cloudflare.com fonts.gstatic.com;style-src 'self' 'unsafe-inline' *.senado.gov.br *.senado.leg.br cdnjs.cloudflare.com fonts.googleapis.com;worker-src blob: *.senado.leg.br *.senado.gov.br;object-src 'none';frame-src 'self' *.senado.gov.br *.senado.leg.br *.youtube.com www.youtube-nocookie.com;base-uri 'self';frame-ancestors 'self' *.senado.gov.br *.senado.leg.br 2 connect-src 'self' https: wss:; default-src 'self'; font-src 'self' data: https://fonts.gstatic.com https://defi-promo.volet.com https://cdn.megabonus.com/fonts/; frame-src 'self' https://consentcdn.cookiebot.eu https://consentcdn.cookiebot.com https://challenges.cloudflare.com https://calendly.com https://verify.walletconnect.org https://mc.yandex.ru https://mc.yandex.com; img-src 'self' data: blob: https:; manifest-src 'self'; media-src 'self' https://blog.static.volet.com data:; object-src 'none'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://defi-promo.volet.com https://consent.cookiebot.eu https://consentcdn.cookiebot.eu https://connect.facebook.net https://eu-assets.i.posthog.com https://mc.yandex.com https://mc.yandex.ru https://www.googletagmanager.com; script-src-elem 'self' 'unsafe-inline' blob: https://www.googletagmanager.com https://consentcdn.cookiebot.eu https://mc.yandex.com https://mc.yandex.ru https://connect.facebook.net https://eu-assets.i.posthog.com https://defi-promo.volet.com https://consent.cookiebot.eu https://challenges.cloudflare.com https://*.kaspersky-labs.com; style-src 'self' 'unsafe-inline' https://defi-promo.volet.com; style-src-elem 'self' 'unsafe-inline' https://fonts.googleapis.com https://defi-promo.volet.com https://www.gstatic.com https://www.gstatic.com:443 https://*.kaspersky-labs.com; worker-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'; report-uri https://csp.volet.com/csp-reports; report-to csp-endpoint 2 font-src 'self'; frame-src 'self'; img-src 'self' data: https://img.airtel.tv https://moe-email-campaigns.s3.amazonaws.com https://image.moengage.com; style-src report-sample 'self' 'unsafe-inline'; script-src report-sample 'self' 'unsafe-inline' https://app.link/_r https://cdn.branch.io/branch-latest.min.js https://www.googletagmanager.com/gtag/js; 2 default-src 'self' https://*.wistia.com https://*.wistia.net https://cdn.growthbook.io; script-src 'self' 'unsafe-inline' 'unsafe-eval' data: https://www.google.com https://www.gstatic.com https://www.googletagmanager.com https://gtm.moneybird.nl https://gtm.moneybird.de https://gtm.moneybird.com https://gtm.moneybird.be https://www.google-analytics.com https://www.youtube.com https://maps.googleapis.com https://bat.bing.com https://*.demio.com https://d3s4clg74dg0wr.cloudfront.net https://zapier.com https://www.clarity.ms https://static.homerun.co https://unpkg.com/@googlemaps/ https://euc-widget.freshworks.com https://moneybird.freshdesk.com https://*.wistia.com https://*.wistia.net https://*.intercom.io wss://*.intercom.io https://intercom-sheets.com/ https://*.intercomcdn.eu https://*.intercomcdn.com https://*.intercomassets.eu; style-src 'self' 'unsafe-inline' https://moneybird.nl https://www.moneybird.nl https://www.googletagmanager.com https://gtm.moneybird.nl https://gtm.moneybird.de https://gtm.moneybird.com https://gtm.moneybird.be https://www.gstatic.com https://d3s4clg74dg0wr.cloudfront.net https://fonts.googleapis.com https://*.demio.com https://static.homerun.co https://fonts.bunny.net https://euc-widget.freshworks.com https://moneybird.freshdesk.com https://*.adyen.com/ https://intercom-sheets.com/ https://*.intercomcdn.eu https://*.intercomcdn.com https://*.intercomassets.eu; img-src 'self' https://moneybird.nl https://www.moneybird.nl https://prismic-io.s3.amazonaws.com https://images.prismic.io https://moneybird.cdn.prismic.io https://dl6oytjgv033w.cloudfront.net https://www.gstatic.com https://www.google-analytics.com https://stats.g.doubleclick.net https://googleads.g.doubleclick.net https://www.googletagmanager.com https://gtm.moneybird.nl https://gtm.moneybird.de https://gtm.moneybird.com https://gtm.moneybird.be https://www.google.nl https://www.google.com https://i.ytimg.com https://maps.gstatic.com https://csi.gstatic.com https://maps.googleapis.com https://bat.bing.com https://zapier.com https://cdn.zapier.com https://euc-widget.freshworks.com https://moneybird.freshdesk.com https://*.wistia.com https://*.wistia.net data: https://*.adyen.com/ https://intercom-sheets.com/ https://*.intercomcdn.eu https://*.intercomcdn.com https://*.intercomassets.eu; object-src 'self' https://www.youtube-nocookie.com https://www.youtube.com; connect-src 'self' https://moneybird.nl https://www.moneybird.nl https://help.moneybird.nl https://bat.bing.com https://gtm.moneybird.nl https://gtm.moneybird.com https://gtm.moneybird.be https://gtm.moneybird.de https://pagead2.googlesyndication.com https://*.google-analytics.com https://www.gstatic.com https://moneybird.com https://www.moneybird.com https://homerun.co https://stats.g.doubleclick.net https://*.demio.com https://*.clarity.ms https://embed.homerun.co https://maps.googleapis.com https://euc-widget.freshworks.com https://moneybird.freshdesk.com https://*.wistia.com https://*.wistia.net https://cdn.growthbook.io https://*.intercom.io wss://*.intercom.io https://*.intercom-messenger.com wss://*.intercom-messenger.com https://intercom-sheets.com/ https://*.intercomcdn.eu https://*.intercomcdn.com https://*.intercomassets.eu; frame-src 'self' https://www.googletagmanager.com https://gtm.moneybird.nl https://gtm.moneybird.de https://gtm.moneybird.com https://gtm.moneybird.be https://www.google.com https://www.youtube.com https://www.youtube-nocookie.com https://moneybird.clickwebinar.com https://w.soundcloud.com https://euc-widget.freshworks.com https://moneybird.freshdesk.com https://fast.wistia.com https://fast.wistia.net https://intercom-sheets.com/ https://*.intercomcdn.eu https://*.intercomcdn.com https://*.intercomassets.eu; font-src 'self' https://moneybird.nl https://www.moneybird.nl https://fonts.googleapis.com https://fonts.gstatic.com https://fonts.bunny.net https://*.wistia.com data: https://intercom-sheets.com/ https://*.intercomcdn.eu https://*.intercomcdn.com https://*.intercomassets.eu; report-uri https://moneybird.com/csp_report; 2 font-src https://www.googletagmanager.com *.googleapis.com *.gstatic.com *.rab.equipment magento2.docker *.intervieweb.it *.algolia.com *.cloudflare.com *.twitter.com *.typekit.net *.fontawesome.com *.bootstrapcdn.com *.klarnaservices.com *.klarna.com *.klarnacdn.net *.rentle.io *.wisepops.net wisepops.net *.wisepops.com wisepops.com feather.rab.equipment *.yotpo.com dhv2ziothpgrr.cloudfront.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.adyen.com pay.google.com payments-eu.amazon.com *.amazon.de *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors *.storyblok.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.adyen.com pay.google.com *.paypal.com *.dotdigital-pages.com *.dotdigital.com magento2.docker *.intervieweb.it *.rentle.io *.twitter.com *.google.com *.wisepops.net wisepops.net *.wisepops.com wisepops.com feather.rab.equipment www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com account.fetchify.com *.hub-box.com c.paypal.com checkout.paypal.com assets.braintreegateway.com *.cardinalcommerce.com * www.youtube.com *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.adyen.com pay.google.com *.payments-amazon.com *.media-amazon.com *.paypalobjects.com *.gstatic.com https://images.unsplash.com magento2.docker *.clarity.ms *.rab.equipment *.intervieweb.it *.rentle.io *.klarnaservices.com *.klarna.com *.klarnacdn.net *.algolia.com *.iesnare.com *.locally.com *.cloudflare.com *.googleadservices.com *.google-analytics.com *.google.co.uk *.paypal.com *.twitter.com *.wisepops.net wisepops.net *.wisepops.com wisepops.com feather.rab.equipment *.storyblok.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://cc-cdn.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com www.google.com.ua *.adobedtm.com *.yotpo.com dhv2ziothpgrr.cloudfront.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal tagmanager.google.com https://www.googletagmanager.com https://cdn.jsdelivr.net/npm/@ryangjchandler/spruce@2.x.x/dist/spruce.umd.js https://*.avln.me/t.js https://developer.adobe.com https://magento.com https://cdn.avmws.com/ http://cdn.avmws.com/ magento2.docker *.rab.equipment *.rentle.io *.intervieweb.it *.klarnaservices.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.trustpilot.com *.algolia.com *.algolia.io *.locally.com *.outtra.com *.cookiefirst.com *.iesnare.com *.cloudflare.com *.twitter.com *.google-analytics.com *.googlesyndication.com googletagmanager.com *.google.com *.gstatic.com *.trustedshops.com *.fontawesome.com apis.google.com feather.rab.equipment gtm.rab.equipment gtm.mcstaging.rab.equipment *.polyfill-fastly.io polyfill-fastly.io *.clarity.ms *.wisepops.net wisepops.net *.wisepops.com wisepops.com *.storyblok.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://cc-cdn.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com www.youtube.com player.vimeo.com *.yotpo.com dhv2ziothpgrr.cloudfront.net *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com d18eg7dreypte5.cloudfront.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://www.googletagmanager.com tagmanager.google.com *.googleapis.com *.rab.equipment magento2.docker *.intervieweb.it *.rentle.io *.algolia.com *.outtra.com *.locally.com *.cloudflare.com *.twitter.com *.gstatic.com *.typekit.net *.fontawesome.com *.bootstrapcdn.com *.klarnaservices.com *.klarna.com *.klarnacdn.net *.cookiefirst.com *.wisepops.net wisepops.net *.wisepops.com wisepops.com feather.rab.equipment *.storyblok.com cc-cdn.com unsafe-inline assets.braintreegateway.com *.yotpo.com dhv2ziothpgrr.cloudfront.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.intervieweb.it magento2.docker *.klarnaservices.com *.klarna.com *.klarnacdn.net *.algolia.com *.iesnare.com *.locally.com 'self' data: *.rab.equipment *.rentle.io *.wisepops.net wisepops.net *.wisepops.com wisepops.com feather.rab.equipment *.amazonaws.com *.googleapis.com *.google.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adyen.com *.google.com google.com payments-eu.amazon.com *.paypal.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com https://www.google-analytics.com https://developer.adobe.com https://cdn.avmws.com/ http://cdn.avmws.com/ magento2.docker *.intervieweb.it *.rentle.io *.klarnaevt.com *.klarnaservices.com *.klarna.com *.klarnacdn.net *.algolia.io *.locally.com *.outtra.com wss://mpsnare.iesnare.com *.iesnare.com *.cloudflare.com *.twitter.com *.google-analytics.com *.googlesyndication.com *.doubleclick.net *.cookiefirst.com *.clarity.ms *.wisepops.net wisepops.net *.wisepops.com wisepops.com feather.rab.equipment www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com api.craftyclicks.co.uk pcls1.craftyclicks.co.uk *.hub-box.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com cdn.plyr.io noembed.com *.yotpo.com dhv2ziothpgrr.cloudfront.net *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://static.unzer.com https://applepay.cdn-apple.com maxcdn.bootstrapcdn.com 'self' data: https://widgets.trustedshops.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de https://plumrocket.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * www.facebook.com *.facebook.com *.nkd.com *.nkd.it 'self' 'unsafe-inline'; frame-ancestors *.nkd.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de https://www.googletagmanager.com/ *.facebook.com https://plumrocket.com https://payment.unzer.com https://payment.heidelpay.com https://sbx-payment.heidelpay.com https://sbx-payment.unzer.com https://h.online-metrix.net https://google.com/pay https://pay.google.com/ https://test-heidelpay.hpcgw.net/ https://sbx-api.heidelpay.com/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * secure.pay1.de payments.amazon.de jsctool.com www.jsctool.com js.playground.klarna.com https://accounts.google.com ad4m.at *.criteo.com *.doubleclick.net www.facebook.com hal9000.redintelligence.net *.usercentrics.eu www.usemaxserver.de *.fls.doubleclick.net *.creativecdn.com tsdtocl.com *.sovendus-benefits.com *.sovendus-connect.com *.usemaxserver.de 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com *.google-analytics.com *.analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.payments-amazon.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ *.cdninstagram.com maps.googleapis.com maps.gstatic.com https://static.unzer.com *.online-metrix.net https://www.gstatic.com flagpedia.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com cdn.pay1.de x.klarnacdn.net *.cloudfront.net m.media-amazon.com static-eu.payments-amazon.com *.hsforms.net *.hsforms.com 'self' data: ad11.adfarm1.adition.com bat.bing.com *.doubleclick.net *.google.com *.google.pl imagesrv.adition.com lantern.roeye.com *.nkd.com track.adform.net usage.trackjs.com *.usercentrics.eu widgets.trustedshops.com www.facebook.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com *.etrusted.com *.360yield.com *.3lift.com *.addlv.smt.docomo.ne.jp *.adform.net *.admixer.net *.adnxs.com *.adscale.de *.adx.opera.com *.bing.com *.casalemedia.com *.ck-ie.com *.connectad.io *.console.adtarget.com.tr *.creativecdn.com *.dmxleo.com *.e-planning.net *.facebook.com *.facebook.net *.g.doubleclick.net *.go.sonobi.com *.gumgum.com *.inmobi.com *.leap.de *.loopme.me *.marphezis.com *.media.net *.mgid.com *.nexx360.io *.openx.net *.outbrain.com *.roeye.com *.rubiconproject.com *.sharethrough.com *.taboola.com *.teads.tv *.trackjs.com *.udmserve.net *.visx.net *.adition.com *.trustedshops.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com commerce-payments-sdk.adobe.io www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.plugins.emarsys.net *.scarabresearch.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ *.googleapis.com player.vimeo.com connect.facebook.net cdnjs.cloudflare.com *.googleoptimize.com maps.googleapis.com https://static.unzer.com https://applepay.cdn-apple.com https://pay.google.com https://code.jquery.com https://h.online-metrix.net https://h64.online-metrix.net *.gstatic.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com secure.pay1.de d.ratepay.com static-eu.payments-amazon.com x.klarnacdn.net cdn.klarna.com jsctool.com d.payla.io https://accounts.google.com https://www.gstatic.com *.hsforms.net *.hsforms.com ad4m.at api.sovendus.com bat.bing.com *.taboola.com cdn.mouseflow.com core.loopingo.com *.criteo.com *.epoq.de epoq-systems.de *.facebook.net lantern.roeyecdn.com *.nkd.com tags.creativecdn.com *.usercentrics.eu webanalytics.mso.digital widgets.trustedshops.com www.dwin1.com www.usemaxserver.de https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.etrusted.com *.bing.com *.dwin1.com *.epoq-systems.de *.loopingo.com *.usemaxserver.de *.trustedshops.com *.googletagmanager.com *.mouseflow.com *.outbrain.com *.creativecdn.com d22q3dafggn5rg.cloudfront.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com maxcdn.bootstrapcdn.com *.gstatic.com assets.braintreegateway.com d.ratepay.com d.payla.io dr.payla.io https://accounts.google.com https://www.gstatic.com *.googleapis.com *.epoq.de epoq-systems.de https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.etrusted.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.googleadservices.com *.google-analytics.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.scarabresearch.com *.eservice.emarsys.net http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ maps.googleapis.com https://api.unzer.com https://api.heidelpay.com https://sbx-api.heidelpay.com https://sbx-api.unzer.com https://payment.unzer.com https://payment.heidelpay.com https://sbx-payment.heidelpay.com https://sbx-payment.unzer.com https://h.online-metrix.net https://h64.online-metrix.net https://google.com/pay https://www.google.com/pay https://pay.google.com https://test-heidelpay.hpcgw.net/ https://sbx-api.heidelpay.com/ www.gstatic.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com payments.amazon.de payments-eu.amazon.com d.ratepay.com jsctool.com eu.playground.klarnaevt.com https://accounts.google.com t.elasticsuite.io *.hsforms.net *.hsforms.com ams.creativecdn.com api.usercentrics.eu bat.bing.com *.criteo.com *.googleapis.com *.taboola.com webanalytics.mso.digital *.trustedshops.com *.etrusted.com https://integrations.etrusted.site *.bing.com *.usercentrics.eu *.creativecdn.com *.bing.net *.loopingo.com *.kameleoon.eu *.sovendus.com *.arc.epoq.de *.facebook.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 font-src https://www.googletagmanager.com *.googleapis.com *.gstatic.com https://*.gopersonal.ai *.yotpo.com data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com https://plumrocket.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ https://*.gopersonal.ai https://plumrocket.com *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com validator.swagger.io *.gstatic.com https://*.gopersonal.ai *.yotpo.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ tagmanager.google.com https://www.googletagmanager.com https://assets.emarsys.net https://cdn.scarabresearch.com https://*.gopersonal.ai https://*.gstatic.com *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://www.googletagmanager.com tagmanager.google.com *.googleapis.com https://production-tailoy-repo-magento-statics.s3.us-east-2.amazonaws.com https://*.gopersonal.ai *.yotpo.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com https://www.google-analytics.com https://recommender.scarabresearch.com https://*.gopersonal.ai https://*.goshops.ai https://*.googleapis.com https://*.gstatic.com *.yotpo.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 default-src 'self' https://exercism.org https://api.exercism.org https://assets.exercism.org; connect-src 'self' ws://exercism.org https://cdn.jsdelivr.net https://sessions.bugsnag.com/; img-src 'self' data: https://*; media-src *; script-src 'self' https://exercism.org https://api.exercism.org https://assets.exercism.org https://js.stripe.com https://cdn.jsdelivr.net https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/; frame-src https://js.stripe.com https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/; font-src 'self' https://exercism.org https://api.exercism.org https://assets.exercism.org https://maxcdn.bootstrapcdn.com; style-src 'self' https://exercism.org https://api.exercism.org https://assets.exercism.org 'unsafe-inline' https://maxcdn.bootstrapcdn.com; child-src 'none' 2 upgrade-insecure-requests 2 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.klevu.com *.ksearchnet.com *.cloudflare.com *.googleapis.com *.zopim.com *.tawk.to *.jsdelivr.net media.flixfacts.com 'unsafe-inline' data: *.yotpo.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com oppwa.com *.oppwa.com peachpayments.com *.peachpayments.com *.facebook.com webchat.jdg.co.za *.jdg.co.za *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors *.hana.ondemand.com 'self'; frame-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.braintreegateway.com *.paypal.com google.com *.google.com *.dotdigital-pages.com *.dotdigital.com webchat.dotdigital.com webchat.staging.dotdigital.com maps.googleapis.com chart.googleapis.com oppwa.com *.oppwa.com peachpayments.com *.peachpayments.com *.nosto.com *.issuu.com *.hotjar.com *.hotjar.io *.googletagmanager.com *.criteo.net *.criteo.com *.addthis.com *.facebook.com webchat.jdg.co.za *.jdg.co.za *.yotpo.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com 'unsafe-inline' data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com *.trackedlink.net *.klevu.com *.ksearchnet.com oppwa.com *.oppwa.com *.peachpayments.com *.eu-west-1.amazonaws.com *.cloudflare.com *.google.com *.google.lv *.google.co.za *.google.com.na *.google.na *.zopim.com *.nosto.com *.hotjar.com *.hotjar.io *.googletagmanager.com *.zopim.io *.sfdr.co sfdr.co *.tawk.to tawk.link *.tawk.link *.addthis.com *.jsdelivr.net *.facebook.com *.azurewebsites.net maps.googleapis.com app.mobicredwidget.co.za amcglobal.sc.omtrdc.net media.flixcar.com rt.flix360.com assets.secure.checkout.visa.com mrpg.scene7.com *.yotpo.com data: 'self' 'unsafe-inline'; script-src geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal webchat.dotdigital.com webchat.staging.dotdigital.com js.klevu.com *.ksearchnet.com maps.googleapis.com chart.googleapis.com *.oppwa.com oppwa.com *.peachpayments.com *.zopim.com *.videoly.co sfdr.co *.cnetcontent.com *.cloudfront.net *.klevu.com *.google.lv *.google.co.za *.google.com.na *.google.na *.cloudflare.com *.cloudflareinsights.com *.nosto.com *.hotjar.com *.googletagmanager.com *.criteo.net *.criteo.com *.sfdr.co *.tawk.to *.tawk.link *.jsdelivr.net *.addthis.com *.addthisedge.com *.moatads.com *.mouseflow.com *.facebook.com *.what3words.com commerce.adobedtm.com magento-recs-sdk.adobe.net static.zdassets.com app.mobicredwidget.co.za www.gstatic.com connect.facebook.net bam.nr-data.net js.testfreaks.com media.flixfacts.com media.flixcar.com security-hub.vaimo.network *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com webchat.dotdigital.com webchat.staging.dotdigital.com *.klevu.com *.ksearchnet.com oppwa.com *.oppwa.com *.peachpayments.com *.cloudflare.com *.googleapis.com *.jsdelivr.net www.gstatic.com media.flixcar.com 'unsafe-inline' data: *.yotpo.com https://js.klevu.com 'self' 'unsafe-inline'; object-src maps.googleapis.com chart.googleapis.com 'self' 'unsafe-inline'; media-src *.zdassets.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com *.klevu.com *.ksearchnet.com maps.googleapis.com chart.googleapis.com oppwa.com *.oppwa.com *.peachpayments.com *.testfreaks.com *.nosto.com *.hotjar.io *.hotjar.com *.doubleclick.net *.zendesk.com *.tawk.to wss://*.tawk.to *.tawk.link *.addthis.com *.addthisedge.com *.what3words.com *.googleapis.com vsb111.tawk.to ekr.zdassets.com api.magento.com commerce.adobedc.net app.mobicredwidget.co.za wss://widget-mediator.zopim.com bam.nr-data.net *.googletagmanager.com security-hub.vaimo.network 'unsafe-eval' data: *.yotpo.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://security-hub.vaimo.network/public/api/content-security-policy.php; report-to report-endpoint; 2 default-src 'self'; script-src 'self' 'report-sample'; style-src 'self'; report-to csp-endpoint 2 font-src fonts.gstatic.com use.typekit.net https://cdnjs.cloudflare.com *.fontawesome.com https://fonts.gstatic.com https://www.google.com https://www.gstatic.com http://fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.googleadservices.com *.paypal.com *.google-analytics.com https://l.clarity.ms/collect *.paypal.com https://get.geojs.io https://js-agent.newrelic.com https://royaloak-dev.codilar.in https://mcstaging.royaloakindia.com https://royaloakindia.com https://bam.nr-data.net https://f.clarity.ms https://sdk-01.moengage.com/ https://mcprod.royaloakindia.com https://cdnjs.cloudflare.com https://commerce.adobedtm.com https://js-agent.newrelic.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * https://plumrocket.com 'self' 'unsafe-inline'; frame-ancestors https://cdnjs.cloudflare.com https://js-agent.newrelic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.googletagmanager.com *.googleadservices.com *.paypal.com *.google-analytics.com https://l.clarity.ms/collect *.paypal.com https://get.geojs.io https://js-agent.newrelic.com https://royaloak-dev.codilar.in https://mcstaging.royaloakindia.com https://royaloakindia.com https://bam.nr-data.net https://f.clarity.ms https://sdk-01.moengage.com/ https://mcprod.royaloakindia.com https://cdnjs.cloudflare.com https://commerce.adobedtm.com https://js-agent.newrelic.com api.razorpay.com www.youtube-nocookie.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com http://x.nitrocommerce.ai https://x.nitrocommerce.ai http://t.makehook.ws https://t.makehook.ws c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * https://plumrocket.com testourcode.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net *.googleadservices.com *.paypalobjects.com *.google-analytics.com https://l.clarity.ms/collect *.paypal.com https://get.geojs.io https://js-agent.newrelic.com https://royaloak-dev.codilar.in https://mcstaging.royaloakindia.com https://royaloakindia.com https://bam.nr-data.net https://f.clarity.ms https://sdk-01.moengage.com/ https://mcprod.royaloakindia.com https://cdnjs.cloudflare.com https://commerce.adobedtm.com https://js-agent.newrelic.com cdn.razorpay.com magefan.com cm.magefan.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com http://x.nitrocommerce.ai https://x.nitrocommerce.ai http://t.makehook.ws https://t.makehook.ws www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com assets.snapmint.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net amcglobal.sc.omtrdc.net commerce.adobe.net use.typekit.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com www.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-ds.com *.googleadservices.com *.paypal.com *.google-analytics.com https://l.clarity.ms/collect *.paypal.com https://get.geojs.io https://js-agent.newrelic.com https://royaloak-dev.codilar.in https://mcstaging.royaloakindia.com https://royaloakindia.com https://bam.nr-data.net https://f.clarity.ms https://sdk-01.moengage.com/ https://mcprod.royaloakindia.com https://cdnjs.cloudflare.com https://commerce.adobedtm.com https://js-agent.newrelic.com checkout.razorpay.com *.googleapis.com *.google.com *.gstatic.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com http://x.nitrocommerce.ai https://x.nitrocommerce.ai http://t.makehook.ws https://t.makehook.ws js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com api.snapmint.com assets.snapmint.com sandboxapi.snapmint.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://cdnjs.cloudflare.com *.fontawesome.com *.googleapis.com *.google.com *.gstatic.com http://x.nitrocommerce.ai https://x.nitrocommerce.ai http://t.makehook.ws https://t.makehook.ws http://fonts.googleapis.com https://fonts.googleapis.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io commerce.adobe.net qa-api.magedevteam.com *.sentry.io *.googleadservices.com *.paypal.com *.google-analytics.com https://l.clarity.ms/collect *.paypal.com https://get.geojs.io https://js-agent.newrelic.com https://royaloak-dev.codilar.in https://mcstaging.royaloakindia.com https://royaloakindia.com https://bam.nr-data.net https://f.clarity.ms https://sdk-01.moengage.com/ https://mcprod.royaloakindia.com https://cdnjs.cloudflare.com https://commerce.adobedtm.com https://js-agent.newrelic.com lumberjack.razorpay.com lumberjack-metrics.razorpay.com www.youtube.com http://dpm.demdex.net https://www.google.com https://www.gstatic.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.googleapis.com *.gstatic.com http://x.nitrocommerce.ai https://x.nitrocommerce.ai http://t.makehook.ws https://t.makehook.ws api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.google.com google.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 object-src 'none'; script-src 'self' 'unsafe-inline' 'unsafe-eval' addtocalendar.com https://api.mapbox.com https://cdn.jsdelivr.net https://cdn.rawgit.com https://cdnjs.cloudflare.com https://static.addtoany.com https://unpkg.com https://www.google.com https://www.tintup.com unpkg.com; script-src-attr 'self'; script-src-elem 'self' 'unsafe-inline' https://apps.elfsight.com https://static.elfsight.com https://www.youtube.com https://storage.elfsight.com https://apis.google.com https://www.googletagmanager.com addtocalendar.com https://api.mapbox.com https://cdn.jsdelivr.net https://cdn.rawgit.com https://cdnjs.cloudflare.com https://static.addtoany.com https://unpkg.com https://www.google.com https://www.tintup.com unpkg.com; style-src 'self' 'unsafe-inline' https://p.typekit.net addtocalendar.com https://api.mapbox.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com https://use.typekit.net unpkg.com; style-src-attr 'self' 'unsafe-inline'; frame-ancestors 'self' 2 font-src portal.bulkgate.com *.gstatic.com *.fontawesome.com maxcdn.bootstrapcdn.com https://cdnjs.cloudflare.com *.benu.hu data: *.googleapis.com *.hotjar.com 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com portal.bulkgate.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com portal.bulkgate.com *.facebook.com business.facebook.com data: *.google.com *.youtube.com *.publitas.com *.fliphtml5.com *.hotjar.com www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net *.vimeocdn.com s.ytimg.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com portal.bulkgate.com *.facebook.com business.facebook.com https://redchamps.com www.safemage.com *.benu.hu *.cloudfront.net *.google.com *.gstatic.com *.googleapis.com *.googletagmanager.com image.arukereso.hu *.google.hu *.hotjar.com *.arukereso.hu *.bing.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline'; script-src assets.adobedtm.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com s.ytimg.com video.google.com vimeo.com www.vimeo.com www.youtube.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com portal.bulkgate.com *.gstatic.com business.facebook.com *.avada.io https://cdnjs.cloudflare.com maps.googleapis.com *.google.com *.googletagmanager.com https://googleads.g.doubleclick.net *.googleadservices.com *.prefixbox.com *.publitas.com *.hotjar.com *.benu.hu *.arukereso.com gravity-dev-assets.oss-eu-central-1.aliyuncs.com benuhu.engine.yusp.com https://maileon-cdn.s3.eu-central-1.amazonaws.com/met/met.js clarity.ms *.clarity.ms *.bing.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src getfirebug.com portal.bulkgate.com *.gstatic.com *.fontawesome.com maxcdn.bootstrapcdn.com https://fonts.googleapis.com https://cdnjs.cloudflare.com *.googleapis.com *.prefixbox.com *.benu.hu 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com portal.bulkgate.com *.gstatic.com business.facebook.com *.benu.hu *.google-analytics.com *.prefixbox.com *.doubleclick.net *.services.visualstudio.com *.hotjar.com *.hotjar.io benuhu.engine.yusp.com *.maileon.hu 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 script-src-attr 'unsafe-inline'; font-src https://*.gstatic.com *.bglobale.com *.global-e.com https://use.typekit.net https://x.klarnacdn.net *.yotpo.com *.googleapis.com *.gstatic.com https://static.klaviyo.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.adyen.com pay.google.com payments-eu.amazon.com payments.amazon.de https://www.shopmyexchange.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com https://www.google.com/recaptcha/ www.googletagmanager.com *.adyen.com pay.google.com *.paypal.com *.bglobale.com *.global-e.com https://ct.pinterest.com https://*.fls.doubleclick.net https://postrelease.com https://*.rfihub.com *.yotpo.com https://frame.hub-box.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com validator.swagger.io *.adyen.com pay.google.com *.payments-amazon.com *.media-amazon.com *.paypalobjects.com https://*.gstatic.com *.bglobale.com *.global-e.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://alb.reddit.com https://analytics.twitter.com https://bat.bing.com https://*.doubleclick.net https://*.facebook.com https://sync.intentiq.com https://jadserve.postrelease.com https://t.co https://*.teads.tv https://r.turn.com https://*.yahoo.com *.yotpo.com https://i.lfi.media https://cdn.hub-box.com https://www.danner.com https://www.lacrossefootwear.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com *.bglobale.com *.global-e.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.convertexperiments.com https://ads.pubmatic.com https://static.ads-twitter.com https://bat.bing.com https://cdn.attn.tv https://cdn.ravm.tv https://cdnjs.cloudflare.com https://ct.pinterest.com https://connect.facebook.net https://cdn.id5-sync.com https://agent.intentiq.com https://s.ntv.io https://s.pinimg.com https://platform.twitter.com https://jadserve.postrelease.com https://c1.rfihub.net https://*.taboola.com https://*.teads.tv https://s.yimg.com https://static.zdassets.com https://assets.calendly.com https://js.klarna.com https://*.locally.com *.yotpo.com https://*.klaviyo.com https://cdn.segment.com https://*.cdp.danner.com https://*.cdp.lacrossefootwear.com https://cdn.hub-box.com https://*.addressy.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://fonts.googleapis.com/ *.bglobale.com *.global-e.com https://static.klaviyo.com https://cdnjs.cloudflare.com https://*.typekit.net https://x.klarnacdn.net *.yotpo.com *.googleapis.com https://*.klaviyo.com https://api.addressy.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com https://i.lfi.media 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adyen.com *.google.com google.com payments-eu.amazon.com *.paypal.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://*.attn.tv https://bat.bing.com https://cdn.ravm.tv https://gum.criteo.com https://id.crwdcntrl.net https://ct.pinterest.com https://*.doubleclick.net https://id5-sync.com https://eu-1-id5-sync.com/ https://*.reddit.com https://*.redditstatic.com https://*.taboola.com https://*.teads.tv https://s.yimg.com https://*.zdassets.com https://*.zendesk.com https://tags.w55c.net https://js.klarna.com https://evt-na.klarnaservices.com https://www.locally.com *.yotpo.com https://*.klaviyo.com https://api.segment.io https://cdn.segment.com https://*.cdp.danner.com https://*.cdp.lacrossefootwear.com https://api.addressy.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 frame-ancestors 'none'; report-uri https://endpoint3.collection.us2.sumologic.com/receiver/v1/http/ZaVnC4dhaV30Tj5vtZfuZ0tYPfqb8xOSxI9TJ5CbQ_ZE4W4aGoGW8HViqViD0nttCcDqHOZNNhObvJtSbYn1XDP7uSjlITCzSLlNsuSdwZ46El5dcVC6kg== 2 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.sagepay.com *.opayo.eu.elavon.com *.fontawesome.com *.cloudflare.com *.twitter.com *.twimg.com *.trustedshops.com *.googleapis.com *.usablenet.com *.udev1a.net *.narvar.com *.narvar.qa *.tawk.to data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.sagepay.com *.opayo.eu.elavon.com *.arcot.com *.rsa3dsauth.co.uk *.rsa3dsauth.com *.boc.cn *.afs.com.bh *.enfuce.com *.cardcenter.ch *.nexigroup.com *.pluscard.de *.qiib.com.qa *.paylife.at *.redsys.es *.3dsecure.no *.modirum.com *.edb.com *.viseca.ch *.apata.io *.capitalone.com *.dnp-cdms.jp *.revolut.com *.bankserv.co.za *.swisscard.ch *.six-group.com *.marqeta.com *.cardinalcommerce.com *.wlp-acs.com *.imbank.com *.tsys.co.uk *.sia.eu *.garanti.com.tr *.commerzbank.de *.cmbchina.com *.alahli.com *.mycardsecure.com *.gps.com.bh *.citibank.com *.wibmo.com *.dkb.de *.monzo.com *.alinma.com *.nccc.com.tw *.starlingbank.com *.danskebank.com *.pekao24.pl *.lloydsbank.co.uk/ *.lloydsbank.com/ *.lloydsbankinggroup.com/ *.channel-cards-auth-api.lloydsbankinggroup.com/ *.sparebank1.no *.rabobank.nl *.s-id-check-sparkassen.de *.sparkassen-kreditkarten.de *.mbank.pl *.secure2gw.ro *.btrl.ro *.cafis-paynet.jp *.borica.bg *.fibank.bg *.cic.fr *.zaba.hr *.citibank.co.in *.centrum24.pl *.bankmillennium.pl *.icps.mu *.egolomt.mn *.lcl.fr *.ctbcbank.com *.qiwi.com *.postfinance.ch *.citadele.lv *.kib.com.kw *.cathaybk.com.tw *.pkobp.pl *.acdcproc.com *.abanca.com *.n26.com *.klikbca.com *.psa.at *.sumup.com *.eglobal.com.mx *.pl.ing.com *.qnb.com *.rpc-raiffeisen.com *.sebkort.com *.ocbc.com *.tapngo.com.hk *.stcpay.com.sa *.creditmutuel.fr *.luottokunta.fi *.swedbank.se *.unibank.am *.estcard.ee *.hyundaicard.com *.privatbank.ua *.fssnet.co.in *.kbcard.com *.luminorgroup.com *.mashreq.com *.mercurypaymentservices.it *.moneta.cz *.sensebank.com.ua *.sibs.pt *.stripeauthentications.com *.dskbank.bg *.otpbank.hu *.techcombank.com.vn *.touch.tech *.asseco-see.hr *.3dsecure-csas.cz *.cyris.com *.secureacs.com *.acb.com.vn https://logistics-stage.ecpay.com.tw/Express/map https://logistics.ecpay.com.tw/Express/map https://logistics-stage.ecpay.com.tw/helper/printTradeDocument https://logistics.ecpay.com.tw/helper/printTradeDocument *.twitter.com *.usablenet.com *.udev1a.net https://plumrocket.com *.authorize.net 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com * *.tawk.to 'self' 'unsafe-inline'; frame-ancestors *.certcapture.com *.authorize.net 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.affirm.com *.affirm.ca *.certcapture.com *.sagepay.com *.opayo.eu.elavon.com *.arcot.com *.rsa3dsauth.co.uk *.rsa3dsauth.com *.boc.cn *.afs.com.bh *.enfuce.com *.cardcenter.ch *.pluscard.de *.qiib.com.qa *.nexigroup.com *.paylife.at *.redsys.es *.3dsecure.no *.modirum.com *.edb.com *.viseca.ch *.apata.io *.capitalone.com *.dnp-cdms.jp *.revolut.com *.bankserv.co.za *.swisscard.ch *.six-group.com *.marqeta.com *.cardinalcommerce.com *.wlp-acs.com *.imbank.com *.tsys.co.uk *.sia.eu *.garanti.com.tr *.commerzbank.de *.cmbchina.com *.alahli.com *.mycardsecure.com *.gps.com.bh *.citibank.com *.wibmo.com *.dkb.de *.monzo.com *.alinma.com *.nccc.com.tw *.starlingbank.com *.danskebank.com *.pekao24.pl *.lloydsbank.co.uk/ *.lloydsbank.com/ *.lloydsbankinggroup.com/ *.channel-cards-auth-api.lloydsbankinggroup.com/ *.sparebank1.no *.rabobank.nl *.s-id-check-sparkassen.de *.sparkassen-kreditkarten.de *.mbank.pl *.secure2gw.ro *.btrl.ro *.cafis-paynet.jp *.borica.bg *.fibank.bg *.cic.fr *.zaba.hr *.citibank.co.in *.centrum24.pl *.bankmillennium.pl *.icps.mu *.egolomt.mn *.lcl.fr *.ctbcbank.com *.qiwi.com *.postfinance.ch *.citadele.lv *.kib.com.kw *.cathaybk.com.tw *.pkobp.pl *.acdcproc.com *.abanca.com *.n26.com *.klikbca.com *.psa.at *.sumup.com *.eglobal.com.mx *.pl.ing.com *.qnb.com *.rpc-raiffeisen.com *.sebkort.com *.ocbc.com *.tapngo.com.hk *.stcpay.com.sa *.creditmutuel.fr *.luottokunta.fi *.swedbank.se *.unibank.am *.estcard.ee *.hyundaicard.com *.privatbank.ua *.fssnet.co.in *.kbcard.com *.luminorgroup.com *.mashreq.com *.mercurypaymentservices.it *.moneta.cz *.sensebank.com.ua *.sibs.pt *.stripeauthentications.com *.dskbank.bg *.otpbank.hu *.techcombank.com.vn *.touch.tech *.asseco-see.hr *.3dsecure-csas.cz *.cyris.com *.secureacs.com *.acb.com.vn landofcoder.com maps.googleapis.com chart.googleapis.com *.twitter.com *.usablenet.com *.udev1a.net https://plumrocket.com *.authorize.net c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com * https://accounts.google.com *.tawk.to 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com p.typekit.net *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net data: d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.payments-amazon.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.affirm.com *.affirm.ca *.certcapture.com *.sagepay.com *.opayo.eu.elavon.com ebizmarts-website.s3.amazonaws.com magefan.com cm.magefan.com *.cloudflare.com *.klarna.com *.googleadservices.com *.google-analytics.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.usablenet.com *.udev1a.net *.clarity.ms *.bing.com *.nofraud.com *.googletagmanager.com *.doubleclick.net *.facebook.net *.facebook.com *.facebook.com/tr/ *.tiktok.com *.googlesyndication.com *.google.com *.criteo.com *.narvar.com *.narvar.qa hexagon-analytics.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.tawk.to cdn.jsdelivr.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com amcglobal.sc.omtrdc.net *.adobe.io use.typekit.net magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.magento-ds.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.magento-datasolutions.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.affirm.com *.affirm.ca *.certcapture.com *.sagepay.com *.opayo.eu.elavon.com landofcoder.com maps.googleapis.com chart.googleapis.com *.mookie1.com 'self' *.paypal.com *.sandbox.paypal.com *.googletagmanager.com *.plumrocket.com *.tawk.to *.bam-cell.nr-data.net *.gstatic.com *.usablenet.com *.udev1a.net *.nofraud.com *.clarity.ms *.mmapiws.com *.googleadservices.com *.doubleclick.net *.google-analytics.com *.facebook.net *.facebook.com *.facebook.com/tr/ *.tiktok.com *.criteo.com *.bing.com cdn.sift.com api3.veritrans.co.jp *.authorize.net js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com https://accounts.google.com https://www.gstatic.com cdn.jsdelivr.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com *.certcapture.com *.sagepay.com *.opayo.eu.elavon.com *.fontawesome.com self *.cloudflare.com *.googleapis.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.usablenet.com *.udev1a.net *.bing.com *.criteo.com assets.braintreegateway.com https://accounts.google.com https://www.gstatic.com *.tawk.to cdn.jsdelivr.net 'self' 'unsafe-inline'; object-src landofcoder.com maps.googleapis.com chart.googleapis.com 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.narvar.com *.narvar.qa 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.magento.com *.adobe.io performance.typekit.net commerce.adobe.io *.sentry.io *.paypal.com google.com *.google.com *.magento-datasolutions.com *.magento-ds.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.affirm.com *.affirm.ca *.certcapture.com *.sagepay.com *.opayo.eu.elavon.com landofcoder.com maps.googleapis.com chart.googleapis.com self *.cloudflare.com *.twitter.com *.twimg.com *.usablenet.com *.udev1a.net *.nofraud.com *.clarity.ms *.mmapiws.com *.googletagmanager.com *.googleadservices.com *.doubleclick.net *.google-analytics.com *.facebook.net *.facebook.com *.facebook.com/tr/ *.tiktok.com *.criteo.com api3.veritrans.co.jp *.authorize.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com https://accounts.google.com *.tawk.to wss://*.tawk.to 'self' 'unsafe-inline'; child-src *.certcapture.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://mcstaging.mikimoto.com/; report-to report-endpoint; 2 default-src 'self' data: ; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://maps.googleapis.com *.inviewuclab.com static.zdassets.com js.stripe.com *.google.com *.gstatic.com gstatic.com connect.facebook.net *.zendesk.com blob: ; script-src-elem 'self' 'unsafe-inline' https://maps.googleapis.com *.google.com *.gstatic.com static.zdassets.com js.stripe.com ; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com cdn.datatables.net ; style-src-elem 'self' 'unsafe-inline' fonts.googleapis.com cdn.datatables.net ; style-src-attr 'unsafe-inline' ; img-src 'self' https://maps.gstatic.com https://maps.googleapis.com data: blob: 127.0.0.1:18623 *.mapbox.com *.facebook.com *.google.com *.gstatic.com ; frame-src 'self' *.google.com *.google.ie js.stripe.com player.vimeo.com www.youtube.com; font-src 'self' https://fonts.gstatic.com data: gstatic.com *.gstatic.com *.alicdn.com ; connect-src 'self' https://google.com *.google.com https://maps.googleapis.com https://maps.gstatic.com ekr.zdassets.com *.zendesk.com wss://127.0.0.1:18623 https://127.0.0.1:18623 mlts.dynamsoft.com *.mapbox.com https://events.mapbox.com *.inviewuclab.com https://tiles.openfreemap.org ; worker-src 'self' blob: ; upgrade-insecure-requests ; report-uri https://9a1a6d99ab6aa4ac3290a60bae476ab7.report-uri.com/r/d/csp/enforce 2 default-src 'self'; script-src 'self' 'unsafe-inline' blob: https://*.prismic.io https://*.cdn.prismic.io https://*.google.com https://*.googletagmanager.com https://*.google-analytics.com https://*.doubleclick.net https://*.vidyard.com https://*.ceros.com https://*.salesloft.com https://*.clarity.ms https://*.consentmanager.net https://*.linkedin.com https://*.stackadapt.com https://*.6sc.co https://*.adsrvr.org https://js.zi-scripts.com https://cdn.calibermind.com https://pi.pardot.com https://snap.licdn.com https://siteimproveanalytics.com https://analytics-sm.com https://cdn.evgnet.com https://connect.bakertilly.com https://explore.bakertilly.com https://connect.facebook.net https://bat.bing.com https://static.cloudflareinsights.com https://api.fouanalytics.com; style-src 'self' 'unsafe-inline' https:; img-src 'self' blob: data: https:; font-src 'self' data: https:; connect-src 'self' https://*.prismic.io https://*.algolia.net https://*.algolianet.com https://*.google-analytics.com https://*.googletagmanager.com https://*.doubleclick.net https://*.googleadservices.com https://*.salesloft.com https://*.stackadapt.com https://*.consentmanager.net https://*.6sc.co https://*.adsrvr.org https://scout.salesloft.com https://e.calibermind.com https://js.zi-scripts.com https://ws.zoominfo.com https://px.ads.linkedin.com https://analytics-sm.com https://bakertillyusllp.us-6.evergage.com https://epsilon.6sense.com https://connect.bakertilly.com https://www.google.com https://pagead2.googlesyndication.com https://bat.bing.net https://a.clarity.ms https://translate.googleapis.com https://translate-pa.googleapis.com https://api.fouanalytics.com https://static.cloudflareinsights.com; frame-src 'self' https://*.youtube.com https://*.vimeo.com https://*.vidyard.com https://*.ceros.com https://view.ceros.com https://cdn.consentmanager.net https://bakertilly.prismic.io https://www.googletagmanager.com https://connect.bakertilly.com https://explore.bakertilly.com https://experience.arcgis.com https://player.simplecast.com https://widget.spreaker.com https://insight.adsrvr.org https://match.adsrvr.org; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self' https://bakertilly.prismic.io; report-uri /api/csp-report; report-to csp-endpoint 2 default-src 'self' data: blob: https://*.trustage.com https://*.trustagedem.com https://*.trustagedemo.com; connect-src 'self' data: properties: https://cmfglifeinsurance.us-6.evergage.com https://*.google-analytics.com https://*.google.com https://*.linkedin.com https://*.niceincontact.com https://clientstream.launchdarkly.com/ https://fonts.gstatic.com https://*.optimizely.com https://*.cunamutual.com https://www.nextinsure.com https://geolocation.onetrust.com https://privacyportal.onetrust.com https://*.googlesyndication.com https://*.trustage.com https://us-central1-adaptive-growth.cloudfunctions.net https://cdn.linkedin.oribi.io https://s.yimg.com https://*.doubleclick.net https://*.trustagedem.com https://*.trustagedemo.com https://*.oktacdn.com https://*.bing.com https://*.googleapis.com https://cunamutual.okta.com https://cdn.cookielaw.org https://cunamutual.oktapreview.com/ https://*.googleadservices.com/ https://*.qualtrics.com/ https://dc.services.visualstudio.com/ https://*.levelaccess.net https://www.googletagmanager.com https://facebook.com/ https://*.segment.io https://*.segment.com https://*.permutive.com https://calc-backend-prod.herokuapp.com https://www.facebook.com https://eastus2-0.in.applicationinsights.azure.com https://*.api.boomtrain.com; frame-ancestors 'self' https://trustage.com https://*.optimizely.com https://*.trustagedem.com https://*.trustagedemo.com; frame-src 'self' https://trustage.com https://*.googlesyndication.com https://cunamutual.widen.net https://login.microsoftonline.com https://*.widencdn.net https://*.opendns.com https://*.optimizely.com https://www.youtube.com https://chase.hostedpaymentservice.net https://chase-var.hostedpaymentservice.net https://*.doubleclick.net https://*.trustage.com https://*.trustagedem.com https://*.trustagedemo.com https://*.oktacdn.com https://www.googletagmanager.com https://*.trustpilot.com/ https://*.flashtalking.com https://*.google.com https://*.qualtrics.com https://*.affec.tv https://*.opendns.com https://www.facebook.com https://*.ceros.com https://home-c27.incontact.com https://*.polly.co https://web-modules-de-na1.niceincontact.com; script-src 'self' 'unsafe-eval' 'unsafe-inline' blob: https://cmfglifeinsurance.us-6.evergage.com https://*.googlesyndication.com https://*.optimizely.com https://optimizely.s3.amazonaws.com https://cdn-assets-prod.s3.amazonaws.com https://static-demo.trustage.cloud https://*.trustage.com https://*.googleadservices.com https://*.trustagedem.com https://*.trustagedemo.com https://cdn.cookielaw.org https://*.signalintent.com https://*.google.com https://chase-var.hostedpaymentservice.net https://chase.hostedpaymentservice.net https://cdn.pdst.fm https://snap.licdn.com https://insurance.mediaalpha.com https://us-central1-adaptive-growth.cloudfunctions.net https://s.yimg.com https://*.facebook.net https://geolocation.onetrust.com https://cdn.linkedin.oribi.io https://privacyportal.onetrust.com https://*.google.com https://sp.analytics.yahoo.com https://*.linkedin.com https://www.pagespeed-mod.com https://*.google-analytics.com https://*.salesforceliveagent.com/ https://*.oktacdn.com/ https://*.trustpilot.com/ https://*.gstatic.com/ https://*.googletagmanager.com/ https://az416426.vo.msecnd.net/ https://*.levelaccess.net/ https://*.qualtrics.com/ https://www.googleoptimize.com https://bat.bing.com https://solutions.invocacdn.com https://pnapi.invoca.net https://*.affec.tv/ https://*.evgnet.com/ https://*.ceros.com https://home-c27.incontact.com https://secure.adnxs.com https://cdn.permutive.com https://trkn.us https://www.facebook.com https://cdn.c360a.salesforce.com/ https://seal.digicert.com/ https://*.boomtrain.com; script-src-elem 'self' 'unsafe-eval' 'unsafe-inline' https://*.trustage.com https://cmfglifeinsurance.us-6.evergage.com https://www.gstatic.com https://*.optimizely.com https://*.affec.tv/ https://chase.hostedpaymentservice.net https://*.bing.com https://*.google.com https://*.doubleclick.net https://*.googleadservices.com https://*.google-analytics.com https://www.googletagmanager.com https://*.googleadservices.com https://*.googlesyndication.com https://cdn.pdst.fm https://cdn.cookielaw.org https://snap.licdn.com https://*.qualtrics.com https://s.yimg.com https://*.salesforceliveagent.com https://*.facebook.com https://connect.facebook.net https://www.youtube.com https://bat.bing.com https://*.evgnet.com/ https://*.levelaccess.net https://chase-var.hostedpaymentservice.net https://*.oktacdn.com https://www.googleoptimize.com https://*.trustpilot.com/ https://az416426.vo.msecnd.net/ https://solutions.invocacdn.com https://secure.adnxs.com https://cdn.permutive.com https://*.signalintent.coms https://*.segment.com https://*.ceros.coms https://cdn.c360a.salesforce.com/ https://seal.digicert.com/ https://tracking.intentsify.io/ https://web-modules-de-na1.niceincontact.com/; style-src 'self' 'unsafe-inline' https://cmfglifeinsurance.us-6.evergage.com https://*.trustage.com https://*.trustagedem.com https://*.trustagedemo.com https://*.signalintent.com https://rsms.me https://*.googleapis.com https://*.google.com https://*.googlesyndication.com https://google.ca https://www.googleoptimize.com https://*.google-analytics.com https://*.trustpilot.com/ https://www.youtube.com https://web-modules-de-na1.niceincontact.com https://pwm-image.trendmicro.com https://cdn.honey.io https://www.gstatic.com/; img-src 'self' 'unsafe-inline' 'unsafe-eval' data: https:; font-src 'self' data: https://cmfglifeinsurance.us-6.evergage.com https://fonts.gstatic.com https://rsms.me https://maxcdn.bootstrapcdn.com https://fonts.cdnfonts.com https://use.fontawesome.com https://static2.sharepointonline.com https://static.zip.co https://embed.signalintent.com https://appservice.azureedge.net/; report-uri /api/csp/report; 2 default-src 'self'; img-src * data: https:; script-src 'unsafe-inline' 'unsafe-eval' https:; style-src 'unsafe-inline' *; frame-src https:; connect-src https:; font-src 'self' https://cdn.segmentify.com; 2 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com cash-f.squarecdn.com *.googleapis.com fonts.googleapis.com *.fontawesome.com https://fonts.bunny.net https://cdnjs.cloudflare.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com * https://plumrocket.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com * *.instagram.com https://plumrocket.com *.dotdigital-pages.com *.dotdigital.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.trustpilot.com *.doubleclick.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io * *.cdninstagram.com *.googleapis.com *.openstreetmap.org maps.googleapis.com maps.gstatic.com *.trackedlink.net magefan.com cm.magefan.com https://firebasestorage.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.hsforms.net *.hsforms.com 'self' data: *.cookielaw.org *.facebook.com *.google.fr data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com *.cash.app *.visa.com *.mastercard.com *.instagram.com *.googleapis.com *.gstatic.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal *.avada.io https://cdnjs.cloudflare.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com https://paul-marius.my.join-stories.com *.hsforms.net *.hsforms.com https://genki.paulmarius.fr https://genki.paulmarius.de https://genki.paulmarius.es https://genki.paulmarius.it https://genki.paulmarius.nl https://genki.paulmarius.com https://genki.paulmarius.us https://genki.paulmarius.co.uk *.bing.com *.clarity.ms https://js.klarna.com *.trustpilot.com *.cookielaw.org *.cookieless-data.com *.paulmarius.fr *.googlesyndication.com *.doubleclick.net *.apicit.net *.clickintext.net *.facebook.net *.googletagmanager.com apicit.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.cash.app *.fontawesome.com https://fonts.bunny.net https://fonts.googleapis.com https://cdnjs.cloudflare.com assets.braintreegateway.com *.googleapis.com *.gstatic.com https://x.klarnacdn.net *.trustpilot.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.cdninstagram.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com * *.googleapis.com maps.googleapis.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com *.cookielaw.org *.googlesyndication.com *.db-ip.com *.doubleclick.net 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 script-src 'self' 'unsafe-inline' 'unsafe-eval' https:; script-src-elem 'self' 'unsafe-inline' 'unsafe-eval' https:; script-src-attr 'self' 'unsafe-inline' 'unsafe-eval' https:; img-src 'self' data: blob: https:; font-src 'self' data: https:; connect-src 'self' wss: https:; object-src 'self'; child-src blob:; frame-src 'self' https:; worker-src blob:; frame-ancestors 'none'; base-uri 'none'; report-uri https://47327c6a613c1754bda1362d946d96dd.report-uri.com/r/t/csp/reportOnly; report-to csp-endpoint 2 font-src *.googleapis.com *.gstatic.com *.fontawesome.com fonts.googleapis.com parfumerie.com.ar d3cdlnm7te7ky2.cloudfront.net pftesting.66ecommerce.com editionprivee.com d28dzyqv2ij3aj.cloudfront.net eptesting.66ecommerce.com diorassets.blob.core.windows.net player.freecaster.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.apptrian.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com https://seo.mageplaza.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com 'self' 'unsafe-inline'; frame-ancestors *.despegar.com *.koin.com.br *.googletagmanager.com *.gocuotas.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com player.vimeo.com https://www.google.com/recaptcha/ www.apptrian.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com bytedance: sslocal: www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.despegar.com *.koin.com.br *.googletagmanager.com maps.googleapis.com chart.googleapis.com *.gocuotas.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com https://mobbex.com *.weltpixel.com https://www.googletagmanager.com https://www.google-analytics.com https://www.googleadservices.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.googleapis.com *.gstatic.com www.apptrian.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com analytics.tiktok.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.adobedtm.com *.despegar.com *.koin.com.br *.googletagmanager.com fonts.googleapis.com *.gocuotas.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com res.sugaway.io parfumerie.com.ar d3cdlnm7te7ky2.cloudfront.net pftesting.66ecommerce.com static.whatsapp.net editionprivee.com d28dzyqv2ij3aj.cloudfront.net eptesting.66ecommerce.com c.clarity.ms www.google.com.ar www.mercadopago.com.ar c.bing.com diorassets.blob.core.windows.net player.freecaster.com maps.gstatic.com https://www.googletagmanager.com https://www.google-analytics.com https://www.googleadservices.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://maps.googleapis.com *.gstatic.com www.apptrian.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com analytics.tiktok.com chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.despegar.com *.koin.com.br *.googletagmanager.com maps.googleapis.com chart.googleapis.com *.gocuotas.com *.avada.io *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.mobbex.com parfumerie.com.ar d3cdlnm7te7ky2.cloudfront.net pftesting.66ecommerce.com editionprivee.com d28dzyqv2ij3aj.cloudfront.net eptesting.66ecommerce.com js-agent.newrelic.com www.clarity.ms maps.google.com live.decidir.com fpcdn.io assets-cdn.woowup.com diorassets.blob.core.windows.net player.freecaster.com https://www.googletagmanager.com https://www.google-analytics.com https://www.googleadservices.com https://merchants.playdigital.com.ar/ https://merchants.preprod.playdigital.com.ar/ https://ecommerce-modal.modo.com.ar/ https://ecommerce-modal.preprod.modo.com.ar/ 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com downloads.mailchimp.com *.fontawesome.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com parfumerie.com.ar d3cdlnm7te7ky2.cloudfront.net pftesting.66ecommerce.com editionprivee.com d28dzyqv2ij3aj.cloudfront.net eptesting.66ecommerce.com cdn.jsdelivr.net diorassets.blob.core.windows.net player.freecaster.com https://www.googletagmanager.com https://www.google-analytics.com https://www.googleadservices.com https://ecommerce-modal.modo.com.ar/ https://ecommerce-modal.preprod.modo.com.ar/ 'self' 'unsafe-inline'; object-src maps.googleapis.com chart.googleapis.com 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com parfumerie.com.ar d3cdlnm7te7ky2.cloudfront.net pftesting.66ecommerce.com static.whatsapp.net editionprivee.com d28dzyqv2ij3aj.cloudfront.net eptesting.66ecommerce.com diorassets.blob.core.windows.net player.freecaster.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.googleapis.com www.apptrian.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com analytics.tiktok.com form-assets.mailchimp.com *.intuit.com *.amazonaws.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.despegar.com *.googletagmanager.com maps.googleapis.com chart.googleapis.com *.gocuotas.com https://get.geojs.io *.avada.io *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.mobbex.com parfumerie.com.ar d3cdlnm7te7ky2.cloudfront.net pftesting.66ecommerce.com editionprivee.com d28dzyqv2ij3aj.cloudfront.net eptesting.66ecommerce.com google.com i.clarity.ms n.clarity.ms z.clarity.ms parfumerie.zendesk.com pod-20.zendesk.com bam.nr-data.net api.fpjs.io rum-collector-2.pingdom.net diorassets.blob.core.windows.net player.freecaster.com https://merchants.playdigital.com.ar/ https://merchants.preprod.playdigital.com.ar/ https://ecommerce-modal.modo.com.ar/ https://ecommerce-modal.preprod.modo.com.ar/ 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 default-src 'self' 'unsafe-inline' https:; report-uri https://reporturi.savagescape.com/report.php; report-to default 2 default-src 'self' ; style-src 'self' 'unsafe-inline' https://cdn-cookieyes.com ; script-src 'self' 'unsafe-inline' 'wasm-unsafe-eval' https://cdn.apple-mapkit.com https://www.googletagmanager.com https://www.google.com https://www.gstatic.com https://cdn-cookieyes.com ; img-src 'self' blob: data: https://snapshot.apple-mapkit.com https://cdn.apple-mapkit.com https://www.googletagmanager.com https://www.google.co.uk https://*.ytimg.com https://img.youtube.com https://secure.gravatar.com https://cdn-cookieyes.com ; font-src 'self' data: https://fonts.gstatic.com ; media-src 'self' data: ; connect-src 'self' https://api.apple-mapkit.com https://cdn.apple-mapkit.com https://gsp10.apple-mapkit.com https://www.google.com https://*.google-analytics.com https://analytics.google.com https://*.analytics.google.com https://www.googletagmanager.com https://log.cookieyes.com https://cdn-cookieyes.com https://*.cookieyes.com ; frame-src 'self' https://allergens.jdwetherspoon.com https://www.jdwetherspooncareers.com https://www.google.com https://*.youtube-nocookie.com https://*.youtube.com ; frame-ancestors 'self' ; object-src 'none' ; base-uri 'self' ; form-action 'self' ; worker-src 'self' blob: ; upgrade-insecure-requests ; report-uri https://jdwetherspoon.report-uri.com/r/d/csp/reportOnly ; report-to default ; 2 default-src 'self' 'unsafe-inline' 'unsafe-eval' data: blob: *; script-src 'self' https://*.churnkey.co https://*.cello.so https://*.hotjar.com https://*.hotjar.io https://*.posthog.com https://prodregistryv2.org https://featureassets.org https://api.statsig.com https://featuregates.org https://statsigapi.net https://events.statsigapi.net https://assetsconfigcdn.org https://cloudflare-dns.com https://*.ingest.sentry.io https://challenges.cloudflare.com https://consent.cookiebot.com https://consentcdn.cookiebot.com https://googleads.g.doubleclick.net https://plausible.io https://*.google.com https://www.google.com https://www.google-analytics.com https://www.googleadservices.com https://pagead2.googlesyndication.com https://www.googletagmanager.com https://*.googleusercontent.com https://*.mermaidchart.com https://vercel.live https://*.reddit.com https://www.redditstatic.com https://bat.bing.com https://www.bing.com https://c.bing.com https://www.clarity.ms 'nonce-TwqbsC+BvedTIoSOSalkwQ=='; report-to sentry 2 default-src 'self' blob: *; img-src 'self' data: *; script-src 'self' blob: * 'unsafe-inline' 'unsafe-eval'; style-src 'self' * 'unsafe-inline'; font-src 'self' data: *; connect-src *; frame-ancestors 'self'; base-uri 'self'; form-action 'self' 2 object-src 'none'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://cdn.jsdelivr.net https://cdn.tagcommander.com https://cdnjs.cloudflare.com https://instant.page https://polyfill-fastly.io https://unpkg.com https://use.fontawesome.com https://www.google.com; script-src-attr 'self'; script-src-elem 'self' 'unsafe-inline' http://pero.securite-routiere.gouv.fr https://www.gstatic.com https://www.youtube.com https://s2.adform.net/banners/scripts/st/trackpoint-async.js https://server.adform.net/Serving/TrackPoint/ https://cstatic.weborama.fr cdn.trustcommander.net www.googletagmanager.com https://api.dmcdn.net https://*.criteo.com https://connect.facebook.net https://cdn.jsdelivr.net https://cdn.tagcommander.com https://cdnjs.cloudflare.com https://instant.page https://polyfill-fastly.io https://unpkg.com https://use.fontawesome.com https://www.google.com; style-src 'self' 'unsafe-inline' code.ionicframework.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://fonts.googleapis.com https://maxcdn.bootstrapcdn.com https://unpkg.com; style-src-attr 'self' 'unsafe-inline'; frame-ancestors 'self' 2 font-src fonts.gstatic.com use.typekit.net cash-f.squarecdn.com https://*.gstatic.com data: *.sodatech.com *.sodatech.net *.gstatic.com *.typekit.net cdn.livechatinc.com mediacdn.espssl.com viewer.byondxr.com use.fontawesome.com 'self' data: https://fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com * *.adyen.com api.bazaarvoice.com stg.api.bazaarvoice.com pal-test.adyen.com www.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ * *.adyen.com *.sharethis.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com *.ehappify.com www.xtento.com *.vimeo.com *.jsctool.com *.pinterest.com *.mmcagentur.at *.doubleclick.net *.facebook.com *.facebook.net *.google.com *.demdex.net *.authorize.net *.paypal.com *.googletagmanager.com *.xtento.com *.app-wallee.com *.waltpixel.com *.equitystory.com offer.slgnt.us vars.hotjar.com *.pepperjamnetwork.com services.listrak.com *.serverdata.net *.livechatinc.com *.lindtusa.com *.russellstover.com *.ghirardelli.com https://*.ordergroove.com *.weltpixel.com app-wallee.com www.jsctool.com static.ogmystyle.com static2.ogmystyle.com www.mystyleplatform.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.trustpilot.com geowidget.inpost.pl sandbox-easy-geowidget-sdk.easypack24.net widget.packeta.com https://www.paypalobjects.com https://lindtusa.rlvs.co.uk https://ghirardelli.slgnt.us https://byondxr-viewer.byondxr.com/launcher/1.0.58/package/index.js tinyurl.com/LINDT-LAUNCHER https://optmize.google.com nytrng.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io * https://*.gstatic.com *.adyen.com *.sharethis.com display.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com network-a.bazaarvoice.com network-stg-a.bazaarvoice.com photos-uat-us.bazaarvoice.com img.youtube.com *.cloudfront.net *.amazonaws.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ www.xtento.com cdn.xtento.com blob: lindt.test *.lindt.test maps.googleapis.com *.pinterest.com *.postcodeanywhere.co.uk *.klarna.com *.invibes.com *.b26net.com https://www.google-analytics.com *.googletagmanager.com *.teads.tv *.videostep.com *.facebook.com *.google.com *.google.ad *.google.ae *.google.com.af *.google.com.ag *.google.com.ai *.google.al *.google.am *.google.co.ao *.google.com.ar *.google.as *.google.at *.google.com.au *.google.az *.google.ba *.google.com.bd *.google.be *.google.bf *.google.bg *.google.com.bh *.google.bi *.google.bj *.google.com.bn *.google.com.bo *.google.com.br *.google.bs *.google.bt *.google.co.bw *.google.by *.google.com.bz *.google.ca *.google.cd *.google.cf *.google.cg *.google.ch *.google.ci *.google.co.ck *.google.cl *.google.cm *.google.cn *.google.com.co *.google.co.cr *.google.com.cu *.google.cv *.google.com.cy *.google.cz *.google.de *.google.dj *.google.dk *.google.dm *.google.com.do *.google.dz *.google.com.ec *.google.ee *.google.com.eg *.google.es *.google.com.et *.google.fi *.google.com.fj *.google.fm *.google.fr *.google.ga *.google.ge *.google.gg *.google.com.gh *.google.com.gi *.google.gl *.google.gm *.google.gr *.google.com.gt *.google.gy *.google.com.hk *.google.hn *.google.hr *.google.ht *.google.hu *.google.co.id *.google.ie *.google.co.il *.google.im *.google.co.in *.google.iq *.google.is *.google.it *.google.je *.google.com.jm *.google.jo *.google.co.jp *.google.co.ke *.google.com.kh *.google.ki *.google.kg *.google.co.kr *.google.com.kw *.google.kz *.google.la *.google.com.lb *.google.li *.google.lk *.google.co.ls *.google.lt *.google.lu *.google.lv *.google.com.ly *.google.co.ma *.google.md *.google.me *.google.mg *.google.mk *.google.ml *.google.com.mm *.google.mn *.google.ms *.google.com.mt *.google.mu *.google.mv *.google.mw *.google.com.mx *.google.com.my *.google.co.mz *.google.com.na *.google.com.ng *.google.com.ni *.google.ne *.google.nl *.google.no *.google.com.np *.google.nr *.google.nu *.google.co.nz *.google.com.om *.google.com.pa *.google.com.pe *.google.com.pg *.google.com.ph *.google.com.pk *.google.pl *.google.pn *.google.com.pr *.google.ps *.google.pt *.google.com.py *.google.com.qa *.google.ro *.google.ru *.google.rw *.google.com.sa *.google.com.sb *.google.sc *.google.se *.google.com.sg *.google.sh *.google.si *.google.sk *.google.com.sl *.google.sn *.google.so *.google.sm *.google.sr *.google.st *.google.com.sv *.google.td *.google.tg *.google.co.th *.google.com.tj *.google.tl *.google.tm *.google.tn *.google.to *.google.com.tr *.google.tt *.google.com.tw *.google.co.tz *.google.com.ua *.google.co.ug *.google.co.uk *.google.com.uy *.google.co.uz *.google.com.vc *.google.co.ve *.google.vg *.google.co.vi *.google.com.vn *.google.vu *.google.ws *.google.rs *.google.co.za *.google.co.zm *.google.co.zw *.google.cat *.taboola.com *.doubleclick.net *.outbrain.com *.adobedtm.com *.omtrdc.net *.demdex.net *.everesttech.net *.magentocommerce.com *.sodatech.com *.sodatech.net api.official-deals.co.uk api.official-coupons.com *.adsymptotic.com cdn.livechat-files.com cp.official-coupons.com cookie-cdn.cookiepro.com cp.official-deals.co.uk site-azp.slgnt.us ct.pinterest.com *.ads.linkedin.com cdn.polyfill.io offer.slgnt.us *.blob.core.windows.net s.pinimg.com snap.licdn.com mediacdn.espssl.com *.clarity.ms *.bing.com *.serverdata.net lindtna.test *.lindtna.test *.livechatinc.com mageside.com app-wallee.com *.gstatic.com d.ratepay.com viewer.byondxr.com s3.us-west-2.amazonaws.com showroom-media.byondxr.com media-optimization-service.byondxr.com *.byondxr.com *.listrakbi.com www.mystyleplatform.com static.mystyleplatform.com static2.mystyleplatform.com static2.ogmystyle.com mystyleplatform.s3.us-west-2.amazonaws.com https://www.unifaunonline.se https://*.tile.openstreetmap.org/ www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com https://redchamps.com 'self' data: geowidget.inpost.pl sandbox-easy-geowidget-sdk.easypack24.net widget.packeta.com https://mediacdn.espssl.com/2824/Shared/Modal/chocolate.png https://www.linkedin.com https://*.linkedin.com/ https://px.ads.linkedin.com https://mcstaging.russellstover.com https://mcstaging.lindtusa.com https://mcstaging.ghirardelli.com https://mcprod.lindtusa.com *.googleadservices.com *.yieldify.com https://www.google-anaytics.com https://www.googletagmanager.com https://optimize.google.com https://cdn.livechat-static.com *.bazaarvoice.com https://shopper.shop.pe i.liadm.com v2assets.zopim.io *.cloudfunctions.net partner.mediawallahscript.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net amcglobal.sc.omtrdc.net *.adobe.io use.typekit.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com *.magento-ds.com *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com *.cash.app *.visa.com *.mastercard.com *.sharethis.com *.googleapis.com *.attn.tv events.attentivemobile.com apps.bazaarvoice.com apps.nexus.bazaarvoice.com apps-stg.nexus.bazaarvoice.com analytics-static.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com mpsnare.iesnare.com widget.freshworks.com m2epro.freshdesk.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ www.xtento.com cdn.xtento.com *.pcapredict.com lindt.slgnt.eu maps.googleapis.com *.pinterest.com *.postcodeanywhere.co.uk *.cloudflare.com *.teads.tv *.r66net.com *.facebook.net *.googleadservices.com *.doubleclick.net *.cookiepro.com *.cloudfront.net *.videostep.com *.mfgroup.ch *.taboola.com *.outbrain.com *.adobedtm.com *.authorize.net *.unpkg.com *.fontawesome.com *.sodatech.net *.sodatech.com www.clarity.ms bat.bing.com *.b2c.com bt.fraud0.com container.pepperjam.com www.googleoptimize.com *.hotjar.com *.pepperjamnetwork.com *.revlifter.io site-azp.slgnt.us ct.pinterest.com *.ads.linkedin.com cdn.polyfill.io offer.slgnt.us *.blob.core.windows.net s.pinimg.com snap.licdn.com acsbapp.com cdn.noibu.com www.youtube.com *.upsellit.com *.livechatinc.com *.serverdata.net *.tiktok.com *.ordergroove.com app-wallee.com https://www.googletagmanager.com tagmanager.google.com d.ratepay.com www.jsctool.com byondxr-viewer.byondxr.com web-apps.byondxr.com *.listrakbi.com *.listrak.com mystyleplatform.com www.mystyleplatform.com static.ogmystyle.com static2.ogmystyle.com d203yb14zlmxwn.cloudfront.net cdnjs.cloudflare.com cdn.jsdelivr.net use.fontawesome.com *.mczbf.com https://api.unifaun.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com songbird.cardinalcommerce.com *.google.com *.gstatic.com *.trustpilot.com geowidget.inpost.pl sandbox-easy-geowidget-sdk.easypack24.net widget.packeta.com https://www.youtube.com https://acsbapp.com/apps/app/dist/js/app.js https://cdn.noibu.com/collect.js https://byondxr-viewer.byondxr.com/launcher/1.0.58/package/index.js tinyurl.com/LINDT-LAUNCHER *.yieldify.com *.fraud0.com https://www.googleanalytics.com https://www.google-analytics.com https://www.googleoptimize.com 'unsafe-inline' https://optimize.google.com 'unsafe-inline' https://cdn.attn.tv https://www.lindt-spruengli.com/* https://www.lindt-spruengli.com/media/target/VAPI.min.js https://www.lindt-spruengli.com/media/target/at.js shop.pe *.shop.pe d3rr3d0n31t48m.cloudfront.net addshoppers.s3.amazonaws.com .traversedlp.com .voltn.com *.addshoppers.com static.traversedlp.com static.zdassets.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com *.cash.app https://fonts.googleapis.com/ *.sharethis.com display.ugc.bazaarvoice.com *.amazonaws.com widget.freshworks.com m2epro.freshdesk.com https://static.klaviyo.com *.fonts.net *.postcodeanywhere.co.uk *.cloudfront.net *.cloudflare.com *.sodatech.com *.sodatech.net *.googleapis.com *.getfirebug.com cloud.typography.com *.serverdata.net *.myfonts.net *.russellstover.com tagmanager.google.com d.ratepay.com *.listrakbi.com *.listrak.com use.fontawesome.com www.mystyleplatform.com static.ogmystyle.com static2.ogmystyle.com unsafe-inline assets.braintreegateway.com *.gstatic.com *.trustpilot.com geowidget.inpost.pl widget.packeta.com https://cloud.typography.com https://byondxr-viewer.byondxr.com/launcher/1.0.58/package/index.js 'unsafe-inline' https://optimize.google.com https://fonts.googleapis.com 'unsafe-inline' cookie-cdn.cookiepro.com https://cookie-cdn.cookiepro.com https://cdn.cookiepro.com/scripttemplates/*/assets 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.cloudfront.net *.serverdata.net *.livechatinc.com *.listrakbi.com static.zdassets.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io *.magento-datasolutions.com *.magento-ds.com *.sentry.io * *.adyen.com *.sharethis.com *.googleapis.com *.attn.tv events.attentivemobile.com api.bazaarvoice.com stg.api.bazaarvoice.com apps.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com widget.freshworks.com m2epro.freshdesk.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.paypal.com *.postcodeanywhere.co.uk *.ratepay.com *.luckyorange.net *.cookiepro.com *.mfgroup.ch *.doubleclick.net *.visitors.live wss://in.visitors.live wss://visitors.live wss://in.visitors.live/ wss://visitors.live/ visitors.live *.taboola.com *.demdex.net *.omtrdc.net *.magento.com *.adobe.net *.adobedtm.com *.adobedc.net *.typekit.net *.magedevteam.com *.sodatech.com *.sodatech.net *.teads.tv www.sjwoe.com input.noibu.com wss://input.noibu.com/pv_part in.hotjar.com www.facebook.com *.b2c.com bt.fraud0.com *.revlifter.com *.pepperjamnetwork.com *.revlifter.io site-azp.slgnt.us ct.pinterest.com *.ads.linkedin.com cdn.polyfill.io offer.slgnt.us s.pinimg.com snap.licdn.com *.acsbapp.com cdn.noibu.com https://maps.googleapis.com *.clarity.ms *.facebook.com *.serverdata.net *.livechatinc.com api.addressy.com *.listrakbi.com *.mczbf.com *.tiktok.com *.ordergroove.com https://www.google-analytics.com d.ratepay.com www.jsctool.com *.byondxr.com api.byondxr.com s3.us-west-2.amazonaws.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.google.com google.com t.elasticsuite.io *.google-analytics.com https://vc.hotjar.io https://cdn.linkedin.oribi.io https://byondxr-viewer.byondxr.com/launcher/1.0.58/package/index.js *.fraud0.com *.lindtusa.com *.yieldify.com https://content.hotjar.io wss://ws.hotjar.com https://metrics.hotjar.io https://lindt-us.attn.tv https://events.attentivemobile.com lindt.attn.tv cookie-cdn.cookiepro.com https://geolocation.onetrust.com https://bat.bing.com shop.pe *.shop.pe ekr.zdassets.com lindtusa.zendesk.com wss://widget-mediator.zopim.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.byondxr.com *.googleapis.com https://viewer.byondxr.com https://web-apps.byondxr.com https://app.byondxr.com https://byondxr-viewer.byondxr.com https://app.byondvr.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 font-src *.typekit.net fonts.gstatic.com use.typekit.net *.gstatic.com *.googleapis.com *.klarnacdn.net *.klevu.com *.ksearchnet.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnaevt.com *.link.com *.amazon.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.instagram.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.dotdigital-pages.com *.dotdigital.com webchat.dotdigital.com webchat.staging.dotdigital.com *.klarna.com *.stripe.com klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.trustpilot.com *.weltpixel.com www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.googleapis.com *.cdninstagram.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.payments-amazon.com *.trackedlink.net *.klarna.com *.klarnaevt.com *.klarnacdn.net *.klevu.com *.ksearchnet.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com beacon-qa.magento-datasolutions.com beacon-stage.magento-ds.com beacon.magento-ds.com beacon-audiences.magento-ds.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net amcglobal.sc.omtrdc.net *.adobe.io use.typekit.net *.commerce-payment-services.com *.magento-ds.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://rum.hlx.page *.googleapis.com *.gstatic.com *.instagram.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal webchat.dotdigital.com webchat.staging.dotdigital.com *.klarna.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com js.klevu.com *.ksearchnet.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarnaevt.com *.amazon.com *.link.com *.trustpilot.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com beacon-audiences.magento-ds.com fonts.googleapis.com webchat.dotdigital.com webchat.staging.dotdigital.com *.klarnacdn.net *.klevu.com *.ksearchnet.com *.stripe.network *.stripecdn.com *.amazon.com *.googleapis.com *.trustpilot.com https://js.klevu.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.cdninstagram.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.snplow.net commerce.adobedc.net p13n-mr.adobe.io beacon-audiences.magento-ds.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net *.sentry.io www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.adobedc.net *.demdex.net *.googleapis.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com *.klarnaevt.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.klarna.com *.klevu.com *.ksearchnet.com *.stripe.com klarna.com *.link.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://7dc0cf2f-7ee0-4e32-abdf-e62b11896390.sansec.watch/; report-to report-endpoint; 2 script-src 'self' 'unsafe-inline' 'unsafe-eval' *.chartbeat.com optanon.blob.core.windows.net *.brightcove.net *.brightcove.com *.googleadservices.com *.adservice.google.com https://adservice.google.com/* adservice.google.com.br *.googletagmanager.com *.tagmanager.google.com *.chimpstatic.com chimpstatic.com *.jquery.com *.zencdn.net *.ytimg.com *.surveymonkey.com *.googleapis.com *.facebook.net *.googletagservices.com *.addthis.com *.google-analytics.com *.onetrust.com *.ampproject.org *.doubleclick.net *.google.com *.mailchimp.com *.addthisedge.com *.youtube.com *.google.co.uk *.list-manage.com *.outbrain.com *.twitter.com *.twimg.com *.googlesyndication.com *.moatads.com *.radioplayer.co.uk *.cheqzone.com *.rubiconproject.com *.cookielaw.org *.cloudflareinsights.com *.instagram.com *.apester.com *.snap.licdn.com *.doubleverify.com *.aniview.com *.vidazoo.com *.ajax.cloudflare.com *.licdn.com *.pinterest.com *.embedresponsively.com *.amazonaws.com *.apester.com/* *.forces.liveblog.pro *.forces.liveblog.pro/* *.strawpoll.com *.freewheel.tv *.lkqd.net *.beachfront.com *.smartadserver.com *.aniview.com *.admanmedia.com *.improvedigital.com *.onetag.com *.indexexchange.com *.pubmatic.com *.rhythmone.com *.video.unrulymedia.com *.gstatic.com *.newrelic.com cdn.jsdelivr.net cdn.bidder.dev c.amazon-adsystem.com quantcast.mgr.consensu.org secure.quantserve.com rules.quantcount.com static.criteo.net *.dotomi.com *.tiktok.com *.google.ie *.ibytedtos.com *.tiktokcdn.com chartbeat.com *.media.net *.sharethrough.com *.openx.com *.sonobi.com *.districtm.io *.emxdgt.com *.appnexus.com *.google.com *.rhythmone.com *.33across.com *.lemmatechnologies.com *.e-planning.net *.themediagrid.com *.sovrn.com *.lijit.com *.gumgum.com *.nr-data.net *.ttwstatic.com *.thinglink.com *.thinglink.me *.defybrick.com e.infogram.com *.clarity.ms; frame-src 'self' 'unsafe-eval' *.addthis.com *.googlesyndication.com *.facebook.com/ *.outbrain.com *.twitter.com *.surveymonkey.com embeds.audioboom.com *.rubiconproject.com *.apester.com *.openx.net *.pinterest.com *.instagram.com *.embedresponsively.com *.youtube.com *.pubmatic.com *.forces.net *.forcesnews.com *.google.com *.bfbs.com apester.com/* forces.liveblog.pro forces.liveblog.pro/* *.strawpoll.com/ timbre-player.sharp-stream.com *.tiktok.com googleads.g.doubleclick.net gum.criteo.com pre.ads.justpremium.com console.googletagservices.com giphy.com *.giphy.com e.infogram.com *.thinglink.com *.thinglink.me; child-src 'self' 'unsafe-inline' 'unsafe-eval' blob: apester.com/* forces.liveblog.pro/* *.strawpoll.com/; upgrade-insecure-requests 2 default-src 'self' *.fontawesome.com *.visualstudio.com cdn.cookielaw.org *.azure.com *.krxd.net *.facebook.com *.googletagmanager.com *.linkedin.oribi.io *.google.com *.doubleclick.net *.liveperson.net *.google-analytics.com fintactix.com *.adsrvr.org *.lpsnmedia.net *.elfsight.com *.optimizely.com *.decibelinsight.net *.onescreen.ai;script-src 'self' 'unsafe-inline' unpkg.com code.jquery.com stackpath.bootstrapcdn.com customer.cludo.com cdnjs.cloudflare.com *.fontawesome.com *.googletagmanager.com *.licdn.com *.convergetrack.com js.monitor.azure.com *.adroll.com *.facebook.net *.google-analytics.com *.doubleclick.net *.lpsnmedia.net *.liveperson.net *.adsrvr.org *.google.com *.elfsight.com cdn.cookielaw.org maxcdn.bootstrapcdn.com cdn.jsdelivr.net;style-src 'self' 'unsafe-inline' customer.cludo.com fonts.googleapis.com maxcdn.bootstrapcdn.com cdn.jsdelivr.net;img-src 'self' data: *.adsrvr.org *.convergetrack.com *.demdex.net *.google.com *.lpsnmedia.net *.linkedin.com *.facebook.com *.krxd.com *.krxd.net *.adroll.com *.google-analytics.com *.doubleclick.net *.googletagmanager.com *.elfsight.com;font-src 'self' data: fonts.gstatic.com *.fontawesome.com;worker-src 'self' blob: 2 default-src blob: data: https: 'self'; style-src blob: https: 'self' 'unsafe-inline'; media-src blob: data: https: 'self'; connect-src blob: data: https: 'self' 'unsafe-inline' wss://*.hotjar.com; frame-ancestors 'self'; script-src blob: 'self' 'unsafe-eval' 'unsafe-inline' https://*.adform.net/ https://*.app-us1.com/ https://*.go-mpulse.net https://*.hotjar.com https://*.outbrain.com/ https://*.rapidimages.net https://*.scene7.com https://*.volvo.com/ https://*.volvotrucks.com https://assets.adobedtm.com https://c2c.mct.co.il/ https://cdn.cookielaw.org https://connect.facebook.net https://googleads.g.doubleclick.net/ https://s3.eu-central-1.amazonaws.com/ https://snap.licdn.com/ https://documentservices.adobe.com/ https://trackcmp.net/ https://volvo-trucks.activehosted.com/ https://www.google-analytics.com/ https://www.google.com/ https://www.googletagmanager.com/ https://www.gstatic.com/ https://www.instagram.com/ https://www.youtube.com; report-to csp-endpoint; report-uri https://knxzhhty06.execute-api.eu-west-1.amazonaws.com/prod/browser-reporting/csp; 2 object-src 'none'; script-src 'self' 'unsafe-eval' fonts.googleapis translate.google.com translate.googleapis.com translate-pa.googleapis.com *.gstatic.com siteimproveanalytics.com *.siteimprove.com svc.webspellchecker.net js-agent.newrelic.com bam.nr-data.net cdn.jsdelivr.net https://cdn.jsdelivr.net https://cdn.siteimprove.net https://cdnjs.cloudflare.com https://maps.googleapis.com https://rebilly.github.io https://static.addtoany.com https://unpkg.com https://webapp.recyclecoach.com maps.googleapis.com platform.instagram.com platform.twitter.com; script-src-attr 'self'; script-src-elem 'self' fonts.googleapis translate.google.com translate.googleapis.com translate-pa.googleapis.com *.gstatic.com siteimproveanalytics.com *.siteimprove.com svc.webspellchecker.net js-agent.newrelic.com bam.nr-data.net cdn.jsdelivr.net https://cdn.jsdelivr.net https://cdn.siteimprove.net https://cdnjs.cloudflare.com https://maps.googleapis.com https://rebilly.github.io https://static.addtoany.com https://unpkg.com https://webapp.recyclecoach.com maps.googleapis.com platform.instagram.com platform.twitter.com; style-src 'self' fonts.googleapis translate.google.com translate.googleapis.com translate-pa.googleapis.com *.gstatic.com siteimproveanalytics.com *.siteimprove.com svc.webspellchecker.net js-agent.newrelic.com bam.nr-data.net cdn.jsdelivr.net https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com https://use.fontawesome.com; style-src-attr 'self'; frame-ancestors 'self' 2 default-src 'self'; base-uri 'self'; object-src 'none'; frame-ancestors 'self' https://zb.tdicompliancecloud.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' blob: https://*.marketo.com https://cloud-dev.zimmerbiomet.com https://*.clarity.ms https://acsbapp.com https://munchkin.marketo.net https://*.sharethis.com https://cdn.mouseflow.com https://bat.bing.com https://buttons-config.sharethis.com https://platform-api.sharethis.com https://players.brightcove.net https://vjs.zencdn.net https://cdn.cookielaw.org https://assets.adobedtm.com https://tags.srv.stackadapt.com https://snap.licdn.com https://connect.facebook.net https://www.googletagmanager.com https://www.google-analytics.com https://www.googleadservices.com https://pagead2.googlesyndication.com https://*.doubleclick.net https://*.googleapis.com https://*.gstatic.com https://*.google.com https://js.driftt.com https://assets.map.brightcove.com https://personalizedknee.zimmerbiomet.com https://qvdt3feo.com; style-src 'self' 'unsafe-inline' https://*.marketo.com https://tags.srv.stackadapt.com https://*.googleapis.com https://cdn.cookielaw.org https://cdn.jsdelivr.net; img-src 'self' data: https://www.thepersonalizedknee.com https://*.salesforce.com https://www.google.com.mx https://dpm.demdex.net https://cm.everesttech.net https://dev.day.com https://c.bing.com https://*.clarity.ms https://hostedseal.trustarc.com https://privacy-policy.truste.com https://www.zimmerbiomet.com https://*.sharethis.com https://zimzbdotcomprod.112.2o7.net https://*.sharethis.com https://bat.bing.com https://www.facebook.com https://cf-images.us-east-1.prod.boltdns.net https://metrics.brightcove.com https://cdn.cookielaw.org https://assets.adobedtm.com https://tags.srv.stackadapt.com https://snap.licdn.com https://connect.facebook.net https://www.googletagmanager.com https://www.google-analytics.com https://www.googleadservices.com https://pagead2.googlesyndication.com https://*.doubleclick.net https://*.googleapis.com https://*.gstatic.com https://*.google.com https://personalizedknee.zimmerbiomet.com https://assets.map.brightcove.com https://picsum.photos https://*.picsum.photos; font-src 'self' data: https://fonts.gstatic.com https://cdn.jsdelivr.net; connect-src 'self' data: https://platform-api.sharethis.com https://*.salesforce.com https://*.clarity.ms https://dpm.demdex.net https://zimzbdotcomprod.112.2o7.net https://metrics.brightcove.com https://bcp.crwdcntrl.net https://*.doubleclick.net https://cdn.acsbapp.com https://*.mktoresp.com https://*.mktoutil.com https://n2.mouseflow.com https://zimmerbiomet.tt.omtrdc.net https://house-fastly-signed-us-east-1-prod.brightcovecdn.com https://manifest.prod.boltdns.net https://*.sharethis.com https://api.ipdata.co https://edge.api.brightcove.com https://geolocation.onetrust.com https://cdn.cookielaw.org https://assets.adobedtm.com https://tags.srv.stackadapt.com https://snap.licdn.com https://connect.facebook.net https://www.googletagmanager.com https://www.google-analytics.com https://www.google.com https://www.googleadservices.com https://pagead2.googlesyndication.com https://*.googleapis.com https://*.gstatic.com https://*.google.com https://js.driftt.com https://assets.map.brightcove.com https://*.zimmerbiomet.com https://zimmerbiometglobal.my.salesforce.com https://data.stbuttons.click https://*.bing.com; frame-src 'self' https://zimmer.demdex.net https://*.marketo.com https://*.doubleclick.net https://*.sharethis.com https://www.googletagmanager.com https://*.google.com https://connect.facebook.net https://js.driftt.com https://assets.map.brightcove.com https://zb-id-test.vercel.app; media-src 'self' data: blob: https://cloud-dev.zimmerbiomet.com https://*.brightcove.com https://*.brightcovecdn.com https://*.boltdns.net https://personalizedknee.zimmerbiomet.com; form-action 'self' 2 img-src 'self' data: https://cdn-ildfakh.nitrocdn.com https://www.facebook.com https://cc.swiftype.com https://px.ads.linkedin.com https://imgsct.cookiebot.com https://img.youtube.com https://www.google-analytics.com https://resources.bamboohr.com https://www.google.ch https://www.googletagmanager.com https://www.google.ie https://www.google.si https://www.google.co.in https://pagead2.googlesyndication.com https://www.google.com.vn https://www.google.co.id https://www.google.co.uk https://www.google.de https://www.google.ro https://www.google.fr https://www.google.co.th https://www.google.co.cr https://www.google.co.ke https://www.google.be https://www.google.iq https://www.google.com.sa blob: https://www.google.nl https://www.google.com.eg https://www.google.gr https://i.ytimg.com https://www.google.co.nz https://www.google.hu https://www.google.com.tw https://www.google.com.ph https://www.google.ae https://www.google.cz https://www.google.dk https://googleads.g.doubleclick.net https://www.google.ca https://www.google.co.jp https://www.google.it https://www.google.es https://www.google.co.ug https://fonts.gstatic.com https://stats.g.doubleclick.net https://www.google.is https://plugin-updates.wpengine.com https://www.google.hr https://www.google.com.au https://www.google.com.tr https://www.google.pt https://www.google.ge https://www.google.co.za https://www.google.com.mx https://www.google.je https://www.google.com.co https://www.google.com.sg https://www.google.co.kr https://www.google.cl https://www.google.at https://www.google.com.mt https://www.google.mk https://www.google.sk https://www.google.com.hk https://www.google.com.ua https://www.google.pl https://log-papago.naver.com https://www.google.rs https://www.google.com.np https://www.google.com.ar https://www.google.lt https://www.google.com.pk https://www.google.co.il https://www.google.com.mm https://www.google.bg https://translate.google.com https://www.google.com.bd https://wpengine.com https://www.google.cd https://www.google.se https://www.google.com.br https://www.crossiety.ch https://www.google.com.et https://yt3.ggpht.com https://connect.advancedcustomfields.com https://really-simple-ssl.com https://www.open-systems.com https://www.google.ru https://www.google.dz https://www.google.com.pg https://www.googleadservices.com https://www.google.com.my https://www.google.com.ng https://www.google.sn https://www.google.com.ly https://www.google.by https://www.google.lu https://www.google.fi https://burst-statistics.com https://www.google.no https://www.google.com.pe https://www.google.com.gh https://secure.gravatar.com https://ts.w.org https://s.w.org https://ps.w.org; default-src 'self'; script-src 'self' 'unsafe-inline' https://js.adsrvr.org https://munchkin.marketo.net https://www.gartner.com https://scout-cdn.salesloft.com https://js.zi-scripts.com https://nitroscripts.com https://www.googletagmanager.com https://s.swiftypecdn.com https://opench.bamboohr.com https://consent.cookiebot.com https://cdn-ildfakh.nitrocdn.com https://snap.licdn.com blob: https://yoast.com https://consentcdn.cookiebot.com https://connect.facebook.net https://www.google-analytics.com https://googleads.g.doubleclick.net https://beacon-v2.helpscout.net https://www.youtube.com https://api.pirsch.io https://www.googleadservices.com https://pagead2.googlesyndication.com https://www.google.com https://ws-assets.zoominfo.com https://retagro.com https://gc.kis.v2.scr.kaspersky-labs.com https://apis.google.com https://cdnjs.cloudflare.com https://api.wire.threatspike.com https://3001.scriptcdn.net https://data1.sabuf.com https://go.open-systems.com https://www.open-systems.com http://go.open-systems.com https://gc.kes.v2.scr.kaspersky-labs.com https://cdn.gtranslate.net http://munchkin.marketo.net http://s.swiftypecdn.com 'unsafe-eval'; script-src-elem 'self' 'unsafe-inline' https://js.adsrvr.org https://munchkin.marketo.net https://www.gartner.com https://scout-cdn.salesloft.com https://js.zi-scripts.com https://nitroscripts.com https://www.googletagmanager.com https://s.swiftypecdn.com https://opench.bamboohr.com https://consent.cookiebot.com https://cdn-ildfakh.nitrocdn.com https://snap.licdn.com blob: https://yoast.com https://consentcdn.cookiebot.com https://connect.facebook.net https://www.google-analytics.com https://googleads.g.doubleclick.net https://beacon-v2.helpscout.net https://www.youtube.com https://api.pirsch.io https://www.googleadservices.com https://pagead2.googlesyndication.com https://www.google.com https://ws-assets.zoominfo.com https://retagro.com https://gc.kis.v2.scr.kaspersky-labs.com https://apis.google.com https://cdnjs.cloudflare.com https://api.wire.threatspike.com https://3001.scriptcdn.net https://data1.sabuf.com https://go.open-systems.com https://www.open-systems.com http://go.open-systems.com https://gc.kes.v2.scr.kaspersky-labs.com https://cdn.gtranslate.net http://munchkin.marketo.net http://s.swiftypecdn.com ; style-src 'self' 'unsafe-inline' https://s.swiftypecdn.com https://cdn-ildfakh.nitrocdn.com https://fonts.googleapis.com https://adblockers.opera-mini.net https://www.gstatic.com https://gc.kis.v2.scr.kaspersky-labs.com https://me.kis.v2.scr.kaspersky-labs.com https://ff.kis.v2.scr.kaspersky-labs.com https://www.open-systems.com https://www.gartner.com ; style-src-elem 'self' 'unsafe-inline' https://s.swiftypecdn.com https://cdn-ildfakh.nitrocdn.com https://fonts.googleapis.com https://adblockers.opera-mini.net https://www.gstatic.com https://gc.kis.v2.scr.kaspersky-labs.com https://me.kis.v2.scr.kaspersky-labs.com https://ff.kis.v2.scr.kaspersky-labs.com https://www.open-systems.com https://www.gartner.com ; font-src 'self' https://cdn-ildfakh.nitrocdn.com https://fonts.gstatic.com https://www.open-systems.com https://cdn.fontshare.com https://use.typekit.net https://www.gartner.com https://r2cdn.perplexity.ai data:; frame-src 'self' https://www.youtube.com https://www.googletagmanager.com https://consentcdn.cookiebot.com https://td.doubleclick.net https://match.adsrvr.org data: https://www.gartner.com https://www.youtube-nocookie.com https://app.stylar.com https://support.google.com https://insight.adsrvr.org.x.53a1087a04f89043e70b1950e8116089eded.9270f457.id.opendns.com https://connect.useparagon.com https://safeframe.googlesyndication.com blob:; connect-src 'self' https://www.google-analytics.com https://analytics.google.com https://px.ads.linkedin.com https://514-zbl-151.mktoresp.com https://region1.analytics.google.com https://cdn-ildfakh.nitrocdn.com https://to.getnitropack.com https://pagead2.googlesyndication.com https://consentcdn.cookiebot.com https://s.swiftypecdn.com https://my.yoast.com https://region1.google-analytics.com https://stats.g.doubleclick.net https://514-zbl-151.mktoutil.com https://www.facebook.com https://opench.bamboohr.com https://www.google.ie https://www.google.ro https://www.google.fr https://www.google.kz https://www.google.co.in https://search-api.swiftype.com https://www.google.co.id https://www.google.co.nz https://www.google.cz https://www.google.de https://www.google.ch https://www.google.je https://js.zi-scripts.com https://consent.cookiebot.com https://www.google.dk https://www.google.nl https://www.google.com.sa https://ws.zoominfo.com https://yoast.com https://www.google.co.uk https://www.google.co.th https://www.google.co.za https://www.google.ca https://www.google.co.ug https://www.google.com.sg https://www.google.at https://www.google.co.il https://www.google.com.au https://www.google.is https://www.google.se https://scout.salesloft.com https://infragrid.v.network https://www.google.com.ec https://www.google.ru https://www.google.com.mx https://www.google.com.co https://controlbar.eblocker.org https://www.google.it https://www.google.co.kr https://www.google.com.ph https://www.google.lt https://www.google.com.mm https://www.google.pl https://translate.googleapis.com https://www.google.es https://www.google.com.hk https://www.google.com.bd https://www.google.co.jp https://www.googletagmanager.com https://www.google.be https://js.adsrvr.org https://insight.adsrvr.org https://www.google.com.pk https://www.google.com.pe https://www.google.lv https://www.google.sk https://www.google.tn https://www.google.rs https://www.google.hu https://www.google.pt https://www.google.gr https://overbridgenet.com https://www.google.no https://ws-assets.zoominfo.com https://www.google.com.vn https://nitropack.io https://www.google.com.tw https://www.google.si https://www.google.com.br https://www.google.vu https://www.googleadservices.com https://go.open-systems.com https://localhost https://www.google.co.ke https://www.google.com.my https://www.google.mk https://www.google.fi https://www.open-systems.com https://www.google.co.zw data: https://www.google.bg https://googleads.g.doubleclick.net; child-src 'self' blob:; media-src 'self' data:; worker-src 'self' blob: data:; report-uri https://www.open-systems.com/wp-json/really-simple-security/v1/csp?rsssl_apitoken=530964519; 2 default-src 'self' 'unsafe-inline' *.bazaarvoice.com; connect-src 'self' 'unsafe-inline' maps.googleapis.com www.google.com www.gstatic.com analytics.google.com *.google-analytics.com *.googletagmanager.com www.google-analytics.com bam.nr-data.net *.afterpay.com *.afterpaycdn.com *.squarecdn.com static.afterpay.com *.paypal.com *.bazaarvoice.com edge.fullstory.com rs.fullstory.com ekr.zdassets.com; font-src 'self' 'unsafe-inline' data: fonts.gstatic.com use.typekit.net *.afterpay.com *.afterpaycdn.com *.squarecdn.com; frame-src 'self' 'unsafe-inline' www.google.com www.youtube.com player.vimeo.com *.afterpay.com *.afterpaycdn.com *.squarecdn.com assets.braintreegateway.com *.paypal.com; img-src 'self' 'unsafe-inline' data: maps.googleapis.com maps.gstatic.com *.googletagmanager.com *.google-analytics.com ssl.gstatic.com www.gstatic.com fonts.gstatic.com i.vimeocdn.com *.afterpay.com *.afterpaycdn.com *.squarecdn.com site-assets.afterpay.com www.paypalobjects.com *.bazaarvoice.com rs.fullstory.com insight.adsrvr.org theathletesfootcustomercarenz.zendesk.com accentgroupsupport.zendesk.com www.facebook.com; script-src 'self' 'unsafe-inline' blob: maps.googleapis.com www.google.com www.gstatic.com *.googletagmanager.com *.google-analytics.com tagmanager.google.com js-agent.newrelic.com; style-src 'self' 'unsafe-inline' fonts.googleapis.com tagmanager.google.com www.googletagmanager.com *.afterpay.com *.afterpaycdn.com *.squarecdn.com; child-src blob:; media-src 'self' blob: data:; worker-src 'self' blob:; report-uri https://36eddd1e-785d-4d1e-a6e1-6809b1003cef.sansec.watch/ 2 script-src 'self' 'unsafe-eval' 'unsafe-hashes' 'unsafe-inline' assets.adobedtm.com secure.authorize.net test.authorize.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com js.authorize.net jstest.authorize.net t.paypal.com s.ytimg.com video.google.com vimeo.com *.vimeocdn.com cdn-scripts.signifyd.com *.googleapis.com r1-t.trackedlink.net r2-t.trackedlink.net r3-t.trackedlink.net r1.trackedweb.net r2.trackedweb.net r3.trackedweb.net static.trackedweb.net cdn.dnky.co api.comapi.com webchat.dotdigital.com connect.facebook.net graph.facebook.com business.facebook.com cdn.xtento.com *.klevu.com *.ksearchnet.com *.avada.io *.trustpilot.com *.yotpo.com preferredliving.com *.preferredliving.com sportys.com *.sportys.com sportystoolshop.com *.sportystoolshop.com wright-bros.com *.wright-bros.com na-library.klarnaservices.com www.googleadservices.com bat.bing.com www.googletagmanager.com *.bc0a.com hello.zonos.com cdn.mouseflow.com secure.quantserve.com cdn.attn.tv *.datasteam.io googleads.g.doubleclick.net rules.quantcount.com aa.agkn.com *.cloudmaestro.com cdn.b0e8.com cdn.iglobalstores.com *.listrakbi.com www.google-analytics.com *.listrak.com widgets.turnto.com www.google.com www.gstatic.com widget.heymarket.com *.clarity.ms *.aviationgifts.com; report-uri /.webscale/csp-report 2 default-src 'self';base-uri 'self' https://d6tizftlrpuof.cloudfront.net/live/;connect-src 'self' https://api.cz.nl https://app.talkjs.com https://consent.cookiebot.com https://consentcdn.cookiebot.com https://czgroep.piwik.pro https://dev.visualwebsiteoptimizer.com https://js.monitor.azure.com https://westeurope-5.in.applicationinsights.azure.com;font-src 'self' data:;frame-src 'self' https://consentcdn.cookiebot.com https://overzicht.cz.nl;frame-ancestors 'self';img-src 'self' https://6005850.global.siteimproveanalytics.io https://d6tizftlrpuof.cloudfront.net https://dev.visualwebsiteoptimizer.com https://imgsct.cookiebot.com;manifest-src 'self';media-src 'self' https://cdn.talkjs.com;object-src 'self';script-src 'self' https://cdn.talkjs.com https://cdstatic-sc.cz.nl https://consent.cookiebot.com https://consentcdn.cookiebot.com/consentconfig/ https://czgroep.containers.piwik.pro/ppms.js https://dev.visualwebsiteoptimizer.com https://inzicht.cz.nl/containers/ https://siteimproveanalytics.com/js/ https://w.usabilla.com https://www.googletagmanager.com 'unsafe-inline' 'unsafe-eval';style-src 'self' https://cdstatic-sc.cz.nl 'unsafe-inline';worker-src 'self' blob:; 2 default-src 'self' https://s0.wp.com https://fonts.googleapis.com https://fonts.gstatic.com data:; frame-src 'self' data: blob: https://www.youtube.com https://player.vimeo.com https://wp-themes.com; img-src * data:; media-src * data:; style-src 'self' https://fonts.googleapis.com data: 'unsafe-inline'; script-src https://wp-themes.com 'self' data: 'unsafe-inline' 'unsafe-eval'; worker-src 'self'; frame-ancestors 'self' https://hub.libraesva.com; report-uri https://sentry.libraesva.com/api/16/security/?sentry_key=ec35ea3e850202bb70633fcd5d55c698 2 object-src 'self' *.cined.com; report-uri /_/csp-report/ 2 script-src 'self' 'unsafe-inline' 'unsafe-eval'; 2 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://cdn.checkout.com data: checkout.tabby.ai widgets.tabby.ai cdn.tabby.ai fonts.googleapis.com storage.googleapis.com *.cloudflare.com *.twitter.com *.twimg.com *.trustedshops.com *.googleapis.com *.fontawesome.com *.alothemes.com *.magepow.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.paypal.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.ccavenue.ae 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://js.checkout.com *.klarna.com *.ccavenue.ae checkout.tabby.ai https://c.sharethis.mgr.consensu.org https://secure.ccavenue.ae 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.ccavenue.ae cdn.jsdelivr.net data: checkout.tabby.ai widgets.tabby.ai cdn.tabby.ai fonts.googleapis.com storage.googleapis.com *.magentocommerce.com *.cloudfront.com *.googleadservices.com *.google-analytics.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu https://l.sharethis.com https://sharethis.com https://platform-cdn.sharethis.com *.facebook.com *.alothemes.com *.magepow.com *.tamara.co data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net assets.adobedtm.com amcglobal.sc.omtrdc.net *.adobe.io use.typekit.net *.commerce-payment-services.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.magento-ds.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.magento-datasolutions.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://cdn.checkout.com *.klarnacdn.net *.ccavenue.ae *.moengage.com sc-static.net *.snapchat.com *.spotii.me apigoswirl.com cdn.jsdelivr.net checkout.tabby.ai widgets.tabby.ai cdn.segment.com cdn.sift.com score.jcsc.online seondf.com deviceinf.com getdeviceinf.com *.cloudflare.com *.authorize.net *.braintreegateway.com *.ytimg.com *.paypal.com *.payments-amazon.com *.croapp.net https://buttons-config.sharethis.com https://platform-api.sharethis.com s7.addthis.com *.googletagmanager.com *.facebook.net *.alothemes.com *.magepow.com cdn.tamara.co maps.googleapis.com *.tamara.co 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com https://cdn.checkout.com apigoswirl.com cdn.jsdelivr.net *.yotpo.com *.googleapis.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.alothemes.com *.magepow.com *.tamara.co 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.tamara.co 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net commerce.adobe.io *.sentry.io *.paypal.com google.com *.google.com *.magento-datasolutions.com *.magento-ds.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://js.checkout.com *.klarnaevt.com *.ccavenue.ae *.moengage.com sc-static.net *.snapchat.com *.spotii.me apigoswirl.com api.goswirl.live checkout.tabby.ai widgets.tabby.ai cdn.segment.com api.segment.com api.segment.io api.amplitude.com *.seondfresolver.com *.deviceinfresolver.com *.getdeviceinfresolver.com *.cloudflare.com *.twitter.com *.twimg.com api.homesrusae.evinent.site homesrusaenew-api.evinent.site api.homesrusqa.evinent.site homesrusqanew-api.evinent.site api.momstore.evinent.site momstorenew-api.evinent.site api.carters.evinent.site https://l.sharethis.com https://sharethis.com ekr.zdassets.com/ *.google-analytics.com *.alothemes.com *.magepow.com maps.googleapis.com *.tamara.co 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.seondnsresolve.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 font-src *.bglobale.com *.global-e.com *.googleapis.com *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com https://*.gstatic.com *.narvar.com *.narvar.qa *.optimizely.com optimizely.s3.amazonaws.com logx.optimizely.com script.hotjar.com fonts.googleapis.com fonts.gstatic.com *.inside-graph.com integration-cdn.toshi.co acsbapp.com shopping.qantas.com appdown.pstatic.net data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.adyen.com pay.google.com payments-eu.amazon.com *.amazon.de *.facebook.com *.optimizely.com optimizely.s3.amazonaws.com logx.optimizely.com *.cardinalcommerce.com www.facebook.com *.kaptcha.com bid.g.doubleclick.net ct.pinterest.com www.rsa3dsauth.co.uk www.securesuite.co.uk *.americanexpress.com 3dsecure-vrp.de 'self' 'unsafe-inline'; frame-ancestors *.optimizely.com optimizely.s3.amazonaws.com logx.optimizely.com au-tracker.inside-graph.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.adyen.com pay.google.com *.paypal.com *.bglobale.com *.global-e.com *.google.com *.doubleclick.net *.facebook.com *.optimizely.com optimizely.s3.amazonaws.com logx.optimizely.com *.pinterest.com *.sharethis.com *.hotjar.co vimeo.com acsbapp.com *.kaptcha.com player.smartzer.com www.google.com www.facebook.com accounts.accessibe.com dashboard.accessibe.com cestream.me 3ds.sia.eu acs2.3dsecure.no www.houzz.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.adyen.com pay.google.com *.payments-amazon.com *.media-amazon.com *.paypalobjects.com *.bglobale.com *.global-e.com *.googleapis.com *.gstatic.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com https://*.gstatic.com *.narvar.com *.narvar.qa *.optimizely.com optimizely.s3.amazonaws.com logx.optimizely.com adservice.google.com script.hotjar.com www.google.sa www.google.ca *.bing.com *.clarity.ms data:* web1.acsbapp.com integration-sandbox-cdn.toshi.co www.google.bg www.google.be www.google.co.uk www.google.nl www.gstatic.com translate.google.com idsync.rlcdn.com consent.linksynergy.com au-live.inside-graph.com bam-cell.nr-data.net integration-cdn.toshi.co bat.bing.com www.google.com.au google.com.au *.searchspring.io *.media.tumblr.com s.ytimg.com maps.googleapis.com maps.gstatic.com au-cdn.inside-graph.com www.google.co.in d3cgm8py10hi0z.cloudfront.net track.linksynergy.com *.sharethis.com *.micpn.com *.pinterest.com zimmermann.com www.google.tn www.google.com.hk www.google.com.et www.google.com.eg www.google.co.tz www.google.ci www.google.co.ke www.google.cm www.google.lk www.google.com.ng www.google.ne www.google.com.mm www.google.co.mz www.google.co.id www.google.bi www.google.com.kh www.google.co.ve www.google.cd www.google.com.gh www.google.so www.google.com.af www.google.ht www.google.com.ni www.google.la www.google.cg www.google.bf www.google.sn www.google.com.ly www.google.mg www.google.com.sb www.google.com.pg www.google.com.np sync.sharethis.com www.google.com.py www.google.ml www.google.com.sl www.google.co.ls www.google.to www.google.gm www.google.rw www.google.com.vn www.google.com.sv www.google.co.kr www.google.com.bo www.google.com.sg www.google.mw www.google.si www.google.tl www.google.sc www.google.co.zm www.google.tg www.google.com.pk 4mrr1kwk.micpn.com www.google.ge www.google.com.fj www.google.com.na www.google.td www.google.ee www.google.mk www.google.bj www.google.mn www.google.bt www.google.co.bw www.google.fi www.google.com.uy www.google.co.th www.google.com.pe www.google.cv www.google.co.zw www.google.ga www.google.by www.google.iq www.google.com.ec www.google.co.jp www.google.com.pa www.google.dz www.google.ws analytics.tiktok.com www.google.gy www.google.de sdk.privacy-center.org data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com *.bglobale.com *.global-e.com *.googleapis.com *.gstatic.com *.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com https://cdn.searchspring.net/intellisuggest/is.min.js *.optimizely.com optimizely.s3.amazonaws.com logx.optimizely.com analytics.tiktok.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net widgets.magentocommerce.com *.searchspring.net *.acsbapp.com au-tracker.inside-graph.com cdn.scarabresearch.com intljs.rmtag.com *.inside-graph.co js-agent.newrelic.com *.inside-graph.com acsbapp.com tag.lexer.io *.toshi.co *.bugsnag.com *.sharethis.com script.crazyegg.com *.clarity.ms www.fullstory.com songbirdstag.cardinalcommerce.com www.gstatic.com vimeocdn.com youtube.com googletagmanager.com maps.googleapis.com fullstory.com bat.bing.com 4mrr1kwk.micpn.com s.pinimg.com tag.rmp.rakuten.com *.hotjar.com ut.rd.linksynergy.com ct.pinterest.com unsafe-inline sdk.privacy-center.org www.onelink-edge.com 'unsafe-inline' 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.bglobale.com *.global-e.com fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com https://fonts.googleapis.com/ *.optimizely.com optimizely.s3.amazonaws.com logx.optimizely.com *.inside-graph.com *.searchspring.net webchat.dotdigital.com cdn.honey.io *.aptrinsic.com 'unsafe-inline' 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.narvar.com *.narvar.qa *.optimizely.com optimizely.s3.amazonaws.com logx.optimizely.com au-cdn.inside-graph.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adyen.com *.google.com payments-eu.amazon.com *.paypal.com *.googleapis.com *.google-analytics.com *.facebook.com *.facebook.net https://beacon.searchspring.io/beacon *.optimizely.com optimizely.s3.amazonaws.com logx.optimizely.com analytics.tiktok.com data.stbuttons.click www.google.com.au translate.googleapis.com *.searchspring.io *.acsbapp.co cdn.acsbapp.com au-live.inside-graph.com bam.nr-data.net uat.tryzens-analytics.com:12280 *.scarabresearch.com wss://au-live.inside-graph.com *.bugsnag.com *.postcodeanywhere.co.uk *.sharethis.com script.crazyegg.com stats.g.doubleclick.net *.pinterest.com track.lexer.io www.tryzens-analytics.com:12280 www.google.co.ke www.google.bi pagestates-tracking.crazyegg.com www.google.com.sl www.google.co.ao www.google.cm www.google.com.np www.google.cd www.google.co.ve www.google.lk www.google.co.tz www.google.com.ng www.google.so www.google.ne www.google.co.id www.google.co.ls www.google.tn assets-tracking.crazyegg.com www.google.ht www.google.co.mz acsbapp.com www.google.com.co cp.crwdcntrl.net www.google.ci tracking.crazyegg.com www.google.co.za www.google.tl www.google.com.pk www.google.com.sv www.google.com.ly www.google.mg www.google.tg www.google.gm www.google.com.eg www.google.co.kr www.google.bf www.google.sn www.google.ga www.google.bj ad.doubleclick.net www.google.cg www.google.com.ar www.google.co.ma www.google.com.et www.google.fr www.google.com.na www.google.co.uk www.google.nl www.google.ml www.google.rw www.google.com.uy www.google.com.bo www.google.com.ni www.google.ki www.google.ee www.google.com.gt www.google.com.py www.google.com.gh www.google.com.kh www.google.com.vn www.google.ru www.google.cv www.google.com.mm www.google.co.zm www.google.vu www.google.com.ec www.google.es www.google.at bat.bing.com vc.hotjar.io www.google.de ws.hotjar.com content.hotjar.io metrics.hotjar.io www.google.ca www.tryzens-analytics.com ct.pinterest.com www.google.com.pe www.google.co.in www.google.ge googleads.g.doubleclick.net fresnel.vimeocdn.com api.privacy-center.org pagead2.googlesyndication.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://289r1hnfc9.execute-api.eu-west-1.amazonaws.com/prod/zmn-cspdata; report-to report-endpoint; 2 default-src https: 'unsafe-inline' 'unsafe-eval'; report-uri https://www.allesedv.at/mixedContentReporting.php 2 upgrade-insecure-requests; report-to https://www.codium.ai; report-uri https://www.codium.ai; 2 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com data: *.fontawesome.com *.cloudflare.com *.twitter.com *.bootstrapcdn.com https://fonts.bunny.net maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * https://plumrocket.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.twitter.com https://plumrocket.com https://t.pepperjamnetwork.com *.googleapis.com *.trustpilot.com 'self' 'unsafe-inline'; img-src 'self' data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: *.googleapis.com http://hemin11112.pcapredict.com http://services.postcodeanywhere.co.uk *.cloudflare.com *.googleadservices.com *.twitter.com *.adobedtm.com https://firebasestorage.googleapis.com https://img.youtube.com https://shareasale.com/sale.cfm https://track.linksynergy.com https://www.bizrate.com https://www.awin1.com https://*.zenaps.com https://track.webgains.com https://prf.hn https://track.flexlinks.com https://scripts.affiliatefuture.com https://t.powerreviews.com https://match.sharethrough.com https://cm.g.doubleclick.net https://x.bidswitch.net https://ib.adnxs.com https://rtb-csync.smartadserver.com https://sync-t1.taboola.com https://visitor.omnitagjs.com https://r.casalemedia.com https://gum.criteo.com https://jadserve.postrelease.com https://id5-sync.com https://ad.360yield.com https://matching.ivitrack.com https://contextual.media.net https://exchange.mediavine.com https://sync.outbrain.com https://simage2.pubmatic.com https://pixel.rubiconproject.com https://criteo-sync.teads.tv https://criteo-partners.tremorhub.com https://eb2.3lift.com https://ad.yieldlab.net https://sync-criteo.ads.yieldmo.com https://e1.emxdgt.com https://sync.1rx.io https://dis.criteo.com https://dpm.demdex.net https://ps.eyeota.net https://public-prod-dspcookiematching.dmxleo.com maps.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://rum.hlx.page js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com apis.google.com *.gstatic.com http://hemin11112.pcapredict.com http://services.postcodeanywhere.co.uk *.cloudflare.com *.twitter.com *.google-analytics.com googletagmanager.com *.trustedshops.com *.fontawesome.com graph.facebook.com *.adobedtm.com https://analytics.webgains.io *.avada.io *.shopify.com s7.addthis.com https://www.dwin1.com https://intljs.rmtag.com https://cdn.avmws.com https://images.bizrate.com https://www.awin1.com https://*.zenaps.com https://swrap.tradedoubler.com https://analytics.optimalpeople.fr https://www.linkconnector.com https://d3v27wwd40f0xu.cloudfront.net https://static.criteo.net https://sslwidget.criteo.com https://*.affiliatefuture.com https://static.powerreviews.com *.googleapis.com *.trustpilot.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com assets.braintreegateway.com *.fontawesome.com http://services.postcodeanywhere.co.uk *.cloudflare.com *.googleapis.com *.twitter.com *.gstatic.com *.typekit.net *.bootstrapcdn.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.trustpilot.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.googleapis.com http://hemin11112.pcapredict.com http://services.postcodeanywhere.co.uk *.cloudflare.com *.twitter.com https://get.geojs.io *.avada.io api.addressy.com ekr.zdassets.com/ https://shareasale.com/sale.cfm https://analytics.optimalpeople.fr https://measurement-api.criteo.com https://api.webgains.io 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 default-src 'self'; script-src 'self' cdn.jsdelivr.net cdnjs.cloudflare.com; style-src 'self' cdn.jsdelivr.net cdnjs.cloudflare.com; font-src 'self' cdn.jsdelivr.net cdnjs.cloudflare.com; img-src 'self' data: 2 default-src 'self'; script-src 'self' 'unsafe-eval' 'unsafe-inline' https://consent.ory.com https://fast.wistia.com https://fast.wistia.net https://distillery.wistia.com https://js.hsforms.net; script-src-elem blob: 'self' 'unsafe-inline' https://vercel.live https://fast.wistia.com https://fast.wistia.net https://js.hsforms.net https://static.hsappstatic.net https://js-eu1.hs-banner.com https://js-eu1.hs-analytics.net https://js-eu1.hsadspixel.net https://js-eu1.usemessages.com https://googleads.g.doubleclick.net https://js.zi-scripts.com https://*.hs-scripts.com https://script.crazyegg.com https://www.googletagmanager.com https://sqa-web.ory.com https://static.reo.dev https://s.ory.com https://consent.ory.com https://www.redditstatic.com https://core.sanity-cdn.com https://cdn.jsdelivr.net https://browser.sentry-cdn.com; style-src 'self' 'unsafe-inline'; style-src-elem 'self' 'unsafe-inline' https://fast.wistia.com https://fast.wistia.net https://js.hsforms.net https://static.hsappstatic.net https://cdn.jsdelivr.net; img-src 'self' data: blob: https:; connect-src 'self' https://stats.g.doubleclick.net https://ws.zoominfo.com https://*.hubapi.com https://*.hubspot.com https://static.hsappstatic.net https://analytics.google.com https://js.zi-scripts.com https://script.crazyegg.com https://conversions-config.reddit.com https://www.redditstatic.com https://pixel-config.reddit.com https://www.google.com https://api.reo.dev https://project.console.ory.sh https://api.console.ory.sh https://sqa-web.ory.com https://consent.ory.com https://fast.wistia.net https://fast.wistia.com https://distillery.wistia.com https://embed-cloudfront.wistia.com https://forms.hsforms.com https://hubspot-forms-static-embed.s3.amazonaws.com https://forms-eu1.hsforms.com https://33xluxe1.api.sanity.io https://33xluxe1.apicdn.sanity.io https://cdn.sanity.io https://cdn.jsdelivr.net wss://33xluxe1.api.sanity.io https://pipedream.wistia.com https://fg8vvsvnieiv3ej16jby.litix.io https://raw.githubusercontent.com https://api.github.com https://www.googleadservices.com; font-src 'self' data: https://fast.wistia.net https://cdn.jsdelivr.net; worker-src blob: 'self'; media-src 'self' https://embed-ssl.wistia.com blob:; frame-src 'self' https://*.hubspot.com https://vercel.live https://app-eu1.hubspot.com https://www.googletagmanager.com https://consent.ory.com https://sqa-web.ory.com https://fast.wistia.com https://fast.wistia.net https://embed-ssl.wistia.com https://www.youtube.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self' https://app-eu1.hubspot.com https://www.googletagmanager.com https://www.einpresswire.com https://*.vercel.app; upgrade-insecure-requests; report-uri https://o481709.ingest.us.sentry.io/api/4510205854482432/security/?sentry_key=62382f4c47aefd04c9afd518f417b97a; report-to csp-endpoint; 2 default-src https: 'unsafe-inline' 2 style-src-elem cdn.consentmanager.net cdn.honey.io *.hagel-shop.de tracking.paqato.com static-tracking.klaviyo.com m2stage-blog.hagel-shop.de www.gstatic.com fonts.googleapis.com; font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com data: cdn.elev.io media.flixfacts.com static.klaviyo.com tracking.paqato.com account.affilitizer.com at.alicdn.com cdn-uicons.flaticon.com cdn.faceworks.nl cdn.honey.io media.flixcar.com moz-extension: r2cdn.perplexity.ai http://*.hotjar.com https://*.hotjar.com http://*.hotjar.io https://*.hotjar.io d3dc1lgancj6l0.cloudfront.net maxcdn.bootstrapcdn.com https://widgets.trustedshops.com https://integrations.etrusted.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de www.facebook.com 'self' connect.facebook.net graph.facebook.com business.facebook.com http://*.facebook.com https://*.facebook.com test.saferpay.com www.saferpay.com saferpay.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.hagel-shop.de 'self' www.hagel-shop.de 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.demdex.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com www.google.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de https://cdn.consentmanager.net https://delivery.consentmanager.net www.awin1.com cdn.consentmanager.net *.criteo.com *.criteo.net *.dixa.io *.doubleclick.net *.durchsichtig.xyz *.hagel-shop.de *.hotjar.com www.facebook.com media.flixcar.com *.klarinsights.net www.paypalobjects.com www.sovendus-benefits.com www.sovendus-campaign.com www.sovendus-connect.com www.sovendus-network.com bat.bing.com www.instagram.com return.4sellers.de 10.10.10.1:8090 bcsgsrv.com bispadisch.de caclk.com cdn.elev.io cmodul.solutenetwork.com div.show fwwh.werkhaus-bielefeld.de:8091 gateway.zscaler.net gateway.zscloud.net hipodi.com kerastase-quiz.vercel.app oponas.com ptclk.com www.explorr.net www.pricejoe.com https://www.googletagmanager.com/ connect.facebook.net graph.facebook.com business.facebook.com https://*.hotjar.com http://*.hotjar.io https://*.hotjar.io https://www.google.com/ http://*.facebook.com https://*.facebook.com js.mollie.com test.saferpay.com www.saferpay.com saferpay.com gateways.zscloud.net ifw.noel.gv.at 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net data: *.googleapis.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.payments-amazon.com https://cdn.consentmanager.net https://delivery.consentmanager.net validate.fishpig.co.uk sync.1rx.io ad.360yield.com eb2.3lift.com *.adnxs.com *.agkn.com www.awin1.com *.bing.com *.bing.net *.bidswitch.net *.casalemedia.com *.cloudfront.net *.consentmanager.net *.criteo.com public-prod-dspcookiematching.dmxleo.com *.doubleclick.net e1.emxdgt.com www.facebook.com media.flixcar.com *.flix360.com *.google.com *.google.de *.googletagmanager.com fonts.gstatic.com *.hagel-shop.de id5-sync.com matching.ivitrack.com contextual.media.net exchange.mediavine.com visitor.omnitagjs.com sync.outbrain.com jadserve.postrelease.com simage2.pubmatic.com *.roeye.com pixel.rubiconproject.com match.sharethrough.com rtb-csync.smartadserver.com criteo-sync.teads.tv *.tiktok.com criteo-partners.tremorhub.com a.twiago.com *.taboola.com sync.targeting.unrulymedia.com t.ssl.ak.dynamic.tiles.virtualearth.net www.wepowerconnections.com ad.yieldlab.net sync-criteo.ads.yieldmo.com *.zenaps.com c.clarity.ms assets.paqato.com www.google.hu www.google.es csm.nl3.eu.criteo.net www.google.nl *.hagel-shop.at bat.bing.com blob: client-side-metrics.fr3.eu.criteo.net client-side-metrics.nl3.eu.criteo.net d3k81ch9hvuctc.cloudfront.net google.com hagel-de.ddev.site media.flixfacts.com modular.flix360.io static-eu.payments-amazon.com t0.ssl.ak.dynamic.tiles.virtualearth.net t1.ssl.ak.dynamic.tiles.virtualearth.net www.google.ae www.google.am www.google.at www.google.ba www.google.be www.google.bg www.google.ca www.google.ch www.google.co.il www.google.co.in www.google.co.kr www.google.co.th www.google.co.uk www.google.co.uz www.google.co.za www.google.com.au www.google.com.br www.google.com.eg www.google.com.hk www.google.com.lb www.google.com.mt www.google.com.mx www.google.com.sg www.google.com.tr www.google.com.tw www.google.com.ua www.google.com.vn www.google.cz www.google.de www.google.dk www.google.ee www.google.fi www.google.fr www.google.gr www.google.hr www.google.ie www.google.it www.google.jo www.google.li www.google.lu www.google.lv www.google.md www.google.mk www.google.no www.google.pl www.google.pt www.google.ro www.google.rs www.google.ru www.google.se www.google.si www.google.sk www.google.tn www.zenaps.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ connect.facebook.net graph.facebook.com business.facebook.com http://*.hotjar.com https://*.hotjar.com http://*.hotjar.io https://*.hotjar.io http://*.linkedin.com https://*.linkedin.com http://*.facebook.com https://*.facebook.com http://www.google.com/ http://www.google.de/ https://www.google.de/ https://www.googletagmanager.com http://www.googletagmanager.com userlike-cdn-operators.s3-eu-west-1.amazonaws.com https://widgets.trustedshops.com/ https://www.mollie.com test.saferpay.com www.saferpay.com saferpay.com https://widgets.trustedshops.com https://integrations.etrusted.com www.hagel-shop.at www.googleads.g.doubleckick.net www.google.com.ro data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net assets.adobedtm.com *.adobe.io *.commerce-payment-services.com *.magento-ds.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.magento-datasolutions.com *.googletagmanager.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de jsd-widget.atlassian.com https://cdn.consentmanager.net https://delivery.consentmanager.net *.hagel-shop.de *.hagel-shop.at *.ablyft.com www.awin1.com *.bing.com *.clarity.ms *.consentmanager.net *.criteo.com messenger.dixa.io www.dwin1.com cdn.elev.io connect.facebook.net prod.flixgvid.flix360.io media.flixcar.com media.flixfacts.com *.google-analytics.com *.googleoptimize.com *.hotjar.com lantern.roeyecdn.com lantern.roeye.com the.sciencebehindecommerce.com *.sovendus.com www.sovendus-benefits.com www.sovendus-campaign.com www.sovendus-connect.com www.sovendus-network.com analytics.tiktok.com *.virtualearth.net www.zeitung-direkt.de tracking.paqato.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ http://www.googletagmanager.com/ https://www.googletagmanager.com/ www.facebook.com graph.facebook.com business.facebook.com https://connect.facebook.net/ https://snap.licdn.com/li.lms-analytics/insight.min.js http://*.hotjar.com https://*.hotjar.com http://*.hotjar.io https://*.hotjar.io unsafe-inline userlike-cdn-widgets.s3-eu-west-1.amazonaws.com d3dc1lgancj6l0.cloudfront.net api.userlike.com http://www.google.com/recaptcha/ https://widgets.trustedshops.com/ js.mollie.com test.saferpay.com www.saferpay.com saferpay.com https://widgets.trustedshops.com https://integrations.etrusted.com rum.hlx.page 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com *.magento-datasolutions.com *.magento-ds.com *.bing.com media.flixcar.com *.googletagmanager.com css/light.theme.css static-tracking.klaviyo.com tracking.paqato.com www.gstatic.com https://static.klaviyo.com maxcdn.bootstrapcdn.com https://widgets.trustedshops.com https://integrations.etrusted.com 'self' 'unsafe-inline'; object-src https://cdn.consentmanager.net https://delivery.consentmanager.net data: 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com https://cdn.consentmanager.net https://delivery.consentmanager.net *.hagel-shop.de data: mcprod.hagel-shop.de media.flixfacts.com youtube.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.magento-datasolutions.com *.magento-ds.com *.googleapis.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de jsd-widget.atlassian.com api-private.atlassian.com https://cdn.consentmanager.net https://delivery.consentmanager.net *.ablyft.com magento-recs-sdk.adobe.net commerce.adobedtm.com *.bing.com *.bing.net *.clarity.ms *.consentmanager.net *.dixa.io *.criteo.com *.doubleclick.net *.durchsichtig.xyz *.elev.io media.flixcar.com maps.googleapis.com *.google-analytics.com *.google.de *.hagel-shop.de *.hotjar.com *.hotjar.io *.klarinsights.net the.sciencebehindecommerce.com *.sovendus.com analytics.tiktok.com unpkg.com/@adobe/ www.wepowerconnections.com tracking.paqato.com api-js.datadome.co api.killadsapi.com api.vid-adblocker.com cmodul.solutenetwork.com data: overbridgenet.com rt.flix360.com static-eu.payments-amazon.com update.adblock360.org www.facebook.com www.google.at www.google.ba www.google.be www.google.bg www.google.ca www.google.ch www.google.co.il www.google.co.in www.google.co.kr www.google.co.th www.google.co.uk www.google.com.eg www.google.com.hk www.google.com.mx www.google.com.sg www.google.com.tr www.google.com.tw www.google.com.vn www.google.dk www.google.es www.google.fi www.google.fr www.google.gr www.google.hr www.google.hu www.google.it www.google.lt www.google.lu www.google.mk www.google.nl www.google.pl www.google.pt www.google.ro www.google.rs www.google.ru www.google.se www.google.si www.google.sk www.google.tn https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ connect.facebook.net graph.facebook.com business.facebook.com http://*.hotjar.com:* https://*.hotjar.com:* http://*.hotjar.io https://*.hotjar.io wss://*.hotjar.com http://salesviewer.org/ userlike-cdn-widgets.s3-eu-west-1.amazonaws.com autocomplete2.postdirekt.de test.saferpay.com www.saferpay.com saferpay.com *.trustedshops.com *.etrusted.com analytics-ipv6.tiktokw.us www.google.cz 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com https://cdn.consentmanager.net https://delivery.consentmanager.net test.saferpay.com www.saferpay.com saferpay.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 frame-ancestors 'self'; report-uri https://www.goldcoastbulletin.com.au/csp-reports 2 default-src 'self' https:; connect-src 'self' https: wss: javascript:; font-src 'self' data: use.typekit.net fonts.gstatic.com *.cloudfront.net fonts.googleapis.com assets.parentsquare.com assets.sandbox.parentsquare.com assets.staging.parentsquare.com themes.googleusercontent.com; form-action 'self' https:; frame-ancestors 'self'; img-src 'self' blob: data: https: pbs.twimg.com; media-src 'self' data: blob: https:; object-src 'self' parentsquare-restricted-data-production.s3.amazonaws.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https:; script-src-elem 'self' 'unsafe-inline' 'unsafe-eval' https:; style-src 'self' 'unsafe-inline' https:; upgrade-insecure-requests; worker-src 'self' blob:; report-uri /csp_report 2 base-uri 'none'; connect-src 'self' analytics-ipv6.tiktokw.us api.ldnfrpl.com api.leadinfo.com c.ba.contentsquare.net cdn.cookielaw.org collector.leadinfo.net collector4.leadinfo.net *.bing.com *.bing.net *.brightsg.com *.clarity.ms *.cloudflare.com *.doubleclick.net *.facebook.com *.google-analytics.com *.google.com *.googleapis.com *.googletagmanager.com *.googlesyndication.com *.hotjar.com *.hotjar.io *.hubapi.com *.hubspot.com *.linkedin.com *.onetrust.com *.reddit.com *.redditstatic.com *.tiktok.com sentry.io wss://ws.hotjar.com; default-src 'none'; font-src https: data:; form-action 'self' *.hsforms.com shop.ie.brightsg.com; frame-ancestors 'self'; frame-src 'self' *.cloudflare.com *.google.com *.googletagmanager.com *.hs-sites-eu1.com *.hs-sites.com *.hsforms.com *.hubspot.com *.jotform.com *.vimeo.com *.youtube.com; img-src https: data: blob:; media-src https: data:; object-src 'none'; prefetch-src 'self' https:; script-src 'self' 'unsafe-inline' brightsg.referralrock.com cdn.cookielaw.org cdn.ldnfrpl.com cdn.leadinfo.net *.bing.com *.bing.net *.brightsg.com *.capterra.com *.clarity.ms *.cloudflare.com *.doubleclick.net *.facebook.com *.facebook.net *.google-analytics.com *.google.com *.googleadservices.com *.googletagmanager.com *.googlesyndication.com *.gstatic.com *.hotjar.com *.hotjar.io *.hs-analytics.net *.hs-banner.com *.hs-scripts.com *.hsadspixel.net *.hsforms.net *.hubapi.com *.hubspot.com *.jotform.com *.licdn.com *.linkedin.com *.tiktok.com; script-src-attr 'unsafe-inline'; style-src 'self' 'unsafe-inline' https:; upgrade-insecure-requests; worker-src 'self' blob:; report-uri https://brightsg.report-uri.com/r/d/csp/wizard; report-to csp-endpoint; 2 object-src 'none'; script-src 'self' 'unsafe-inline' 'unsafe-eval' metrics.mastercard.com smetrics.mastercard.com assets.adobedtm.com cdn.cookielaw.org www.onetrust.com onetrust.com geolocation.onetrust.com privacyportal.onetrust.com www.googletagmanager.com googleads.g.doubleclick.net www.googleadservices.com cdn.jsdelivr.net https://asset.forms.mastercard.com https://assets.adobedtm.com https://cdn.cookielaw.org https://play.vidyard.com https://unpkg.com platform.instagram.com platform.twitter.com; script-src-attr 'self' 'unsafe-inline' 'unsafe-hashes'; script-src-elem 'self' 'unsafe-inline' metrics.mastercard.com smetrics.mastercard.com assets.adobedtm.com cdn.cookielaw.org www.onetrust.com onetrust.com geolocation.onetrust.com privacyportal.onetrust.com st.dynamicyield.com go.mastercardservices.com pi.pardot.com snap.licdn.com assets.adobetm.com api-mastercard-dxp.nd.nudatasecurity.com s.go-mpulse.net 6sc.co 6sense.com *.6sc.co *.6sense.com www.googletagmanager.com googleads.g.doubleclick.net www.googleadservices.com cdn.jsdelivr.net https://asset.forms.mastercard.com https://assets.adobedtm.com https://cdn.cookielaw.org https://play.vidyard.com https://unpkg.com platform.instagram.com platform.twitter.com; style-src 'self' 'unsafe-inline' https://asset.forms.mastercard.com; style-src-attr 'self' 'unsafe-inline'; style-src-elem 'self' 'unsafe-inline' https://cdn.dynamicyield.com https://asset.forms.mastercard.com; frame-ancestors 'self' 2 default-src https: data: 'self' 'unsafe-inline' 'unsafe-eval' *.googleapis.com fonts.gstatic.com *.fontawesome.com *.aspnetcdn.com *.jsdelivr.net *.googletagmanager.com *.googleadservices.com s.adroll.com wss://*.hotjar.com/api/v2/client/ws *.jquery.com; img-src data: *; frame-ancestors 'self'; object-src 'none'; form-action 'self'; base-uri 'self'; media-src s3.amazonaws.com; report-uri /csp/; 2 default-src 'self' https://jobs.b-ite.com https://bwp-online.gelsenkirchen.de https://ads.gelsen.net https://ads2.gelsen.net https://twebshop.tomas-travel.com https://player.podigee-cdn.net https://start.video-stream-hosting.de https://www.xn--fundbrodeutschland-q6b.de; style-src 'self' 'unsafe-inline' https://bwp-online.gelsenkirchen.de https://twebshop.tomas-travel.com https://player.podigee-cdn.net https://cdn.podigee.com; img-src 'self' https://ads.gelsen.net https://ads.gelsen.net https://webstatistik.gelsenkirchen.de https://server.arcgisonline.com https://*.tile.openstreetmap.org https://geodaten.metropoleruhr.de https://gdi.gelsenkirchen.de https://twebshop.tomas-travel.com https://cdn.podigee.com https://images.podigee-cdn.net https://cs-assets.b-ite.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://www.youtube.com https://pansite6.gelsenkirchen.de https://ads.gelsen.net https://ads.gelsen.net https://webstatistik.gelsenkirchen.de https://static.b-ite.com https://cs-assets.b-ite.com https://bwp-online.gelsenkirchen.de/ https://twebshop.tomas-travel.com https://player.podigee-cdn.net https://cdn.podigee.com https://start.video-stream-hosting.de https://www.xn--fundbrodeutschland-q6b.de; child-src 'self' https://www.youtube.com https://player.vimeo.com https://www.youtube-nocookie.com https://whitelabel.hotel.de https://tempus-termine.com https://*.gelsenkirchen.de https://player.podigee-cdn.net https://start.video-stream-hosting.de https://www.xn--fundbrodeutschland-q6b.de 2 default-src 'self' 'unsafe-inline' blob: data: https:; script-src 'self' 'unsafe-eval' 'unsafe-inline'; script-src-elem 'self' 'unsafe-inline' http://*.quantserve.com https: https://*.doubleclick.net https://*.teads.tv; worker-src 'self' blob:; connect-src 'self' https: wss:; img-src 'self' https:; frame-src 'self' http://*.trendmicro.com https:; report-to csp-endpoint 2 connect-src 'self' 'unsafe-inline' 'unsafe-eval' *.bewakingscamera.nl *.bing.net *.googletagmanager.com *.mouseflow.com *.returnless.com *.storyblok.com api.marker.io ssr.marker.io s3.eu-west-1.amazonaws.com/marker.sessions.prod; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.bewakingscamera.nl *.googletagmanager.com *.mouseflow.com *.returnless.com *.storyblok.com edge.marker.io app.marker.io; default-src 'self' 'unsafe-inline' 'unsafe-eval' *.bing.net *.googletagmanager.com *.mouseflow.com *.storyblok.com; img-src 'self' 'unsafe-inline' 'unsafe-eval' *.bing.net *.googletagmanager.com *.storyblok.com blob: data: media.marker.io app.marker.io edge.marker.io; style-src 'self' 'unsafe-inline' 'unsafe-eval' *.googletagmanager.com; frame-src 'self' 'unsafe-inline' 'unsafe-eval' *.returnless.com app.marker.io; media-src 'self' 'unsafe-inline' 'unsafe-eval' *.storyblok.com media.marker.io app.marker.io edge.marker.io; child-src 'self' 'unsafe-inline' 'unsafe-eval' app.marker.io; font-src 'self' 'unsafe-inline' 'unsafe-eval' app.marker.io edge.marker.io; form-action 'self' 'unsafe-inline' 'unsafe-eval' app.marker.io api.marker.io; report-uri https://14edc0c0-b3cc-497c-8aa2-2e84efa49370.sansec.watch/; report-to report-endpoint; 2 default-src 'none'; script-src 'self' 'unsafe-inline' 'unsafe-eval' www.googletagmanager.com kit.fontawesome.com connect.facebook.net cdn.polyfill.io code.jquery.com www.google-analytics.com ssl.google-analytics.com www.googleoptimize.com script.crazyegg.com cdn.syndication.twimg.com speedtest.bestbroadbanddeals.co.uk cdnjs.cloudflare.com maxcdn.bootstrapcdn.com widget.trustpilot.com s3.amazonaws.com cable.us4.list-manage.com admin.bestbroadbanddeals.co.uk services.xg4ken.com unpkg.com script.hotjar.com static.hotjar.com c5.adalyser.com plausible.io consent.cookiebot.com consentcdn.cookiebot.com e.infogram.com localhost:3000; connect-src 'self' consentcdn.cookiebot.com *.fontawesome.com api.addressy.com wss://ws.hotjar.com *.hotjar.com content.hotjar.io cable.us4.list-manage.com admin.bestbroadbanddeals.co.uk stats.g.doubleclick.net plausible.io localhost:3000; img-src 'self' data: *.bestbroadbanddeals.co.uk www.google.com www.googletagmanager.com www.google.co.uk www.google-analytics.com s1.2mdn.net ad.doubleclick.net stats.g.doubleclick.net gtrk.s3.amazonaws.com pbs.twimg.com code.jquery.com 19.xg4ken.com s3-eu-west-1.amazonaws.com pcf.tdscd.com c5.adalyser.com v2.crocdn.com 540k006f.tinifycdn.com imgsct.cookiebot.com; style-src 'self' 'unsafe-inline' code.jquery.com maxcdn.bootstrapcdn.com cdnjs.cloudflare.com admin.bestbroadbanddeals.co.uk pro.fontawesome.com localhost:3000; font-src 'self' *.fontawesome.com maxcdn.bootstrapcdn.com admin.bestbroadbanddeals.co.uk data: localhost:3000; object-src 'self' api.ookla.com fpdownload.adobe.com; frame-src 'self' widget.trustpilot.com vars.hotjar.com googleads.g.doubleclick.net consentcdn.cookiebot.com e.infogram.com data:; child-src 'self' blob:; report-uri /csp-violation-report/ 2 object-src 'none'; script-src 'self' 'report-sample' cdnjs.cloudflare.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://maps.googleapis.com https://polyfill-fastly.io https://unpkg.com maps.google.com; style-src 'self' 'report-sample' https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com; webrtc 'block'; worker-src 'self'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'; report-uri https://www.electronics.org/log-report-uri/reportOnly 2 default-src 'self' https://quickquack.com https://*.quickquack.com https://dontdrivedirty.com https://*.dontdrivedirty.com *.qqcw.us; connect-src 'self' https://*.ads.linkedin.com https://www.googleadservices.com https://analytics-ipv6.tiktokw.us https://analytics.tiktok.com https://sdk.iad-07.braze.com https://js.appboycdn.com https://quickquack.com https://*.quickquack.com https://dontdrivedirty.com https://*.dontdrivedirty.com https://*.qqcw.us https://js.stripe.com https://m.stripe.network https://m.stripe.com https://api.stripe.com https://*.googleapis.com https://cdn.sanity.io https://*.google.com https://*.gstatic.com https://unpkg.com https://*.mouseflow.com https://api.segment.io/v1/m https://connect.facebook.net/en_US/fbevents.js https://*.facebook.net https://*.facebook.com https://qqcw.report-uri.com/r/t/csp/reportOnly https://www.googletagmanager.com https://tagmanager.google.com https://*.fbot.me https://cdn.feathery.io https://api.feathery.io https://cdn.jsdelivr.net https://www.google-analytics.com https://google.com https://*.doubleclick.net data: blob:; font-src 'self' https://use.fontawesome.com https://fonts.gstatic.com https://js.stripe.com https://m.stripe.network https://m.stripe.com https://*.fbot.me; img-src 'self' https://d3st4nmzrq9nfk.cloudfront.net https://*.ads.linkedin.com https://analytics.tiktok.com https://sdk.iad-07.braze.com https://js.appboycdn.com https://quickquack.com https://*.quickquack.com https://dontdrivedirty.com https://*.dontdrivedirty.com https://*.qqcw.us https://*.googleapis.com https://*.gstatic.com https://cdn.sanity.io *.google.com *.facebook.net www.facebook.com *.googleusercontent.com https://www.google-analytics.com https://*.googleadservices.com https://*.doubleclick.net https://www.googletagmanager.com https://*.fbot.me data: blob:; media-src 'self' https://quickquack.com https://*.quickquack.com https://dontdrivedirty.com https://*.dontdrivedirty.com https://*.qqcw.us https://*.fbot.me; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://*.ads.linkedin.com https://snap.licdn.com https://analytics.tiktok.com https://sdk.iad-07.braze.com https://js.appboycdn.com https://quickquack.com https://*.quickquack.com https://dontdrivedirty.com https://*.dontdrivedirty.com https://*.qqcw.us https://js.stripe.com https://m.stripe.network https://m.stripe.com https://*.googleapis.com https://*.gstatic.com *.google.com https://*.ggpht.com https://unpkg.com https://cdn.mouseflow.com *.googleusercontent.com https://connect.facebook.net/en_US/fbevents.js *.facebook.net https://www.googletagmanager.com https://tagmanager.google.com/ https://*.fbot.me https://*.feathery.io https://cdn.jsdelivr.net https://www.google-analytics.com https://*.doubleclick.net https://googleadservices.com https://www.youtube.com blob:; style-src 'self' 'unsafe-inline' https://quickquack.com https://*.quickquack.com https://dontdrivedirty.com https://*.dontdrivedirty.com https://use.fontawesome.com https://fonts.googleapis.com https://tagmanager.google.com/ https://fonts.googleapis.com/ https://*.fbot.me data: blob:; frame-src 'self' https://www.facebook.com https://js.stripe.com https://m.stripe.network https://m.stripe.com *.google.com https://www.googletagmanager.com https://tagmanager.google.com/ https://*.fbot.me https://cdn.feathery.io https://cdn.jsdelivr.net https://*.doubleclick.net https://www.youtube-nocookie.com/ https://keycloak.dev.qqcw.us https://auth.dontdrivedirty.com; report-uri https://qqcw.report-uri.com/r/t/csp/reportOnly?ngsw-bypass=true; 2 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://code.jquery.com https://www.google.com https://www.gstatic.com https://cdn.userecho.com https://yandex.ru/ https://*.yandex.ru https://*.maps.yandex.net https://yastatic.net; font-src 'self' https://fonts.gstatic.com https://maxcdn.bootstrapcdn.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://maxcdn.bootstrapcdn.com; img-src 'self' data: https://*.starline.ru https://*.maps.yandex.net https://*.google.com https://enterprise.api-maps.yandex.ru https://cdn.userecho.com https://*.openstreetmap.org http://yandex.st/ https://yandex.st/ https://mc.yandex.ru https://yastatic.net; connect-src 'self' ws://*.starline.ru wss://rpl.starline-online.ru https://mc.yandex.ru https://geocode.starline.ru; frame-src 'self' https://*.google.com https://mc.yandex.ru/ https://arkan.ru; 2 default-src 'self' data: gap: *.klarna.com *.freshchat.com *.vimeo.com *.youtube.com *.whittard.co.uk *.whittard.com mention-me.com *.zenaps.com *.sub2tech.com *.gstatic.com *.facebook.com *.bglobale.com *.global-e.com *.onetrust.com *.windows.net *.whittardofchelsea.freshdesk.com *.tvsquared.com; img-src data: blob: *.demandware.net *.commercecloud.salesforce.com *.ads.linkedin.com *.demdex.net *.amazonaws.com *.ometria.com *.googletagmanager.com *.facebook.net *.facebook.com *.google.com *.google.ad *.google.ae *.google.com.af *.google.com.ag *.google.com.ai *.google.al *.google.am *.google.co.ao *.google.com.ar *.google.as *.google.at *.google.com.au *.google.az *.google.ba *.google.com.bd *.google.be *.google.bf *.google.bg *.google.com.bh *.google.bi *.google.bj *.google.com.bn *.google.com.bo *.google.com.br *.google.bs *.google.bt *.google.co.bw *.google.by *.google.com.bz *.google.ca *.google.cd *.google.cf *.google.cg *.google.ch *.google.ci *.google.co.ck *.google.cl *.google.cm *.google.cn *.google.com.co *.google.co.cr *.google.com.cu *.google.cv *.google.com.cy *.google.cz *.google.de *.google.dj *.google.dk *.google.dm *.google.com.do *.google.dz *.google.com.ec *.google.ee *.google.com.eg *.google.es *.google.com.et *.google.fi *.google.com.fj *.google.fm *.google.fr *.google.ga *.google.ge *.google.gg *.google.com.gh *.google.com.gi *.google.gl *.google.gm *.google.gr *.google.com.gt *.google.gy *.google.com.hk *.google.hn *.google.hr *.google.ht *.google.hu *.google.co.id *.google.ie *.google.co.il *.google.im *.google.co.in *.google.iq *.google.is *.google.it *.google.je *.google.com.jm *.google.jo *.google.co.jp *.google.co.ke *.google.com.kh *.google.ki *.google.kg *.google.co.kr *.google.com.kw *.google.kz *.google.la *.google.com.lb *.google.li *.google.lk *.google.co.ls *.google.lt *.google.lu *.google.lv *.google.com.ly *.google.co.ma *.google.md *.google.me *.google.mg *.google.mk *.google.ml *.google.com.mm *.google.mn *.google.ms *.google.com.mt *.google.mu *.google.mv *.google.mw *.google.com.mx *.google.com.my *.google.co.mz *.google.com.na *.google.com.ng *.google.com.ni *.google.ne *.google.nl *.google.no *.google.com.np *.google.nr *.google.nu *.google.co.nz *.google.com.om *.google.com.pa *.google.com.pe *.google.com.pg *.google.com.ph *.google.com.pk *.google.pl *.google.pn *.google.com.pr *.google.ps *.google.pt *.google.com.py *.google.com.qa *.google.ro *.google.ru *.google.rw *.google.com.sa *.google.com.sb *.google.sc *.google.se *.google.com.sg *.google.sh *.google.si *.google.sk *.google.com.sl *.google.sn *.google.so *.google.sm *.google.sr *.google.st *.google.com.sv *.google.td *.google.tg *.google.co.th *.google.com.tj *.google.tl *.google.tm *.google.tn *.google.to *.google.com.tr *.google.tt *.google.com.tw *.google.co.tz *.google.com.ua *.google.co.ug *.google.co.uk *.google.com.uy *.google.co.uz *.google.com.vc *.google.co.ve *.google.vg *.google.co.vi *.google.com.vn *.google.vu *.google.ws *.google.rs *.google.co.za *.google.co.zm *.google.co.zw *.google.cat *.gstatic.com *.doubleclick.net *.googleapis.com *.google-analytics.com *.googleadservices.com *.google.com *.whittard.co.uk *.whittard.com *.postcodeanywhere.co.uk *.pcapredict.com *.yotpo.com *.tokywoky.com img.tokywoky.com *.klarnaservices.com *.klarnacdn.net *.mention-me.com *.awin1.com *.dwin1.com bda.bookatable.com i.ytimg.com *.contentsquare.net *.contentsquare.com *.sub2tech.com *.cloudfront.net *.youtube.com *.vimeo.com bat.bing.com *.zenaps.com *.msgfocus.com *.fbsbx.com *.fbcdn.net graph.facebook.com *.zscloud.net *.googleusercontent.com *.klarnaevt.com i.vimeocdn.com *.surveymonkey.com *.kaltura.com *.gocertify.me *.bglobale.com *.global-e.com *.bc0a.com *.b0e8.com *.onetrust.com *.windows.net *.particularaudience.com *.p-a.io *.googleanalytics.com *.google-analytics.com *.googleoptimize.com *.tvsquared.com analytics.whittard.com analytics.whittard.co.uk ade.googlesyndication.com *.abtasty.com *.roeyecdn.com *.roeye.com *.linkedin.com *.hotjar.com *.hotjar.io wss://*.hotjar.com; child-src 'self' blob: *.abtasty.com *.studentbeans.com *.google.com *.doubleclick.net *.facebook.com *.tokywoky.com *.freshchat.com mention-me.com *.mention-me.com *.klarna.com *.klarnaservices.com bda.bookatable.com *.sub2tech.com *.youtube.com *.vimeo.com *.zenaps.com *.googlesyndication.com *.online-metrix.net *.pagetiger.com *.googletagmanager.com connect.studentbeans.com *.googleapis.com *.surveymonkey.com *.paperform.co paperform.co *.ordergroove.com *.worldpay.com *.cardinalcommerce.com *.gocertify.me *.bglobale.com *.global-e.com whittardofchelsea.freshdesk.com *.pinterest.com *.whittard.co.uk *.whittard.com; style-src 'self' 'unsafe-inline' *.googleapis.com *.postcodeanywhere.co.uk *.pcapredict.com *.bootstrapcdn.com *.myfonts.net cdnjs.cloudflare.com *.yotpo.com *.freshchat.com *.mention-me.com *.sub2tech.com bda.bookatable.com *.klarnacdn.net *.whittard.co.uk *.whittard.com *.ordergroove.com *.particularaudience.com *.p-a.io *.google.com *.amazonaws.com *.abtasty.com *.gstatic.com *.hotjar.com *.hotjar.io wss://*.hotjar.com; font-src 'self' data: *.gstatic.com *.g.doubleclick.net *.bootstrapcdn.com *.yotpo.com *.bookatable.com *.alicdn.com *.klarnacdn.net *.whittard.co.uk *.whittard.com *.ordergroove.com *.fontawesome.com *.bglobale.com *.global-e.com *.abtasty.com *.googleapis.com use.typekit.net *.hotjar.com *.hotjar.io wss://*.hotjar.com; media-src 'self' data: *.facebook.com *.youtube.com *.vimeo.com *.paypal.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' snap.licdn.com code.jquery.com *.pinimg.com *.cquotient.com *.ometria.com *.tryzens-analytics.com:12443 *.tvsquared.com *.facebook.net cdnjs.cloudflare.com cdn.cquotient.com *.googletagmanager.com www.googletagmanager.com *.g.doubleclick.net *.googleapis.com *.google-analytics.com *.googleadservices.com *.google.com *.gstatic.com *.dwin1.com *.postcodeanywhere.co.uk *.pcapredict.com *.z-analytics.net *.yotpo.com *.tokywoky.com *.msecnd.net *.freshchat.com *.klarnaservices.com *.klarna.com *.klarnaevt.com *.klarnacdn.net *.mention-me.com *.worldpay.com *.cardinalcommerce.com bda.bookatable.com bat.bing.com *.contentsquare.net *.contentsquare.com *.sub2tech.com *.yottaa.com *.cloudfront.net *.freshworksapi.com *.zenaps.com *.paypal.com *.paypalobjects.com *.awin1.com *.dwin1.com *.sessioncam.com *.whittard.co.uk *.whittard.com *.bootstrapcdn.com *.googlesyndication.com www.google.com *.studentbeans.com onlineerp.solution.quebec widget.surveymonkey.com *.paperform.co paperform.co *.ordergroove.com cdnapisec.kaltura.com *.gocertify.me *.bglobale.com *.global-e.com *.b0e8.com *.vimeo.com *.onetrust.com *.windows.net *.particularaudience.com *.p-a.io *.googleanalytics.com *.googleoptimize.com analytics.whittard.com analytics.whittard.co.uk *.amazonaws.com *.abtasty.com *.roeyecdn.com *.roeye.com *.pinterest.com *.zi-scripts.com *.roeye.com *.payments-amazon.com *.tryzens-analytics.com unpkg.com cdn.cookielaw.org *.hotjar.com *.hotjar.io wss://*.hotjar.com; connect-src 'self' *.ads.linkedin.com snap.licdn.com *.rapid.yottaa-network.net pagead2.googlesyndication.com *.google-analytics.com *.googleadservices.com *.g.doubleclick.net *.tryzens-analytics.com:12280 *.ometria.com *.postcodeanywhere.co.uk *.pcapredict.com *.yotpo.com *.tokywoky.com *.klarnauserservices.com *.klarnaservices.com *.klarna.com *.klarnaevt.com *.klarnacdn.net *.mention-me.com mention-me.com bda.bookatable.com *.z-analytics.net *.contentsquare.net *.contentsquare.com *.sub2tech.com *.cloudfront.net *.awin1.com *.dwin1.com *.yottaa.net *.sessioncam.com bat.bing.com *.facebook.com *.google.com *.facebook.net *.googleapis.com widget.surveymonkey.com *.s3.amazonaws.com *.ordergroove.com *.worldpay.com *.cardinalcommerce.com *.gocertify.me *.bglobale.com *.global-e.com *.vimeo.com *.onetrust.com *.windows.net *.particularaudience.com *.p-a.io *.gstatic.com *.abtasty.com analytics.whittard.com analytics.whittard.co.uk ade.googlesyndication.com *.whittard.com *.whittard.co.uk *.amazonaws.com *.pinterest.com *.zi-scripts.com *.zoominfo.com *.tryzens-analytics.com unpkg.com cdn.cookielaw.org *.google.co.uk *.bing.net payments-eu.amazon.com *.hotjar.com *.hotjar.io wss://*.hotjar.com; manifest-src 'self'; ; report-uri https://289r1hnfc9.execute-api.eu-west-1.amazonaws.com/prod/whittard-cspdata; 2 font-src 'self' data:; 2 script-src-elem *.bing.com *.clarity.ms *.googleadservices.com *.youtube.com *.global-e.com *.bglobale.com *.redditstatic.com *.bing-int.com *.trustpilot.com www.googletagmanager.com static-tracking.klaviyo.com static.klaviyo.com *.herroom.com unpkg.com *.googleapis.com www.paypal.com js.braintreegateway.com pay.google.com c.paypal.com cdn.kustomerapp.com connect.facebook.net gepi.global-e.com web.global-e.com webservices.global-e.com www.google.com www.gstatic.com *.pinimg.com cdn.noibu.com *.cloudfront.net utt.impactcdn.com googleads.g.doubleclick.net *.pinterest.com se.monetate.net www.paypalobjects.com *.sitejabber.com *.slick.min.js *.msn.com *.r.msn.com *.listrakbi.com cdn.jsdelivr.net *.listrak.com *.aftership.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src-elem *.googleapis.com *.bglobale.com *.trustpilot.com *.herroom.com p.typekit.net use.typekit.net gepi.global-e.com static.klaviyo.com static-tracking.klaviyo.com *.sitejabber.com *.listrakbi.com 'self' 'unsafe-inline'; font-src fonts.gstatic.com use.typekit.net maxcdn.bootstrapcdn.com *.global-e.com *.bglobale.com *.gstatic.com s3-eu-west-1.amazonaws.com cdn.kustomerapp.com globale-prod.s3-eu-west-1.amazonaws.com *.sitejabber.com *.espssl.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com 'self' 'unsafe-inline'; frame-ancestors *.google.com *.cloudfront.net *.pinterest.com *.global-e.com *.youtube.com *.listrakbi.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com www.google.com www.googletagmanager.com *.weltpixel.com *.bglobale.com *.global-e.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.braintreegateway.com *.google.com *.cloudfront.net *.pinterest.com *.listrakbi.com *.trustpilot.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.global-e.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.gstatic.com *.facebook.com *.reddit.com *.bglobale.com assets.herroom.net media.herroom.com *.bing.com *.clarity.ms maps.googleapis.com *.herroom.com *.google.ch bat.bing.net widgets.automizely.com widgets.automizely.io *.trustpilot.com herroom.scene7.com www.googletagmanager.com s3-eu-west-1.amazonaws.com cdn.kustomerhostedcontent.com *.google.com *.brandlock.io media.hisroom.com www.ojrq.net logs-01.loggly.com *.cloudfront.net connect.facebook.net *.sitejabber.com *.doubleclick.net *.g.doubleclick.net *.listrakbi.com *.espssl.com *.kustomerapp.com data: 'self' 'unsafe-inline'; script-src *.adobe.com www.googleadservices.com use.typekit.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com s.ytimg.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ *.magento-ds.com *.global-e.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com maps.googleapis.com *.facebook.net *.redditstatic.com *.reddit.com *.maxmind.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com assets.adobedtm.com amcglobal.sc.omtrdc.net t.paypal.com www.googleapis.com vimeo.com www.vimeo.com www.google.com www.googletagmanager.com www.google-analytics.com *.bglobale.com unpkg.com *.clarity.ms *.cloudfront.net *.listrakbi.com ajax.googleapis.com fonts.googleapis.com widgets.automizely.com widgets.automizely.io *.trustpilot.com *.pinimg.com *.listrak.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com maxcdn.bootstrapcdn.com *.global-e.com assets.braintreegateway.com *.bglobale.com *.typekit.net widgets.automizely.com widgets.automizely.io *.trustpilot.com use.typekit.net *.sitejabber.com *.listrakbi.com 'self' 'unsafe-inline'; object-src *.listrakbi.com 'self' 'unsafe-inline'; media-src *.adobe.com assets.herroom.net *.espssl.com *.listrakbi.com 'self' 'unsafe-inline'; manifest-src *.listrakbi.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.sentry.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.google-analytics.com *.facebook.net *.redditstatic.com *.reddit.com *.doubleclick.net *.mmapiws.com *.googleapis.com *.bing.com *.clarity.ms *.brandlock.io *.cloudfront.net *.clartity.ms *.google.ch bat.bing.net *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io api.automizely.com api.automizely.io *.global-e.com *.bing-int.com *.trustpilot.com a.klaviyo.com andragroup.api.kustomerapp.com www.facebook.com input.noibu.com cdn.noibu.com wss://input.noibu.com herroom.pxf.io hisroom.sjv.io *.pinterest.com herroom.scene7.com *.pndsn.com resource-proxy.noibu.com *.sitejabber.com *.listrakbi.com *.listrak.com *.bglobale.com *.impact.site *.googleadservices.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src self *.herroom.com *.hisroom.com mcprod.herroom.com *.hisrroom.com *.listrakbi.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri self *.herroom.com *.hisroom.com *.listrakbi.com 'self' 'unsafe-inline'; 2 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://*.acer.org https://kit.fontawesome.com https://cdnjs.cloudflare.com https://code.jquery.com https://cdn.jsdelivr.net https://www.youtube.com https://player.vimeo.com https://www.googletagmanager.com https://www.gstatic.com https://www.google-analytics.com https://cdn.monsido.com https://www.gstatic.com/call-tracking/ https://www.google.com/recaptcha/ https://static.ads-twitter.com https://snap.licdn.com https://connect.facebook.net https://googleads.g.doubleclick.net https://maxcdn.bootstrapcdn.com/bootstrap/ https://stackpath.bootstrapcdn.com/bootstrap/ https://*.adroll.com https://fast.wistia.com/embed/medias/ https://fast.wistia.com/assets/external/ https://acer.tfaforms.net/ https://www.tfaforms.com/wForms/ https://platform.twitter.com/ https://widgets.sociablekit.com/ https://cdn.mouseflow.com/ https://js.createsend1.com/javascript/ https://bat.bing.com; style-src 'self' 'unsafe-inline' https://*.acer.org https://fonts.googleapis.com https://cdnjs.cloudflare.com https://www.gstatic.com https://cdn.jsdelivr.net https://stackpath.bootstrapcdn.com/font-awesome/4.7.0/ https://acer.tfaforms.net/dist/ https://acer.tfaforms.net/uploads/themes/ https://www.tfaforms.com/dist/ https://widgets.sociablekit.com/ https://kit.fontawesome.com https://maxcdn.bootstrapcdn.com/font-awesome/; img-src 'self' data: blob: https://*.acer.org https://www.acer-ibt.org https://www.researchconference.com.au https://www.immchallenge.org.au https://www.stemgames.org.au https://tracking.monsido.com https://www.google.com.au/ads/ https://www.google.com.au/pagead/ https://www.google.com https://www.google-analytics.com/ https://www.googletagmanager.com https://px.ads.linkedin.com https://media.licdn.com/dms/image/ https://media.licdn.com/dms/image/ https://sociablekit.com/app/ https://images.sociablekit.com/ https://t.co/i/ https://analytics.twitter.com/i/ https://www.facebook.com/tr/ https://ping.eeharbor.com https://*.adroll.com https://bat.bing.com; font-src 'self' data: https://*.acer.org https://fonts.googleapis.com https://fonts.gstatic.com https://cdnjs.cloudflare.com https://cdn.jsdelivr.net https://ka-p.fontawesome.com https://maxcdn.bootstrapcdn.com/font-awesome/ https://stackpath.bootstrapcdn.com/font-awesome/4.7.0/; media-src 'self' https://www.acer.org https://www.youtube.com https://player.vimeo.com; frame-src https://www.google.com/recaptcha/ https://www.googletagmanager.com https://platform.twitter.com/widgets/ https://www.acer.org https://www.youtube.com https://player.vimeo.com https://shorthand.com; connect-src 'self' https://*.acer.org https://ka-p.fontawesome.com https://kit.fontawesome.com https://www.google.com https://googleads.g.doubleclick.net https://www.google-analytics.com https://www.googleadservices.com https://www.google.com.au/pagead/ https://acer.tfaforms.net/api_v2/ https://stats.g.doubleclick.net/ https://www.facebook.com/tr/ https://updates.expressionengine.com https://px.ads.linkedin.com/wa/; object-src 'none'; base-uri 'self'; form-action 'self'; upgrade-insecure-requests; report-uri https://csp-testing.acer.org/reportOnly/index; 2 font-src storage.googleapis.com/rtux-rtux-data-integration-rti/ *.cloudflare.com fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action test.saferpay.com www.saferpay.com saferpay.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ bid.g.doubleclick.net www.google.com *.prismic.io *.google.com *.criteo.com *.criteo.net *.doubleclick.net *.pinterest.com *.facebook.com *.livechatinc.com *.sovendus-connect.com *.googletagmanager.com *.weltpixel.com test.saferpay.com www.saferpay.com saferpay.com www.xtento.com 'self' 'unsafe-inline'; img-src data: widgets.magentocommerce.com *.vimeocdn.com i.ytimg.com *.youtube.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com *.google-analytics.com *.analytics.google.com www.googletagmanager.com https://images.unsplash.com *.prism.app-us1.com *.prismic.io *.bing.com *.google.ch *.trackjs.com *.google.com *.twiago.com *.doubleclick.net *.bidswitch.net *.adnxs.com *.smartadserver.com *.taboola.com *.adform.net *.omnitagjs.com *.lehner-versand.ch *.casalemedia.com *.criteo.com id5-sync.com *.360yield.com *.ivitrack.com *.media.net *.mediavine.com *.postrelease.com *.outbrain.com *.pubmatic.com *.rubiconproject.com *.sharethrough.com *.teads.tv *.tremorhub.com *.3lift.com *.yieldlab.net *.yieldmo.com *.emxdgt.com *.demdex.net *.livechat-files.com *.dmxleo.com *.profity.ch *.googleapis.com *.1rx.io test.saferpay.com www.saferpay.com saferpay.com www.xtento.com cdn.xtento.com *.gstatic.com *.facebook.com *.reddit.com *.ads-twitter.com t.co *.twitter.com *.bing.net *.klaviyo.com *.clarity.ms *.googletagmanager.com data: 'self' 'unsafe-inline'; script-src *.newrelic.com *.nr-data.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com https://maps.googleapis.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ bx-cdn.com/static/bav2.min.js track.bx-cloud.com/static/bav2.min.js r-st.bx-cloud.com/static/bav2.min.js r-st.bx-cloud.com/static/rti.min.js track.bx-cloud.com/static/rti.min.js bx-cdn.com/static/rti.min.js storage.googleapis.com/rtux-rtux-data-integration-rti/ *.prism.app-us1.com *.prismic.io *.trackjs.com *.gstatic.com *.livechatinc.com *.cdn.prismic.io *.google.com *.criteo.com *.pinimg.com *.bing.com *.adt313.net htm1.ch *.pinterest.com profity.ch *.profity.ch/clients/main.js *.getback.ch *.sovendus.com *.sovendus-connect.com *.googleapis.com storage.googleapis.com/*_rtux-data* *.wi-platform-cloud.com *.bx-cdn.com *.googletagmanager.com *.bx-cloud.com *.doubleclick.net test.saferpay.com www.saferpay.com saferpay.com www.xtento.com cdn.xtento.com *.googleadservices.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.clarity.ms *.klaviyo.com unpkg.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.getback.ch *.cloudflare.com *.googleapis.com storage.googleapis.com/*_rtux-data* *.tagmanager.google.com *.googletagmanager.com fonts.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src storage.googleapis.com/rtux-rtux-data-integration-rti/ *.googleapis.com storage.googleapis.com/*_rtux-data* 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src *.newrelic.com *.nr-data.net www.googleadservices.com *.google-analytics.com *.analytics.google.com www.googletagmanager.com https://maps.googleapis.com https://player.vimeo.com track.bx-cloud.com main.bx-cloud.com track-gw1.bx-cloud.com bx-cloud.com main.wi-platform-cloud.com r-st.bx-cloud.com track.bx-cloud.com/track/v2 storage.googleapis.com/rtux-rtux-data-integration-rti/ *.prism.app-us1.com *.prismic.io htm1.ch *.pinterest.com *.lehner-versand.ch *.criteo.com *.google.com *.getback.ch *.doubleclick.net *.wi-platform-cloud.com *.trackjs.com *.livechatinc.com *.sovendus.com *.googleapis.com storage.googleapis.com/*_rtux-data* *.bing.com test.saferpay.com www.saferpay.com saferpay.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.net *.klaviyo.com *.clarity.ms *.run.app 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src test.saferpay.com www.saferpay.com saferpay.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com *.googleapis.com https://www.gstatic.com https://fonts.googleapis.com https://fonts.gstatic.com applepay.cdn-apple.com https://cdnjs.cloudflare.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.payplug.com *.dalenys.com api-qa.payplug.com secure-qa.payplug.com https://*.google.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net magefan.com cm.magefan.com *.disqus.com *.googleapis.com https://*.gstatic.com https://*.afflelou.com https://p.sharinpix.com *.googlesyndication.com https://editor-assets.abtasty.com cdn.doofinder.com https://images.unsplash.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com https://flagcdn.com https://mafranchise.afflelou.com https://cms-mafranchise.afflelou.com https://mcstaging.afflelou.com https://secure-magenta.dalenys.com https://*.google.com https://*.googleapis.com https://*.googleusercontent.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://rum.hlx.page *.disqus.com *.googleapis.com https://*.gstatic.com https://eu1-config.doofinder.com https://*.googlesyndication.com https://halc.iadvize.com https://static.iadvize.com https://iadvize.com https://static.livechat.iadvize.com https://api.iadvize.com https://try.abtasty.com https://msr.afflelou.com cdn.doofinder.com https://maps.googleapis.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com afflelou.containers.piwik.pro https://vto-advanced-integration-api.fittingbox.com/ https://secure-magenta.dalenys.com applepay.cdn-apple.com api-qa.payplug.com cdn-qa.payplug.com cdn.payplug.com https://cdn.payplug.com https://cdn-qa.payplug.com https://*.google.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com https://try.abtasty.com https://cdn.fonts.net *.doofinder.com assets.braintreegateway.com https://secure-magenta.dalenys.com https://fonts.googleapis.com https://hcaptcha.com https://*.hcaptcha.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.googleapis.com https://cdn.plyr.io https://*.googlesyndication.com https://halc.iadvize.com https://api.iadvize.com https://collector.iadvize.com wss://*.iadvize.com https://*.abtasty.com https://fonts.googleapis.com https://fonts.gstatic.com https://cdn.fonts.net *.doofinder.com wss://*.doofinder.com https://maps.googleapis.com https://player.vimeo.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com afflelou.piwik.pro afflelou.containers.piwik.pro https://ipinfo.io https://*.google.com https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com https://int-bohds.afflelou.com https://int-bohds.afflelou.be https://int-bohds.afflelou.ch https://int-bohds.afflelou.ma https://int-bohds.afflelou.pt https://int-bohds.afflelou.es https://preprod-bohds.afflelou.com https://preprod-bohds.afflelou.be https://preprod-bohds.afflelou.ch https://preprod-bohds.afflelou.ma https://preprod-bohds.afflelou.pt https://preprod-bohds.afflelou.es https://bohds.afflelou.com https://bohds.afflelou.be https://bohds.afflelou.ch https://bohds.afflelou.ma https://bohds.afflelou.pt https://bohds.afflelou.es 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com static.klaviyo.com www.shopperapproved.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://img.youtube.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com tracking.avantlink.com dgjcoqnzn763b.cloudfront.net www.shopperapproved.com seal.trustguard.com tgscript.s3.amazonaws.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://developer.adobe.com https://magento.com https://cdn.avmws.com/ http://cdn.avmws.com/ https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ s7.addthis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com acsbapp.com *.google-analytics.com js-agent.newrelic.com googletagmanager.com *.hotjar.com ssl.avmws.com d395yjvh5spyzw.cloudfront.net edge.curalate.com www.google.com *.googleapis.com config.gorgias.chat contact.gorgias.help s.pinimg.com *.pinterest.com https://cdn.searchspring.net/intellisuggest/is.min.js www.shopperapproved.com shopperapproved.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com analytics.tiktok.com tgscript.s3.amazonaws.com https://app.zinrelo.com app.zinrelo.com https://cdn.zinrelo.com/js/all.js snapui.searchspring.io 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://static.klaviyo.com assets.braintreegateway.com www.gstatic.com www.shopperapproved.com use.typekit.net p.typekit.net tgscript.s3.amazonaws.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://developer.adobe.com https://cdn.avmws.com/ http://cdn.avmws.com/ https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ ekr.zdassets.com/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com cdn.acsbapp.com stats.g.doubleclick.net *.google-analytics.com googletagmanager.com *.hotjar.io *.hotjar.com wss://*.hotjar.com *.tiktokw.us *.googleapis.com config.gorgias.chat wss://us-east1-898b.gorgias.chat s.pinimg.com ct.pinterest.com *.pinterest.com https://beacon.searchspring.io/beacon shopperapproved.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com analytics.tiktok.com api.trustguard.com *.searchspring.io 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src assets.gorgias.chat 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 object-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; child-src *.certcapture.com https://aws-staging-aeroprecisionusa.smarterspecies.com https://aws-staging-2-aeroprecisionusa.smarterspecies.com/ https://www.aeroprecisionusa.com blob: assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; upgrade-insecure-requests ; frame-ancestors 'self' *.avantlink.com *.certcapture.com *.credova.com www.gstatic.com *.authorize.net assets.secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com *.publicsquare.com 'self'; form-action 'self' https://enews.aeroprecisionusa.com/ geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com https://plumrocket.com *.authorize.net assets.secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.sitevibes.com sitevibes.com 'self' 'unsafe-inline'; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://maxcdn.bootstrapcdn.com/font-awesome/4.5.0/css/ https://cdn.listrakbi.com https://mediacdn.espssl.com *.adobe.com *.certcapture.com https://maxcdn.bootstrapcdn.com fonts.googleapis.com *.fontawesome.com https://fonts.bunny.net unsafe-inline assets.braintreegateway.com *.sitevibes.com sitevibes.com 'self' 'unsafe-inline'; script-src 'self' 'unsafe-eval' 'unsafe-inline' https://cdn.avmws.com https://cdn.listrakbi.com https://s1.listrakbi.com https://m1.listrakbi.com https://at1.listrakbi.com https://www.google-analytics.com https://www.google.com https://maps.google.com https://maps.googleapis.com https://www.googletagmanager.com https://www.gstatic.com https://jstest.authorize.net https://*.addthis.com https://v1.addthisedge.com https://z.moatads.com https://ssl.avmws.com https://bat.bing.com/bat.js https://js.hs-scripts.com https://js-agent.newrelic.com https://bam.nr-data.net https://player.vimeo.com https://f.vimeocdn.com https://widget-prime.rafflecopter.com https://js.hs-banner.com/ https://v2.zopim.com https://js.hs-analytics.net https://static.zdassets.com https://widget-mediator.zopim.com/ https://bam-cell.nr-data.net/ https://cdn.quantummetric.com https://plugin.credova.com https://tags.clickagy.com https://tags.clickagy.com/ https://widget.gleamjs.io *.upsellit.com https://upsellit.com https://prod.upsellit.com/ https://bl.listrakbi.com https://cdnjs.cloudflare.com/ajax/libs/OwlCarousel2/2.3.4/owl.carousel.min.js https://cdnjs.cloudflare.com/ajax/libs/jquery.inputmask/3.3.1/jquery.inputmask.bundle.js assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://rum.hlx.page *.certcapture.com https://static.elfsight.com *.credova.com https://js.hs-banner.com https://bat.bing.com https://ekr.zdassets.com https://plugin.credova.com/plugin.min.js https://www.youtube.com *.gettopple.com *.aggle.net cdn.mouseflow.com *.googleapis.com *.gstatic.com *.kaptcha.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ https://developer.adobe.com https://assets.armanet.us https://magento.com https://cdn.avmws.com/ http://cdn.avmws.com/ *.authorize.net assets.secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com *.disqus.com *.avada.io js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.publicsquare.com *.basistheory.com *.sitevibes.com sitevibes.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; media-src https://static.zdassets.com/ *.adobe.com 'self' 'unsafe-inline'; img-src 'self' https://stats.g.doubleclick.net https://mediacdn.espssl.com https://www.xtento.com/media/images/ https://*.listrakbi.com https://www.google.com https://www.google.com.ua https://store.paradoxlabs.com https://cdn.klarna.com https://tracking.avantlink.com https://bat.bing.com https://bam.nr-data.net https://www.googletagmanager.com https://track.hubspot.com https://v2.zopim.com data: https://maps.gstatic.com https://maps.googleapis.com https://www.google-analytics.com https://pippio.com https://d2df4e9l5rljaz.cloudfront.net https://api.delivrabl.net https://aorta.clickagy.com https://idsync.rlcdn.com https://us-u.openx.net https://cm.g.doubleclick.net https://yotpo-editor-production.s3.amazonaws.com https://aa.agkn.com https://sync.crwdcntrl.net https://pixel-sync.sitescout.com https://d.agkn.com https://region1.google-analytics.com https://v2assets.zopim.io https://js.gleam.io https://upsellit.com https://prod.upsellit.com/ *.upsellit.com assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.certcapture.com https://files.elfsightcdn.com https://sca1.listrakbi.com https://img.youtube.com https://via.placeholder.com *.gettopple.com *.googleapis.com *.gstatic.com *.authorize.net assets.secure.checkout.visa.com sandbox.secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com magefan.com cm.magefan.com *.disqus.com https://firebasestorage.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.publicsquare.com *.sitevibes.com sitevibes.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; frame-src 'self' https://www.full30.com https://s7.addthis.com https://player.vimeo.com https://www.google.com https://widget-prime.rafflecopter.com https://ssl.kaptcha.com https://hemsync.clickagy.com https://gleam.io https://upsellit.com https://prod.upsellit.com/ *.upsellit.com fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.certcapture.com *.credova.com * https://tst.kaptcha.com www.google.com https://plumrocket.com *.authorize.net assets.secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com *.publicsquare.com *.basistheory.com *.sitevibes.com sitevibes.com www.xtento.com 'self' 'unsafe-inline'; font-src 'self' data: https://fonts.gstatic.com https://maxcdn.bootstrapcdn.com/font-awesome/ https://assets.iglobalstores.com/ https://v2.zopim.com/ https://yotpo-stool.s3.amazonaws.com https://maxcdn.bootstrapcdn.com https://993ecd1fa9.nxcli.io *.googleapis.com *.gstatic.com *.fontawesome.com https://fonts.bunny.net *.sitevibes.com sitevibes.com data: 'self' 'unsafe-inline'; connect-src 'self' https://api2.authorize.net/ https://js.authorize.net https://jstest.authorize.net https://apitest.authorize.net https://m.addthis.com https://bat.bing.com https://bam.nr-data.net/ https://bat.bing.com/ https://ekr.zdassets.com/ https://www.google-analytics.com https://stats.g.double.analytics.js https://assets.iglobalstores.com/ wss://widget-mediator.zopim.com/ https://*.listrak.com/ https://*.listrakbi.com/ https://stats.g.doubleclick.net/ https://bam-cell.nr-data.net/ https://oc.listrakbi.com/coupon https://enews.aeroprecisionusa.com/ https://aeroprecisionsupport.zendesk.com/ https://aeroprecision-app.quantummetric.com/ https://rl.quantummetric.com/ https://region1.google-analytics.com https://aorta.clickagy.com https://hemsync.clickagy.com https://maps.googleapis.com https://vimeo.com https://upsellit.com https://prod.upsellit.com/ *.upsellit.com https://cdn.listrakbi.com https://bl.listrakbi.com dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.certcapture.com https://core.service.elfsight.com *.credova.com https://api2.authorize.net wss://widget-mediator.zopim.com https://onsite-api.listrak.com https://product.listrakbi.com https://stats.g.doubleclick.net https://aeroprecision-app.quantummetric.com https://rl.quantummetric.com https://sandbox-lending-api.credova.com https://lending-api.credova.com *.gettopple.com oirt.aggle.net https://www.stagarms.com *.googleapis.com *.kaptcha.com https://srv.armanet.us https://assets.armanet.us https://developer.adobe.com https://cdn.avmws.com/ http://cdn.avmws.com/ *.authorize.net assets.secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.publicsquare.com *.basistheory.com *.launchdarkly.com *.browser-intake-datadoghq.com *.sitevibes.com sitevibes.com 'self' 'unsafe-inline'; default-src 'self' 'self' 'unsafe-inline' 'unsafe-eval'; worker-src 'self'; 2 img-src 'self' staccwexerius.blob.core.windows.net cdn.xerius.be consentcdn.cookiebot.com *.cookiebot.com data: *.google-analytics.com www.googletagmanager.com xerius-prd-911.azureedge.net media.xerius.be media.accdesk.be media.myfamily.be media.xerius-lei.eu *.google.com *.google.ad *.google.ae *.google.com.af *.google.com.ag *.google.al *.google.am *.google.co.ao *.google.com.ar *.google.as *.google.at *.google.com.au *.google.az *.google.ba *.google.com.bd *.google.be *.google.bf *.google.bg *.google.com.bh *.google.bi *.google.bj *.google.com.bn *.google.com.bo *.google.com.br *.google.bs *.google.bt *.google.co.bw *.google.by *.google.com.bz *.google.ca *.google.cd *.google.cf *.google.cg *.google.ch *.google.ci *.google.co.ck *.google.cl *.google.cm *.google.cn *.google.com.co *.google.co.cr *.google.com.cu *.google.cv *.google.com.cy *.google.cz *.google.de *.google.dj *.google.dk *.google.dm *.google.com.do *.google.dz *.google.com.ec *.google.ee *.google.com.eg *.google.es *.google.com.et *.google.fi *.google.com.fj *.google.fm *.google.fr *.google.ga *.google.ge *.google.gg *.google.com.gh *.google.com.gi *.google.gl *.google.gm *.google.gr *.google.com.gt *.google.gy *.google.com.hk *.google.hn *.google.hr *.google.ht *.google.hu *.google.co.id *.google.ie *.google.co.il *.google.im *.google.co.in *.google.iq *.google.is *.google.it *.google.je *.google.com.jm *.google.jo *.google.co.jp *.google.co.ke *.google.com.kh *.google.ki *.google.kg *.google.co.kr *.google.com.kw *.google.kz *.google.la *.google.com.lb *.google.li *.google.lk *.google.co.ls *.google.lt *.google.lu *.google.lv *.google.com.ly *.google.co.ma *.google.md *.google.me *.google.mg *.google.mk *.google.ml *.google.com.mm *.google.mn *.google.com.mt *.google.mu *.google.mv *.google.mw *.google.com.mx *.google.com.my *.google.co.mz *.google.com.na *.google.com.ng *.google.com.ni *.google.ne *.google.nl *.google.no *.google.com.np *.google.nr *.google.nu *.google.co.nz *.google.com.om *.google.com.pa *.google.com.pe *.google.com.pg *.google.com.ph *.google.com.pk *.google.pl *.google.pn *.google.com.pr *.google.ps *.google.pt *.google.com.py *.google.com.qa *.google.ro *.google.ru *.google.rw *.google.com.sa *.google.com.sb *.google.sc *.google.se *.google.com.sg *.google.sh *.google.si *.google.sk *.google.com.sl *.google.sn *.google.so *.google.sm *.google.sr *.google.st *.google.com.sv *.google.td *.google.tg *.google.co.th *.google.com.tj *.google.tl *.google.tm *.google.tn *.google.to *.google.com.tr *.google.tt *.google.com.tw *.google.co.tz *.google.com.ua *.google.co.ug *.google.co.uk *.google.com.uy *.google.co.uz *.google.com.vc *.google.co.ve *.google.co.vi *.google.com.vn *.google.vu *.google.ws *.google.rs *.google.co.za *.google.co.zm *.google.co.zw *.google.cat *.ads.linkedin.com *.linkedin.com connect.facebook.net www.facebook.com *.doubleclick.net *.tiktok.com dev.visualwebsiteoptimizer.com *.clarity.ms *.bing.com https://www.google-analytics.com https://www.googletagmanager.com; object-src 'none'; script-src 'self' 'unsafe-inline' 'unsafe-eval' app.varify.io media.xerius.be media.accdesk.be media.myfamily.be media.xerius-lei.eu cxppusa1formui01cdnsa01-endpoint.azureedge.net *.google.com *.google.ad *.google.ae *.google.com.af *.google.com.ag *.google.al *.google.am *.google.co.ao *.google.com.ar *.google.as *.google.at *.google.com.au *.google.az *.google.ba *.google.com.bd *.google.be *.google.bf *.google.bg *.google.com.bh *.google.bi *.google.bj *.google.com.bn *.google.com.bo *.google.com.br *.google.bs *.google.bt *.google.co.bw *.google.by *.google.com.bz *.google.ca *.google.cd *.google.cf *.google.cg *.google.ch *.google.ci *.google.co.ck *.google.cl *.google.cm *.google.cn *.google.com.co *.google.co.cr *.google.com.cu *.google.cv *.google.com.cy *.google.cz *.google.de *.google.dj *.google.dk *.google.dm *.google.com.do *.google.dz *.google.com.ec *.google.ee *.google.com.eg *.google.es *.google.com.et *.google.fi *.google.com.fj *.google.fm *.google.fr *.google.ga *.google.ge *.google.gg *.google.com.gh *.google.com.gi *.google.gl *.google.gm *.google.gr *.google.com.gt *.google.gy *.google.com.hk *.google.hn *.google.hr *.google.ht *.google.hu *.google.co.id *.google.ie *.google.co.il *.google.im *.google.co.in *.google.iq *.google.is *.google.it *.google.je *.google.com.jm *.google.jo *.google.co.jp *.google.co.ke *.google.com.kh *.google.ki *.google.kg *.google.co.kr *.google.com.kw *.google.kz *.google.la *.google.com.lb *.google.li *.google.lk *.google.co.ls *.google.lt *.google.lu *.google.lv *.google.com.ly *.google.co.ma *.google.md *.google.me *.google.mg *.google.mk *.google.ml *.google.com.mm *.google.mn *.google.com.mt *.google.mu *.google.mv *.google.mw *.google.com.mx *.google.com.my *.google.co.mz *.google.com.na *.google.com.ng *.google.com.ni *.google.ne *.google.nl *.google.no *.google.com.np *.google.nr *.google.nu *.google.co.nz *.google.com.om *.google.com.pa *.google.com.pe *.google.com.pg *.google.com.ph *.google.com.pk *.google.pl *.google.pn *.google.com.pr *.google.ps *.google.pt *.google.com.py *.google.com.qa *.google.ro *.google.ru *.google.rw *.google.com.sa *.google.com.sb *.google.sc *.google.se *.google.com.sg *.google.sh *.google.si *.google.sk *.google.com.sl *.google.sn *.google.so *.google.sm *.google.sr *.google.st *.google.com.sv *.google.td *.google.tg *.google.co.th *.google.com.tj *.google.tl *.google.tm *.google.tn *.google.to *.google.com.tr *.google.tt *.google.com.tw *.google.co.tz *.google.com.ua *.google.co.ug *.google.co.uk *.google.com.uy *.google.co.uz *.google.com.vc *.google.co.ve *.google.co.vi *.google.com.vn *.google.vu *.google.ws *.google.rs *.google.co.za *.google.co.zm *.google.co.zw *.google.cat *.googleadservices.com googleads.g.doubleclick.net pagead2.googlesyndication.com *.google-analytics.com *.doubleclick.net fonts.gstatic.com www.googleoptimize.com www.googletagmanager.com *.cookiebot.com consentcdn.cookiebot.com connect.facebook.net www.facebook.com *.ads.linkedin.com *.linkedin.com cdn.xerius.be staccwexerius.blob.core.windows.net xerius-prd-911.azureedge.net www.youtube.com data: xerius.piwik.pro www.gstatic.com script.hotjar.com static.hotjar.com js.monitor.azure.com js.cdn.applicationinsights.io js.cdn.monitor.azure.com *.tiktok.com amazon-adsystem.com *.amazon-adsystem.com paa-reporting-advertising.amazon *.paa-reporting-advertising.amazon trk.adbutter.net *.adnxs.com *.clarity.ms *.bing.com snap.licdn.com *.bannernow.com; worker-src 'none'; frame-ancestors 'self' auth.xerius.be 2 base-uri 'none' ; connect-src 'self' https://mc.yandex.ru/ https://mc.yandex.md/ https://mc.yandex.uz/ https://mc.yandex.com/ https://privacy-cs.mail.ru/ https://top-fwz1.mail.ru/ ; default-src 'self' ; font-src 'self' data: ; frame-ancestors 'none' ; img-src 'self' data: https://top-fwz1.mail.ru/ https://mc.yandex.ru/ https://mc.yandex.com/ ; report-to vkpay-csp-endpoint ; report-uri https://cspreport.mail.ru/vkpay?disposition=report ; script-src 'self' 'unsafe-inline' https://top-fwz1.mail.ru/ https://mc.yandex.ru/* https://privacy-cs.mail.ru/ ; style-src 'self' 'unsafe-inline' 2 default-src 'self' 'unsafe-eval' 'unsafe-inline' essentialed.com *.essentialed.com passged.com *.passged.com d2lpurk2qe2oc.cloudfront.net d3ebkza70oew6x.cloudfront.net dpg0n9q1lsnov.cloudfront.net d37nqy2yusfq54.cloudfront.net d2pfk5on3dtp5q.cloudfront.net js-agent.newrelic.com bam.nr-data.net *.typekit.net *.google.com *.google.ca *.google.com.mx *.google.co.uk *.google.de *.googletagmanager.com *.google-analytics.com *.googleapis.com *.doubleclick.net *.googlesyndication.com *.gstatic.com *.wistia.com *.wistia.net *.litix.io *.credly.com *.hubspot.com *.hs-banner.com *.hs-analytics.net *.hs-analytics.com *.hs-scripts.com *.hsforms.com *.hsforms.net *.hscollectedforms.net *.plyr.io *.crazyegg.com *.hotjar.com *.hotjar.io analytics.tiktok.com *.bing.com hiset.org *.clarity.ms *.jquery.com *.fontawesome.com *.cloudflare.com *.bootstrapcdn.com *.paypal.com *.paypalobjects.com js.stripe.com *.facebook.com *.facebook.net widget.trustpilot.com unpkg.com data: ws: wss: about: blob:; frame-ancestors 'self' essentialed.com *.essentialed.com passged.com *.passged.com 2 font-src fonts.gstatic.com *.klevu.com *.ksearchnet.com *.fontawesome.com *.fonts.googleapis.com *.gstatic.com data: *.cloudflare.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com *.facebook.net 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net https://www.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.facebook.com *.facebook.net *.google.com *.addthis.com *.pinterest.com www.youtube.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com *.klevu.com *.ksearchnet.com magefan.com cm.magefan.com *.facebook.com *.facebook.net https://www.magezon.com ozow-live-cdn.s3.eu-west-1.amazonaws.com *.cloudflare.com https://cdn.klarna.com https://s.ytimg.com *.widgets.magentocommerce.com *.fpdbs.paypal.com *.t.paypal.com *.paypal.com *.fpdbs.sandbox.paypal.com *.googleapis.com *.gstatic.com *.addthis.com *.pinterest.com *.cdninstagram.com *.adobedtm.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ cdn.ampproject.org raw.githubusercontent.com chimpstatic.com downloads.mailchimp.com *.list-manage.com https://polyfill-fastly.io https://browser.sentry-cdn.com js.klevu.com *.ksearchnet.com s7.addthis.com *.facebook.com *.facebook.net *.avada.io *.google.com/ *.googleapis.com *.addthis.com *.moatads.com *.addthisedge.com *.pinterest.com www.youtube.com player.vimeo.com https://js.klevu.com https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com downloads.mailchimp.com *.klevu.com *.ksearchnet.com *.fontawesome.com *.googleapis.com https://js.klevu.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.amazonaws.com *.googleapis.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com cdn.ampproject.org https://*.ingest.sentry.io *.klevu.com *.ksearchnet.com ekr.zdassets.com/ *.facebook.com *.facebook.net https://get.geojs.io *.avada.io *.cloudflare.com *.paypal.com *.googleapis.com *.addthis.com *.cardinalcommerce.com https://graph.instagram.com cdn.plyr.io noembed.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline' 'unsafe-eval' 'strict-dynamic'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 font-src maxcdn.bootstrapcdn.com *.googleapis.com *.gstatic.com lancerto-proxy.eu-de.mybluemix.net actionbot-proxy-lancerto.12lsncf5rsle.eu-de.codeengine.appdomain.cloud https://geowidget.easypack24.net data: https://cdn.thulium.com/ script.hotjar.com widget.fitanalytics.com/ fontawesome.com *.fontawesome.com widget.fitanalytics.com static.lancerto.com data: 'self' 'unsafe-inline'; form-action www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ consentcdn.cookiebot.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.instagram.com pay.google.com play.google.com testpay.autopay.eu pay.autopay.eu testcards.autopay.eu cards.autopay.eu secure.payu.com merch-prod.snd.payu.com smartforms.ekomi.com *.ekomiapps.de https://geowidget-app.inpost.pl/ https://pudofinder.dpd.com.pl/ *.google.com *.fls.doubleclick.net creativecdn.com gum.criteo.com *.hotjar.com facebook.com start.paypo.pl https://tbs.tradedoubler.com https://imgstatic.eu *.tradedoubler.com *.imgstatic.eu static.criteo.net 'self' fledge.eu.criteo.com td.doubleclick.net *.creativecdn.com ct.pinterest.com ms.lancerto.com js-agent.newrelic.com *.googletagmanager.com csr.onet.pl ms.prochnik.pl 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'unsafe-inline' data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io imgsct.cookiebot.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cdninstagram.com platnosci.bm.pl platnosci-accept.bm.pl www.gstatic.com testimages.autopay.eu images.autopay.eu *.inpost.pl static.payu.com *.gstatic.com *.googleapis.com *.ggpht lancerto-proxy.eu-de.mybluemix.net actionbot-proxy-lancerto.12lsncf5rsle.eu-de.codeengine.appdomain.cloud https://lancerto.com https://geowidget.easypack24.net https://osm.inpost.pl *.revhunter.tech assets.swarmcdn.com analytics.tiktok.com https://maps.googleapis.com/ https://maps.gstatic.com/ https://developers.google.com *.g.doubleclick.net pixel.wp.pl *.google.com facebook.com *.google-analytics.com www.google.pl google.pl script.hotjar.com data: smart-widget-assets.ekomiapps.de tbl.tradedoubler.com *.stickyadstv.com *.bing.com *.adform.net *.advertising.com ade.clmbtech.com *.criteo.com *.adnxs.com sync.outbrain.com *.analytics.yahoo.com *.yahoo.com *.tribalfusion.com sw-assets.ekomiapps.de *.taboola.com *.3lift.com *.rtb-csync.smartadserver.com *.casalemedia.com *.pixel.rubiconproject.com *.simage2.pubmatic.com *.criteo-sync.teads.tv *.360yield.com *.pubmatic.com *.bidswitch.net criteo-sync.teads.tv *.adscale.de *.omnitagjs.com *.smartadserver.com *.ivitrack.com *.ad.smaato.net *.sharethrough.com *.ssp.rambler.ru *.fls.doubleclick.net *.atdmt.com *.rubiconproject.com *.yieldlab.net *.e-planning.net *.ads.linkedin.com sync-tm.everesttech.net s-cs.send.microad.jp contextual.media.net us-u.openx.net cm.mgid.com pixel.tapad.com ad.as.amanad.adtdp.com an.yandex.ru trends.revcontent.com cw.addthis.com crb.kargo.com i.liadm.com jadserve.postrelease.com sync.aralego.com ad.mail.ru sync-criteo.ads.yieldmo.com a.twiago.com idsync.rlcdn.com criteo-partners.tremorhub.com d.turn.com https://tbs.tradedoubler.com https://imgstatic.eu *.tradedoubler.com *.imgstatic.eu googleads4.g.doubleclick.net *.emxdgt.com *.googletagmanager.com static.lancerto.com htlfkw.lancerto.com s.thebrighttag.com beacon.krxd.net id5-sync.com exchange.mediavine.com https://csr.onet.pl https://upload.snrcdn.net *.clarity.ms dmp.adform.net ad.doubleclick.net ekomi-srr.s3.eu-central-1.amazonaws.com *.googlesyndication.com hb.yahoo.net *.salestube.pl dot.wp.pl mapa.orlenpaczka.pl tile.openstreetmap.org lantern.roeye.com *.analytics.google.com *.google.pl region1.analytics.google.com media.prochnik.pl media.lancerto.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ consent.cookiebot.com consentcdn.cookiebot.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.instagram.com testcards.autopay.eu cards.autopay.eu pay.google.com *.google-analytics.com *.googletagmanager.com *.inpost.pl *.snrbox.com secure.payu.com secure.snd.payu.com *.googleapis.com *.gstatic.com lancerto-proxy.eu-de.mybluemix.net actionbot-proxy-lancerto.12lsncf5rsle.eu-de.codeengine.appdomain.cloud smartforms.ekomi.com *.ekomiapps.de https://geowidget.easypack24.net https://geowidget.inpost.pl https://bat.bing.com/ https://www.clarity.ms/ assets.swarmcdn.com web.snrbox.com https://cdn.thulium.com/ analytics.tiktok.com https://maps.googleapis.com/ *.google.com sw-assets.ekomiapps.de smart-widget-assets.ekomiapps.de *.googleadservices.com px.leadexpert.pl static.lamoda.pl *.hotjar.com pixel.wp.pl wrap.tradedoubler.com static.criteo.net sslwidget.criteo.com widget.fitanalytics.com metrics.fitanalytics.com metrics-nl.fitanalytics.com cdn.wootric.com swrap.tradedoubler.com ocdn.eu js-agent.newrelic.com bam-cell.nr-data.net *.platform.hicloud.com snap.licdn.com www.snrcdn.net unpkg.com *.doubleclick.net googletagservices.com *.googlesyndication.com www.googletagservices.com https://tbs.tradedoubler.com *.tradedoubler.com https://imgstatic.eu *.imgstatic.eu maps.googleapis.com 'unsafe-inline' https://tagmanager.google.com/ https://www.googletagmanager.com/ https://cdnjs.cloudflare.com https://cdn.juo.io https://sgqcvfjvr.onet.pl https://artemis-cdn.ocdn.eu https://player.vimeo.com https://lib.onet.pl dc.cux.io js.go2sdk.com *.creativecdn.com s.pinimg.com ct.pinterest.com cdn.jsdelivr.net ms.lancerto.com mapa.orlenpaczka.pl stapecdn.com ms.prochnik.pl www.dwin1.com *.bam.eu01.nr-data.net bam.eu01.nr-data.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com testpay.autopay.eu pay.autopay.eu testcards.autopay.eu cards.autopay.eu *.googleapis.com *.snrcdn.net maxcdn.bootstrapcdn.com *.gstatic.com lancerto-proxy.eu-de.mybluemix.net actionbot-proxy-lancerto.12lsncf5rsle.eu-de.codeengine.appdomain.cloud https://geowidget.easypack24.net https://geowidget.inpost.pl assets.swarmcdn.com sw-assets.ekomiapps.de widget.fitanalytics.com customizations.fitanalytics.com www.snrcdn.net 'self' 'unsafe-inline'; object-src 'self' 'self' 'unsafe-inline'; media-src *.adobe.com *.cdninstagram.com assets.swarmcdn.com swarmify: blob: video-node.swarmcdn.com https://cdn.thulium.com/ chat-widget.thulium.com static.lancerto.com https://static.lancerto.com media.lancerto.com media.prochnik.pl 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com consentcdn.cookiebot.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.google-analytics.com *.snrbox.com secure.payu.com merch-prod.snd.payu.com lancerto-proxy.eu-de.mybluemix.net actionbot-proxy-lancerto.12lsncf5rsle.eu-de.codeengine.appdomain.cloud smartforms.ekomi.com *.ekomiapps.de https://geowidget.easypack24.net https://api-pl-points.easypack24.net https://osm.inpost.pl https://bat.bing.com/ *.clarity.ms video-node.swarmcdn.com wss://hornets.swarmcdn.com *.swarmcdn.com https://cdn.thulium.com/ analytics.tiktok.com https://maps.googleapis.com/ *.g.doubleclick.net wss://v18dxapjmd.execute-api.eu-west-1.amazonaws.com *.google.com smart-widget-assets.ekomiapps.de *.hotjar.com *.facebook.com clk.leadexpert.pl wss://ws17.hotjar.com data: eligibility.wootric.com bam-cell.nr-data.net web.snrbox.com widget.fitanalytics.com https://in.juo.io https://csr.onet.pl wss://n-541921153-0-27272500-1569843303-5d91e8674295d.track.cux.io events.ocdn.eu bat.bing.com google.com/pay *.analytics.google.com pixel.wp.pl measurement-api.criteo.com pagead2.googlesyndication.com *.creativecdn.com ct.pinterest.com ms.lancerto.com js-agent.newrelic.com ms.prochnik.pl *.google.pl *.bam.eu01.nr-data.net bam.eu01.nr-data.net 'self' 'unsafe-inline'; child-src https://tbs.tradedoubler.com https://imgstatic.eu *.tradedoubler.com *.imgstatic.eu bam.eu01.nr-data.net http: https: blob: 'self' 'unsafe-inline'; default-src 'self' *.bam.eu01.nr-data.net bam.eu01.nr-data.net media.lancerto.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri bam.eu01.nr-data.net 'self' 'unsafe-inline'; 2 default-src 'self'; connect-src 'self' https://api.mixpanel.com https://api-js.mixpanel.com https://api-eu.mixpanel.com https://www.google-analytics.com https://www.googletagmanager.com; frame-src 'self' https://www.youtube.com https://tagheuer-tcs-london.vercel.app https://vimeo.com/; img-src *; media-src *; object-src 'none'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://api.uk.exponea.com https://www.googletagmanager.com https://www.google-analytics.com https://www.google.com https://cookie-cdn.cookiepro.com https://cdn.mxpnl.com https://cdn-dev.mxpnl.com https://mixpanel.com https://*.mixpanel.com https://cdnjs.cloudflare.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://cdnjs.cloudflare.com; webrtc 'block'; worker-src 'self' blob: 2 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com maxcdn.bootstrapcdn.com *.klevu.com *.ksearchnet.com *.klaviyo.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors https://cdn.loadbee.com/ https://petertysonelectricals.co.uk 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * js.mollie.com https://www.googletagmanager.com/ *.addthis.com *.googleapis.com https://service.loadbee.com/ http://www.paypal.com http://www.sandbox.paypal.com *.trustpilot.com petertysonelectricals.co.uk 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://images.unsplash.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.payments-amazon.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com https://www.mollie.com *.facebook.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ magefan.com cm.magefan.com *.disqus.com *.finance-calculator.co.uk *.dekopay.com 'self' data: https://img.youtube.com maps.gstatic.com *.bing.com *.opentracker.net *.clarity.ms *.adtrafficquality.google *.flix360.com *.google.co.uk *.sweetanalytics.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://maps.googleapis.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de widget.freshworks.com m2epro.freshdesk.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com js.mollie.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ *.disqus.com *.addthis.com https://z.moatads.com https://v1.addthisedge.com https://cdn.jsdelivr.net *.finance-calculator.co.uk *.dekopay.com *.googleapis.com https://cdn.loadbee.com/js/loadbee_integration.js *.trustpilot.com *.smartsuppchat.com *.facebook.net *.hotjar.com *.bing.com *.clickguardian.app *.opentracker.net *.googlesyndication.com *.cloudfront.net *.cloudflare.com *.smartsuppcdn.com *.dwin1.com *.pinimg.com *.kk-resources.com *.clarity.ms *.pinterest.com *.adtrafficquality.google *.flixfacts.com *.flixcar.com *.sweetanalytics.com https://js.klevu.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com widget.freshworks.com m2epro.freshdesk.com assets.braintreegateway.com maxcdn.bootstrapcdn.com https://static.klaviyo.com *.klevu.com *.ksearchnet.com https://cdn.jsdelivr.net *.trustpilot.com *.smartsuppcdn.com *.klaviyo.com *.finance-calculator.co.uk *.flixcar.com https://js.klevu.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://maps.googleapis.com https://player.vimeo.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de widget.freshworks.com m2epro.freshdesk.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com api.addressy.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ *.finance-calculator.co.uk *.dekopay.com *.googleapis.com https://availability.loadbee.com *.smartsuppchat.com *.hotjar.com *.hotjar.io *.smartsuppcdn.com *.amazonaws.com *.clickguardian.app *.adtrafficquality.google *.smartsupp.com *.googlesyndication.com *.google-analytics.com *.pinterest.com *.clarity.ms wss: *.flixcar.com *.gstatic.com *.google.co.uk *.sweetanalytics.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 default-src 'self'; child-src 'self' blob:; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://www.googleadservices.com https://*.storage.googleapis.com https://*.vimeo.com https://vimeo.com https://octus.chilipiper.com https://app.pendo.io https://cookie-cdn.cookiepro.com https://*.cookiepro.com https://cdn.cookielaw.org https://ajax.googleapis.com https://widget.surveymonkey.com https://go.octus.com https://go.reorg-research.com https://*.pardot.com https://cdn.pendo.io https://*.pendo.io https://*.doubleclick.net https://js.chilipiper.com https://cdn.us.heap-api.com https://cdn.jsdelivr.net https://www.googletagmanager.com https://www.google-analytics.com https://*.google-analytics.com https://*.analytics.google.com https://www.google.com https://rs.fullstory.com https://edge.fullstory.com https://px.ads.linkedin.com https://analytics.google.com https://snap.licdn.com https://stats.g.doubleclick.net https://dev.visualwebsiteoptimizer.com; style-src 'self' 'unsafe-inline' https:; img-src 'self' data: https:; font-src 'self' data: https:; connect-src 'self' https://*.algolia.net https://*.algolia.io https://*.algolianet.com https://www.googleadservices.com https://*.doubleclick.net https://app.pendo.io https://*.pendo.io https://geolocation.onetrust.com https://*.cookiepro.com https://cdn.cookielaw.org https://go.octus.com https://c.us.heap-api.com https://www.google-analytics.com https://*.google-analytics.com https://*.analytics.google.com https://www.google.com https://rs.fullstory.com https://edge.fullstory.com https://px.ads.linkedin.com https://analytics.google.com https://snap.licdn.com https://*.doubleclick.net https://stats.g.doubleclick.net https://dev.visualwebsiteoptimizer.com; frame-src 'self' https://app.vwo.com https://vimeo.com https://octus.chilipiper.com https://player.vimeo.com https://www.googletagmanager.com https://www.surveymonkey.com https://td.doubleclick.net https://go.octus.com https://reorg-research.chilipiper.com https://www.podbean.com https://*.podbean.com https://res.cloudinary.com https://*.cloudinary.com; worker-src 'self' blob:; report-uri https://octus.com/wp-json/csp/v1/report/; report-to csp-endpoint; 2 script-src-elem *.crazyegg.com; style-src-elem *.stackadapt.com; font-src fonts.gstatic.com use.typekit.net www.paypalobjects.com *.typekit.net *.gstatic.com *.googleapis.com *.alothemes.com *.magepow.com maxcdn.bootstrapcdn.com https://d1cwup7r903a1d.cloudfront.net *.mypurecloud.com *.cloudflare.com *.adnxs.com *.thecpapshop.com *.paypalobjects.com *.doubleclick.net *.adacado.com *.authorize.net *.oxygenconcentratorsupplies.com *.adapthealthmarketplace.com *.espssl.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.authorize.net *.facebook.com *.mypurecloud.com *.cloudflare.com *.adnxs.com *.thecpapshop.com *.paypalobjects.com *.doubleclick.net *.adacado.com *.oxygenconcentratorsupplies.com *.adapthealthmarketplace.com 'self' 'unsafe-inline'; frame-ancestors *.authorize.net 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.demdex.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.getbread.com *.breadpayments.com *.rbcpayplan.com *.authorize.net *.visualwebsiteoptimizer.com https://cryptnsend.com *.cryptnsend.net *.bbb.org *.lpsnmedia.net *.salecycle.com *.facebook.com *.adsrvr.org *.mypurecloud.com *.cloudflare.com *.adnxs.com *.thecpapshop.com *.paypalobjects.com *.doubleclick.net *.adacado.com *.oxygenconcentratorsupplies.com *.adapthealthmarketplace.com *.webeyez.com storage.googleapis.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com widgets.automizely.com widgets.automizely.io *.googleapis.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.payments-amazon.com *.getbread.com *.breadpayments.com *.rbcpayplan.com https://maps.gstatic.com https://maps.googleapis.com www.google-analytics.com *.ftcdn.net *.behance.net https://images.unsplash.com blob: *.alothemes.com *.magepow.com *.google.com *.googleadservices.com *.googletagmanager.com *.reddit.com *.visualwebsiteoptimizer.com *.listrakbi.com *.bing.com *.facebook.com *.lpsnmedia.net *.amazonaws.com *.routeapp.io *.mypurecloud.com *.adnxs.com *.cloudflare.com *.thecpapshop.com *.paypalobjects.com *.doubleclick.net *.adacado.com *.authorize.net *.oxygenconcentratorsupplies.com *.adapthealthmarketplace.com *.adsrvr.org data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net assets.adobedtm.com *.adobe.io *.commerce-payment-services.com *.magento-ds.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.magento-datasolutions.com ajax.googleapis.com https//fonts.googleapis.com widgets.automizely.com widgets.automizely.io *.googleapis.com *.gstatic.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.getbread.com *.breadpayments.com *.rbcpayplan.com https://maps.googleapis.com/maps/api/ https://places.googleapis.com/ https://examplecdn.com https://maps.googleapis.com https://maps.googleapis.com/maps-api-v3/ https://places.googleapis.com *.alothemes.com *.magepow.com connect.facebook.net *.googletagmanager.com *.googleadservices.com *.google-analytics.com *.authorize.net cdn.routeapp.io https://api.lab.amplitude.com https://flag.lab.amplitude.com https://protect-quote-q.route.com protection-widget.route.com protect-lightning-bolt-widget.route.com d3od5si8vgcekb.cloudfront.net ddbmicszvqxcg.cloudfront.net https://unpkg.com wobs.route.com *.stackadapt.com/events.js *.crazyegg.com *.redditstatic.com *.listrak.com *.listrakbi.com *.liveperson.net *.lpsnmedia.net *.tiqcdn.com *.bing.com *.cybba.solutions *.cloudfront.net *.adsrvr.org *.facebook.net *.pepperjam.com *.rtb123.com *.routeapp.io *.route.com *.mypurecloud.com https://sentry.io *.cloudflare.com *.adnxs.com *.paypalobjects.com *.doubleclick.net *.adacado.com *.thecpapshop.com *.oxygenconcentratorsupplies.com *.adapthealthmarketplace.com *.webeyez.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.magento-datasolutions.com *.magento-ds.com widgets.automizely.com widgets.automizely.io *.alothemes.com *.magepow.com maxcdn.bootstrapcdn.com https//fonts.googleapis.com https://d1cwup7r903a1d.cloudfront.net *.listrak.com *.listrakbi.com *.googleapis.com *.mypurecloud.com *.cloudflare.com *.adnxs.com *.thecpapshop.com *.paypalobjects.com *.doubleclick.net *.adacado.com *.authorize.net *.oxygenconcentratorsupplies.com *.adapthealthmarketplace.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.magento-datasolutions.com *.magento-ds.com api.automizely.com api.automizely.io *.googleapis.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.getbread.com *.breadpayments.com *.rbcpayplan.com https://maps.googleapis.com https://places.googleapis.com *.alothemes.com *.magepow.com *.googletagmanager.com stats.g.doubleclick.net *.authorize.net api.route.com https://api.lab.amplitude.com https://flag.lab.amplitude.com https://protect-quote-q.route.com protection-widget.route.com d3od5si8vgcekb.cloudfront.net protect-lightning-bolt-widget.route.com ddbmicszvqxcg.cloudfront.net https://unpkg.com wobs.route.com *.stackadapt.com *.redditstatic.com *.reddit.com *.crazyegg.com *.visualwebsiteoptimizer.com *.listrak.com *.listrakbi.com *.sandbox.paypal.com *.googleadservices.com *.doubleclick.net *.salescycle.com wss://ws.salescycle.com *.salecycle.com wss://ws.salecycle.com *.facebook.com https://www.facebook.com *.route.com *.adnxs.com *.mypurecloud.com wss://webmessaging.mypurecloud.com *.cloudflare.com *.thecpapshop.com *.paypalobjects.com *.adacado.com *.oxygenconcentratorsupplies.com *.adapthealthmarketplace.com *.pro.ip-api.com *.ip-api.com *.amazonaws.com *.breadgateway.net *.bing.com *.webeyez.com storage.googleapis.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://smartsolutions.report-uri.com/r/d/csp/reportOnly; report-to report-endpoint; 2 default-src 'self' https://langara.lndo.site https://seckit-langara.pantheonsite.io https://dev-langara.pantheonsite.io https://test-langara.pantheonsite.io https://live-langara.pantheonsite.io https://langara.ca; script-src 'self' 'unsafe-inline' https://sites.langara.ca https://iweb.langara.ca https://www.googletagmanager.com https://www.google-analytics.com https://js-agent.newrelic.com https://code.tidio.co https://langara.lndo.site https://seckit-langarscript-src-elema.pantheonsite.io https://dev-langara.pantheonsite.io https://test-langara.pantheonsite.io https://live-langara.pantheonsite.io https://cdn.jsdelivr.net https://langaratest.h5p.com https://langara.h5p.com https://public.tableau.com https://langara.libwizard.com https://api3-ca.libcal.com https://lgapi-ca.libapps.com https://unpkg.com https://cdnjs.cloudflare.com https://googleads.g.doubleclick.net https://www.googleadservices.com https://connect.facebook.net https://script.crazyegg.com https://analytics.tiktok.com https://www.redditstatic.com https://tags.srv.stackadapt.com https://sc-static.net https://tr.snapchat.com https://snap.licdn.com https://script.crazyegg.com blob: https://bbox.blackbaudhosting.com https://payments.blackbaud.com https://www.google.com https://www.gstatic.com https://widget.lightcastcc.com; object-src 'self' fonts.googleapis.com fonts.gstatic.com *.googletagmanager.com *.google-analytics.com https://langara.lndo.site https://seckit-langara.pantheonsite.io https://dev-langara.pantheonsite.io https://test-langara.pantheonsite.io https://live-langara.pantheonsite.io; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://use.typekit.net https://p.typekit.net https://langara.lndo.site https://seckit-langara.pantheonsite.io https://dev-langara.pantheonsite.io https://test-langara.pantheonsite.io https://live-langara.pantheonsite.io https://lgapi-ca.libapps.com https://unpkg.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://tags.srv.stackadapt.com https://bbox.blackbaudhosting.com; img-src 'self' data: https://cdnjs.cloudflare.com https://www.google-analytics.com https://langara.lndo.site https://seckit-langara.pantheonsite.io https://dev-langara.pantheonsite.io https://test-langara.pantheonsite.io https://live-langara.pantheonsite.io https://public.tableau.com https://www.googleadservices.com https://www.google.ca https://www.google.com https://googleads.g.doubleclick.net https://www.facebook.com https://tr.snapchat.com https://px.ads.linkedin.com https://alb.reddit.com https://www.googletagmanager.com https://www.googletagmanager.so https://www.googletagmanager.mx https://tracking.crazyegg.com https://*.googletagmanager.com https://www.google.com.tw https://px4.ads.linkedin.com https://bbox.blackbaudhosting.com https://www.linkedin.com https://www.google.co.jp https://connect.facebook.net https://www.google.fr https://www.google.com.br; media-src 'self' https://code.tidio.co https://langara.lndo.site https://seckit-langara.pantheonsite.io https://dev-langara.pantheonsite.io https://test-langara.pantheonsite.io https://live-langara.pantheonsite.io; frame-src 'self' https://sites.langara.ca https://iweb.langara.ca https://www.youtube.com https://code.tidio.co https://seckit-langara.pantheonsite.io https://dev-langara.pantheonsite.io https://test-langara.pantheonsite.io https://live-langara.pantheonsite.io https://langaratest.h5p.com https://langara.h5p.com https://public.tableau.com https://forms.office.com https://login.microsoftonline.com https://langara.libwizard.com https://outlook.office365.com https://www.googletagmanager.com https://tr.snapchat.com https://alb.reddit.com https://bbox.blackbaudhosting.com https://bbox.blackbaudhosting.com https://www.google.com https://www.facebook.com https://widget.lightcastcc.com; frame-ancestors 'self' https://sites.langara.ca https://iweb.langara.ca https://seckit-langara.pantheonsite.io https://dev-langara.pantheonsite.io https://test-langara.pantheonsite.io https://live-langara.pantheonsite.io https://www.google.com/; font-src 'self' data: https://fonts.gstatic.com https://use.typekit.net https://code.tidio.co https://langara.lndo.site https://seckit-langara.pantheonsite.io https://dev-langara.pantheonsite.io https://test-langara.pantheonsite.io https://live-langara.pantheonsite.io https://lgapi-ca.libapps.com; connect-src 'self' https://www.google.com https://www.google-analytics.com https://bam.nr-data.net https://code.tidio.co wss://socket.tidio.co https://langara.lndo.site https://seckit-langara.pantheonsite.io https://dev-langara.pantheonsite.io https://test-langara.pantheonsite.io https://live-langara.pantheonsite.io https://langara.libcal.com https://lgapi-ca.libapps.com https://unpkg.com https://analytics.google.com https://stats.g.doubleclick.net https://analytics.tiktok.com https://tr.snapchat.com https://tags.srv.stackadapt.com https://www.redditstatic.com https://analytics-ipv6.tiktokw.us https://www.google.ca https://pixel-config.reddit.com https://tr6.snapchat.com https://www.googleadservices.com https://script.crazyegg.com https://px.ads.linkedin.com https://assets-tracking.crazyegg.com https://pagestates-tracking.crazyegg.com https://*.crazyegg.com https://www.facebook.com https://www.googletagmanager.com https://region1.google-analytics.com https://www.google.fr https://www.google.com.br; report-uri /report-csp-violation 2 default-src https: wss:; script-src https: 'unsafe-eval' 'unsafe-inline'; style-src https: 'unsafe-inline'; img-src https: data:; font-src https: data:; report-uri /csp-report 2 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com maxcdn.bootstrapcdn.com 'self' data: *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.klaviyo.com *.cdnfonts.com *.yotpo.com *.googleapis.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com *.certcapture.com checkout.sezzle.com sandbox.checkout.sezzle.com tracking.sezzle.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.facebook.com *.amazon-adsystem.com *.doubleclick.net *.sitescout.com *.adsrvr.org *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com https://images.unsplash.com *.certcapture.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ magefan.com cm.magefan.com *.disqus.com *.googleapis.com media.sezzle.com *.hsforms.net *.hsforms.com 'self' data: *.gstatic.com/mapfiles/api-3/images/* *.s3.amazonaws.com *.net/company/SPJKye/images/* *.google.co.in *.cloudfront.net *.facebook.com *.amazonaws.com https://maps.googleapis.com *.sitescout.com trkn.us *.zdassets.com *.zendesk.com *.zdusercontent.com *.nextdoor.com *.redditstatic.com *.reddit.com *.amazon-adsystem.com *.googletagmanager.com *.google-analytics.com ssl.gstatic.com www.gstatic.com *.yotpo.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://rum.hlx.page *.certcapture.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.disqus.com https://cdn.jsdelivr.net *.googleapis.com checkout-sdk.sezzle.com sandbox.checkout-sdk.sezzle.com widget.sezzle.com *.hsforms.net *.hsforms.com *.gstatic.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com *.cloudfront.net/js/grin-sdk.js *.googleapis.com/maps/* *.googleapis.com/maps-api-v3/api/js *.zdassets.com *.mouseflow.com *.jquery.com *.direct/feathersnap.js *.facebook.net/en_US/fbevents.js *.facebook.net *.facebook.com *.googletagmanager.com *.amazon-adsystem.com *.googleadservices.com *.google-analytics.com *.klaviyo.com q.stripe.com *.basis.net *.smooch.io *.adsrvr.org *.redditstatic.com *.nextdoor.com safevisit.online tagmanager.google.com *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.certcapture.com https://static.klaviyo.com https://cdn.jsdelivr.net *.gstatic.com *.googleapis.com maxcdn.bootstrapcdn.com fonts.cdnfonts.com *.stripe.network *.stripecdn.com *.amazon.com *.cdnfonts.com *.typekit.net *.sezzle.com *.net/ffj4apz.css *.klaviyo.com tagmanager.google.com fonts.google.com *.yotpo.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.certcapture.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ maps.googleapis.com gateway.sezzle.com sandbox.gateway.sezzle.com media.sezzle.com widget.sezzle.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.cloudflare.com/cdn-cgi/trace *.googleapis.com/maps/api/* *.grin.co/fingerprint/* *.sezzle.com *.grin.co *.g.doubleclick.net https://ipapi.co *.zendesk.com *.googleapis.com *.ipdata.co *.googletagmanager.com *.mouseflow.com *.amazon-adsystem.com *.paa-reporting-advertising.amazon *.webpagefx.org *.facebook.com *.zdassets.com *.smooch.io wss://api.smooch.io *.redditstatic.com *.reddit.com *.adsrvr.org *.analytics.google.com *.yotpo.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 default-src 'self' *.zdassets.com *.zopim.com *.zendesk.com wss://*.zendesk.com wss://*.zopim.com ; script-src 'self' 'unsafe-inline' 'unsafe-eval' api-accent.bloomreach.co *.qantasloyalty.com api.smooch.io applepay.cdn-apple.com *.googleadservices.com assets.braintreegateway.com/web *.bazaarvoice.com *.doubleclick.net storage.googleapis.com/workbox-cdn www.google.com/pagead *.google.com/recaptcha/ www.gstatic.com/recaptcha/ cfjump.platypusshoes.com.au cfjump.platypusshoes.co.nz *.fullstory.com www.googletagmanager.com analytics.tiktok.com cdn.unidays.world *.truefitcorp.com www.paypalobjects.com/api/checkout.min.js *.klaviyo.com t.cfjump.com *.zdassets.com connect.facebook.net maps.googleapis.com js-agent.newrelic.com js.datadome.co ct.captcha-delivery.com *.adobedtm.com *.afterpay.com *.demdex.net *.forter.com dlthst9q2beh8.cloudfront.net d2nww8zpyj5pk0.cloudfront.net *.google-analytics.com *.paypal.com afterpay.com foursixty.com *.useinsider.com *.roymorgan.com s.pinimg.com lantern.roeyecdn.com ct.pinterest.com js-sandbox.squarecdn.com js.squarecdn.com ; style-src 'self' 'unsafe-inline' display.ugc.bazaarvoice.com maxcdn.bootstrapcdn.com/font-awesome *.typekit.net fonts.googleapis.com assets.braintreegateway.com *.adobetm.com foursixty.com assets.api.useinsider.com *.adobemc.com ; img-src data: 'self' api-accent.bloomreach.co *.zendesk.com dpm.demdex.net www.googleadservices.com/ccm www.magentocommerce.com/products/media *.platypusshoes.co.nz *.platypusshoes.com.au googleads.g.doubleclick.net ad.doubleclick.net www.google.com/ccm www.paypalobjects.com www.google.com www.google.com.au www.google.co.nz www.google.com.vn maps.gstatic.com/mapfiles scontent.cdninstagram.com *.afterpay.com *.accentgra.com www.googletagmanager.com www.facebook.com *.bazaarvoice.com t.paypal.com duuytoqss3gu4.cloudfront.net df45ay5pw60dy.cloudfront.net d3nocrch4qti4v.cloudfront.net *.google-analytics.com *.pinterest.com *.twilio.com *.tiktok.com *.useinsider.com maps.googleapis.com/maps developers.google.com *.zopim.io *.zdassets.com amcglobal.sc.omtrdc.net adservice.google.com lantern.roeye.com accentgroupxpdev.112.2o7.net/b/ss/accentgroup-xpdev i.vimeocdn.com/video ; object-src 'none' ; base-uri 'self' ; child-src 'self' blob: ; connect-src 'self' api-accent.bloomreach.co *.qantasloyalty.com analytics.google.com/g/collect iq.afterpay.com/us/v1 iq.afterpay-beta.com/us/v1 *.my.sentry.io wss://api.smooch.io *.accentgra.com www.facebook.com/tr google.com www.google.com collect-ap2.attraqt.io smetrics.platypusshoes.co.nz *.fullstory.com *.klaviyo.com smetrics.platypusshoes.com.au api-js.datadome.co *.adobedc.net *.afterpay.com *.bazaarvoice.com *.braintree-api.com *.braintreegateway.com *.demdex.net *.forter.com *.foursixty.com google.com/ccm www.google.com/ccm *.google-analytics.com *.googleapis.com www.google.com.au/ads/ga-audiences *.nr-data.net *.paypal.com *.truefitcorp.com *.zdassets.com *.zendesk.com *.zopim.com accentgroupxpdev.112.2o7.net afterpay.com analytics.tiktok.com facebook.com *.roymorgan.com foursixty.com kleber.datatoolscloud.net.au sentry.io vimeo.com wss://*.twilio.com wss://widget-mediator.zopim.com d2o5idwacg3gyw.cloudfront.net dz8rit8v72mig.cloudfront.net d2lxqodqbpy7c2.cloudfront.net d6rak4b14t5gp.cloudfront.net d3k4bt74u9esq1.cloudfront.net wss://cdn0.forter.com api.myunidays.com ct.pinterest.com stats.g.doubleclick.net *.useinsider.com ; font-src data: 'self' maxcdn.bootstrapcdn.com/font-awesome fonts.gstatic.com *.truefitcorp.com *.useinsider.com static.klaviyo.com use.typekit.net shopping.qantas.com ; frame-src 'self' api-accent.bloomreach.co *.qlstg.qantas.com www.googletagmanager.com geo.captcha-delivery.com *.formstack.com *.afterpay.com *.bazaarvoice.com *.demdex.net *.doubleclick.net *.facebook.com *.myunidays.com *.omniparcelreturns.com *.paypal.com *.paypalobjects.com *.truefitcorp.com *.useinsider.com *.vimeo.com *.youtu.be *.youtube.com afterpay.com assets.braintreegateway.com facebook.com foursixty.com google.com www.google.com vimeo.com ct.pinterest.com ; worker-src 'self' blob: *.accentgra.com *.platypusshoes.co.nz *.platypusshoes.com.au; 2 frame-ancestors 'self' https://bioland.we.network/ https://my.dlv.de/ 2 font-src https://www.googletagmanager.com *.googleapis.com *.gstatic.com *.bootstrapcdn.com *.cloudflare.com 'self' data: *.hotjar.com *.hotjar.io data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * www.facebook.com 'self' connect.facebook.net graph.facebook.com business.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.doubleclick.net *.googlesyndication.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com 'self' data: *.paypal.com *.gstatic.com *.googleapis.com *.openstreetmap.org *.googlesyndication.com *.google.com *.google.rs *.google.hr *.google.ba *.google.si *.google.bg *.google.me *.google.mk *.google.nl *.google.de *.google.be *.google.fr *.googleadservices.com www.facebook.com trengo.s3.eu-central-1.amazonaws.com ecom-stage.iutecredit.mk ecom.iutecredit.mk ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com connect.facebook.net graph.facebook.com business.facebook.com *.cmi.co.ma yandex.com yandex.md *.yandex.md *.yandex.com yandex.ru *.yandex.ru *.yads.tech yads.tech *.yango.com *.doubleclick.net t.adx.opera.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com songbird.cardinalcommerce.com tagmanager.google.com https://www.googletagmanager.com *.googleapis.com *.gstatic.com https://widget-cdn.boxnow.hr *.googlesyndication.com *.googleadservices.com *.google.com *.google.rs *.google.hr *.google.ba *.google.si *.google.bg *.google.me *.google.mk www.facebook.com *.widget.trengo.eu map.gls-croatia.com map.gls-czech.com map.gls-hungary.com map.gls-romania.com map.gls-slovenia.com map.gls-slovakia.com map.gls-serbia.com *.openstreetmap.org ecom-stage.iutecredit.mk ecom.iutecredit.mk chimpstatic.com downloads.mailchimp.com *.list-manage.com s7.addthis.com connect.facebook.net graph.facebook.com business.facebook.com *.hotjar.com *.hotjar.io onesignal.com *.onesignal.com *.criteo.com *.adsmurai.com gateway.bankart.si yandex.com yandex.md *.yandex.md *.yandex.com yandex.ru *.yandex.ru *.yads.tech yads.tech *.yango.com *.doubleclick.net t.adx.opera.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com unsafe-inline assets.braintreegateway.com https://www.googletagmanager.com tagmanager.google.com *.googleapis.com fonts.googleapis.com *.bootstrapcdn.com ecom-stage.iutecredit.mk ecom.iutecredit.mk downloads.mailchimp.com onesignal.com *.onesignal.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com static.widget.trengo.eu 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com https://www.google-analytics.com *.googleapis.com https://widget-cdn.boxnow.hr *.google.com *.google.rs *.google.hr *.google.ba *.google.si *.google.bg *.google.me *.google.mk *.google.nl *.google.de *.google.be *.google.fr *.googlesyndication.com *.doubleclick.net www.facebook.com *.trengo.eu map.gls-croatia.com map.gls-czech.com map.gls-hungary.com map.gls-romania.com map.gls-slovenia.com map.gls-slovakia.com map.gls-serbia.com *.openstreetmap.org ecom-stage.iutecredit.mk ecom.iutecredit.mk ekr.zdassets.com/ connect.facebook.net graph.facebook.com business.facebook.com wss://ws.hotjar.com *.hotjar.io yandex.com *.yandex.md *.yandex.com yandex.ru *.yandex.ru *.yads.tech *.yango.com cm.g.doubleclick.net t.adx.opera.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src yandex.com yandex.md *.yandex.md *.yandex.com yandex.ru *.yandex.ru *.yads.tech yads.tech *.yango.com *.doubleclick.net t.adx.opera.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.spotify.com https://dimedic.eu https://*.dimedic.eu https://geowidget.easypack24.net 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com sandbox.przelewy24.pl secure.przelewy24.pl 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com pay.google.com apm.przelewy24.pl *.spotify.com https://aptekaradicula.pl https://dimedic.eu https://*.dimedic.eu https://geowidget-app.inpost.pl/ https://sandbox-easy-geowidget.easypack24.net/ 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net https://images.unsplash.com *.salesmanago.pl *.salesmanago.es *.salesmanago.com *.googletagmanager.com *.google-analytics.com ssl.gstatic.com www.gstatic.com magefan.com cm.magefan.com *.disqus.com https://img.youtube.com static.przelewy24.pl gstatic.com *.spotify.com https://dimedic.eu https://*.dimedic.eu https://geowidget.easypack24.net *.easypack24.net *.inpost.pl *.openstreetmap.org *.hsforms.net *.hsforms.com 'self' data: data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com https://cdn.jsdelivr.net/npm/@ryangjchandler/spruce@2.x.x/dist/spruce.umd.js https://maps.googleapis.com https://player.vimeo.com *.salesmanago.pl *.salesmanago.es *.salesmanago.com *.googletagmanager.com tagmanager.google.com *.disqus.com sandbox.przelewy24.pl secure.przelewy24.pl pay.google.com apm.przelewy24.pl *.spotify.com https://dimedic.eu https://*.dimedic.eu https://geowidget.easypack24.net *.easypack24.net *.inpost.pl *.openstreetmap.org *.hsforms.net *.hsforms.com *.gstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com tagmanager.google.com fonts.google.com *.spotify.com https://dimedic.eu https://*.dimedic.eu https://geowidget.easypack24.net https://geowidget.inpost.pl *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com https://geowidget.easypack24.net 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com https://maps.googleapis.com https://player.vimeo.com *.salesmanago.pl *.salesmanago.es *.salesmanago.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com sandbox.przelewy24.pl secure.przelewy24.pl wss://sandbox-ws.przelewy24.pl wss://secure-ws.przelewy24.pl apple-pay-gateway.apple.com apm.przelewy24.pl *.spotify.com https://dimedic.eu https://*.dimedic.eu *.easypack24.net *.inpost.pl *.openstreetmap.org t.elasticsuite.io *.hsforms.net *.hsforms.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.salesmanago.pl *.salesmanago.es *.salesmanago.com *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 report-to https://r4com.report-uri.io/r/default/csp/reportOnly 2 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com maxcdn.bootstrapcdn.com https://fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.paypal.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com https://mobbex.com 'self' 'unsafe-inline'; frame-ancestors *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://mobbex.com *.weltpixel.com *.getblue.io *.doubleclick.net *.criteo.com *.groovinads.com www.tfaforms.com https://mercadopago.com.ar https://www.mercadopago.com.ar 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.mobbex.com https://res.sugaway.io *.visualwebsiteoptimizer.com https://*.g.doubleclick.net *.clarity.ms *.bing.com mcstaging.sommiercenter.com *.groovinads.com *.criteo.com https://facebook.com url.directo.com.ar https://*.google-analytics.com https://*.googletagmanager.com https://*.google.com https://www.gstatic.com https://ssl.gstatic.com https://ad.doubleclick.net https://ade.googlesyndication.com https://www.mercadopago.com.ar https://m.facebook.com https://maps.googleapis.com https://www.afip.gob.ar https://www.google.com.ar data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net amcglobal.sc.omtrdc.net *.adobe.io use.typekit.net *.commerce-payment-services.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.magento-ds.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.magento-datasolutions.com https://rum.hlx.page https://live.decidir.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.mobbex.com https://www.google.com https://maps.googleapis.com api.wcx.cloud f.wcentrix.com https://www.googletagmanager.com tagmanager.google.com https://merchants.playdigital.com.ar/ https://merchants.preprod.playdigital.com.ar/ https://ecommerce-modal.modo.com.ar/ https://ecommerce-modal.preprod.modo.com.ar/ *.hotjar.com *.cardinalcommerce.com *.embluemail.com *.navdmp.com *.zdassets.com *.visualwebsiteoptimizer.com *.getblue.io *.zopim.com *.clarity.ms *.groovinads.com *.criteo.net *.criteo.com *.decidir.com https://*.googletagmanager.com https://tagmanager.google.com https://www.googleadservices.com https//static.zdassets.com https://v2.zopim.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com maxcdn.bootstrapcdn.com tagmanager.google.com https://ecommerce-modal.modo.com.ar/ https://ecommerce-modal.preprod.modo.com.ar/ *.embluemail.com https://fonts.googleapis.com https://*.googletagmanager.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com bedtime.com.ar *.bedtime.com.ar 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net commerce.adobe.io *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.magento-datasolutions.com *.magento-ds.com https://developers.decidir.com/ *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.mobbex.com https://www.google-analytics.com https://merchants.playdigital.com.ar/ https://merchants.preprod.playdigital.com.ar/ https://ecommerce-modal.modo.com.ar/ https://ecommerce-modal.preprod.modo.com.ar/ wss://widget-mediator.zopim.com *.braindw.com *.clarity.ms *.zdassets.com *.zendesk.com *.embluemail.com *.visualwebsiteoptimizer.com *.criteo.com *.decidir.com https://*.google-analytics.com https://*.google.com https://*.googletagmanager.com https://*.g.doubleclick.net https://maps.googleapis.com https://www.google.com.ar https://analytics.google.com/g/collect https://www.google.com.ar/ads https://ad.doubleclick.net 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 default-src 'self'; script-src 'nonce-KjlwR0pVUGk3YkR1dFRBV2ZmIUo=' 'self' 'unsafe-eval' https://*.googletagmanager.com https://*.google-analytics.com https://*.analytics.google.com https://cdnjs.cloudflare.com; script-src-elem 'nonce-MTo4MDY2MDoxNjE3MDQ5ODExOjE3MzQ5NTc2NzU=' 'nonce-MTo4MDY2MzoxNjQ4Nzg0NDUxOjE3MzQ5NTc4NTQ=' 'self' 'unsafe-eval' 'unsafe-inline' https://*.googletagmanager.com https://*.google-analytics.com https://*.analytics.google.com https://*.google.com https://connect.facebook.net https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://*.kaspersky-labs.com https://api.mailxpert.ch; script-src-attr 'self' 'unsafe-inline' https://*.googletagmanager.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; style-src-attr 'self' 'unsafe-inline'; style-src-elem 'self' 'unsafe-inline' https://fonts.googleapis.com https://www.google.com https://*.kaspersky-labs.com https://cdnjs.cloudflare.com; object-src 'self'; base-uri 'self'; connect-src 'self' https://*.googletagmanager.com https://*.google-analytics.com https://analytics.google.com https://*.analytics.google.com https://*.g.doubleclick.net https://api.friendlycaptcha.com; font-src 'self' data: https://fonts.gstatic.com https://cdnjs.cloudflare.com; frame-src 'self' https://ige.prospective.ch https://td.doubleclick.net https://nl.mailxpert.ch https://www.youtube-nocookie.com; img-src 'self' data: blob: https://*.googletagmanager.com https://*.google-analytics.com https://*.analytics.google.com https://*.g.doubleclick.net https://i.ytimg.com; manifest-src 'self'; media-src 'self' data:; worker-src blob:; report-uri /CspReportLogger.php 2 default-src https: data: 'unsafe-inline' 'unsafe-eval'; frame-src https: data: blob:; report-uri https://temporarycsp.azurewebsites.net/api/CreateReport 2 default-src 'self' 'unsafe-inline' 'unsafe-eval' *.audioeye.com akstat.io *.akstat.io cookielaw.org cdn.cookielaw.org *.google-analytics.com *.quantummetric.com quantummetric.com *.typekit.net www.googletagmanager.com tapestry.com *.tapestry.com tapestry.support *.licdn.com *.jwplatform.com *.jwpcdn.com cdn.jwplayer.com prd.jwpltx.com *.jwpsrv.com jsdelivr.net *.jsdelivr.net *.newrelic.com *-tapestry-news.pantheonsite.io cdnjs.cloudflare.com fonts.googleapis.com secure.gravatar.com px.ads.linkedin.com cdn.linkedin.oribi.io p.adsymptotic.com tapestry.gcs-web.com opensupplyhub.org *.akamaihd.net go-mpulse.net *.go-mpulse.net geolocation.onetrust.com stats.g.doubleclick.net fonts.gstatic.com data: blob:; 2 report-uri https://d1aosrekaw7sk8.cloudfront.net/reports; upgrade-insecure-requests; default-src 'self' 'unsafe-eval' 'unsafe-inline' ws: blob: data: tagging.dupixent.com ad.doubleclick.net iron-wsa01 ironport 8188202.fls.doubleclick.net ad.doubleclick.net adservice.google.com aim-tag.hcn.health ajax.googleapis.com analytics.google.com analytics.tiktok.com ap.lijit.com apis.google.com apps.healthgrades.com bat.bing.com bcbolt446c5271-a.akamaihd.net bcp.crwdcntrl.net bh.contextweb.com c.clarity.ms cdn.cookielaw.org cdn.di-capt.com cdn.jsdelivr.net cdnjs.cloudflare.com clientstream.launchdarkly.com cm.g.doubleclick.net code.jquery.com connect.facebook.net content.hotjar.io contextual.media.net d1lkfzu2puirk6.cloudfront.net di.rlcdn.com dpm.demdex.net eb2.3lift.com edge.api.brightcove.com fast.fonts.net feedback-pa.clients6.google.com fonts.cdnfonts.com fonts.googleapis.com fonts.googleapis.com fonts.gstatic.com form.typeform.com geolocation.onetrust.com googleads.g.doubleclick.net gum.criteo.com i.liadm.com i6.liadm.com ib.adnxs.com insight.adsrvr.org insights.algolia.io integrations.eu-de.assistant.watson.appdomain.cloud js.adsrvr.org manzanasjuegosco-a.akamaihd.net maps.googleapis.com maps.gstatic.com match.adsrvr.org match.deepintent.com match.sharethrough.com metrics.brightcove.com metrics.hotjar.io ms-cookie-sync.presage.io pixel.rubiconproject.com player.vimeo.com players.brightcove.net players.brightcove.net privacyportal-eu.onetrust.com px.ads.linkedin.com px4.ads.linkedin.com region1.analytics.google.com region1.google-analytics.com rialto-gms.s3.amazonaws.com rtb-csync.smartadserver.com rtb.gumgum.com sc-static.net script.hotjar.com security-eu.mimecast.com snap.licdn.com spoppe-b.azureedge.net ssum-sec.casalemedia.com staging-apps.healthgrades.com static.hotjar.com stats.g.doubleclick.net sync.1rx.io sync.crwdcntrl.net tags.bluekai.com td.doubleclick.net td.doubleclick.net thrtle.com token.rubiconproject.com translate-pa.googleapis.com translate.googleapis.com trc.lhmos.com trotjidayo-1.algolianet.com trotjidayo-2.algolianet.com trotjidayo-3.algolianet.com trotjidayo-dsn.algolia.net uipglob.semasio.net unpkg.com use.fontawesome.com vc.hotjar.io vjs.zencdn.net web-chat.global.assistant.watson.appdomain.cloud www.clarity.ms www.dupixent.com www.facebook.com www.google-analytics.com www.google-analytics.com www.google.com www.google.com.au www.googletagmanager.com fresnel-events.vimeocdn.com vod-adaptive-ak.vimeocdn.com player-telemetry.vimeo.com fresnel.vimeocdn.com www.medtargetsystem.com z.clarity.ms ws.hotjar.com secure.adnxs.com www.gstatic.com www.eventmgmtportal.com sanofi-privacy.my.onetrust.com trotjidayo-1.algolianet.com trotjidayo-3.algolianet.com trotjidayo-2.algolianet.com trotjidayo-dsn.algolia.net lpopeventportal-2-0-2.sanofigenzyme.intouch-preview.com som.healthgrades.com sanofi-japan-dev.eval.janraincapture.com sanofi-japan-staging.eval.janraincapture.com sanofi-japan.us.janraincapture.com sanofi-dev.us-dev.janraincapture.com sanofi-staging.us-dev.janraincapture.com sanofi.us.janraincapture.com sanofi-dev.eu-dev.janraincapture.com sanofi-staging.eu-dev.janraincapture.com sanofi.eu.janraincapture.com vod-adaptive-ak.vimeocdn.com player-telemetry.vimeo.com fresnel.vimeocdn.com fresnel-events.vimeocdn.com photos.healthgrades.com use.typekit.net p.typekit.net; 2 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://components-bnpl-pe-bbva-moprestamo-com.s3.amazonaws.com data: *.fontawesome.com fonts.googleapis.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.paypal.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com static.zdassets.com www.gstatic.com script.hotjar.com static.hotjar.com googleadservices.com maps.googleapis.com/ webpay3g.transbank.cl webpay3gint.transbank.cl *.google.com 'self' 'unsafe-inline'; frame-ancestors *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com static.zdassets.com www.gstatic.com static.hotjar.com script.hotjar.com googleadservices.com maps.googleapis.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com *.moprestamo.com cdn.dnky.co amc.demdex.net www.google.com www.facebook.com youtube.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com vars.hotjar.com *.doubleclick.net *.pinterest.com *.tryadviser.com *.webviewer.appar.io *.paperless.com.pe *.extranetrosen.cl static-content.vnforapps.com 'self' 'unsafe-inline'; img-src *.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net data: *.moprestamo.com maps.gstatic.com maps.googleapis.com accounts.google.com www.facebook.com magefan.com cm.magefan.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com connect.facebook.net graph.facebook.com business.facebook.com www.extranetrosen.cl *.hsforms.com track.hubspot.com mercadopago.cl www.mercadopago.cl *.google.com.cl static.zdassets.com www.gstatic.com static.hotjar.com script.hotjar.com *.pinterest.com *.sendtric.com *.tryadviser.com *.adnxs.com *.linkedin.com *.doubleclick.net *.rosen.cl *.rosen.com.pe *.sonataplatform.com *.googleadservices.com *.google-analytics.com cdn.ckeditor.com google.com.ar https://www.mercadopago.com.pe https://www.google.com.ar https://www.google.es data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.dpm.demdex.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net assets.adobedtm.com amcglobal.sc.omtrdc.net *.adobe.io use.typekit.net *.commerce-payment-services.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.magento-ds.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.magento-datasolutions.com *.moprestamo.com cdn.dnky.co r1-t.trackedlink.net www.gstatic.com js-agent.newrelic.com bam.nr-data.net maps.googleapis.com connect.facebook.net player.vimeo.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com www.facebook.com graph.facebook.com business.facebook.com https://maps.googleapis.com www.extranetrosen.cl static.zdassets.com js.hs-scripts.com js.hs-analytics.net js.hscollectedforms.net js.hs-banner.com www.googleoptimize.com static.hotjar.com *.google.cl script.hotjar.com js.hsleadflows.net *.pinimg.com www.youtube.com *.tryadviser.com *.adnxs.com *.hsadspixel.net *.verificado.ai api.verificado.ai snap.licdn.com *.google-analytics.com *.commerce.adobe.net *.magento.com *.hscollectedforms.net *.doubleclick.net *.omtrdc.net *.googletagmanager.com *.rosen.cl *.rosen.com.pe *.sonataplatform.com *.mouseflow.com *.hubspot.com *.vnforapps.com *.gstatic.com cdn.ckeditor.com/ pinterest.com https://www.googletagmanager.com data.appar.io *.pinterest.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com *.moprestamo.com cdn.dnky.co *.fontawesome.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.rosen.cl *.rosen.com.pe www.extranetrosen.cl *.tryadviser.com *.googleapis.com *.gstatic.com fonts.googleapis.com/ cdn.ckeditor.com/ 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com static.zdassets.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net commerce.adobe.io *.sentry.io *.paypal.com google.com *.google.com *.magento-datasolutions.com *.magento-ds.com maps.googleapis.com api.comapi.com bam.nr-data.net *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.facebook.com connect.facebook.net graph.facebook.com business.facebook.com static.zdassets.com v2.zopim.com ekr.zdassets.com rollbar-eu.zendesk.com wa.me *.hubspot.com stats.g.doubleclick.net rosen.zendesk.com wss://widget-mediator.zopim.com *.hotjar.com vc.hotjar.io www.facebook.com public.delivery.janisqa.in public.delivery.janis.in *.google.cl *.pinterest.com wss://*.hotjar.com *.hscollectedforms.net *.hubapi.com *.amazonaws.com *.amazon.com *.zendesk.com *.linkedin.com ad.doubleclick.net *.google-analytics.com maps.googleapis.com/ *.visualwebsiteoptimizer.com http://localhost:12387 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 font-src https://*.gstatic.com *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.klarnacdn.net *.klevu.com *.ksearchnet.com *.yotpo.com *.googleapis.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.adyen.com *.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.punchout2go.com *.tradecentric.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.adyen.com *.google.com *.doubleclick.net *.facebook.com *.affirm.com *.affirm.ca *.klarna.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.punchout2go.com *.tradecentric.com *.yotpo.com https://*.online-metrix.net https://imgs.signifyd.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.adyen.com https://images.unsplash.com https://*.gstatic.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.gstatic.com *.affirm.com *.affirm.ca www.feedoptimise.com cdn.feedoptimise.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klarna.com *.klarnaevt.com *.klarnacdn.net *.klevu.com *.ksearchnet.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.yotpo.com https://imgs.signifyd.com https://*.online-metrix.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.adyen.com https://cdn.jsdelivr.net/npm/@ryangjchandler/spruce@2.x.x/dist/spruce.umd.js *.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.affirm.com *.affirm.ca *.attn.tv events.attentivemobile.com www.feedoptimise.com cdn.feedoptimise.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klarna.com *.klarnacdn.net *.klarnaservices.com *.klevu.com *.ksearchnet.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.punchout2go.com *.tradecentric.com * *.yotpo.com https://cdn-scripts.signifyd.com https://imgs.signifyd.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://fonts.googleapis.com/ *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com https://static.klaviyo.com *.klarnacdn.net *.klevu.com *.ksearchnet.com unsafe-inline assets.braintreegateway.com *.punchout2go.com *.tradecentric.com *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adyen.com *.google-analytics.com *.facebook.com *.facebook.net *.google.com *.affirm.com *.affirm.ca *.attn.tv events.attentivemobile.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klarnaevt.com *.klarnacdn.net *.klarna.com *.klarnaservices.com *.klevu.com *.ksearchnet.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com google.com * *.yotpo.com https://imgs.signifyd.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 default-src 'self'; script-src 'self' 'unsafe-eval' https://www.youtube.com https://*.wistia.com https://*.wistia.net https://*.org.coveo.com https://elearning.childrenswi.org https://ajax.googleapis.com https://js.eruptr.io https://siteimproveanalytics.com https://storage.googleapis.com https://mychart.chw.org https://my-symptom.appcatalyst.com https://mychart-np.et0815.epichosted.com https://l6bcxsyfvoka8mbm.public.blob.vercel-storage.com; script-src-elem 'self' 'unsafe-inline' https://www.youtube.com https://*.wistia.com https://*.wistia.net https://elearning.childrenswi.org https://ajax.googleapis.com https://js.eruptr.io https://siteimproveanalytics.com https://storage.googleapis.com https://browser.sentry-cdn.com https://mychart-np.et0815.epichosted.com https://mychart.chw.org https://www.google.com https://www.gstatic.com https://cdnjs.cloudflare.com https://cdn.jsdelivr.net https://*.addtoany.com https://my-symptom.appcatalyst.com https://*.contentsquare.net https://*.heap-api.com https://*.calltrk.com https://elearning.childrenswi.org https://fonts.googleapis.com https://l6bcxsyfvoka8mbm.public.blob.vercel-storage.com; style-src 'self' 'unsafe-inline' https://*.sitecorecloud.io https://mychart.chw.org https://cdn.jsdelivr.net https://*.addtoany.com https://my-symptom.appcatalyst.com https://mychart-np.et0815.epichosted.com https://elearning.childrenswi.org https://fonts.googleapis.com https://l6bcxsyfvoka8mbm.public.blob.vercel-storage.com; img-src 'self' data: https: blob:; font-src 'self' data: https:; connect-src 'self' https://xmc-childrensho3e59-cw60b4-prod2126.sitecorecloud.io https://www.youtube.com https://*.sitecorecloud.io https://*.wistia.com https://*.wistia.net https://*.org.coveo.com https://elearning.childrenswi.org https://ajax.googleapis.com https://js.eruptr.io https://siteimproveanalytics.com https://storage.googleapis.com https://cw-sp-collector.modea.com https://mychart.chw.org https://cdn.jsdelivr.net https://ipapi.co https://*.addtoany.com https://my-symptom.appcatalyst.com https://mychart-np.et0815.epichosted.com https://*.litix.io https://*.contentsquare.net https://*.heap-api.com https://js.calltrk.com https://l6bcxsyfvoka8mbm.public.blob.vercel-storage.com; frame-src 'self' https://xmc-childrensho3e59-cw60b4-prod2126.sitecorecloud.io https://www.youtube.com https://mychart.chw.org https://*.addtoany.com https://my-symptom.appcatalyst.com https://mychart-np.et0815.epichosted.com https://mychart.chw.org; frame-ancestors 'self' https://xmc-childrensho3e59-cw60b4-prod2126.sitecorecloud.io https://*.sitecorecloud.io http://localhost:3000 https://mychart.chw.org https://*.xealth.io; media-src 'self' https: data: blob:; object-src 'none'; base-uri 'self'; form-action 'self'; worker-src 'self' blob:; manifest-src 'self'; report-to csp-endpoint; report-uri https://childrenswi.org/api/csp-report/xt2c9f8er8 2 default-src https:; connect-src https: wss:; script-src 'unsafe-inline' 'unsafe-eval' https:; style-src 'self' 'unsafe-inline' *.google.com fonts.googleapis.com static.pazaruvaj.com unpkg.com api.mapbox.com cdn.jsdelivr.net geowidget.easypack24.net maxcdn.bootstrapcdn.com ssl.ceneo.pl s.kk-resources.com elnino.daktela.com www.wiarygodneopinie.pl ts.tradetracker.net cdn.foxentry.cz www.parfemy-elnino.cz geowidget.inpost.pl www.googletagmanager.com smartsuppcdn.com static.compari.ro *.demandware.net; object-src 'self'; img-src 'self' https: data:; font-src https: data:; frame-ancestors 'self' *.creativecdn.com *.hotjar.com *.googletagmanager.com; report-uri https://elnino.report-uri.com/r/d/csp/enforce 2 img-src https://higherlogicdownload.s3.amazonaws.com/CONSERVATIONUS/ https://cdn.jsdelivr.net/jquery.slick/ https://higherlogic-holdingpen-us-east-1.s3.amazonaws.com/CONSERVATIONUS/ https://img.youtube.com/vi/ https://static.filestackapi.com/picker/ https://d2x5ku95bkycr3.cloudfront.net https://higherlogiclongterm.s3.amazonaws.com/CONSERVATIONUS/ blob: https://d132x6oi8ychic.cloudfront.net 'self'; style-src https://d132x6oi8ychic.cloudfront.net 'unsafe-inline' https://higherlogiccloudfront.s3.amazonaws.com https://cdn.jsdelivr.net/jquery.slick/ https://cdnjs.cloudflare.com/ajax/libs/prism/ https://d2x5ku95bkycr3.cloudfront.net/ https://ajax.googleapis.com/ajax/libs/jqueryui/ https://use.fortawesome.com/ https://static.filestackapi.com/picker/ https://fonts.googleapis.com/ https://d3uf7shreuzboy.cloudfront.net/ https://higherlogic-holdingpen-us-east-1.s3.amazonaws.com/CONSERVATIONUS/ https://higherlogicdownload.s3.amazonaws.com/CONSERVATIONUS/ https://higherlogiclongterm.s3.amazonaws.com/CONSERVATIONUS/ 'self'; font-src https://fonts.googleapis.com/ https://fonts.gstatic.com/ https://cdn.jsdelivr.net/jquery.slick/ https://higherlogiccloudfront.s3.amazonaws.com https://higherlogicdownload.s3.amazonaws.com/CONSERVATIONUS/ https://higherlogic-holdingpen-us-east-1.s3.amazonaws.com/CONSERVATIONUS/ 'self' https://higherlogiclongterm.s3.amazonaws.com/CONSERVATIONUS/ https://maxcdn.bootstrapcdn.com/font-awesome/ https://d2x5ku95bkycr3.cloudfront.net https://d132x6oi8ychic.cloudfront.net data:; script-src-elem https://www.google.com/recaptcha/ https://www.recaptcha.net/recaptcha/ https://d2x5ku95bkycr3.cloudfront.net/HigherLogic/jquery/jquery-ui-1.13.3.min.js https://d3uf7shreuzboy.cloudfront.net/ https://static.filestackapi.com/picker/ https://d2x5ku95bkycr3.cloudfront.net/HigherLogic/jquery/jquery-3.7.1.min.js https://d2x5ku95bkycr3.cloudfront.net/ https://cdnjs.cloudflare.com/ajax/libs/prism/ https://www.gstatic.com/recaptcha/ https://static.filestackapi.com/filestack-js/ 'self' https://ajax.aspnetcdn.com/ajax/ 'unsafe-eval' 'unsafe-inline'; media-src https://higherlogiclongterm.s3.amazonaws.com/CONSERVATIONUS/ https://higherlogicdownload.s3.amazonaws.com/CONSERVATIONUS/ https://higherlogic-holdingpen-us-east-1.s3.amazonaws.com/CONSERVATIONUS/ https://higherlogicstream.s3.amazonaws.com/CONSERVATIONUS/ 'self' https://d132x6oi8ychic.cloudfront.net; script-src https://higherlogiclongterm.s3.amazonaws.com/CONSERVATIONUS/ https://higherlogicdownload.s3.amazonaws.com/CONSERVATIONUS/ https://ajax.aspnetcdn.com/ajax/ https://cdn.jsdelivr.net/jquery.slick/ https://d2x5ku95bkycr3.cloudfront.net/HigherLogic/jquery/jquery-ui-1.13.3.min.js https://d132x6oi8ychic.cloudfront.net https://cdn.informz.net 'unsafe-eval' https://use.fortawesome.com/ https://higherlogic-holdingpen-us-east-1.s3.amazonaws.com/CONSERVATIONUS/ https://cdnjs.cloudflare.com/ajax/libs/prism/ 'unsafe-inline' https://d2x5ku95bkycr3.cloudfront.net/ https://higherlogiccloudfront.s3.amazonaws.com https://static.filestackapi.com https://d2x5ku95bkycr3.cloudfront.net/HigherLogic/jquery/jquery-3.7.1.min.js https://d3uf7shreuzboy.cloudfront.net/ 'self'; frame-src https://www.google.com/recaptcha/ https://www.recaptcha.net/recaptcha/ https://api.connectedcommunity.org/ 'self' https://www.youtube.com/embed/; connect-src https://upload.filestackapi.com https://static.filestackapi.com https://cloud.filestackapi.com/folder/list/ 'self' https://hl-managedservices.informz.net https://d3uf7shreuzboy.cloudfront.net/ blob:; worker-src 'self'; default-src 'self'; base-uri 'self'; frame-ancestors https://*.connectedcommunity.org/ 'self'; object-src 'none'; manifest-src 'self'; 2 require-trusted-types-for 'script'; report-uri https://csp.withgoogle.com/csp/uxe-owners-acl/mapsplatform_google_com 2 font-src *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.gstatic.com 'self' data: data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.multisafepay.com https://pay.google.com 'self'; frame-src bid.g.doubleclick.net player.vimeo.com *.youtube.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com *.youtube-nocookie.com www.google.com https://*.dpdconnect.nl youtube.com *.doubleclick.net *.multisafepay.com https://pay.google.com *.weltpixel.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com *.youtube.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com https://firebasestorage.googleapis.com flagpedia.net www.jmpbonderdelen.nl www.jmpbonderdelen.be www.jmpbparts.com www.jmpbteile.de www.jmpbteile.at www.jmpbdele.dk 'self' data: *.google.nl *.multisafepay.com *.gstatic.com data: 'self' 'unsafe-inline'; script-src googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ https://*.dpdconnect.nl https://cdn.polyfill.io https://browser.sentry-cdn.com *.avada.io player.vimeo.com *.gstatic.com maps.googleapis.com *.multisafepay.com https://pay.google.com https://www.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.gstatic.com *.googleapis.com *.multisafepay.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com vimeo.com https://*.ingest.sentry.io https://get.geojs.io *.avada.io www.gstatic.com maps.googleapis.com *.google-analytics.com *.doubleclick.net *.google.com google.com *.googlesyndication.com *.googleadservices.com *.google.nl *.multisafepay.com https://www.google-analytics.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 font-src *.googleapis.com *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com https://fonts.gstatic.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com *.googlesyndication.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.multisafepay.com https://pay.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.google.com *.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com *.multisafepay.com https://pay.google.com *.trustpilot.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://images.unsplash.com *.googleapis.com *.gstatic.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.googlesyndication.com *.roeye.com *.multisafepay.com www.magmodules.eu *.squeezely.tech data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://cdn.jsdelivr.net/npm/@ryangjchandler/spruce@2.x.x/dist/spruce.umd.js www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.googleapis.com *.gstatic.com *.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.googlesyndication.com *.jsdelivr.net https://cdn.polyfill.io https://browser.sentry-cdn.com *.multisafepay.com https://pay.google.com squeezely.tech www.squeezely.tech *.squeezely.tech *.trustpilot.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com https://fonts.googleapis.com *.fontawesome.com *.multisafepay.com *.trustpilot.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.googleapis.com *.google-analytics.com *.facebook.com *.facebook.net *.google.com *.doubleclick.net *.googlesyndication.com https://*.ingest.sentry.io *.multisafepay.com squeezely.tech *.squeezely.tech 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com commerce-payments-sdk.adobe.io www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://rum.hlx.page js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 default-src 'self' *.ultramusicfestival.com ultramusicfestival.com umfworldwide.com ultrapassport.com *.ultrapassport.net resistancemusic.com *.resistancemusic.com roadtoultra.com *.roadtoultra.com; font-src 'self' *.ultramusicfestival.com ultramusicfestival.com umfworldwide.com ultrapassport.com *.ultrapassport.net resistancemusic.com *.resistancemusic.com roadtoultra.com *.roadtoultra.com data: *.olark.com fonts.gstatic.com; script-src 'self' *.ultramusicfestival.com ultramusicfestival.com umfworldwide.com ultrapassport.com *.ultrapassport.net resistancemusic.com *.resistancemusic.com roadtoultra.com *.roadtoultra.com 'unsafe-inline' 'unsafe-eval' *.turn.com static.cloudflareinsights.com ajax.cloudflare.com *.youtube.com *.ytimg.com *.datadoghq-browser-agent.com *.getclicky.com clicky.com *.twitter.com *.ads-twitter.com *.facebook.net analytics.tiktok.com www.recaptcha.net recaptcha.net www.gstatic.com www.gstatic.cn www.google.com *.olark.com *.adroll.com *.googletagmanager.com tagmanager.google.com analytics.google.com google-analytics.com *.google-analytics.com *.g.doubleclick.net *.doubleclick.net *.googleadservices.com *.google.com *.googlesyndication.com *.googletagservices.com; style-src 'self' *.ultramusicfestival.com ultramusicfestival.com umfworldwide.com ultrapassport.com *.ultrapassport.net resistancemusic.com *.resistancemusic.com roadtoultra.com *.roadtoultra.com 'unsafe-inline' *.getclicky.com clicky.com *.olark.com *.googletagmanager.com tagmanager.google.com *.google.com fonts.googleapis.com; img-src 'self' *.ultramusicfestival.com ultramusicfestival.com umfworldwide.com ultrapassport.com *.ultrapassport.net resistancemusic.com *.resistancemusic.com roadtoultra.com *.roadtoultra.com 'unsafe-inline' data: *.turn.com secure.gravatar.com *.ytimg.com *.youtube.com *.getclicky.com *.twitter.com t.co *.facebook.com www.gstatic.com/recaptcha *.olark.com *.adroll.com d.adroll.com *.googletagmanager.com analytics.google.com *.analytics.google.com google-analytics.com *.google-analytics.com *.gstatic.com *.google.com *.doubleclick.net *.g.doubleclick.net *.googlesyndication.com www.googleadservices.com *.google.ad *.google.ae *.google.com.af *.google.com.ag *.google.com.ai *.google.al *.google.am *.google.co.ao *.google.com.ar *.google.as *.google.at *.google.com.au *.google.az *.google.ba *.google.com.bd *.google.be *.google.bf *.google.bg *.google.com.bh *.google.bi *.google.bj *.google.com.bn *.google.com.bo *.google.com.br *.google.bs *.google.bt *.google.co.bw *.google.by *.google.com.bz *.google.ca *.google.cd *.google.cf *.google.cg *.google.ch *.google.ci *.google.co.ck *.google.cl *.google.cm *.google.cn *.google.com.co *.google.co.cr *.google.com.cu *.google.cv *.google.com.cy *.google.cz *.google.de *.google.dj *.google.dk *.google.dm *.google.com.do *.google.dz *.google.com.ec *.google.ee *.google.com.eg *.google.es *.google.com.et *.google.fi *.google.com.fj *.google.fm *.google.fr *.google.ga *.google.ge *.google.gg *.google.com.gh *.google.com.gi *.google.gl *.google.gm *.google.gr *.google.com.gt *.google.gy *.google.com.hk *.google.hn *.google.hr *.google.ht *.google.hu *.google.co.id *.google.ie *.google.co.il *.google.im *.google.co.in *.google.iq *.google.is *.google.it *.google.je *.google.com.jm *.google.jo *.google.co.jp *.google.co.ke *.google.com.kh *.google.ki *.google.kg *.google.co.kr *.google.com.kw *.google.kz *.google.la *.google.com.lb *.google.li *.google.lk *.google.co.ls *.google.lt *.google.lu *.google.lv *.google.com.ly *.google.co.ma *.google.md *.google.me *.google.mg *.google.mk *.google.ml *.google.com.mm *.google.mn *.google.ms *.google.com.mt *.google.mu *.google.mv *.google.mw *.google.com.mx *.google.com.my *.google.co.mz *.google.com.na *.google.com.ng *.google.com.ni *.google.ne *.google.nl *.google.no *.google.com.np *.google.nr *.google.nu *.google.co.nz *.google.com.om *.google.com.pa *.google.com.pe *.google.com.pg *.google.com.ph *.google.com.pk *.google.pl *.google.pn *.google.com.pr *.google.ps *.google.pt *.google.com.py *.google.com.qa *.google.ro *.google.ru *.google.rw *.google.com.sa *.google.com.sb *.google.sc *.google.se *.google.com.sg *.google.sh *.google.si *.google.sk *.google.com.sl *.google.sn *.google.so *.google.sm *.google.sr *.google.st *.google.com.sv *.google.td *.google.tg *.google.co.th *.google.com.tj *.google.tl *.google.tm *.google.tn *.google.to *.google.com.tr *.google.tt *.google.com.tw *.google.co.tz *.google.com.ua *.google.co.ug *.google.co.uk *.google.com.uy *.google.co.uz *.google.com.vc *.google.co.ve *.google.vg *.google.co.vi *.google.com.vn *.google.vu *.google.ws *.google.rs *.google.co.za *.google.co.zm *.google.co.zw *.google.cat https://umfworldwide.com https://ultrapassport.com https://umfstage.com https://london.resistancemusic.com https://warsaw.resistancemusic.com https://resistanceibiza.com https://ultraeurope.com https://ultrasouthafrica.com https://ultranewzealand.com https://ultrabuenosaires.com https://ultraperu.com https://ultraaustralia.com https://ultramusicfestival.com https://resistancemiami.com https://medellin.resistancemusic.com https://santiago.resistancemusic.com https://lima.resistancemusic.com https://ultrataiwan.com https://guatemala.roadtoultra.com https://ecuador.roadtoultra.com https://ultrajapan.com https://ultrahongkong.com https://ultrakorea.com https://resistancemusic.com https://ultrabali.com https://ultrachile.com https://thailand.roadtoultra.com https://india.roadtoultra.com https://ultraabudhabi.com https://costadelsol.ultrabeach.com https://costarica.roadtoultra.com https://ultrabrasil.com https://buenosaires.resistancemusic.com https://guatemala.resistancemusic.com https://colombia.roadtoultra.com https://australia.resistancemusic.com https://mexico.resistancemusic.com https://santacruz.resistancemusic.com https://panama.resistancemusic.com https://sanjose.resistancemusic.com https://uruguay.resistancemusic.com https://ultrasingapore.com https://ultramexico.com https://quito.resistancemusic.com https://ultrabeijing.com https://ultrashanghai.com https://philippines.roadtoultra.com https://paraguay.roadtoultra.com https://roadtoultra.com https://bolivia.roadtoultra.com https://*.umfworldwide.com https://*.ultrapassport.com https://*.umfstage.com https://*.london.resistancemusic.com https://*.warsaw.resistancemusic.com https://*.resistanceibiza.com https://*.ultraeurope.com https://*.ultrasouthafrica.com https://*.ultranewzealand.com https://*.ultrabuenosaires.com https://*.ultraperu.com https://*.ultraaustralia.com https://*.ultramusicfestival.com https://*.resistancemiami.com https://*.medellin.resistancemusic.com https://*.santiago.resistancemusic.com https://*.lima.resistancemusic.com https://*.ultrataiwan.com https://*.guatemala.roadtoultra.com https://*.ecuador.roadtoultra.com https://*.ultrajapan.com https://*.ultrahongkong.com https://*.ultrakorea.com https://*.resistancemusic.com https://*.ultrabali.com https://*.ultrachile.com https://*.thailand.roadtoultra.com https://*.india.roadtoultra.com https://*.ultraabudhabi.com https://*.costadelsol.ultrabeach.com https://*.costarica.roadtoultra.com https://*.ultrabrasil.com https://*.buenosaires.resistancemusic.com https://*.guatemala.resistancemusic.com https://*.colombia.roadtoultra.com https://*.australia.resistancemusic.com https://*.mexico.resistancemusic.com https://*.santacruz.resistancemusic.com https://*.panama.resistancemusic.com https://*.sanjose.resistancemusic.com https://*.uruguay.resistancemusic.com https://*.ultrasingapore.com https://*.ultramexico.com https://*.quito.resistancemusic.com https://*.ultrabeijing.com https://*.ultrashanghai.com https://*.philippines.roadtoultra.com https://*.paraguay.roadtoultra.com https://*.roadtoultra.com https://*.bolivia.roadtoultra.com; media-src 'self' *.ultramusicfestival.com ultramusicfestival.com umfworldwide.com ultrapassport.com *.ultrapassport.net resistancemusic.com *.resistancemusic.com roadtoultra.com *.roadtoultra.com *.olark.com; connect-src 'self' *.ultramusicfestival.com ultramusicfestival.com umfworldwide.com ultrapassport.com *.ultrapassport.net resistancemusic.com *.resistancemusic.com roadtoultra.com *.roadtoultra.com cloudflareinsights.com *.datadoghq.com *.browser-intake-datadoghq.com *.getclicky.com *.facebook.com analytics.tiktok.com analytics.pangle-ads.com *.olark.com *.googletagmanager.com *.google-analytics.com analytics.google.com *.analytics.google.com *.g.doubleclick.net *.doubleclick.net *.google.com *.googlesyndication.com www.googletagservices.com *.google.ad *.google.ae *.google.com.af *.google.com.ag *.google.com.ai *.google.al *.google.am *.google.co.ao *.google.com.ar *.google.as *.google.at *.google.com.au *.google.az *.google.ba *.google.com.bd *.google.be *.google.bf *.google.bg *.google.com.bh *.google.bi *.google.bj *.google.com.bn *.google.com.bo *.google.com.br *.google.bs *.google.bt *.google.co.bw *.google.by *.google.com.bz *.google.ca *.google.cd *.google.cf *.google.cg *.google.ch *.google.ci *.google.co.ck *.google.cl *.google.cm *.google.cn *.google.com.co *.google.co.cr *.google.com.cu *.google.cv *.google.com.cy *.google.cz *.google.de *.google.dj *.google.dk *.google.dm *.google.com.do *.google.dz *.google.com.ec *.google.ee *.google.com.eg *.google.es *.google.com.et *.google.fi *.google.com.fj *.google.fm *.google.fr *.google.ga *.google.ge *.google.gg *.google.com.gh *.google.com.gi *.google.gl *.google.gm *.google.gr *.google.com.gt *.google.gy *.google.com.hk *.google.hn *.google.hr *.google.ht *.google.hu *.google.co.id *.google.ie *.google.co.il *.google.im *.google.co.in *.google.iq *.google.is *.google.it *.google.je *.google.com.jm *.google.jo *.google.co.jp *.google.co.ke *.google.com.kh *.google.ki *.google.kg *.google.co.kr *.google.com.kw *.google.kz *.google.la *.google.com.lb *.google.li *.google.lk *.google.co.ls *.google.lt *.google.lu *.google.lv *.google.com.ly *.google.co.ma *.google.md *.google.me *.google.mg *.google.mk *.google.ml *.google.com.mm *.google.mn *.google.ms *.google.com.mt *.google.mu *.google.mv *.google.mw *.google.com.mx *.google.com.my *.google.co.mz *.google.com.na *.google.com.ng *.google.com.ni *.google.ne *.google.nl *.google.no *.google.com.np *.google.nr *.google.nu *.google.co.nz *.google.com.om *.google.com.pa *.google.com.pe *.google.com.pg *.google.com.ph *.google.com.pk *.google.pl *.google.pn *.google.com.pr *.google.ps *.google.pt *.google.com.py *.google.com.qa *.google.ro *.google.ru *.google.rw *.google.com.sa *.google.com.sb *.google.sc *.google.se *.google.com.sg *.google.sh *.google.si *.google.sk *.google.com.sl *.google.sn *.google.so *.google.sm *.google.sr *.google.st *.google.com.sv *.google.td *.google.tg *.google.co.th *.google.com.tj *.google.tl *.google.tm *.google.tn *.google.to *.google.com.tr *.google.tt *.google.com.tw *.google.co.tz *.google.com.ua *.google.co.ug *.google.co.uk *.google.com.uy *.google.co.uz *.google.com.vc *.google.co.ve *.google.vg *.google.co.vi *.google.com.vn *.google.vu *.google.ws *.google.rs *.google.co.za *.google.co.zm *.google.co.zw *.google.cat; frame-src 'self' *.ultramusicfestival.com ultramusicfestival.com umfworldwide.com ultrapassport.com *.ultrapassport.net resistancemusic.com *.resistancemusic.com roadtoultra.com *.roadtoultra.com *.zohopublic.com *.apple.com open.spotify.com *.soundcloud.com *.youtube.com *.youtube-nocookie.com www.facebook.com *.recaptcha.net recaptcha.net www.google.com recaptcha.google.com *.olark.com *.googletagmanager.com bid.g.doubleclick.net *.google.com *.doubleclick.net *.googlesyndication.com; child-src *.youtube.com *.youtube-nocookie.com *.googletagmanager.com; worker-src www.recaptcha.net; object-src *.googlesyndication.com; report-uri https://csp-report.browser-intake-datadoghq.com/api/v2/logs?dd-api-key=pub7c55919a7d54d6386d0f0b19bc82e82f&dd-evp-origin=content-security-policy&ddsource=csp-report; 2 default-src 'self' https://*.adnxs.com https://*.avanser.com https://*.hubapi.com https://*.algolia.com https://*.algolia.net https://*.algolianet.com https://*.readspeaker.com https://*.cloudflare.com https://*.facebook.net https://*.cdnfonts.com https://*.googleapis.com https://*.gstatic.com https://*.hs-analytics.net https://*.hs-banner.com https://*.hsforms.net https://*.hs-scripts.com https://*.hsleadflows.net https://*.hsadspixel.net https://*.hsform.com https://*.hubspot.com https://*.google.com.au https://*.google-analytics.com https://*.googletagmanager.com https://*.clarity.ms https://*.doubleclick.net https://*.cdninstagram.com https://*.myhealthforlife.com.au https://*.myhealthforlife.org.au https://*.newrelic.com https://*.vimeo.com https://*.raisely.com https://*.siteimproveanalytics.com https://*.hotjar.com https://*.licdn.com https://*.ewaypayments.com https://*.linkedin.com https://*.google.com https://*.doubleclick.net https://*.yimg.com https://*.youtube.com; object-src 'none'; img-src * data:; script-src 'self' https://*.adnxs.com https://*.avanser.com https://*.hubapi.com https://*.algolia.com https://*.algolia.net https://*.algolianet.com https://*.readspeaker.com https://*.cloudflare.com https://*.facebook.net https://*.cdnfonts.com https://*.googleapis.com https://*.gstatic.com https://*.hs-analytics.net https://*.hs-banner.com https://*.hsforms.net https://*.hs-scripts.com https://*.hsleadflows.net https://*.hsadspixel.net https://*.hsform.com https://*.hubspot.com https://*.google.com.au https://*.google-analytics.com https://*.googletagmanager.com https://*.clarity.ms https://*.doubleclick.net https://*.cdninstagram.com https://*.myhealthforlife.com.au https://*.myhealthforlife.org.au https://*.newrelic.com https://*.vimeo.com https://*.raisely.com https://*.siteimproveanalytics.com https://*.hotjar.com https://*.licdn.com https://*.ewaypayments.com https://*.linkedin.com https://*.google.com https://*.doubleclick.net https://*.yimg.com https://*.youtube.com; style-src 'self' * 'unsafe-inline'; font-src * data:; media-src *; frame-src *.vimeo.com *.googletagmanager.com *.doubleclick.net *.youtube.com; 2 font-src *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net https://www.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.googletagmanager.com www.google.com *.stevens.com.pa https://www.googletagmanager.com/ *.google.com/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com tracker.metricool.com www.facebook.com www.google.cl *.stevens.com.pa stevens.com.pa *.clau.io http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ https://www.magezon.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ chimpstatic.com downloads.mailchimp.com *.list-manage.com www.google.com rum-static.pingdom.net connect.facebook.net www.gstatic.com js-agent.newrelic.com bam.nr-data.net http://www.googletagmanager.com/ https://www.googletagmanager.com/ *.google.com/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com downloads.mailchimp.com *.fontawesome.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com bam.nr-data.net rum-collector-2.pingdom.net www.google.com.ar test-drive-11-s6uit34pua-uc.a.run.app http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src bam.nr-data.net www.google.com *.stevens.com.pa stevens.com.pa 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 font-src *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com https://cdnjs.cloudflare.com https://widgets.trustedshops.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ js.mollie.com *.weltpixel.com *.addthis.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * www.xtento.com www.googletagmanager.com js.stripe.com m.stripe.network www.facebook.com www.google.com tally.so 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://images.unsplash.com *.bird.eu https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://www.mollie.com *.disqus.com https://img.youtube.com https://firebasestorage.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com maps.gstatic.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com *.gstatic.com *.facebook.com www.xtento.com cdn.xtento.com www.burdastyle.fr www.facebook.com bat.bing.com *.burdastyle.fr *.burdastyle.com *.abo-online.fr *.burdastyle.es *.burdastyle.pt *.burdastyle.uk *.burdastyle.nl *.burdastyle.dk *.burdastyle.se *.burdastyle.pl *.faitmain-magazine.fr maps.googleapis.com www.google.fr data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://cdn.jsdelivr.net/npm/@ryangjchandler/spruce@2.x.x/dist/spruce.umd.js https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ js.mollie.com *.disqus.com *.addthis.com https://z.moatads.com https://v1.addthisedge.com https://cdn.jsdelivr.net *.avada.io https://cdnjs.cloudflare.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com maps.googleapis.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com https://www.googletagmanager.com tagmanager.google.com *.facebook.net unpkg.com www.xtento.com cdn.xtento.com static.klaviyo.com connect.facebook.net *.googletagmanager.com bat.bing.com js.stripe.com m.stripe.network analytics.tiktok.com static.cloudflareinsights.com static-tracking.klaviyo.com www.google.com www.gstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://static.klaviyo.com https://cdn.jsdelivr.net *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com https://fonts.googleapis.com https://cdnjs.cloudflare.com unsafe-inline assets.braintreegateway.com https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com maps.googleapis.com *.trustedshops.com *.etrusted.com https://integrations.etrusted.site *.google-analytics.com *.facebook.net *.a.klaviyo.com static-forms.klaviyo.com bat.bing.com m.stripe.com www.google.com www.google.fr region1.analytics.google.co 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 default-src 'self' https:; script-src 'self' 'unsafe-inline' 'unsafe-eval' https:; style-src 'self' 'unsafe-inline' https:; img-src 'self' data: https:; frame-src 'self' https:; connect-src 'self' https:; report-to csp-endpoint; 2 default-src 'self'; base-uri 'self'; frame-ancestors 'self'; object-src 'none'; worker-src 'self' blob:; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://api.w3-edge.com https://www.googletagmanager.com https://www.googletagservices.com https://cdn.privacy-mgmt.com https://cdnjs.cloudflare.com https://secure.hook6vein.com https://a.usbrowserspeed.com https://www.details-enterprise-7.com https://pi.pardot.com https://www.google.com https://www.google-analytics.com https://go.skymedia.co.uk https://js-agent.newrelic.com https://bam.nr-data.net https://yoast.com https://ajax.googleapis.com https://assets.adobedtm.com https://www.gstatic.com https://skymediaglobal.b-cdn.net https://cdn.skymedia.de https://cdn.skymedia.ie https://cdn.skymedia.co.uk https://cdn.adsmartfromsky.co.uk https://cdn.adsmartfromsky.ie https://cdn.cflight.co.uk https://gdpr-tcfv2.sp-prod.net https://fluid.4strokemedia.com https://cdnb.4strokemedia.com https://z.moatads.com https://imasdk.googleapis.com https://pagead2.googlesyndication.com https://s0.2mdn.net;connect-src 'self' https://bam.nr-data.net https://cdn.privacy-mgmt.com https://my.yoast.com https://www.skymedia.co.uk https://cdn.skymedia.co.uk https://cdn.skymedia.ie https://cmp.skymedia.de https://edge.adobedc.net https://region1.google-analytics.com https://www.google-analytics.com https://www.google.com https://fluid.4strokemedia.com https://feed.4strokemedia.com https://api.condatis.sky https://playback.brightcovecdn.com https://videos.skysports.com https://manifest.prod.boltdns.net https://securepubads.g.doubleclick.net https://videos.skynews.com https://csi.gstatic.com https://idx.liadm.com; img-src 'self' data: https: https://skymediaglobal.b-cdn.net https://cdn.skymedia.de https://cdn.skymedia.ie https://cdn.skymedia.co.uk https://cdn.adsmartfromsky.co.uk https://cdn.adsmartfromsky.ie; font-src 'self' data: https://fonts.gstatic.com https://skymediaglobal.b-cdn.net https://cdn.skymedia.de https://cdn.skymedia.ie https://cdn.skymedia.co.uk https://cdn.adsmartfromsky.co.uk https://cdn.adsmartfromsky.ie https://fonts.bunny.net; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://skymediaglobal.b-cdn.net https://cdn.skymedia.de https://cdn.skymedia.ie https://cdn.skymedia.co.uk https://cdn.adsmartfromsky.co.uk https://cdn.adsmartfromsky.ie https://fonts.bunny.net;media-src 'self' https: blob: https://skymediaglobal.b-cdn.net https://cdn.skymedia.de https://cdn.skymedia.ie https://cdn.skymedia.co.uk https://cdn.adsmartfromsky.co.uk https://cdn.adsmartfromsky.ie https://playback.brightcovecdn.com https://videos.skysports.com https://videos.skynews.com;frame-src 'self' https://www.google.com https://www.gstatic.com https://www.recaptcha.net https://players.brightcove.net https://www.youtube.com https://securepubads.g.doubleclick.net https://tpc.googlesyndication.com https://cdn.privacy-mgmt.com https://skymediaglobal.b-cdn.net https://cdn.skymedia.de https://cdn.skymedia.ie https://cdn.skymedia.co.uk https://cdn.adsmartfromsky.co.uk https://cdn.adsmartfromsky.ie; 2 font-src https://www.gstatic.com https://fonts.gstatic.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src bid.g.doubleclick.net player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com https://*.google.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com js.mollie.com *.sendcloud.sc *.jsdelivr.net https://www.googletagmanager.com https://td.doubleclick.net 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com *.youtube.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com https://images.unsplash.com https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.googleusercontent.com magefan.com cm.magefan.com *.disqus.com https://img.youtube.com *.sooqr.com *.spotlersearch.com https://www.mollie.com *.amazonaws.com epc.het-magazijn.com https://imgproxy.vendic.dev www.ghmparts.com https://pagead2.googlesyndication.com data: 'self' 'unsafe-inline'; script-src googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com https://maps.googleapis.com https://browser.sentry-cdn.com https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com *.disqus.com *.sooqr.com *.spotlersearch.com spotlersearchanalytics.com js.mollie.com *.sendcloud.sc *.jsdelivr.net https://cdn.cookie-script.com https://static.cloudflareinsights.com https://d5yoctgpv4cpx.cloudfront.net https://pagead2.googlesyndication.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src https://fonts.googleapis.com https://hcaptcha.com https://*.hcaptcha.com *.fontawesome.com *.sooqr.com *.spotlersearch.com *.sendcloud.sc *.jsdelivr.net https://www.vizeo.nl 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://maps.googleapis.com https://player.vimeo.com https://*.ingest.sentry.io https://ipinfo.io https://www.google.com https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com *.sooqr.com *.spotlersearch.com *.sendcloud.sc *.cdn.jsdelivr.net *.mapbox.com https://pagead2.googlesyndication.com https://p2iqhncxyh.execute-api.eu-central-1.amazonaws.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 font-src *.agrialpro.fr *.lamaison.fr fonts.gstatic.com https://cdnjs.cloudflare.com *.gstatic.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors dynamic.criteo.com api.oney.io 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.googletagmanager.com gum.criteo.com youtu.be facebook.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io magefan.com cm.magefan.com *.agrialpro.fr *.lamaison.fr maps.gstatic.com maps.google.com maps.googleapis.com cl.avis-verifies.com www.google.fr www.facebook.com *.dmxleo.com *.bidswitch.net *.adform.net *.casalemedia.com *.criteo.com sync.1rx.io sync.targeting.unrulymedia.com *.id5-sync.com id5-sync.com *.ivitrack.com *.mediavine.com *.postrelease.com *.outbrain.com *.pubmatic.com *.yieldmo.com *.yieldlab.net *.emxdgt.com *.doubleclick.net *.adnxs.com *.media.net *.rubiconproject.com *.smartadserver.com *.taboola.com *.teads.tv *.yahoo.net *.3lift.com *.omnitagjs.com *.360yield.com *.sharethrough.com *.tremorhub.com *.krxd.net *.join-stories.com ade.googlesyndication.com *.hsforms.net *.hsforms.com *.disqus.com https://img.youtube.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com 'self' data: data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://rum.hlx.page maps.google.com maps.googleapis.com *.agrialpro.fr *.lamaison.fr cdn.jsdelivr.net cl.avis-verifies.com connect.facebook.net js-agent.newrelic.com *.criteo.com bam.nr-data.net *.join-stories.com cdn.webotit.ai secure.adnxs.com *.hsforms.net *.hsforms.com *.disqus.com https://cdn.jsdelivr.net/npm/pwacompat@2.0.8/pwacompat.min.js https://widgets.rr.skeepers.io/ https://api-product-reviews.cxr.skeepers.io/ https://cl-ppr.rr.skeepers.io/ https://cl-pbr.cxr.skeepers.io/ https://cdnjs.cloudflare.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.google.com *.gstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.agrialpro.fr *.lamaison.fr https://fonts.googleapis.com https://cdnjs.cloudflare.com unsafe-inline assets.braintreegateway.com *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.join-stories.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.agrialpro.fr *.lamaison.fr stats.g.doubleclick.net bam.nr-data.net *.criteo.com maps.googleapis.com *.stories.studio t.elasticsuite.io *.hsforms.net *.hsforms.com https://widgets.rr.skeepers.io/ https://api-product-reviews.cxr.skeepers.io/ https://cl-ppr.rr.skeepers.io/ https://cl-pbr.cxr.skeepers.io/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.google-analytics.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 default-src * 'unsafe-inline' 'unsafe-eval' data: blob:; 2 default-src 'self'; script-src 'report-sample' 'self' 'unsafe-inline' 'unsafe-eval' https://static.zdassets.com https://region1.google-analytics.com https://v2.zopim.com https://ajax.googleapis.com https://analytics.silktide.com https://analytics.tiktok.com https://api.reciteme.com/asset/js https://app.geckoform.com https://cdn.populo-services.com https://connect.facebook.net https://embed.geckochat.io https://googleads.g.doubleclick.net https://l.getsitecontrol.com https://sc-static.net/scevent.min.js https://script.hotjar.com https://static.hotjar.com https://tr.snapchat.com https://www.googletagmanager.com https://cdn.populo-services.com https://www.gstatic.com; style-src 'report-sample' 'self' 'unsafe-inline' https://fonts.geckoform.com https://fonts.gstatic.com/ https://embed.geckochat.io https://fonts.googleapis.com; object-src 'none'; base-uri 'self'; connect-src 'self' https://cms-stmarys.cloud.contensis.com https://surveystats.hotjar.io https://googleads.g.doubleclick.net https://capigateway.adaptworldwide.com wss://widget-mediator.zopim.com https://router-euwest2.geckochat.io https://stats.g.doubleclick.net https://www.google.com https://region1.google-analytics.com https://pagead2.googlesyndication.com https://a.eu.silktide.com https://analytics.tiktok.com https://api.geckochat.io https://ekr.zdassets.com https://l.getsitecontrol.com https://region1.analytics.google.com https://tr.snapchat.com https://tr6.snapchat.com https://www.google.co.uk https://www.google.com https://www.googleadservices.com https://app.geckoform.com; font-src 'self' https://script.hotjar.com https://fonts.geckoform.com https://embed.geckochat.io https://fonts.gstatic.com/; frame-src 'self' https://app.geckoform.com https://td.doubleclick.net https://tr.snapchat.com https://www.youtube.com; img-src 'self' data: https://survey-images.hotjar.com https://img.youtube.com https://www.googletagmanager.com https://widget-assets.geckochat.io https://www.facebook.com https://i.ytimg.com https://populo.populo-services.com https://www.google.co.uk https://www.google.com; manifest-src 'self'; media-src 'self' https://audio.geckochat.io; worker-src 'none'; 2 font-src *.fontawesome.com fonts.googleapis.com https://www.gstatic.com https://fonts.gstatic.com fonts.gstatic.com *.yotpo.com *.googleapis.com *.gstatic.com dhv2ziothpgrr.cloudfront.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors *.certcapture.com 'self' 'unsafe-inline'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.certcapture.com *.weltpixel.com https://*.google.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com *.wesupply.xyz https://wesupplylabs.com guarantee-cdn.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.googletagmanager.com *.doubleclick.net www.xtento.com *.yotpo.com https://*.online-metrix.net https://imgs.signifyd.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.certcapture.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.googleusercontent.com maps.googleapis.com maps.gstatic.com guarantee-cdn.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.gstatic.com *.facebook.com *.reddit.com *.ads-twitter.com t.co *.twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.google-analytics.com *.googletagmanager.com *.doubleclick.net *.google.com www.xtento.com cdn.xtento.com *.yotpo.com dhv2ziothpgrr.cloudfront.net https://imgs.signifyd.com https://*.online-metrix.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://rum.hlx.page *.certcapture.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com maps.googleapis.com get.geojs.io *.cloudflare.com guarantee-cdn.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googletagmanager.com *.googleadservices.com *.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.bing.com *.clarity.ms *.klaviyo.com unpkg.com *.doubleclick.net www.xtento.com cdn.xtento.com *.yotpo.com dhv2ziothpgrr.cloudfront.net *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com d18eg7dreypte5.cloudfront.net https://cdn-scripts.signifyd.com https://imgs.signifyd.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.certcapture.com https://static.klaviyo.com *.fontawesome.com fonts.googleapis.com https://fonts.googleapis.com https://hcaptcha.com https://*.hcaptcha.com *.googleapis.com *.addtoany.com unsafe-inline assets.braintreegateway.com *.tagmanager.google.com *.googletagmanager.com *.yotpo.com dhv2ziothpgrr.cloudfront.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.certcapture.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://ipinfo.io https://*.google.com https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com maps.googleapis.com http://dpm.demdex.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.google-analytics.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.doubleclick.net *.run.app *.yotpo.com dhv2ziothpgrr.cloudfront.net *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com https://imgs.signifyd.com 'self' 'unsafe-inline'; child-src *.certcapture.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 script-src 'self' 'unsafe-inline' 'unsafe-eval' https://stanleysteemer.com https://static.ads-twitter.com https://analytics.tiktok.com https://widget-prime.rafflecopter.com https://www.googletagmanager.com https://view.ceros.com https://amplify.review-alerts.com https://ajax.googleapis.com https://labs.ceros.com https://api.ipify.org https://sdk.ceros.com https://cdn.chatavise.com https://apps.usw2.pure.cloud https://maps.googleapis.com https://apis.google.com https://cdn.cookielaw.org https://api.ipify.org https://*.api.ipify.org https://www.google-analytics.com https://schema-cf.bc0a.com https://*.audioeye.com https://f.vimeocdn.com https://www.gstatic.com https://fonts.gstatic.com https://marvel-b1-cdn.bc0a.com https://s.pinimg.com https://snap.licdn.com https://connect.facebook.net https://googleads.g.doubleclick.net https://ct.pinterest.com https://static.hotjar.com https://script.hotjar.com https://i.loopme.me https://bat.bing.com https://*.tvsquared.com https://cdn.chatavise.com https://www.googleadservices.com https://www.google.com https://bam.nr-data.net https://js-agent.newrelic.com; connect-src 'self' blob: 'unsafe-inline' https://www.google-analytics.com https://analytics.tiktok.com https://www.facebook.com https://bat.bing.com https://adservice.google.com https://bam.nr-data.net https://maps.googleapis.com https://cdn.cookielaw.org https://analytics.google.com https://*.bc0a.com https://qa.metrics.stanleysteemer.com https://ct.pinterest.com https://*.linkedin.com https://gdpr.loopme.com https://*.audioeye.com https://*.vimeocdn.com https://*.onetrust.com https://*.doubleclick.net https://vimeo.com https://www.google.com https://api.chatavise.com; report-uri https://66787c15d528e3ceb6b0d8fe.endpoint.csper.io/?v=0 2 font-src https://www.googletagmanager.com *.googleapis.com *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.fontawesome.com https://fonts.gstatic.com *.typekit.net *.optimonk.com *.guidebot.org guidebot.org *.taggrs.cloud *.taggrs.io google.ro google.sk google.at google.it google.fr google.de google.nl google.si google.co-uk *.google.ro *.google.sk *.google.at *.google.it *.google.fr *.google.de *.google.nl *.google.si *.google.co-uk data: 'self' 'unsafe-inline'; form-action *.facebook.com *.google.com test.saferpay.com www.saferpay.com saferpay.com *.cardinalcommerce.com *.paypal.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ www.google.com *.google.com/ *.doubleclick.net *.facebook.com *.weltpixel.com test.saferpay.com www.saferpay.com saferpay.com https://player.vimeo.com https://www.youtube-nocookie.com *.pinterest.com/ *.gorgias.chat *.gorgias.io *.hotjar.com *.pinimg.com *.tiktok.com *.polyfill.io *.profitmetrics.io *.clarity.ms *.amplitude.com *.google.com *.google.hu *.google.ie *.google.sk *.google.ro *.google.co.in *.cookiebot.com *.optimonk.com *.luigisbox.com *.luigisbox.tech *.diego.itg.cloud facebook.com youtube.com pinterest.com/ gorgias.chat gorgias.io hotjar.com pinimg.com tiktok.com polyfill.io profitmetrics.io clarity.ms amplitude.com google.com google.hu google.ie google.sk google.ro google.co.in doubleclick.net cookiebot.com optimonk.com luigisbox.com diego.itg.cloud www.paypal.com www.sandbox.paypal.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com https://consentcdn.cookiebot.com *.googletagmanager.com *.diego.hu *.guidebot.org guidebot.org *.taggrs.cloud *.taggrs.io google.at google.it google.fr google.de google.nl google.si google.co-uk *.google.at *.google.it *.google.fr *.google.de *.google.nl *.google.si *.google.co-uk www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.gstatic.com *.googleapis.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.google-analytics.com test.saferpay.com www.saferpay.com saferpay.com magefan.com cm.magefan.com https://www.magezon.com blob: https://updates.themepunch.tools http://updates.themepunch.tools https://updates.themepunch-ext-a.tools http://updates.themepunch-ext-a.tools https://updates.themepunch-ext-b.tools http://updates.themepunch-ext-b.tools https://dev.sliderrevolution.com https://revolution.themepunch.com http://revolution5.themepunch.com http://pbs.twimg.com https://pbs.twimg.com http://scontent.cdninstagram.com https://img.youtube.com http://live.staticflickr.com https://live.staticflickr.com *.pinterest.com/ *.gorgias.chat *.gorgias.io *.hotjar.com *.pinimg.com *.tiktok.com *.polyfill.io *.profitmetrics.io *.clarity.ms *.amplitude.com *.google.hu *.google.ie *.google.sk *.google.ro *.google.co.in *.cookiebot.com *.optimonk.com *.luigisbox.com *.luigisbox.tech *.diego.itg.cloud maps.gstatic.com www.paypal.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.hsforms.net *.hsforms.com *.diego.hu *.taggrs.io *.bing.com *.guidebot.org guidebot.org *.taggrs.cloud google.ro google.sk google.at google.it google.fr google.de google.nl google.si google.co-uk *.google.at *.google.it *.google.fr *.google.de *.google.nl *.google.si *.google.co-uk www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ tagmanager.google.com https://www.googletagmanager.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.googleapis.com *.gstatic.com *.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com test.saferpay.com www.saferpay.com saferpay.com player.vimeo.com https://player.vimeo.com https://www.youtube.com *.adobedtm.com *.pinterest.com/ *.gorgias.chat *.gorgias.io *.hotjar.com *.pinimg.com *.tiktok.com *.polyfill.io *.profitmetrics.io *.clarity.ms *.amplitude.com *.google.hu *.google.ie *.google.sk *.google.ro *.google.co.in *.cookiebot.com *.optimonk.com *.luigisbox.tech *.diego.itg.cloud facebook.net adobedtm.com adobe.com googleapis.com pinterest.com/ gorgias.chat gorgias.io hotjar.com pinimg.com tiktok.com polyfill.io profitmetrics.io clarity.ms amplitude.com google.com google.hu google.ie google.sk google.ro google.co.in doubleclick.net cookiebot.com optimonk.com luigisbox.com diego.itg.cloud www.paypal.com www.sandbox.paypal.com www.paypalobjects.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com *.hsforms.net *.hsforms.com *.dyn-rev.app stapecdn.com *.guidebot.org guidebot.org *.taggrs.cloud *.taggrs.io google.at google.it google.fr google.de google.nl google.si google.co-uk *.google.at *.google.it *.google.fr *.google.de *.google.nl *.google.si *.google.co-uk www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://www.googletagmanager.com tagmanager.google.com *.googleapis.com fonts.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.fontawesome.com https://fonts.googleapis.com http://fonts.googleapis.com *.typekit.net *.optimonk.com *.pinterest.com unsafe-inline 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com blob: 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com https://www.google-analytics.com *.googleapis.com *.google-analytics.com *.facebook.com *.facebook.net *.google.com test.saferpay.com www.saferpay.com saferpay.com https://fonts.googleapis.com https://fonts.gstatic.com https://api.weatherbit.io *.pinterest.com/ *.gorgias.chat *.gorgias.io *.hotjar.com *.pinimg.com *.tiktok.com *.polyfill.io *.profitmetrics.io *.clarity.ms *.amplitude.com *.google.hu *.google.ie *.google.sk *.google.ro *.google.co.in *.doubleclick.net *.cookiebot.com *.optimonk.com *.luigisbox.com *.luigisbox.tech *.diego.itg.cloud pinterest.com/ gorgias.chat gorgias.io hotjar.com pinimg.com tiktok.com polyfill.io profitmetrics.io clarity.ms amplitude.com google.com google.hu google.ie google.sk google.ro google.co.in doubleclick.net cookiebot.com optimonk.com luigisbox.com diego.itg.cloud maps.googleapis.com www.paypal.com www.sandbox.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.diego.hu gorgias-convert.com *.googlesyndication.com region1.google-analytics.com *.guidebot.org guidebot.org *.taggrs.cloud *.taggrs.io google.at google.it google.fr google.de google.nl google.si google.co-uk *.google.at *.google.it *.google.fr *.google.de *.google.nl *.google.si *.google.co-uk 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src test.saferpay.com www.saferpay.com saferpay.com *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 default-src 'self' https:; script-src 'self' 'unsafe-eval' https://www.googletagmanager.com https://*.google-analytics.com https://*.googleadservices.com https://*.company-target.com https://a.omappapi.com https://stage-cms-portal.quest.com https://www.quest.com https://*.qualified.com https://*.ddev.site https://cdn.cookielaw.org https://app.qualified.com https://*.qualified.com https://cdn.cookielaw.org https://s.company-target.com 'nonce-1Okut-hRZ0H4RZNZQvFH-C_Pujtgm30r'; object-src 'none'; style-src 'self' 'unsafe-inline' *.google.com *.userway.org *.googleapis.com *.analysis.windows.net *.twitter.com *.nr-data.net *.youtube.com *.youtube-nocookie.com *.vimeo.com *.pagespeed-mod.com *.googletagmanager.com *.gstatic.com *.sharethis.com *.gleap.io *.cloudflare.com *.jsdelivr.net *.gitbook.com *.omappapi.com/; img-src 'self' 'unsafe-inline' https: data: quest.com *.quest.com blob:; media-src 'self' 'unsafe-inline' quest.com *.quest.com; frame-src 'self' 'unsafe-inline' *.webp *.twitter.com *.youtube.com *.youtube-nocookie.com *.facebook.com facebook.com *.nr-data.net *.youtube.com *.vimeo.com *.googletagmanager.com *.gleap.io *.company-target.com players.brightcove.net *.gitbook.io https://app.qualified.com; frame-ancestors 'self' *.google.com *.google-analytics.com *.analysis.windows.net *.googleapis.com *.twitter.com *.nr-data.net *.youtube.com *.youtube-nocookie.com *.vimeo.com *.pagespeed-mod.com *.googletagmanager.com *.gstatic.com *.sharethis.com *.gleap.io *.company-target.com; child-src *; font-src 'self' *.googleapis.com *.typekit.net *.userway.org *.analysis.windows.net *.gstatic.com *.twitter.com *.nr-data.net *.youtube.com *.youtube-nocookie.com *.vimeo.com *.pagespeed-mod.com *.googletagmanager.com data *.sharethis.com *.google.com *.gleap.io *.jsdelivr.net *.cloudflare.com; connect-src 'self' *.google-analytics.com *.vardot.com https: *.gleap.io 2 font-src maxcdn.bootstrapcdn.com *.lasportivausa.com data: *.googleapis.com *.gstatic.com *.bootstrapcdn.com *.klaviyo.com *.locally.com *.typekit.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com api.bazaarvoice.com stg.api.bazaarvoice.com https://plumrocket.com 'self' *.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.lasportivausa.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.sharethis.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com connect.bolt.com connect-sandbox.bolt.com account.bolt.com account-sandbox.bolt.com https://plumrocket.com *.weltpixel.com *.facebook.com connect.facebook.net graph.facebook.com business.facebook.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.lasportivausa.com *.doubleclick.net *.google.com *.googleapis.com *.vimeo.com *.addthis.com *.pinterest.com disqus.com *.bazaarvoice.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.sharethis.com display.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com network-a.bazaarvoice.com network-stg-a.bazaarvoice.com photos-uat-us.bazaarvoice.com img.youtube.com connect.bolt.com connect-sandbox.bolt.com s3-us-west-1.amazonaws.com magefan.com cm.magefan.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.lasportivausa.com *.google.com *.googleapis.com *.gstatic.com *.googlesyndication.com via.placeholder.com *.pinterest.com *.disqus.com *.addthis.com *.bazaarvoice.com *.curalate.com *.viglink.com *.klaviyo.com *.locally.com *.doubleclick.net *.cloudfront.net *.avantlink.com *.localizecdn.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.sharethis.com apps.bazaarvoice.com apps.nexus.bazaarvoice.com apps-stg.nexus.bazaarvoice.com analytics-static.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com mpsnare.iesnare.com connect.bolt.com connect-sandbox.bolt.com account.bolt.com account-sandbox.bolt.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.lasportivausa.com bam.nr-data.net cdnjs.cloudflare.com *.cookielaw.org *.doubleclick.net *.google.com *.googleapis.com *.gstatic.com js-agent.newrelic.com *.newrelic.com player.vimeo.com *.addthis.com *.addthisedge.com *.moatads.com *.avmws.com *.pinimg.com *.pinterest.com *.disqus.com *.disquscdn.com *.bazaarvoice.com *.locally.com *.curalate.com *.experticity.com *.eventscalendar.co *.localizecdn.com https://global.localizecdn.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.sharethis.com display.ugc.bazaarvoice.com maxcdn.bootstrapcdn.com https://static.klaviyo.com unsafe-inline assets.braintreegateway.com *.lasportivausa.com *.disquscdn.com *.bazaarvoice.com *.googleapis.com *.typekit.net *.localizecdn.com 'self' 'unsafe-inline'; object-src connect.bolt.com connect-sandbox.bolt.com account.bolt.com account-sandbox.bolt.com *.bolt.com 'self' 'unsafe-inline'; media-src *.adobe.com *.lasportivausa.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.sharethis.com api.bazaarvoice.com stg.api.bazaarvoice.com apps.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com connect.bolt.com connect-sandbox.bolt.com account.bolt.com account-sandbox.bolt.com sessions.bugsnag.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.facebook.com connect.facebook.net graph.facebook.com business.facebook.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.lasportivausa.com bam.nr-data.net *.doubleclick.net *.googleapis.com *.googlesyndication.com *.pinterest.com *.disqus.com *.addthis.com *.bazaarvoice.com *.curalate.com *.locally.com *.eventscalendar.co *.mixpanel.com *.localizecdn.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.lasportivausa.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 default-src 'self' 846-hel-222.mktoresp.com 173-dti-322.mktoresp.com 059-alg-683.mktoresp.com js.zi-scripts.com static.addtoany.com stats.g.doubleclick.net tracking-api.g2.com play.google.com www.google.com; connect-src 'self' 846-hel-222.mktoweb.com analytics.google.com c.6sc.co ipv6.6sc.co cdn.cookielaw.org distillery.wistia.com fast.wistia.com pipedream.wistia.com geolocation.onetrust.com epsilon.6sense.com secure.adnxs.com ws.zoominfo.com px.ads.linkedin.com www.google.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net jnn-pa.googleapis.com api.simplecast.com cdn.simplecast.com givebutter.com umsafoundation.org www.youtube.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com pagead2.googlesyndication.com google.com stats.g.doubleclick.net js.zi-scripts.com privacyportal-eu.onetrust.com 846-hel-222.mktoresp.com app.qualified.com tracking-api.g2.com tr.capterra.com 173-dti-322.mktoresp.com embed-cloudfront.wistia.com *.clarity.ms 173-dti-322.mktoutil.com www.google.com.co; font-src 'self' www.perforce.com www.blazemeter.com www.gliffy.com www.jrebel.com www.openlogic.com www.zend.com www.puppet.com www.perfecto.io fonts.gstatic.com cdn.simplecast.com data: fast.wistia.com use.typekit.net www.gartner.com; frame-src 'self' 846-hel-222.mktoweb.com 173-dti-322.mktoresp.com 059-alg-683.mktoresp.com resources.perforce.com static.addtoany.com www.googletagmanager.com www.perforce.com www.blazemeter.com www.gliffy.com www.jrebel.com www.openlogic.com www.zend.com www.puppet.com www.perfecto.io fast.wistia.net player.simplecast.com www.youtube.com umsafoundation.org live-totalview.pantheonsite.io live-imsl.pantheonsite.io www.google.com app.qualified.com fast.wistia.com player.vimeo.com player.captivate.fm 605957.extforms.netsuite.com www.gartner.com; img-src 'self' data: b.6sc.co c.bing.com bat.bing.com *.clarity.ms cdn.cookielaw.org cdn2.hubspot.net embed-ssl.wistia.com f.hubspotusercontent00.net pic.trendemon.com px.ads.linkedin.com trackingapi.trendemon.com analytics.twitter.com cdn.bizible.com cdn.bizibly.com googleads.g.doubleclick.net t.co track.hubspot.com www.facebook.com www.gliffy.com www.google.com www.linkedin.com www.perforce.com www.blazemeter.com www.jrebel.com www.openlogic.com www.zend.com www.puppet.com www.perfecto.io umsafoundation.org live-mondrian.pantheonsite.io i.ytimg.com image.simplecastcdn.com yt3.ggpht.com fast.wistia.net googletagmanager.com ssl.gstatic.com www.gstatic.com *.google-analytics.com *.googletagmanager.com www.googletagmanager.com pagead2.googlesyndication.com www.googleadservices.com google.com www.google.com.tw www.google.mn fast.wistia.com www.google.co.uk www.google.com.br www.google.no fonts.gstatic.com www.google.co.in www.google.com.ec www.google.pl; manifest-src 'self' 846-hel-222.mktoresp.com 173-dti-322.mktoresp.com 059-alg-683.mktoresp.com js.zi-scripts.com static.addtoany.com stats.g.doubleclick.net tracking-api.g2.com play.google.com www.google.com www.perforce.com www.blazemeter.com www.gliffy.com www.jrebel.com www.openlogic.com www.zend.com www.puppet.com www.perfecto.io; media-src 'self' blob: app.qualified.com fast.wistia.com embed-ssl.wistia.com data: embed-fastly.wistia.com embed-cloudfront.wistia.com; object-src 'self'; script-src 'self' 'report-sample' 'unsafe-eval' 846-hel-222.mktoweb.com assets.trendemon.com browser.sentry-cdn.com cdn.cookielaw.org cdn.jsdelivr.net cdnjs.cloudflare.com fast.wistia.com fast.wistia.net googleads.g.doubleclick.net j.6sc.co js.zi-scripts.com munchkin.marketo.net resources.perforce.com *.clarity.ms snap.licdn.com static.addtoany.com static.cloudflareinsights.com trackingapi.trendemon.com tracking.g2crowd.com ct.capterra.com cdn.bizible.com cdn.getmoreproof.com js.hs-analytics.net js.hs-banner.com js.hs-scripts.com connect.facebook.net static.ads-twitter.com p-js.s3.amazonaws.com player.simplecast.com widgets.givebutter.com www.google.com www.googletagmanager.com www.perforce.com www.blazemeter.com www.gliffy.com www.jrebel.com www.openlogic.com www.zend.com www.puppet.com www.perfecto.io umsafoundation.org www.youtube.com googletagmanager.com tagmanager.google.com *.googletagmanager.com www.googleadservices.com pagead2.googlesyndication.com https://cdn.ckeditor.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://code.highcharts.com https://fast.wistia.com https://resources.perforce.com https://resources.roguewave.com https://static.addtoany.com https://unpkg.com info.perforce.com 'nonce-HJp8kg-KC1-B82rgWol4DA'; script-src-elem 'self' feedback.perforce.com js.qualified.com cdn.cookielaw.org googleads.g.doubleclick.net ct.capterra.com gist.github.com j.6sc.co munchkin.marketo.net trackingapi.trendemon.com scripts.clarity.ms js.zi-scripts.com cdnjs.cloudflare.com https://cdn.ckeditor.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://code.highcharts.com https://fast.wistia.com https://resources.perforce.com https://resources.roguewave.com https://static.addtoany.com https://unpkg.com info.perforce.com resources.perforce.com 'nonce-HJp8kg-KC1-B82rgWol4DA'; style-src 'self' 'report-sample' 'unsafe-inline' 846-hel-222.mktoweb.com cdnjs.cloudflare.com resources.perforce.com www.perforce.com www.blazemeter.com www.gliffy.com www.jrebel.com www.openlogic.com www.zend.com www.puppet.com www.perfecto.io fonts.googleapis.com www.youtube.com googletagmanager.com tagmanager.google.com app-ab48.marketo.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://code.highcharts.com https://unpkg.com; style-src-elem 'self' feedback.perforce.com resources.perforce.com www.googletagmanager.com cdnjs.cloudflare.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://code.highcharts.com https://unpkg.com; webrtc 'block'; worker-src 'self' blob:; base-uri 'self'; form-action 'self' https://feedback.perforce.com; frame-ancestors 'self' www.perforce.com 2 default-src 'self' ; style-src 'self' 'unsafe-inline' optimize.google.com www.googletagmanager.com fonts.googleapis.com *.typekit.net *.yotpo.com *.myfonts.net *.cloudfront.net; font-src 'self' data: optimize.google.com fonts.gstatic.com *.abtasty.com *.dwin1.com *.typekit.net *.livechatinc.com snap.licdn.com *.tiktok.com static.ads-twitter.com ct.pinterest.com *.yotpo.com *.addthis.com *.moatads.com *.curalate.com *.cloudflare.com *.cloudfront.net; img-src 'self' data: *; base-uri 'self' ; form-action *; frame-ancestors 'self' ; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.sandersondesigngroup.com *.googleapis.com translate.google.com www.google-analytics.com www.googleoptimize.com www.googleadservices.com maps.googleapis.com polyfill.io player.vimeo.com connect.facebook.net *.klevu.com *.searchspring.com api.exponea.com s.pinimg.com intljs.rmtag.com assistjs.skimresources.com googleads.g.doubleclick.net bat.bing.com t.contentsquare.net track.sweetanalytics.com *.yotpo.com snap.licdn.com static.ads-twitter.com *.tiktok.com *.abtasty.com *.dwin1.com *.livechatinc.com *.voyado.com *.ksearchnet.com *.hotjar.com *.veinteractive.com *.mouseflow.com *.sleeknote.com *.stripe.com *.zdassets.com *.trustpilot.com *.clarity.ms *.addthis.com *.addthisedge.com *.moatads.com *.clearpay.co.uk *.amplitude.com *.sagepay.com snapppt.com *.snapppt.com; connect-src 'self' www.mage.sandersondesigngroup.com *.sandersondesigngroup.com *.klevu.com *.searchspring.com api.exponea.com ct.pinterest.com *.abtasty.com *.tiktok.com *.yotpo.com maps.googleapis.com vimeo.com *.addthis.com *.moatads.com *.dwin1.com *.54proxy.com *.ksearchnet.com *.hotjar.com *.hotjar.io *.zdassets.com *.clarity.ms *.amplitude.com *.sweetanalytics.com snapppt.com *.snapppt.com api.addressy.com; frame-src 'self' player.vimeo.com *.fls.doubleclick.net ct.pinterest.com vimeo.com secure.livechatinc.com *.addthis.com *.curalate.com *.54proxy.com *.hotjar.com *.stripe.com *.trustpilot.com *.paypal.com; 2 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com data: *.fontawesome.com *.bootstrapcdn.com *.hotjar.com fonts.googleapis.com cdn.cookiehub.eu https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com 'self' 'unsafe-inline'; frame-ancestors *.certcapture.com https://www.youtube.com https://www.google.com/maps https://www.google.com/ https://insight.adsrvr.org/ https://analytics.google.com https://vimeo.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.networkmerchants.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.certcapture.com googleads.g.doubleclick.net secure.livechatinc.com https://songbird.cardinalcommerce.com https://centinelapi.cardinalcommerce.com https://*.cardinalcommerce.com https://*.centinelapi.cardinalcommerce.com https://insight.adsrvr.org/ https://analytics.google.com https://vimeo.com *.weltpixel.com *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.googletagmanager.com *.doubleclick.net www.xtento.com https://*.online-metrix.net https://imgs.signifyd.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net data: *.networkmerchants.com *.googleapis.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.certcapture.com *.amazonaws.com bat.bing.com cdn.ywxi.net blob *.instantsearchplus.com *.bbb.org cdn.livechat-files.com *.facebook.com *.hotjar.com *.clarity.ms *.bing.com *.google.com.ar www.doubleclick.net cdn.cookiehub.eu p.brsrvr.com *.trackedlink.net magefan.com cm.magefan.com *.disqus.com https://firebasestorage.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.reddit.com *.google-analytics.com *.googletagmanager.com *.doubleclick.net *.google.com www.xtento.com cdn.xtento.com https://imgs.signifyd.com https://*.online-metrix.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com https://vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://rum.hlx.page *.networkmerchants.com *.googleapis.com *.gstatic.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com acp-magento.appspot.com *.akamaized.net *.instantsearchplus.com *.fastsimon.com fastsimon-grid.akamaized.net *.certcapture.com *.fontawesome.com *.livechatinc.com bat.bing.com *.clarity.ms 199001.tctm.co *.facebook.net *.facebook.com *.cokertirecompany.com *.hotjar.com e.zip-corvette.com www.googletagservices.com www.doubleclick.net cdn.cookiehub.eu cdn.brcdn.com https://cdn1.ebizcharge.net https://songbird.cardinalcommerce.com https://centinelapi.cardinalcommerce.com https://cdnjs.cloudflare.com https://insight.adsrvr.org/ https://dpm.demdex.net https://amcglobal.sc.omtrdc.net https://geostag.cardinalcommerce.com https://geo.cardinalcommerce.com https://centinelapistag.cardinalcommerce.com https://analytics.google.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com *.disqus.com *.avada.io js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googletagmanager.com *.googleadservices.com *.redditstatic.com *.reddit.com *.tiktok.com unpkg.com *.doubleclick.net www.xtento.com cdn.xtento.com https://cdn-scripts.signifyd.com https://imgs.signifyd.com https://h64.online-metrix.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.networkmerchants.com *.certcapture.com *.bootstrapcdn.com static-autocomplete.fastsimon.com ping.fastsimon.com settings.fastsimon.com static-grid.fastsimon.com *.typekit.net cdn.cookiehub.eu cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com *.fontawesome.com https://fonts.bunny.net assets.braintreegateway.com *.tagmanager.google.com *.googletagmanager.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net https://vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.networkmerchants.com *.googleapis.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.certcapture.com *.clarity.ms api.livechatinc.com bat.bing.com api.fastsimon.com suggest.instantsearchplus.com suggest.fastsimon.com static-autocomplete.fastsimon.com static-grid.fastsimon.com ping.fastsimon.com settings.fastsimon.com stats.g.doubleclick.net bam.nr-data.net 199001.tctm.co *.facebook.com *.hotjar.com *.hotjar.io wss://ws.hotjar.com googleads.g.doubleclick.net cdn.cookiehub.eu c.ba.contentsquare.net 3dsapi.ebizcharge.net kg668dbov0.execute-api.us-east-1.amazonaws.com ebizcharge3ds-staging1.azurewebsites.net *.ebizcharge.net https://songbird.cardinalcommerce.com https://centinelapi.cardinalcommerce.com https://cdnjs.cloudflare.com https://insight.adsrvr.org/ https://dpm.demdex.net https://amcglobal.sc.omtrdc.net https://geostag.cardinalcommerce.com https://geo.cardinalcommerce.com https://centinelapistag.cardinalcommerce.com https://analytics.google.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.google-analytics.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.doubleclick.net *.run.app https://imgs.signifyd.com 'self' 'unsafe-inline'; child-src *.certcapture.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 default-src 'self' blob: data:; connect-src 'self' https://*.analytics.google.com https://graphql.landsbankinn.is https://www.google-analytics.com cdn.landsbankinn.is https://log.landsbankinn.is https://www.google.com https://landsbankinn.boost.ai/ https://googleads.g.doubleclick.net https://region1.google-analytics.com/ https://stats.g.doubleclick.net/ events.mapbox.com https://landsbankinn.cdn.prismic.io/ api.mapbox.com https://a.landsbankinn.is/; script-src 'self' 'unsafe-eval' 'unsafe-inline' https://connect.facebook.net/ https://www.googletagmanager.com/ https://www.google-analytics.com/ https://landsbankinn.boost.ai https://www.google.com https://www.gstatic.com cdn.landsbankinn.is https://static.cdn.prismic.io blob: data: https://td.doubleclick.net https://graphql.landsbankinn.is https://e.infogram.com/ https://prismic.io/ https://*.jotform.com https://a.landsbankinn.is/; style-src 'self' 'unsafe-eval' 'unsafe-inline' https://www.gstatic.com; img-src 'self' blob: data: images.prismic.io https://prismic-io.s3.amazonaws.com/ www.gstatic.com www.google-analytics.com/ api.mapbox.com cdn.landsbankinn.is https://landsbankinn.is/ https://www.googletagmanager.com https://www.facebook.com/tr/ https://www.facebook.com/ https://boost-files-general-eu-west-1-prod.s3-eu-west-1.amazonaws.com/files/LANDSBANKINN/ https://www.google.is/ https://www.google.com/ https://landsbankinn.cdn.prismic.io/; font-src 'self' cdn.landsbankinn.is fonts.gstatic.com https://unpkg.com blob: data:; object-src 'self' https://graphql.landsbankinn.is; base-uri 'self'; form-action 'self' https://graphql.landsbankinn.is; frame-ancestors 'self' cdn.landsbankinn.is; frame-src 'self' https://www.googletagmanager.com/ https://landsbankinn.prismic.io/ cdn.landsbankinn.is https://td.doubleclick.net/ https://landsbankinn.boost.ai https://www.google.com/ https://www.google.is/ https://e.infogram.com/ https://*.jotform.com; style-src-elem https://fonts.googleapis.com 'self' https://unpkg.com 'unsafe-eval' 'unsafe-inline' https://a.landsbankinn.is/; media-src 'self' blob: https://prismic-io.s3.amazonaws.com/landsbankinn/ cdn.landsbankinn.is https://landsbankinn.cdn.prismic.io/; report-to name-of-endpoint; report-uri https://log.landsbankinn.is/api/20/security/?sentry_key=5619b3ff53a764b525920b31d3e32e4a; 2 frame-ancestors *.vee24.com 2 default-src https://d3tw2v68rmxuj7.cloudfront.net; connect-src 'self' https: wss://*.zopim.com; font-src data: https:; frame-src https://js.stripe.com https://m.stripe.network https://www.google.com https://www.youtube.com https://googleads.g.doubleclick.net https://bid.g.doubleclick.net https://platform.twitter.com https://x.adroll.com https://15347100.fls.doubleclick.net https://td.doubleclick.net; img-src https:; media-src https://static.zdassets.com/web_widget/classic/latest/fda6cd35495c75f83508d9d2e77ee33d.mp3 https://d3tw2v68rmxuj7.cloudfront.net;script-src 'unsafe-inline' 'unsafe-eval' https:; style-src 'unsafe-inline' https://d3tw2v68rmxuj7.cloudfront.net https://fonts.googleapis.com https://cdnjs.cloudflare.com/ajax/libs/ionicons/4.5.6/css/ionicons.min.css https://use.typekit.net https://p.typekit.net; report-uri /csp 2 script-src 'unsafe-inline' 'unsafe-eval' www.dropbox.com 'self' apis.google.com assets.adobedtm.com c.go-mpulse.net connect.facebook.net googleads.g.doubleclick.net static.ads-twitter.com www.adobetag.com www.google-analytics.com www.google.com www.googleadservices.com www.googletagmanager.com www.gstatic.com www.youtube.com s.pinimg.com snap.licdn.com blob:; script-src-elem 'self' 'unsafe-inline' assets.adobedtm.com apis.google.com az416426.vo.msecnd.net connect.facebook.net snap.licdn.com static.ads-twitter.com www.google-analytics.com www.googletagmanager.com googleads.g.doubleclick.net c.go-mpulse.net www.adobetag.com www.gstatic.com www.youtube.com www.google.com s.pinimg.com ct.pinterest.com www.dropbox.com www.googleadservices.com www.scrible.com ajax.googleapis.com cdnjs.cloudflare.com googletagmanager.com script.hotjar.com static.hotjar.com; script-src-attr 'unsafe-inline'; style-src-elem 'self' 'unsafe-inline' cdn.flowplayer.com cdn.jsdelivr.net fonts.googleapis.com cdnjs.cloudflare.com www.gstatic.com www.scrible.com use.fontawesome.com; style-src-attr 'unsafe-inline'; img-src 'self' data: *.oerproject.com analytics.twitter.com px.ads.linkedin.com www.facebook.com www.google.com cm.everesttech.net t.co *.bighistoryproject.com www.google-analytics.com googleads.g.doubleclick.net www.googletagmanager.com bgc3worldhistorydev.112.2o7.net csi.gstatic.com ssl.gstatic.com www.google.co.uk www.google.com.ar www.googleadservices.com cfdc4d69b.lwcdn.com stats.g.doubleclick.net www.google.ca www.google.co.in www.google.co.jp www.google.co.kr www.google.co.th www.google.com.au www.google.com.bz www.google.com.co www.google.com.hk www.google.com.mx www.google.com.ng www.google.com.ph www.google.com.sg www.google.mn cm.g.doubleclick.net www.google.cl www.google.co.id www.google.ae www.google.am www.google.at www.google.ba www.google.be www.google.bg www.google.bs www.google.bt www.google.ch www.google.ci www.google.co.cr www.google.co.il www.google.co.ke www.google.co.ls www.google.co.ma www.google.co.nz www.google.co.tz www.google.co.ug www.google.co.uz www.google.co.ve www.google.co.vi www.google.co.za www.google.co.zm www.google.com.af www.google.com.bd www.google.com.bh www.google.com.bo www.google.com.br www.google.com.cu www.google.com.do www.google.com.ec www.google.com.eg www.google.com.et www.google.com.gh www.google.com.gt www.google.com.jm www.google.com.kh www.google.com.lb www.google.com.my www.google.com.np www.google.com.om www.google.com.pa www.google.com.pe www.google.com.pg www.google.com.pk www.google.com.pr www.google.com.py www.google.com.qa www.google.com.sa www.google.com.sv www.google.com.tj www.google.com.tr www.google.com.tw www.google.com.ua www.google.com.vn www.google.cv www.google.cz www.google.de www.google.es www.google.fi www.google.fr www.google.gl www.google.gm www.google.gr www.google.gy www.google.hr www.google.ht www.google.hu www.google.ie www.google.iq www.google.is www.google.it www.google.jo www.google.kg www.google.kz www.google.lk www.google.lv www.google.nl www.google.no www.google.pl www.google.pt www.google.ro www.google.ru www.google.rw www.google.se www.google.sk www.google.so www.google.tn www.linkedin.com fonts.gstatic.com translate.google.com ad.doubleclick.net adservice.google.com px4.ads.linkedin.com i.ytimg.com live.rezync.com yastatic.net dpm.demdex.net cdn.honey.io bat.bing.com 20537739p.rfihub.com 20537741p.rfihub.com a.rfihub.com blob: assets.clever.com www.google.as www.google.az www.google.bj www.google.by www.google.cg www.google.co.ao www.google.co.ck www.google.co.zw www.google.com.cy www.google.com.fj www.google.com.kw www.google.com.ly www.google.com.mm www.google.com.mt www.google.com.na www.google.com.ni www.google.com.sl www.google.com.uy www.google.dj www.google.dk www.google.dz www.google.ee www.google.ga www.google.ge www.google.hn www.google.la www.google.lt www.google.lu www.google.md www.google.me www.google.mk www.google.mu www.google.mw www.google.ps www.google.rs www.google.si www.google.sc accounts.google.com connect.facebook.net google.com l.facebook.com www.google.ad www.google.al www.google.bf www.google.cd www.google.cm www.google.co.mz www.google.com.bn www.google.com.gi www.google.dm www.google.gg www.google.je www.google.ml www.google.mv www.google.ne www.google.sn www.google.td www.google.tl www.google.tt www.youtube.com; font-src 'self' fonts.gstatic.com assets.clever.com use.fontawesome.com; connect-src 'self' dc.services.visualstudio.com dpm.demdex.net px.ads.linkedin.com *.oerproject.com www.google-analytics.com c.go-mpulse.net cfdc4d69b.lwcdn.com ihi.flowplayer.com ljsp.lwcdn.com ptm.flowplayer.com www.facebook.com adservice.google.com ct.pinterest.com apis.google.com google.com pmi.flowplayer.com region1.google-analytics.com www.google.com analytics.google.com api.facebook.com region1.analytics.google.com stats.g.doubleclick.net translate-pa.googleapis.com translate.googleapis.com www.googleadservices.com www.googletagmanager.com www.scrible.com ad.doubleclick.net api.fbanalytics.org cdn.flowplayer.com fonts.googleapis.com fonts.gstatic.com analytics.twitter.com edge.microsoft.com oerproject.report-uri.com t.co www.google.ca; frame-src 'self' bgc3.demdex.net www.google.com ct.pinterest.com td.doubleclick.net accounts.google.com drive.google.com *.oerproject.com www.facebook.com www.googletagmanager.com www.youtube.com; frame-ancestors * 'self'; form-action 'self'; worker-src 'self' blob:; report-uri https://oerproject.report-uri.com/r/d/csp/wizard 2 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com *.fontawesome.com https://fonts.bunny.net *.lndo.site *.weprovide.shop script.hotjar.com unpkg.com *.triggerbee.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com *.googlesyndication.com *.tiktok.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com https://www.paypal.com https://hostedfields-externalapi.alpha.buckaroo.aws https://hostedfields-externalapi.prod-pci.buckaroo.io landofcoder.com maps.googleapis.com chart.googleapis.com https://www.googletagmanager.com/ *.trustpilot.com *.lndo.site *.weprovide.shop dtm.cando.eu vars.hotjar.com ct.pinterest.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com https://d1pna5l3xsntoj.cloudfront.net https://helloretailcdn.com https://banners.helloretailcdn.com 'self' data: www.google.nl *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.googlesyndication.com *.roeye.com *.tiktok.com https://portal.payconiq.com https://static.buckaroo.nl https://www.paypalobjects.com cdn.flbx.io *.cloudfront.net 'self' blob: data http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ magefan.com cm.magefan.com https://firebasestorage.googleapis.com *.lndo.site *.weprovide.shop maps.google.com maps.googleapis.com mailing.deli-home.nl *.clarity.ms *.omappapi.com ct.pinterest.com cdn.cookielaw.org *.cando.eu skantrae.com *.weekampdeuren.nl dev.visualwebsiteoptimizer.com *.triggerbee.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://core.helloretail.com https://d1pna5l3xsntoj.cloudfront.net https://helloretailcdn.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com cdn.jsdelivr.net *.tiktok.com https://static.buckaroo.nl https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl https://buckaroo.nl https://www.paypal.com https://hostedfields-externalapi.alpha.buckaroo.aws https://hostedfields-externalapi.prod-pci.buckaroo.io *.getflowbox.com landofcoder.com maps.googleapis.com chart.googleapis.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ *.avada.io *.shopify.com *.trustpilot.com *.lndo.site *.weprovide.shop cdnjs.cloudflare.com code.jquery.com optanon.blob.core.windows.net geolocation.onetrust.com *.omappapi.com bam.nr-data.net cdn.cookielaw.org js-agent.newrelic.com s.pinimg.com *.hotjar.com *.clarity.ms cdn.leadinfo.net ct.pinterest.com dev.visualwebsiteoptimizer.com *.triggerbee.com *.myvisitors.se *.jotform.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://d1pna5l3xsntoj.cloudfront.net https://helloretailcdn.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com *.tiktok.com https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl *.fontawesome.com https://fonts.bunny.net *.trustpilot.com *.lndo.site *.weprovide.shop optanon.blob.core.windows.net a.omappapi.com cdn.cookielaw.org p.typekit.net skantrae.com 'self' 'unsafe-inline'; object-src landofcoder.com maps.googleapis.com chart.googleapis.com 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://core.helloretail.com https://helloretailcdn.com *.google-analytics.com *.facebook.com *.facebook.net *.doubleclick.net *.googlesyndication.com *.tiktok.com wss://websocketservice-externalapi.prod.buckaroo.io https://static.buckaroo.nl wss://websockets.buckaroo.io/ https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl https://hostedfields-externalapi.alpha.buckaroo.aws https://hostedfields-externalapi.prod-pci.buckaroo.io https://applepay.buckaroo.io https://www.paypal.com *.getflowbox.com *.googleapis.com landofcoder.com maps.googleapis.com chart.googleapis.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ https://get.geojs.io *.avada.io *.lndo.site *.weprovide.shop *.cando.eu bam.nr-data.net *.clarity.ms *.omappapi.com ct.pinterest.com sp.spheremall.com *.hotjar.com *.hotjar.io wss://*.hotjar.com cdn.cookielaw.org geolocation.onetrust.com dev.visualwebsiteoptimizer.com *.triggerbee.com gethatch.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.cloudfront.net *.podigee-cdn.net 'self' data: d3c2yqbxx52o4l.cloudfront.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * d3c2yqbxx52o4l.cloudfront.net 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com https://www.googletagmanager.com/ *.facebook.com js.mollie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.office365.com schoeffel-lowa.de *.podigee-cdn.net komoot.com d3c2yqbxx52o4l.cloudfront.net www.komoot.com d3ms8mre5rhtvu.cloudfront.net 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com *.google-analytics.com *.analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io maps.googleapis.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ *.cdninstagram.com https://www.mollie.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.usercentrics.eu *.hubspot.com *.podigee-cdn.net *.hsforms.net *.hsforms.com 'self' data: maps.gstatic.com d3c2yqbxx52o4l.cloudfront.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com maps.googleapis.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ player.vimeo.com connect.facebook.net cdnjs.cloudflare.com js.mollie.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googleadservices.com *.usercentrics.eu *.googleapis.com *.hs-scripts.com *.hs-banner.com *.hs-analytics.net *.podigee-cdn.net *.hsforms.net *.hsforms.com *.gstatic.com d3c2yqbxx52o4l.cloudfront.net pagead2.googlesyndication.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com assets.braintreegateway.com *.podigee-cdn.net *.googleapis.com *.gstatic.com d3c2yqbxx52o4l.cloudfront.net 'self' 'unsafe-inline'; object-src d3c2yqbxx52o4l.cloudfront.net 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ *.cloudfront.net d3c2yqbxx52o4l.cloudfront.net 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.googleadservices.com *.google-analytics.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com maps.googleapis.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.usercentrics.eu *.googleapis.com *.googlesyndication.com t.elasticsuite.io *.hsforms.net *.hsforms.com d3c2yqbxx52o4l.cloudfront.net www.google-analytics.com analytics.google.com paypal.com *.paypalobjects.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com d3c2yqbxx52o4l.cloudfront.net 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 font-src *.klevu.com *.ksearchnet.com https://staticfiles.solutiontree.com *.cloudflare.com *.twitter.com *.gstatic.com *.typekit.net *.olark.com *.trustedshops.com *.googleapis.com https://fast.fonts.net *.yotpo.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.authorize.net secure.authorize.net test.authorize.net pilot-payflowlink.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.yotpo.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors *.authorize.net 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com player.vimeo.com https://www.google.com/recaptcha/ *.authorize.net https://fast.wistia.net https://www.googletagmanager.com secure.authorize.net test.authorize.net 1eaf.cardinalcommerce.om www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.weltpixel.com *.yotpo.com https://mkt.solution-tree.com https://mkt.solutiontree.com https://mkt.marzanoresources.com *.olark.com *.facebook.com https://bid.g.doubleclick.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.klevu.com *.ksearchnet.com store.paradoxlabs.com https://staticfiles.solutiontree.com https://cloudfront-s3.solutiontree.com https://marzano-s3.solutiontree.com https://mediafiles.solutiontree.com https://solutiontree.s3.amazonaws.com https://px.ads.linkedin.com https://t.co https://www.google.com https://www.google.co.in https://www.facebook.com https://d.adroll.com https://log.olark.com https://dc.ads.linkedin.com https://googleads.g.doubleclick.net https://dsum-sec.casalemedia.com https://pixel.rubiconproject.com https://pixel.advertising.com https://sync.outbrain.com https://simage2.pubmatic.com https://ads.yahoo.com https://sync.taboola.com https://eb2.3lift.com https://p.adsymptotic.com https://ups.analytics.yahoo.com https://soltreemrls3.s3-us-west-2.amazonaws.com fpdbs.paypal.com t.paypal.com fpdbs.sandbox.paypal.com *.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.yotpo.com *.olark.com https://soltreemrls3.s3.us-west-2.amazonaws.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com s.ytimg.com www.googleapis.com *.vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ js.klevu.com *.ksearchnet.com *.authorize.net https://cdn.raygun.io https://staticfiles.solutiontree.com *.googletagmanager.com https://connect.facebook.net https://s.adroll.com https://snap.licdn.com https://static.ads-twitter.com https://script.crazyegg.com https://analytics.twitter.com https://d.adroll.com https://fast.wistia.com https://fast.wistia.net https://static.olark.com https://pi.pardot.com https://stats.g.doubleclick.net https://googleads.g.doubleclick.net secure.authorize.net test.authorize.net *.google.co.in *.facebook.com *.olark.com/ *.pardot.com/ *.cloudflare.com *.twitter.com *.google.com *.linkedin.com *.twimg.com *.gstatic.com *.paypalobjects.com *.paypal.com *.bootstrapcdn.com www.paypalobjects.com js.braintreegateway.com t.paypal.com *.cardinalcommerce.com www.sandbox.paypal.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com cdn.dnky.co webchat.dotdigital.com *.klevu.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.yotpo.com https://mkt.solution-tree.com https://mkt.solutiontree.com https://mkt.marzanoresources.com https://static.cloudflareinsights.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.klevu.com *.ksearchnet.com https://staticfiles.solutiontree.com https://s.adroll.com *.olark.com https://fast.fonts.net/ *.yotpo.com *.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.olark.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.klevu.com *.ksearchnet.com *.authorize.net https://api.raygun.io https://staticfiles.solutiontree.com https://stats.g.doubleclick.net https://script.crazyegg.com https://www.facebook.com https://s.adroll.com https://d.adroll.com https://tracking.crazyegg.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com api.braintreegateway.com client-analytics.sandbox.braintreegateway.com client-analytics.braintreegateway.com *.braintree-api.com *.yotpo.com *.olark.com *.crazyegg.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 report-uri https://fathom.report-uri.com/r/t/csp/wizard; default-src 'none'; form-action 'none'; object-src 'none'; frame-ancestors 'none'; block-all-mixed-content; upgrade-insecure-requests 2 font-src *.googleapis.com *.gstatic.com *.fontawesome.com maxcdn.bootstrapcdn.com *.restorio.cz *.restorio.sk *.restorio.eu *.vegadesign.cz *.vegadesign.local 'self' data: *.twitter.com *.twimg.com *.zopim.com data: 'self' 'unsafe-inline'; form-action self *.restorio.cz *.restorio.sk *.restorio.eu *.vegadesign.cz *.vegadesign.local *.facebook.com *.twitter.com yaby.eu 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.restorio.cz 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ www.google.com www.facebook.com platform.twitter.com *.restorio.cz *.restorio.sk *.restorio.eu *.vegadesign.cz *.vegadesign.local *.criteo.com *.criteo.net *.doubleclick.net *.facebook.com *.google.com *.googletagmanager.com *.ladesk.com elibro.ladesk.com *.ec1.vbus.apps.ladesk.com *.gopay.cz *.gopay.com *.hotjar.com *.outfindo.com *.packeta.com *.pinterest.com *.twitter.com www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.googleapis.com *.gstatic.com data: *.facebook.com www.facebook.com pinterest.com assets.pinterest.com syndication.twitter.com *.restorio.cz *.restorio.sk *.restorio.eu media.restorio.cz media.restorio.sk media.restorio.eu yaby.eu *.yaby.eu *.vegadesign.cz *.vegadesign.local blob: *.ceneo.pl *.bing.com *.bing.net *.clarity.ms *.doofinder.com eu1-doofinderuser.s3.amazonaws.com *.doubleclick.net *.g.doubleclick.net *.facebook.net *.google.at *.google.be *.google.bg *.google.com google.com *.google.com.au *.google.com.cr *.google.com.cy *.google.com.do *.google.com.eg *.google.com.mt *.google.com.mx *.google.com.ph *.google.com.tr *.google.com.ua *.google.co.il *.google.co.in *.google.co.jp *.google.co.ma *.google.co.nz *.google.co.th *.google.co.tw *.google.co.uk *.google.ae *.google.by *.google.ca *.google.ch *.google.cz *.google.de *.google.dk *.google.es *.google.fi *.google.fr *.google.gr *.google.hr *.google.hu *.google.ie *.google.is *.google.it *.google.lu *.google.lv *.google.md *.google.me *.google.nl *.google.no *.google.pl *.google.pt *.google.ro *.google.ru *.google.rs *.google.se *.google.sk *.google.tn *.google.tr *.googleadservices.com *.google-analytics.com *.googletagmanager.com *.googleusercontent.com *.googlesyndication.com *.heureka.cz *.heureka.sk im9.cz *.imedia.cz *.packeta.com *.seznam.cz t.co *.tiktok.com *.twiago.com *.twitter.com *.twimg.com *.ytimg.com *.zopim.com *.ziskejte.cz *.zbozi.cz *.criteo.com *.criteo.net ad.360yield.com eb2.3lift.com *.adform.net *.adnxs.com *.adnxs.net *.bidswitch.net r.casalemedia.com *.emxdgt.com id5-sync.com matching.ivitrack.com beacon.krxd.net *.1rx.io exchange.mediavine.com contextual.media.net visitor.omnitagjs.com sync.outbrain.com jadserve.postrelease.com simage2.pubmatic.com pixel.rubiconproject.com match.sharethrough.com rtb-csync.smartadserver.com sync-t1.taboola.com/ criteo-sync.teads.tv criteo-partners.tremorhub.com sync.targeting.unrulymedia.com *.yahoo.net ad.yieldlab.net sync-criteo.ads.yieldmo.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ https://browser.sentry-cdn.com *.googletagmanager.com *.facebook.net cdn.jsdelivr.net connect.facebook.net twitter.com platform.twitter.com *.restorio.cz *.restorio.sk *.restorio.eu static.restorio.cz static.restorio.sk static.restorio.eu *.vegadesign.cz *.vegadesign.local *.addthis.com *.adform.net *.bing.com *.cloudflare.com *.ceneo.pl *.clarity.ms *.cloudflareinsights.com *.cookiehub.com cookiehub.net *.cookiehub.eu restorio.bot.coworkers.ai *.criteo.com *.criteo.net *.daktela.com *.dognet.sk login.dognet.sk *.doofinder.com *.doubleclick.net *.facebook.com *.fontawesome.com *.googleadservices.com *.google-analytics.com *.googlesyndication.com *.google.com *.google.cz *.gopay.cz *.gopay.com *.hotjar.com im9.cz *.im9.cz *.imedia.cz *.ladesk.com *.outfindo.com *.packeta.com *.pinterest.com *.pinimg.com *.selltoro.com *.seznam.cz sc-static.net *.srovname.cz stapecdn.com *.tiktok.com *.ads-twitter.com *.twitter.com *.twimg.com *.zbozi.cz *.zdassets.com *.zopim.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com cdn.jsdelivr.net maxcdn.bootstrapcdn.com *.restorio.cz *.restorio.sk *.restorio.eu static.restorio.cz static.restorio.sk static.restorio.eu *.vegadesign.cz *.vegadesign.local *.cloudflare.com *.cookiehub.com *.cookiehub.eu cookiehub.net *.doofinder.com *.googleapis.com *.gstatic.com *.twitter.com *.twimg.com *.zopim.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com data: 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com *.googleapis.com https://*.ingest.sentry.io *.google-analytics.com *.restorio.cz *.restorio.sk *.restorio.eu yaby.eu *.vegadesign.cz *.vegadesign.local *.bing.com *.bing.net *.clarity.ms *.cookiehub.com *.cookiehub.net cookiehub.net *.cookiehub.eu restorio.bot.coworkers.ai wss://restorio.bot.coworkers.ai *.criteo.com *.criteo.net *.doofinder.com wss://eu1-layer.doofinder.com wss://eu1-recommendations.doofinder.com *.doubleclick.net *.facebook.com *.facebook.net google.com *.google.com *.google.cz *.google.sk adservice.google.com *.googleadservices.com *.googlesyndication.com *.gopay.cz *.gopay.com *.outfindo.com *.packeta.com *.pinterest.com *.selltoro.com *.seznam.cz *.srovname.cz *.tiktok.com *.tiktokw.us *.twitter.com *.twimg.com *.yaby.eu *.zdassets.com wss://widget-mediator.zopim.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.restorio.cz *.restorio.sk *.restorio.eu *.vegadesign.cz *.vegadesign.local *.gopay.cz *.gopay.com *.yaby.eu yaby.eu 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://sentry.vegadesign.cz/api/4/security/?sentry_key=aabf49608cca46b2bf8fb3c0ad2a8eba; report-to report-endpoint; 2 default-src 'self' 'unsafe-inline' 'unsafe-eval' https: data: blob: *; script-src 'self' 'unsafe-inline' 'unsafe-eval' blob: techport.ru *.techport.ru https://*.yandex.net https://techport.api.useinsider.com https://vk.com https://*.vk.com https://www.odnoklassniki.ru https://odnoklassniki.ru https://ok.ru https://connect.ok.ru https://yandex.ru https://*.yandex.ru https://ya.ru https://yandex.st https://yastatic.net https://*.yadro.ru https://webvisor.com https://mc.webwisor.org https://google.com https://*.google.com https://google.ru https://*.google.ru https://translate.google.cn https://*.googleapis.com https://*.googleadservices.com https://googletagservices.com https://*.googletagservices.com https://google-analytics.com https://*.google-analytics.com https://gstatic.com https://*.gstatic.com https://*.googlesyndication.com https://*.mail.ru https://top-fwz1.mail.ru https://youtube.ru https://*.youtube.ru https://youtube.com https://*.youtube.com https://s.ytimg.com https://9khj7ltnoi.a.trbcdn.net https://techpont.ru https://*.flixfacts.com https://*.flixcar.com https://*.flix360.com https://*.flix360.io https://logo.flixfacts.co.uk https://media.flixsyndication.net https://*.doubleclick.net https://www.alexa.com https://*.alexa.com https://ssp.rambler.ru https://profile.ssp.rambler.ru https://*.paymentgate.ru https://*.robokassa.ru https://*.sandbox.paypal.com https://*.paypal.com https://paypal.com https://www.paypal.com https://*.mkb.ru https://*.rbsuat.com https://*.begun.ru https://newrelic.com https://*.newrelic.com https://bam.nr-data.net https://techport.api.sociaplus.com https://flv.isitetv.com https://rum.ngenix.net https://*.cdnvideo.ru https://app.clicker.one https://*.24ttl.stream https://goodmod.ru https://p95bxv.ru https://x.cnt.my/ https://dmrtx.com/ https://*.searchbooster.io https://*.searchbooster.net https://cdn.diginetica.net https://getrcmx.com https://ga.segmel.com https://api.b2pos.ru/shop/v2/connect.js https://dpartaptm.com/ https://widget.yourgood.app https://cdn1.imshop.io https://do.price-port.ru; report-uri //www.techport.ru/csp; report-to //www.techport.ru/csp; 2 object-src 'none'; script-src 'self' 'report-sample' 'unsafe-inline' 'unsafe-eval' https://www.googletagmanager.com https://connect.facebook.net https://googleads.g.doubleclick.net https://d3js.org https://www.gstatic.com https://cse.google.com https://www.googleadservices.com cdn.jsdelivr.net https://cdn.ckeditor.com https://cdn.datatables.net https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com https://www.google.com https://www.lbtu.lv; script-src-elem 'self' 'unsafe-inline' https://www.googletagmanager.com https://connect.facebook.net https://googleads.g.doubleclick.net https://d3js.org https://www.gstatic.com https://cse.google.com https://www.googleadservices.com cdn.jsdelivr.net https://cdn.ckeditor.com https://cdn.datatables.net https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com https://www.google.com https://www.lbtu.lv; style-src 'self' 'report-sample' 'unsafe-inline' https://fonts.googleapis.com https://cdn.datatables.net https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://maxcdn.bootstrapcdn.com https://unpkg.com; style-src-elem 'self' 'unsafe-inline' https://fonts.googleapis.com https://cdn.datatables.net https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://maxcdn.bootstrapcdn.com https://unpkg.com; worker-src 'self'; base-uri 'self'; form-action 'self'; frame-ancestors 'self' 2 font-src maxcdn.bootstrapcdn.com data: https://*.cloudflare.com *.typekit.net *.googleapis.com https://*.authorize.net https://*.cardinalcommerce.com https://*.trustedshops.com https://*.tawk.to https://fonts.gstatic.com https://maxcdn.bootstrapcdn.com https://embed.productlead.me https://*.stage.xpertbeauty.bg https://xpertbeauty.local https://*.xpertbeauty.ro 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net https://www.facebook.com/ https://ct.pinterest.com/ https://*.stage.xpertbeauty.bg https://xpertbeauty.local https://*.xpertbeauty.ro 'self' 'unsafe-inline'; frame-ancestors data: 'self'; frame-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net js.stripe.com www.google.com https://www.youtube.com https://www.google.com https://www.google.ro https://www.google.bg https://www.facebook.com/ https://*.cardinalcommerce.com https://*.authorize.net https://*.paypal.com https://*.sandbox.paypal.com https://*.hotjar.com https://*.pinterest.com https://*.googlesyndication.com https://googleads.g.doubleclick.net https://*.stage.xpertbeauty.bg https://xpertbeauty.local https://*.xpertbeauty.ro https://*.tawk.to https://s7.addthis.com *.xpertbeauty.ro *.xpertbeauty.bg *.xpertbeauty.hu *.xpertbeauty.com *.datareshape.net 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com www.googleadservices.com www.google-analytics.com *.vimeocdn.com s.ytimg.com www.apptrian.com www.facebook.com ct.pinterest.com data: https://*.cloudflare.com https://cdn.klarna.com https://www.magecomp.com https://*.paypal.com www.paypalobjects.com https://*.sandbox.paypal.com https://*.g.doubleclick.net https://*.vimeocdn.com https://s.ytimg.com https://*.usercentrics.eu https://*.magentocommerce.com https://www.google.ro https://www.google.com https://*.tawk.to https://cdn.jsdelivr.net https://*.cdninstagram.com https://*.xx.fbcdn.net www.instagram.com https://instagram.fcnd1-1.fna.fbcdn.net http://seal.alphassl.com/ https://secure.trust-provider.com https://ssl.comodo.com https://feedback.trusted.ro https://*.stage.xpertbeauty.bg https://xpertbeauty.local https://*.xpertbeauty.ro https://ct.pinterest.com maps.gstatic.com maps.google.com https://*.themarketer.com *.xpertbeauty.ro *.xpertbeauty.bg *.xpertbeauty.hu *.xpertbeauty.com *.datareshape.net https://*.google.com https://sslseal.certum.pl/ *.collect.igodigital.com flagpedia.net cdn1.themarketer.com 'self' 'unsafe-inline'; script-src https://*.adobedtm.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com secure.authorize.net test.authorize.net s.ytimg.com video.google.com https://*.vimeo.com www.vimeo.com js.authorize.net jstest.authorize.net cdn-scripts.signifyd.com www.youtube.com js.stripe.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ www.apptrian.com www.facebook.com connect.facebook.net graph.facebook.com www.pinterest.com s.pinimg.com https://*.cloudflare.com https://*.google.com *.gstatic.com https://www.googletagmanager.com https://*.googlesyndication.com maps.googleapis.com https://*.trustedshops.com https://*.usercentrics.eu https://*.cardinalcommerce.com https://*.googleadservices.com https://googleadservices.com https://*.authorize.net https://*.paypalobjects.com https://*.ytimg.com *.braintreegateway.com *.signifyd.com https://connect.facebook.net https://embed.productlead.me https://chimpstatic.com https://*.tawk.to https://*.hotjar.com https://*.getsitecontrol.com https://*.g.doubleclick.net https://js-agent.newrelic.com/ https://bam.eu01.nr-data.net/ http://seal.alphassl.com/ https://secure.trust-provider.com https://cdn.jsdelivr.net https://s.pinimg.com https://*.pinterest.com https://*.paypal.com https://*.sandbox.paypal.com https://*.stage.xpertbeauty.bg https://xpertbeauty.local https://*.xpertbeauty.ro https://*.themarketer.com https://*.tiktok.com *.xpertbeauty.ro *.xpertbeauty.bg *.xpertbeauty.hu *.xpertbeauty.com *.datareshape.net *.collect.igodigital.com *.avada.io cdn1.themarketer.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src getfirebug.com maxcdn.bootstrapcdn.com https://*.cloudflare.com https://*.trustedshops.com https://*.usercentrics.eu https://maxcdn.bootstrapcdn.com https://embed.productlead.me https://*.tawk.to https://cdn.jsdelivr.net https://*.googleapis.com https://*.stage.xpertbeauty.bg https://xpertbeauty.local https://*.xpertbeauty.ro https://static.xpertbeauty.ro https://*.themarketer.com *.xpertbeauty.ro *.xpertbeauty.bg *.xpertbeauty.hu *.xpertbeauty.com *.datareshape.net *.gstatic.com cdn1.themarketer.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src www.apptrian.com www.facebook.com ct.pinterest.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.apptrian.com connect.facebook.net graph.facebook.com ct.pinterest.com https://*.cloudflare.com https://*.paypal.com https://*.cardinalcommerce.com www.facebook.com *.google-analytics.com https://*.tawk.to wss://*.tawk.to https://*.productlead.me wss://*.productlead.me www.instagram.com https://instagram.fcnd1-1.fna.fbcdn.net https://stats.g.doubleclick.net https://bam.eu01.nr-data.net https://*.stage.xpertbeauty.bg https://xpertbeauty.local https://*.xpertbeauty.ro https://ct.pinterest.com https://s7.addthis.com https://api-public.addthis.com https://in.hotjar.com https://vc.hotjar.io maps.googleapis.com https://*.themarketer.com https://*.tiktok.com *.xpertbeauty.ro *.xpertbeauty.bg *.xpertbeauty.hu *.xpertbeauty.com *.datareshape.net www.gstatic.com cdn1.themarketer.com 'self' 'unsafe-inline'; child-src 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://*.xpertbeauty.ro/; report-to report-endpoint; 2 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com maxcdn.bootstrapcdn.com https://widgets.trustedshops.com https://fonts.googleapis.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.googlesyndication.com *.tiktok.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.multisafepay.com https://pay.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.google.com *.google.com *.doubleclick.net *.googlesyndication.com *.tiktok.com *.multisafepay.com https://pay.google.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io *.facebook.com connect.facebook.net graph.facebook.com business.facebook.com 'self' data: *.google.com *.google.bg *.facebook.net *.doubleclick.net *.googletagmanager.com *.gstatic.com *.googlesyndication.com *.roeye.com *.tiktok.com flagpedia.net *.multisafepay.com assets.myparcel.nl https://widgets.trustedshops.com https://widgets-qa.trustedshops.com *.etrusted.com https://mylivechat.com https://uk.mylivechat.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.google.com *.google.bg *.googletagmanager.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com *.jsdelivr.net *.tiktok.com maps.googleapis.com *.multisafepay.com https://pay.google.com cdnjs.cloudflare.com cdn.jsdelivr.net https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.etrusted.com https://www.feedbackcompany.com https://mylivechat.com https://uk.mylivechat.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com *.tiktok.com maxcdn.bootstrapcdn.com *.multisafepay.com cdn.jsdelivr.net https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.etrusted.com https://uk.mylivechat.com https://fonts.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.facebook.net *.google.com *.doubleclick.net *.googlesyndication.com *.tiktok.com www.gstatic.com maps.googleapis.com *.multisafepay.com api.myparcel.nl cdn.jsdelivr.net *.trustedshops.com *.etrusted.com https://integrations.etrusted.site https://www.feedbackcompany.com https://mylivechat.com https://uk.mylivechat.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.oney.io *.staging.oney.io *.klarnacdn.net *.fontawesome.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.hipay-tpp.com *.hipay.com *.googleapis.com *.klarna.com https://www.googletagmanager.com/ *.addthis.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.payments-amazon.com *.hipay.com *.googleapis.com *.oney.io *.staging.oney.io *.klarna.com *.klarnaevt.com *.klarnacdn.net http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ magefan.com cm.magefan.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com commerce-payments-sdk.adobe.io www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.hipay-tpp.com *.hipay.com mpsnare.iesnare.com *.paypal.com *.googleapis.com *.oney.io *.staging.oney.io *.klarna.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ *.addthis.com *.moatads.com *.addthisedge.com *.pinterest.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.hipay.com *.googleapis.com *.klarnacdn.net *.fontawesome.com maxcdn.bootstrapcdn.com assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com data: mpsnare.iesnare.com *.googleapis.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.hipay-tpp.com *.hipay.com wss://mpsnare.iesnare.com *.googleapis.com *.oney.io *.staging.oney.io *.klarnaevt.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.klarna.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ *.addthis.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 worker-src blob: *.osano.com; font-src 'self' data: *.gstatic.com; style-src 'self' data: fonts.googleapis.com *.leadoo.com 'unsafe-inline' *.osano.com; default-src 'self' 'unsafe-eval' data: media.hachettelearning.com; frame-src passport.hoddereducation.co.uk *.trustpayments.com *.securetrading.net *.secure.checkout.visa.com secure.checkout.visa.com *.cardinalcommerce.com pay.google.com thm.visa.com *.datadoghq-browser-agent.com *.browser-intake-datadoghq.eu *.trustpilot.com *.youtube.com *.vimeo.com *.osano.com td.doubleclick.net verify.monzo.com; connect-src *.algolia.net *.algolianet.com 'self' *.algolia.io *.sentry.io *.browser-intake-datadoghq.eu *.sentry.io google.com/pay *.cardinalcommerce.com *.fontawesome.com vimeo.com *.osano.com *.ads.linkedin.com analytics.tiktok.com *.analytics.google.com *.google-analytics.com *.googlesyndication.com *.hotjar.io www.google.com googleads.g.doubleclick.net ws.hotjar.com adservice.google.com analytics.google.com stats.g.doubleclick.net; frame-ancestors admin.hachettelearning.com 'self' admin.hachettelearning.com; script-src cdn.eu.trustpayments.com 'self' *.securetrading.net *.secure.checkout.visa.com secure.checkout.visa.com *.cardinalcommerce.com *.datadoghq-browser-agent.com *.browser-intake-datadoghq.eu pay.google.com *.fontawesome.com *.trustpilot.com *.youtube.com *.vimeo.com *.cloudflare.com *.osano.com www.googletagmanager.com 'unsafe-inline' snap.licdn.com static.hotjar.com connect.facebook.net static.ads-twitter.com analytics.tiktok.com *.analytics.google.com script.hotjar.com googleads.g.doubleclick.net; img-src secure.checkout.visa.com *.secure.checkout.visa.com *.vims.visa.com 'self' data: resourcehub-resource-api.hodder.education analytics.twitter.com *.ads.linkedin.com www.facebook.com/tr www.facebook.com www.googletagmanager.com www.google.com t.co www.google.co.uk googleads.g.doubleclick.net media.hachettelearning.com; form-action 'self' *.cardinalcommerce.com *.securetrading.net verify.monzo.com; base-uri 'self'; report-uri https://www.hachettelearning.com/csp-report 2 base-uri 'self'; default-src 'self' https:; connect-src 'self' data: blob: h https://ga.jspm.io *.sentry.io https://consentcdn.cookiebot.com https://consent.cookiebot.com https://*.hotjar.com https://*.hotjar.io wss://*.hotjar.com https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://*.googleapis.com *.google.com https://*.gstatic.com https://static.raspberrypi.org; font-src 'self' https: data: https://fonts.gstatic.com https://*.hotjar.com; frame-src 'self' https://challenges.cloudflare.com https://consentcdn.cookiebot.com *.google.com e.issuu.com prezi.com storify.com youtube.com www.youtube.com youtube-nocookie.com www.youtube-nocookie.com; img-src 'self' https: data: https://*.raspberrypi.org https://*.hotjar.com https://*.google-analytics.com https://*.googletagmanager.com https://*.googleapis.com https://*.gstatic.com *.google.com *.googleusercontent.com; media-src 'self' https: data:; object-src 'none'; script-src 'self' https: 'unsafe-inline' blob: https://static.raspberrypi.org/js/global-nav-web-component/ https://challenges.cloudflare.com https://*.googleapis.com https://*.gstatic.com *.google.com https://*.ggpht.com *.googleusercontent.com https://*.googletagmanager.com https://*.hotjar.com https://browser.sentry-cdn.com https://js.sentry-cdn.com; style-src 'self' https: 'unsafe-inline' https://fonts.googleapis.com https://*.hotjar.com https://static.raspberrypi.org/styles/design-system/ https://*.cookiebot.com; worker-src blob:; report-uri https://o17504.ingest.us.sentry.io/api/4507769026707457/security/?sentry_key=53fc037dc5040a1a9fe07334577adc13&sentry_environment=production 2 font-src fonts.gstatic.com use.typekit.net *.bglobale.com *.global-e.com *.fontawesome.com *.alothemes.com *.magepow.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com *.facebook.net *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com https://plumrocket.com 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com https://*.vimeo.com https://*.youtube.com *.bglobale.com *.global-e.com landofcoder.com *.facebook.com *.facebook.net *.google.com/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * https://plumrocket.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.wesupply.xyz https://wesupplylabs.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com p.typekit.net *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net https://bluesound.com https://forms-na1.hsforms.com https://mcstaging.bluesound.com https://static.zdassets.com https://static.hotjar.com https://cdn.cookielaw.org https://www.google.co.uk *.bglobale.com *.global-e.com magefan.com cm.magefan.com *.facebook.com *.facebook.net *.alothemes.com *.magepow.com https://www.milople.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com amcglobal.sc.omtrdc.net commerce.adobe.net use.typekit.net magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-ds.com https://js.hsforms.net https://cdn.weglot.com unsafe-inline unsafe-eval https://static.zdassets.com https://static.hotjar.com https://script.hotjar.com https://cdn.cookielaw.org https://widget-mediator.zopim.com https://js.hs-scripts.com *.bglobale.com *.global-e.com landofcoder.com *.facebook.com *.facebook.net *.alothemes.com *.magepow.com *.google.com/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.cloudflare.com https://www.googletagmanager.com tagmanager.google.com unpkg.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src http://*.adobe.com fonts.googleapis.com http://fonts.googleapis.com https://js.digitalriverws.com *.fontawesome.com http://*.alothemes.com http://*.magepow.com http://assets.braintreegateway.com http://tagmanager.google.com https://www.googletagmanager.com 'self' 'unsafe-inline' https://cdn.weglot.com *.bglobale.com *.global-e.com *.alothemes.com *.magepow.com unsafe-inline assets.braintreegateway.com *.stripe.network *.stripecdn.com tagmanager.google.com 'self' 'unsafe-inline'; object-src landofcoder.com 'self' 'unsafe-inline'; media-src *.adobe.com https://*.adobe.com https://mcstaging.bluesound.com https://www.bluesound.com https://bluesound.com https://content-bluesound-com.s3.amazonaws.com 'self' 'unsafe-inline' 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.snplow.net commerce.adobedc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.magento.com *.adobe.io performance.typekit.net commerce.adobe.io commerce.adobe.net qa-api.magedevteam.com *.sentry.io https://forms.hsforms.com https://js.hsforms.net https://cdn.weglot.com 'self' https://ekr.zdassets.com https://script.hotjar.com https://geolocation.onetrust.com https://cdn.cookielaw.org https://bluesound.zendesk.com https://psbspeakers.zendesk.com wss://widget-mediator.zopim.com https://region1.analytics.google.com landofcoder.com *.facebook.com *.facebook.net *.alothemes.com *.magepow.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.google-analytics.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com 'self' 'unsafe-inline'; frame-ancestors *.certcapture.com *.chasepaymentechhostedpay.com *.chasepaymentechhostedpay-var.com *.chase.hostedpaymentservice.net *.chase-var.hostedpaymentservice.net 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com google.com *.braintreegateway.com *.paypal.com *.google.com *.certcapture.com *.dotdigital-pages.com *.dotdigital.com webchat.dotdigital.com webchat.staging.dotdigital.com https://*.google.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com *.chasepaymentechhostedpay.com *.chasepaymentechhostedpay-var.com *.chase.hostedpaymentservice.net *.chase-var.hostedpaymentservice.net c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.weltpixel.com *.googletagmanager.com *.doubleclick.net youtu.be *.nr-data.net 'self' 'unsafe-inline'; img-src *.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.certcapture.com *.trackedlink.net https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.googleusercontent.com *.yahoo.com *.bing.com *.facebook.com mossmotors.com *.mossmotors.com services.postcodeanywhere.co.uk www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.reddit.com *.google-analytics.com *.googletagmanager.com *.doubleclick.net *.google.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net assets.adobedtm.com amcglobal.sc.omtrdc.net *.adobe.io use.typekit.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.magento-ds.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.magento-datasolutions.com https://rum.hlx.page *.certcapture.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal webchat.dotdigital.com webchat.staging.dotdigital.com widget.freshworks.com m2epro.freshdesk.com https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com *.hotjar.com *.facebook.net *.bing.com *.murdoog.com *.pcapredict.com *.jsdelivr.net *.yimg.com *.maxmind.com services.postcodeanywhere.co.uk *.cloudfront.net *info.mossmotors.com form.jotform.com *.freshrelevance.com *.chasepaymentechhostedpay.com *.chasepaymentechhostedpay-var.com *.chase.hostedpaymentservice.net *.chase-var.hostedpaymentservice.net js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googletagmanager.com *.googleadservices.com *.redditstatic.com *.reddit.com *.tiktok.com unpkg.com *.doubleclick.net *.gstatic.com dmp.info.mossmotors.com dmp.info.mossmiata.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com *.certcapture.com webchat.dotdigital.com webchat.staging.dotdigital.com widget.freshworks.com m2epro.freshdesk.com https://fonts.googleapis.com https://hcaptcha.com https://*.hcaptcha.com *.pcapredict.com services.postcodeanywhere.co.uk assets.braintreegateway.com *.tagmanager.google.com *.googletagmanager.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.magento-datasolutions.com *.magento-ds.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io *.certcapture.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com widget.freshworks.com m2epro.freshdesk.com https://ipinfo.io https://*.google.com https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com *.yimg.com *.doubleclick.net *.adobedtm.com *.mmapiws.com *.cloudfront.net connect.facebook.net *.facebook.com *.chasepaymentechhostedpay.com *.chasepaymentechhostedpay-var.com *.chase.hostedpaymentservice.net *.chase-var.hostedpaymentservice.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.run.app dmp.info.mossmotors.com dmp.info.mossmiata.com *.dycdn.net *.freshrelevance.com wss://am.freshrelevance.com 'self' 'unsafe-inline'; child-src *.certcapture.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 default-src 'self' https: data: blob:; script-src 'self' https: 'unsafe-inline' 'unsafe-eval'; style-src 'self' https: 'unsafe-inline'; img-src 'self' https: data: blob:; font-src 'self' https: data:; connect-src 'self' https:; frame-ancestors 'self'; base-uri 'self'; 2 font-src fonts.gstatic.com use.typekit.net *.googleapis.com *.gstatic.com data: *.fontawesome.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com https://plumrocket.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ https://plumrocket.com *.affirm.com *.affirm.ca www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * https://www.google.com www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net *.hubspot.com *.hsforms.com static.hsappstatic.net bat.bing.com *.googleusercontent.com obs.withflowersea.com aorta.clickagy.com *.affirm.com *.affirm.ca *.gstatic.com *.googleapis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://firebasestorage.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com maps.gstatic.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com amcglobal.sc.omtrdc.net commerce.adobe.net use.typekit.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-ds.com js.usemessages.com js.hs-banner.com *.hubspot.com js.hs-analytics.net js.hs-scripts.com js.hsadspixel.net js-agent.newrelic.com ob.withflowersea.com obs.withflowersea.com script.crazyegg.com bat.bing.com www.clarity.ms amplify.outbrain.com wave.outbrain.com bigsur.ai ws-assets.zoominfo.com js.zi-scripts.com tags.clickagy.com js.adsrvr.org js.callrail.com cdn.callrail.com *.affirm.com *.affirm.ca *.googleapis.com *.gstatic.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ https://www.googletagmanager.com tagmanager.google.com https://www.googleadservices.com *.avada.io *.shopify.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://apis.google.com maps.googleapis.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com https://fonts.bunny.net unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io commerce.adobe.net qa-api.magedevteam.com *.sentry.io *.hubspot.com api.hubapi.com bam.nr-data.net tr.outbrain.com amplify.outbrain.com paid.outbrain.com obs.withflowersea.com js.callrail.com script.crazyegg.com api.prod.bigsur.ai v.clarity.ms js.zi-scripts.com ws.zoominfo.com aorta.clickagy.com hemsync.clickagy.com *.affirm.com *.affirm.ca *.googleapis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 font-src fonts.gstatic.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.sagepay.com *.opayo.eu.elavon.com *.fontawesome.com maxcdn.bootstrapcdn.com *.brooktaverner.us *.cloudflare.com *.gstatic.com pouch-global-font-assets.s3.eu-central-1.amazonaws.com *.slant.co *.smassets.net *.typekit.net data: 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.stripe.com *.stripe.network *.google.com *.sagepay.com *.opayo.eu.elavon.com *.arcot.com *.rsa3dsauth.co.uk *.rsa3dsauth.com *.boc.cn *.afs.com.bh *.enfuce.com *.cardcenter.ch *.nexigroup.com *.pluscard.de *.qiib.com.qa *.paylife.at *.redsys.es *.3dsecure.no *.modirum.com *.edb.com *.viseca.ch *.apata.io *.capitalone.com *.dnp-cdms.jp *.revolut.com *.bankserv.co.za *.swisscard.ch *.six-group.com *.marqeta.com *.cardinalcommerce.com *.wlp-acs.com *.imbank.com *.tsys.co.uk *.sia.eu *.garanti.com.tr *.commerzbank.de *.cmbchina.com *.alahli.com *.mycardsecure.com *.gps.com.bh *.citibank.com *.wibmo.com *.dkb.de *.monzo.com *.alinma.com *.nccc.com.tw *.starlingbank.com *.danskebank.com *.pekao24.pl *.lloydsbank.co.uk/ *.lloydsbank.com/ *.lloydsbankinggroup.com/ *.channel-cards-auth-api.lloydsbankinggroup.com/ *.sparebank1.no *.rabobank.nl *.s-id-check-sparkassen.de *.sparkassen-kreditkarten.de *.mbank.pl *.secure2gw.ro *.btrl.ro *.cafis-paynet.jp *.borica.bg *.fibank.bg *.cic.fr *.zaba.hr *.citibank.co.in *.centrum24.pl *.bankmillennium.pl *.icps.mu *.egolomt.mn *.lcl.fr *.ctbcbank.com *.qiwi.com *.postfinance.ch *.citadele.lv *.kib.com.kw *.cathaybk.com.tw *.pkobp.pl *.acdcproc.com *.abanca.com *.n26.com *.klikbca.com *.psa.at *.sumup.com *.eglobal.com.mx *.pl.ing.com *.qnb.com *.rpc-raiffeisen.com *.sebkort.com *.ocbc.com *.tapngo.com.hk *.stcpay.com.sa *.creditmutuel.fr *.luottokunta.fi *.swedbank.se *.unibank.am *.estcard.ee *.hyundaicard.com *.privatbank.ua *.fssnet.co.in *.kbcard.com *.luminorgroup.com *.mashreq.com *.mercurypaymentservices.it *.moneta.cz *.sensebank.com.ua *.sibs.pt *.stripeauthentications.com *.dskbank.bg *.otpbank.hu *.techcombank.com.vn *.touch.tech *.asseco-see.hr *.3dsecure-csas.cz *.cyris.com *.secureacs.com *.acb.com.vn *.facebook.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; frame-ancestors *.stripe.com stripe.com *.stripe.network *.link.com *.amazon.com *.google.com pay.google.com 'self'; frame-src secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.bugherd.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.sagepay.com *.opayo.eu.elavon.com *.arcot.com *.rsa3dsauth.co.uk *.rsa3dsauth.com *.boc.cn *.afs.com.bh *.enfuce.com *.cardcenter.ch *.pluscard.de *.qiib.com.qa *.nexigroup.com *.paylife.at *.redsys.es *.3dsecure.no *.modirum.com *.edb.com *.viseca.ch *.apata.io *.capitalone.com *.dnp-cdms.jp *.revolut.com *.bankserv.co.za *.swisscard.ch *.six-group.com *.marqeta.com *.cardinalcommerce.com *.wlp-acs.com *.imbank.com *.tsys.co.uk *.sia.eu *.garanti.com.tr *.commerzbank.de *.cmbchina.com *.alahli.com *.mycardsecure.com *.gps.com.bh *.citibank.com *.wibmo.com *.dkb.de *.monzo.com *.alinma.com *.nccc.com.tw *.starlingbank.com *.danskebank.com *.pekao24.pl *.lloydsbank.co.uk/ *.lloydsbank.com/ *.lloydsbankinggroup.com/ *.channel-cards-auth-api.lloydsbankinggroup.com/ *.sparebank1.no *.rabobank.nl *.s-id-check-sparkassen.de *.sparkassen-kreditkarten.de *.mbank.pl *.secure2gw.ro *.btrl.ro *.cafis-paynet.jp *.borica.bg *.fibank.bg *.cic.fr *.zaba.hr *.citibank.co.in *.centrum24.pl *.bankmillennium.pl *.icps.mu *.egolomt.mn *.lcl.fr *.ctbcbank.com *.qiwi.com *.postfinance.ch *.citadele.lv *.kib.com.kw *.cathaybk.com.tw *.pkobp.pl *.acdcproc.com *.abanca.com *.n26.com *.klikbca.com *.psa.at *.sumup.com *.eglobal.com.mx *.pl.ing.com *.qnb.com *.rpc-raiffeisen.com *.sebkort.com *.ocbc.com *.tapngo.com.hk *.stcpay.com.sa *.creditmutuel.fr *.luottokunta.fi *.swedbank.se *.unibank.am *.estcard.ee *.hyundaicard.com *.privatbank.ua *.fssnet.co.in *.kbcard.com *.luminorgroup.com *.mashreq.com *.mercurypaymentservices.it *.moneta.cz *.sensebank.com.ua *.sibs.pt *.stripeauthentications.com *.dskbank.bg *.otpbank.hu *.techcombank.com.vn *.touch.tech *.asseco-see.hr *.3dsecure-csas.cz *.cyris.com *.secureacs.com *.acb.com.vn account.fetchify.com *.mention-me.com *.convert.com *.doubleclick.net *.evri.com *.facebook.com *.gnatta.com google.com *.google.com *.googletagmanager.com *.surveymonkey.com *.termly.io *.trustpilot.com *.vimeo.com vimeo.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; img-src widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com validator.swagger.io www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.sweetanalytics.com *.brooktaverner.us *.ometria.com *.visualwebsiteoptimizer.com *.bing.com *.clarity.ms *.google.co.uk *.stripe.com *.stripe.network *.google.com ebizmarts-website.s3.amazonaws.com *.sagepay.com *.paypal.com *.opayo.eu.elavon.com *.klarna.com *.klarnaevt.com *.klarnacdn.net https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ magefan.com cm.magefan.com https://maps.gstatic.com *.adalyser.com *.adroll.com *.bing.net brippo.s3.amazonaws.com *.brooktaverner.co.uk *.cloudflare.com *.convertexperiments.com d3k81ch9hvuctc.cloudfront.net *.doubleclick.net ebizmartsextensions.s3.amazonaws.com *.facebook.com *.facebook.net gnattawatchtower.blob.core.windows.net *.googleadservices.com *.googleapis.com www.google.ad www.google.ae www.google.al www.google.am www.google.at www.google.az www.google.ba www.google.be www.google.bg www.google.bi www.google.bs www.google.by www.google.ca www.google.cd www.google.cg www.google.ch www.google.cl www.google.cm www.google.co.ao www.google.co.bw www.google.co.cr www.google.co.id www.google.co.il www.google.co.in www.google.co.jp www.google.co.ke www.google.co.kr www.google.co.ma www.google.com.ag www.google.com.ar www.google.com.au www.google.com.bd www.google.com.bh www.google.com.bn www.google.com.bo www.google.com.br www.google.com.bz www.google.com.co www.google.com.cy www.google.com.do www.google.com.ec www.google.com.eg www.google.com.et www.google.com.fj www.google.com.gh www.google.com.gi www.google.com.gt www.google.com.hk www.google.com.jm www.google.com.kh www.google.com.kw www.google.com.lb www.google.com.ly www.google.com.mm www.google.com.mt www.google.com.mx www.google.com.my www.google.com.na www.google.com.ng www.google.com.np www.google.com.pa www.google.com.pe www.google.com.pg www.google.com.ph www.google.com.pk www.google.com.pr www.google.com.qa www.google.com.sa www.google.com.sg www.google.com.sl www.google.com.sv www.google.com.tr www.google.com.tw www.google.com.ua www.google.com.uy www.google.com.vn www.google.co.mz www.google.co.nz www.google.co.th www.google.co.tz www.google.co.ug www.google.co.uk www.google.co.uz www.google.co.ve www.google.co.za www.google.co.zm www.google.co.zw www.google.cv www.google.cz www.google.de www.google.dj www.google.dk www.google.dz www.google.ee www.google.es www.google.fi www.google.fr www.google.ga www.google.ge www.google.gg www.google.gr www.google.gy www.google.hn www.google.hr www.google.hu www.google.ie www.google.im www.google.iq www.google.is www.google.it www.google.je www.google.jo www.google.kz www.google.la www.google.li www.google.lk www.google.lt www.google.lu www.google.lv www.google.md www.google.me www.google.mg www.google.mk www.google.mn www.google.mu www.google.mv www.google.mw www.google.nl www.google.no www.google.pl www.google.pt www.google.ro www.google.rs www.google.ru www.google.sc www.google.se www.google.sh www.google.si www.google.sk www.google.sn www.google.so www.google.tg www.google.tn www.google.tt www.google.vu google.com *.googlesyndication.com *.googletagmanager.com *.gstatic.com mageside.com *.omguk.com *.smassets.net t.co *.twitter.com *.vimeo.com data: 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; script-src secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.trustpilot.com *.glopal.com *.sweetanalytics.com *.ometria.com *.ads-twitter.com *.twitter.com *.googletagmanager.com *.visualwebsiteoptimizer.com *.zdassets.com *.bing.com *.clarity.ms *.adroll.com *.bugherd.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com *.google.com *.sagepay.com *.opayo.eu.elavon.com *.klarnaservices.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.avada.io https://maps.googleapis.com *.mention-me.com *.33across.com *.adalyser.com *.brooktaverner.co.uk brooktaverner.us *.brooktaverner.us *.cloudflare.com *.cloudflareinsights.com *.convert.com *.convertexperiments.com *.doubleclick.net *.evri.com *.facebook.net *.getelevar.com *.gnatta.com *.googleapis.com *.googlesyndication.com *.gstatic.com *.klaviyo.com *.omguk.com *.paypal.com *.surveymonkey.com *.termly.io *.webgains.io 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; style-src *.glopal.com *.googleapis.com *.stripe.network *.stripecdn.com *.amazon.com *.google.com *.sagepay.com *.opayo.eu.elavon.com cc-cdn.com *.klarnacdn.net https://static.klaviyo.com *.fontawesome.com maxcdn.bootstrapcdn.com *.brooktaverner.co.uk *.brooktaverner.us *.gnatta.com *.googletagmanager.com *.gstatic.com *.klaviyo.com *.typekit.net 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; object-src 'self' 'unsafe-inline'; media-src www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.gstatic.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; manifest-src 'self' 'unsafe-inline'; connect-src www.google-analytics.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.ometria.com *.sweetanalytics.com *.zopim.com *.clarity.ms *.google-analytics.com brooktaverner.zendesk.com *.zdassets.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.sagepay.com *.paypal.com *.opayo.eu.elavon.com api.craftyclicks.co.uk pcls1.craftyclicks.co.uk *.klarnaservices.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://maps.googleapis.com *.mention-me.com *.bing.com *.bing.net *.brooktaverner.co.uk *.brooktaverner.us *.convertexperiments.com *.datadome.co *.doubleclick.net *.facebook.com *.getelevar.com *.gnatta.com *.googleadservices.com www.google.ad www.google.ae www.google.al www.google.am www.google.at www.google.az www.google.ba www.google.be www.google.bg www.google.bs www.google.by www.google.ca www.google.cd www.google.cg www.google.ch www.google.cl www.google.cm www.google.co.ao www.google.co.cr www.google.co.id www.google.co.il www.google.co.in www.google.co.jp www.google.co.ke www.google.co.kr www.google.co.ma www.google.com.ar www.google.com.au www.google.com.bd www.google.com.bh www.google.com.bn www.google.com.br www.google.com.co www.google.com.cy www.google.com.do www.google.com.ec www.google.com.eg www.google.com.et www.google.com.gh www.google.com.gi www.google.com.hk www.google.com.jm www.google.com.kh www.google.com.kw www.google.com.lb www.google.com.ly www.google.com.mm www.google.com.mt www.google.com.mx www.google.com.my www.google.com.na www.google.com.ng www.google.com.np www.google.com.pa www.google.com.pe www.google.com.ph www.google.com.pk www.google.com.pr www.google.com.qa www.google.com.sa www.google.com.sg www.google.com.sv www.google.com.tr www.google.com.tw www.google.com.ua www.google.com.uy www.google.com.vn www.google.co.mz www.google.co.nz www.google.co.th www.google.co.tz www.google.co.ug www.google.co.uk www.google.co.uz www.google.co.ve www.google.co.za www.google.co.zm www.google.co.zw www.google.cv www.google.cz www.google.de www.google.dj www.google.dk www.google.dz www.google.ee www.google.es www.google.fi www.google.fr www.google.ge www.google.gg www.google.gr www.google.gy www.google.hr www.google.hu www.google.ie www.google.im www.google.iq www.google.is www.google.it www.google.je www.google.jo www.google.kz www.google.li www.google.lk www.google.lt www.google.lu www.google.lv www.google.md www.google.me www.google.mk www.google.mn www.google.mu www.google.mw www.google.nl www.google.no www.google.pl www.google.pt www.google.ro www.google.rs www.google.ru www.google.sc www.google.se www.google.sh www.google.si www.google.sk www.google.sn www.google.so www.google.tn www.google.tt www.google.vu *.google.com google.com *.googlesyndication.com *.googletagmanager.com *.klaviyo.com *.sentry.io *.termly.io vimeo.com *.visualwebsiteoptimizer.com *.webgains.io 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://c07a795d-56fb-4453-8188-078c928ca0fb.sansec.watch/; report-to report-endpoint; 2 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com 'self' data: *.doubleclick.net *.facebook.com https://maxcdn.bootstrapcdn.com https://iwae.com https://cdn.iwae.com https://static.ecorebates.com www.searchanise.com *.searchserverapi.com *.fontawesome.com *.yotpo.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * www.searchanise.com *.searchserverapi.com *.twitter.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.certcapture.com https://phone.aircall.io/ 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com https://static.addtoany.com/ www.google.com *.google.com/ *.doubleclick.net *.facebook.com *.certcapture.com https://phone.aircall.io/ *.getbread.com *.breadpayments.com *.rbcpayplan.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.wesupply.xyz https://wesupplylabs.com guarantee-cdn.com www.searchanise.com *.searchserverapi.com *.twitter.com *.weltpixel.com www.xtento.com *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.googleapis.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.certcapture.com https://cdn.aircall.io/ *.getbread.com *.breadpayments.com *.rbcpayplan.com magefan.com cm.magefan.com https://seal-louisville.bbb.org https://www.google.com https://bid.g.doubleclick.net https://iwae.com https://cdn.iwae.com https://bat.bing.com https://c.bing.com https://clarity.ms https://static.zdassets.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com validate.fishpig.co.uk https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ guarantee-cdn.com *.twitter.com *.twimg.com www.google.ru www.searchanise.com *.searchserverapi.com s3.amazonaws.com https://www.magezon.com https://redchamps.com www.xtento.com cdn.xtento.com *.yotpo.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://static.addtoany.com/ www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.googleapis.com *.gstatic.com *.google.com/ *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.certcapture.com https://cdn.rawgit.com/ https://phone.aircall.io/ https://phone.aircall.io/static/ *.getbread.com *.breadpayments.com *.rbcpayplan.com widget.freshworks.com m2epro.freshdesk.com https://static.zdassets.com https://acsbapp.com https://www.mczbf.com https://widget.trustpilot.com https://maxcdn.bootstrapcdn.com https://static.klaviyo.com https://fast.a.klaviyo.com https://connect.facebook.net https://ekr.zdassets.com https://static-tracking.klaviyo.com https://telemetrics.klaviyo.com/ *.googleadservices.com *.paypal.com *.cardinalcommerce.com https://static.ecorebates.com https://iwae.com https://cdn.iwae.com searchserverapi.com *.searchserverapi.com https://ingrams.ecorebates.com https://bat.bing.com https://s.pinimg.com https://clarity.ms https://ct.pinterest.com *.leadmanagerfx.com *.marketingcloudfx.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com https://static-forms.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ *.cloudflare.com guarantee-cdn.com searchanise-ef84.kxcdn.com s3.amazonaws.com ajax.aspnetcdn.com www.searchanise.com *.searchanise.com api.amplitude.com *.twitter.com *.twimg.com www.xtento.com cdn.xtento.com *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.certcapture.com https://cdn.jsdelivr.net/ widget.freshworks.com m2epro.freshdesk.com https://maxcdn.bootstrapcdn.com https://iwae.com https://cdn.iwae.com https://static.ecorebates.com assets.braintreegateway.com https://static.klaviyo.com www.searchanise.com *.searchserverapi.com searchanise-ef84.kxcdn.com s3.amazonaws.com *.twitter.com ton.twimg.com *.fontawesome.com *.yotpo.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://stats.addtoany.com/menu *.googleapis.com *.google-analytics.com *.facebook.com *.facebook.net *.certcapture.com *.getbread.com *.breadpayments.com *.rbcpayplan.com widget.freshworks.com m2epro.freshdesk.com https://www.mczbf.com https://iwae.zendesk.com https://cdn.acsbapp.com https://ekr.zdassets.com https://iwae.com https://cdn.iwae.com *.breadgateway.net https://ct.pinterest.com https://b.clarity.ms https://bat.bing.com https://acsbapp.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ api.amplitude.com stats.g.doubleclick.net *.yotpo.com 'self' 'unsafe-inline'; child-src *.certcapture.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src https://fonts.googleapis.com/ 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 default-src 'self' 'unsafe-inline' 'unsafe-eval' data: blob: ace.de *.ace.de ace-clubinitiative.de *.ace-clubinitiative.de 360yield.com 3lift.com adform.net adnxs.com adsrvr.org agkn.com bidr.io bidswitch.net bing.com bugsnag.com bussgeldrechner.org casalemedia.com clarity.ms clmbtech.com co.kr cookielaw.org criteo.com *.criteo.com demdex.net dmxleo.com doubleclick.net *.doubleclick.net dwin1.com facebook.net *.facebook.net finanzcheck.de *.finanzcheck.de fwmrm.net ggpht.com google.com *.google.com googleadservices.com googlesyndication.com googletagmanager.com *.googletagmanager.com gsitrix.com gstatic.com *.gstatic.com ioadentifi.com *.ioadentifi.com liadm.com media.net mediavine.com mediawallahscript.com outbrain.com pippio.com postrelease.com pubmatic.com revcontent.com rezync.com rfihub.com roeye.com roeyecdn.com rubiconproject.com smartadserver.com springserve.com stape.net stapecdn.com stickyadstv.com taboola.com tapad.com teads.tv thrtle.com tpmn.io tremorhub.com turn.com ubembed.com unrulymedia.com usemaxserver.de *.usemaxserver.de w55c.net yahoo.com *.yahoo.com youtube.com *.youtube.com ytimg.com; frame-ancestors 'self' ace.de *.ace.de ace-clubinitiative.de *.ace-clubinitiative.de; 2 default-src 'self'; script-src 'report-sample' 'self' 'unsafe-inline' https://acsbapp.com/ https://browser.sentry-cdn.com/ https://cdn.cookielaw.org/ https://cdn.jsdelivr.net/ https://cdn.tailwindcss.com/ https://code.jquery.com/ https://fast.wistia.com/ https://js.monitor.azure.com/ https://kit.fontawesome.com/ https://www.google.com/ https://www.googletagmanager.com/ https://www.gstatic.com/; style-src 'report-sample' 'self' 'unsafe-inline' https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://code.jquery.com https://fonts.googleapis.com; img-src *; font-src * data:; frame-src 'self' https://privacyportal.onetrust.com https://www.google.com; frame-ancestors 'self' *.weatherturndown.corpweb; connect-src 'self' https://*.litix.io https://cdn.acsbapp.com https://cdn.cookielaw.org https://centralus-2.in.applicationinsights.azure.com https://dc.services.visualstudio.com https://distillery.wistia.com https://embed-cloudfront.wistia.com https://fast.wistia.com https://fast.wistia.net https://geolocation.onetrust.com https://ka-p.fontawesome.com https://pipedream.wistia.com https://privacyportal.onetrust.com https://www.google-analytics.com; object-src 'none'; base-uri 'self'; manifest-src 'self'; media-src 'self' blob:; worker-src 'none'; report-uri https://68654b2b841f0014a4c0d0f7.endpoint.csper.io?v=1; 2 default-src 'self' https://*.securetrustbank.com https://*.v12retailfinance.com https://*.googletagmanager.com;; connect-src 'self' https://*.securetrustbank.com https://*.v12retailfinance.com https://stats.g.doubleclick.net https://*.google-analytics.com https://cdn.cookielaw.org https://*.feefo.com https://*.trustpilot.com https://*.civiccomputing.com;; img-src 'self' https://*.securetrustbank.com https://*.v12retailfinance.com data: https://*.google-analytics.com https://*.google.com https://*.google.co.uk https://siteimproveanalytics.com https://*.siteimproveanalytics.com https://*.siteimproveanalytics.io https://*.feefo.com https://*.trustpilot.com;; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://*.securetrustbank.com https://*.v12retailfinance.com https://*.googletagmanager.com https://static.srcspot.com https://cdn.cookielaw.org https://*.google-analytics.com https://siteimproveanalytics.com https://*.siteimproveanalytics.com https://code.jquery.com https://*.feefo.com; https://*.trustpilot.com;; style-src 'self' 'unsafe-inline' https://*.securetrustbank.com https://*.v12retailfinance.com https://siteimproveanalytics.com https://*.siteimproveanalytics.com https://*.feefo.com https://*.trustpilot.com;; font-src 'self' https://*.securetrustbank.com https://*.v12retailfinance.com https://*.trustpilot.com;; frame-src 'self' https://*.securetrustbank.com https://*.v12retailfinance.com https://*.youtube-nocookie.com https://*.trustpilot.com;; frame-ancestors 'self' 2 font-src *.fontawesome.com script.hotjar.com hyfin.app data: maxcdn.bootstrapcdn.com fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.weltpixel.com *.wesupply.xyz https://wesupplylabs.com vars.hotjar.com maps.googleapis.com stats.g.doubleclick.net *.fls.doubleclick.net cdn.evgnet.com hyfin.app *.globalpay.com *.verygoodvault.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io static.hotjar.com script.hotjar.com maps.googleapis.com stats.g.doubleclick.net cdn.evgnet.com hyfin.app *.globalpay.com *.verygoodvault.com *.gstatic.com *.googleapis.com *.cdninstagram.com *.fbcdn.net * www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.cloudflare.com script.hotjar.com static.hotjar.com maps.googleapis.com stats.g.doubleclick.net cdn.evgnet.com *.us-6.evergage.com hyfin.app *.globalpay.com *.verygoodvault.com *.smartystreets.com *.googleapis.com *.gstatic.com * www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com ajax.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.fontawesome.com static.hotjar.com script.hotjar.com cdn.evgnet.com hyfin.app *.globalpay.com *.verygoodvault.com *.gstatic.com *.googleapis.com maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com fonts.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.cdninstagram.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.hotjar.com *.hotjar.io wss://*.hotjar.com bam.nr-data.net stats.g.doubleclick.net cookie-cdn.cookiepro.com maps.googleapis.com cdn.evgnet.com *.us-6.evergage.com wss://*.hyfin.app hyfin.app *.globalpay.com *.verygoodvault.com *.smartystreets.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 font-src fonts.gstatic.com use.typekit.net www.paypalobjects.com *.gstatic.com https://s3-eu-west-1.amazonaws.com/globale-prod/Images/Help-Center/fonts/TitilliumWeb-Regular.ttf https://s3.global-e.com d1dwsi2ysdg1so.cloudfront.net d15ll0qrusyhmh.cloudfront.net fonts.googleapis.com *.fontawesome.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.snapchat.com https://plumrocket.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.demdex.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.gomoxie.solutions *.snapchat.com *.doubleclick.net *.paypalobjects.com *.kaptcha.com *.adsrvr.org https://plumrocket.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.sprinklr.com *.global-e.com *.bglobale.com *.ietf.org *.cookielaw.org *.google.ca *.doubleclick.net d1dwsi2ysdg1so.cloudfront.net us.coca-cola.com cocacola.scene7.com ct.pinterest.com *.facebook.com *.userway.org *.agkn.com *.google.com *.snapchat.com https://firebasestorage.googleapis.com maps.gstatic.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com beacon-qa.magento-datasolutions.com beacon-stage.magento-ds.com beacon.magento-ds.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com *.newrelic.com *.nr-data.net assets.adobedtm.com *.adobe.io *.commerce-payment-services.com *.magento-ds.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com *.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.magento-datasolutions.com https://rum.hlx.page js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com songbird.cardinalcommerce.com https://static.queue-it.net https://assets.queue-it.net https://edge.adobedc.net *.global-e.com *.bglobale.com https://analytics.tiktok.com https://queue.cokestore.com https://ct.pinterest.com d1dwsi2ysdg1so.cloudfront.net d15ll0qrusyhmh.cloudfront.net rpxnow.com *.rpxnow.com forty11115.pcapredict.com *.gomoxie.solutions js-agent.newrelic.com *.gstatic.com bam.nr-data.net *.coca-cola.com *.pricespider.com *.googletagmanager.com sc-static.net *.sc-static.net *.pinimg.com cdn.kxrd.net *.userway.org *.doubleclick.net connect.facebook.net cdn.krxd.net cdn.cookielaw.org api.addressy.com *.ccnag.com *.sprinklr.com *.adsrvr.org *.snapchat.com *.googleoptimize.com *.coke.com *.avada.io *.shopify.com maps.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.magento-datasolutions.com *.magento-ds.com assets.braintreegateway.com *.global-e.com *.bglobale.com https://cdn.userway.org d1dwsi2ysdg1so.cloudfront.net d15ll0qrusyhmh.cloudfront.net *.gomoxie.solutions p.typekit.net *.pricespider.com api.addressy.com cdn.cookielaw.org *.fontawesome.com https://fonts.bunny.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.sprinklr.com *.global-e.com *.bglobale.com 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.snplow.net commerce.adobedc.net p13n.adobe.io *.adobedc.net *.demdex.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.magento-datasolutions.com *.magento-ds.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com https://edge.adobedc.net *.sprinklr.com https://analytics.tiktok.com https://privacyportal.onetrust.com https://smetrics.coca-colastore.com https://gem-storefront-service-stg.bglobale.com d1dwsi2ysdg1so.cloudfront.net d15ll0qrusyhmh.cloudfront.net *.shareacoke.com *.gomoxie.solutions bam.nr-data.net *.doubleclick.net *.coca-cola.com *.coke.com *.b2clogin.com *.facebook.com ct.pinterest.com *.userway.org api.addressy.com *.ccnag.com *.paypalobjects.com *.snapchat.com *.googleapis.com *.cookielaw.org https://get.geojs.io *.avada.io maps.googleapis.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com d1dwsi2ysdg1so.cloudfront.net d15ll0qrusyhmh.cloudfront.net 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://cokestore.report-uri.com/r/d/csp/reportOnly; report-to report-endpoint; 2 font-src https://cdn.riverty.design/ *.googleapis.com https://www.gstatic.com https://fonts.gstatic.com https://widgets.trustedshops.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com uc8.tv 'self' 'unsafe-inline'; frame-ancestors *.multisafepay.com https://pay.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com player.vimeo.com https://www.google.com/recaptcha/ uc8.tv https://documents.riverty.com/ consentcdn.cookiebot.com https://www.googletagmanager.com/ https://*.google.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com *.multisafepay.com https://pay.google.com 'self' 'unsafe-inline'; img-src cdn.annadiva.nl assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com data: widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://cdn.myafterpay.com/ uc8.tv https://cdn.riverty.design/ *.googleapis.com https://*.gstatic.com imgsct.cookiebot.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ https://*.google.com https://*.googleapis.com https://*.googleusercontent.com magefan.com cm.magefan.com *.disqus.com *.multisafepay.com maps.gstatic.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com data: https: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ uc8.tv https://cdn.myafterpay.com/ https://cdn.bnpl.riverty.io/ *.googleapis.com https://*.gstatic.com https://widget-acc.paazl.com www.googleoptimize.com d36mpcpuzc4ztk.cloudfront.net consent.cookiebot.com consentcdn.cookiebot.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ *.voyado.com https://*.google.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com *.disqus.com *.multisafepay.com https://pay.google.com maps.googleapis.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://widget-acc.paazl.com https://fonts.googleapis.com https://hcaptcha.com https://*.hcaptcha.com *.multisafepay.com https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com uc8.tv https://cdn.myafterpay.com/ https://documents.myafterpay.com/ https://documents.riverty.com/ https://www.afterpay.nl/ https://cdn.bnpl.riverty.io/ https://trace-api.newrelic.com/ https://distributions.crowdin.net/ https://api.crowdin.com/ *.googleapis.com https://widget-acc.paazl.com chat.freshdesk.com consentcdn.cookiebot.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ https://ipinfo.io https://*.google.com https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com *.multisafepay.com *.trustedshops.com *.etrusted.com https://integrations.etrusted.site 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.paypal.com www.sandbox.paypal.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com https://firebasestorage.googleapis.com www.paypal.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com commerce-payments-sdk.adobe.io s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.avada.io *.shopify.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://get.geojs.io *.avada.io www.paypal.com www.sandbox.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 font-src maxcdn.bootstrapcdn.com *.fontawesome.com fonts.gstatic.com https://widgets.trustedshops.com https://integrations.etrusted.com data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.awin1.com *.zenaps.com *.fls.doubleclick.net js.mollie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.sendcloud.sc *.jsdelivr.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com validator.swagger.io *.awin1.com *.zenaps.com https://images.unsplash.com flagpedia.net https://www.mollie.com www.bunzlaucastle.nl www.bunzlaucastle.com www.bunzlaucastle.de www.bunzlaucastle.fr www.returntosender.nl returntosender.content.clipbv.com bunzlaucastle.content.clipbv.com bat.bing.com googleads.g.doubleclick.net www.google.nl www.google.com b2b.content.clipbv.com b2b.clipbv.com www.thetable.store thetable.content.clipbv.com viavel.content.clipbv.com www.viavel.nl www.facebook.com d15k2d11r6t6rl.cloudfront.net www.googletagmanager.com api.mapbox.com pins.stockist.co stockist.co c.bing.com c.clarity.ms https://widgets.trustedshops.com https://integrations.etrusted.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.amazonaws.com *.googletagmanager.com *.google-analytics.com ssl.gstatic.com www.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.awin1.com www.dwin1.com *.zenaps.com https://the.sciencebehindecommerce.com https://maps.googleapis.com *.gstatic.com maps.googleapis.com js.mollie.com bat.bing.com cdn-eu.pagesense.io app.reloadify.com s.pinimg.com connect.facebook.net ct.pinterest.com stockist.co cdnjs.cloudflare.com widget-portal.givacard.nl tagging.bunzlaucastle.nl pagead2.googlesyndication.com tagging.bunzlaucastle.com tagging.bunzlaucastle.de tagging.thetable.store tagging.returntosender.nl https://widgets.trustedshops.com https://integrations.etrusted.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.sendcloud.sc *.jsdelivr.net *.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com maxcdn.bootstrapcdn.com *.fontawesome.com *.gstatic.com fonts.googleapis.com stockist.co https://widgets.trustedshops.com https://integrations.etrusted.com unsafe-inline assets.braintreegateway.com *.sendcloud.sc *.jsdelivr.net tagmanager.google.com fonts.google.com 'self' 'unsafe-inline'; object-src b2b.content.clipbv.com 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://the.sciencebehindecommerce.com https://maps.googleapis.com https://player.vimeo.com www.gstatic.com maps.googleapis.com bat.bing.com app.reloadify.com region1.google-analytics.com ct.pinterest.com www.google.nl stockist.co us-central1-stockist-prod.cloudfunctions.net gap.stockist.workers.dev pro.ip-api.com www.pinterest.com widget-portal.givacard.nl tagging.bunzlaucastle.nl tagging.bunzlaucastle.com tagging.bunzlaucastle.de tagging.thetable.store pagead2.googlesyndication.com tagging.returntosender.nl www.facebook.com *.trustedshops.com *.etrusted.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.sendcloud.sc *.cdn.jsdelivr.net *.mapbox.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com 'self' 'unsafe-inline'; child-src *.awin1.com *.zenaps.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.cloudflare.com *.twitter.com *.twimg.com *.trustedshops.com *.googleapis.com https://*.tawk.to/ *.fontawesome.com fonts.googleapis.com maxcdn.bootstrapcdn.com http://cdnjs.cloudflare.com/ajax/libs/ data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.twitter.com *.google.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.youtube.com/ https://platform-api.sharethis.com https://buttons-config.sharethis.com https://l.sharethis.com https://scontent-ams4-1.cdninstagram.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * api.razorpay.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://platform-api.sharethis.com *.cloudflare.com *.klarna.com *.googleadservices.com *.google-analytics.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.google.com *.maps.gstatic.com maps.gstatic.com maps.googleapis.com https://clauem2.arrowtheme.com https://scontent.cdninstagram.com/ https://buttons-config.sharethis.com https://l.sharethis.com https://platform-cdn.sharethis.com https://scontent-ams4-1.cdninstagram.com https://s3.ap-south-1.amazonaws.com/* https://s3.ap-south-1.amazonaws.com https://*.tawk.to flagpedia.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com cdn.razorpay.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com */walletsystem/index/applypaymentamount www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.cloudflare.com *.twitter.com *.google-analytics.com *.twimg.com *.gstatic.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com maps.googleapis.com *.trackedlink.net *.maps.gstatic.com *.googletagmanager.com *.googleadservices.com https://connect.facebook.net https://platform-api.sharethis.com https://buttons-config.sharethis.com https://l.sharethis.com https://scontent-ams4-1.cdninstagram.com https://*.tawk.to https://adtarbo.eywamedia.com/scripts/adtarbo.min.js https://static.getbutton.io/widget-send-button/js/init.js https://adtarbo.eywamedia.com/scripts/adtarbo-core.min.js?v=66.68988515157149 player.vimeo.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com checkout.razorpay.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.cloudflare.com *.googleapis.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.google.com *.maps.gstatic.com maps.gstatic.com maps.googleapis.com *.google-analytics.com https://platform-api.sharethis.com https://buttons-config.sharethis.com https://l.sharethis.com https://*.tawk.to/ https://s3.ap-south-1.amazonaws.com/* https://s3.ap-south-1.amazonaws.com maxcdn.bootstrapcdn.com assets.braintreegateway.com unsafe-inline http://cdnjs.cloudflare.com/ajax/libs/ 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.cloudflare.com *.twitter.com *.twimg.com *.googleadservices.com *.google-analytics.com *.sandbox.paypal.com *.paypalobjects.com *.trackedlink.net *.ampproject.org *.google.co.in *.maps.gstatic.com *.maps.googleapis.com maps.googleapis.com https://platform-api.sharethis.com https://buttons-config.sharethis.com https://l.sharethis.com https://scontent-ams4-1.cdninstagram.com https://*.tawk.to/ wss://*.tawk.to https://adtarbo.eywamedia.com/ www.gstatic.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com lumberjack.razorpay.com lumberjack-metrics.razorpay.com *.gstatic.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://csp-reporting-service.com/my-project/endpoint; report-to report-endpoint; 2 font-src *.gstatic.com *.addtoany.com *.hotjar.com *.hotjar.io *.gettopple.com https://analytics.tiktok.com https://static.klaviyo.com https://wsv3cdn.audioeye.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com 'self' business.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com 'self' 'unsafe-inline'; frame-ancestors *.certcapture.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.certcapture.com *.addtoany.com *.hotjar.com *.hotjar.io *.hsforms.com *.google.com *.braintreegateway.com *.paypal.com *.kaptcha.com https://bid.g.doubleclick.net *.gettopple.com https://analytics.tiktok.com *.weltpixel.com business.facebook.com www.commercepartnerhub.com platform.twitter.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.googletagmanager.com *.doubleclick.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.certcapture.com *.paypal.com *.hubspot.com *.hotjar.com *.hotjar.io wss://*.hotjar.com *.google.com blob: https://a5.behance.net https://www.googletagmanager.com *.hsforms.com https://forms.hsforms.com https://forms-na1.hsforms.com *.gettopple.com https://analytics.tiktok.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://firebasestorage.googleapis.com business.facebook.com pinterest.com assets.pinterest.com syndication.twitter.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com https://redchamps.com *.hsforms.net *.gstatic.com *.facebook.com *.reddit.com *.google-analytics.com *.googletagmanager.com *.doubleclick.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.certcapture.com https://developer.adobe.com https://magento.com https://cdn.avmws.com/ http://cdn.avmws.com/ https://wsmcdn.audioeye.com/aem.js *.gstatic.com https://ssl.avmws.com *.addtoany.com *.hotjar.com *.hotjar.io *.hsforms.com *.hsforms.net *.hs-scripts.com *.hsleadflows.net *.hs-analytics.net *.hs-banner.com *.google.com *.braintreegateway.com *.paypal.com amcglobal.sc.omtrdc.net https://js.hsadspixel.net https://connect.facebook.net https://googleads.g.doubleclick.net https://cdnjs.cloudflare.com *.gettopple.com https://analytics.tiktok.com player.vimeo.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.avada.io *.shopify.com business.facebook.com twitter.com platform.twitter.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com *.googletagmanager.com *.googleadservices.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com unpkg.com *.doubleclick.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.certcapture.com *.googleapis.com amcglobal.sc.omtrdc.net *.gettopple.com https://analytics.tiktok.com https://static.klaviyo.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com *.tagmanager.google.com *.googletagmanager.com fonts.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.certcapture.com https://developer.adobe.com https://cdn.avmws.com/ http://cdn.avmws.com/ *.hubspot.com *.google.com hubspot-forms-static-embed.s3.amazonaws.com *.braintreegateway.com *.braintree-api.com *.paypal.com *.hotjar.com *.hotjar.io wss://*.hotjar.com *.hs-banner.com *.facebook.net https://api.hubapi.com https://googleads.g.doubleclick.net *.doubleclick.net https://dpm.demdex.net *.hsforms.com https://forms.hsforms.com *.gettopple.com https://analytics.tiktok.com https://analytics-ipv6.tiktokw.us/ipv6/enrich_ipv6 https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://get.geojs.io *.avada.io business.facebook.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com google.com t.elasticsuite.io *.hsforms.net *.google-analytics.com *.analytics.google.com *.redditstatic.com *.reddit.com *.tiktok.com *.run.app 'self' 'unsafe-inline'; child-src *.certcapture.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 default-src 'self'; connect-src 'self' dc.services.visualstudio.com ssl.google-analytics.com stats.g.doubleclick.net https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com partner.testseek.com intranet.microk12.com middleman.microk12.com; font-src 'self' data: fonts.gstatic.com static.stockinthechannel.com; frame-src 'self' accounts.us.stockinthechannel.com app.powerbi.com ad.doubleclick.net bid.g.doubleclick.net www.youtube.com www.google.com www.vimeo.com; frame-ancestors accounts.us.stockinthechannel.com; img-src * data:; media-src 'self' images.us.stockinthechannel.com media.stockinthechannel.com static.stockinthechannel.com; manifest-src images.us.stockinthechannel.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' 'report-sample' accounts.us.stockinthechannel.com images.us.stockinthechannel.com static.stockinthechannel.com www.googleadservices.com ssl.google-analytics.com googleads.g.doubleclick.net https://*.googletagmanager.com www.google.com www.gstatic.com www.youtube.com; style-src 'self' 'unsafe-inline' static.stockinthechannel.com fonts.googleapis.com ajax.googleapis.com; report-uri https://stockchannel.report-uri.com/r/d/csp/reportOnly 2 default-src 'self' *.zdassets.com *.zopim.com *.zendesk.com wss://*.zendesk.com wss://*.zopim.com ; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.klaviyo.com cdn.qantasloyalty.com api-accent.bloomreach.co api.smooch.io mpsnare.iesnare.com/snare.js mpsnare.iesnare.com/script/logo.js applepay.cdn-apple.com *.googleadservices.com assets.braintreegateway.com/web *.bazaarvoice.com *.doubleclick.net storage.googleapis.com/workbox-cdn www.google.com/recaptcha www.gstatic.com/recaptcha *.squarecdn.com cfjump.drmartens.com.au cfjump.drmartens.co.nz *.fullstory.com www.googletagmanager.com analytics.tiktok.com cdn.unidays.world *.truefitcorp.com www.paypalobjects.com/api/checkout.min.js *.klaviyo.com t.cfjump.com *.zdassets.com connect.facebook.net maps.googleapis.com dma-cdn.staging.truefitcorp.com/fitrec/dma/js/tracker.js js-agent.newrelic.com js.datadome.co ct.captcha-delivery.com *.adobedtm.com *.afterpay.com *.demdex.net *.forter.com dlthst9q2beh8.cloudfront.net d2nww8zpyj5pk0.cloudfront.net *.google-analytics.com *.paypal.com afterpay.com foursixty.com *.useinsider.com *.roymorgan.com *.adobemc.com ajax.googleapis.com/ajax/libs/jquery/2.1.1/jquery.min.js js-sandbox.squarecdn.com s.pinimg.com lantern.roeyecdn.com ct.pinterest.com js.squarecdn.com *.stg.qantasloyalty.com/appcache/wid-redemptions-button/master/ ; style-src 'self' 'unsafe-inline' *.klaviyo.com/onsite/ display.ugc.bazaarvoice.com maxcdn.bootstrapcdn.com/font-awesome *.typekit.net fonts.googleapis.com assets.braintreegateway.com assets.braintreegateway.com/web/dropin/1.16.0/css/dropin.css *.adobetm.com foursixty.com *.adobemc.com static.klaviyo.com/onsite/js static-tracking.klaviyo.com/onsite/js assets.api.useinsider.com/css ; img-src data: 'self' api-accent.bloomreach.co *.zendesk.com dpm.demdex.net www.googleadservices.com/ccm www.magentocommerce.com/products/media *.drmartens.co.nz *.drmartens.com.au cm.everesttech.net/cm/dd googleads.g.doubleclick.net ad.doubleclick.net www.google.com/ccm www.paypalobjects.com www.google.com www.google.com.au www.google.co.nz www.google.com.vn maps.gstatic.com/mapfiles scontent.cdninstagram.com *.afterpay.com *.accentgra.com www.googletagmanager.com www.facebook.com *.bazaarvoice.com t.paypal.com duuytoqss3gu4.cloudfront.net df45ay5pw60dy.cloudfront.net d3nocrch4qti4v.cloudfront.net *.google-analytics.com *.pinterest.com *.tiktok.com *.useinsider.com maps.googleapis.com/maps developers.google.com *.zopim.io *.zdassets.com adservice.google.com www.drmartens.com lantern.roeye.com ; object-src 'none' ; base-uri 'self' ; child-src 'self' blob: ; connect-src 'self' gateway.stg.qantasloyalty.com gateway.qantasloyalty.com api-accent.bloomreach.co analytics.google.com/g/collect iq.afterpay.com/us/v1 iq.afterpay-beta.com/us/v1 *.my.sentry.io wss://api.smooch.io *.accentgra.com www.facebook.com/tr google.com www.google.com collect-ap2.attraqt.io smetrics.drmartens.co.nz *.fullstory.com *.klaviyo.com smetrics.drmartens.com.au api-js.datadome.co *.adobedc.net *.afterpay.com *.bazaarvoice.com *.braintree-api.com *.braintreegateway.com *.demdex.net *.forter.com *.foursixty.com google.com/ccm www.google.com/ccm *.google-analytics.com *.googleapis.com *.nr-data.net *.paypal.com *.taboola.com *.truefitcorp.com *.zdassets.com *.zendesk.com *.zopim.com accentgroupxpdev.112.2o7.net afterpay.com analytics.tiktok.com facebook.com *.roymorgan.com foursixty.com kleber.datatoolscloud.net.au sentry.io vimeo.com wss://widget-mediator.zopim.com d2o5idwacg3gyw.cloudfront.net dz8rit8v72mig.cloudfront.net d2lxqodqbpy7c2.cloudfront.net d6rak4b14t5gp.cloudfront.net d3k4bt74u9esq1.cloudfront.net wss://cdn0.forter.com *.useinsider.com api.myunidays.com opreq.observepoint.com ct.pinterest.com stats.g.doubleclick.net/g/collect *.stg.qantasloyalty.com/redemptions/ ; font-src data: 'self' maxcdn.bootstrapcdn.com/font-awesome fonts.gstatic.com *.truefitcorp.com *.useinsider.com static.klaviyo.com use.typekit.net ; frame-src 'self' checkout.qantas.com api-accent.bloomreach.co www.googletagmanager.com geo.captcha-delivery.com *.formstack.com *.afterpay.com *.bazaarvoice.com *.criteo.net *.demdex.net *.everesttech.net *.everestjs.net *.doubleclick.net *.facebook.com *.myunidays.com *.omniparcelreturns.com *.paypal.com *.paypalobjects.com *.truefitcorp.com *.useinsider.com *.vimeo.com *.youtu.be *.youtube.com afterpay.com assets.braintreegateway.com everestjs.net facebook.com foursixty.com google.com www.google.com vimeo.com ct.pinterest.com *.qlstg.qantas.com/ ; worker-src 'self' blob: *.accentgra.com *.drmartens.co.nz *.drmartens.com.au; 2 default-src https:; script-src https: 'unsafe-eval' 'unsafe-inline'; style-src https: 'unsafe-inline'; media-src https: data:; object-src https: data:; img-src https: data:; font-src https: data:; report-uri /csp-report 2 object-src 'none'; script-src 'self' https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com 'unsafe-inline' https://analytics.aefe.fr/; script-src-attr 'self'; script-src-elem 'self' https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com; style-src 'self' https://app.unpkg.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com; style-src-attr 'self'; frame-ancestors 'self' 2 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.tawk.to cdnjs.cloudflare.com cdn.jsdelivr.net voidlabs.containers.piwik.pro dl.frontapp.com hcaptcha.com; connect-src 'self' wss://*.tawk.to *.tawk.to newassets.hcaptcha.com; style-src 'self' 'unsafe-inline' cdnjs.cloudflare.com fonts.googleapis.com embed.tawk.to; frame-src 'self' demo.voxmail.it www.youtube-nocookie.com newassets.hcaptcha.com; font-src 'self' cdnjs.cloudflare.com fonts.gstatic.com embed.tawk.to; media-src 'self' embed.tawk.to; report-uri https://catbzhkx.uriports.com/reports/report 2 default-src 'self'; script-src 'self' https://trusted-scripts.example.com;style-src 'self'; 2 default-src https: data: 'unsafe-inline' 'unsafe-eval'; report-uri /nmms/csp-reporting-lo 2 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com https://*.gstatic.com data: 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com https://widgets.trustedshops.com *.fontawesome.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com *.googlesyndication.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.sendcloud.sc *.jsdelivr.net js.mollie.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.googleapis.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.googlesyndication.com *.roeye.com https://belco-prod.s3-eu-central-1.amazonaws.com https://images.unsplash.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com *.etrusted.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.sooqr.com *.spotlersearch.com www.magmodules.eu *.squeezely.tech *.amazonaws.com https://firebasestorage.googleapis.com https://www.mollie.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.googlesyndication.com *.jsdelivr.net https://cdn.belco.io https://maps.googleapis.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.etrusted.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.sooqr.com *.spotlersearch.com spotlersearchanalytics.com squeezely.tech www.squeezely.tech *.squeezely.tech *.sendcloud.sc *.avada.io *.shopify.com js.mollie.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com https://*.googleapis.com https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.etrusted.com assets.braintreegateway.com *.sooqr.com *.spotlersearch.com *.sendcloud.sc *.jsdelivr.net *.fontawesome.com https://fonts.bunny.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.googleapis.com *.google-analytics.com *.facebook.com *.facebook.net *.doubleclick.net *.googlesyndication.com wss://chat.belco.io https://cdn.belco.io https://maps.googleapis.com https://player.vimeo.com *.trustedshops.com *.etrusted.com https://integrations.etrusted.site api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.sooqr.com *.spotlersearch.com squeezely.tech *.squeezely.tech *.sendcloud.sc *.cdn.jsdelivr.net *.mapbox.com https://get.geojs.io *.avada.io 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 default-src https: data: blob: ; object-src https: data: 'unsafe-inline'; style-src https: data: 'unsafe-inline' ; script-src https: data: 'unsafe-inline' 'unsafe-eval' 2 default-src https:; script-src https: 'unsafe-eval' 'unsafe-inline'; style-src https: 'unsafe-inline'; img-src https: data:; font-src https: data:; report-uri /csp-report; connect-src https: wss://*.lkiit.ru wss://*.iitrust.ru:* wss://*.sber-solutions.ru 2 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://fonts.gstatic.com https://use.fontawesome.com https://cdn.nlpg.com https://cdn.masterbooks.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.masterbooks.com *.nlpg.com self https: 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com www.google.com *.youtu.be *.dotdigital-pages.com *.dotdigital.com webchat.dotdigital.com webchat.staging.dotdigital.com *.doubleclick.net *.masterbooks.com *.nlpg.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * www.xtento.com www.facebook.com platform.twitter.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net https://images.unsplash.com *.youtu.be *.img.youtube.com *.trackedlink.net www.facebook.com https://online.flippingbook.com https://*.cloudfront.net https://*.masterbooks.com https://*.nlpg.com *.google.com.ar *.google.com *.googletagmanager.com https://cdn-cookieyes.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com www.xtento.com cdn.xtento.com pinterest.com assets.pinterest.com syndication.twitter.com flagpedia.net *.google-analytics.com ssl.gstatic.com www.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://maps.googleapis.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal webchat.dotdigital.com webchat.staging.dotdigital.com https://cdn.noibu.com https://cdn.jsdelivr.net https://connect.facebook.net https://static.zdassets.com https://online.flippingbook.com https://*.cloudfront.net https://cdn.nlpg.com https://cdn.masterbooks.com *.googletagmanager.com app.viralsweep.com https://cdn-cookieyes.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com www.xtento.com cdn.xtento.com connect.facebook.net twitter.com platform.twitter.com static.addtoany.com *.gstatic.com maps.googleapis.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com webchat.dotdigital.com webchat.staging.dotdigital.com https://fonts.googleapis.com https://use.fontawesome.com https://cdn.nlpg.com https://cdn.masterbooks.com *.googletagmanager.com *.googleapis.com assets.braintreegateway.com maxcdn.bootstrapcdn.com *.gstatic.com tagmanager.google.com fonts.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.youtube.com *.youtu.be *.img.youtube.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://maps.googleapis.com https://player.vimeo.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com https://ekr.zdassets.com https://fbo-b.flippingbook.com https://nlpg.zendesk.com wss://input.noibu.com *.noibu.com *.doubleclick.net https://cdn.nlpg.com https://cdn.masterbooks.com https://www.google.com.ar https://www.facebook.com *.cookieyes.com https://cdn-cookieyes.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com stats.addtoany.com www.gstatic.com maps.googleapis.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://53272415-ac62-4480-bded-0011a34ac7cd.sansec.watch/; report-to report-endpoint; 2 default-src 'self'; script-src 'self' 'strict-dynamic' https: data:; object-src 'none'; style-src 'self' 'unsafe-inline'; img-src 'self' https: data:; connect-src 'self' https://www.google-analytics.com https://www.googletagmanager.com; report-uri /report-csp-violation; upgrade-insecure-requests 2 font-src *.gstatic.com 'self' data: fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.cookiebot.com *.google.com maps.googleapis.com js.mollie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.googletagmanager.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.google.co.uk *.cloudflare.com *.google.co.in maps.googleapis.com https://images.unsplash.com https://www.mollie.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.hsforms.net *.hsforms.com 'self' data: *.googletagmanager.com *.google-analytics.com ssl.gstatic.com www.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com *.vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.cookiebot.com *.bing.com *.facebook.net *.google.com *.googleapis.com static.cloudflareinsights.com www.gstatic.com https://maps.googleapis.com js.mollie.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.hsforms.net *.hsforms.com *.gstatic.com *.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com maps.googleapis.com unsafe-inline assets.braintreegateway.com *.googleapis.com *.gstatic.com tagmanager.google.com fonts.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com maps.googleapis.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.google.com *.cookiebot.com googleads.g.doubleclick.net maps.googleapis.com https://maps.googleapis.com https://player.vimeo.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com google.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 font-src fonts.gstatic.com use.typekit.net maxcdn.bootstrapcdn.com www.searchanise.com *.searchserverapi.com searchserverapi.com *.searchserverapi1.com searchserverapi1.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com eu-gateway.mastercard.com ap-gateway.mastercard.com na-gateway.mastercard.com *.gateway.mastercard.com *.mpgs.axisbank.com *.americanexpress.com *-gateway.mastercard.com *.accertify.net *paymentsvcs.com *.amxvpos.com *.accelya.com *.commbank.com.au *.americanexpress.co.in *.areeba.com *.bbvaglobalgateway.com *.arcpay.travel *.merchantlink.com *paymentgateway.nomba.com *.nab.com.au *.unicredit.ro *paymentgateway.epay.halykbank.kz *commerce.nbg.gr *.prahsys.com www.searchanise.com *.searchserverapi.com *.searchserverapi1.com *.twitter.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com eu-gateway.mastercard.com ap-gateway.mastercard.com na-gateway.mastercard.com *.gateway.mastercard.com *.mpgs.axisbank.com *.americanexpress.com *-gateway.mastercard.com *.accertify.net *paymentsvcs.com *.amxvpos.com *.accelya.com *.commbank.com.au *.americanexpress.co.in *.areeba.com *.bbvaglobalgateway.com *.arcpay.travel *.merchantlink.com *paymentgateway.nomba.com *.nab.com.au *.unicredit.ro *paymentgateway.epay.halykbank.kz *commerce.nbg.gr *.prahsys.com www.googletagmanager.com www.searchanise.com *.searchserverapi.com *.searchserverapi1.com *.twitter.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.google.com *.googleadservices.com *.googletagmanager.com *.twitter.com *.twimg.com www.google.ru www.searchanise.com *.searchserverapi.com searchserverapi.com *.searchserverapi1.com searchserverapi1.com s3.amazonaws.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com commerce-payments-sdk.adobe.io s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com eu-gateway.mastercard.com ap-gateway.mastercard.com na-gateway.mastercard.com *.gateway.mastercard.com *.gateway.spring.citi.com *.mpgs.axisbank.com *.americanexpress.com *-gateway.mastercard.com *.accertify.net *paymentsvcs.com *.amxvpos.com *.accelya.com *.commbank.com.au *.americanexpress.co.in *.areeba.com *.bbvaglobalgateway.com *.arcpay.travel *.merchantlink.com *paymentgateway.nomba.com *.nab.com.au *.unicredit.ro *paymentgateway.epay.halykbank.kz *commerce.nbg.gr *.prahsys.com *.googletagmanager.com *.googleadservices.com *.google-analytics.com searchanise-ef84.kxcdn.com s3.amazonaws.com ajax.aspnetcdn.com www.searchanise.com *.searchserverapi.com searchserverapi.com *.searchserverapi1.com searchserverapi1.com *.searchanise.com api.amplitude.com *.twitter.com *.twimg.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com maxcdn.bootstrapcdn.com www.searchanise.com *.searchserverapi.com searchserverapi.com *.searchserverapi1.com searchserverapi1.com searchanise-ef84.kxcdn.com s3.amazonaws.com *.twitter.com ton.twimg.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.adobe.io performance.typekit.net *.sentry.io www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.googletagmanager.com stats.g.doubleclick.net api.amplitude.com www.google-analytics.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.bootstrapcdn.com js.klevu.com *.finance-calculator.co.uk *.klarnacdn.net *.klevu.com *.ksearchnet.com *.magentocommerce.com *.googleapis.com *.cloudfront.net fonts.googleapis.com *.hotjar.com *.zopim.com *.fontawesome.com *.paypal.com *.feefo.com *.postcodeanywhere.co.uk *.magentosite.cloud https://www.gstatic.com https://fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com https://plumrocket.com www.facebook.com 1merchantacsstag.cardinalcommerce.com payments.securetrading.net 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com *.instagram.com https://www.google.com *.doubleclick.net *.facebook.com assets.braintreegateway.com tst.kaptcha.com c.paypal.com www.paypalobjects.com *.zopim.com *.finance-calculator.co.uk *.deko.finance *.dekopay.com *.dekopay.org *.klarnacdn.net https://plumrocket.com *.magentocommerce.com cdn.dnky.co *.hotjar.com www.facebook.com *.trustpilot.com *.feefo.com *.postcodeanywhere.co.uk *.magentosite.cloud x.klarnacdn.net *.pinterest.com *.pinterdev.com commerce-app.pintergration.com webservices.securetrading.net cdn.eu.trustpayments.com brw.3ds.trustpayments.com songbirdstag.cardinalcommerce.com 1merchantacsstag.cardinalcommerce.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.cdninstagram.com 'self' data: https://*.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.bing.com *.clarity.ms js.klevu.com cdn-cookieyes.com *.finance-calculator.co.uk *.dekopay.com *.klarnacdn.net *.klarnaevt.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com *.magentocommerce.com *.cloudfront.net https://*.gstatic.com www.google.nl connect.onlinesucces.nl px.ads.linkedin.com *.googleapis.com www.linkedin.com linkedin.com gallery.mailchimp.com *.trustedshops.com *.zopim.com cdn.jsdelivr.net *.feefo.com *.postcodeanywhere.co.uk *.magentosite.cloud *.increasingly.co https://*.googleapis.com https://*.googleusercontent.com https://www.magezon.com *.pinterest.com *.pinterdev.com *.pinimg.com commerce-app.pintergration.com gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.instagram.com 'self' *.google.com/ *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com bat.bing.com js.klevu.com *.clarity.ms c.paypal.com chimpstatic.com cdn-cookieyes.com *.hotjar.com sentry.bigeyedeers.dev browser.sentry-cdn.com *.finance-calculator.co.uk *.dekopay.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.ksearchnet.com *.magentocommerce.com *.cloudfront.net maps.googleapis.com *.trackedlink.net *.increasingly.co *.increasingly.com *.googleapis.com cdn.dnky.co api.comapi.com snap.licdn.com checkout.buckaroo.nl *.adyen.com *.zopim.com *.zdassets.com *.sendcloud.sc *.mailchimp.com *.trustedshops.com *.fontawesome.com www.feedbackcompany.com *.trustpilot.com cdn.jsdelivr.net www.googleoptimize.com *.paypal.com js.klarna.com *.eu-library.klarnaservices.com/lib.js *.feefo.com *.postcodeanywhere.co.uk *.magentosite.cloud *.mouseflow.com *.webgains.io https://*.gstatic.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com player.vimeo.com *.pinterest.com *.pinterdev.com *.pinimg.com commerce-app.pintergration.com https://apis.google.com webservices.securetrading.net cdn.eu.trustpayments.com songbirdstag.cardinalcommerce.com https://js.klevu.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.bootstrapcdn.com *.typekit.net js.klevu.com *.klarnacdn.net https://static.klaviyo.com *.klevu.com *.ksearchnet.com 'self' *.magentocommerce.com *.cloudfront.net cdn.dnky.co *.fontawesome.com *.mailchimp.com *.finance-calculator.co.uk *.trustpilot.com cdn.jsdelivr.net *.paypal.com *.feefo.com *.postcodeanywhere.co.uk *.magentosite.cloud *.increasingly.co https://fonts.googleapis.com https://statsjs.klevu.com https://js.klevu.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.cdninstagram.com *.zopim.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.google-analytics.com *.facebook.com *.facebook.net https://*.google.com *.sandbox.braintree-api.com *.clarity.ms *.cookieyes.com cdn-cookieyes.com *.doubleclick.net *.trustpilot.com *.hotjar.com *.googlesyndication.com sentry.bigeyedeers.dev *.finance-calculator.co.uk *.dekopay.com *.klarnaevt.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com *.cloudfront.net *.magentocommerce.com commerce.adobedc.net api.comapi.com *.googleapis.com *.zdassets.com *.hotjar.io *.zopim.com wss://*.zopim.com www.feedbackcompany.com *.zendesk.com *.eu-library.klarnaservices.com/lib.js *.feefo.com *.postcodeanywhere.co.uk *.magentosite.cloud *.increasingly.co api.addressy.com https://ipinfo.io https://*.gstatic.com https://*.googleapis.com *.pinterest.com *.pinterdev.com commerce-app.pintergration.com o402164.ingest.sentry.io 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 font-src www.paypalobjects.com *.relaxdays.com *.gstatic.com *.trustami.com cdn.userway.org *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com 'self' data: data: 'self' 'unsafe-inline'; form-action *.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.facebook.com *.pinterest.com 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src *.paypal.com www.paypalobjects.com *.relaxdays.com *.youtube.com *.google.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.consentmanager.net *.googlesyndication.com *.youtube-nocookie.com *.facebook.com *.pinterest.com *.pinterest.de *.sibforms.com sibautomation.com *.paypalobjects.com *.googletagmanager.com cdn.userway.org *.doubleclick.net conversations-widget.brevo.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com 'self' 'unsafe-inline'; img-src data: widgets.magentocommerce.com *.paypal.com *.paypalobjects.com *.relaxdays.com i.ytimg.com *.youtube.com *.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.payments-amazon.com *.consentmanager.net www.it-recht-kanzlei.de *.clarity.ms *.google.com *.pinimg.com *.pinterest.com *.doubleclick.net *.googleadservices.com *.google-analytics.com *.googletagmanager.com *.gstatic.com *.googleusercontent.com *.facebook.com *.tiktok.com alb.reddit.com www.datenschutz.net *.trustami.com bat.bing.com bat.bing.net cdn.userway.org www.google.de www.google.ch www.google.at www.google.es www.google.it www.google.nl www.google.pl www.google.be www.google.sk www.google.pt www.google.fr www.google.dk www.google.se www.google.co.uk www.google.bg www.google.cz www.google.ee www.google.gr www.google.hu www.google.lv www.google.lt www.google.lu www.google.ro www.google.si www.google.ie www.google.hr www.google.fi www.google.com.mt www.google.com.cy 'self' data: data: 'self' 'unsafe-inline'; script-src *.newrelic.com *.nr-data.net *.paypal.com *.paypalobjects.com s.ytimg.com *.googleapis.com *.relaxdays.com *.youtube.com *.gstatic.com *.google.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.consentmanager.net *.clarity.ms *.pinterest.com *.pinimg.com *.googletagmanager.com *.googleadservices.com *.google-analytics.com *.facebook.net *.doubleclick.net *.googlesyndication.com bat.bing.com bat.bing.net bat.bing-int.com *.tiktok.com sibautomation.com *.sendinblue.com www.redditstatic.com *.trustami.com conversations-widget.brevo.com cdn.userway.org www.google.de www.google.ch www.google.at www.google.es www.google.it www.google.nl www.google.pl www.google.be www.google.sk www.google.pt www.google.fr www.google.dk www.google.se www.google.co.uk www.google.bg www.google.cz www.google.ee www.google.gr www.google.hu www.google.lv www.google.lt www.google.lu www.google.ro www.google.si www.google.ie www.google.hr www.google.fi *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.relaxdays.com *.googletagmanager.com *.googleapis.com *.gstatic.com cdn.userway.org *.stripe.network *.stripecdn.com *.amazon.com 'self' 'unsafe-inline'; object-src *.relaxdays.com 'self' 'unsafe-inline'; media-src *.relaxdays.com 'self' 'unsafe-inline'; manifest-src *.relaxdays.com 'self' 'unsafe-inline'; connect-src *.newrelic.com *.nr-data.net *.paypal.com *.paypalobjects.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.relaxdays.com blob: *.consentmanager.net *.google.com *.clarity.ms *.google-analytics.com *.googletagmanager.com *.googleadservices.com *.doubleclick.net *.googlesyndication.com google.com www.google.de www.google.ch www.google.at www.google.es www.google.it www.google.nl www.google.pl www.google.be www.google.sk www.google.pt www.google.fr www.google.dk www.google.se www.google.co.uk www.google.bg www.google.cz www.google.ee www.google.gr www.google.hu www.google.lv www.google.lt www.google.lu www.google.ro www.google.si www.google.ie www.google.hr www.google.fi *.facebook.com *.pinterest.com bat.bing.com bat.bing.net bat.bing-int.com *.tiktok.com *.sendinblue.com in-automate.brevo.com analytics.pangle-ads.com analytics-ipv6.tiktokw.us api.userway.org cdn.userway.org cmodul.solutenetwork.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://relaxdays.com/_csp_report_; report-to report-endpoint; 2 worker-src * blob:; font-src *.typekit.net *.gstatic.com fonts.gstatic.com use.typekit.net *.fontawesome.com *.zdassets.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com *.mb-app.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.hcaptcha.com hcaptcha.com cdn.jsdelivr.net *.cloudflare.com *.twitter.com *.google.co.in *.facebook.com *.googleadservices.com *.google-analytics.com *.gstatic.com *.usercentrics.eu *.fontawesome.com connect.facebook.net *.paypalobjects.com *.googletagmanager.com *.trustpilot.com *.cookiebot.com *.doubleclick.net *.stripe.com *.zendesk.com *.zdassets.com *.googleapis.com *.atlantic.fr *.azurewebsites.net c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com p.typekit.net validator.swagger.io groupe-mb.scene7.com *.cloudflare.com *.google.com *.google.co.in www.facebook.com *.klarna.com *.googleadservices.com *.google-analytics.com *.twitter.com *.twimg.com *.connect.facebook.net *.doubleclick.net *.google.fr *.trustpilot.com * *.stripe.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.commerce-payment-services.com *.typekit.net google.com *.google.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.hcaptcha.com hcaptcha.com maps.googleapis.com cdn.jsdelivr.net *.cloudflare.com *.twitter.com *.google.co.in *.facebook.com *.googleadservices.com *.google-analytics.com *.gstatic.com *.usercentrics.eu *.fontawesome.com connect.facebook.net *.paypalobjects.com *.paypal.com *.googletagmanager.com *.trustpilot.com *.cookiebot.com *.doubleclick.net *.stripe.com *.licdn.com *.bing.com *.zendesk.com *.zdassets.com *.clarity.ms *.sparkow.net t4.my-probance.one *.contentsquare.net *.googleapis.com bam.nr-data.net bam.eu01.nr-data.net *.octipas-emerch.net js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.gstatic.com *.zoovu.com assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.zdassets.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.paypal.com google.com *.google.com *.adobe.io performance.typekit.net *.sentry.io *.hcaptcha.com hcaptcha.com cdn.jsdelivr.net *.cloudflare.com *.twitter.com *.google.co.in *.facebook.com *.googleadservices.com *.google-analytics.com *.gstatic.com *.usercentrics.eu *.fontawesome.com connect.facebook.net *.paypalobjects.com *.googletagmanager.com *.youtube.com *.trustpilot.com *.cookiebot.com *.doubleclick.net *.stripe.com *.clarity.ms *.scandit.com *.zendesk.com tereva.zendesk.com mabeo.zendesk.com tereva.zendesk.com/frontendevents mabeo.zendesk.com/frontendevents *.zdassets.com *.bing.com *.sparkow.net *.contentsquare.net bam.nr-data.net bam.eu01.nr-data.net *.googleapis.com *.octipas-emerch.net *.linkedin.com px.ads.linkedin.com/wa/ *.zoovu.com *.cloudfront.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 frame-src 'self' *.app.baqend.com www.youtube.com www.google.com js.playground.klarna.com js.klarna.com https://checkoutshopper-test.adyen.com https://pay.google.com https://wchat.freshchat.com https://connect.getflowbox.com return.4sellers.de *.webpush.freshchat.com ct.pinterest.com vercel.live *.sovendus.com *.adyen.com gum.criteo.com fledge.eu.criteo.com *.cnstrc.com cnstrc.com graphical-editor.kameleoon.com *.vimeo.com vimeo.com www.googletagmanager.com *.chat.getzowie.com 2 frame-src 'self' https://consentcdn.cookiebot.com https://checkoutshopper-test.adyen.com/ https://checkoutshopper.adyen.com/ https://checkoutshopper-live.adyen.com https://pay.google.com https://td.doubleclick.net https://tr.snapchat.com https://ajax.cloudflare.com https://cdn.cxense.com https://scdn.cxense.com https://id.cxense.com https://www.googleadservices.com https://mainf.global-cache.online https://www.gstatic.com https://analytics.soulz.lt https://analytics.soulz.lv https://analytics.soulz.ee https://app.omnisend.com https://cdn.userway.org https://www.googletagmanager.com https://omnisnippet1.com https://www.google.com https://acs2.3ds.modirum.com https://acs.3ds.modirum.com https://acs1.3ds.modirum.com https://acs1.swedbank.se https://acs2.swedbank.se https://3ds2-visasecure2.acdcproc.com https://3dsec.cardcenter.ch https://googleads.g.doubleclick.net https://acs.revolut.com https://acs-challenge.apata.io https://pal-test.adyen.com; object-src 'none'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://boomio-widgets.adomas.workers.dev https://connect.facebook.net https://consentcdn.cookiebot.com https://*.cookiebot.com https://assets.pinterest.com https://omnisnippet1.com https://www.googletagmanager.com https://www.redditstatic.com https://services.digitalmatter.ai http://assets.pinterest.com https://www.primeai.co.uk https://www.google-analytics.com https://scdn.cxense.com/cx.js https://static.cloudflareinsights.com https://pay.google.com https://maps.googleapis.com https://checkoutshopper-test.adyen.com https://unpkg.com https://cdn.cxense.com https://analytics.tiktok.com https://ajax.cloudflare.com https://script.hotjar.com https://static.hotjar.com https://payment.ecommerce.sebgroup.com https://googleads.g.doubleclick.net https://instagram.com https://tr.snapchat.com https://sc-static.net https://checkoutshopper-live.adyen.com https://id.cxense.com https://www.googleadservices.com https://analytics.soulz.lt https://analytics.soulz.lv https://analytics.soulz.ee https://test.soulz.lt/cdn-cgi/challenge-platform/scripts/jsd/main.js https://soulz.lt/cdn-cgi/challenge-platform/scripts/jsd/main.js https://soulz.lv/cdn-cgi/challenge-platform/scripts/jsd/main.js https://soulz.ee/cdn-cgi/challenge-platform/scripts/jsd/main.js https://ajax.googleapis.com https://app.omnisend.com https://www.google.com https://www.gstatic.com; report-uri /nelmio/csp/report 2 default-src 'self' https://*.trinitywallstreet.org; connect-src 'self' https://translate.googleapis.com https://bam.nr-data.net https://*.kaltura.com https://analytics.google.com https://stats.g.doubleclick.net; font-src * data:; img-src * data:; object-src 'none'; script-src 'self' 'unsafe-inline' 'unsafe-eval' blob: https://translate.google.com https://translate.googleapis.com addevent.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://js.hs-scripts.com https://static.addtoany.com https://unpkg.com https://www.eventbrite.com https://www.google.com; script-src-attr 'self' 'unsafe-inline'; script-src-elem 'self' 'unsafe-inline' https://*.google.com https://*.googleapis.com https://*.google-analytics.com https://*.newrelic.com https://*.kaltura.com https://*.addevent.com/ https://www.googletagmanager.com addevent.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://js.hs-scripts.com https://static.addtoany.com https://unpkg.com https://www.eventbrite.com https://www.google.com; style-src 'self' 'unsafe-inline' https://www.gstatic.com cloud.typography.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com; style-src-attr 'self' 'unsafe-inline'; style-src-elem 'self' 'unsafe-inline' https://www.gstatic.com https://live-tcws-new.pantheonsite.io https://*.googleapis.com/ cloud.typography.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com; worker-src 'self' blob:; frame-ancestors 'self'; report-uri https://trinitychurchnyc.org/report-uri/reportOnly 2 require-trusted-types-for 'script'; report-uri https://csp.withgoogle.com/csp/youtube-marketing/artists_youtube 2 font-src fonts.gstatic.com use.typekit.net *.cloudfront.net *.klaviyo.com *.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' *.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net https://*.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.googletagmanager.com widgets.sandbox.afterpay.com widgets.sandbox.clearpay.co.uk www.google.com https://*.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com *.braintreegateway.com *.google.com *.doubleclick.net *.shophumm.com.au *.criteo.com *.hotjar.com *.adsrvr.org *.freshchat.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.wesupply.xyz https://wesupplylabs.com *.weltpixel.com www.xtento.com zip.co static.zip.co sandbox.zip.co zipmoney.com.au sandbox.zipmoney.com.au checkout.gb.zip.co checkout.quadpay.com checkout-sandbox.quadpay.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com https://img.youtube.com validator.swagger.io *.ftcdn.net *.behance.net https://static.afterpay.com https://site-assets.afterpay.com/ https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://*.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.klevu.com *.cloudflare.com https://cdn.klarna.com *.paypal.com *.afterpay.com *.cloudfront.net https://*.paypal.com *.nextopia.net https://*.zipmoney.com.au *.data-dynamic.net images.latitudepayapps.com *.godfreys.com.au *.feefo.com *.google.com *.google.com.au *.googletagmanager.com.au *.googletagmanager.com *.gstatic.com *.googleapis.com *.bing.com *.criteo.com *.bluekai.com *.socdm.com *.krxd.net *.pubmatic.com *.outbrain.com *.mediavine.com *.aralego.com *.aralego.net *.smaato.net *.clmbtech.com *.yieldmo.com *.emxdgt.com *.doubleclick.net *.bidswitch.net *.adnxs.com *.media.net *.rubiconproject.com *.sharethrough.com *.smartadserver.com *.taboola.com *.teads.tv *.yahoo.com *.casalemedia.com *.dable.io *.adingo.jp *.stickyadstv.com *.rlcdn.com *.3lift.com *.360yield.com *.mytopia.com.au *.clarity.ms *.edisons.com.au *.google.co.in *.1rx.io sync.targeting.unrulymedia.com aa.agkn.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com maps.gstatic.com *.facebook.com www.xtento.com cdn.xtento.com t.zip.co static.zipmoney.com.au static.zip.co data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net amcglobal.sc.omtrdc.net commerce.adobe.net use.typekit.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-ds.com https://portal.sandbox.clearpay.co.uk https://portal.clearpay.co.uk https://portal.sandbox.afterpay.com https://portal.afterpay.com https://static.afterpay.com https://js.sandbox.afterpay.com https://js.afterpay.com polyfill.io www.google.com/recaptcha/ www.gstatic.com/recaptcha/ https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.facebook.net connect.facebook.net graph.facebook.com business.facebook.com app.alhena.ai *.forter.com *.cloudfront.net *.openpay.com.au https://js-agent.newrelic.com https://oc-library.playground.klarnaservices.com/lib.js *.bing.com *.criteo.com *.mytopia.com.au *.google.com *.googleoptimize.com *.cfjump.com *.freshchat.com *.zip.co *.clarity.ms *.hotjar.com *.edisons.com.au commerce.adobe.io cdn.jsdelivr.net js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com maps.googleapis.com *.cloudflare.com https://www.googletagmanager.com tagmanager.google.com unpkg.com www.xtento.com cdn.xtento.com static.zipmoney.com.au static.zip.co zip.co 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com static.afterpay.com/ js.sandbox.afterpay.com js.afterpay.com https://static.klaviyo.com cdn.jsdelivr.net https://js.klevu.com/klevu-css/* *.klevu.com *.cloudflare.com *.bootstrapcdn.com *.fontawesome.com *.googleapis.com *.ecomm-nav.com https://*.zipmoney.com.au *.nextopiasoftware.com https://*.facebook.com https://*.safelinks.protection.outlook.com/ *.zdassets.com *.barilliance.com *.barilliance.net *.newrelic.com *.nr-data.net data: https://fonts.googleapis.com https://fonts.gstatic.com https://maxcdn.bootstrapcdn.com https://use.typekit.net https://p.typekit.net *.nextopia.net *.cloudfront.net *.freshchat.com unsafe-inline assets.braintreegateway.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io commerce.adobe.net qa-api.magedevteam.com *.sentry.io static.afterpay.com static.sandbox.afterpay.com js.sandbox.afterpay.com js.afterpay.com *.algolia.net *.algolia.io *.algolianet.com *.insights.algolia.io insights.algolia.io https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.facebook.com connect.facebook.net graph.facebook.com business.facebook.com app.alhena.ai *.cloudfront.net *.forter.com *.zipmoney.com.au *.zip.co *.criteo.com *.googlesyndication.com *.googleapis.com *.afterpay.com https://ipapi.co/json/ *.clarity.ms *.hotjar.com *.bugsnag.com millsbrands.app.n8n.cloud siteperformancetest.net *.siteperformancetest.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com maps.googleapis.com *.google-analytics.com *.facebook.net 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 font-src *.cloudflare.com *.twitter.com https://*.gstatic.com https://*.typekit.net *.twimg.com *.trustedshops.com *.googleapis.com *.klarnacdn.net https://*.hotjar.com maxcdn.bootstrapcdn.com fonts.gstatic.com *.yotpo.com *.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.twitter.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.google.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.twitter.com *.klarna.com https://*.doubleclick.net https://www.google.com https://*.hotjar.com https://*.livechatinc.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.weltpixel.com *.googletagmanager.com *.doubleclick.net *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.payments-amazon.com *.cloudflare.com *.klarna.com *.googleadservices.com *.google-analytics.com *.paypal.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu https://*.cloudfront.net https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klarnaevt.com *.klarnacdn.net www.feedoptimise.com cdn.feedoptimise.com https://*.doubleclick.net https://www.google.com https://www.google.co.uk https://*.facebook.com https://*.yotpo.com services.postcodeanywhere.co.uk www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.gstatic.com *.facebook.com *.reddit.com *.ads-twitter.com t.co *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.googletagmanager.com *.doubleclick.net *.google.com *.yotpo.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.cloudflare.com *.twitter.com *.google-analytics.com *.twimg.com https://www.gstatic.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.googleapis.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klarna.com *.klarnacdn.net www.feedoptimise.com cdn.feedoptimise.com https://*.pcapredict.com/js/sensor.js https://www.googletagmanager.com https://*.google.com https://*.hotjar.com https://*.doubleclick.net https://secure.leadforensics.com https://*.googleapis.com *.klarnaservices.com https://*.nr-data.net https://*.newrelic.net https://*.livechatinc.com https://*.facebook.net https://*.webgains.io https://*.chimpstatic.com https://*.yotpo.com api.addressy.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googletagmanager.com *.googleadservices.com *.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.bing.com *.clarity.ms *.klaviyo.com unpkg.com *.doubleclick.net *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.cloudflare.com *.googleapis.com *.twitter.com *.twimg.com *.gstatic.com https://*.typekit.net *.trustedshops.com *.usercentrics.eu *.fontawesome.com https://static.klaviyo.com https://*.googleapis.com *.klarnacdn.net https://*.yotpo.com api.addressy.com maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com *.tagmanager.google.com *.googletagmanager.com fonts.googleapis.com *.yotpo.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com https://*.livechatinc.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.cloudflare.com *.twitter.com *.paypal.com *.twimg.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klarnaevt.com https://*.hotjar.com https://*.adobedc.net https://*.nr-data.net *.klarnacdn.net *.klarna.com *.klarnaservices.com api.addressy.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.google.com google.com *.google-analytics.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.doubleclick.net *.run.app *.yotpo.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 font-src *.fontawesome.com fonts.gstatic.com 'self' 'unsafe-inline'; form-action 'self' 'unsafe-inline'; frame-ancestors 'self' 'unsafe-inline'; frame-src *.vimeo.com *.texdecor.test *.texdecor.com www.google.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com *.vimeocdn.com s.ytimg.com data *.cdninstagram.com 'self' 'unsafe-inline'; script-src *.sbc29.com *.sbc30.net *.sbc33.com *.sbc35.com www.vimeo.com cdn-scripts.signifyd.com www.youtube.com *.texdecor.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src getfirebug.com *.fontawesome.com fonts.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src api.sarbacane.com *.texdecor.test *.texdecor.com *.fact-finder.fr www.google-analytics.com 'self' 'unsafe-inline'; child-src 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 default-src https:; connect-src https: wss:; font-src https: data:; frame-src https:; img-src https: data:; media-src https:; object-src https:; script-src 'unsafe-inline' 'unsafe-eval' https: data: blob:; style-src 'unsafe-inline' https:; report-uri https://www.tarifcheck-partnerprogramm.de/csp-violation-ezmd9dpdxv7nb0ecejb9/ 2 script-src-elem webcache.datareporter.eu webcache-eu.datareporter.eu https://apis.google.com static.zdassets.com buerostuhl24.app.baqend.com www.dwin1.com unpkg.com widget.trustpilot.com bat.bing.com invitejs.trustpilot.com lantern.roeyecdn.com www.googletagmanager.com s.pinimg.com s.kk-resources.com ct.beslist.nl dynamic.criteo.com data.bureaustoel24.nl www.google.com connect.facebook.net widgets.trustedshops.com googleads.g.doubleclick.net www.gstatic.com static.trbo.com api-v4.trbo.com sslwidget.criteo.com integrations.etrusted.com static.hotjar.com data.buerostuhl24.com secure.pay1.de script.hotjar.com tm708.ad-srv.net tm706.ad-srv.net tm.ad-srv.net ct.pinterest.com tm716.ad-srv.net data.sillasdeoficina24.es static-eu.payments-amazon.com cdn.jsdelivr.net snap.licdn.com tm710.ad-srv.net data.buerostuhl24.at tm701.ad-srv.net data.hjh-office.fr tm720.ad-srv.net data.hjh-office.se data.buerostuhl24.ch tm722.ad-srv.net tm712.ad-srv.net sibforms.com widget-mediator.zopim.com data.hjh-office.fi tm702.ad-srv.net tm724.ad-srv.net tm723.ad-srv.net tm709.ad-srv.net tm718.ad-srv.net tm707.ad-srv.net tm715.ad-srv.net tm711.ad-srv.net data.hjh-office.it tm719.ad-srv.net tm704.ad-srv.net tm703.ad-srv.net tm721.ad-srv.net www.moebel.de www.awin1.com data.hjh-office.dk 'self' 'unsafe-inline' 'unsafe-eval'; style-src-elem https://webcache.datareporter.eu https://webcache-eu.datareporter.eu webcache-eu.datareporter.eu integrations.etrusted.com 'self' 'unsafe-inline'; font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://www.googletagmanager.com *.googleapis.com webcachex-eu.datareporter.eu https://widgets.trustedshops.com https://integrations.etrusted.com *.fontawesome.com 'self' data: *.yotpo.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.adyen.com https://plumrocket.com *.yotpo.com www.sillasdeoficina24.es www.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.adyen.com *.awin1.com *.zenaps.com *.fls.doubleclick.net secure.pay1.de payments.amazon.de jsctool.com www.jsctool.com js.playground.klarna.com www.xtento.com https://plumrocket.com *.trustpilot.com *.yotpo.com gum.criteo.com ct.pinterest.com collect.trbo.com fledge.eu.criteo.com tm708.ad-srv.net td.doubleclick.net tm706.ad-srv.net tm722.ad-srv.net ad.ad-srv.net my.meetergo.com tm710.ad-srv.net tm720.ad-srv.net gumi.criteo.com static.criteo.net tm718.ad-srv.net tm701.ad-srv.net tm716.ad-srv.net tm702.ad-srv.net tm712.ad-srv.net tm723.ad-srv.net www.facebook.com tm707.ad-srv.net tm715.ad-srv.net tm711.ad-srv.net tm704.ad-srv.net tm703.ad-srv.net tm721.ad-srv.net tm719.ad-srv.net tm709.ad-srv.net www.instagram.com www.pinterest.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.adyen.com *.awin1.com *.zenaps.com *.wepowerconnections.com cdn.pay1.de x.klarnacdn.net *.cloudfront.net https://widgets.trustedshops.com https://integrations.etrusted.com *.pixriot.com *.storeimaging.com www.xtento.com cdn.xtento.com *.hsforms.net *.hsforms.com 'self' data: *.yotpo.com buerostuhl24.app.baqend.com www.buerostuhl24.at www.facebook.com bat.bing.net www.google.nl lantern.roeye.com bat.bing.com www.buerostuhl24.com visitor.omnitagjs.com rtb-csync.smartadserver.com r.casalemedia.com id5-sync.com x.bidswitch.net ib.adnxs.com ad.360yield.com gum.criteo.com sync-t1.taboola.com cm.g.doubleclick.net px.ads.linkedin.com img.idealo.com www.google.de a.twiago.com matching.ivitrack.com www.hjh-office.se www.buerostuhl24.ch collect.trbo.com www.bureaustoel24.nl www.google.co.in static.trbo.com contextual.media.net sync.outbrain.com match.sharethrough.com jadserve.postrelease.com sync.1rx.io exchange.mediavine.com simage2.pubmatic.com pixel.rubiconproject.com eb2.3lift.com sync-criteo.ads.yieldmo.com criteo-partners.tremorhub.com e1.emxdgt.com dis.criteo.com ad.yieldlab.net criteo-sync.teads.tv www.hjh-office.fi www.google.ch px4.ads.linkedin.com www.hjh-office.it www.google.es www.google.at s.kelkoogroup.net www.google.it pagead2.googlesyndication.com v2assets.zopim.io www.google.be data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.adyen.com tagmanager.google.com https://www.googletagmanager.com *.awin1.com *.dwin1.com *.zenaps.com *.wepowerconnections.com https://the.sciencebehindecommerce.com lantern.roeyecdn.com *.datareporter.eu *.plugins.emarsys.net *.scarabresearch.com secure.pay1.de d.ratepay.com static-eu.payments-amazon.com x.klarnacdn.net cdn.klarna.com jsctool.com d.payla.io https://widgets.trustedshops.com https://integrations.etrusted.com data.hjh-office.fr www.xtento.com cdn.xtento.com *.hsforms.net *.hsforms.com *.gstatic.com *.trustpilot.com *.yotpo.com https://apis.google.com buerostuhl24.app.baqend.com static.zdassets.com data.buerostuhl24.com static.hotjar.com tm706.ad-srv.net tm.ad-srv.net script.hotjar.com unpkg.com https://www.dwin1.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://www.googletagmanager.com tagmanager.google.com *.googleapis.com https://webcache.datareporter.eu d.ratepay.com d.payla.io dr.payla.io https://widgets.trustedshops.com https://integrations.etrusted.com *.fontawesome.com *.gstatic.com *.trustpilot.com *.yotpo.com webcache-eu.datareporter.eu 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com static.zdassets.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.adyen.com https://www.google-analytics.com *.wepowerconnections.com https://the.sciencebehindecommerce.com *.datareporter.eu *.scarabresearch.com *.eservice.emarsys.net payments.amazon.de d.ratepay.com jsctool.com eu.playground.klarnaevt.com *.trustedshops.com *.etrusted.com *.pixriot.com *.storeimaging.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com *.yotpo.com ekr.zdassets.com ct.pinterest.com hjhoffice.zendesk.com buerostuhl24.app.baqend.com data.bureaustoel24.nl wss://widget-mediator.zopim.com bat.bing.net data.hjh-office.dk px.ads.linkedin.com data.buerostuhl24.com vc.hotjar.io pagead2.googlesyndication.com data.buerostuhl24.at measurement-api.criteo.com payments-de.amazon.com data.sillasdeoficina24.es bat.bing.com data.hjh-office.fr data.hjh-office.se data.buerostuhl24.ch ct.beslist.nl ws://localhost:12387 sslwidget.criteo.com data.hjh-office.fi www.facebook.com data.hjh-office.it d158d42c.sibforms.com s.kelkoogroup.net invitejs.trustpilot.com 'self' 'unsafe-inline'; child-src *.awin1.com *.zenaps.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://www.buerostuhl24.com/rest/all/V1/cspmanager/frontend_report; 2 worker-src blob: 'self'; font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com maxcdn.bootstrapcdn.com *.fontawesome.com https://fonts.bunny.net 'self' data: *.kxcdn.com geowidget.easypack24.net v2.zopim.com cdn.thulium.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.paypal.com sandbox.przelewy24.pl secure.przelewy24.pl www.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com geowidget-app.inpost.pl mapa.ecommerce.poczta-polska.pl pudofinder.dpd.com.pl js.mollie.com pay.google.com facebook.com www.facebook.com *.kxcdn.com youtube.com www.youtube.com platform.twitter.com www.google.com *.addthis.com secure.livechatinc.com cm.g.doubleclick.net td.doubleclick.net sync.clickonometrics.pl static.clickonometrics.pl www.googletagmanager.com vars.hotjar.com ct.pinterest.com cdn2.pollster.pl widget.spreaker.com start.assets.paypo.pl start.paypo.pl popup.paypo.pl 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://images.unsplash.com *.googleapis.com https://firebasestorage.googleapis.com https://www.mollie.com static.przelewy24.pl www.gstatic.com gstatic.com *.hsforms.net *.hsforms.com 'self' data: *.googletagmanager.com *.google-analytics.com ssl.gstatic.com *.cdninstagram.com *.kxcdn.com *.twitter.com google.com td.doubleclick.net www.google.pl ct.pinterest.com *.fbcdn.net cdn.livechatinc.com www.facebook.com img.onesignal.com v2.zopim.com cdn.stamped.io content.pollster.pl s1782711468.t.eloqua.com *.adform.net ads.avct.cloud c.clarity.ms c.bing.com ssl.ceneo.pl mrtg.emailpartners.net conversionlabs.net geowidget.easypack24.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com https://maps.googleapis.com geowidget.inpost.pl api.inpost.pl mapa.ecommerce.poczta-polska.pl api.furgonetka.pl maps.googleapis.com *.avada.io js.mollie.com sandbox.przelewy24.pl secure.przelewy24.pl pay.google.com ruch-osm.sysadvisors.pl *.hsforms.net *.hsforms.com *.gstatic.com *.googletagmanager.com tagmanager.google.com *.googleapis.com www.google.com www.google.pl cdn.ampproject.org connect.facebook.net googletagmanager.com analytics.tiktok.com *.kxcdn.com platform.twitter.com *.addthis.com *.addthisedge.com *.moatads.com cdn.livechatinc.com api.livechatinc.com chimpstatic.com delivery.clickonometrics.pl static.clickonometrics.pl profiling.clickonometrics.pl cdn.mouseflow.com onesignal.com cdn.onesignal.com geowidget.easypack24.net v2.zopim.com static.zdassets.com widget-mediator.zopim.com chat-widget.thulium.com cdn.thulium.com s.pinimg.com static.hotjar.com script.hotjar.com smart.idmnet.pl cdn2.pollster.pl exchange.pollster.pl *.adform.net img06.en25.com utrack.buybox.click hop-js.buybox.click shop-js.buybox.click s1782711468.t.eloqua.com cdn.files.smcloud.net ssl.ceneo.pl api.bebio.pl www.clarity.ms s-eu-1.pushpushgo.com ct.pinterest.com cdn.jsdelivr.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com maxcdn.bootstrapcdn.com geowidget.inpost.pl mapa.orlenpaczka.pl *.gstatic.com *.googleapis.com *.fontawesome.com https://fonts.bunny.net ruch-osm.sysadvisors.pl tagmanager.google.com fonts.google.com google.com *.kxcdn.com onesignal.com www.googletagmanager.com geowidget.easypack24.net api.bebio.pl cdn.jsdelivr.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com chat-widget.thulium.com cdn.thulium.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com https://maps.googleapis.com https://player.vimeo.com api.furgonetka.pl maps.googleapis.com https://get.geojs.io *.avada.io sandbox.przelewy24.pl secure.przelewy24.pl wss://sandbox-ws.przelewy24.pl wss://secure-ws.przelewy24.pl apple-pay-gateway.apple.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com https://www.paypal.com/xoplatform/logger/api/logger cdn.ampproject.org *.kxcdn.com stats.g.doubleclick.net pagead2.googlesyndication.com region1.google-analytics.com region1.analytics.google.com www.facebook.com analytics.tiktok.com sandbox-api-shipx-pl.easypack24.net api-shipx-pl.easypack24.net wss://widget-mediator.zopim.com widget-mediator.zopim.com ekr.zdassets.com onesignal.com api.synerise.com ai-api.synerise.com api.bebio.pl ct.pinterest.com in.hotjar.com smart.idmnet.pl check.pollster.pl q.clarity.ms utrack.buybox.click content.pollster.pl y.clarity.ms s1782711468.t.eloqua.com ssl.ceneo.pl o2.mouseflow.com grow-apps.growpoland.pl delivery.clickonometrics.pl googleads.g.doubleclick.net cdn.thulium.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 object-src 'none'; connect-src 'self' *.nextdoorstudios.com *.asgmax.com cognito-identity.us-east-1.amazonaws.com backend.getbeamer.com *.comm100.io *.algolia.net insights.algolia.io *.algolianet.com *.gammaapis.com *.gammacdn.com analytics.google.com *.google-analytics.com adservice.google.com *.analytics.google.com *.doubleclick.net *.pubnub.com *.lovense.com *.handyfeeling.com www.gammaentertainment.com *.tiypa.com *.recombee.us dasasoveekepl.cloudfront.net capture.trackjs.com ws: jlduihq7lrcdxgw4vrndhdfcsq.appsync-api.us-east-1.amazonaws.com tcs4u525zrg5hnnoe5kzndxuaq.appsync-api.us-east-1.amazonaws.com xtnzefcqrb.execute-api.us-east-1.amazonaws.com 2aed6ghjsb4436qtebuqk3gfzq0xeauy.lambda-url.us-east-1.on.aws lzzos7clo5.execute-api.us-east-1.amazonaws.com *.izooto.com www.idealgasm.com 3tt0xhv5u7.execute-api.us-east-1.amazonaws.com; form-action 'self' *.nextdoorstudios.com *.asgmax.com join.gammasecure.com; script-src 'self' *.nextdoorstudios.com *.asgmax.com app.getbeamer.com static.getbeamer.com blob: vue.comm100.com standby.comm100vue.com *.gammacdn.com www.google-analytics.com www.googletagmanager.com www.gstatic.com www.google.com code.jquery.com d3a3ewgd1iewwz.cloudfront.net cdn.izooto.com 'unsafe-eval' 'unsafe-inline'; frame-src 'self' *.nextdoorstudios.com *.asgmax.com push.getbeamer.com app.getbeamer.com www.google.com *.doubleclick.net cdn.izooto.com *.banhq.com; report-uri https://csp-report.browser-intake-datadoghq.com/api/v2/logs?dd-api-key=pub787d5a6164b329b26f2e4f7956bbed10&dd-evp-origin=content-security-policy&ddsource=csp-prod&ddtags=CSP-Prod; 2 script-src 'self' https://cdn.suitableshop.net https://bat.bing.com https://d5yoctgpv4cpx.cloudfront.net https://tggng.suitableshop.com 'unsafe-inline' ; 2 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.google.com *.googlesyndication.com *.googleadservices.com *.doubleclick.net *.google-analytics.com www.googletagmanager.com va.vercel-scripts.com vitals.vercel-insights.com challenges.cloudflare.com tags.srv.stackadapt.com *.tiktok.com *.tiktokw.us *.attn.tv *.attentivemobile.com *.crispnow.com *.honeybook.com *.facebook.com connect.facebook.net *.cloudfront.net *.userway.org *.formstack.com *.clarity.ms; style-src 'self' 'unsafe-inline' use.typekit.net p.typekit.net tags.srv.stackadapt.com *.googleapis.com *.tiktok.com *.tiktokw.us *.attn.tv *.attentivemobile.com *.crispnow.com *.userway.org *.formstack.com; img-src 'self' data: blob: cdn.shopify.com picsum.photos *.placehold.co api.mapbox.com events.mapbox.com *.tiles.mapbox.com *.tile.openstreetmap.org *.google.com *.googlesyndication.com *.googleadservices.com *.doubleclick.net *.google-analytics.com www.googletagmanager.com tags.srv.stackadapt.com *.tiktok.com *.tiktokw.us *.attn.tv *.attentivemobile.com *.crispnow.com *.facebook.com connect.facebook.net *.honeybook.com *.userway.org *.formstack.com *.clarity.ms; media-src 'self' cdn.shopify.com; font-src 'self' use.typekit.net p.typekit.net data: *.googleapis.com *.gstatic.com swig.franconnect.net *.formstack.com; connect-src 'self' *.google.com *.googlesyndication.com *.googleadservices.com *.doubleclick.net *.google-analytics.com www.googletagmanager.com va.vercel-scripts.com vitals.vercel-insights.com api.mapbox.com events.mapbox.com *.tiles.mapbox.com challenges.cloudflare.com tags.srv.stackadapt.com *.tiktok.com *.tiktokw.us *.attn.tv *.attentivemobile.com *.crispnow.com *.facebook.com connect.facebook.net *.honeybook.com *.cloudfront.net *.userway.org *.salesforce-sites.com *.formstack.com *.clarity.ms; frame-src 'self' challenges.cloudflare.com www.googletagmanager.com *.google.com *.googlesyndication.com *.doubleclick.net *.tiktok.com *.tiktokw.us *.attn.tv *.attentivemobile.com *.crispnow.com *.honeybook.com *.facebook.com connect.facebook.net swig.franconnect.net *.swig.franconnect.net *.formstack.com 2 script-src-elem www.googletagmanager.com ajax.googleapis.com consent.cookiebot.com consentcdn.cookiebot.com embed.sendcloud.sc cdn.jsdelivr.net gc.kis.v2.scr.kaspersky-labs.com ff.kis.v2.scr.kaspersky-labs.com infirc.com ritrag.com me.kis.v2.scr.kaspersky-labs.com connect.facebook.net infird.com kproxyservers.site gc.kes.v2.scr.kaspersky-labs.com cdn.toolszen.com ff.kes.v2.scr.kaspersky-labs.com mstat.acestream.net cdnjs.cloudflare.com data1.pletar.com apis.google.com translate.google.com translate.googleapis.com c.chuyueshop.com gc.kis.scr.kaspersky-labs.com me.kes.v2.scr.kaspersky-labs.com dakotaram.com jullyambery.net hublosk.com wistiaextension.com utq.vvipquan.com secured-pixel.com 3001.scriptcdn.net api.wire.threatspike.com extensionscontrol.com cdn.cookie-script.com www.oilonline.store sc-static.net 4ddons.com cdn.sleak.chat static.ads-twitter.com rialto-gms.s3.amazonaws.com vk-online.xyz pro-sw.ru mainf.global-cache.online www.pagespeed-mod.com www.google-analytics.com images.uc.cn g.alicdn.com vtesting.yoganc.fun dmp.im-apps.net static.hotjar.com www.clickcease.com script.hotjar.com assets.adobedtm.com pagead2.googlesyndication.com conversations-widget.sendinblue.com cdn.by.wonderpush.com bokezu.tijapixuno.com static.cloudflareinsights.com www.google.com www.gstatic.com mediashower.com www.youtube.com youwanoss.oss-cn-shanghai.aliyuncs.com cdn.livechatinc.com api.livechatinc.com img.otv.cc veniwa.bakowiseda.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src-elem maxcdn.bootstrapcdn.com fonts.googleapis.com cdn.jsdelivr.net gc.kis.v2.scr.kaspersky-labs.com ff.kis.v2.scr.kaspersky-labs.com www.gstatic.com pwm-image.trendmicro.com me.kis.v2.scr.kaspersky-labs.com www.oilonline.store cdn.honey.io use.fontawesome.com cdn.sleak.chat adblockers.opera-mini.net mediashower.com sleakbot-v2.pages.dev 'self' 'unsafe-inline'; font-src maxcdn.bootstrapcdn.com fonts.gstatic.com fonts.googleapis.com at.alicdn.com cdn.megabonus.com use.typekit.net static.hsappstatic.net themes.googleusercontent.com chrome-extension://jcmcbmdmfmelmlelagelpfhmohipjjia static3.avast.com use.fontawesome.com aceify.ai cdn.scite.ai cdn.fontshare.com www.slant.co appdown.pstatic.net app.escribelo.ai qncdn.aoscdn.com cdn.faceworks.nl www.oilonline.store assets.alicdn.com cdnjs.cloudflare.com images.simplycodes.com pouch-global-font-assets.s3.eu-central-1.amazonaws.com r2cdn.perplexity.ai www.vinci.com cdn-uicons.flaticon.com migaku-public-data.migaku.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com *.facebook.com www.oilonline.store translate.googleapis.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com www.oilonline.store 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.google.com js.mollie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com *.sendcloud.sc *.jsdelivr.net *.weltpixel.com www.xtento.com *.googletagmanager.com *.doubleclick.net consentcdn.cookiebot.com www.googletagmanager.com pwm-image.trendmicro.com gateway.zscloud.net gateway.zscalerthree.net menrealitycalc.com safe.menlosecurity.com gateway.zscaler.net acestream.tv emet.live emet.news gateway.zscalertwo.net feedback-pa.clients6.google.com c.safen110.com div.show global.acs.prismaaccess.com 172.16.1.240:9123 noop.style portal.farsons.com 10.33.141.1 wm-livechat-2-prod-dot-watermelonmessenger.appspot.com translate.googleapis.com widget.sleak.chat lordfilm-crew.net remove.video block.opendns.com www.youtube.com.x.11d761ca0d21704a6c0b3510df542b18da88.d045213f.id.opendns.com www.oelonline.com saml.saasprotection.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io quickchart.io img.youtube.com https://www.mollie.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.amazonaws.com *.gstatic.com *.facebook.com maps.googleapis.com www.xtento.com cdn.xtento.com *.reddit.com *.google-analytics.com *.googletagmanager.com *.doubleclick.net *.google.com https://www.magezon.com flagpedia.net imgsct.cookiebot.com www.olieonline.nl www.olieonline.co.uk www.oelonline.com translate.google.com log-papago.naver.com pos.baidu.com www.oilonline.store cdn.honey.io mc.yandex.ru translate.googleapis.com dakotaram.com yastatic.net staging.oilonline.store sygpwnluwwetrkmwilea.supabase.co uploads-ssl.webflow.com t.co analytics.twitter.com my.productfruits.com gateway.zscalertwo.net cdn.sleak.chat actimg.heytapimg.com stagingcw.olieonline.co.uk www.bing.com img.alicdn.com sleak-chat.github.io db.sleak.chat data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.google.com/recaptcha/ www.gstatic.com/recaptcha/ js.mollie.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com *.sendcloud.sc *.jsdelivr.net ajax.googleapis.com *.google.com *.facebook.net unpkg.com maps.googleapis.com www.xtento.com cdn.xtento.com *.googletagmanager.com *.googleadservices.com *.redditstatic.com *.reddit.com *.tiktok.com *.doubleclick.net *.gstatic.com consent.cookiebot.com consentcdn.cookiebot.com greasyfork.org update.greasyfork.org cdn.cookie-script.com cdn.sleak.chat static.cloudflareinsights.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com maxcdn.bootstrapcdn.com fonts.gstatic.com fonts.googleapis.com unsafe-inline *.sendcloud.sc *.jsdelivr.net *.tagmanager.google.com *.googletagmanager.com *.gstatic.com www.gstatic.com cdn.sleak.chat 'self' 'unsafe-inline'; object-src object.center 'self' 'unsafe-inline'; media-src *.adobe.com ssl.gstatic.com sygpwnluwwetrkmwilea.supabase.co cdn.sleak.chat 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.sendcloud.sc *.cdn.jsdelivr.net *.mapbox.com *.google-analytics.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.doubleclick.net *.run.app www.gstatic.com maps.googleapis.com consentcdn.cookiebot.com translate.googleapis.com translate-pa.googleapis.com overbridgenet.com api.global-data-lab.com api.mkmediaworks.com wss://ny1.xmrminingproxy.com consent.cookiebot.com www.oilonline.store gjtrack.ucweb.com api.amcreativemedia.com api.fbanalytics.org yandex.ru www.google.com s3.ap-east-1.amazonaws.com o0rmue7xt0.execute-api.il-central-1.amazonaws.com wss://127.0.0.1:2020 wss://127.0.0.1:2023 wss://127.0.0.1:2024 wss://127.0.0.1:2021 wss://127.0.0.1:2025 wss://127.0.0.1:2027 wss://127.0.0.1:2022 wss://127.0.0.1:2026 wss://127.0.0.1:2029 wss://127.0.0.1:2028 localhost:8036 api.trongrid.io n.wistiaextension.com region1.google-analytics.com ajax.googleapis.com baidustatics.net infragrid.v.network adtonus.com code.jquery.com rktds.net d1lkfzu2puirk6.cloudfront.net consent.cookie-script.com editor.api.clonable.net clientstream.launchdarkly.com fonts.googleapis.com fonts.gstatic.com local.adblock360.com cdn.sleak.chat widget.sleak.chat sygpwnluwwetrkmwilea.supabase.co my.productfruits.com api.video-adblock.com gateway.zscalertwo.net api.privacy-protector-adblocker.com ws://127.0.0.1:35729 tl.ytlogs.ru service.gstatic-cache.com cdnmmh.global-cache.online aegis.qq.com api.vid-adblocker.com localhost:4443 detector.scamsniffer.io px.wpk.quark.cn vtesting.yoganc.fun www.facebook.com api.freevideoguard.org www.olieonline.co.uk junklip.com ad-ninja.net felo-crawler.com metrics-dra.dt.dbankcloud.cn sleakbot-v2.pages.dev 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri www.amazon.de www.exxonmobil.com www.mobil.com www.oelonline.com 7gtronic.pl 'self' 'unsafe-inline'; report-uri https://www.olieonline.co.uk/rest/all/V1/cspmanager/frontend_report; 2 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com widget.thuiswinkel-cdn.org data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com *.googlesyndication.com *.tiktok.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com consent.cookiebot.com *.freshchat.com consentcdn.cookiebot.com js.mollie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.trustpilot.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://images.unsplash.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.googlesyndication.com *.roeye.com *.tiktok.com imgsct.cookiebot.com *.google.com.ua *.google.com.nl api.taggrs.io widget.thuiswinkel-cdn.org px.ads.linkedin.com bat.bing.com sst.officecentre.nl https://www.mollie.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://maps.googleapis.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com *.jsdelivr.net *.tiktok.com consent.cookiebot.com static.zdassets.com wss://widget-mediator.zopim.com consentcdn.cookiebot.com widget.thuiswinkel.org widget.thuiswinkel-cdn.org eu.fw-cdn.com *.freshchat.com bat.bing.com sst.officecentre.nl js.mollie.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.trustpilot.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com *.tiktok.com *.typekit.net *.freshchat.com static-tracking.klaviyo.com widget.thuiswinkel-cdn.org https://static.klaviyo.com assets.braintreegateway.com *.trustpilot.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com static.zdassets.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://maps.googleapis.com https://player.vimeo.com *.facebook.com *.facebook.net *.doubleclick.net *.googlesyndication.com *.tiktok.com ekr.zdassets.com wss://widget-mediator.zopim.com consentcdn.cookiebot.com widget.trustpilot.com widget.thuiswinkel.org widget.thuiswinkel-cdn.org app-euc.freshmarketer.com widgetcontent.thuiswinkel-cdn.org sst.officecentre.nl px.ads.linkedin.com bat.bing.com ws://127.0.0.1:35729/livereload https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 default-src 'self'; script-src 'self' https://api-maps.yandex.ru https://www.google.com https://www.gstatic.com 'unsafe-inline' 'unsafe-eval'; style-src 'self' 'unsafe-inline'; img-src 'self' data: https://api-maps.yandex.ru https://www.gstatic.com; font-src 'self'; connect-src 'self' https://www.google.com https://www.gstatic.com; frame-src https://www.google.com; child-src https://www.google.com; 2 frame-ancestors 'self'; report-uri https://www.klik.de/api/csp-reports; report-to csp-endpoint; 2 font-src *.klaviyo.com res-1.cdn.office.net i.icomoon.io fonts.gstatic.com *.typekit.net data: 'self' 'unsafe-inline'; form-action *.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com https://api.clerk.io https://cdn.clerk.io *.multisafepay.com https://pay.google.com 'self'; frame-src bid.g.doubleclick.net player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.google.com *.clic2buy.com *.facebook.com *.linkbux.com *.opendns.com *.perfsimpl.com *.zipchat.ai consentcdn.cookiebot.com consentcdn.cookiebot.eu *.multisafepay.com https://pay.google.com *.googletagmanager.com 'self' 'unsafe-inline'; img-src data: widgets.magentocommerce.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com *.google-analytics.com *.analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com *.youtube.com *.bing.com *.clarity.ms *.doubleclick.net *.facebook.com *.facebook.net *.google.com *.googleadservices.com *.googleapis.com *.gstatic.com *.trustprofile.com *.usercentrics.eu d3k81ch9hvuctc.cloudfront.net www.google.be www.google.fr www.google.nl www.google.ro https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://cdn.clerk.io imgsct.cookiebot.com imgsct.cookiebot.eu https://at19.net https://bdt9.net https://ds1.nl https://dt51.net https://dt61.net https://fr135.net https://glp8.net https://jdt8.net https://jf79.net https://hs82.net https://lt45.net https://mt74.net https://ndt5.net https://rkn3.net *.multisafepay.com *.googletagmanager.com ssl.gstatic.com www.gstatic.com data: 'self' 'unsafe-inline'; script-src googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.google.com/recaptcha/ www.gstatic.com/recaptcha/ https://widget-acc.paazl.com https://api-acc.paazl.com/ *.clarity.ms *.clerk.io *.clic2buy.com *.cookiebot.eu *.facebook.net *.feedbackcompany.com *.getsitecontrol.com *.google.com *.googleapis.com *.googlesyndication.com *.hotjar.com *.paazl.com *.tiktok.com *.zipchat.ai https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://api.clerk.io https://cdn.clerk.io https://custom.clerk.io consent.cookiebot.com consent.cookiebot.eu *.multisafepay.com https://pay.google.com *.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src https://widget-acc.paazl.com https://api-acc.paazl.com/ *.gstatic.com *.klaviyo.com *.paazl.com https://static.klaviyo.com https://api.clerk.io https://cdn.clerk.io i.icomoon.io fonts.googleapis.com *.typekit.net *.multisafepay.com tagmanager.google.com fonts.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.googleadservices.com *.google-analytics.com *.analytics.google.com www.googletagmanager.com https://widget-acc.paazl.com https://api-acc.paazl.com/ *.clarity.ms *.conversionsapigateway.com *.datadome.co *.doubleclick.net *.facebook.com *.feedbackcompany.com *.getsitecontrol.com *.google.com *.googleadservices.com *.googleapis.com *.googlesyndication.com *.hotjar.com *.hotjar.io *.paazl.com *.sentry.io *.tiktok.com *.tiktokw.us *.zipchat.ai google.com mpc-prod-21-1053047382554.us-central1.run.app wss://ws.hotjar.com www.google.be www.google.fr www.google.nl www.google.ro https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ consentcdn.cookiebot.com consentcdn.cookiebot.eu consent.cookiebot.com consent.cookiebot.eu *.multisafepay.com *.googletagmanager.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://84966c07-9303-4ce4-a8a1-d967b6d75831.sansec.watch/; report-to report-endpoint; 2 font-src *.googleapis.com *.gstatic.com https://cdn.checkout.com *.fontawesome.com *.cloudflare.com *.twitter.com *.typekit.net *.twimg.com *.trustedshops.com *.klarnacdn.net *.salesfire.co.uk fonts.gstatic.com data: hello.myfonts.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.twitter.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://plumrocket.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.google.com https://js.checkout.com *.klarna.com https://www.googletagmanager.com/ *.twitter.com *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com account.fetchify.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://plumrocket.com *.salesfire.co.uk tikkurila-dev.prismic.io *.cookiebot.com wisepops.net www.awin1.com td.doubleclick.net *.attn.tv pay.google.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.googleapis.com *.gstatic.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ *.cloudflare.com *.klarna.com *.googleadservices.com *.google-analytics.com *.paypal.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.cloudfront.net *.trackedlink.net ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com *.klarnaevt.com *.klarnacdn.net www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://redchamps.com *.salesfire.co.uk www.photofusion.org www.tikkurila.co.uk images.prismic.io *.prismic.io *.feefo.com v2assets.zopim.io www.google.co.uk www.google.ie *.cookiebot.com www.awin1.com www.tagserve.com lantern.roeye.com bat.bing.com www.wepowerconnections.com events.attentivemobile.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.googleapis.com *.gstatic.com *.attn.tv events.attentivemobile.com https://*.checkout.com *.klarnacdn.net *.cdn-apple.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ *.cloudflare.com *.twitter.com *.google-analytics.com *.twimg.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com chimpstatic.com downloads.mailchimp.com *.list-manage.com *.klarna.com *.klarnaservices.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.salesfire.co.uk static.zdassets.com register.feefo.com cdn.noibu.com static.cdn.prismic.io *.googleoptimize.com wisepops.net *.wisepops.net *.gorgias.chat *.cookiebot.com bat.bing.com static.hotjar.com script.hotjar.com lantern.roeyecdn.com *.googlesyndication.com www.awin1.com www.dwin1.com the.sciencebehindecommerce.com api.feefo.com pay.google.com https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://cdn.checkout.com *.fontawesome.com *.cloudflare.com *.googleapis.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com downloads.mailchimp.com cc-cdn.com *.klarnacdn.net *.salesfire.co.uk hello.myfonts.net *.feefo.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ static.zdassets.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.googleapis.com *.attn.tv events.attentivemobile.com https://js.checkout.com *.klarnaevt.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ *.cloudflare.com *.twitter.com *.paypal.com *.twimg.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com api.craftyclicks.co.uk pcls1.craftyclicks.co.uk *.klarnacdn.net *.klarna.com *.klarnaservices.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.salesfire.co.uk *.smartmetrics.co.uk ekr.zdassets.com api.feefo.com valttihelp.zendesk.com collect.feefo.com wss://widget-mediator.zopim.com tikkurila-dev.prismic.io wisepops.net *.wisepops.com *.gorgias.chat *.cookiebot.com *.analytics.google.com *.googlesyndication.com *.google-analytics.com ws.hotjar.com content.hotjar.io the.sciencebehindecommerce.com bam.eu01.nr-data.net google.com pay.google.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri /csp/report/log; report-to report-endpoint; 2 frame-src 'self' https://*.adyen.com *.cookiebot.com https://cdn.tagcommander.com https://cdn.trustcommander.net https://privacy.trustcommander.net https://privacy.commander1.com https://apps.apple.com https://*.zebet.fr https://*.zebet.com https://*.zebet.be https://*.zebet.es https://*.zebet.nl https://*.zeturf.be https://*.zeturf.com https://*.zeturf.es https://*.zeturf.fr https://*.zeturf.nl https://*.m-itrust.com https://*.redsys.es https://*.apata.io https://*.abanca.com https://*.n26.com https://*.postfinance.ch https://*.ing.fr https://*.monext.fr https://*.ing.com https://*.vinea.es https://*.verifiedbyvisa.com https://*.cic.fr https://*.cm-cic.com https://*.creditmutuel.fr https://*.modirum.com https://*.gbp.ma https://*.cornercard.ch https://*.wlp-acs.com ; report-uri /en/webservice/api/report-csp 2 script-src 'unsafe-inline' 'unsafe-eval' blob: data: https://googleads.g.doubleclick.net/pagead/viewthroughconversion/ https://translate.google.com/translate_a/element.js https://www.youtube.com/iframe_api https://www.googletagmanager.com/gtag/js https://www.google-analytics.com/analytics.js https://www.googletagmanager.com/gtag/destination https://www.gstatic.com/_/mss/boq-one-google/_/ https://www.gstatic.com/og/_/js/ https://apis.google.com/js/api.js https://apis.google.com/js/client.js https://www.google.com/tools/feedback/chat_load.js https://www.google.com/tools/feedback/help_api.js https://www.google.com/tools/feedback/load.js https://www.google.com/tools/feedback/open.js https://www.google.com/tools/feedback/open_to_help_guide_lazy.js https://www.gstatic.com/feedback/js/ https://www.gstatic.com/feedback/js/help/prod/service/lazy.min.js https://www.gstatic.com/inproduct_help/api/main.min.js https://www.gstatic.com/inproduct_help/chatsupport/chatsupport_button_v2.js https://www.gstatic.com/inproduct_help/service/lazy.min.js https://www.gstatic.com/uservoice/feedback/client/web/live/ https://www.gstatic.com/uservoice/surveys/resources/prod/js/survey/ https://www.gstatic.com/_/mss/boq-chrome-webstore/_/js/k=boq-chrome-webstore.ChromeWebStoreConsumerFeUi.en_US.Smm9x_ip2gU.2018.O/ https://apis.google.com/_/scs/abc-static/_/js/ https://www.youtube.com/s/player/ https://translate.googleapis.com/_/translate_http/_/js/;report-uri /_/ChromeWebStoreConsumerFeUi/cspreport/fine-allowlist 2 font-src fonts.gstatic.com use.typekit.net https://static.iadvize.com/ https://media.flixfacts.com *.fontawesome.com applepay.cdn-apple.com https://fonts.gstatic.com *.alothemes.com *.magepow.com googlepay.cdn-google.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com eu-gateway.mastercard.com ap-gateway.mastercard.com na-gateway.mastercard.com *.gateway.mastercard.com https://www.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com eu-gateway.mastercard.com ap-gateway.mastercard.com na-gateway.mastercard.com *.gateway.mastercard.com https://static.addtoany.com https://www.google.com/ https://service.loadbee.com/ https://vars.hotjar.com/ https://static.rolex.com/ https://retailers.rolex.com/ https://media.flixfacts.com *.webengage.co https://corners.rolex.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.weltpixel.com *.googletagmanager.com *.doubleclick.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io *.ftcdn.net *.behance.net https://static.iadvize.com/ https://fstatic.iadvize.com/ https://www.facebook.com https://www.google.com https://www.google.co.in https://googleads.g.doubleclick.net https://www.googletagmanager.com https://media.flixfacts.com https://m.media-amazon.com https://www.darwishholding.com/ https://theqa.qa metrics.rolex.com maps.googleapis.com smetrics.rolex.com *.disqus.com *.alothemes.com *.magepow.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.gstatic.com *.facebook.com *.reddit.com *.google-analytics.com *.googletagmanager.com *.doubleclick.net *.google.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net eu-gateway.mastercard.com ap-gateway.mastercard.com na-gateway.mastercard.com *.gateway.mastercard.com https://cobrowsing-ha.iadvize.com/ https://fstatic.iadvize.com/ https://static.iadvize.com/ https://halc.iadvize.com https://api.iadvize.com/ https://static.addtoany.com https://www.google.com https://js-agent.newrelic.com https://bam.nr-data.net https://graph.facebook.com https://widgets.pinterest.com https://cdn.loadbee.com/js/loadbee_integration.js https://static.hotjar.com https://script.hotjar.com https://static.rolex.com https://retailers.rolex.com http://media.flixfacts.com https://test-gateway.mastercard.com https://ap-gateway.mastercard.com/ https://starpay-easy.starboss.biz/ https://www.qpay.gov.qa/ https://m.media-amazon.com https://connect.facebook.net https://analytics.tiktok.com/ *.webengage.com applepay.cdn-apple.com https://corners.rolex.com maps.googleapis.com *.disqus.com *.alothemes.com *.magepow.com googlepay.cdn-google.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com cdn.ampproject.org www.gstatic.com *.googletagmanager.com *.googleadservices.com *.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com unpkg.com *.doubleclick.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://halc.iadvize.com/ https://static.iadvize.com/ https://media.flixfacts.com https://test-gateway.mastercard.com https://ap-gateway.mastercard.com/ https://starpay-easy.starboss.biz/ https://www.qpay.gov.qa/ *.fontawesome.com *.googleapis.com *.addtoany.com *.alothemes.com *.magepow.com assets.braintreegateway.com www.gstatic.com maxcdn.bootstrapcdn.com *.tagmanager.google.com *.googletagmanager.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com https://m.media-amazon.com https://media.flixfacts.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io https://cobrowsing-ha.iadvize.com/ https://halc.iadvize.com https://api.iadvize.com/ https://static.iadvize.com/ https://stats.g.doubleclick.net https://bam.nr-data.net https://availability.loadbee.com https://analytics.google.com https://in.hotjar.com https://vc.hotjar.io https://static.rolex.com https://retailers.rolex.com https://static.addtoany.com https://media.flixfacts.com https://stats.addtoany.com https://m.media-amazon.com c.webengage.com assets.adobedtm.com maps.googleapis.com http://dpm.demdex.net *.alothemes.com *.magepow.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com cdn.ampproject.org *.google-analytics.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.doubleclick.net *.run.app 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com *.fontawesome.com 'self' data: https://widgets.trustedshops.com https://integrations.etrusted.com *.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.cleverreach.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * www.google.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com secure.pay1.de payments.amazon.de jsctool.com www.jsctool.com js.playground.klarna.com *.hotjar.com secure.pay1.de/ 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.googleapis.com *.cloudfront.net ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://api.mapbox.com cdn.pay1.de x.klarnacdn.net m.media-amazon.com static-eu.payments-amazon.com *.hsforms.net *.hsforms.com 'self' data: https://widgets.trustedshops.com https://integrations.etrusted.com widgets.trustedshops.com mcstagingmedia.carou.com mcprodmedia.carou.com *.google.com www.google.com.ua ct.pinterest.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com songbird.cardinalcommerce.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com widget.freshworks.com m2epro.freshdesk.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com secure.pay1.de d.ratepay.com static-eu.payments-amazon.com x.klarnacdn.net cdn.klarna.com jsctool.com d.payla.io *.hotjar.com unsafe-inline *.hsforms.net *.hsforms.com https://widgets.trustedshops.com https://integrations.etrusted.com widgets.trustedshops.com bam.nr-data.net js-agent.newrelic *.ratepay.com js-agent.newrelic.com s.pinimg.com analytics.tiktok.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com assets.braintreegateway.com downloads.mailchimp.com widget.freshworks.com m2epro.freshdesk.com *.fontawesome.com d.ratepay.com d.payla.io dr.payla.io maxcdn.bootstrapcdn.com *.googleapis.com *.gstatic.com https://widgets.trustedshops.com https://integrations.etrusted.com *.bootstrapcdn.com maxcdn.bootstrapcdn.com/ *.ratepay.com/ 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.googleapis.com form-assets.mailchimp.com *.intuit.com *.amazonaws.com widget.freshworks.com m2epro.freshdesk.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com payments.amazon.de payments-eu.amazon.com d.ratepay.com jsctool.com eu.playground.klarnaevt.com autocomplete2.postdirekt.de t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com *.trustedshops.com *.etrusted.com *.hotjar.com wss://*.hotjar.com/ bam.nr-data.net www.carou.com stats.g.doubleclick.net vc.hotjar.io ct.pinterest.com analytics.tiktok.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 font-src fonts.gstatic.com use.typekit.net *.fontawesome.com https://fonts.bunny.net *.gstatic.com 'self' data: https://fonts.gstatic.com *.googleapis.com *.hsappstatic.net data: 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; form-action *.facebook.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; frame-ancestors 'self'; frame-src bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ *.cookiebot.com *.doubleclick.net js.mollie.com *.weltpixel.com www.xtento.com *.googletagmanager.com *.bing.com *.facebook.com *.google.com google.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; img-src data: widgets.magentocommerce.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com *.google-analytics.com *.analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.bing.com *.hsforms.net *.hsforms.com *.prism.app-us1.com *.prismic.io https://images.unsplash.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://firebasestorage.googleapis.com https://www.mollie.com 'self' data: www.google.com.ua www.xtento.com cdn.xtento.com *.googletagmanager.com ssl.gstatic.com www.gstatic.com *.cookiebot.com *.doubleclick.net *.facebook.com *.facebook.net *.googleapis.com www.google.ad www.google.ae www.google.al www.google.am www.google.at www.google.az www.google.ba www.google.be www.google.bg www.google.bi www.google.bj www.google.bs www.google.by www.google.ca www.google.ch www.google.ci www.google.cl www.google.cm www.google.co.ao www.google.co.cr www.google.co.id www.google.co.il www.google.co.in www.google.co.jp www.google.co.ke www.google.co.kr www.google.co.ma www.google.com.ar www.google.com.au www.google.com.bd www.google.com.bh www.google.com.bo www.google.com.br www.google.com.bz www.google.com.co www.google.com.cu www.google.com.cy www.google.com.do www.google.com.ec www.google.com.eg www.google.com.et www.google.com.fj www.google.com.gh www.google.com.gi www.google.com.gt www.google.com.hk www.google.com.jm www.google.com.kh www.google.com.kw www.google.com.lb www.google.com.mm www.google.com.mt www.google.com.mx www.google.com.my www.google.com.na www.google.com.ng www.google.com.ni www.google.com.np www.google.com.om www.google.com.pa www.google.com.pe www.google.com.ph www.google.com.pk www.google.com.pr www.google.com.py www.google.com.qa www.google.com.sa www.google.com.sg www.google.com.sl www.google.com.tr www.google.com.tw www.google.com.vn www.google.co.nz www.google.co.th www.google.co.tz www.google.co.ug www.google.co.uk www.google.co.uz www.google.co.ve www.google.co.za www.google.co.zm www.google.co.zw www.google.cv www.google.cz www.google.de www.google.dk www.google.dz www.google.ee www.google.es www.google.fi www.google.fr www.google.ga www.google.ge www.google.gg www.google.gl www.google.gm www.google.gr www.google.hn www.google.hr www.google.hu www.google.ie www.google.iq www.google.is www.google.it www.google.jo www.google.kz www.google.la www.google.li www.google.lk www.google.lt www.google.lu www.google.lv www.google.md www.google.me www.google.mg www.google.mk www.google.mn www.google.mu www.google.mv www.google.nl www.google.no www.google.pl www.google.pt www.google.ro www.google.rs www.google.ru www.google.rw www.google.sc www.google.se www.google.si www.google.sk www.google.sn www.google.sr www.google.td www.google.tm www.google.tn *.google.com google.com *.googlesyndication.com *.googleusercontent.com data: 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; script-src googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.cookiebot.com *.cloudfront.net *.bing.com *.facebook.net *.hsforms.net *.hsforms.com *.prism.app-us1.com *.prismic.io https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.avada.io *.shopify.com js.mollie.com *.google.com *.gstatic.com www.xtento.com cdn.xtento.com *.googletagmanager.com tagmanager.google.com *.doubleclick.net *.googleapis.com *.googlesyndication.com *.klaviyo.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; style-src fonts.googleapis.com https://static.klaviyo.com *.fontawesome.com https://fonts.bunny.net *.googleapis.com *.gstatic.com tagmanager.google.com fonts.google.com https://fonts.googleapis.com *.klaviyo.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.googleadservices.com *.google-analytics.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com *.adobe.io performance.typekit.net *.sentry.io t.elasticsuite.io *.hsforms.net *.hsforms.com *.prism.app-us1.com *.prismic.io https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://get.geojs.io *.avada.io *.googletagmanager.com *.pay.nl *.bing.com *.cookiebot.com *.doubleclick.net *.facebook.com *.facebook.net *.googleapis.com www.google.ad www.google.ae www.google.al www.google.am www.google.at www.google.az www.google.ba www.google.be www.google.bg www.google.bi www.google.bj www.google.bs www.google.ca www.google.ch www.google.cl www.google.cm www.google.co.ao www.google.co.cr www.google.co.id www.google.co.il www.google.co.in www.google.co.jp www.google.co.ke www.google.co.kr www.google.co.ma www.google.com.ar www.google.com.au www.google.com.bd www.google.com.bh www.google.com.bo www.google.com.br www.google.com.bz www.google.com.co www.google.com.cy www.google.com.do www.google.com.ec www.google.com.eg www.google.com.et www.google.com.gh www.google.com.hk www.google.com.kh www.google.com.kw www.google.com.mm www.google.com.mt www.google.com.mx www.google.com.my www.google.com.na www.google.com.np www.google.com.pe www.google.com.ph www.google.com.pk www.google.com.py www.google.com.qa www.google.com.sa www.google.com.sg www.google.com.sl www.google.com.tr www.google.com.tw www.google.com.ua www.google.com.vn www.google.co.nz www.google.co.th www.google.co.tz www.google.co.ug www.google.co.uk www.google.co.ve www.google.co.za www.google.co.zw www.google.cv www.google.cz www.google.de www.google.dk www.google.dz www.google.ee www.google.es www.google.fi www.google.fr www.google.ga www.google.ge www.google.gm www.google.gr www.google.hr www.google.hu www.google.ie www.google.iq www.google.is www.google.it www.google.jo www.google.kz www.google.lk www.google.lt www.google.lu www.google.lv www.google.me www.google.mg www.google.mk www.google.mu www.google.nl www.google.no www.google.pl www.google.pt www.google.ro www.google.rs www.google.ru www.google.rw www.google.se www.google.si www.google.sk www.google.sn www.google.sr www.google.td www.google.tn *.google.com google.com *.googlesyndication.com *.klaviyo.com p2iqhncxyh.execute-api.eu-central-1.amazonaws.com rkkck31tec.execute-api.eu-central-1.amazonaws.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://cc69216c-160f-49b7-b5a2-f80ae473753e.sansec.watch/; report-to report-endpoint; 2 default-src 'self' https://assetspwa.bananarepublic.com.mx; script-src 'self' https://assetspwa.bananarepublic.com.mx; script-src 'self' https://assetspwa.bananarepublic.com.mx* 'unsafe-inline'; font-src 'self' https://assetspwa.bananarepublic.com.mx; script-src https://assetspwa.bananarepublic.com.mx; style-src 'self' https://assetspwa.bananarepublic.com.mx 2 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com maxcdn.bootstrapcdn.com assets.reviews.io *.fontawesome.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de 1merchantacsstag.cardinalcommerce.com payments.securetrading.net *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de account.fetchify.com webservices.securetrading.net cdn.eu.trustpayments.com brw.3ds.trustpayments.com songbirdstag.cardinalcommerce.com 1merchantacsstag.cardinalcommerce.com js.mollie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.payments-amazon.com https://images.unsplash.com www.google.co.uk assets.reviews.io c.clarity.ms gstatic.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ magefan.com cm.magefan.com *.disqus.com https://img.youtube.com https://www.mollie.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de https://maps.googleapis.com cdn-eu.pagesense.io *.clarity.ms widget.reviews.co.uk seal.digicert.com *.zoho.eu gtm.adt313.net googletagmanager.com static.cloudflareinsights.com self unsafe-inline webservices.securetrading.net cdn.eu.trustpayments.com songbirdstag.cardinalcommerce.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.disqus.com https://cdn.jsdelivr.net js.mollie.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com cc-cdn.com maxcdn.bootstrapcdn.com assets.reviews.io data: https://static.klaviyo.com https://cdn.jsdelivr.net *.fontawesome.com assets.braintreegateway.com *.stripe.network *.stripecdn.com *.amazon.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de api.craftyclicks.co.uk pcls1.craftyclicks.co.uk https://maps.googleapis.com https://player.vimeo.com stats.g.doubleclick.net cnv.adt623.net log.adtraction.fail api.reviews.co.uk pagesense-collect.zoho.eu salesiq.zohopublic.eu googleads.g.doubleclick.net *.zoho.eu o402164.ingest.sentry.io https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://5138b325-f342-4866-ad48-54385dfcfca7.sansec.watch/; report-to report-endpoint; 2 font-src https://www.gstatic.com https://fonts.gstatic.com *.gstatic.com *.fontawesome.com https://fonts.bunny.net *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com https://a.klaviyo.com https://www.klaviyo.com *.klaviyo.com *.cloudflare.com *.adyen.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.adyen.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.adyen.com https://*.google.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.google.it *.google.fr *.googletagmanager.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.wesupply.xyz https://wesupplylabs.com *.weltpixel.com www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.adyen.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.googleusercontent.com magefan.com cm.magefan.com *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.google.it *.google.fr *.gstatic.com *.doubleclick.net *.googletagmanager.com https://firebasestorage.googleapis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.cookiebot.com *.google.se *.utils.elfsightcdn.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.adyen.com chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.google.it *.google.fr *.gstatic.com *.googletagmanager.com *.doubleclick.net *.avada.io *.shopify.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com *.klaviyo.com *.matomo.cloud *.locally.com instant.page *.cookiebot.com *.clarity.ms *.jsdelivr.net *.elfsight.com plausible.io analytics.optimalpeople.fr *.equalweb.com *.newrelic.com *.cloudflare.com https://www.googletagmanager.com tagmanager.google.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com downloads.mailchimp.com https://static.klaviyo.com https://fonts.googleapis.com https://hcaptcha.com https://*.hcaptcha.com *.googleapis.com *.googletagmanager.com *.fontawesome.com https://fonts.bunny.net unsafe-inline assets.braintreegateway.com *.stripe.network *.stripecdn.com *.amazon.com *.cloudflare.com https://static-tracking.klaviyo.com/ *.jsdelivr.net *.adyen.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adyen.com form-assets.mailchimp.com *.intuit.com *.amazonaws.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://ipinfo.io https://*.google.com https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com *.google-analytics.com *.google.com *.doubleclick.net *.googlesyndication.com https://www.merchant-center-analytics.goog https://get.geojs.io *.avada.io www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com google.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.klaviyo.com *.locally.com *.clarity.ms *.matomo.cloud *.instagram *.instagram.com *.elfsight.com analytics.optimalpeople.fr plausible.io *.equalweb.com *.cookiebot.com *.nr-data.net *.g.doubleclick.net 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://security-hub.vaimo.network/api/v2/content-security-policy; report-to report-endpoint; 2 default-src 'self' https:; font-src 'self' https: data:; img-src 'self' https: data:; object-src 'none'; script-src 'self' https: 'unsafe-inline' 'unsafe-eval'; style-src 'self' https: 'unsafe-inline'; connect-src 'self' https:; report-uri /csp-violation-report-endpoint 2 default-src 'self'; base-uri 'self'; object-src 'none'; frame-ancestors 'self'; img-src 'self' data: https:; font-src 'self' data: https:; style-src 'self' 'unsafe-inline' https:; script-src 'self' https:; connect-src 'self' https:; form-action 'self'; upgrade-insecure-requests 2 font-src *.fontawesome.com https://fonts.bunny.net www.searchanise.com *.searchserverapi.com *.gstatic.com 'self' data: fonts.gstatic.com *.yotpo.com *.googleapis.com *.cloudflare.com fonts.googleapis.com 'unsafe-inline' data: *.abakhan.co.uk *.woolbox.co.uk *.fabriczone.co.uk data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * www.searchanise.com *.searchserverapi.com *.twitter.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors *.meetanshi.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com www.google.com *.awin1.com *.zenaps.com *.fls.doubleclick.net c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.meetanshi.com js.mollie.com www.searchanise.com *.searchserverapi.com *.twitter.com www.xtento.com *.googletagmanager.com *.yotpo.com widget.trustpilot.com lpcdn.lpsnmedia.net www.paypalobjects.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://images.unsplash.com *.awin1.com *.zenaps.com *.wepowerconnections.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ magefan.com cm.magefan.com https://firebasestorage.googleapis.com https://meetanshi.com/media/logo.png *.meetanshi.com https://www.mollie.com *.twitter.com *.twimg.com www.google.ru www.searchanise.com *.searchserverapi.com s3.amazonaws.com *.hsforms.net *.hsforms.com 'self' data: www.xtento.com cdn.xtento.com *.googletagmanager.com *.google-analytics.com ssl.gstatic.com www.gstatic.com *.yotpo.com *.cloudflare.com *.mdoq.io *.ibottles.co.uk *.google.com *.google.co.uk *.abakhan.co.uk *.woolbox.co.uk *.fabriczone.co.uk data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://maps.googleapis.com *.awin1.com *.dwin1.com *.zenaps.com *.wepowerconnections.com https://the.sciencebehindecommerce.com lantern.roeyecdn.com widget.freshworks.com m2epro.freshdesk.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.avada.io *.shopify.com *.meetanshi.com js.mollie.com searchanise-ef84.kxcdn.com s3.amazonaws.com ajax.aspnetcdn.com www.searchanise.com *.searchserverapi.com *.searchanise.com api.amplitude.com *.twitter.com *.twimg.com *.hsforms.net *.hsforms.com *.google.com *.gstatic.com www.xtento.com cdn.xtento.com *.googletagmanager.com tagmanager.google.com *.yotpo.com *.cloudflare.com *.fontawesome.com *.liveperson.net *.trustpilot.com static.zdassets.com *.abakhan.co.uk *.woolbox.co.uk *.fabriczone.co.uk 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com widget.freshworks.com m2epro.freshdesk.com unsafe-inline assets.braintreegateway.com https://static.klaviyo.com *.fontawesome.com https://fonts.bunny.net www.searchanise.com *.searchserverapi.com searchanise-ef84.kxcdn.com s3.amazonaws.com *.twitter.com ton.twimg.com *.googleapis.com *.gstatic.com tagmanager.google.com fonts.google.com *.yotpo.com *.cloudflare.com *.bootstrapcdn.com fonts.googleapis.com *.abakhan.co.uk *.woolbox.co.uk *.fabriczone.co.uk 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://maps.googleapis.com https://player.vimeo.com *.wepowerconnections.com https://the.sciencebehindecommerce.com widget.freshworks.com m2epro.freshdesk.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.ideal-postcodes.co.uk https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://get.geojs.io *.avada.io *.meetanshi.com api.amplitude.com stats.g.doubleclick.net t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com *.yotpo.com *.cloudflare.com *.abakhan.co.uk *.woolbox.co.uk *.fabriczone.co.uk *.zendesk.com 'self' 'unsafe-inline'; child-src *.awin1.com *.zenaps.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 default-src * 'unsafe-inline' 'unsafe-eval'; report-to report; report-uri /?_task=background&_action=csp_report 2 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net cash-f.squarecdn.com https://client.crisp.chat https://plugin-magento-ui.glopalservice.com https://applepay.cdn-apple.com *.fontawesome.com https://fonts.bunny.net *.cloudflare.com fonts.gstatic.com/ maxcdn.bootstrapcdn.com https://cdnjs.cloudflare.com applepay.cdn-apple.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com * 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com p.monetico-services.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ * ct.pinterest.com *.payplug.com *.dalenys.com https://applepay.cdn-apple.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com api-qa.payplug.com secure-qa.payplug.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com *.google-analytics.com *.analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io * https://images.unsplash.com https://image.crisp.chat *.jardindupicvert.com *.jardindupicvert.com.localhost *.promessedefleurs.com *.promessedefleurs.com.localhost cl.avis-verifies.com ct.pinterest.com bat.bing.com www.google.com.vn https://cdn-redirector.glopal.com https://plugin-magento-ui.glopalservice.com https://secure-magenta.dalenys.com https://firebasestorage.googleapis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://redchamps.com *.openstreetmap.fr *.openstreetmap.org unpkg.com *.google.com *.google.fr *.google.ie data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com *.cash.app *.visa.com *.mastercard.com applepay.cdn-apple.com https://maps.googleapis.com https://player.vimeo.com https://client.crisp.chat cl.avis-verifies.com bat.bing.com s.pinimg.com https://cdn-redirector.glopal.com https://plugin-magento-ui.glopalservice.com cdn-renderer.glopalstore.com https://secure-magenta.dalenys.com https://applepay.cdn-apple.com api-qa.payplug.com cdn-qa.payplug.com cdn.payplug.com *.avada.io *.shopify.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://cdnjs.cloudflare.com https://cdn.payplug.com https://cdn-qa.payplug.com https://unpkg.com/pwacompat *.google.com *.google.fr *.google.ie *.googletagmanager.com *.googleadservices.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.cash.app https://client.crisp.chat https://cdn-redirector.glopal.com https://plugin-magento-ui.glopalservice.com https://secure-magenta.dalenys.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com https://fonts.googleapis.com https://cdnjs.cloudflare.com unpkg.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.googleadservices.com *.google-analytics.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io * https://maps.googleapis.com https://player.vimeo.com https://client.crisp.chat wss://client.relay.crisp.chat https://plugins.crisp.chat *.jardindupicvert.com *.jardindupicvert.com.localhost *.promessedefleurs.com *.promessedefleurs.com.localhost ct.pinterest.com https://api-plugin-facade.glopalservice.com https://cognito-idp.eu-west-1.amazonaws.com api.glopaltranslator.com https://get.geojs.io *.avada.io www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.openstreetmap.org *.arcgis.com *.doubleclick.net 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src cl.avis-verifies.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 font-src *.fontawesome.com *.googleapis.com *.gstatic.com maxcdn.bootstrapcdn.com fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com www.apptrian.com pinterest.com www.pinterest.com ct.pinterest.com *.elavon.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.apptrian.com pinterest.com www.pinterest.com ct.pinterest.com *.clearpay.co.uk secure.livechatinc.com *.addthis.com *.elavon.com js.mollie.com *.trustpilot.com *.weltpixel.com *.googletagmanager.com *.doubleclick.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.apptrian.com pinterest.com www.pinterest.com ct.pinterest.com *.afterpay.com *.clearpay.co.uk cdn.doofinder.com www.google.co.uk bat.bing.com c.clarity.ms c.bing.com bat.bing.net https://meetanshi.com/media/logo.png https://www.mollie.com *.gstatic.com *.facebook.com *.reddit.com *.google-analytics.com *.googletagmanager.com *.doubleclick.net *.google.com *.cdninstagram.com *.fbcdn.net maps.googleapis.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.apptrian.com pinterest.com www.pinterest.com s.pinimg.com *.afterpay.com *.clearpay.co.uk *.squarecdn.com https://hbiq.net cdn.doofinder.com cdn.livechatinc.com api.livechatinc.com static.getclicky.com in.getclicky.com cdn.cookie-script.com www.facebook.com widget.trustpilot.com bat.bing.com www.clarity.ms scripts.clarity.ms widgets.tree-nation.com portal.clearpay.co.uk *.addthis.com *.moatads.com *.addthisedge.com *.pinterest.com *.fontawesome.com *.googleapis.com *.gstatic.com *.avada.io *.elavon.com js.mollie.com *.trustpilot.com ajax.googleapis.com *.googletagmanager.com *.googleadservices.com *.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com unpkg.com *.doubleclick.net https://www.googletagmanager.com tagmanager.google.com *.instagram.com maps.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.afterpay.com/ *.squarecdn.com *.doofinder.com *.fontawesome.com maxcdn.bootstrapcdn.com *.trustpilot.com fonts.googleapis.com *.tagmanager.google.com *.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com pinterest.com www.pinterest.com ct.pinterest.com *.cdninstagram.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com www.apptrian.com pinterest.com www.pinterest.com ct.pinterest.com *.clearpay.co.uk *.squarecdn.com https://hbiq.net https://iq.afterpay-beta.com https://iq.afterpay.com *.doofinder.com wss://*.doofinder.com googleads.g.doubleclick.net pagead2.googlesyndication.com www.facebook.com consent.cookie-script.com stats.g.doubleclick.net api.livechatinc.com cdn.livechatinc.com q.clarity.ms o.clarity.ms v.clarity.ms in.getclicky.com bat.bing.net bat.bing.com www.google.co.uk www.google.com portal.clearpay.co.uk cdn.jsdelivr.net *.addthis.com https://get.geojs.io *.avada.io *.google-analytics.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.doubleclick.net *.run.app https://www.google-analytics.com *.instagram.com *.googleusercontent.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 font-src https://*.gstatic.com https://fonts.gstatic.com *.googleapis.com *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com *.fontawesome.com *.yotpo.com *.klevu.com *.ksearchnet.com fonts.gstatic.com use.fontawesome.com app.christies.test static.klaviyo.com https://widgets.trustedshops.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.adyen.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com *.googlesyndication.com *.tiktok.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors *.multisafepay.com https://pay.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.adyen.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * js.stripe.com *.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com https://*.dpdconnect.nl *.yotpo.com *.multisafepay.com https://pay.google.com www.googletagmanager.com widget.trustpilot.com d.la1-core1.sfdc-cehfhs.salesforceliveagent.com service.force.com insight.adsrvr.org 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.adyen.com https://images.unsplash.com https://*.gstatic.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.googleapis.com *.gstatic.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.googlesyndication.com *.roeye.com *.tiktok.com www.feedoptimise.com cdn.feedoptimise.com *.yotpo.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com *.multisafepay.com app.christies.test cdn-ukwest.onetrust.com cdn.christiesdirect.com x.klarnacdn.net apple-resources.s3.amazonaws.com play.google.com www.facebook.com js.klevu.com bat.bing.com maps.gstatic.com bat.bing.net www.google.co.uk static.klaviyo.com static-forms.klaviyo.com fast.a.klaviyo.com static-tracking.klaviyo.com a.klaviyo.com telemetrics.klaviyo.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.adyen.com https://maps.googleapis.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googleapis.com *.gstatic.com https://cdn.jsdelivr.net/npm/@ryangjchandler/spruce@2.x.x/dist/spruce.umd.js js.stripe.com *.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.googlesyndication.com *.jsdelivr.net *.tiktok.com https://*.dpdconnect.nl www.feedoptimise.com cdn.feedoptimise.com *.yotpo.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ js.klevu.com *.ksearchnet.com *.multisafepay.com https://pay.google.com app.christies.test widget.trustpilot.com js.klarna.com integrations.etrusted.com www.dwin1.com connect.facebook.net lantern.roeyecdn.com cdn-ukwest.onetrust.com bat.bing.com static.hotjar.com cdn.attn.tv service.force.com js.adsrvr.org analytics.tiktok.com www.clarity.ms d.la2-c2-cdg.salesforceliveagent.com d.la1-core1.sfdc-cehfhs.salesforceliveagent.com christiesdirect-dev.my.salesforce-sites.com tag.mention-me.com static.mention-me.com maps.googleapis.com static.klaviyo.com static-forms.klaviyo.com fast.a.klaviyo.com static-tracking.klaviyo.com a.klaviyo.com telemetrics.klaviyo.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://fonts.googleapis.com/ https://fonts.googleapis.com unsafe-inline assets.braintreegateway.com fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com *.tiktok.com *.fontawesome.com *.yotpo.com https://static.klaviyo.com *.klevu.com *.ksearchnet.com *.multisafepay.com app.christies.test use.fontawesome.com x.klarnacdn.net js.klevu.com service.force.com pay.multisafepay.com https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com https://js.klevu.com 'self' 'unsafe-inline' 'unsafe-eval'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adyen.com https://maps.googleapis.com https://player.vimeo.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.googleapis.com *.google-analytics.com *.facebook.com *.facebook.net *.doubleclick.net *.googlesyndication.com *.tiktok.com *.yotpo.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com *.multisafepay.com region1.google-analytics.com s.clarity.ms js.klarna.com app.christies.test widget.trustpilot.com cdn-ukwest.onetrust.com geolocation.onetrust.com pay.google.com play.google.com maps.googleapis.com bat.bing.net static.klaviyo.com static-forms.klaviyo.com fast.a.klaviyo.com static-tracking.klaviyo.com a.klaviyo.com telemetrics.klaviyo.com *.trustedshops.com *.etrusted.com https://integrations.etrusted.site 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src app.christies.test bat.bing.com s.clarity.ms pagead2.googlesyndication.com analytics.tiktok.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com https://use.typekit.net https://static.formstack.com https://css.zohocdn.com https://fonts.gstatic.com https://maxcdn.bootstrapcdn.com maxcdn.bootstrapcdn.com *.fontawesome.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com *.googlesyndication.com *.tiktok.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com https://www.google.com https://www.youtube.com https://www.bullseyelocations.com landofcoder.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.googleapis.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.googlesyndication.com *.roeye.com *.tiktok.com https://www.truck-lite.com https://www.rigidindustries.com https://www.clariencetechnologies.com https://www.lumiteclighting.com https://www.truck-lite.eu.com https://mcstaging.truck-lite.com https://trucklite.localhost https://mcstaging.clariencetechnologies.com https://pm.geniusmonkey.com https://css.zohocdn.com https://static.ctctcdn.com https://www.facebook.com https://www.google.com https://www.googletagmanager.com https://maps.googleapis.com https://maps.gstatic.com https://firebasestorage.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com commerce-payments-sdk.adobe.io www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://rum.hlx.page www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.googleapis.com https://www.gstatic.com https://www.google.com *.google.bg *.googletagmanager.com https://connect.facebook.net *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com *.jsdelivr.net *.tiktok.com https://browser-update.org https://wwwtrucklitecom.formstack.com https://static.formstack.com https://www.google.com/recaptcha/api.js https://code.jquery.com https://cdnjs.cloudflare.com https://static.ctctcdn.com https://salesiq.zoho.com https://js.zohocdn.com https://static.zohocdn.com https://js-agent.newrelic.com https://www.googletagmanager.com https://maps.googleapis.com https://googleads.g.doubleclick.net https://www.truck-lite.com https://mcstaging.truck-lite.com https://cdn.jsdelivr.net landofcoder.com *.avada.io *.shopify.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://js.stripe.com https://www.gstatic.com/recaptcha/releases/Trd6gj1dhC_fx0ma_AWHc1me/recaptcha__en.js 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com *.tiktok.com https://use.typekit.net https://p.typekit.net https://static.ctctcdn.com https://css.zohocdn.com https://fonts.googleapis.com https://maxcdn.bootstrapcdn.com https://www.truck-lite.com https://mcstaging.truck-lite.com https://cdn.jsdelivr.net maxcdn.bootstrapcdn.com *.fontawesome.com https://fonts.bunny.net assets.braintreegateway.com 'self' 'unsafe-inline'; object-src landofcoder.com 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.googleapis.com *.google-analytics.com *.facebook.com *.facebook.net *.doubleclick.net *.googlesyndication.com *.tiktok.com https://wwwtrucklitecom.formstack.com https://listgrowth.ctctcdn.com https://bam.nr-data.net https://salesiq.zohopublic.com https://www.google-analytics.com https://analytics.google.com https://www.facebook.com https://maps.googleapis.com https://www.truck-lite.com https://mcstaging.truck-lite.com landofcoder.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://ajax.googleapis.com https://beacon-v2.helpscout.net https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://googleads.g.doubleclick.net https://js.chargebee.com https://www.googletagmanager.com https://www.gstatic.com/firebasejs/ https://www.gstatic.com/charts/ https://www.youtube.com https://static.cloudflareinsights.com https://js.stripe.com; script-src-elem 'self' 'unsafe-inline' blob: https://rehearse-api.ccli.com https://cdn.jsdelivr.net/gh/ https://apis.google.com https://cdn.segment.com https://ajax.googleapis.com https://cdnjs.cloudflare.com https://googleads.g.doubleclick.net https://pagead2.googlesyndication.com https://www.google.com https://www.googletagmanager.com https://www.gstatic.com https://www.youtube.com https://js.chargebee.com https://js.stripe.com https://static.cloudflareinsights.com https://beacon-v2.helpscout.net; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; style-src-elem 'self' 'unsafe-inline' https://fonts.googleapis.com https://www.gstatic.com; img-src 'self' data: blob: https://api.builder.io/api/v1/ https://d33v4339jhl8k0.cloudfront.net https://support.apple.com https://www.googleadservices.com https://*.mzstatic.com https://beacon-v2.helpscout.net https://s3.amazonaws.com/helpscout.net/docs/ https://s3.amazonaws.com/helpscout.net https://cdn.worshipextreme.com https://i3.ytimg.com https://i.ytimg.com https://www.google.com https://www.googletagmanager.com https://googleads.g.doubleclick.net https://pagead2.googlesyndication.com https://translate.google.com https://www.worshipextreme.com https://fonts.gstatic.com; font-src 'self' data: https://fonts.gstatic.com; connect-src 'self' https://googleads.g.doubleclick.net/pagead https://api.worship.tools https://beaconapi.helpscout.net https://d3hb14vkzrxvla.cloudfront.net https://download.worshiptools.com https://ipapi.co https://pagead2.googlesyndication.com https://www.google.com https://www.googleapis.com https://region1.google-analytics.com https://www.google-analytics.com https://firestore.googleapis.com https://securetoken.googleapis.com https://translate.googleapis.com https://www.googleadservices.com https://www.googletagmanager.com https://us-east1-worship-extreme.cloudfunctions.net; media-src 'self' data: https://ssl.gstatic.com https://cdn.worshipextreme.com https://media.worshiptools.com; object-src 'none'; frame-src 'self' https://rehearse-api.ccli.com https://bluecirclelab.chargebee.com https://js.chargebee.com https://www.googletagmanager.com https://www.youtube.com https://docs.google.com https://www.google.com https://js.stripe.com https://worship-extreme-datastore.firebaseapp.com; worker-src 'none'; base-uri 'self'; manifest-src 'self'; report-uri https://starpraise.report-uri.com/r/t/csp/reportOnly; 2 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com https://fonts.bunny.net 'self' data: https://*.sovendus.com https://widgets.trustedshops.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com https://www.googletagmanager.com/ *.facebook.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * https://*.sovendus.com https://www.sovendus-benefits.com https://www.sovendus-campaign.com https://www.sovendus-connect.com https://www.sovendus-network.com https://app-wallee.com https://paymentshub.weareplanet.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com *.google-analytics.com *.analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io magefan.com cm.magefan.com *.disqus.com *.cookiebot.com maps.googleapis.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ *.cdninstagram.com https://firebasestorage.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.hsforms.net *.hsforms.com 'self' data: https://*.sovendus.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com *.etrusted.com https://app-wallee.com https://paymentshub.weareplanet.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com commerce-payments-sdk.adobe.io www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.disqus.com tracking.moevenpick-wein.com *.cookiebot.com maps.googleapis.com newsletter.moevenpick-wein.de http://www.googletagmanager.com/ https://www.googletagmanager.com/ player.vimeo.com connect.facebook.net cdnjs.cloudflare.com *.avada.io *.shopify.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.hsforms.net *.hsforms.com *.gstatic.com https://*.sovendus.com https://www.sovopt.com https://static.sovopt.com https://www.getback.ch https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.etrusted.com https://app-wallee.com https://paymentshub.weareplanet.com https://gmtech.mfgroup.ch https://assets.secure.checkout.visa.com consent.cookiebot.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com https://fonts.bunny.net assets.braintreegateway.com *.googleapis.com *.gstatic.com https://static.getback.ch https://*.sovendus.com https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.etrusted.com https://app-wallee.com https://paymentshub.weareplanet.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.googleadservices.com *.google-analytics.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com tracking.moevenpick-wein.com *.cookiebot.com maps.googleapis.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com t.elasticsuite.io *.hsforms.net *.hsforms.com https://*.sovendus.com https://www.sovendus-benefits.com https://www.sovendus-campaign.com https://www.sovendus-connect.com https://www.sovendus-network.com *.trustedshops.com *.etrusted.com https://integrations.etrusted.site https://app-wallee.com https://paymentshub.weareplanet.com https://assets.secure.checkout.visa.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 default-src 'self' data: 'unsafe-inline' 'unsafe-eval' unpkg.com *.cookieinformation.com *.episerver.net *.itxuc.com *.googletagmanager.com *.imgi.no *.youtube.com siteimproveanalytics.com *.siteimproveanalytics.io *.doubleclick.net localhost:5000 *.snapchat.com *.google.com *.facebook.com js.monitor.azure.com *.facebook.net snap.licdn.com sc-static.net *.tiktok.com px.ads.linkedin.com *.cloudfront.net *.eu1.odp.optimizely.com *.bing.com *.ads.linkedin.com *.services.visualstudio.com *.googlesyndication.com *.aptrinsic.com cdn.siteimprove.net adservice.google.com *.googleapis.com *.gstatic.com elvia.my.site.com elvia.my.salesforce-scrt.com elvia--test.sandbox.my.site.com elvia--test.sandbox.my.salesforce-scrt.com cookie-cdn.cookiepro.com fonts.vev.design;report-uri https://phoenix-csp-reporting.azurewebsites.net/cspreport 2 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com cdn.jsdelivr.net geowidget.easypack24.net *.fontawesome.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com *.wesupply.xyz https://wesupplylabs.com secure.payu.com merch-prod.snd.payu.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io www.google.pl www.facebook.com px.ads.linkedin.com elmark.com.pl www.elmark.com.pl *.clarity.ms *.bing.com geowidget.easypack24.net osm.inpost.pl www.rugged.com.pl elmatic.net magefan.com cm.magefan.com https://firebasestorage.googleapis.com static.payu.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com maps.googleapis.com snap.licdn.com connect.facebook.net *.clarity.ms pi.pardot.com unpkg.com api.mapbox.com cdn.jsdelivr.net geowidget.easypack24.net info.elmark.com.pl consent.cookiefirst.com *.googlesyndication.com *.cloudflare.com *.avada.io secure.payu.com secure.snd.payu.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com cdn.jsdelivr.net geowidget.easypack24.net *.fontawesome.com https://fonts.bunny.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com maps.googleapis.com region1.analytics.google.com px.ads.linkedin.com *.clarity.ms stats.g.doubleclick.net *.googlesyndication.com api-pl-points.easypack24.net *.google-analytics.com https://get.geojs.io *.avada.io secure.payu.com merch-prod.snd.payu.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src www.google.com *.clarity.ms 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 default-src 'self' https://cdn.wolterskluwer.io/ https://www.googletagmanager.com/ https://analytics.sleeknote.com/ https://dc.services.visualstudio.com/v2/track https://www.google-analytics.com/ https://region1.google-analytics.com/ https://vimeo.com/ https://pagead2.googlesyndication.com/ https://cmtt.nl/ https://ep1.adtrafficquality.google/ https://securepubads.g.doubleclick.net/; script-src 'self' 'unsafe-eval' 'unsafe-inline' https://cdn.userdatatrust.com/ https://securepubads.g.doubleclick.net/ https://pagead2.googlesyndication.com/ https://ep2.adtrafficquality.google/ https://www.googletagmanager.com/ https://eu2.cdn.thunderhead.com/one/rt/js/one-tag.js?siteKey=ONE-JHGTRIWT14-2067 http://sleeknotecustomerscripts.sleeknote.com/23807.js http://img.en25.com/i/elqCfg.min.js https://az416426.vo.msecnd.net/scripts/a/ai.0.js http://sleeknotestaticcontent.sleeknote.com/ https://googleads.g.doubleclick.net/pagead/viewthroughconversion/1069938057/ https://www.google-analytics.com/analytics.js https://www.googletagservices.com/ https://connect.facebook.net/ http://cdn.feedbackify.com/ http://dev.visualwebsiteoptimizer.com/ https://certify-js.alexametrics.com/ http://ajax.googleapis.com/; style-src 'self' 'unsafe-inline' https://cdn.wolterskluwer.io/; img-src 'self' https://cdn.wolterskluwer.io/wk-logos/1.0.x/ https://s1364398973.t.eloqua.com/visitor/v200/svrGP data: https://www.google.com/ https://www.google.it/ https://www.google-analytics.com/ https://i.vimeocdn.com/ https://www.taxvisions.nl/ https://acc.taxvisions.nl/ https://ep1.adtrafficquality.google/ https://ep2.adtrafficquality.google/ https://tpc.googlesyndication.com/ https://pagead2.googlesyndication.com/ https://www.googletagmanager.com/ http://cdn.feedbackify.com/ https://dev.visualwebsiteoptimizer.com/; font-src 'self' https://cdn.wolterskluwer.io/; frame-src 'self' https://player.vimeo.com/ *.safeframe.googlesyndication.com/ https://ep2.adtrafficquality.google/; frame-ancestors 'self'; 2 font-src fonts.gstatic.com use.typekit.net *.klarnacdn.net *.fontawesome.com maxcdn.bootstrapcdn.com *.klaviyo.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.demdex.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.sharethis.com www.xtento.com *.klarna.com *.resurs.com *.vimeo.com *.google.com *.googletagmanager.com gtm.sharkgaming.dk gtm.sharkgaming.se gtm.sharkgaming.no gtm-p7bx89s-nwviz.uc.r.appspot.com *.chatbotize.com *.cookieinformation.com *.trustpilot.com *.viabill.com *.doubleclick.net *.getzowie.com chat.karlachat.com *.getblue.io *.facebook.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net *.sharethis.com www.xtento.com cdn.xtento.com *.bird.eu *.klarna.com *.klarnaevt.com *.klarnacdn.net https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.facebook.com *.google.com *.googleadservices.com *.google-analytics.com *.googletagmanager.com *.bing.com *.magentocommerce.com sharkgaming.dk sharkgaming.se sharkgaming.no *.sharkgaming.dk *.sharkgaming.se *.sharkgaming.no *.google.dk *.google.se *.google.no *.charpstar.net s7g10.scene7.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net assets.adobedtm.com commerce.adobe.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com *.magento-ds.com *.sharethis.com www.xtento.com cdn.xtento.com *.klarna.com *.klarnacdn.net *.klarnaservices.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ connect.facebook.net *.googletagmanager.com *.googleadservices.com *.google-analytics.com *.resurs.com *.sharkgaming.dk *.sharkgaming.se *.sharkgaming.no *.app.cookieinformation.com *.viabill.com *.trustpilot.com *.emaerket.dk *.payever.org *.hotjar.com *.bing.com addrevenue.io *.retargeted.co *.getzowie.com *.zopim.com *.adii.se *.charpstar.net *.azureedge.net gtm-p7bx89s-nwviz.uc.r.appspot.com analytics.tiktok.com *.getblue.io analytics.bestofluck.io 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.magento-datasolutions.com *.magento-ds.com *.sharethis.com *.klarnacdn.net https://static.klaviyo.com *.fontawesome.com maxcdn.bootstrapcdn.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.magento-datasolutions.com *.magento-ds.com *.adobe.io *.omtrdc.net data: 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.magento-datasolutions.com *.magento-ds.com *.sharethis.com *.klarnaevt.com *.klarnacdn.net *.klarna.com *.klarnaservices.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.google-analytics.com *.analytics.google.com *.googletagmanager.com stats.g.doubleclick.net *.charpstar.net *.klaviyo.com *.doubleclick.net *.google.com *.app.cookieinformation.com *.getzowie.com *.zopim.com wss://widget-mediator.zopim.com *.browser-intake-datadoghq.eu *.googlesyndication.com blob: *.sharkgaming.dk *.sharkgaming.se *.sharkgaming.no *.payever.org *.elastic-cloud.com addrevenue.io *.chatbotize.com mboxedge37.tt.omtrdc.net gtm-p7bx89s-nwviz.uc.r.appspot.com analytics.tiktok.com *.bing.com wss://ws.hotjar.com *.hotjar.com *.hotjar.io maps.googleapis.com bat.bing.net *.sparxpres.dk sparxpres.dk 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 font-src *.fontawesome.com *.yotpo.com *.googleapis.com *.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net pilot-payflowlink.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com assets.braintreegateway.com www.google.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de cdn.dnky.co webchat.dotdigital.com www.xtento.com *.yotpo.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com s.ytimg.com validator.swagger.io d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.facebook.com www.xtento.com cdn.xtento.com *.yotpo.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com video.google.com vimeo.com www.vimeo.com *.vimeocdn.com js.authorize.net jstest.authorize.net js.braintreegateway.com cdn-scripts.signifyd.com www.youtube.com maps.googleapis.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de r1-t.trackedlink.net r2-t.trackedlink.net r3-t.trackedlink.net r1.trackedweb.net r2.trackedweb.net r3.trackedweb.net static.trackedweb.net cdn.dnky.co api.comapi.com webchat.dotdigital.com *.googletagmanager.com *.facebook.net *.avada.io www.xtento.com cdn.xtento.com *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src getfirebug.com cdn.dnky.co webchat.dotdigital.com *.fontawesome.com *.yotpo.com *.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com payments.sandbox.braintree-api.com origin-analytics-sand.sandbox.braintree-api.com assets.braintreegateway.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de r1-t.trackedlink.net r2-t.trackedlink.net r3-t.trackedlink.net r1.trackedweb.net r2.trackedweb.net r3.trackedweb.net static.trackedweb.net api.comapi.com webchat.dotdigital.com *.google-analytics.com *.yotpo.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://js.monitor.azure.com https://vimeo.com https://player.vimeo.com https://*.vimeo.com https://dc.services.visualstudio.com https://js.monitor.azure.com https://www.youtube.com https://youtube.com https://www.youtube-nocookie.com https://i.ytimg.com/ https://i.vimeocdn.com https://player-telemetry.vimeo.com https://viewer.mapme.com https://m.ankiro.dk/ https://www.googletagmanager.com https://tracking.m.dk https://*.googleapis.com https://*.analytics.google.com https://tagmanager.google.com https://policy.app.cookieinformation.com https://consent.app.cookieinformation.com/api/consent https://fonst.gstatic.com https://www.google.com/recaptcha/api.js https://www.gstatic.com/recaptcha/releases/ https://www.google.com/ https://hittegods.metroservice.dk https://hittegodseng.metroservice.dk https://hittegodsvedikke.metroservice.dk/ https://hittegodsvedikkeeng.metroservice.dk/ https://henvendelseeng.metroservice.dk/ https://henvendelse.metroservice.dk/ https://payment.metroservice.dk/ https://connect.facebook.net/en_US/fbevents.js https://*.adform.net https://s2.adform.net/banners/scripts/st/trackpoint-async.js https://cdn.matomo.cloud/metroselskabet.matomo.cloud/matomo.js https://connect.facebook.net/signals/config/ https://s2.adform.net/Serving/TrackPoint/ https://metroselskabet.matomo.cloud/matomo.php https://ad.doubleclick.net/activity https://9562205.fls.doubleclick.net/ https://td.doubleclick.net/ https://api-eu1.agillic.net/recipients https://api-eu1.agillic.net/recipients/v2/:upsertAndAchieve https://app-ne-metro-p-website-cd.azurewebsites.net https://app-ne-metro-p-corp-cd.azurewebsites.net; style-src 'self' 'unsafe-inline' https://www.googletagmanager.com https://tagmanager.google.com https://fonts.googleapis.com; img-src 'self' https://metroselskabet.euwest01.umbraco.io/ https://js.monitor.azure.com https://vimeo.com https://player.vimeo.com https://*.vimeo.com https://dc.services.visualstudio.com https://js.monitor.azure.com https://www.youtube.com https://youtube.com https://www.youtube-nocookie.com https://i.ytimg.com/ https://i.vimeocdn.com https://player-telemetry.vimeo.com https://viewer.mapme.com https://m.ankiro.dk/ https://www.googletagmanager.com https://tracking.m.dk https://*.googleapis.com https://*.analytics.google.com https://tagmanager.google.com https://policy.app.cookieinformation.com https://consent.app.cookieinformation.com/api/consent https://fonst.gstatic.com https://www.google.com/recaptcha/api.js https://www.gstatic.com/recaptcha/releases/ https://www.google.com/ https://hittegods.metroservice.dk https://hittegodseng.metroservice.dk https://hittegodsvedikke.metroservice.dk/ https://hittegodsvedikkeeng.metroservice.dk/ https://henvendelseeng.metroservice.dk/ https://henvendelse.metroservice.dk/ https://payment.metroservice.dk/ https://connect.facebook.net/en_US/fbevents.js https://*.adform.net https://s2.adform.net/banners/scripts/st/trackpoint-async.js https://cdn.matomo.cloud/metroselskabet.matomo.cloud/matomo.js https://connect.facebook.net/signals/config/ https://s2.adform.net/Serving/TrackPoint/ https://metroselskabet.matomo.cloud/matomo.php https://ad.doubleclick.net/activity https://9562205.fls.doubleclick.net/ https://td.doubleclick.net/ https://api-eu1.agillic.net/recipients https://api-eu1.agillic.net/recipients/v2/:upsertAndAchieve https://app-ne-metro-p-website-cd.azurewebsites.net https://app-ne-metro-p-corp-cd.azurewebsites.net https://ssl.gstatic.com https://www.gstatic.com https://www.facebook.com blob: data:; media-src 'self' https://metroselskabet.euwest01.umbraco.io/ blob: data:; font-src 'self' https://fonts.gstatic.com data:; object-src 'none'; base-uri 'self'; form-action 'self' https://metroselskabet.euwest01.umbraco.io/; frame-ancestors 'none'; upgrade-insecure-requests; connect-src 'self' https://metroselskabet.euwest01.umbraco.io/ https://js.monitor.azure.com https://vimeo.com https://player.vimeo.com https://*.vimeo.com https://dc.services.visualstudio.com https://js.monitor.azure.com https://www.youtube.com https://youtube.com https://www.youtube-nocookie.com https://i.ytimg.com/ https://i.vimeocdn.com https://player-telemetry.vimeo.com https://viewer.mapme.com https://m.ankiro.dk/ https://www.googletagmanager.com https://tracking.m.dk https://*.googleapis.com https://*.analytics.google.com https://tagmanager.google.com https://policy.app.cookieinformation.com https://consent.app.cookieinformation.com/api/consent https://fonst.gstatic.com https://www.google.com/recaptcha/api.js https://www.gstatic.com/recaptcha/releases/ https://www.google.com/ https://hittegods.metroservice.dk https://hittegodseng.metroservice.dk https://hittegodsvedikke.metroservice.dk/ https://hittegodsvedikkeeng.metroservice.dk/ https://henvendelseeng.metroservice.dk/ https://henvendelse.metroservice.dk/ https://payment.metroservice.dk/ https://connect.facebook.net/en_US/fbevents.js https://*.adform.net https://s2.adform.net/banners/scripts/st/trackpoint-async.js https://cdn.matomo.cloud/metroselskabet.matomo.cloud/matomo.js https://connect.facebook.net/signals/config/ https://s2.adform.net/Serving/TrackPoint/ https://metroselskabet.matomo.cloud/matomo.php https://ad.doubleclick.net/activity https://9562205.fls.doubleclick.net/ https://td.doubleclick.net/ https://api-eu1.agillic.net/recipients https://api-eu1.agillic.net/recipients/v2/:upsertAndAchieve https://app-ne-metro-p-website-cd.azurewebsites.net https://app-ne-metro-p-corp-cd.azurewebsites.net; frame-src 'self' https://js.monitor.azure.com https://vimeo.com https://player.vimeo.com https://*.vimeo.com https://dc.services.visualstudio.com https://js.monitor.azure.com https://www.youtube.com https://youtube.com https://www.youtube-nocookie.com https://i.ytimg.com/ https://i.vimeocdn.com https://player-telemetry.vimeo.com https://viewer.mapme.com https://m.ankiro.dk/ https://www.googletagmanager.com https://tracking.m.dk https://*.googleapis.com https://*.analytics.google.com https://tagmanager.google.com https://policy.app.cookieinformation.com https://consent.app.cookieinformation.com/api/consent https://fonst.gstatic.com https://www.google.com/recaptcha/api.js https://www.gstatic.com/recaptcha/releases/ https://www.google.com/ https://hittegods.metroservice.dk https://hittegodseng.metroservice.dk https://hittegodsvedikke.metroservice.dk/ https://hittegodsvedikkeeng.metroservice.dk/ https://henvendelseeng.metroservice.dk/ https://henvendelse.metroservice.dk/ https://payment.metroservice.dk/ https://connect.facebook.net/en_US/fbevents.js https://*.adform.net https://s2.adform.net/banners/scripts/st/trackpoint-async.js https://cdn.matomo.cloud/metroselskabet.matomo.cloud/matomo.js https://connect.facebook.net/signals/config/ https://s2.adform.net/Serving/TrackPoint/ https://metroselskabet.matomo.cloud/matomo.php https://ad.doubleclick.net/activity https://9562205.fls.doubleclick.net/ https://td.doubleclick.net/ https://api-eu1.agillic.net/recipients https://api-eu1.agillic.net/recipients/v2/:upsertAndAchieve https://app-ne-metro-p-website-cd.azurewebsites.net https://app-ne-metro-p-corp-cd.azurewebsites.net; 2 https://www.calyxsoftware.com;static.hsappstatic.net, *.hubspotusercontent-*.net, *.hubspot.net, *.hs-scripts.com 2 font-src *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.yotpo.com *.googleapis.com *.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paymentexpress.com *.windcave.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com www.xtento.com *.paymentexpress.com *.windcave.com *.yotpo.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.xtento.com cdn.xtento.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com *.files-text.com *.livechatinc.com *.livechat-files.com *.livechat-static.com https://firebasestorage.googleapis.com flagpedia.net *.yotpo.com data: 'self' 'unsafe-inline'; script-src geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.xtento.com cdn.xtento.com chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com https://browser.sentry-cdn.com *.livechatinc.com *.livechat-static.com *.avada.io *.shopify.com *.gstatic.com maps.googleapis.com *.yotpo.com https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src downloads.mailchimp.com *.livechatinc.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.gstatic.com *.yotpo.com *.googleapis.com 'self' 'unsafe-inline'; object-src *.livechatinc.com 'self' 'unsafe-inline'; media-src *.livechatinc.com *.livechat-static.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com form-assets.mailchimp.com *.intuit.com *.amazonaws.com https://*.ingest.sentry.io *.livechatinc.com *.text.com https://get.geojs.io *.avada.io www.gstatic.com maps.googleapis.com *.yotpo.com 'self' 'unsafe-inline'; child-src *.livechatinc.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 font-src fonts.gstatic.com use.typekit.net *.cloudflare.com *.twitter.com *.gstatic.com *.typekit.net *.twimg.com *.trustedshops.com *.googleapis.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.twitter.com *.google.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.youtube.com/ *.google.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io *.cloudflare.com *.klarna.com *.googleadservices.com *.google-analytics.com *.paypal.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.google.com *.maps.gstatic.com maps.gstatic.com maps.googleapis.com data: 'self' 'unsafe-inline'; script-src www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.cloudflare.com *.twitter.com *.google-analytics.com *.twimg.com *.gstatic.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.maps.googleapis.com *.trackedlink.net *.google.com *.maps.gstatic.com maps.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com *.cloudflare.com *.googleapis.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.google.com *.maps.gstatic.com maps.gstatic.com maps.googleapis.com *.google-analytics.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.cloudflare.com *.twitter.com *.paypal.com *.twimg.com *.googleadservices.com *.google-analytics.com *.sandbox.paypal.com *.paypalobjects.com *.trackedlink.net *.ampproject.org *.google.com *.google.co.in *.maps.gstatic.com *.maps.googleapis.com maps.googleapis.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://csp-reporting-service.com/my-project/endpoint; report-to report-endpoint; 2 default-src 'self'; connect-src 'self' www.googleadservices.com ct.pinterest.com bat.bing.net px.ads.linkedin.com settings.luckyorange.net bat.bing.com analytics.google.com www.google.co.uk www.facebook.com stats.g.doubleclick.net live.opayo.eu.elavon.com/api/v1/ services.postcodeanywhere.co.uk api.vimeo.com fresnel.vimeocdn.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com; font-src 'self' www.westdean.ac.uk assets.westdean.ac.uk/ data:; frame-ancestors 'self'; frame-src 'self' ct.pinterest.com discoveruni.gov.uk widget.discoveruni.gov.uk live.opayo.eu.elavon.com/api/v1/ my.matterport.com www.googletagmanager.com player.vimeo.com vimeo.com www.youtube.com *.luckyorange.com; img-src 'self' * data:; media-src d10lpsik1i8c69.cloudfront.net player.vimeo.com download-video-ak.vimeocdn.com/v3-1/playback/ vod-adaptive-ak.vimeocdn.com skyfire.vimeocdn.com; script-src 'self' static.cloudflareinsights.com www.westdean.ac.uk assets.westdean.ac.uk/ chimpstatic.com s.pinimg.com d10lpsik1i8c69.cloudfront.net ct.pinterest.com snap.licdn.com assets.opayo.cloud/assets/js/opayo-1.2.40.js cdn.tickettailor.com services.postcodeanywhere.co.uk player.vimeo.com www.youtube.com *.doubleclick.net *.bing.com *.facebook.net *.googletagmanager.com *.vimeocdn.com 'unsafe-inline' 'unsafe-eval'; style-src 'self' www.westdean.ac.uk assets.westdean.ac.uk/ d10lpsik1i8c69.cloudfront.net services.postcodeanywhere.co.uk 'unsafe-inline'; report-uri https://o74830.ingest.us.sentry.io/api/215515/security/?sentry_key=610a8846728c479cb10b52482e41c8cc; report-to csp-endpoint 2 object-src 'none'; script-src * 'report-sample' 'unsafe-inline' 'unsafe-eval'; style-src * 'report-sample' 'unsafe-inline'; webrtc 'block'; worker-src 'self'; base-uri 'self'; form-action 'self'; frame-ancestors 'self' 2 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com maxcdn.bootstrapcdn.com instantcredit.net test.instantcredit.net *.klarnacdn.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de www.paycomet.com api.paycomet.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de www.paycomet.com api.paycomet.com instantcredit.net test.instantcredit.net sandbox.sequracdn.com live.sequracdn.com sandbox.sequrapi.com live.sequrapi.com *.klarna.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src data: *.assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.payments-amazon.com *.salesmanago.pl *.salesmanago.es *.salesmanago.com https://images.unsplash.com *.doubleclick.net analytics.google.com *.cloudfront.net static-eu.payments-amazon.com assets.braintreegateway.com *.instantcredit.net instantcredit.net test.instantcredit.net sandbox.sequracdn.com live.sequracdn.com sandbox.sequrapi.com live.sequrapi.com *.sooqr.com *.spotlersearch.com *.klarna.com *.klarnaevt.com *.klarnacdn.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src *.assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.salesmanago.pl *.salesmanago.es *.salesmanago.com dpm.demdex.net cm.everesttech.net widgets.magentocommerce.com *.doubleclick.net maps.googleapis.com *.ftcdn.net *.behance.net *.paypal.com *.gstatic.com validator.swagger.io *.cloudfront.net *.ssl-images-amazon.com *.media-amazon.com static-eu.payments-amazon.com assets.braintreegateway.com *.instantcredit.net www.paycomet.com api.paycomet.com instantcredit.net test.instantcredit.net code.jquery.com sandbox.sequracdn.com live.sequracdn.com sandbox.sequrapi.com live.sequrapi.com *.sooqr.com *.spotlersearch.com spotlersearchanalytics.com *.klarna.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com js.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com cdn.jsdelivr.net maxcdn.bootstrapcdn.com instantcredit.net test.instantcredit.net *.sooqr.com *.spotlersearch.com *.klarnacdn.net assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.salesmanago.pl *.salesmanago.es *.salesmanago.com *.spotlersearch.com maps.googleapis.com instantcredit.net *.instantcredit.net sandbox.sequracdn.com live.sequracdn.com sandbox.sequrapi.com live.sequrapi.com *.sooqr.com *.klarnaevt.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.klarna.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.salesmanago.pl *.salesmanago.es *.salesmanago.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com 'self' data: maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.authorize.net *.twitter.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.authorize.net 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com *.addthis.com *.facebook.com *.twitter.com *.authorize.net www.youtube.com accounts.google.com *.iubenda.com cdn-quick-ar.threedy.ai quick-ar.threedy.ai td.doubleclick.net www.googletagmanager.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.addthisedge.com *.twitter.com *.hsforms.net *.hsforms.com 'self' data: cdn.ywxi.net seal.networksolutions.com ssl.gstatic.com syndication.twitter.com *.stats.paypal.com *.cloudmaestro.com *.twimg.com maps.gstatic.com maps.googleapis.com seal-santabarbara.bbb.org *.google.com csi.gstatic.com fonts.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com commerce-payments-sdk.adobe.io www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.addthis.com *.moatads.com *.addthisedge.com *.facebook.net *.twitter.com *.authorize.net *.hsforms.net *.hsforms.com *.gstatic.com diffuser-cdn.app-us1.com/ prism.app-us1.com trackcmp.net seal-santabarbara.bbb.org platform.twitter.com apis.google.com seal.networksolutions.com www.google.com www.gstatic.com *.iubenda.com *.paypal.com *.twimg.com maps.googleapis.com https://js-agent.newrelic.com https://bam.nr-data.net https://bam-cell.nr-data.net cdn-quick-ar.threedy.ai acsbapp.com cdn.iubenda.com *.googletagmanager.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com *.googleapis.com *.gstatic.com maxcdn.bootstrapcdn.com *.twitter.com *.twimg.com www.googletagmanager.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.googleadservices.com www.google-analytics.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.authorize.net t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com *.iubenda.com *.facebook.com maps.googleapis.com https://js-agent.newrelic.com https://bam.nr-data.net https://bam-cell.nr-data.net quick-ar.threedy.ai *.acsbapp.com *.doubleclick.net stats.g.doubleclick.net 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://ab6dd833-5ccc-470b-a6cb-3bca3080bb2f.sansec.watch/; report-to report-endpoint; 2 script-src-elem assets.adobedtm.com *.cardinalcommerce.com local.behangwebshopm2.nl; font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.bootstrapcdn.com data: *.fontawesome.com *.cloudflare.com fonts.googleapis.com *.googleapis.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com 'self' 'unsafe-inline'; frame-ancestors *.multisafepay.com https://pay.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.hotjar.com *.criteo.com https://consentcsn.cookiebot.com *.multisafepay.com https://pay.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.wesupply.xyz https://wesupplylabs.com *.weltpixel.com *.googletagmanager.com *.doubleclick.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io www.behangwebshop.nl *.cloudfront.net magefan.com cm.magefan.com https://firebasestorage.googleapis.com *.multisafepay.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.facebook.com *.reddit.com *.google-analytics.com *.googletagmanager.com *.doubleclick.net *.google.com *.bing.com *.clarity.ms *.cookiebot.com www.google.ae www.google.al www.google.am www.google.at www.google.az www.google.ba www.google.be www.google.bg www.google.bs www.google.by www.google.ca www.google.ch www.google.cl www.google.co.ao www.google.co.cr www.google.co.id www.google.co.il www.google.co.in www.google.co.jp www.google.co.ke www.google.co.kr www.google.co.ma www.google.com.ar www.google.com.au www.google.com.bd www.google.com.bh www.google.com.bo www.google.com.br www.google.com.co www.google.com.cy www.google.com.do www.google.com.ec www.google.com.eg www.google.com.gi www.google.com.gt www.google.com.hk www.google.com.jm www.google.com.kh www.google.com.kw www.google.com.lb www.google.com.ly www.google.com.mm www.google.com.mt www.google.com.mx www.google.com.my www.google.com.ng www.google.com.np www.google.com.om www.google.com.pa www.google.com.pe www.google.com.ph www.google.com.pk www.google.com.pr www.google.com.qa www.google.com.sa www.google.com.sg www.google.com.sv www.google.com.tj www.google.com.tr www.google.com.tw www.google.com.ua www.google.com.vn www.google.co.nz www.google.co.th www.google.co.uk www.google.co.uz www.google.co.ve www.google.co.za www.google.co.zw www.google.cz www.google.de www.google.dk www.google.ee www.google.es www.google.fi www.google.fr www.google.ge www.google.gr www.google.hn www.google.hr www.google.hu www.google.ie www.google.im www.google.iq www.google.is www.google.it www.google.je www.google.jo www.google.kg www.google.kz www.google.la www.google.li www.google.lk www.google.lt www.google.lu www.google.lv www.google.md www.google.me www.google.mg www.google.mk www.google.mn www.google.mu www.google.nl www.google.no www.google.pl www.google.pt www.google.ro www.google.rs www.google.ru www.google.se www.google.si www.google.sk www.google.sn www.google.sr www.google.tn *.googlesyndication.com data: 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; script-src assets.adobedtm.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com widget.thuiswinkel.org *.hotjar.com *.criteo.net *.criteo.com api.widget.trengo.eu static.widget.trengo.eu *.trustpilot.com bam-cell.nr-data.net vanerkel.zendesk.com static.zdassets.com chimpstatic.com *.cardinalcommerce.com *.authorize.net *.bing.com *.doubleclick.net https://*.cookiebot.eu *.fontawesome.com *.googleapis.com *.gstatic.com *.avada.io *.multisafepay.com https://pay.google.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.cloudflare.com *.googletagmanager.com *.googleadservices.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com unpkg.com *.clarity.ms *.cloudflareinsights.com *.cookiebot.com *.googlesyndication.com *.zopim.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; style-src *.adobe.com fonts.googleapis.com *.bootstrapcdn.com *.fontawesome.com *.thuiswinkel-cdn.org *.googleapis.com https://fonts.bunny.net *.multisafepay.com assets.braintreegateway.com *.tagmanager.google.com *.googletagmanager.com *.gstatic.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com static.widget.trengo.eu static.zdassets.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com api.widget.trengo.eu *.thuiswinkel-cdn.org *.hotjar.com bam-cell.nr-data.net wss://ws17.hotjar.com *.google-analytics.com vanerkel.zendesk.com *.zdassets.com *.doubleclick.net *.zopim.com wss://widget-mediator.zopim.com https://*.cookiebot.eu https://get.geojs.io *.avada.io *.multisafepay.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.run.app *.bing.com *.clarity.ms *.cookiebot.com www.google.ae www.google.al www.google.am www.google.at www.google.ba www.google.be www.google.bg www.google.bs www.google.by www.google.ca www.google.ch www.google.cl www.google.co.cr www.google.co.id www.google.co.il www.google.co.in www.google.co.jp www.google.co.kr www.google.co.ma www.google.com.ar www.google.com.au www.google.com.bd www.google.com.bh www.google.com.br www.google.com.co www.google.com.cy www.google.com.do www.google.com.ec www.google.com.eg www.google.com.gt www.google.com.hk www.google.com.jm www.google.com.kw www.google.com.lb www.google.com.mt www.google.com.mx www.google.com.my www.google.com.na www.google.com.ng www.google.com.om www.google.com.pa www.google.com.pe www.google.com.ph www.google.com.pk www.google.com.pr www.google.com.qa www.google.com.sa www.google.com.sg www.google.com.tj www.google.com.tr www.google.com.tw www.google.com.ua www.google.com.vn www.google.co.nz www.google.co.th www.google.co.uk www.google.co.ve www.google.co.za www.google.co.zw www.google.cz www.google.de www.google.dk www.google.ee www.google.es www.google.fi www.google.fr www.google.ge www.google.gr www.google.hn www.google.hr www.google.hu www.google.ie www.google.iq www.google.is www.google.it www.google.je www.google.jo www.google.kz www.google.lt www.google.lu www.google.lv www.google.md www.google.me www.google.mg www.google.mn www.google.nl www.google.no www.google.pl www.google.pt www.google.ro www.google.rs www.google.ru www.google.se www.google.si www.google.sk www.google.sr *.googlesyndication.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://70340d24-235b-4990-9e78-f23006e4ffdf.sansec.watch/; report-to report-endpoint; 2 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://*.quadpay.com https://*.zip.co maxcdn.bootstrapcdn.com https://fonts.gstatic.com *.lewandmassager.com *.bvibe.com use.fontawesome.com *.yotpo.com *.googleapis.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.yotpo.com swellrewards.com *.swellrewards.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net https://www.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * https://bid.g.doubleclick.net *.lewandmassager.com *.bvibe.com https://www.googletagmanager.com/ *.yotpo.com swellrewards.com *.swellrewards.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://*.quadpay.com https://*.zip.co www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com shareasale.com *.bvibe.com *.lewandmassager.com *.yotpo.com swellrewards.com *.swellrewards.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com chimpstatic.com downloads.mailchimp.com *.list-manage.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.kaptcha.com https://*.quadpay.com https://*.zip.co *.avada.io js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://www.googletagmanager.com https://googleads.g.doubleclick.net https://www.gstatic.com https://www.google.com https://cdnjs.cloudflare.com *.lewandmassager.com *.bvibe.com *.impactcdn.com https://maps.googleapis.com https://maps.gstatic.com *.yotpo.com swellrewards.com *.swellrewards.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com downloads.mailchimp.com https://static.klaviyo.com maxcdn.bootstrapcdn.com assets.braintreegateway.com https://fonts.gstatic.com https://fonts.googleapis.com *.lewandmassager.com *.bvibe.com *.yotpo.com swellrewards.com *.swellrewards.com *.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.kaptcha.com https://*.quadpay.com https://*.zip.co api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com https://bvibe.pxf.io/ https://lewand-massager.sjv.io/ *.yotpo.com swellrewards.com *.swellrewards.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 default-src 'self'; font-src 'self'; img-src 'self'; script-src 'self'; style-src 'self'; frame-ancestors 'self'; report-uri https://lleung.uriports.com/reports/report; report-to default 2 font-src https://js.klevu.com *.googleapis.com *.hotjar.com dhv2ziothpgrr.cloudfront.net *.klevu.com *.ksearchnet.com use.fontawesome.com maxcdn.bootstrapcdn.com fonts.gstatic.com *.yotpo.com *.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * https://plumrocket.com *.ometria.com *.yotpo.com swellrewards.com *.swellrewards.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com account.fetchify.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * https://plumrocket.com *.hotjar.com https://9957200.fls.doubleclick.net https://danv01ao0kdr2.cloudfront.net https://dj3zaulksz6yg.cloudfront.net *.brandlock.io *.braintreegateway.com *.klarna.com https://accounts.google.com *.mention-me.com *.yotpo.com swellrewards.com *.swellrewards.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com https://www.incontinencechoice.co.uk https://prod.choiceadmin.co.uk https://staging.choiceadmin.co.uk https://admin.vivactive.com https://trk.ometria.com *.brandlock.io https://www.google.com https://bat.bing.com https://pixel.quantserve.com https://www.facebook.com *.googleapis.com *.klarna.com *.klarnaevt.com *.klarnacdn.net https://s3-eu-west-1.amazonaws.com dhv2ziothpgrr.cloudfront.net *.klevu.com *.ksearchnet.com *.yotpo.com swellrewards.com *.swellrewards.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://rum.hlx.page js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://cdn.ometria.com cdnjs.cloudflare.com https://js.klevu.com/ https://bat.bing.com https://secure.quantserve.com https://www.gstatic.com https://connect.facebook.net https://dj3zaulksz6yg.cloudfront.net *.brandlock.io https://cdn-ukwest.onetrust.com https://geolocation.onetrust.com https://songbirdstag.cardinalcommerce.com https://www.googleoptimize.com https://cdn.oribi.io https://app.factors.ai https://rules.quantcount.com https://googleads.g.doubleclick.net https://www.clarity.ms https://www.clarity.ms/tag/ *.googleapis.com https://www.googletagmanager.com/gtag/js *.klarna.com *.klarnacdn.net https://accounts.google.com dhv2ziothpgrr.cloudfront.net *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com d18eg7dreypte5.cloudfront.net https://tag.rmp.rakuten.com *.klevu.com *.ksearchnet.com *.mention-me.com *.yotpo.com swellrewards.com *.swellrewards.com https://js.klevu.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com cc-cdn.com assets.braintreegateway.com *.googleapis.com *.hotjar.com https://accounts.google.com https://www.gstatic.com dhv2ziothpgrr.cloudfront.net *.klevu.com *.ksearchnet.com *.yotpo.com swellrewards.com *.swellrewards.com fonts.googleapis.com maxcdn.bootstrapcdn.com https://statsjs.klevu.com https://js.klevu.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.craftyclicks.co.uk pcls1.craftyclicks.co.uk api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com https://payments.sandbox.braintree-api.com https://api.sandbox.braintreegateway.com https://origin-analytics-sand.sandbox.braintree-api.com/ https://danv01ao0kdr2.cloudfront.net *.brandlock.io https://cdn-ukwest.onetrust.com https://privacyportal-uk.onetrust.com *.google-analytics.com https://stats.g.doubleclick.net https://www.paypal.com https://geolocation.onetrust.com *.hotjar.com *.hotjar.io wss://*.hotjar.com https://api.factors.ai https://b.clarity.ms https://y.clarity.ms/collect *.googleapis.com *.klarnaevt.com https://accounts.google.com dhv2ziothpgrr.cloudfront.net *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com *.klevu.com *.ksearchnet.com *.mention-me.com *.ometria.com *.yotpo.com swellrewards.com *.swellrewards.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://f720cf68-df7d-4a7b-a5e9-4e537ae99361.sansec.watch/; report-to report-endpoint; 2 font-src data: cdn.jsdelivr.net *.googleapis.com *.gstatic.com *.tawk.to https://webchat.saysimple.io/ fonts.googleapis.com fonts.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.adyen.com *.facebook.com *.googlesyndication.com *.tiktok.com 'self' 'unsafe-inline'; frame-ancestors *.multisafepay.com https://pay.google.com www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.adyen.com *.multisafepay.com https://pay.google.com https://player.vimeo.com/ *.google.com https://googleads.g.doubleclick.net/ https://www.google.nl/ https://ct.pinterest.com/ consentcdn.cookiebot.com consentcdn.cookiebot.eu www.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.adyen.com *.multisafepay.com *.doubleclick.net 'self' data: *.googleapis.com *.gstatic.com cdn.jsdelivr.net *.tawk.to tawk.link *.facebook.com *.gravatar.com https://www.google.nl/ https://imgsct.cookiebot.com/1.gif https://ct.pinterest.com/v3/* https://images.unsplash.com maps.googleapis.com maps.gstatic.com *.google.com *.google.bg *.facebook.net *.googletagmanager.com *.googlesyndication.com *.roeye.com *.tiktok.com imgsct.cookiebot.com imgsct.cookiebot.eu ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com https://vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.adyen.com *.multisafepay.com https://pay.google.com *.googleapis.com *.gstatic.com *.jsdelivr.net *.tawk.to player.vimeo.com http://player.vimeo.com/api/player.js chimpstatic.com https://connect.facebook.net/ https://webchat.saysimple.io/ *.smooch.io https://s.pinimg.com/ https://ct.pinterest.com/ consent.cookiebot.com consent.cookiebot.eu https://s.pinimg.com/ct/lib/main.742e9fad.js https://s.pinimg.com/ct/core.js https://ct.pinterest.com/static/ct/token_create.js https://maps.googleapis.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com https://cdn.jsdelivr.net/npm/@ryangjchandler/spruce@2.x.x/dist/spruce.umd.js www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.googlesyndication.com *.tiktok.com downloads.mailchimp.com *.list-manage.com https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.multisafepay.com *.googleapis.com cdn.jsdelivr.net *.tawk.to https://webchat.saysimple.io/ fonts.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com *.tiktok.com downloads.mailchimp.com maxcdn.bootstrapcdn.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net https://vimeo.com/api/ geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adyen.com *.multisafepay.com 'self' data: *.google-analytics.com *.googleapis.com *.googletagmanager.com *.gstatic.com/ *.paypal.com *.tawk.to 'self' ws: *.doubleclick.net https://webchat.saysimple.io/ *.smooch.io *.gravatar.com https://ct.pinterest.com/ consent.cookiebot.com consent.cookiebot.eu https://ct.pinterest.com/* https://ct.pinterest.com/v3/* https://ct.pinterest.com/user/* https://maps.googleapis.com https://player.vimeo.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.facebook.com *.facebook.net *.google.com *.googlesyndication.com *.tiktok.com consentcdn.cookiebot.com consentcdn.cookiebot.eu 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 font-src *.googleapis.com *.gstatic.com data: maxcdn.bootstrapcdn.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cenpos.net *.cenpos.com *.google.com *.gstatic.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.google.com *.cenpos.net *.cenpos.com *.google.com *.gstatic.com *.cardinalcommerce.com *.google.com/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.gstatic.com *.googleapis.com www.facebook.com *.cenpos.net *.cenpos.com https://www.magezon.com *.hubspot.com *.hsforms.com *.linkedin.com *.adsymptotic.com *.otcindustrial.com *.google.com *.googleadservices.com *.google-analytics.com *.googletagmanager.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.hsforms.net 'self' data: data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://rum.hlx.page *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ ws.zoominfo.com secure.venture-365-inspired.com js.hubspot.com cdn.callrail.com js.usemessages.com *.cenpos.com *.cenpos.net *.google.com *.cardinalcommerce.com *.termly.io *.fullstory.com *.licdn.com *.doubleclick.net *.listenlayer.com *.hs-scripts.com *.hscollectedforms.net *.hs-analytics.net *.hsadspixel.net *.hs-banner.com connect.facebook.net *.googletagmanager.com *.googleadservices.com *.google-analytics.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.hsforms.net *.hsforms.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.googleapis.com ws.zoominfo.com idx.liadm.com px.ads.linkedin.com forms.hscollectedforms.net static.listenlayer.com pagead2.googlesyndication.com googleads.g.doubleclick.net js.hs-banner.com *.fullstory.com *.termly.io *.linkedin.oribi.io *.analytics.google.com *.hubspot.com *.hubapi.com *.google-analytics.com *.googletagmanager.com stats.g.doubleclick.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com t.elasticsuite.io *.hsforms.net *.hsforms.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 upgrade-insecure-requests; report-to https://myrgroup.com/csp-report.php;; report-uri https://myrgroup.com/csp-report.php;; 2 frame-ancestors 'self' *.qualtrics.com *.my.salesforce.com *.visualforce.com *.visual.force.com *.lightning.force.com; report-uri https://sjc1.qualtrics.com/csp-report 2 font-src *.fontawesome.com maxcdn.bootstrapcdn.com *.gstatic.com *.tawk.to data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.google.com https://www.googletagmanager.com/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.sandbox.paypal.com *.paypalobjects.com paypal.com www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ magefan.com cm.magefan.com *.disqus.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.feefo.com www.google.co.uk *.tawk.to *.sandbox.paypal.com *.paypalobjects.com paypal.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.google.com/recaptcha/ www.gstatic.com/recaptcha/ chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ *.disqus.com player.vimeo.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com cdn.noibu.com fullstory.com www.fullstory.com *.hotjar.com embed.tawk.to cdn.jsdelivr.net connect.facebook.net *.feefo.com www.roomvo.com www.xtento.com cdn.xtento.com https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com downloads.mailchimp.com *.fontawesome.com maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com *.tawk.to *.feefo.com *.sandbox.paypal.com *.paypalobjects.com *.paypal.com paypal.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com form-assets.mailchimp.com *.intuit.com *.amazonaws.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com www.roomvo.com *.feefo.com *.tawk.to wss://*.tawk.to *.sandbox.paypal.com *.paypalobjects.com paypal.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 default-src 'self'; script-src 'self' 'unsafe-eval' 'unsafe-inline' https://assets.adobedtm.com https://customer.cludo.com https://ds-aksb-a.akamaihd.net https://help.cybonline.co.uk https://googleservices.com https://www.googleadservices.com https://googleads.g.doubleclick.net https://maps.googleapis.com https://www.google.com https://www.googletagmanager.com https://www.google.com https://www.gstatic.com https://fusiontables.google.com https://connect.facebook.net https://www.youtube.com https://s.ytimg.com https://cse.google.com https://www.advanced-web-analytics.com https://platform.twitter.com https://casper.tsbc.com https://healthcheck252.tsbc.com https://t.contentsquare.net https://contentsquare.com https://webapp.woosmap.com https://dispawsusva.inmoment.com https://intercept-client.inmoment.com https://*.evidon.com; style-src 'self' 'unsafe-inline' https://www.gstatic.com https://fonts.googleapis.com https://www.google.com https://platform.twitter.com https://casper.tsbc.com https://healthcheck252.tsbc.com; img-src 'self' https: data: ; font-src 'self' https: ; connect-src 'self' https://clydesdalebank.tt.omtrdc.net https://clydesdalebank.d3.sc.omtrdc.net https://dpm.demdex.net https://ds-aksb-a.akamaihd.net https://api-eu1.cludo.com https://api.cludo.com https://www.google.com https://www.facebook.com https://www.twitter.com https://www.linkedin.com https://www.youtube.com https://my.cybservices.co.uk https://adservice.google.com https://casper.tsbc.com https://*.contentsquare.net https://api.woosmap.com https://webapp-conf.woosmap.com https://cybg.egain.cloud https://dispawsusva.inmoment.com https://ad.doubleclick.net https://maps.googleapis.com https://*.evidon.com; media-src 'self'; object-src 'self'; worker-src 'self' blob:; child-src 'self' blob:; frame-src 'self' https://*.cybusinessonline.co.uk https://*.cbonline.co.uk https://*.ybonline.co.uk https://*.cybonline.co.uk https://clydesdalebankplc.demdex.net https://*.fls.doubleclick.net https://www.youtube.com https://bid.g.doubleclick.net https://www.google.com https://assets.adobedtm.com https://player.vimeo.com https://platform.twitter.com https://syndication.twitter.com https://www.youtube-nocookie.com https://healthcheck252.tsbc.com https://www.inmoment.com https://td.doubleclick.net; frame-ancestors 'self' https://*.cybusinessonline.co.uk https://*.cbonline.co.uk https://*.ybonline.co.uk https://*.cybonline.co.uk; report-uri https://cyburi.report-uri.com/r/t/csp/reportOnly; 2 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com fonts.googleapis.com *.googleapis.com data: https://www.googletagmanager.com *.fontawesome.com https://fonts.bunny.net https://widgets.trustedshops.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.multisafepay.com https://pay.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.sharethis.com https://static.addtoany.com/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.google.com *.multisafepay.com https://pay.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.sharethis.com https://images.unsplash.com maps.googleapis.com maps.gstatic.com *.googleapis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com magefan.com cm.magefan.com https://firebasestorage.googleapis.com *.multisafepay.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com https://www.google.co.in https://widget.paazl.com https://integrations.etrusted.com https://maps.googleapis.com https://www.sbsupply.nl https://widgets.trustedshops.com https://widgets-qa.trustedshops.com *.etrusted.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.sharethis.com https://maps.googleapis.com https://static.addtoany.com/ maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.googleapis.com *.gstatic.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com tagmanager.google.com https://www.googletagmanager.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ chimpstatic.com downloads.mailchimp.com *.list-manage.com *.crwdcntrl.net *.avada.io *.shopify.com *.multisafepay.com https://pay.google.com https://widget-acc.paazl.com https://api-acc.paazl.com/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com http://maps.googleapis.com https://api.paazl.com https://widgets.trustedshops.com http://widgets.trustedshops.com https://www.googleadservices.com/ https://bootstrap.smartsuppchat.com https://www.smartsuppchat.com https://consent.studio https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.etrusted.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.sharethis.com https://www.googletagmanager.com tagmanager.google.com *.googleapis.com downloads.mailchimp.com *.fontawesome.com https://fonts.bunny.net *.multisafepay.com https://widget-acc.paazl.com https://api-acc.paazl.com/ assets.braintreegateway.com https://integrations.etrusted.com https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.etrusted.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.sharethis.com https://maps.googleapis.com https://player.vimeo.com https://stats.addtoany.com/menu maps.googleapis.com maps.gstatic.com fonts.googleapis.com http://maps.googleapis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://www.google-analytics.com https://*.google-analytics.com https://*.analytics.google.com fcmregistrations.googleapis.com firebaseinstallations.googleapis.com *.crwdcntrl.net https://get.geojs.io *.avada.io *.multisafepay.com https://widget-acc.paazl.com https://api-acc.paazl.com/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com https://pagead2.googlesyndication.com https://api.paazl.com https://widgets.trustedshops.com https://bootstrap.smartsuppchat.com https://consent.studio https://widget.paazl.com *.trustedshops.com *.etrusted.com https://integrations.etrusted.site 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 font-src www.paypalobjects.com *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com maxcdn.bootstrapcdn.com *.fontawesome.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com *.googlesyndication.com *.tiktok.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ www.google.com *.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com *.innoship.ro https://*.sameday.ro *.addthis.com www.xtento.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://images.unsplash.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.gstatic.com *.googlesyndication.com *.roeye.com *.tiktok.com *.tile.openstreetmap.org *.openstreetmap.org magefan.com cm.magefan.com *.disqus.com https://firebasestorage.googleapis.com www.xtento.com cdn.xtento.com https://oqtagonmedia-1224e.kxcdn.com https://www.google.ro/ads/ga-audiences https://region1.analytics.google.com/ https://airsoftcluj-1224e.kxcdn.com/ https://airsoftbucuresti-1224e.kxcdn.com https://oqtagon-1224e.kxcdn.com https://www.oqtagon.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://maps.googleapis.com https://player.vimeo.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com https://cdn.jsdelivr.net *.tiktok.com https://*.sameday.ro *.disqus.com *.addthis.com https://z.moatads.com https://v1.addthisedge.com *.avada.io *.shopify.com www.xtento.com cdn.xtento.com https://airsoftbucuresti-1224e.kxcdn.com https://oqtagon-1224e.kxcdn.com https://airsoftcluj-1224e.kxcdn.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com *.tiktok.com https://*.sameday.ro maxcdn.bootstrapcdn.com https://cdn.jsdelivr.net *.fontawesome.com https://fonts.bunny.net https://oqtagonmedia-1224e.kxcdn.com https://airsoftcluj-1224e.kxcdn.com/ https://airsoftbucuresti-1224e.kxcdn.com https://oqtagon-1224e.kxcdn.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://maps.googleapis.com https://player.vimeo.com *.facebook.com *.facebook.net *.google.com *.doubleclick.net *.googlesyndication.com *.tiktok.com https://get.geojs.io *.avada.io https://region1.analytics.google.com/g/collect 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 font-src *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com https://static.dhlecommerce.nl https://fonts.gstatic.com fonts.gstatic.com fonts.googleapis.com https://widgets.trustedshops.com *.afzuigkapfilterwinkel.nl *.allspares.fr *.cdnfonts.com *.cloudflare.com *.filtre-de-hotte.fr *.flaticon.com *.fontawesome.com *.hotjar.com *.hsappstatic.net *.slant.co *.userway.org *.varify.io *.waterfilterwinkel.com data: 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com *.googlesyndication.com *.afzuigkapfilterwinkel.nl *.allspares.fr *.filtre-de-hotte.fr 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; frame-ancestors *.multisafepay.com https://pay.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ https://*.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com https://*.dpdconnect.nl *.newrelic.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com *.multisafepay.com https://pay.google.com *.allspares.fr *.allspares.nl *.allspares.de *.dunstabzugshaube-filter.de *.filtricasafacile.it *.filtraciondomestica.es *.filtre-de-hotte.fr *.afzuigkapfilterwinkel.nl *.waterfilterwinkel.com *.wasserfilterspezialist.de *.paypal.com *.paypalobjects.com *.allspares.com *.bing.com *.cookiebot.com *.criteo.com *.criteo.net google.co.th *.googletagmanager.com *.hotjar.com *.opendns.com *.robinhq.com server-side-tagging-hgb22rqeua-uc.a.run.app *.userway.org *.varify.io *.yahoo.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io 'self' data: https://*.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.gstatic.com *.googlesyndication.com https://maps.googleapis.com https://maps.gstatic.com *.trackedlink.net https://*.gstatic.com https://*.googleapis.com https://*.googleusercontent.com *.openstreetmap.org maps.googleapis.com maps.gstatic.com *.multisafepay.com https://api.mapbox.com moogento.com *.moogento.com *.paypal.com *.paypalobjects.com *.hsforms.net *.hsforms.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com *.1rx.io *.3lift.com *.adnxs.com *.adsrvr.org *.afzuigkapfilterwinkel.nl *.agkn.com *.allspares.de *.allspares.fr *.allspares.nl *.baidu.com *.bidswitch.net *.bing.com *.bing.net *.casalemedia.com *.cookiebot.com *.criteo.com *.criteo.net *.crwdcntrl.net *.dunstabzugshaube-filter.de *.etrusted.com *.filtre-de-hotte.fr *.googleadservices.com *.google-analytics.com www.google.ad www.google.ae www.google.al www.google.am www.google.as www.google.at www.google.az www.google.ba www.google.be www.google.bf www.google.bi www.google.bj www.google.bs www.google.by www.google.ca www.google.cd www.google.cg www.google.ch www.google.ci www.google.cl www.google.cm www.google.co.ao www.google.co.cr www.google.co.id www.google.co.il www.google.co.in www.google.co.jp www.google.co.ke www.google.co.kr www.google.co.ma www.google.com.ar www.google.com.au www.google.com.bd www.google.com.bh www.google.com.bn www.google.com.bo www.google.com.br www.google.com.co www.google.com.cy www.google.com.do www.google.com.ec www.google.com.eg www.google.com.et www.google.com.fj www.google.com.gh www.google.com.gi www.google.com.gt www.google.com.hk www.google.com.jm www.google.com.kh www.google.com.kw www.google.com.lb www.google.com.ly www.google.com.mm www.google.com.mt www.google.com.mx www.google.com.my www.google.com.na www.google.com.ng www.google.com.ni www.google.com.np www.google.com.om www.google.com.pa www.google.com.pe www.google.com.ph www.google.com.pk www.google.com.pr www.google.com.py www.google.com.qa www.google.com.sa www.google.com.sg www.google.com.sl www.google.com.sv www.google.com.tj www.google.com.tr www.google.com.tw www.google.com.ua www.google.com.uy www.google.com.vn www.google.co.mz www.google.co.nz www.google.co.th www.google.co.tz www.google.co.ug www.google.co.uk www.google.co.uz www.google.co.ve www.google.co.za www.google.cv www.google.cz www.google.de www.google.dj www.google.dk www.google.dm www.google.dz www.google.ee www.google.es www.google.fi www.google.fr www.google.ga www.google.ge www.google.gl www.google.gm www.google.gr www.google.gy www.google.hr www.google.ht www.google.hu www.google.ie www.google.im www.google.iq www.google.is www.google.it www.google.je www.google.jo www.google.kg www.google.kz www.google.li www.google.lk www.google.lt www.google.lu www.google.lv www.google.md www.google.me www.google.mg www.google.mk www.google.ml www.google.mn www.google.mu www.google.mv www.google.mw www.google.nl www.google.no www.google.pl www.google.ps www.google.pt www.google.ro www.google.rs www.google.ru www.google.rw www.google.sc www.google.se www.google.si www.google.sk www.google.sm www.google.sn www.google.so www.google.sr www.google.tg www.google.tn www.google.tt google.com *.google.com *.hsappstatic.net *.hubspot.com id5-sync.com *.kelkoogroup.net *.liadm.com *.media.net *.outbrain.com *.pubmatic.com robincontentdesktop.blob.core.windows.net *.rubiconproject.com *.smartadserver.com *.taboola.com *.teads.tv *.trackedweb.net *.tremorhub.com *.trustedshops.com *.usercentrics.eu *.userway.org *.visualwebsiteoptimizer.com *.wasserfilterspezialist.de *.waterfilterwinkel.com *.webflow.com *.yahoo.com yastatic.net data: 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com https://static.dhlecommerce.nl https://maps.googleapis.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com https://*.dpdconnect.nl https://*.gstatic.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.multisafepay.com https://pay.google.com l.moogento.com *.hsforms.net *.hsforms.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.afzuigkapfilterwinkel.nl *.allspares.com *.allspares.fr az416426.vo.msecnd.net *.beslist.nl *.bing.com *.cloudflare.com *.cloudflareinsights.com *.cookiebot.com *.criteo.com *.criteo.net d5yoctgpv4cpx.cloudfront.net *.etrusted.com *.filtre-de-hotte.fr *.googleadservices.com *.hotjar.com *.hs-analytics.net *.hs-banner.com *.hs-scripts.com *.hubspot.com *.jquery.com *.kk-resources.com robincontentdesktop.blob.core.windows.net *.robinhq.com *.trengo.eu *.trustedshops.com *.usercentrics.eu *.userway.org *.varify.io *.waterfilterwinkel.com *.webeyez.com yastatic.net 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; style-src *.adobe.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com https://static.dhlecommerce.nl https://maps.googleapis.com https://fonts.googleapis.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com https://hcaptcha.com https://*.hcaptcha.com fonts.googleapis.com *.multisafepay.com https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.afzuigkapfilterwinkel.nl *.allspares.fr *.etrusted.com *.filtre-de-hotte.fr *.fontawesome.com *.trustedshops.com *.userway.org *.varify.io *.waterfilterwinkel.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.bing.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.google-analytics.com *.facebook.com *.facebook.net https://*.google.com *.doubleclick.net *.googlesyndication.com https://api-gw.dhlparcel.nl https://static.dhlecommerce.nl https://maps.googleapis.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com https://ipinfo.io https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com maps.googleapis.com *.multisafepay.com autocomplete2.postdirekt.de ws.hotjar.com mpc-prod-17-s6uit34pua-wl.a.run.app *.paypal.com *.paypalobjects.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.trustedshops.com *.etrusted.com https://integrations.etrusted.site *.afzuigkapfilterwinkel.nl *.allspares.de *.allspares.fr *.allspares.nl *.baidu.com *.beslist.nl *.bing.com *.bing.net *.cookiebot.com *.criteo.com *.dunstabzugshaube-filter.de *.filtre-de-hotte.fr *.googleadservices.com www.google.ad www.google.ae www.google.al www.google.am www.google.at www.google.az www.google.ba www.google.be www.google.bf www.google.bg www.google.bi www.google.bj www.google.by www.google.ca www.google.cd www.google.cg www.google.ch www.google.ci www.google.cl www.google.cm www.google.co.id www.google.co.il www.google.co.in www.google.co.jp www.google.co.ke www.google.co.kr www.google.co.ma www.google.com.ar www.google.com.au www.google.com.bd www.google.com.bh www.google.com.bn www.google.com.bo www.google.com.br www.google.com.co www.google.com.cy www.google.com.do www.google.com.eg www.google.com.gi www.google.com.gt www.google.com.hk www.google.com.kw www.google.com.lb www.google.com.mt www.google.com.mx www.google.com.my www.google.com.na www.google.com.ng www.google.com.ni www.google.com.np www.google.com.om www.google.com.pa www.google.com.ph www.google.com.pk www.google.com.pr www.google.com.py www.google.com.qa www.google.com.sa www.google.com.sg www.google.com.tr www.google.com.tw www.google.com.ua www.google.com.uy www.google.com.vn www.google.co.nz www.google.co.th www.google.co.tz www.google.co.uk www.google.co.uz www.google.co.ve www.google.co.za www.google.cv www.google.cz www.google.de www.google.dk www.google.dz www.google.ee www.google.es www.google.fi www.google.fr www.google.ga www.google.ge www.google.gr www.google.hr www.google.hu www.google.ie www.google.iq www.google.is www.google.it www.google.kz www.google.li www.google.lk www.google.lt www.google.lu www.google.lv www.google.md www.google.me www.google.mg www.google.mk www.google.ml www.google.mu www.google.nl www.google.no www.google.pl www.google.ps www.google.pt www.google.ro www.google.rs www.google.ru www.google.se www.google.si www.google.sk www.google.sn www.google.sr www.google.tg www.google.tn google.com *.google.com *.hotjar.com *.hotjar.io *.hubspot.com *.jquery.com *.kelkoogroup.net localhost p2iqhncxyh.execute-api.eu-central-1.amazonaws.com *.robinhq.com *.samsung.com server-side-tagging-hgb22rqeua-uc.a.run.app *.trengo.eu *.usercentrics.eu *.userway.org *.varify.io *.visualstudio.com *.visualwebsiteoptimizer.com *.waterfilterwinkel.com *.webeyez.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri *.trustedshops.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; report-uri https://c6d02f62-c45e-4c56-876c-2102faf3fd5c.sansec.watch/; report-to report-endpoint; 2 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://*.contentsquare.net https://*.contentsquare.com; style-src 'self' 'unsafe-inline' https://*.contentsquare.net https://*.contentsquare.com; img-src 'self' data: https://*.contentsquare.net https://*.contentsquare.com; connect-src 'self' https://*.contentsquare.net https://*.contentsquare.com; font-src 'self' data: https://*.contentsquare.net https://*.contentsquare.com; frame-src 'self' https://*.contentsquare.net https://*.contentsquare.com; 2 script-src 'self' 'unsafe-inline' 'unsafe-eval' https://*.ioteams.com https://hm.baidu.com https://assets.growingio.com https://res.wx.qq.com; report-uri https://m.sre.videoteams.cn:8043/monitor/csp-report.htm 2 font-src fonts.gstatic.com use.typekit.net maxcdn.bootstrapcdn.com *.gstatic.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.adyen.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.adyen.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * www.youtube.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com p.typekit.net *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.adyen.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com 'self' data: data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com unpkg.com commerce.adobedtm.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net amcglobal.sc.omtrdc.net use.typekit.net commerce.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.adyen.com *.acp-magento.appspot.com *.akamaized.net *.instantsearchplus.com *.fastsimon.com fastsimon-grid.akamaized.net js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.google.com *.gstatic.com www.youtube.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com api.magento.com commerce.adobe.io commerce.adobedtm.com commerce.adobedc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com performance.typekit.net commerce.adobe.net *.adyen.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com t.elasticsuite.io *.google-analytics.com cdn.plyr.io noembed.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com data: https://static.lyra.com/static/ *.fontawesome.com 'self' data: *.cloudfront.net *.wistia.com *.hotjar.com *.hotjar.io snippet.maze.co data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com https://secure.lyra.com/vads-payment/ https://api.lyra.com/api-payment/ https://static.lyra.com/static/ http://info.soprema.fr info.soprema.fr *.soprema.fr *.soprema.nl *.soprema.com *.soprema.be *.soprema.ch *.soprema.co.uk *.soprema.de *.soprema.at *.soprema.se *.soprema.dk *.soprema.no *.soprema.ie *.soprema.es *.georgboerner.de *.soprasolar.com *.nesta.fr *.soprema.ca *.soprema.ae *.soprema.com.mx *.soprema.us *.convoy-supply.com *.furbishco.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com app.sarooma.de *.sopremauvalue.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com https://secure.lyra.com/vads-payment/ https://static.lyra.com/static/ *.bynder.com my.assets-library.com app.ideta.io checkout.sandbox.dev.clover.com checkout.clover.com copilotstudio.microsoft.com sopremap.wpenginepowered.com app.sarooma.de *.sopremauvalue.com *.soprema.fr *.soprema.nl *.soprema.com *.soprema.be *.soprema.ch *.soprema.co.uk *.soprema.de *.soprema.at *.soprema.se *.soprema.dk *.soprema.no *.soprema.ie *.soprema.es *.soprema.pt *.georgboerner.de *.soprasolar.com *.nesta.fr *.soprema.ca *.soprema.ae *.soprema.com.mx *.soprema.us *.convoy-supply.com *.furbishco.com s7.addthis.com *.hotjar.com *.hotjar.io fast.wistia.com fast.wistia.net fortress.maptive.com widget.getcody.ai ausschreiben.de *.calameo.com uvalue.nettt.nl websiteintegration.source.thenbs.com bimobject.com *.bimobject.com productsite.bimobject.com youtube.googleapis.com outlook.office365.com soprema.factorialhr.pt tel: *.soprema-cms.awstudio.website 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com maps.googleapis.com *.googleapis.com magefan.com cm.magefan.com https://secure.lyra.com/static/latest/images/type-carte/ https://static.lyra.com/static/ https://secure.lyra.com/vads-payment/ *.disqus.com https://img.youtube.com 'self' data: *.bynder.com my.assets-library.com *.cloudfront.net *.cloudinary.com checkout.sandbox.dev.clover.com checkout.clover.com *.soprema.fr *.soprema-eu.test *.soprema-na.test *.soprema.nl *.soprema.com *.soprema.be *.soprema.ch *.soprema.co.uk *.soprema.de *.soprema.at *.soprema.se *.soprema.dk *.soprema.no *.soprema.ie *.soprema.es *.georgboerner.de *.soprasolar.com *.nesta.fr *.soprema.ca *.soprema.ae *.soprema.com.mx *.soprema.us *.convoy-supply.com *.furbishco.com *.google.com *.google.fr *.google.ca *.googletagmanager.com *.g.doubleclick.net *.hotjar.com *.hotjar.io *.pardot.com *.linkedin.com *.facebook.com bat.bing.com *.wistia.com *.wistia.net embedwistia-a.akamaihd.net *.clarity.ms pagead2.googlesyndication.com *.teads.tv tags.srv.stackadapt.com snippet.maze.co data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com maps.googleapis.com developers.google.com https://rum.hlx.page *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ https://api.lyra.com/api-payment/ https://static.lyra.com/static/ *.disqus.com d8ejoa1fys2rk.cloudfront.net ucv.bynder.com checkout.sandbox.dev.clover.com checkout.clover.com www.ingenuityinsightful-52.com info.soprema.fr *.soprema.fr *.soprema.nl *.soprema.com *.soprema.be *.soprema.ch *.soprema.co.uk *.soprema.de *.soprema.at *.soprema.se *.soprema.dk *.soprema.no *.soprema.ie *.soprema.es *.georgboerner.de *.soprasolar.com *.nesta.fr *.soprema.ca *.soprema.ae *.soprema.com.mx *.soprema.us *.convoy-supply.com *.furbishco.com bam.nr-data.net js-agent.newrelic.com z.moatads.com v1.addthisedge.com m.addthis.com *.hotjar.com *.hotjar.io *.googletagmanager.com cdn.leadinfo.net cdn.jsdelivr.net *.pardot.com connect.facebook.net snap.licdn.com bat.bing.com *.wistia.com *.wistia.net src.litix.io secure.leadforensics.com *.clarity.ms *.teads.tv *.bugherd.com join.com *.join.com tags.srv.stackadapt.com srv.stackadapt.com east.srv.stackadapt.com uw.srv.stackadapt.com eu.srv.stackadapt.com qvdt3feo.com/ *.soprema-cms.awstudio.website snippet.maze.co 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://static.lyra.com/static/ *.fontawesome.com *.googleapis.com *.gstatic.com *.cloudfront.net cdn-images.mailchimp.com *.hotjar.com *.hotjar.io *.typekit.net fast.wistia.com *.googletagmanager.com tags.srv.stackadapt.com snippet.maze.co 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.soprema.fr *.soprema.nl *.soprema.com *.soprema.be *.soprema.ch *.soprema.co.uk *.soprema.de *.soprema.at *.soprema.se *.soprema.dk *.soprema.no *.soprema.ie *.soprema.es *.georgboerner.de *.soprasolar.com *.nesta.fr *.soprema.ca *.soprema.ae *.soprema.com.mx *.soprema.us *.convoy-supply.com *.furbishco.com *.wistia.com *.wistia.net embedwistia-a.akamaihd.net blob: my.assets-library.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io *.googleapis.com https://secure.lyra.com/vads-payment/ https://api.lyra.com/api-payment/ t.elasticsuite.io *.cloudfront.net *.bynder.com my.assets-library.com scl-sandbox.dev.clover.com scl.clover.com *.soprema.fr *.soprema.nl *.soprema.com *.soprema.be *.soprema.ch *.soprema.co.uk *.soprema.de *.soprema.at *.soprema.se *.soprema.dk *.soprema.no *.soprema.ie *.soprema.es *.georgboerner.de *.soprasolar.com *.nesta.fr *.soprema.ca *.soprema.ae *.soprema.com.mx *.soprema.us *.convoy-supply.com *.furbishco.com lotus.soprema.fr bat.bing.com app.sarooma.de *.sopremauvalue.com bam-cell.nr-data.net m.addthis.com bam.nr-data.net *.googletagmanager.com pagead2.googlesyndication.com *.leadinfo.net api.leadinfo.com *.g.doubleclick.net *.hotjar.com wss://*.hotjar.com *.hotjar.io wss://*.hotjar.io *.pardot.com *.linkedin.com *.facebook.com *.wistia.com *.litix.io embedwistia-a.akamaihd.net *.clarity.ms *.teads.tv tags.srv.stackadapt.com *.soprema-cms.awstudio.website api.maze.co prompts.maze.co 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src https://secure.lyra.com/vads-payment/ https://api.lyra.com/api-payment/ https://static.lyra.com/static/ *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 font-src *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.fontawesome.com maxcdn.bootstrapcdn.com *.salesfire.co.uk *.typekit.net *.klarnacdn.net fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.facebook.com *.googlesyndication.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.salesfire.co.uk *.googleapis.com *.trustpilot.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de static-eu.payments-amazon.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.gstatic.com *.googlesyndication.com *.roeye.com *.trackedlink.net ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com * www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.salesfire.co.uk maps.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com *.jsdelivr.net *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com chimpstatic.com downloads.mailchimp.com *.list-manage.com * js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.salesfire.co.uk *.googleapis.com *.trustpilot.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com downloads.mailchimp.com *.fontawesome.com maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com *.salesfire.co.uk *.typekit.net fonts.googleapis.com *.trustpilot.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.google-analytics.com *.facebook.com *.facebook.net *.google.com *.doubleclick.net *.googlesyndication.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com https://bam.nr-data.net/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com google.com *.salesfire.co.uk *.smartmetrics.co.uk *.googleapis.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 font-src fonts.gstatic.com use.typekit.net fonts.googleapis.com *.googleapis.com *.gstatic.com data: http://*.hotjar.com https://*.hotjar.com http://*.hotjar.io https://*.hotjar.io d3dc1lgancj6l0.cloudfront.net *.fontawesome.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com http://*.facebook.com https://*.facebook.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.demdex.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com www.google.com https://cdn.consentmanager.net https://delivery.consentmanager.net https://www.googletagmanager.com/ https://*.hotjar.com http://*.hotjar.io https://*.hotjar.io https://www.google.com/ http://*.facebook.com https://*.facebook.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com js.mollie.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net maps.googleapis.com maps.gstatic.com *.gstatic.com *.googleapis.com https://images.unsplash.com https://cdn.consentmanager.net https://delivery.consentmanager.net ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ *.consentmanager.net http://*.hotjar.com https://*.hotjar.com http://*.hotjar.io https://*.hotjar.io http://*.linkedin.com https://*.linkedin.com http://*.facebook.com https://*.facebook.com http://www.google.com/ http://www.google.de/ https://www.google.de/ https://www.googletagmanager.com http://www.googletagmanager.com userlike-cdn-operators.s3-eu-west-1.amazonaws.com https://widgets.trustedshops.com/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://www.mollie.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net assets.adobedtm.com *.adobe.io www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com *.magento-ds.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.googleapis.com *.gstatic.com https://cdn.jsdelivr.net/npm/@ryangjchandler/spruce@2.x.x/dist/spruce.umd.js www.google.com/recaptcha/ www.gstatic.com/recaptcha/ https://maps.googleapis.com https://cdn.consentmanager.net https://delivery.consentmanager.net chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ https://connect.facebook.net/ https://snap.licdn.com/li.lms-analytics/insight.min.js http://*.hotjar.com https://*.hotjar.com http://*.hotjar.io https://*.hotjar.io unsafe-inline userlike-cdn-widgets.s3-eu-west-1.amazonaws.com d3dc1lgancj6l0.cloudfront.net api.userlike.com http://www.google.com/recaptcha/ https://widgets.trustedshops.com/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com consentmanager.net *.googleadservices.com js.mollie.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.magento-datasolutions.com *.magento-ds.com downloads.mailchimp.com *.fontawesome.com maxcdn.bootstrapcdn.com 'self' 'unsafe-inline'; object-src https://cdn.consentmanager.net https://delivery.consentmanager.net 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com https://cdn.consentmanager.net https://delivery.consentmanager.net http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ *.baby-born.com 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.magento-datasolutions.com *.magento-ds.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.googleapis.com https://maps.googleapis.com https://player.vimeo.com https://cdn.consentmanager.net https://delivery.consentmanager.net form-assets.mailchimp.com *.intuit.com *.amazonaws.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ http://*.hotjar.com:* https://*.hotjar.com:* http://*.hotjar.io https://*.hotjar.io wss://*.hotjar.com http://salesviewer.org/ userlike-cdn-widgets.s3-eu-west-1.amazonaws.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.google-analytics.com https://www.google.com/ccm/collect 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com https://cdn.consentmanager.net https://delivery.consentmanager.net 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 font-src fonts.gstatic.com use.typekit.net *.googleapis.com *.gstatic.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.adyen.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.demdex.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.adyen.com consentcdn.cookiebot.com www.google.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net *.adyen.com *.googleapis.com *.gstatic.com maps.googleapis.com imgsct.cookiebot.com www.gstatic.com magefan.com cm.magefan.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net assets.adobedtm.com *.adobe.io *.magento-ds.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com *.adyen.com *.googleapis.com *.gstatic.com player.vimeo.com unpkg.com consent.cookiebot.com d39mkej10j6rgd.cloudfront.net d1wc04gc1zp1rt.cloudfront.net d1ekgxxzy7ounl.cloudfront.net d26u8mjnuxived.cloudfront.net consentcdn.cookiebot.com www.google.com www.gstatic.com js-agent.newrelic.com geoip.improove.io js.klarna.com js.playground.klarna.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.magento-datasolutions.com *.magento-ds.com www.gstatic.com x.klarnacdn.net maxcdn.bootstrapcdn.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.magento-datasolutions.com *.magento-ds.com *.adyen.com *.googleapis.com region1.google-analytics.com consentcdn.cookiebot.com bam.nr-data.net catalog-service-sandbox.adobe.io js.playground.klarna.com js.klarna.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com bam.nr-data.net commerce.adobedc.net eu.playground.klarnaevt.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 default-src 'self'; script-src 'self'; 2 default-src 'self' * data: img.3speakcontent.online emb.d.tube www.youtube.com staticxx.facebook.com player.vimeo.com https://cdnjs.cloudflare.com; img-src https: * data:; worker-src 'self' blob:; style-src 'self' 'unsafe-inline' fonts.googleapis.com https://cdnjs.cloudflare.com https://hcaptcha.com https://*.hcaptcha.com; script-src 'self' 'self' 'unsafe-inline' 'unsafe-eval' data: https: www.google-analytics.com connect.facebook.net https://cdnjs.cloudflare.com https://hcaptcha.com https://*.hcaptcha.com; connect-src 'self' wss://ws.beechat.hive-engine.com https://beechat.hive-engine.com https://history.hive-engine.com https://history.steem-engine.net https://api.hive-engine.com https://api.steem-engine.net https://scot-api.hive-engine.com https://scot-api.steem-engine.net https://steemitimages.com https://images.hive.blog securepubads.g.doubleclick.net https://api.steemit.com https://api.hive.blog api.blocktrades.us https://hivesigner.com https://pagead2.googlesyndication.com http://adservice.google.com https://www.google-analytics.com https://api.openhive.network https://ha.herpc.dtools.dev https://ha.smt-api.dtools.dev https://marketplace.tribaldex.com https://cdn.plyr.io https://api.coingecko.com https://hetestnet.dtools.dev https://smtscot.cryptoempirebot.com https://api.marketplace.tribaldex.com https://hcaptcha.com https://*.hcaptcha.com localhost:8080 https://onboard-api.tribaldex.com https://api.hive.blog https://api.deathwing.me https://rpc.ausbit.dev https://api.ha.deathwing.me; frame-src https://hcaptcha.com https://*.hcaptcha.com; form-action 'self'; frame-ancestors 'none'; object-src 'none'; report-uri /api/v1/csp-violation 2 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.olark.com mediacdn.espssl.com *.imi.chat *.frontiercoop.com *.klevu.com *.ksearchnet.com *.cloudflare.com *.twitter.com *.twimg.com *.trustedshops.com *.googleapis.com *.zopim.com *.zopim.io *.widen.net *.widencdn.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.authorize.net *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.twitter.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors *.certcapture.com *.authorize.net 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.certcapture.com *.authorize.net c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * destinilocators.com *.duosecurity.com *.olark.com *.frontiercoop.com *.yotpo.com *.weltpixel.com https://www.youtube.com http://www.sandbox.paypal.com *.twitter.com *.zendesk.com *.widen.net *.widencdn.net *.googletagmanager.com *.doubleclick.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.paypal.com *.typekit.net *.gstatic.com *.certcapture.com store.paradoxlabs.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com frontiercoop.widen.net *.olark.com lux.speedcurve.com mediacdn.espssl.com brxcdn.com *.frontiercoop.com cdn-cookieyes.com *.yotpo.com *.klevu.com *.ksearchnet.com *.cloudflare.com *.klarna.com *.googleadservices.com *.google-analytics.com *.twitter.com *.twimg.com *.ytimg.com *.bing.com *.zopim.com *.zopim.io *.doubleclick.net *.google.com *.google.co.in *.mastercard.com *.widen.net *.widencdn.net *.facebook.com *.reddit.com *.ads-twitter.com t.co *.bing.net *.klaviyo.com *.clarity.ms *.googletagmanager.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net amcglobal.sc.omtrdc.net commerce.adobe.net use.typekit.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.magento-ds.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.certcapture.com *.authorize.net js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com js-agent.newrelic.com bam.nr-data.net destinilocators.com *.olark.com cdn.speedcurve.com acsbapp.com s.pinimg.com bat.bing.com ct.pinterest.com *.exponea.com *.imi.chat *.frontiercoop.com cdn-cookieyes.com *.yotpo.com js.klevu.com *.ksearchnet.com *.cloudflare.com *.twitter.com *.google-analytics.com *.twimg.com *.gstatic.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.bing.com *.zopim.com *.zdassets.com *.zendesk.com *.widen.net *.widencdn.net *.googletagmanager.com *.googleadservices.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.clarity.ms *.klaviyo.com unpkg.com *.doubleclick.net https://js.klevu.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com *.certcapture.com assets.braintreegateway.com *.olark.com mediacdn.espssl.com *.imi.chat *.frontiercoop.com *.yotpo.com *.klevu.com *.ksearchnet.com 'unsafe-inline' *.cloudflare.com *.googleapis.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.fontawesome.com *.bing.com *.widen.net *.widencdn.net *.tagmanager.google.com *.googletagmanager.com https://statsjs.klevu.com https://js.klevu.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.olark.com *.frontiercoop.com *.zopim.com *.zopim.io *.widen.net *.widencdn.net 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io *.sentry.io *.magento-datasolutions.com *.magento-ds.com *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.certcapture.com *.authorize.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com bam.nr-data.net lux.speedcurve.com *.acsbapp.com acsbapp.com ct.pinterest.com bat.bing.com *.exponea.com facebook.com *.facebook.com *.imi.chat *.frontiercoop.com cdn-cookieyes.com log.cookieyes.com *.yotpo.com *.olark.com *.klevu.com *.ksearchnet.com *.cloudflare.com *.twitter.com *.twimg.com *.zdassets.com *.zopim.com *.zopim.io wss://widget-mediator.zopim.com *.google-analytics.com https://stats.g.doubleclick.net *.zendesk.com *.widen.net *.widencdn.net *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.doubleclick.net *.run.app 'self' 'unsafe-inline'; child-src *.certcapture.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.olark.com *.frontiercoop.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 script-src 'self' 'unsafe-inline' 'unsafe-eval' *.google.com *.sharethis.com *.rawgit.com *.jquery.com *.facebook.net *.usercentrics.eu *.cookiebot.eu *.cookiebot.com *.g.doubleclick.net *.fontawesome.com *.googleapis.com *.linkedin.com *.hotjar.com wasm-eval *.google-analytics.com *.googleoptimize.com *.googletagmanager.com *.gstatic.com; script-src-elem 'self' 'unsafe-inline' *.googleapis.com *.google.com *.sharethis.com *.rawgit.com *.cloudflare.com *.jquery.com *.facebook.net *.cookiebot.com *.g.doubleclick.net *.fontawesome.com *.bootstrapcdn.com *.wisoyekivo.com *.linkedin.com *.vimeo.com *.skedify.io *.plugin.skedify.io *.hotjar.com *.google-analytics.com *.googleoptimize.com *.googletagmanager.com *.gstatic.com *.pagespeed-mod.com; script-src-attr 'unsafe-inline'; style-src 'self' 'unsafe-inline' *.googleapis.com *.fontawesome.com *.sharethis.com *.gstatic.com *.pvgroup.be; style-src-elem 'self' 'unsafe-inline' *.jquery.com *.googleapis.com *.bootstrapcdn.com *.skedify.io pv.skedify.show *.fontawesome.com *.sharethis.com *.gstatic.com *.pvgroup.be; style-src-attr 'unsafe-inline'; img-src 'self' data: *.google.com *.skedify.io *.vimeocdn.com *.ytimg.com *.sharethis.com *.googleapis.com *.gstatic.com *.sharethis.com *.google-analytics.com *.hotjar.com *.gstatic.com *.sharethis.com *.google.com *.sharethis.com *.facebook.com *.google-analytics.com *.google.at *.google.be *.google.ch *.google.co.uk *.google.co.za *.google.com *.google.com.ng *.google.de *.google.es *.google.fi *.google.fr *.google.ie *.google.it *.google.lu *.google.nl *.google.pt *.google.se *.googletagmanager.com *.gstatic.com *.ondernemersbelang.nl *.pv.be *.pvgroep.coop *.pvgroup.be *.reprintsdesk.com *.researchsolutions.com *.verfvanniveau.nl *.google.co.in; font-src 'self' data: *.alicdn.com *.gstatic.com github.com *.fontawesome.com *.bootstrapcdn.com *.hotjar.com; connect-src 'self' *.doubleclick.net *.google.com *.eu1.kaskocloud.com *.skedify.io *.crwdcntrl.net *.cookiebot.com *.withgoogle.com *.stbuttons.click data: *.hotjar.com *.fontawesome.com *.sharethis.com *.google.com *.googleapis.com *.ingest.sentry.io *.googlesyndication.com properties *.google-analytics.com *.g.doubleclick.net *.hotjar.io *.facebook.com; media-src 'self'; child-src *.fls.doubleclick.net *.google.com *.esignlive.eu *.cookiebot.com *.sharethis.com *.facebook.com *.linkedin.com *.youtube-nocookie.com *.youtube.com; frame-src 'self' *.fls.doubleclick.net *.google.com *.esignlive.eu blob: *.cookiebot.com *.ebconnect.be *.zscaler.net *.zscalertwo.net *.vimeo.com *.plugin.skedify.io *.sharethis.com properties *.facebook.com *.sharethis.com *.facebook.com *.google.com *.linkedin.com *.sofiskonline.be *.youtube-nocookie.com *.youtube.com; frame-ancestors 'self'; form-action 'self' *.sips-services.com *.salesforce.com *.facebook.com; manifest-src 'self'; object-src 'none' 2 font-src fonts.gstatic.com use.typekit.net data: *.fontawesome.com *.gstatic.com 'self' data: *.yotpo.com *.googleapis.com 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de https://www.facebook.com/tr/ *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors *.bebemundo.com.do *.jugueton.com.do *.zdassets.com *.hotjar.com 'self'; frame-src fast.amc.demdex.net secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com www.googletagmanager.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de cdn.dnky.co amc.demdex.net www.google.com www.facebook.com *.dotdigital-pages.com *.dotdigital.com webchat.dotdigital.com https://www.hotjar.com https://static.hotjar.com https://script.hotjar.com https://www.facebook.com/tr/ *.youtube.com *.yotpo.com *.doubleclick.net *.googletagmanager.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net data: p.typekit.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com s.ytimg.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de maps.gstatic.com maps.googleapis.com accounts.google.com www.google.com www.facebook.com https://googleads.g.doubleclick.net www.google.com.ar www.google.com.do https://www.googletagmanager.com https://www.m.casacuesta.com *.youtube.com https://connect.facebook.net https://notifications-icommkt.website *.yotpo.com *.notifications-icommkt.com *.simpleanalyticscdn.com 'self' 'unsafe-inline'; script-src assets.adobedtm.com secure.authorize.net test.authorize.net commerce.adobedtm.com www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com amcglobal.sc.omtrdc.net commerce.adobe.net use.typekit.net www.sandbox.paypal.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com video.google.com vimeo.com www.vimeo.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.youtube.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de cdn.dnky.co r1-t.trackedlink.net www.gstatic.com js-agent.newrelic.com bam.nr-data.net maps.googleapis.com connect.facebook.net *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com api.comapi.com webchat.dotdigital.com *.avada.io *.google.com *.gstatic.com https://www.hotjar.com https://static.hotjar.com https://script.hotjar.com https://www.google-analytics.com https://stats.g.doubleclick.net http://www.google.com/recaptcha/api.js https://d12zyq17vm1xwx.cloudfront.net/v2/wpn.min.js https://static.cloudflareinsights.com/ https://www.gstatic.com/recaptcha/releases/tFhBvPrftr7Y91fo1S1ASkA6/recaptcha__es.js https://externalassets.icommarketing.com/icomMkt_tracking_jquery.min.js *.youtube.com https://static.zdassets.com ekr.zdassets.com *.yotpo.com *.simpleanalyticscdn.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com getfirebug.com cdn.dnky.co webchat.dotdigital.com *.fontawesome.com *.googleapis.com *.gstatic.com *.yotpo.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src https://static.zdassets.com *.youtube.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net api.magento.com commerce.adobe.io commerce.adobedtm.com commerce.adobedc.net *.adobe.io performance.typekit.net commerce.adobe.net qa-api.magedevteam.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de api.comapi.com bam.nr-data.net *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com *.google-analytics.com https://www.hotjar.com https://script.hotjar.com https://analytics.google.com https://stats.g.doubleclick.net https://www.facebook.com/tr/ http://ccnecommerce.com/ https://notifications-icommkt.com/ https://track-icommkt.com/ wss://widget-mediator.zopim.com/ *.youtube.com https://static.zdassets.com ekr.zdassets.com jugueton.zendesk.com bebemundord.zendesk.com casacuesta.zendesk.com *.googletagmanager.com *.yotpo.com *.googleapis.com *.zdassets.com *.hotjar.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 font-src *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com www.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net https://www.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.weltpixel.com *.google.com/ js.mollie.com secure.pay1.de payments.amazon.de jsctool.com www.jsctool.com js.playground.klarna.com *.ad-srv.net www.usemaxserver.de *.redintelligence.net www.pinterest.com www.pinterest.de www.facebook.com *.googletagmanager.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io magefan.com cm.magefan.com https://firebasestorage.googleapis.com https://www.magezon.com flagpedia.net https://www.mollie.com cdn.pay1.de x.klarnacdn.net *.cloudfront.net m.media-amazon.com static-eu.payments-amazon.com maps.gstatic.com *.gstatic.com *.cdninstagram.com *.fbcdn.net www.google.de *.facebook.com *.pinterest.com www.usemaxserver.de *.awin1.com *.googleadservices.com *.doubleclick.net widgets.trustedshops.com https://as.ad4m.at https://ad11.adfarm1.adition.com https://imagesrv.adition.com adservice.google.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.avada.io *.shopify.com *.google.com/ *.gstatic.com maps.googleapis.com js.mollie.com ajax.googleapis.com secure.pay1.de d.ratepay.com static-eu.payments-amazon.com x.klarnacdn.net cdn.klarna.com jsctool.com d.payla.io https://freegeoip.app https://www.googletagmanager.com tagmanager.google.com *.instagram.com analytics.gourvita.com www.gstatic.com *.ratepay.com www.dwin1.com www.usemaxserver.de *.ad-srv.net *.doubleclick.net connect.facebook.net *.pinimg.com widgets.trustedshops.com *.googletagmanager.com https://lantern.roeyecdn.com https://ad4m.at 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.gstatic.com fonts.googleapis.com d.ratepay.com d.payla.io dr.payla.io tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.cdninstagram.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.friendlycaptcha.com eu-api.friendlycaptcha.eu https://get.geojs.io *.avada.io www.gstatic.com maps.googleapis.com payments.amazon.de payments-eu.amazon.com d.ratepay.com jsctool.com eu.playground.klarnaevt.com https://freegeoip.app https://www.google-analytics.com *.instagram.com *.googleusercontent.com analytics.gourvita.com *.ratepay.com *.pinterest.com *.google.com *.merchant-center-analytics.goog *.doubleclick.net 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com fonts.googleapis.com *.googleapis.com data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com *.google.com/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io *.ftcdn.net *.behance.net *.paypal.com *.typekit.net *.gstatic.com https://images.unsplash.com maps.googleapis.com maps.gstatic.com *.googleapis.com https://www.magezon.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com https://redchamps.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://rum.hlx.page https://maps.googleapis.com https://player.vimeo.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.google.com/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com rum.hlx.page 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://maps.googleapis.com https://player.vimeo.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.googleapis.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 default-src 'self' https: mcdn.pybydl.com; font-src 'self' https: data:; img-src 'self' https: data: mcdn.pybydl.com; object-src 'none'; script-src 'self' https: 'unsafe-inline' 'unsafe-eval' mcdn.pybydl.com; style-src 'self' https: 'unsafe-inline' mcdn.pybydl.com; frame-src 'self' https: http: data:; connect-src 'self' https: wss: www.luck-nine.com; report-uri /csp_reports 2 worker-src 'none'; 2 font-src *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.fontawesome.com maxcdn.bootstrapcdn.com *.cloudflare.com *.google.com *.google.nl *.google.at *.google.de *.google.be *.google.it *.google.fr *.dhlparcel.nl *.klaviyo.com *.typekit.net *.bing.com *.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com https://api.clerk.io https://cdn.clerk.io 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.langshop.io www.google.com *.google.com *.doubleclick.net *.facebook.com data.henkterhorst.nl js.mollie.com *.google.nl *.google.at *.google.de *.google.be *.google.fr *.google.it www.googletagmanager.com *.trustpilot.com *.pinterest.com *.criteo.com *.criteo.net *.cookiebot.com https://squeezely.tech *.sendcloud.sc *.jsdelivr.net *.weltpixel.com www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.gstatic.com https://cdn.clerk.io retail.googleapis.com henkterhorst.nl *.henkterhorst.nl henkterhorst.de *.henkterhorst.de *.henkterhorst.dk brinks-media.com *.bidswitch.net *.adnxs.com *.smartadserver.com *.taboola.com *.1rx.io *.yieldmo.com *.omnitagjs.com *.casalemedia.com id5-sync.com *.360yield.com *.ivitrack.com *.media.net *.mediavine.com *.postrelease.com *.outbrain.com *.pubmatic.com *.rubiconproject.com *.sharethrough.com *.teads.tv *.tremorhub.com *.3lift.com *.yieldlab.net *.emxdgt.com *.adform.net *.twiago.com *.dmxleo.com *.unrulymedia.com *.eyeota.net *.agkn.com *.clarity.ms https://www.magezon.com https://www.mollie.com *.mailcampaigns.nl/ *.linkedin.com *.pinterest.com *.google.com.ua *.google.de *.google.nl *.google.at *.google.be *.google.fr *.google.it *.twitter.com *.yahoo.com *.webwinkelkeur.nl *.cookiebot.com *.criteo.com *.criteo.net *.bing.com *.cloudflare.com *.jmango360.com *.amazonaws.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com *.vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.gstatic.com https://api.clerk.io https://cdn.clerk.io robincontentdesktop.blob.core.windows.net *.pagesense.io *.adnxs.com *.faslet.net blob: data.henkterhorst.nl *.avada.io js.mollie.com *.google.nl *.google.at *.google.de *.google.be *.google.it *.google.fr *.paypal.com chimpstatic.com *.newrelic.com *.cloudflare.com *.criteo.net *.robinhq.com *.mailcampaigns.nl *.cloudflareinsights.com *.hotjar.com *.trustpilot.com *.dhlparcel.nl *.nr-data.net *.criteo.com *.cookiebot.com *.bing.com *.msecnd.net *.pinterest.com *.clarity.ms *.pinimg.com *.licdn.com *.sooqr.com https://squeezely.tech *.billygrace.com *.sendcloud.sc *.jsdelivr.net www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com https://api.clerk.io https://cdn.clerk.io *.fontawesome.com maxcdn.bootstrapcdn.com *.cloudflare.com *.mailcampaigns.nl *.google.com *.google.nl *.google.at *.google.de *.google.be *.google.it *.google.fr *.dhlparcel.nl *.typekit.net *.klaviyo.com *.bing.com *.sooqr.com https://unpkg.com *.bootstrapcdn.com *.sendcloud.sc *.jsdelivr.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com henkterhorst.nl *.henkterhorst.nl *.google.com *.google.nl *.google.at *.google.de *.google.be *.google.it *.google.fr 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.google-analytics.com *.facebook.com *.facebook.net *.google.com *.faslet.net *.henkterhorst.nl *.zoho.eu *.googlesyndication.com https://get.geojs.io *.avada.io *.nr-data.net *.newrelic.com *.mailcampaigns.nl *.visualstudio.com *.pinterest.com google.com *.google.nl *.google.at *.google.de *.google.be *.google.it *.google.fr *.bing.com *.linkedin.com *.hotjar.com *.hotjar.io *.trustpilot.com *.doubleclick.net *.googletagmanager.com wss://ws.hotjar.com/ *.criteo.com *.criteo.net *.cookiebot.com *.clarity.ms *.amazonaws.com https://squeezely.tech *.jsdelivr.net *.billypx.com *.sendcloud.sc *.cdn.jsdelivr.net *.mapbox.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com *.googletagmanager.com *.doubleclick.net insight.adsrvr.org c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io magefan.com cm.magefan.com *.disqus.com https://firebasestorage.googleapis.com *.linkedin.com www.facebook.com *.doubleclick.net www.google.co.nz *.google.co.nz www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.disqus.com *.avada.io *.shopify.com cdnjs.cloudflare.com connect.facebook.net snap.licdn.com js.adsrvr.org *.cybersource.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com https://fonts.bunny.net *.fonts.net *.googleapis.com assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net analytics.google.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com https://get.geojs.io *.avada.io cdnjs.cloudflare.com www.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 font-src *.fontawesome.com *.googleapis.com *.gstatic.com https://fonts.gstatic.com maxcdn.bootstrapcdn.com fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com https://seo.mageplaza.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com landofcoder.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.weltpixel.com www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.trackedlink.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com www.xtento.com cdn.xtento.com *.googletagmanager.com *.google-analytics.com ssl.gstatic.com www.gstatic.com https://www.facebook.com https://c.clarity.ms/ https://bat.bing.com/ https://c.bing.com/ data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com landofcoder.com s7.addthis.com *.fontawesome.com *.googleapis.com *.gstatic.com player.vimeo.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com www.xtento.com cdn.xtento.com *.googletagmanager.com tagmanager.google.com https://cs.iubenda.com/ static.addtoany.com acsbapp.com mylivechat.com a6.mylivechat.com https://cdn.iubenda.com/cs/ccpa/stub.js https://connect.facebook.net/ http://www.paypalobjects.com http://www.googletagmanager.com http://www.vimeo.com https://cdn.iubenda.com/ https://bat.bing.com/ https://www.clarity.ms/ 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.fontawesome.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com *.googleapis.com *.addtoany.com maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com tagmanager.google.com fonts.google.com a6.mylivechat.com 'self' 'unsafe-inline'; object-src landofcoder.com 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com landofcoder.com ekr.zdassets.com/ http://dpm.demdex.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com cdn.acsbapp.com http://www.googletagmanager.com http://www.sandbox.paypal.com http://www.paypalobjects.com https://hits-i.iubenda.com/ https://w.clarity.ms/collect http://www.google-analytics.com https://consent.iubenda.com/ https://o.clarity.ms/collect https://v.clarity.ms/collect 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 font-src *.googleapis.com *.gstatic.com *.fontawesome.com https://fonts.bunny.net https://fonts.gstatic.com 'self' data: *.oct8ne.com https://oct8necdneu.azureedge.net https://widgets.trustedshops.com fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' 'unsafe-inline'; frame-ancestors localhost:* *.motive.co 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ https://cdn.ealyx.tech https://player.vimeo.com https://www.youtube-nocookie.com *.oct8ne.com sandbox.sequracdn.com live.sequracdn.com sandbox.sequrapi.com live.sequrapi.com https://consentcdn.cookiebot.com https://www.salesmanago.pl https://app3.salesmanago.pl https://www.salesmanago.com https://backoffice-eu.oct8ne.com https://sandbox.sequrapi.com https://live.sequrapi.com https://eu1-search.doofinder.com https://eu1-layer.doofinder.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.googleapis.com *.gstatic.com *.salesmanago.pl *.salesmanago.es *.salesmanago.com https://cdn.ealyx.tech https://maps.gstatic.com https://maps.googleapis.com https://images.unsplash.com blob: https://firebasestorage.googleapis.com *.motive.co *.oct8ne.com sandbox.sequracdn.com live.sequracdn.com sandbox.sequrapi.com live.sequrapi.com https://www.google.com https://www.google.es https://oct8necdneu.azureedge.net https://www.bazarelregalo.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com *.googletagmanager.com *.google-analytics.com ssl.gstatic.com www.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.googleapis.com *.gstatic.com *.salesmanago.pl *.salesmanago.es *.salesmanago.com self https://cdn.ealyx.tech https://maps.googleapis.com/maps/api/ https://maps.googleapis.com/ *.avada.io *.motive.co https://player.vimeo.com https://www.youtube.com *.oct8ne.com *.omniwallet.cloud sandbox.sequracdn.com live.sequracdn.com sandbox.sequrapi.com live.sequrapi.com http://media.flixfacts.com https://prod.flixgvid.flix360.io http://media.flixcar.com https://cdn.doofinder.com https://consent.cookiebot.com https://consentcdn.cookiebot.com https://www.google-analytics.com https://www.google.com https://js-agent.newrelic.com https://bam.nr-data.net https://static-eu.oct8ne.com https://sandbox.sequrapi.com https://live.sequrapi.com https://eu1-search.doofinder.com https://app3.salesmanago.pl https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://cdn.ealyx.tech *.fontawesome.com https://fonts.bunny.net https://fonts.googleapis.com http://fonts.googleapis.com http://media.flixcar.com https://cdn.doofinder.com https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com tagmanager.google.com fonts.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com blob: 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com https://vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.googleapis.com *.salesmanago.pl *.salesmanago.es *.salesmanago.com https://api.ealyx.tech https://cdn.ealyx.tech https://maps.googleapis.com https://get.geojs.io *.avada.io *.motive.co https://fonts.googleapis.com https://fonts.gstatic.com https://api.weatherbit.io *.oct8ne.com *.omniwallet.cloud sandbox.sequracdn.com live.sequracdn.com sandbox.sequrapi.com live.sequrapi.com https://consentcdn.cookiebot.com https://www.google-analytics.com https://www.youtube.com https://youtu.be https://frontal-eu.oct8ne.com https://js-agent.newrelic.com https://bam.nr-data.net https://eu1-layer.doofinder.com wss://eu1-layer.doofinder.com *.trustedshops.com *.etrusted.com https://integrations.etrusted.site *.google-analytics.com *.analytics.google.com *.googletagmanager.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.salesmanago.pl *.salesmanago.es *.salesmanago.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 font-src https://www.gstatic.com https://fonts.gstatic.com *.gstatic.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ https://*.google.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.googleusercontent.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.hsforms.net *.hsforms.com 'self' data: data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.google.com https://*.gstatic.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.hsforms.net *.hsforms.com *.gstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://fonts.googleapis.com https://hcaptcha.com https://*.hcaptcha.com unsafe-inline assets.braintreegateway.com *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://ipinfo.io https://*.google.com https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://9019ddbf-da08-455e-a3c6-d8ea66ab1180.sansec.watch/; report-to report-endpoint; 2 default-src 'self' https: data: blob:; script-src 'self' 'nonce-{{ request.nonce }}' https://*.hubspot.com https://*.hubapi.com https://*.hsforms.com https://*.hs-scripts.com https://*.hscollectedforms.net https://*.hs-banner.com https://*.hubspotusercontent.com https://*.hubspotusercontent-eu1.net https://js.hs-analytics.net https://js.hsforms.net https://api.hsforms.com https://api.hubapi.com https://*.hsleadflows.net https://*.hsadspixel.net https://*.hs-web-analytics.net https://static.hsappstatic.net https://cdn2.hubspot.net https://cdn.hubspot.com https://*.cloudfront.net https://cdn.jsdelivr.net https://www.googletagmanager.com https://www.google-analytics.com https://www.google.com https://www.gstatic.com https://stats.g.doubleclick.net https://www.googleadservices.com https://cdn.cookielaw.org https://www.youtube.com; style-src 'self' 'unsafe-inline' https: data:; img-src 'self' https: data: blob:; font-src 'self' https: data:; frame-src 'self' https: data:; connect-src 'self' https: wss:; media-src 'self' https: data: blob:; worker-src 'self' https: blob:; object-src 'none'; base-uri 'self'; form-action 'self' https:; frame-ancestors 'self' https://*.hubspot.com; 2 font-src fonts.gstatic.com use.typekit.net *.fontawesome.com *.googleapis.com *.gstatic.com https://cdnjs.cloudflare.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.wesupply.xyz *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.googleapis.com *.gstatic.com www.apptrian.com *.mercadolivre.com.br *.mercadolibre.com.mx *.mercadolibre.com.ar www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net amcglobal.sc.omtrdc.net commerce.adobe.net use.typekit.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com *.magento-ds.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.googleapis.com *.gstatic.com www.apptrian.com *.avada.io https://cdnjs.cloudflare.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.cloudflare.com https://www.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.fontawesome.com https://fonts.googleapis.com https://cdnjs.cloudflare.com unsafe-inline assets.braintreegateway.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io *.magento-datasolutions.com *.magento-ds.com *.sentry.io *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.googleapis.com www.apptrian.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com https://www.google-analytics.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 font-src https://www.googletagmanager.com *.googleapis.com *.gstatic.com *.babysmile24.com cdn.babysmile24.de cdn.babysmile24.at cdn.babysmile24.ch *.kameleoon.io *.fontawesome.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * secure.pay1.de payments.amazon.de jsctool.com www.jsctool.com js.playground.klarna.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.gstatic.com *.babygalerie24.de *.facebook.com *.googleapis.com *.google.de *.ovh.net www.google.at www.google.ch www.google.com.bd *.babysmile24.com cdn.babysmile24.de cdn.babysmile24.at cdn.babysmile24.ch *.google.com *.hub.baby *.googlesyndication.com www.google.si *.googleusercontent.com www.google.co.in www.google.kz www.google.ro *.ccm19.de *.kameleoon.io magefan.com cm.magefan.com https://firebasestorage.googleapis.com cdn.pay1.de x.klarnacdn.net *.cloudfront.net m.media-amazon.com static-eu.payments-amazon.com bspic.hub.baby data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com tagmanager.google.com https://www.googletagmanager.com *.etermin.net *.ccm19.de *.facebook.net *.google.com *.googleapis.com *.babysmile24.com cdn.babysmile24.de cdn.babysmile24.at cdn.babysmile24.ch *.googletagmanager.com *.clarity.ms *.kameleoon.io *.avada.io secure.pay1.de d.ratepay.com static-eu.payments-amazon.com x.klarnacdn.net cdn.klarna.com jsctool.com d.payla.io 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com unsafe-inline assets.braintreegateway.com https://www.googletagmanager.com tagmanager.google.com *.googleapis.com cdn.babysmile24.de cdn.babysmile24.at cdn.babysmile24.ch *.ccm19.de *.gstatic.com *.etermin.net *.kameleoon.io *.fontawesome.com https://fonts.bunny.net d.ratepay.com d.payla.io dr.payla.io 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.hub.baby *.babysmile24.com cdn.babysmile24.de cdn.babysmile24.at cdn.babysmile24.ch *.ovh.net 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com https://www.google-analytics.com *.ccm19.de *.google-analytics.com *.googleapis.com *.babysmile24.com cdn.babysmile24.de cdn.babysmile24.at cdn.babysmile24.ch *.doubleclick.net *.googlesyndication.com *.facebook.com *.clarity.ms *.kameleoon.io https://get.geojs.io *.avada.io payments.amazon.de payments-eu.amazon.com d.ratepay.com jsctool.com eu.playground.klarnaevt.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.ccm19.de 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://bec24c5a-6980-491a-b199-6ac1940dc2e1.sansec.watch/; report-to report-endpoint; 2 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com fonts.googleapis.com https://fonts.bunny.net maxcdn.bootstrapcdn.com https://cdnjs.cloudflare.com *.cloudfront.net *.reviews.io *.reviews.co.uk data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.nosto.com *.nos.to *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.reviews.io *.reviews.co.uk 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com platform.twitter.com *.nosto.com *.nos.to c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.reviews.io *.reviews.co.uk *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://firebasestorage.googleapis.com pinterest.com assets.pinterest.com syndication.twitter.com flagpedia.net *.nosto.com *.nos.to www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.cloudfront.net *.reviews.io *.reviews.co.uk maps.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com widget.freshworks.com m2epro.freshdesk.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.avada.io *.shopify.com twitter.com platform.twitter.com static.addtoany.com *.gstatic.com maps.googleapis.com *.nosto.com *.nos.to https://cdnjs.cloudflare.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.reviews.io *.reviews.co.uk https://www.googletagmanager.com tagmanager.google.com unpkg.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com widget.freshworks.com m2epro.freshdesk.com https://static.klaviyo.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.gstatic.com *.nosto.com *.nos.to https://fonts.googleapis.com https://cdnjs.cloudflare.com assets.braintreegateway.com *.cloudfront.net *.reviews.io *.reviews.co.uk tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com widget.freshworks.com m2epro.freshdesk.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://get.geojs.io *.avada.io stats.addtoany.com www.gstatic.com maps.googleapis.com *.nosto.com *.nos.to api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.cloudfront.net *.reviews.io *.reviews.co.uk *.google-analytics.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com maxcdn.bootstrapcdn.com 'self' data: data: *.tiktok.com *.ttcdn-row.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.paypal.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com 'self' 'unsafe-inline'; frame-ancestors *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com cdn.dnky.co amc.demdex.net www.google.com youtube.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com *.ftcdn.net *.behance.net www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com 'self' data: maps.gstatic.com maps.googleapis.com accounts.google.com *.tiktok.com *.ttcdn-row.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.magento-datasolutions.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com https://www.google.com *.gstatic.com cdn.dnky.co r1-t.trackedlink.net www.gstatic.com js-agent.newrelic.com bam.nr-data.net maps.googleapis.com player.vimeo.com https://maps.googleapis.com *.tiktok.com *.ttcdn-row.com *.bytedance.com analytics.tiktok.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com *.fontawesome.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com maxcdn.bootstrapcdn.com *.googleapis.com *.gstatic.com cdn.dnky.co *.googletagmanager.com *.cookielaw.org *.tiktok.com *.ttcdn-row.com 'self' 'unsafe-inline'; object-src *.tiktok.com 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com api.magento.com commerce.adobe.io *.magento-datasolutions.com *.magento-ds.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.google-analytics.com maps.googleapis.com api.comapi.com bam.nr-data.net *.cookielaw.org analytics.tiktok.com business-api.tiktok.com *.ttcdn-row.com *.bytedance.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 font-src *.fontawesome.com https://fonts.bunny.net fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action 'self' 'unsafe-inline'; frame-ancestors *.multisafepay.com https://pay.google.com 'self'; frame-src bid.g.doubleclick.net player.vimeo.com *.youtube.com *.youtube-nocookie.com *.multisafepay.com https://pay.google.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com *.youtube.com https://firebasestorage.googleapis.com *.multisafepay.com *.googletagmanager.com *.google-analytics.com ssl.gstatic.com www.gstatic.com data: 'self' 'unsafe-inline'; script-src googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://browser.sentry-cdn.com *.avada.io *.multisafepay.com https://pay.google.com *.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.fontawesome.com https://fonts.bunny.net *.multisafepay.com tagmanager.google.com fonts.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com https://*.ingest.sentry.io https://get.geojs.io *.avada.io *.multisafepay.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 script-src, object-src, base-uri, frame-src 2 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.klarnacdn.net *.cloudflare.com *.trustedshops.com *.googleapis.com *.klaviyo.com cdn1.stamped.io stamped.io *.fontawesome.com *.yotpo.com dhv2ziothpgrr.cloudfront.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.adyen.com *.facebook.com *.nosto.com *.nos.to *.twitter.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.adyen.com *.doubleclick.net *.facebook.com *.klarna.com *.nosto.com *.nos.to *.freshchat.com *.twitter.com *.pinterest.com js.mollie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.yotpo.com *.ingrid.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com 'self' data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io *.paypal.com *.typekit.net *.gstatic.com *.adyen.com *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.klarna.com *.klarnaevt.com *.nosto.com *.nos.to *.rubiconproject.com/ *.sharethrough.com/ *.teads.tv/ *.tremorhub.com/ *.3lift.com/ *.yieldlab.net/ *.ads.yieldmo.com/ *.emxdgt.com/ *.adform.net/ *.demdex.net/ *.criteo.net *.adnxs.com/ *.cloudfront.net/ *.stamped.io *.freshchat.com/ *.cloudflare.com *.ytimg.com *.bing.com/ *.clarity.ms/ *.google.al/ *.google.am/ *.google.at/ *.google.az/ *.google.ba/ *.google.be/ *.google.bg/ *.google.by/ *.google.ch/ *.google.cz/ *.google.de/ *.google.dk/ *.google.ee/ *.google.es/ *.google.fi/ *.google.fr/ *.google.ge/ *.google.gr/ *.google.hr/ *.google.hu/ *.google.ie/ *.google.is/ *.google.it/ *.google.kz/ *.google.li/ *.google.lt/ *.google.lu/ *.google.lv/ *.google.md/ *.google.me/ *.google.mk/ *.google.mt/ *.google.nl/ *.google.no/ *.google.pl/ *.google.pt/ *.google.ro/ *.google.rs/ *.google.ru/ *.google.se/ *.google.si/ *.google.sk/ *.google.sm/ *.google.tr/ *.google.ua/ *.google.uk/ *.google.com.ua/ *.google.com.tr/ *.google.com.gr/ *.google.com.pt/ *.google.com.pl/ https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ cdn1.stamped.io stamped.io https://www.mollie.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.yotpo.com dhv2ziothpgrr.cloudfront.net data: 'self' 'unsafe-inline'; script-src googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.adyen.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.klarna.com/ *.nosto.com *.nos.to *.cloudfront.net/ *.cookiebot.com/ *.kuvio.io/ *.reamaze.com/ *.shopalike.fi/ *.chatbotize.com/ qanuk-stage.vercel.app *.tradedoubler.com *.criteo.com *.cookiefirst.com *.omappapi.com *.googleoptimize.com *.klaviyo.com reviewsonmywebsite.com 'self' data: *.fontawesome.com *.videoly.co/ *.freshchat.com cdnjs.cloudflare.com/ *.googleapis.com/ *.noibu.com/ *.pinimg.com/ *.bing.com/ *.tiktok.com/ *.pinterest.com/ *.intercom.io/ *.intercomcdn.com/ *.clarity.ms/ *.klarnaservices.com/ *.livechatinc.com/ *.hotjar.com/ https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ player.vimeo.com cdn1.stamped.io stamped.io js.mollie.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.yotpo.com dhv2ziothpgrr.cloudfront.net *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com d18eg7dreypte5.cloudfront.net *.ingrid.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.nosto.com *.nos.to *.cookiefirst.com *.klarnacdn.net *.omappapi.com reviewsonmywebsite.com *.typekit.net *.freshchat.com/ *.cloudflare.com/ *.klaviyo.com/ https://static.klaviyo.com cdn1.stamped.io stamped.io *.fontawesome.com assets.braintreegateway.com *.yotpo.com dhv2ziothpgrr.cloudfront.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src cdn1.stamped.io stamped.io 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.adyen.com *.algolia.net *.algolia.com/ *.algolianet.com *.insights.algolia.io insights.algolia.io *.google-analytics.com *.facebook.com *.facebook.net *.google.com/ *.klarnaevt.com *.nosto.com *.nos.to *.criteo.com *.hobbybox.fi/ *.g.doubleclick.net/ *.reamaze.com/ *.cookiebot.com/ *.kelkoogroup.net/ *.chatbotize.com *.klarnaservices.com *.doubleclick.net *.qanuk.app *.cookiefirst.com *.omappapi.com *.googlesyndication.com reviewsonmywebsite.com *.cloudflare.com *.pinterest.com *.tiktok.com/ *.clarity.ms/ *.noibu.com/ wss://input.noibu.com/ wss://nexus-websocket-a.intercom.io/ *.intercom.io/ *.bing.com/ *.algolia.io/ *.klarna.com/ wss://ws.reamaze.com/ *.reamaze.io/ https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ cdn1.stamped.io stamped.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.yotpo.com dhv2ziothpgrr.cloudfront.net *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src self data: *.nosto.com/ *.klaviyo.com/ *.stamped.io/ https://stamped.io/ *.gstatic.com/ *.cloudfront.net/ *.cloudflare.com/ *.klarnaservices.com/ *.klarna.com/ *.klarnaevt.com/ *.klarnacdn.net/ *.yotpo.com/ *.reamaze.io/ *.reamaze.com/ wss://ws.reamaze.com/ 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 default-src 'self' data: *.pinimg.com *.postaffiliatepro.com partneri.affilmax.cz *.doubleclick.net *.facebook.net *.google-analytics.com *.biano.cz *.dognet.sk *.googlesyndication.com *.imedia.cz *.googletagmanager.com *.googleadservices.com ;font-src 'self' data: fonts.gstatic.com *.zbozi.cz *.biano.cz *.biano.sk *.biano.hu ;connect-src 'self' google.com *.google.com *.google.hu *.google.ae *.google.co.uk *.google.cz *.google.sk *.google.de *.google.at *.google.fr *.google.it *.google.sk *.google.pl *.google.nl *.google.ie *.google.com.ua *.googleapis.com *.google-analytics.com *.googletagmanager.com *.googleadservices.com *.zbozi.cz *.exchangeratesapi.io *.pingdom.net *.biano.cz *.biano.sk *.biano.hu *.bianopixel.com *.dognet.sk *.foxentry.cz *.seznam.cz *.facebook.com *.pinterest.com *.doubleclick.net https://*.clarity.ms partner-events.favi.cz partner-events.favi.sk partner-events.favi.hu t.targito.signal-nabytek.cz t.targito.sg-nabytek.cz t.targito.signal-nabytok.sk t.targito.sg-nabytok.sk t.targito.butor-signal.hu t.targito.sg-butor.hu *.clickcease.com *.targito.com *.googlesyndication.com https://saas.bianoapi.com bat.bing.com bat.bing.net live.luigisbox.com api.luigisbox.com https://*.api.rvndev.com https://*.api.raventic.ai https://*.api.raventic.dev https://api.raventic.dev https://eshops-uet-tags.ams3.cdn.digitaloceanspaces.com apps.sg-nabytek.cz apps.sg-nabytok.sk apps.sg-butor.hu ;script-src 'self' 'unsafe-inline' 'unsafe-eval' *.google.com *.google.cz *.seznam.cz *.googleapis.com *.gstatic.com *.googletagmanager.com *.google-analytics.com *.googleadservices.com *.imedia.cz *.facebook.net *.doubleclick.net *.rival.cz *.fg.cz *.3dliving.cz *.imedia.cz *.zbozi.cz *.exchangeratesapi.io *.facebook.com *.pingdom.net *.biano.cz *.biano.sk *.biano.hu *.bianopixel.com *.dognet.sk *.foxentry.cz *.googlesyndication.com *.pinimg.com *.pinterest.com partneri.affilmax.cz *.postaffiliatepro.com www.heureka.cz im9.cz cz.img9.cz *.glami.cz *.licdn.com *.linkedin.com tracking.srovname.cz https://*.clarity.ms partner-events.favicdn.net cdn.targito.signal-nabytek.cz cdn.targito.sg-nabytek.cz cdn.targito.signal-nabytok.sk cdn.targito.sg-nabytok.sk cdn.targito.butor-signal.hu cdn.targito.sg-butor.hu *.clickcease.com cdn.targito.com https://saas.bianoapi.com bat.bing.com bat.bing.net scripts.luigisbox.com cdn.luigisbox.com https://sdk.cdn.rvndev.com https://sdk.rvndn.com apps.sg-nabytek.cz apps.sg-nabytok.sk apps.sg-butor.hu ;form-action 'self' *.facebook.com *.facebook.net *.pinterest.com ;frame-src 'self' *.youtube.com *.iplatba.cz *.facebook.com *.imedia.cz *.zbozi.cz *.essox.cz *.foxentry.cz *.doubleclick.net *.googletagmanager.com *.google.com *.heureka.cz *.pinterest.com *.googlesyndication.com login.szn.cz ;worker-src 'self' *.youtube.com *.iplatba.cz *.facebook.com *.imedia.cz *.zbozi.cz *.essox.cz *.foxentry.cz *.doubleclick.net *.googletagmanager.com *.google.com *.heureka.cz *.pinterest.com *.googlesyndication.com login.szn.cz ;frame-ancestors 'self' ;img-src 'self' data: blob: *.gstatic.com *.googleapis.com *.googlecode.com *.googletagmanager.com *.google-analytics.com *.seznam.cz *.doubleclick.net *.google.com *.google.hu *.google.ae *.google.co.uk *.google.cz *.google.sk *.google.de *.google.at *.google.fr *.google.it *.google.sk *.google.pl *.google.nl *.google.ie *.google.com.ua *.imedia.cz *.facebook.com *.facebook.net *.fg.cz *.3dliving.cz *.signal-nabytek.cz *.sg-nabytek.cz *.signal-nabytok.sk *.sg-nabytok.sk *.rival.cz *.vykupto.cz *.signal.pl *.zbozi.cz *.exchangeratesapi.io *.dognet.sk *.foxentry.cz *.pinimg.com *.pinterest.com *.biano.cz *.biano.sk *.biano.hu *.heureka.cz *.heureka.sk im9.cz *.glami.cz *.googleadservices.com https://*.clarity.ms bat.bing.com bat.bing.net *.favionline.com *.bing.com cdn.targito.com https://i.cdn.rvndev.com https://i.rvndn.com ;style-src 'self' 'unsafe-inline' fonts.googleapis.com *.seznam.cz *.google.com *.gstatic.com *.fg.cz *.3dliving.cz *.signal-nabytek.cz *.sg-nabytek.cz *.signal-nabytok.sk *.sg-nabytok.sk *.sg-butor.hu *.zbozi.cz *.exchangeratesapi.io *.foxentry.cz cdn.targito.com https://saas.bianoapi.com cdn.luigisbox.com https://sdk.cdn.rvndev.com https://sdk.rvndn.com ;object-src 'self' ; report-uri /frontendreport/report/ 2 default-src 'self'; script-src 'self' 'unsafe-eval' 'unsafe-inline'; style-src 'self' 'unsafe-inline'; report-uri https://a98901cf-47c3-4caa-90c6-689597e5f0ac.sansec.watch/; report-to report-endpoint; 2 font-src *.googleapis.com *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com https://fonts.gstatic.com *.fontawesome.com maxcdn.bootstrapcdn.com https://use.fontawesome.com https://v2.zopim.com *.cloudflare.com data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com *.googlesyndication.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com js.mollie.com *.trustpilot.com *.force.com *.cookiebot.com *.sommify.ai *.googletagmanager.com assets.adobedtm.com *.adobedtm.com https://fprnt.com https://s7.addthis.com https://js.mollie.com https://simplicity.trustpilot.com https://googleads.g.doubleclick.net https://www.google.com www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://images.unsplash.com *.googleapis.com *.gstatic.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.googlesyndication.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com magefan.com cm.magefan.com https://www.mollie.com https://media.jmango360.com https://secure.adnxs.com https://d2dglb1590sxlb.cloudfront.net https://www.google.com https://www.google.ca https://www.google.nl https://www.google.it *.mcusercontent.com *.cookiebot.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://maps.googleapis.com *.googleapis.com *.gstatic.com *.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.googlesyndication.com chimpstatic.com downloads.mailchimp.com *.list-manage.com js.mollie.com *.trustpilot.com https://www.googletagmanager.com https://widget.trustpilot.com/ https://invitejs.trustpilot.com https://v2.zopim.com/ https://www.clickcease.com https://chimpstatic.com https://static.zdassets.com https://pixel.adcrowd.com https://cdn.fraudlabspro.com https://dynamic.adcrowd.com https://s7.addthis.com https://m.addthis.com https://api-public.addthis.com https://z.moatads.com https://v1.addthisedge.com https://js.mollie.com https://service.force.com https://d.la2-c1-cdg.salesforceliveagent.com https://voordeelwijnen.my.salesforce.com *.cookiebot.com *.adobedtm.com *.jquery.com *.cloudflare.com *.conderwines.de *.voordeelwijnen.nl *.zendesk.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com downloads.mailchimp.com https://fonts.googleapis.com *.fontawesome.com maxcdn.bootstrapcdn.com *.trustpilot.com https://use.fontawesome.com https://service.force.com *.cloudflare.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://maps.googleapis.com https://player.vimeo.com *.googleapis.com *.google-analytics.com *.facebook.com *.facebook.net *.google.com *.doubleclick.net *.googlesyndication.com https://stats.g.doubleclick.net *.sentry.io https://www.google-analytics.com https://ekr.zdassets.com wss://widget-mediator.zopim.com https://s7.addthis.com https://m.addthis.com https://api-public.addthis.com https://monitor.clickcease.com https://invitejs.trustpilot.com https://*.force.com *.zendesk.com *.cookiebot.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 default-src 'self'; connect-src 'self' *.kerebro.com *.google-analytics.com *.google.com *.facebook.com *.livechatinc.com store.gsscloud.com opencompany.azurewebsites.net in.hotjar.com kerebro.com stats.g.doubleclick.net vc.hotjar.io www.gsscloud.com ka-p.fontawesome.com b.clarity.ms https://r.adgeek.net; font-src 'self' data: fonts.gstatic.com www.gsscloud.com uwillx.com cdn.livechatinc.com; frame-src 'self' *.doubleclick.net secure.livechatinc.com www.facebook.com vars.hotjar.com www.youtube.com tpc.googlesyndication.com www.googletagmanager.com cdn.videgree.com bizform.vitalyun.com; img-src 'self' data: *.gsscloud.com *.google-analytics.com *.n0.cdn.getcloudapp.com *.g.doubleclick.net *.gstatic.com cdn.files-text.com www.facebook.com i.ytimg.com www.google.com www.google.com.tw gssweb.gss.com.tw www.gss.com.tw cl.ly connect.facebook.net uwillx.com www.googletagmanager.com widgets.magentocommerce.com s3.amazonaws.com lh3.googleusercontent.com lh4.ggpht.com member.kerebro.com www.googleadservices.com jolly-beach-08300eb00.6.azurestaticapps.net; media-src cdn.livechatinc.com; script-src 'self' 'unsafe-eval' 'unsafe-inline' *.livechatinc.com *.hotjar.com *.google-analytics.com *.google.com connect.facebook.net googleads.g.doubleclick.net kerebro.com store.gsscloud.com www.googleadservices.com www.googletagmanager.com www.youtube.com www.linkedin.com uwillx.com tpc.googlesyndication.com unpkg.com kit.fontawesome.com cdnjs.cloudflare.com www.clarity.ms; script-src-elem 'self' 'unsafe-inline' data: store.gsscloud.com cdnjs.cloudflare.com cdn.jsdelivr.net cdn.livechatinc.com api.livechatinc.com unpkg.com www.clarity.ms kit.fontawesome.com www.googletagmanager.com kerebro.com www.youtube.com www.google-analytics.com ssl.google-analytics.com connect.facebook.net googleads.g.doubleclick.net https://r.adgeek.net; style-src 'self' 'unsafe-eval' 'unsafe-inline' fonts.googleapis.com store.gsscloud.com uwillx.com kerebro.com kerebro.com unpkg.com cdnjs.cloudflare.com; style-src-elem 'self' 'unsafe-inline' cdn.jsdelivr.net cdnjs.cloudflare.com unpkg.com; report-uri https://gsscloud.report-uri.com/r/d/csp/wizard 2 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://widgets.trustedshops.com *.moca-bike.com *.urage.com *.eoto-objects.com *.stepbystep-schulranzen.com *.coocazoo.com *.hama.com *.klarnacdn.net https://www.gstatic.com https://fonts.gstatic.com *.stape.io 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.adyen.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com *.adyen.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.moca-bike.com *.urage.com *.eoto-objects.com *.stepbystep-schulranzen.com *.coocazoo.com *.hama.com app.usercentrics.eu *.klarna.com https://*.google.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com *.stape.io 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.adyen.com *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.doubleclick.net cdn.scarabresearch.com orbitvu.co *.orbitvu.co https://widgets.trustedshops.com https://widgets-qa.trustedshops.com *.moca-bike.com *.urage.com *.eoto-objects.com *.stepbystep-schulranzen.com *.coocazoo.com *.hama.com media.brand-distribution.com widgets.trustedshops.com app.usercentrics.eu privacy-proxy-server.usercentrics.eu uct.service.usercentrics.eu *.klarna.com *.klarnaevt.com *.klarnacdn.net https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.googleusercontent.com *.stape.io www.facebook.com connect.facebook.com www.google.de piwik.hama.com *.hsforms.net *.hsforms.com 'self' data: data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.adyen.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.gstatic.com *.googletagmanager.com *.doubleclick.net https://userlike-cdn-widgets.s3-eu-west-1.amazonaws.com https://userlike-cdn-umm.b-cdn.net/ cdn.scarabresearch.com s7.addthis.com orbitvu.co *.orbitvu.co https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.moca-bike.com *.urage.com *.eoto-objects.com *.stepbystep-schulranzen.com *.coocazoo.com *.hama.com widgets.trustedshops.com aggregator.service.usercentrics.eu app.usercentrics.eu api.usercentrics.eu graphql.usercentrics.eu privacy-proxy.usercentrics.eu consent-api.service.consent.usercentrics.eu *.klarna.com *.klarnacdn.net *.klarnaservices.com https://*.gstatic.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com *.stape.io connect.facebook.com connect.facebook.net www.google.com www.google.de piwik.hama.com *.hsforms.net *.hsforms.com https://app.usercentrics.eu https://privacy-proxy.usercentrics.eu 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.googletagmanager.com *.orbitvu.co https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.moca-bike.com *.urage.com *.eoto-objects.com *.stepbystep-schulranzen.com *.coocazoo.com *.hama.com fast.fonts.net hello.myfonts.net *.klarnacdn.net https://fonts.googleapis.com https://hcaptcha.com https://*.hcaptcha.com *.stape.io *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.stepbystep-schulranzen.com *.coocazoo.com *.hama.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.adyen.com *.google-analytics.com *.doubleclick.net *.googlesyndication.com https://userlike-cdn-widgets.s3-eu-west-1.amazonaws.com https://api.userlike.com ekr.zdassets.com/ *.orbitvu.cloud *.trustedshops.com *.etrusted.com https://integrations.etrusted.site *.moca-bike.com *.urage.com *.eoto-objects.com *.stepbystep-schulranzen.com *.coocazoo.com *.hama.com aggregator.service.usercentrics.eu app.usercentrics.eu api.usercentrics.eu graphql.usercentrics.eu privacy-proxy.usercentrics.eu consent-api.service.consent.usercentrics.eu *.klarnaevt.com *.klarnacdn.net *.klarna.com *.klarnaservices.com https://ipinfo.io https://*.google.com https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com *.stape.io connect.facebook.com connect.facebook.net www.google.com www.google.de piwik.hama.com t.elasticsuite.io *.hsforms.net *.hsforms.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.moca-bike.com *.urage.com *.eoto-objects.com *.stepbystep-schulranzen.com *.coocazoo.com *.hama.com *.kameleoon.com *.kameleoon.io *.kameleoon.eu *.kameleoon.net *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 font-src *.punchout2go.com 'self' data: https://*.olark.com https://fonts.gstatic.com data: *.fontawesome.com *.googleapis.com *.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.punchout2go.com 'self' data: https://testsecureacceptance.cybersource.com https://secureacceptance.cybersource.com testsecureacceptance.cybersource.com secureacceptance.cybersource.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 0merchantacsstag.cardinalcommerce.com merchantacs.cardinalcommerce.com 'self' 'unsafe-inline'; frame-ancestors *.bolt.com *.punchout2go.com 'self' data: https://spsco.alpine-integration-rffjevy-cdfc3vwc43inw.us-5.magentosite.cloud https://cw.alpine-integration-rffjevy-cdfc3vwc43inw.us-5.magentosite.cloud https://surefit.alpine-integration-rffjevy-cdfc3vwc43inw.us-5.magentosite.cloud https://hc.alpine-integration-rffjevy-cdfc3vwc43inw.us-5.magentosite.cloud https://stagingm2.spsco.com https://stagingm2.empowersupply.com https://stagingm2.surefitlab.com https://stagingm2.spshangerstore.com https://productionm2.spsco.com https://productionm2.empowersupply.com https://productionm2.surefitlab.com https://productionm2.spshangerstore.com https://www.spsco.com/ https://www.empowersupply.com https://www.surefitlab.com https://www.spshangerstore.com https://www.youtube.com https://www.google.com/maps https://www.google.com/ https://insight.adsrvr.org/ https://analytics.google.com https://vimeo.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.bolt.com https://www.google.com/recaptcha/ www.googletagmanager.com *.online-metrix.net *.punchout2go.com https://static.olark.com https://testsecureacceptance.cybersource.com https://secureacceptance.cybersource.com https://*.spsco.com https://*.punchout2go.com testflex.cybersource.com flex.cybersource.com testsecureacceptance.cybersource.com secureacceptance.cybersource.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * sandbox.secure.checkout.visa.com secure.checkout.visa.com thm.visa.com sandbox.src.mastercard.com merchantacs.cardinalcommerce.com 0merchantacsstag.cardinalcommerce.com https://songbird.cardinalcommerce.com https://centinelapi.cardinalcommerce.com https://*.cardinalcommerce.com https://*.centinelapi.cardinalcommerce.com https://insight.adsrvr.org/ https://analytics.google.com https://vimeo.com https://www.googletagmanager.com/ 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.punchout2go.com https://log.olark.com https://www.google.com https://stats.g.doubleclick.net https://*.hellobar.com https://*.magentocommerce.com https://*.paypal.com https://*.vimeocdn.com https://*.ytimg.com https://*.linkedin.com https://*.facebook.com https://*.hsforms.com https://*.clarity.ms https://*.hubspot.com https://*.bing.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.googleapis.com *.gstatic.com www.gstatic.com sandbox.secure.checkout.visa.com secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com assets.secure.checkout.visa.com thm.visa.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com https://vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.bolt.com *.commerce-quick-checkout.com http://localhost:8082 https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.online-metrix.net *.punchout2go.com https://h.online-metrix.net http://*.olark.com https://cdnjs.cloudflare.com https://*.hellobar.com https://www.google.com https://www.gstatic.com https://www.googletagmanager.com https://www.googleadservices.com https://www.google-analytics.com https://*.hsforms.net https://*.hsforms.com https://js-agent.newrelic.com https://bam.nr-data.net https://*.cybersource.com https://connect.punchout2go.com https://js.hs-scripts.com https://*.facebook.net https://*.facebook.com https://*.paypal.com https://*.paypalobjects.com https://*.braintreegateway.com https://*.licdn.com https://*.cardinalcommerce.com https://*.ccdc02.com https://*.authorize.net https://*.signifyd.com https://*.hs-banner.com https://*.hs-analytics.com https://*.hs-analytics.net https://*.hscollectedforms.com https://*.hscollectedforms.net https://www.vimeo.com https://*.clarity.ms testflex.cybersource.com flex.cybersource.com player.vimeo.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googleapis.com *.gstatic.com x.klarnacdn.net sandbox.secure.checkout.visa.com secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com assets.secure.checkout.visa.com thm.visa.com sandbox.src.mastercard.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com https://cdn1.ebizcharge.net https://songbird.cardinalcommerce.com https://centinelapi.cardinalcommerce.com https://insight.adsrvr.org/ https://dpm.demdex.net https://amcglobal.sc.omtrdc.net https://geostag.cardinalcommerce.com https://geo.cardinalcommerce.com https://centinelapistag.cardinalcommerce.com https://analytics.google.com https://surestepdev.wpenginepowered.com/ https://surestep.net/ http://www.googletagmanager.com/ https://www.googletagmanager.com/ https://form.jotform.com/ https://cdn.jotfor.ms/ https://customfaborders.jotform.com/ 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.punchout2go.com https://static.olark.com https://fonts.googleapis.com https://connect.punchout2go.com *.fontawesome.com unsafe-inline assets.braintreegateway.com fonts.googleapis.com https://surestepdev.wpenginepowered.com/ https://use.typekit.net/ 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com https://static.olark.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net https://vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.bolt.com *.punchout2go.com https://*.olark.com https://forms.hsforms.com https://testsecureacceptance.cybersource.com https://secureacceptance.cybersource.com https://bam.nr-data.net https://www.google-analyitics.com https://stats.g.doubleclick.net https://*.hubspot.com https://pro.ip-api.com https://*.cardinalcommerce.com https://*.google.com https://*.clarity.ms https://*.hscollectedforms.net https://*.googleapis.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.googleapis.com thm.visa.com 3dsapi.ebizcharge.net kg668dbov0.execute-api.us-east-1.amazonaws.com ebizcharge3ds-staging1.azurewebsites.net *.ebizcharge.net https://songbird.cardinalcommerce.com https://centinelapi.cardinalcommerce.com https://cdnjs.cloudflare.com https://insight.adsrvr.org/ https://dpm.demdex.net https://amcglobal.sc.omtrdc.net https://geostag.cardinalcommerce.com https://geo.cardinalcommerce.com https://centinelapistag.cardinalcommerce.com https://analytics.google.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri https://*.clarity.ms https://*.google-analytics.com 'self' 'unsafe-inline'; 2 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://www.googletagmanager.com *.googleapis.com *.fontawesome.com https://fonts.bunny.net *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com airwallex.com *.airwallex.com google.com *.google.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com checkout.airwallex.com checkout-demo.airwallex.com h.online-metrix.net/ static-demo.airwallex.com pci-api-demo.airwallex.com demo-pacybsmock.airwallex.com imgs.signifyd.com airwallex.com *.airwallex.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net google.com validator.swagger.io *.online-metrix.net/ checkout.airwallex.com imgs.signifyd.com checkout-demo.airwallex.com airwallex.com *.airwallex.com *.google.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.gstatic.com *.googleapis.com https://firebasestorage.googleapis.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com checkout.airwallex.com checkout-demo.airwallex.com h.online-metrix.net/ static-demo.airwallex.com static.airwallex.com cdn-scripts.signifyd.com bws-demo.airwallex.com bws.airwallex.com imgs.signifyd.com h64.online-metrix.net airwallex.com *.airwallex.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com tagmanager.google.com https://www.googletagmanager.com *.googleapis.com *.gstatic.com widget.freshworks.com m2epro.freshdesk.com https://cdn.jsdelivr.net *.avada.io *.shopify.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com assets.braintreegateway.com https://www.googletagmanager.com tagmanager.google.com *.googleapis.com widget.freshworks.com m2epro.freshdesk.com *.fontawesome.com https://fonts.bunny.net *.stripe.network *.stripecdn.com *.amazon.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com checkout.airwallex.com checkout-demo.airwallex.com h.online-metrix.net/ bws-demo.airwallex.com bws.airwallex.com api-demo.airwallex.com api.airwallex.com imgs.signifyd.com airwallex.com *.airwallex.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com https://www.google-analytics.com https://*.google-analytics.com https://*.analytics.google.com *.googleapis.com widget.freshworks.com m2epro.freshdesk.com https://get.geojs.io *.avada.io *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com 'self' 'unsafe-inline'; child-src airwallex.com *.airwallex.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src airwallex.com *.airwallex.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 script-src 'unsafe-inline' 'unsafe-eval' blob: data: https://googleads.g.doubleclick.net/pagead/viewthroughconversion/ https://payments.google.com/payments/v4/js/integrator.js https://payments.sandbox.google.com/payments/v4/js/integrator.js https://translate.google.com/translate_a/element.js https://www.google-analytics.com/analytics.js https://www.google-analytics.com/gtm/js https://www.googleadservices.com/pagead/conversion/ https://www.youtube.com/iframe_api https://youtube.googleapis.com/s/player/ https://youtube.googleapis.com/iframe_api https://ssl.gstatic.com/support/realtime/operator/ https://www.gstatic.com/_/mss/boq-one-google/_/ https://www.gstatic.com/og/_/js/ https://apis.google.com/js/api.js https://apis.google.com/js/client.js https://maps.googleapis.com/maps/api/js https://www.google.com/tools/feedback/chat_load.js https://www.google.com/tools/feedback/help_api.js https://www.google.com/tools/feedback/load.js https://www.google.com/tools/feedback/open.js https://www.google.com/tools/feedback/open_to_help_guide_lazy.js https://www.gstatic.com/feedback/js/ https://www.gstatic.com/feedback/js/help/prod/service/lazy.min.js https://www.gstatic.com/inproduct_help/api/main.min.js https://www.gstatic.com/inproduct_help/chatsupport/chatsupport_button_v2.js https://www.gstatic.com/inproduct_help/service/lazy.min.js https://www.gstatic.com/uservoice/feedback/client/web/live/ https://www.gstatic.com/uservoice/surveys/resources/prod/js/survey/ https://www.google.com/js/bg/ https://www.googletagmanager.com/gtag/js https://www.googletagmanager.com/gtag/destination https://www.gstatic.com/_/mss/boq-gstore/_/js/k=boq-gstore.Gstore.en_US.5mqGEbHarwA.2021.O/ https://apis.google.com/_/scs/abc-static/_/js/ https://maps.googleapis.com/maps-api-v3/api/js/ https://maps.googleapis.com/maps/vt https://maps.googleapis.com/maps/api/js/ https://maps.googleapis.com/maps/api/place/js/ https://www.youtube.com/s/player/ https://translate.googleapis.com/_/translate_http/_/js/ https://payments.youtube.com/payments/v4/js/integrator.js https://payments.cloud.google/payments/v4/js/integrator.js;report-uri /_/Gstore/cspreport/fine-allowlist 2 require-trusted-types-for 'script'; report-uri https://csp.withgoogle.com/csp/uxe-owners-acl/verily 2 script-src 'self' 'unsafe-inline' 'unsafe-eval' https: data:; connect-src 'self' wss: https:; style-src 'self' 'unsafe-inline' data: https:; frame-src 'self' https://batmaid.prismic.io https://*.trustpilot.com https://vars.hotjar.com https://*.google.com https://www.facebook.com https://*.doubleclick.net https://tpc.googlesyndication.com https://www.youtube.com https://pay.datatrans.com https://3dsec.cardcenter.ch https://acs1.viseca.ch https://acs.touch.tech https://www.instagram.com https://www.googletagmanager.com https://consentcdn.cookiebot.com data:; frame-ancestors 'self'; form-action 'self' https://pay.datatrans.com https://www.facebook.com; object-src 'none'; upgrade-insecure-requests; report-uri /en/api/v1/csp-violation-report 2 font-src *.sagepay.com *.yotpo.com *.googleapis.com *.gstatic.com www.partstown.co.uk data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.sagepay.com *.facebook.com *.yotpo.com www.partstown.co.uk 'self' 'unsafe-inline'; frame-ancestors www.partstown.co.uk 'self'; frame-src fast.amc.demdex.net *.adobe.com secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.adyen.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com *.sagepay.com *.weltpixel.com *.yotpo.com www.partstown.co.uk 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.adyen.com maps.googleapis.com maps.gstatic.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com *.paypal.com *.sagepay.com validate.fishpig.co.uk *.gstatic.com *.facebook.com *.yotpo.com www.partstown.co.uk data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.adyen.com maps.googleapis.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com cdn.dnky.co webchat.dotdigital.com chimpstatic.com downloads.mailchimp.com *.list-manage.com *.sagepay.com https://www.googletagmanager.com tagmanager.google.com analytics.google.com *.facebook.net *.yotpo.com www.partstown.co.uk https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com cdn.dnky.co webchat.dotdigital.com downloads.mailchimp.com *.sagepay.com tagmanager.google.com *.yotpo.com *.googleapis.com www.partstown.co.uk 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.partstown.co.uk 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com *.paypal.com *.sagepay.com *.google-analytics.com analytics.google.com *.facebook.net https://www.google-analytics.com *.yotpo.com www.partstown.co.uk 'self' 'unsafe-inline'; child-src www.partstown.co.uk http: https: blob: 'self' 'unsafe-inline'; default-src www.partstown.co.uk 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 font-src *.typekit.net *.gstatic.com fonts.gstatic.com use.typekit.net maxcdn.bootstrapcdn.com 'self' data: *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.weltpixel.com www.facebook.com platform.twitter.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.wesupply.xyz https://wesupplylabs.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com p.typekit.net validator.swagger.io ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com www.facebook.com pinterest.com assets.pinterest.com syndication.twitter.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com maps.googleapis.com *.hsforms.net *.hsforms.com 'self' data: *.cdninstagram.com *.fbcdn.net *.google.co.in *.sansha.com *.magento2.sansha.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.commerce-payment-services.com *.typekit.net google.com *.google.com assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.chimpstatic.com downloads.mailchimp.com *.list-manage.com widget.freshworks.com m2epro.freshdesk.com connect.facebook.net twitter.com platform.twitter.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googleadservices.com *.google-analytics.com *.doubleclick.net *.googletagmanager.com *.cardinalcommerce.com *.ccdc02.com *.paypalobjects.com *.ytimg.com *.googleapis.com *.vimeo.eu *.vimeo.com *.gstatic.com *.omtrdc.net *.mailchimp.com *.braintreegateway.com *.packeta.com *.app-wallee.com *.cdek.ru *.chronopost.fr *.authorize.net *.stripe.com *.hsforms.net *.hsforms.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.cloudflare.com *.instagram.com maps.googleapis.com klarna.com ajax.googleapis.com https://www.googletagmanager.com tagmanager.google.com embed.tawk.to *.tawk.to *.jsdelivr.net www.gstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com downloads.mailchimp.com widget.freshworks.com m2epro.freshdesk.com maxcdn.bootstrapcdn.com assets.braintreegateway.com *.googleapis.com *.gstatic.com tagmanager.google.com embed.tawk.to *.tawk.to *.jsdelivr.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.cdninstagram.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.paypal.com google.com *.google.com *.adobe.io performance.typekit.net *.sentry.io widget.freshworks.com m2epro.freshdesk.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com https://www.google-analytics.com *.instagram.com *.googleusercontent.com embed.tawk.to *.tawk.to *.jsdelivr.net vsa104.tawk.to vsa94.tawk.to vsa79.tawk.to 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 worker-src blob:; font-src https://*.yotpo.com https://use.typekit.net https://netdna.bootstrapcdn.com 'self' data: *.googleapis.com https://www.gstatic.com *.kodaris.com *.amazonaws.com https://fonts.gstatic.com *.fontawesome.com https://fonts.bunny.net *.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com https://forms.hsforms.com https://www.google.com https://www.gstatic.com *.tradecentric.com 'self' data: *.cenpos.net *.cenpos.com *.google.com *.gstatic.com *.cardinalcommerce.com *.punchout2go.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.sharethis.com https://forms.hsforms.com *.google.com *.duosecurity.com *.creditkey.com https://www.socialintents.com *.tradecentric.com *.cenpos.net *.cenpos.com *.gstatic.com *.cardinalcommerce.com *.punchout2go.com https://*.google.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com blob: c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.paypal.com * *.wesupply.xyz https://wesupplylabs.com *.weltpixel.com https://*.online-metrix.net https://imgs.signifyd.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' blob: data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.sharethis.com https://*.hsforms.com https://www.google.com https://www.gstatic.com https://*.yotpo.com https://amcglobal.sc.omtrdc.net https://*.punchout2go.com https://hanes.resultspage.com https://empirerigging.resultspage.com https://assets.resultspage.com https://hanes.resultsdemo.com https://empirerigging.resultsdemo.com https://creditkey-assets.s3-us-west-2.amazonaws.com https://*.hanessupply.com https://*.empirerigging.com https://forms.hsforms.com https://track.hubspot.com www.google.de/ads/ga-audiences *.cenpos.net *.cenpos.com *.googleapis.com https://*.gstatic.com *.kodaris.com *.amazonaws.com *.monsido.com bat.bing.com https://*.google.com https://*.googleapis.com https://*.googleusercontent.com https://coc.codes/images/badge/41497493 https://d10lpsik1i8c69.cloudfront.net *.shopperapproved.com https://firebasestorage.googleapis.com store.paradoxlabs.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.hsforms.net *.hsforms.com 'self' data: *.gstatic.com *.facebook.com *.reddit.com https://imgs.signifyd.com https://*.online-metrix.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.sharethis.com https://js.hsforms.net https://cdn.jsdelivr.net https://www.googletagmanager.com https://www.google.com https://ajax.googleapis.com https://www.gstatic.com https://*.yotpo.com https://*.newrelic.com https://*.demdex.net https://*.aptrinsic.com https://*.nr-data.net https://hanes.resultspage.com https://empirerigging.resultspage.com https://hanes.resultsdemo.com https://empirerigging.resultsdemo.com https://unpkg.com https://www.socialintents.com https://*.g.doubleclick.net *.tradecentric.com https://js.hs-scripts.com https://js.hs-banner.com https://js.hs-analytics.net https://*.hscollectedforms.net *.cenpos.com *.cenpos.net *.google.com *.gstatic.com *.cardinalcommerce.com *.googleapis.com https://*.gstatic.com *.kodaris.com *.amazonaws.com *.monsido.com *.punchout2go.com bat.bing.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com https://polyfill-fastly.io https://d10lpsik1i8c69.cloudfront.net *.hubspot.com https://cdn-in.pagesense.io/js/innopplitservices/51b88749fcca40fbbdf7fef19d4c664d.js https://static.zohocdn.com *.shopperapproved.com *.avada.io *.shopify.com *.authorize.net js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.hsforms.net *.hsforms.com *.cloudflare.com tagmanager.google.com *.facebook.net *.redditstatic.com *.reddit.com unpkg.com https://cdn-scripts.signifyd.com https://imgs.signifyd.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.sharethis.com https://www.google.com https://www.gstatic.com https://*.yotpo.com https://*.aptrinsic.com https://hanes.resultspage.com https://empirerigging.resultspage.com https://hanes.resultsdemo.com https://empirerigging.resultsdemo.com https://*.typekit.net https://www.socialintents.com https://netdna.bootstrapcdn.com *.tradecentric.com 'self' data: fonts.googleapis.com *.kodaris.com *.gstatic.com *.googleapis.com *.amazonaws.com *.jsdelivr.net *.punchout2go.com https://fonts.googleapis.com https://hcaptcha.com https://*.hcaptcha.com https://d10lpsik1i8c69.cloudfront.net https://static.zohocdn.com *.fontawesome.com https://fonts.bunny.net unsafe-inline assets.braintreegateway.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com https://d10lpsik1i8c69.cloudfront.net 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.sharethis.com https://forms.hsforms.com *.amazonaws.com https://*.yotpo.com https://*.demdex.net https://*.aptrinsic.com https://www.google-analytics.com https://*.g.doubleclick.net https://*.punchout2go.com https://maps.googleapis.com https://*.nr-data.net *.tradecentric.com https://forms.hscollectedforms.net *.googleapis.com *.kodaris.com *.monsido.com bat.bing.com https://ipinfo.io https://*.google.com https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com https://api.luckyorange.com https://settings.luckyorange.net https://pubsub.googleapis.com wss://visitors.live wss://*.visitors.live *.hubspot.com https://*.pagesense.io https://*.zoho.in https://get.geojs.io *.avada.io *.authorize.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com *.facebook.net *.redditstatic.com *.reddit.com *.doubleclick.net https://imgs.signifyd.com https://sirius-staging.atwixlabs.tech https://sirius.atwixlabs.tech 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 default-src 'self' 'unsafe-inline' 'unsafe-eval' blob: https://go.mufg-investorservices.com/ https://cdn.cookielaw.org https://cdn.bizible.com/ https://www.googletagmanager.com/ https://j.6sc.co/ https://snap.licdn.com/ https://munchkin.marketo.net/ https://www.google-analytics.com/ https://px.ads.linkedin.com/ https://ipv6.6sc.co/ https://b.6sc.co/ https://www.google.com https://c.6sc.co/ https://www.gstatic.com/ https://googleads.g.doubleclick.net https://static.smartrecruiters.com/ https://www.smartrecruiters.com/ https://www.buzzsprout.com/ https://www.youtube-nocookie.com/ https://geolocation.onetrust.com/ www.youtube.com https://privacyportal-eu.onetrust.com/ https://secure.adnxs.com/ https://www.googleadservices.com/ https://td.doubleclick.net/ https://epsilon.6sense.com/ https://427-brk-404.mktoresp.com/ youtu.be; img-src * 'self' data: blob:; font-src 'self' data:; 2 font-src *.fontawesome.com https://fonts.bunny.net https://www.ppl.cz/ fonts.gstatic.com maxcdn.bootstrapcdn.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com data: 'self' 'unsafe-inline'; form-action https://*.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ www.google.com *.weltpixel.com gate.gopay.cz gate.gopay.com gw.sandbox.gopay.com https://*.clic2buy.com https://*.doubleclick.net https://ehub.cz https://*.gls-czech.cz https://*.packeta.com/ https://*.heureka.cz/ https://*.heureka.sk/ https://*.googletagmanager.com https://*.facebook.com *.foxentry.cz widget.packeta.com backup.packeta.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com *.youtube.com https://images.unsplash.com https://firebasestorage.googleapis.com https://*.cdninstagram.com https://*.ppl.cz https://*.seznam.cz https://im9.cz https://*.google.cz https://*.google.sk https://*.google.de https://*.google.at https://*.google.pl https://*.google.nl https://*.google.hu https://*.facebook.com https://*.g.doubleclick.net https://*.mailkit.eu https://ehub.cz https://*.heureka.cz/ https://*.heureka.sk/ https://*.zbozi.cz https://*.bing.com https://*.clarity.ms/ https://bat.bing.net https://bat.bing.com https://*.analytics.google.com *.foxentry.cz flagpedia.net data: 'self' 'unsafe-inline'; script-src googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://maps.googleapis.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ https://scripts.luigisbox.tech https://cdn.luigisbox.tech https://live.luigisbox.tech https://api.luigisbox.tech *.avada.io gate.gopay.cz gate.gopay.com gw.sandbox.gopay.com https://*.clic2buy.com https://*.googletagmanager.com https://*.smartlook.com https://*.smartlook.cloud https://*.smartform.cz https://*.heureka.cz https://*.mailkit.eu https://*.google.cz/ https://*.google.sk https://*.google.de https://*.google.at https://*.google.pl https://*.google.nl https://*.google.hu https://*.seznam.cz https://*.dognet.sk https://ehub.cz https://*.facebook.net https://*.googleadservices.com https://*.google-analytics.com https://*.googleapis.com https://*.packeta.com/ https://*.zbozi.cz/ https://im9.cz/ https://*.clarity.ms/ https://bat.bing.com/ https://bat.bing.net/ https://cdn.heureka.group/ https://*.heureka.sk/ https://*.googlesyndication.com https://*.cdn-apple.com https://*.cloudfront.net *.foxentry.cz widget.packeta.com backup.packeta.com *.gstatic.com maps.googleapis.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src https://scripts.luigisbox.tech https://cdn.luigisbox.tech https://live.luigisbox.tech https://api.luigisbox.tech *.fontawesome.com https://fonts.bunny.net https://www.ppl.cz/ https://client.smartform.cz/ fonts.googleapis.com *.foxentry.cz maxcdn.bootstrapcdn.com *.gstatic.com *.stripe.network *.stripecdn.com *.amazon.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com https://maps.googleapis.com https://player.vimeo.com https://scripts.luigisbox.tech https://cdn.luigisbox.tech https://live.luigisbox.tech https://api.luigisbox.tech https://get.geojs.io *.avada.io https://*.ppl.cz https://*.smartlook.com https://*.smartlook.cloud https://*.mailkit.eu https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://*.google.com https://*.facebook.com https://*.g.doubleclick.net https://ehub.cz https://widget.packeta.com https://*.clarity.ms https://*.heureka.group https://bat.bing.net https://*.seznam.cz https://*.googlesyndication.com https://bat.bing.com https://*.stape.at *.foxentry.cz *.homecredit.cz *.homecredit.sk widget.packeta.com backup.packeta.com www.gstatic.com maps.googleapis.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 font-src fonts.gstatic.com fonts.googleapis.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com https://seo.mageplaza.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ https://www.googletagmanager.com/ *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.bing.com *.google-analytics.com *.googleadservices.com *.google.co.uk *.googletagmanager.com *.expressentry.melissadata.net *.paypalobjects.com *.ometria.services *.feefo.com *.adobedtm.com *.facebook.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ *.ometria.com *.klarna.com *.klarnaevt.com *.klarnacdn.net https://firebasestorage.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.bing.com *.google-analytics.com *.googletagmanager.com googleadservices.com *.googleapis.com expressentry.melissadata.net *.paypalobjects.com *.ometria.services *.noibu.com https://www.noibu.com https://cdn.noibu.com *.facebook.net https://cdn.jsdelivr.net http://www.googletagmanager.com/ https://www.googletagmanager.com/ *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com *.dixa.io x.klarnacdn.net *.klarnaservices.com *.avada.io *.shopify.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com songbird.cardinalcommerce.com https://api.ometria.com *.ometria.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.googleapis.com fonts.googleapis.com *.stripe.network *.stripecdn.com *.amazon.com *.klarnacdn.net *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.bing.com *.bing.net *.google-analytics.com *.googletagmanager.com *.googlesyndication.com *.googleapis.com maps.googleapis.com *.expressentry.melissadata.net *.paypalobjects.com *.ometria.services *.advancedcommerce.services *.algolia.net https://cdn.noibu.com wss://input.noibu.com https://input.noibu.com *.noibu.com https://cdn.jsdelivr.net http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.dixa.io x.klarnacdn.net *.klarnaservices.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com https://api.ometria.com *.ometria.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 default-src 'self'; script-src 'self'; style-src 'self' 'unsafe-inline'; img-src 'self' data:; report-uri /api/csp-report 2 default-src * 'unsafe-inline' 'unsafe-eval' data: blob:; report-uri https://0594ebf9e3dab534acdba65c6100b639.report-uri.com/r/d/csp/reportOnly; 2 font-src https://www.googletagmanager.com *.googleapis.com *.gstatic.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com fonts.gstatic.com cdn.lineicons.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://seo.mageplaza.com 'self' 'unsafe-inline'; frame-ancestors 'self' *.maksekeskus.ee *.test.maksekeskus.ee 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ 'self' *.maksekeskus.ee *.test.maksekeskus.ee www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.doubleclick.net *.googletagmanager.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.gstatic.com *.googleapis.com *.maksekeskus.ee *.test.maksekeskus.ee www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://firebasestorage.googleapis.com https://www.terminalmappingjs.com https://osm.venipak.com http://mano.venipak.lt *.googletagmanager.com *.google-analytics.com ssl.gstatic.com www.gstatic.com *.nsking.com *.nsking.lv nsking.lv nsking.ee nsking.fi nsking.lt *.nsking.lt *.nsking.fi *.nsking.ee *.google.de *.google.ee data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ tagmanager.google.com https://www.googletagmanager.com *.googleapis.com *.gstatic.com 'self' *.maksekeskus.ee *.test.maksekeskus.ee data: www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.avada.io *.shopify.com *.fontawesome.com https://unpkg.com cdn.ampproject.org www.gstatic.com *.googletagmanager.com *.google.com maps.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://www.googletagmanager.com tagmanager.google.com *.googleapis.com fonts.googleapis.com *.fontawesome.com https://fonts.bunny.net https://unpkg.com www.gstatic.com maxcdn.bootstrapcdn.com fonts.google.com cdn.lineicons.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://www.google-analytics.com https://*.google-analytics.com https://*.analytics.google.com *.googleapis.com 'self' *.maksekeskus.ee *.test.maksekeskus.ee www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://get.geojs.io *.avada.io https://www.terminalmappingjs.com https://geocode.arcgis.com cdn.ampproject.org www.googleapis.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com *.doubleclick.net *.google.com maps.google.com maps.googleapis.com google-analytics.com 'self' 'unsafe-inline'; child-src 'self' *.maksekeskus.ee *.test.maksekeskus.ee http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 font-src fonts.gstatic.com use.typekit.net *.fontawesome.com *.gstatic.com 'self' data: data: surveys-static.survicate.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ cdn.dnky.co amc.demdex.net www.google.com www.facebook.com youtube.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net 'self' data: maps.gstatic.com maps.googleapis.com accounts.google.com www.facebook.com www.google.com.co js.intercomcdn.com intercomassets.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net amcglobal.sc.omtrdc.net commerce.adobe.net use.typekit.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-ds.com https://www.google.com *.gstatic.com cdn.dnky.co r1-t.trackedlink.net www.gstatic.com js-agent.newrelic.com bam.nr-data.net maps.googleapis.com connect.facebook.net player.vimeo.com https://maps.googleapis.com *.snrbox.com static.hotjar.com *.clarity.ms surveys-static.survicate.com script.hotjar.com widget.intercom.io js.intercomcdn.com api-iam.intercom.io 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com *.googleapis.com *.gstatic.com cdn.dnky.co *.googletagmanager.com *.cookielaw.org *.snrcdn.net https://surveys-static.survicate.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io commerce.adobe.net qa-api.magedevteam.com *.sentry.io *.synerise.com t.elasticsuite.io *.google-analytics.com maps.googleapis.com api.comapi.com bam.nr-data.net *.cookielaw.org *.snrbox.com t.clarity.ms stats.g.doubleclick.net api-iam.intercom.io wss://nexus-websocket-a.intercom.io wss://ws.hotjar.com https://content.hotjar.io 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 default-src 'self'; script-src 'self' 'unsafe-eval' 'unsafe-inline' https://connect.facebook.net https://*.hotjar.com https://*.clarity.ms https://snap.licdn.com https://widget.tabnav.com https://www.google-analytics.com https://www.googletagmanager.com https://analytics.synaxon.com https://stackpath.bootstrapcdn.com https://*.gstatic.com https://*.adform.net https://*.google.com https://www.youtube.com https://*.googlesyndication.com https://*.twitter.com; style-src 'self' 'unsafe-inline' https://*.gstatic.com https://stackpath.bootstrapcdn.com; img-src 'self' data: 'self' data: https: https://*.gstatic.com https://px.ads.linkedin.com https://widgets.kununu.com https://www.facebook.com https://*.google.com https://www.googletagmanager.com; font-src 'self' data: https://*.gstatic.com https://static2.sharepointonline.com https://*.wp.com; connect-src 'self' https://px.ads.linkedin.com https://region1.google-analytics.com https://*.google.com https://www.googletagmanager.com https://www.youtube-nocookie.com https://*.clarity.ms https://analytics.synaxon.com https://web-api.synaxon.de https://www.facebook.com https://www.google-analytics.com https://region1.analytics.google.com https://*.adform.net https://stats.g.doubleclick.net https://www.googleadservices.com https://*.hotjar.io https://analytics.google.com https://*.googlesyndication.com https://widget-config.tabnav.com; media-src 'self'; frame-src https://www.youtube-nocookie.com https://player.vimeo.com https://*.google.com https://www.googletagmanager.com https://www.youtube.com; worker-src 'self' blob:; object-src 'none'; base-uri 'self'; report-uri /csp-report-endpoint; 2 default-src 'self' f24.com *.f24.com; upgrade-insecure-requests; report-uri https://0ze76053.uriports.com/reports/report; report-to csp-endpoint; manifest-src 'self'; script-src https://www.googletagmanager.com https://tagmanager.google.com https://*.googletagmanager.com googleads.g.doubleclick.net cdn.cookielaw.org cookie-cdn.cookiepro.com *.onetrust.com snap.licdn.com j.6sc.co https://pi.pardot.com https://www.youtube-nocookie.com https://www.youtube.com 'self' f24.com *.f24.com 'unsafe-inline'; style-src https://googletagmanager.com https://tagmanager.google.com https://fonts.googleapis.com cdn.cookielaw.org cookie-cdn.cookiepro.com *.onetrust.com https://www.youtube-nocookie.com https://www.youtube.com 'self' f24.com *.f24.com 'unsafe-inline'; media-src fact24.com 'self' f24.com *.f24.com; img-src fact24.com www.googletagmanager.com https://ssl.gstatic.com https://www.gstatic.com https://*.google-analytics.com https://*.googletagmanager.com www.google.com www.google.hr www.google.fr www.google.no www.google.ch www.google.lu www.google.de www.google.at googleads.g.doubleclick.net cdn.cookielaw.org px.ads.linkedin.com b.6sc.co img.youtube.com img.youtube-nocookie.com data: 'self' f24.com *.f24.com; frame-src https://www.googletagmanager.com https://www.youtube-nocookie.com https://www.youtube.com www.tfaforms.com f24.jobs.personio.de 'self' f24.com *.f24.com; font-src https://fonts.gstatic.com data: 'self' f24.com *.f24.com; connect-src www.googletagmanager.com www.google.com https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com www.googleadservices.com pagead2.googlesyndication.com cdn.cookielaw.org geolocation.onetrust.com privacyportal-eu.onetrust.com px.ads.linkedin.com ipv6.6sc.co c.6sc.co epsilon.6sense.com https://www.youtube-nocookie.com https://www.youtube.com noembed.com 'self' f24.com *.f24.com; frame-ancestors 'none'; 2 Content-Security-Policy-Report-Only: default-src * 'unsafe-inline' 'unsafe-eval'; style-src 'unsafe-inline'; script-src 'none' 'report-sample'; connect-src 'none'; form-action 'none'; frame-src 'none'; worker-src 'none'; frame-ancestors 'none'; upgrade-insecure-requests; block-all-mixed-content; report-uri https://csp.threatview.app/report; report-to threatview 2 font-src *.fontawesome.com https://fonts.bunny.net *.gstatic.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.clover.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ js.mollie.com *.clover.com *.hsforms.com *.doubleclick.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://images.unsplash.com store.paradoxlabs.com https://firebasestorage.googleapis.com https://www.mollie.com *.clover.com 'self' data: *.hsforms.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://maps.googleapis.com *.avada.io js.mollie.com *.clover.com *.google.com *.gstatic.com *.hsforms.com *.hsforms.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.fontawesome.com https://fonts.bunny.net *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://maps.googleapis.com https://player.vimeo.com https://get.geojs.io *.avada.io t.elasticsuite.io *.google-analytics.com *.hsforms.com *.doubleclick.net 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 default-src 'self' *.my127.site blob: *.my127.site inviqa.com inviqa.de youtube.com *.doubleclick.net *.google.com *.googleadservices.com *.google.co.uk *.hubspot.com *.trackedweb.net *.hotjar.com madixel.de cdn.cookielaw.org geolocation.onetrust.com; script-src 'self' 'unsafe-inline' blob: *.googleapis.com 'unsafe-eval' *.my127.site inviqa.com inviqa.de *.googletagmanager.com *.google-analytics.com *.doubleclick.net *.hotjar.com *.gstatic.com *.hs-scripts.com *.hs-banner.com *.hscollectedforms.net *.hs-analytics.net *.licdn.com *.twitter.com *.trackedweb.net *.trackedlink.net madixel.de *.googleadservices.com *.ads-twitter.com cdn.cookielaw.org; style-src 'self' 'unsafe-inline' *.my127.site inviqa.com inviqa.de; img-src 'self' *.my127.site data: inviqa.com inviqa.de *.google.co.uk *.google.com *.google-analytics.com *.twitter.com *.linkedin.com t.co *.hubspot.com *.hsforms.com *.doubleclick.net cdn.cookielaw.org; frame-src *; frame-ancestors 'self'; child-src *; font-src 'self' *.my127.site data: inviqa.com inviqa.de; report-uri https://www.inviqa.report-uri.com/r/d/csp/reportOnly; upgrade-insecure-requests 2 font-src www.paypalobjects.com *.gstatic.com widget.trustpilot.com t4.my-probance.one *.aplazame.com *.zendesk.com *.adobedtm.com *.adobe.com *.authorize.net *.braintreegateway.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cetelem.es *.livechatinc.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.youtube.com *.youtube-nocookie.com player.vimeo.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com https://www.google.com/recaptcha/ *.avis-verifies.com/ widget.trustpilot.com t4.my-probance.one *.aplazame.com *.zendesk.com *.adobedtm.com *.adobe.com *.authorize.net *.braintreegateway.com *.googletagmanager.com *.google.com sandbox.sequracdn.com live.sequracdn.com sandbox.sequrapi.com live.sequrapi.com live.cdn.sequra.svea.com next-live.sequra.svea.com live.sequra.svea.com sandbox.cdn.sequra.svea.com next-sandbox.sequra.svea.com sandbox.sequra.svea.com *.livechatinc.com *.weltpixel.com 'self' 'unsafe-inline'; img-src data: widgets.magentocommerce.com *.vimeocdn.com i.ytimg.com *.youtube.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com validator.swagger.io *.cetelem.es cdn.doofinder.com *.google.com *.youtube.com/ widget.trustpilot.com t4.my-probance.one *.aplazame.com *.zendesk.com *.adobedtm.com *.adobe.com *.authorize.net *.braintreegateway.com sandbox.sequracdn.com live.sequracdn.com sandbox.sequrapi.com live.sequrapi.com live.cdn.sequra.svea.com next-live.sequra.svea.com live.sequra.svea.com sandbox.cdn.sequra.svea.com next-sandbox.sequra.svea.com sandbox.sequra.svea.com *.livechatinc.com imgsct.cookiebot.com *.gstatic.com *.facebook.com data: 'self' 'unsafe-inline'; script-src geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com/ www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.cetelem.es cdn.doofinder.com *.googletagmanager.com *.cdn.cookielaw.org/ widget.trustpilot.com t4.my-probance.one *.aplazame.com *.zendesk.com *.adobedtm.com *.adobe.com *.authorize.net *.braintreegateway.com sandbox.sequracdn.com live.sequracdn.com sandbox.sequrapi.com live.sequrapi.com live.cdn.sequra.svea.com next-live.sequra.svea.com live.sequra.svea.com sandbox.cdn.sequra.svea.com next-sandbox.sequra.svea.com sandbox.sequra.svea.com *.livechatinc.com *.tradedoubler.com consent.cookiebot.com https://widgets.rr.skeepers.io/ https://api-product-reviews.cxr.skeepers.io/ https://cl-ppr.rr.skeepers.io/ https://cl-pbr.cxr.skeepers.io/ https://www.googletagmanager.com tagmanager.google.com analytics.google.com *.facebook.net unpkg.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.cetelem.es *.doofinder.com *.googleapis.com widget.trustpilot.com t4.my-probance.one *.aplazame.com *.zendesk.com *.adobedtm.com *.adobe.com *.authorize.net *.braintreegateway.com *.fontawesome.com *.livechatinc.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.cetelem.es *.doofinder.com wss://*.doofinder.com *.googletagmanager.com *.cdn.cookielaw.org/ *.youtube.com/ widget.trustpilot.com t4.my-probance.one *.aplazame.com *.zendesk.com *.adobedtm.com *.adobe.com *.authorize.net *.braintreegateway.com sandbox.sequracdn.com live.sequracdn.com sandbox.sequrapi.com live.sequrapi.com live.cdn.sequra.svea.com next-live.sequra.svea.com live.sequra.svea.com sandbox.cdn.sequra.svea.com next-sandbox.sequra.svea.com sandbox.sequra.svea.com *.livechatinc.com https://widgets.rr.skeepers.io/ https://api-product-reviews.cxr.skeepers.io/ https://cl-ppr.rr.skeepers.io/ https://cl-pbr.cxr.skeepers.io/ *.google-analytics.com analytics.google.com *.facebook.net 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 default-src * 'unsafe-inline' 'unsafe-eval'; style-src 'unsafe-inline'; script-src 'none' 'report-sample'; connect-src 'none'; form-action 'none'; frame-src 'none'; worker-src 'none'; frame-ancestors 'none'; upgrade-insecure-requests; block-all-mixed-content; report-uri https://csp.threatview.app/report; 2 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com *.saferpay.com https://v2.zopim.com/widget/fonts/ 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com api.broadmail.de test.saferpay.com www.saferpay.com saferpay.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com test.saferpay.com www.saferpay.com saferpay.com * https://js.stripe.com/ https://www.googletagmanager.com/ www.google.com bat.bing.com bat.bing.net *.stape.net *.doubleclick.net 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://api.mapbox.com test.saferpay.com www.saferpay.com saferpay.com *.saferpay.com api.mapbox.com https://v2.zopim.com/widget/images/avatar_simple_visitor.png stats.g.doubleclick.net px.ads.linkedin.com https://www.google.com/pagead/ https://www.google.de/pagead/ https://www.google.com/ads/ https://www.google.de/ads/ t23.intelliad.de bat.bing.com bat.bing.net *.facebook.com *.cookiefirst.com *.udo.solutions *.hsforms.net *.hsforms.com 'self' data: data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com test.saferpay.com www.saferpay.com saferpay.com *.saferpay.com https://js.stripe.com/v3/ https://www.googletagmanager.com/gtm.js https://www.google.com/recaptcha/api.js www.gstatic.com v2.zopim.com https://static.zdassets.com/ekr/asset_composer.js js-agent.newrelic.com https://snap.licdn.com/li.lms-analytics/insight.min.js https://googleads.g.doubleclick.net/pagead/viewthroughconversion/927165981 bam.eu01.nr-data.net bat.bing.com bat.bing.net *.googletagmanager.com *.facebook.net *.cookiefirst.com *.udo.solutions *.intelliad.de *.usercentrics.eu *.doubleclick.net *.hsforms.net *.hsforms.com *.gstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com *.cookiefirst.com *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com test.saferpay.com www.saferpay.com saferpay.com *.saferpay.com wss://widget-mediator.zopim.com/ https://ekr.zdassets.com/compose/zopim_chat/ https://bam.eu01.nr-data.net/events/ ka-f.fontawesome.com https://www.google.com/ccm/ bat.bing.com bat.bing.net stats.g.doubleclick.net *.stape.net *.cookiefirst.com *.udo.solutions autocomplete2.postdirekt.de t.elasticsuite.io *.hsforms.net *.hsforms.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src test.saferpay.com www.saferpay.com saferpay.com *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 default-src https: data: wss: 'unsafe-inline' 'unsafe-eval'; form-action https:; report-uri https://ggj3qf05xeualpl0weo7xdrg.httpschecker.net/report 2 font-src *.googleapis.com *.gstatic.com data: https://www.googletagmanager.com *.klevu.com *.ksearchnet.com *.fontawesome.com fonts.gstatic.com *.yotpo.com use.fontawesome.com maxcdn.bootstrapcdn.com dhv2ziothpgrr.cloudfront.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.adyen.com yotpo.com *.yotpo.com swellrewards.com *.swellrewards.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net https://www.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.adyen.com www.google.com *.dotdigital-pages.com *.dotdigital.com webchat.dotdigital.com webchat.staging.dotdigital.com https://www.googletagmanager.com/ *.google.com/ https://cdn.lightwidget.com/ yotpo.com *.cookiebot.com *.yotpo.com swellrewards.com *.swellrewards.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.adyen.com *.gstatic.com *.googleapis.com *.trackedlink.net https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ magefan.com cm.magefan.com https://www.magezon.com https://*.unifaun.com yotpo.com *.cookiebot.com *.yotpo.com swellrewards.com *.swellrewards.com dhv2ziothpgrr.cloudfront.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.adyen.com *.googleapis.com *.gstatic.com tagmanager.google.com https://www.googletagmanager.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal webchat.dotdigital.com webchat.staging.dotdigital.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ js.klevu.com *.ksearchnet.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ *.google.com/ yotpo.com *.cookiebot.com *.yotpo.com swellrewards.com *.swellrewards.com dhv2ziothpgrr.cloudfront.net *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com d18eg7dreypte5.cloudfront.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://www.googletagmanager.com tagmanager.google.com *.googleapis.com webchat.dotdigital.com webchat.staging.dotdigital.com https://static.klaviyo.com *.klevu.com *.ksearchnet.com *.fontawesome.com *.yotpo.com yotpo.com swellrewards.com *.swellrewards.com maxcdn.bootstrapcdn.com dhv2ziothpgrr.cloudfront.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adyen.com *.googleapis.com https://www.google-analytics.com https://*.google-analytics.com https://*.analytics.google.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ yotpo.com *.cookiebot.com *.google-analytics.com *.googlesyndication.com *.yotpo.com swellrewards.com *.swellrewards.com dhv2ziothpgrr.cloudfront.net *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 policy 2 font-src *.googleapis.com *.gstatic.com *.stape.io maxcdn.bootstrapcdn.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.paymentexpress.com *.windcave.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com https://plumrocket.com 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net https://www.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.stape.io *.google.com/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com *.paymentexpress.com *.windcave.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * https://plumrocket.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.googleapis.com *.gstatic.com https://www.magezon.com https://edge.marker.io *.marker.io *.google-analytics.com *.googleadservices.com *.googletagmanager.com *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.doubleclick.net *.stape.io www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.googleapis.com *.gstatic.com https://edge.marker.io *.marker.io *.marketo.net *.mktoresp.com *.google-analytics.com *.googleadservices.com *.googletagmanager.com *.google.com/ s7.addthis.com *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.doubleclick.net *.stape.io player.vimeo.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.cloudflare.com *.google-analytics.com *.googleadservices.com *.gstatic.com *.googletagmanager.com *.google.com *.stape.io maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com *.stripe.network *.stripecdn.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.googleapis.com https://edge.marker.io *.marker.io *.marketo.net *.mktoresp.com *.google-analytics.com *.googleadservices.com *.gstatic.com *.googletagmanager.com *.google.com ekr.zdassets.com/ *.doubleclick.net *.googlesyndication.com *.stape.io www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 font-src *.cloudflare.com *.bootstrapcdn.com data: maxcdn.bootstrapcdn.com fonts.gstatic.com 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es test.saferpay.com www.saferpay.com saferpay.com yotpo.com www.yotpo.com p.yotpo.com staticw2.yotpo.com w2.yotpo.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com test.saferpay.com www.saferpay.com saferpay.com tradingview-widget.com www.googletagmanager.com *.tradingview-widget.com www.google.com www.facebook.com platform.twitter.com yotpo.com www.yotpo.com p.yotpo.com staticw2.yotpo.com w2.yotpo.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net data: www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com s.ytimg.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es test.saferpay.com www.saferpay.com saferpay.com img.youtube.com *.cloudflare.com www.goldvorsorge.at www.facebook.com pinterest.com assets.pinterest.com syndication.twitter.com amcglobal.sc.omtrdc.net yotpo.com www.yotpo.com p.yotpo.com staticw2.yotpo.com w2.yotpo.com 'self' 'unsafe-inline'; script-src assets.adobedtm.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com video.google.com vimeo.com www.vimeo.com www.youtube.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com cdn.dnky.co api.comapi.com webchat.dotdigital.com test.saferpay.com www.saferpay.com saferpay.com *.cloudflare.com *.twitter.com *.fontawesome.com www.googletagmanager.com www.google.com googleads.g.doubleclick.net stats.g.doubleclick.net pagead2.googlesyndication.com tpc.googlesyndication.com s3.tradingview.com s7.addthis.com *.avada.io connect.facebook.net twitter.com platform.twitter.com yotpo.com www.yotpo.com p.yotpo.com staticw2.yotpo.com w2.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src getfirebug.com cdn.dnky.co webchat.dotdigital.com *.cloudflare.com *.fontawesome.com *.bootstrapcdn.com maxcdn.bootstrapcdn.com yotpo.com www.yotpo.com p.yotpo.com staticw2.yotpo.com w2.yotpo.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es https://www.sandbox.paypal.com https://www.paypal.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com api.comapi.com webchat.dotdigital.com test.saferpay.com www.saferpay.com saferpay.com *.cloudflare.com www.google.com www.googletagmanager.com region1.google-analytics.com www.google-analytics.com ekr.zdassets.com/ yotpo.com www.yotpo.com p.yotpo.com staticw2.yotpo.com w2.yotpo.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src test.saferpay.com www.saferpay.com saferpay.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 2 report-uri /nelmio/csp/report 2 * 2 report-uri https://csp.withgoogle.com/csp/youtube_main/strict;base-uri 'self';object-src 'none';script-src 'report-sample' 'nonce-40qhmT0jB9h6Ft6HSvrq5w' 'unsafe-inline' 'strict-dynamic' https: http: 'unsafe-eval' 1 report-uri https://csp.withgoogle.com/csp/youtube_main/strict;base-uri 'self';object-src 'none';script-src 'report-sample' 'nonce-8BeqYISzlwjDOM1047Mtmw' 'unsafe-inline' 'strict-dynamic' https: http: 'unsafe-eval' 1 require-trusted-types-for 'script'; report-uri https://csp.withgoogle.com/csp/cacerts 1 require-trusted-types-for 'script'; report-uri https://csp.withgoogle.com/csp/uxe-owners-acl/www_google 1 style-src 'self' 'unsafe-inline' data: *.ebay.com *.ebaystatic.com *.ebaystatic.cn *.gstatic.com *.fontawesome.com blob: *.googleapis.com; connect-src 'self' *.ebay.com *.ebaystatic.com data: *.google-analytics.com *.doubleclick.net *.avalon.perfdrive.com *.ebayimg.com *.ucweb.com *.akamaihd.net *.ucads.ucweb.com *.analytics.google.com *.g.doubleclick.net *.googletagmanager.com *.pinterest.com *.snapchat.com *.criteo.com *.facebook.com *.googleapis.com *.googleadservices.com blob: analytics.google.com *.us.shoplive.cloud www.facebook.com *.bing.com www.googletagmanager.com google.com *.google.com *.graphitevault.com *.amplitude.com wss://127.0.0.1:* www.redditstatic.com *.reddit.com *.quantummetric.com; script-src 'self' 'unsafe-eval' 'unsafe-inline' https://* blob: data:; frame-ancestors 'self' *.ebay.com *.ebaystatic.com; img-src 'self' data: blob: https://*; default-src 'self' blob: data: wss: mediastream: https://*; report-uri https://monitor.ebay.com/csp-report/discoveryplatformweb/HomePage?id=2939504940913871808&rid=t6gludlscuzujfwciunrce00%3C%3Dgludlscuzujfwciunrce00%2Bee%3C%3F371d0.qctp01*mb%3Eq%60-19c35a7394d-0x604#pd 1 report-uri https://csp.withgoogle.com/csp/youtube_other/strict;base-uri 'self';object-src 'none';script-src 'report-sample' 'nonce-cD0AybuYWpdulYK1hAi_sw' 'unsafe-inline' 'strict-dynamic' https: http: 'unsafe-eval' 1 script-src 'self' 'unsafe-inline' 'unsafe-eval' 50339659.hs-sites.com 1003891.track.convertexperiments.com app.hubspot.com cdn-3.convertexperiments.com cdn-4.convertexperiments.com *.metrics.convertexperiments.com *.signals.convertexperiments.com logs.convertexperiments.com *.convertexperiments.com cdn.pdst.fm connect.facebook.net js.hs-analytics.net js.hs-banner.com js.hsforms.net js.hsleadflows.net js.hubspotfeedback.com js.usemessages.com play.vidyard.com script.hotjar.com snap.licdn.com static.hotjar.com static.hsappstatic.net www.google-analytics.com www.googletagmanager.com www.recaptcha.net code.highcharts.com www.youtube.com js.hubspot.com www.dropbox.com widget.altrulabs.com www.google.com maps.googleapis.com wt-assets.hubteam.com cdn2.hubspot.net www.redditstatic.com cdn.veritonic.com gosniply.com d.impactradius-event.com test.test.com js.hubspot.com analytics.tiktok.com 'strict-dynamic' 'nonce-lySWqSgBTczwZ0pZOW9dUA=='; report-uri https://send.hsbrowserreports.com/csp/report 1 default-src 'self'; script-src 'self' hubapi.com *.hubapi.com hubspot.com *.hubspot.com app.hubspot.com hubspotusercontent-na1.net *.hubspotusercontent-na1.net hsappstatic.net *.hsappstatic.net hs-banner.com *.hs-banner.com hsforms.com *.hsforms.com forms.hsforms.com *googletagmanager.com  https://munchkin.marketo.net https://snap.licdn.com *linkedin.com; 'unsafe-inline' https://trusted-cdn.com; style-src 'self' 'unsafe-inline'; img-src 'self' data: https:; font-src 'self' https:; connect-src 'self' forms.hscollectedforms.net *.hscollectedforms.net hubspot.com *.hubspot.com hubapi.com *.hubapi.com hsforms.com *.hsforms.com hsforms.net *.hsforms.net hsappstatic.net *.hsappstatic.net googletagmanager.com *.googletagmanager.com google-analytics.com *.google-analytics.com cdn.cookielaw.org *.cookielaw.org www.google.com analytics.google.com px.ads.linkedin.com *.linkedin.com; frame-ancestors 'none'; base-uri 'self'; object-src 'none'; upgrade-insecure-requests 1 script-src 'report-sample' 'nonce-kK-NGphwoL7MSFj_wpBo-w' 'unsafe-inline' 'unsafe-eval';object-src 'none';base-uri 'self';worker-src 'self';report-uri /us/_/BgcMiscSites/cspreport 1 default-src https://*.ft.com https: ; font-src https://*.ft.com https: data: ; img-src https://*.ft.com https: data: ; media-src https://*.ft.com https: data: ; script-src 'unsafe-inline' 'unsafe-eval' https://*.ft.com https: ; style-src 'unsafe-inline' https://*.ft.com https: ; worker-src blob: ; connect-src https: wss://ft.coral.coralproject.net ; frame-ancestors https://*.ft.com https://*.chromatic.com ; report-uri https://csp-report.ft.com/33C06499-DBAB-4FCB-880F-75B0467895F5 1 script-src 'nonce-eB0cXdtw6mVlm7-gXSMZ_w' 'report-sample' 'strict-dynamic' 'unsafe-eval' 'unsafe-inline' http: https:; object-src 'none'; report-uri https://csp.withgoogle.com/csp/static-on-bigtable; base-uri 'none' 1 script-src 'nonce-nHKvo9RoKg9_bZQOB56Big' 'report-sample' 'strict-dynamic' 'unsafe-eval' 'unsafe-inline' http: https:; object-src 'none'; report-uri https://csp.withgoogle.com/csp/static-on-bigtable; base-uri 'none' 1 style-src 'self' 'unsafe-inline' data: *.ebay.com *.ebay.co.uk *.ebaystatic.com *.ebaystatic.co.uk *.ebaystatic.cn *.gstatic.com *.fontawesome.com blob: *.googleapis.com; connect-src 'self' *.ebay.com *.ebay.co.uk *.ebaystatic.com *.ebaystatic.co.uk data: *.google-analytics.com *.doubleclick.net *.avalon.perfdrive.com *.ebayimg.com *.ucweb.com *.akamaihd.net *.ucads.ucweb.com *.analytics.google.com *.g.doubleclick.net *.googletagmanager.com *.pinterest.com *.snapchat.com *.criteo.com *.facebook.com *.googleapis.com *.googleadservices.com blob: analytics.google.com *.us.shoplive.cloud www.facebook.com *.bing.com www.googletagmanager.com google.com *.google.com *.graphitevault.com *.amplitude.com wss://127.0.0.1:* www.redditstatic.com *.reddit.com *.quantummetric.com; script-src 'self' 'unsafe-eval' 'unsafe-inline' https://* blob: data:; frame-ancestors 'self' *.ebay.com *.ebay.co.uk *.ebaystatic.com *.ebaystatic.co.uk; img-src 'self' data: blob: https://*; default-src 'self' blob: data: wss: mediastream: https://*; report-uri https://monitor.ebay.com/csp-report/discoveryplatformweb/HomePage?id=2939504940913871808&rid=t6gludlscuzujfwciunrce00%3C%3Dgludlscuzujfwciunrce00%2Bee%3C%3F371d0.qctp01*%3B1ksy-19c35db61d9-0x702#pd 1 script-src 'nonce-a2tIDae72WZjcmVkE84xhg==' 'strict-dynamic' 'unsafe-eval' 'unsafe-inline' https: 'report-sample'; base-uri 'none'; report-uri https://events.mercadolibre.com/csp/reports?identifier=w1qeU4XKVwGbQGBuEKyE3KhFBIpr5IZSIaRiTowMc8UG7kU18vRsmBTEKL2krAj23LIS&policy_id=26548&user_id=&request_id=84c5740e-3a8a-4010-9b26-54d6f9bbc7a2; report-to csp-endpoint-wqeuxkvwgbqgbuekyekhfbiprizsiaritowmcugkuvrsmbteklkrajlis; object-src https://http2.mlstatic.com/ https://mlstaticquic-a.akamaihd.net/; frame-ancestors 'self' https://*.mercadolibre.cl:* https://*.mercadolibre.com:* https://*.mercadolibre.com.ve:* https://*.mercadolibre.com.ar:* https://*.mercadolivre.com.br:* https://*.mercadolibre.com.co:* https://*.mercadolibre.com.ec:* https://*.mercadolibre.com.mx:* https://*.mercadolibre.com.pe:* https://*.mercadolibre.com.uy:* https://*.mercadopago.cl:* https://*.mercadopago.com.ar:* https://*.mercadopago.com.br:* https://*.mercadopago.com.co:* https://*.mercadopago.com.mx:* https://*.mercadopago.com.pe:* https://*.mercadopago.com.uy:* https://*.mercadopago.com.ve:* https://*.mercadopago.com:* https://*.adminml.com:* https://*.mercadolibre.co.cr:* https://*.mercadolibre.com.pa:* https://*.mercadolibre.com.do:* https://*.mercadolibre.com.bo:* https://*.mercadolibre.com.py:* https://*.mercadolibre.com.gt:* https://*.mercadolibre.com.hn:* https://*.mercadolibre.com.ni:* https://*.mercadolibre.com.sv:* https://*.mercadopago.com.ec:* https://*.portalinmobiliario.com:* https://*.mercadolivre.com:* 1 style-src 'self' 'unsafe-inline' data: *.ebay.com *.ebay.de *.ebaystatic.com *.ebaystatic.de *.ebaystatic.cn *.gstatic.com *.fontawesome.com blob: *.googleapis.com; connect-src 'self' *.ebay.com *.ebay.de *.ebaystatic.com *.ebaystatic.de data: *.google-analytics.com *.doubleclick.net *.avalon.perfdrive.com *.ebayimg.com *.ucweb.com *.akamaihd.net *.ucads.ucweb.com *.analytics.google.com *.g.doubleclick.net *.googletagmanager.com *.pinterest.com *.snapchat.com *.criteo.com *.facebook.com *.googleapis.com *.googleadservices.com blob: analytics.google.com *.us.shoplive.cloud www.facebook.com *.bing.com www.googletagmanager.com google.com *.google.com *.graphitevault.com *.amplitude.com wss://127.0.0.1:* www.redditstatic.com *.reddit.com *.quantummetric.com; script-src 'self' 'unsafe-eval' 'unsafe-inline' https://* blob: data:; frame-ancestors 'self' *.ebay.com *.ebay.de *.ebaystatic.com *.ebaystatic.de; img-src 'self' data: blob: https://*; default-src 'self' blob: data: wss: mediastream: https://*; report-uri https://monitor.ebay.com/csp-report/discoveryplatformweb/HomePage?id=2939504940913871808&rid=t6gludlscuzujfwciunrce00%3C%3Dgludlscuzujfwciunrce00%2Bee%3C%3F371d0.qctp%3C2*gol31-19c35e0a8b4-0x2703#pd 1 frame-ancestors 'self'; report-uri https://www.news.com.au/csp-reports 1 script-src 'nonce-0Psy3UcsFd2dbnkb1LaYUw==' 'strict-dynamic' 'unsafe-eval' 'unsafe-inline' https: 'report-sample'; base-uri 'none'; report-uri https://events.mercadolibre.com/csp/reports?identifier=w1qeU4XKVwGbQGBuEKyE3KhFBIpr5IZSIaRiTowMc8UG7kU18vRsmBTEKL2krAj23LIS&policy_id=26548&user_id=&request_id=fc391c1c-d5e2-4b7b-aea8-37e30d50c791; report-to csp-endpoint-wqeuxkvwgbqgbuekyekhfbiprizsiaritowmcugkuvrsmbteklkrajlis; object-src https://http2.mlstatic.com/ https://mlstaticquic-a.akamaihd.net/; frame-ancestors 'self' https://*.mercadolibre.cl:* https://*.mercadolibre.com:* https://*.mercadolibre.com.ve:* https://*.mercadolibre.com.ar:* https://*.mercadolivre.com.br:* https://*.mercadolibre.com.co:* https://*.mercadolibre.com.ec:* https://*.mercadolibre.com.mx:* https://*.mercadolibre.com.pe:* https://*.mercadolibre.com.uy:* https://*.mercadopago.cl:* https://*.mercadopago.com.ar:* https://*.mercadopago.com.br:* https://*.mercadopago.com.co:* https://*.mercadopago.com.mx:* https://*.mercadopago.com.pe:* https://*.mercadopago.com.uy:* https://*.mercadopago.com.ve:* https://*.mercadopago.com:* https://*.adminml.com:* https://*.mercadolibre.co.cr:* https://*.mercadolibre.com.pa:* https://*.mercadolibre.com.do:* https://*.mercadolibre.com.bo:* https://*.mercadolibre.com.py:* https://*.mercadolibre.com.gt:* https://*.mercadolibre.com.hn:* https://*.mercadolibre.com.ni:* https://*.mercadolibre.com.sv:* https://*.mercadopago.com.ec:* https://*.portalinmobiliario.com:* https://*.mercadolivre.com:* 1 script-src 'nonce-dWABf9WCsNJ9Pfxx3qmgbg==' 'strict-dynamic' 'unsafe-eval' 'unsafe-inline' https: 'report-sample'; base-uri 'none'; report-uri https://events.mercadolibre.com/csp/reports?identifier=w1qeU4XKVwGbQGBuEKyE3KhFBIpr5IZSIaRiTowMc8UG7kU18vRsmBTEKL2krAj23LIS&policy_id=26548&user_id=&request_id=05a53b11-4ffd-4ed8-980f-ef42b7e9101e; report-to csp-endpoint-wqeuxkvwgbqgbuekyekhfbiprizsiaritowmcugkuvrsmbteklkrajlis; object-src https://http2.mlstatic.com/ https://mlstaticquic-a.akamaihd.net/; frame-ancestors 'self' https://*.mercadolibre.cl:* https://*.mercadolibre.com:* https://*.mercadolibre.com.ve:* https://*.mercadolibre.com.ar:* https://*.mercadolivre.com.br:* https://*.mercadolibre.com.co:* https://*.mercadolibre.com.ec:* https://*.mercadolibre.com.mx:* https://*.mercadolibre.com.pe:* https://*.mercadolibre.com.uy:* https://*.mercadopago.cl:* https://*.mercadopago.com.ar:* https://*.mercadopago.com.br:* https://*.mercadopago.com.co:* https://*.mercadopago.com.mx:* https://*.mercadopago.com.pe:* https://*.mercadopago.com.uy:* https://*.mercadopago.com.ve:* https://*.mercadopago.com:* https://*.adminml.com:* https://*.mercadolibre.co.cr:* https://*.mercadolibre.com.pa:* https://*.mercadolibre.com.do:* https://*.mercadolibre.com.bo:* https://*.mercadolibre.com.py:* https://*.mercadolibre.com.gt:* https://*.mercadolibre.com.hn:* https://*.mercadolibre.com.ni:* https://*.mercadolibre.com.sv:* https://*.mercadopago.com.ec:* https://*.portalinmobiliario.com:* https://*.mercadolivre.com:* 1 object-src *.leboncoin.fr *.leboncoin.io *.leboncoin.ci; frame-ancestors *.leboncoin.fr *.leboncoin.io *.leboncoin.ci; report-uri https://api.leboncoin.fr/api/csp-report/v1/report/; 1 block-all-mixed-content ; report-uri /csp-report 1 style-src 'self' 'unsafe-inline' data: *.ebay.com *.ebay.it *.ebaystatic.com *.ebaystatic.it *.ebaystatic.cn *.gstatic.com *.fontawesome.com blob: *.googleapis.com; connect-src 'self' *.ebay.com *.ebay.it *.ebaystatic.com *.ebaystatic.it data: *.google-analytics.com *.doubleclick.net *.avalon.perfdrive.com *.ebayimg.com *.ucweb.com *.akamaihd.net *.ucads.ucweb.com *.analytics.google.com *.g.doubleclick.net *.googletagmanager.com *.pinterest.com *.snapchat.com *.criteo.com *.facebook.com *.googleapis.com *.googleadservices.com blob: analytics.google.com *.us.shoplive.cloud www.facebook.com *.bing.com www.googletagmanager.com google.com *.google.com *.graphitevault.com *.amplitude.com wss://127.0.0.1:* www.redditstatic.com *.reddit.com *.quantummetric.com; script-src 'self' 'unsafe-eval' 'unsafe-inline' https://* blob: data:; frame-ancestors 'self' *.ebay.com *.ebay.it *.ebaystatic.com *.ebaystatic.it; img-src 'self' data: blob: https://*; default-src 'self' blob: data: wss: mediastream: https://*; report-uri https://monitor.ebay.com/csp-report/discoveryplatformweb/HomePage?id=2939504940913871808&rid=t6gludlscuzujfwciunrce00%3C%3Dgludlscuzujfwciunrce00%2Bee%3C%3F371d0.qctp44%3E.gp1oq-19c35fb500c-0x1702#pd 1 default-src 'self'; base-uri 'self'; font-src localhost:3000 *.www.ucla.edu www.ucla.edu cdn.jsdelivr.net; frame-src 'self' cse.google.com www.youtube.com www.google.com *.adtrafficquality.google; img-src 'self' *.amazonaws.com www.google.com cdn.jsdelivr.net clients1.google.com www.googleapis.com *.gstatic.com pbs.twimg.com *.hypemarks.com *.tintup.com www.google-analytics.com stats.g.doubleclick.net cdn.webcomponents.ucla.edu images.sidearmdev.com *.tiktokcdn-us.com *.fbcdn.net t.co analytics.twitter.com *.linkedin.com *.cdninstagram.com www.facebook.com www.googletagmanager.com *.uclabruins.com syndicatedsearch.goog *.adtrafficquality.google data:; script-src 'self' 'unsafe-inline' 'unsafe-eval' www.google.com *.googletagmanager.com www.youtube.com cse.google.com cdn.jsdelivr.net *.ytimg.com cdnjs.cloudflare.com www.google-analytics.com *.amazonaws.com cdn.webcomponents.ucla.edu snap.licdn.com connect.facebook.net analytics.tiktok.com static.ads-twitter.com *.adtrafficquality.google *.gstatic.com data:; style-src 'self' 'unsafe-inline' 'unsafe-eval' cdn.jsdelivr.net cdn.webcomponents.ucla.edu cdnjs.cloudflare.com www.google.com; connect-src 'self' weather.atmos.ucla.edu www.google-analytics.com px.ads.linkedin.com analytics.tiktok.com stats.g.doubleclick.net *.adtrafficquality.google; report-uri /csp-hotline.php 1 script-src 'strict-dynamic' 'nonce-GJLIszuELJsWqsvBKMQvzg==' 'self' https://assets.torob.com; style-src 'self' https://assets.torob.com/ 'unsafe-inline'; frame-ancestors 'self'; object-src 'none'; base-uri 'none'; img-src https: data: blob:; worker-src 'self'; report-uri https://sentry.torob.ir/api/5/security/?sentry_key=f93c967608d0a62ff84a3620cd0bf0e9; report-to csp-endpoint 1 object-src 'none';base-uri 'self';script-src 'nonce-fAOSejkBbu-WvgTCKlrXlA' 'strict-dynamic' 'report-sample' 'unsafe-eval' 'unsafe-inline' https: http:;report-uri https://csp.withgoogle.com/csp/gws/other-hp 1 default-src 'self' https://*.fantia.jp; script-src 'unsafe-inline' 'self' https://*.fantia.jp *.genieesspv.jp *.gsspat.jp *.gsspcln.jp *.gssprt.jp *.im-apps.net *.ad-stir.com *.i-mobile.co.jp *.amoad.com *.criteo.net *.criteo.com *.fout.jp *.goldspotmedia.com *.zucks.net j.zucks.net.zimg.jp *.zucks.co.jp ta-adquick.info nend.net *.rtbhouse.com *.ad-gate.net securepubads.g.doubleclick.net *.geniee.jp https://ec-widget.toranoana.jp nav.yumenosora.co.jp *.google-analytics.com www.googletagmanager.com www.googleoptimize.com cdnjs.cloudflare.com stackpath.bootstrapcdn.com cdn.jsdelivr.net vjs.zencdn.net *.twitter.com static.ads-twitter.com *.clarity.ms *.recaptcha.net *.gstatic.com *.fontawesome.com *.chatplus.jp *.amplitude.com https://csp-report-ij4goxpsha-an.a.run.app/api/v1/csp_report; font-src 'self' https://*.fantia.jp * data:; style-src 'self' https://*.fantia.jp 'unsafe-inline' * data:; img-src 'self' https://*.fantia.jp * blob: data: www.googletagmanager.com; child-src 'self' https://*.fantia.jp blob: *.genieesspv.jp *.gsspat.jp *.gsspcln.jp *.gssprt.jp *.im-apps.net *.ad-stir.com *.i-mobile.co.jp *.amoad.com *.criteo.net *.criteo.com *.fout.jp *.goldspotmedia.com *.zucks.net j.zucks.net.zimg.jp *.zucks.co.jp ta-adquick.info nend.net *.rtbhouse.com *.ad-gate.net securepubads.g.doubleclick.net *.geniee.jp platform.twitter.com www.googletagmanager.com www.youtube.com player.vimeo.com *.recaptcha.net *.chatplus.jp; connect-src 'self' https://*.fantia.jp *.genieesspv.jp *.gsspat.jp *.gsspcln.jp *.gssprt.jp *.im-apps.net *.ad-stir.com *.i-mobile.co.jp *.amoad.com *.criteo.net *.criteo.com *.fout.jp *.goldspotmedia.com *.zucks.net j.zucks.net.zimg.jp *.zucks.co.jp ta-adquick.info nend.net *.rtbhouse.com *.ad-gate.net securepubads.g.doubleclick.net *.geniee.jp https://cc.fantia.jp https://c.fantia.jp https://dd.fantia.jp https://d.fantia.jp https://ec-widget.toranoana.jp www.google-analytics.com stats.g.doubleclick.net *.clarity.ms *.fontawesome.com *.agora.io:* *.agoraio.cn *.ap.sd-rtn.com *.statscollector.sd-rtn.com:* *.veritrans.co.jp *.chatplus.jp wss://*.edge.agora.io:* wss://*.edge.agoraio.cn:* wss://*.edge.sd-rtn.com *.amplitude.com https://ogp-cache-system-prod-ij4goxpsha-an.a.run.app/api/v1/ogp/info https://csp-report-ij4goxpsha-an.a.run.app/api/v1/csp_report https://fantia.s3.ap-northeast-1.amazonaws.com; media-src 'self' https://*.fantia.jp *.genieesspv.jp *.gsspat.jp *.gsspcln.jp *.gssprt.jp *.im-apps.net *.ad-stir.com *.i-mobile.co.jp *.amoad.com *.criteo.net *.criteo.com *.fout.jp *.goldspotmedia.com *.zucks.net j.zucks.net.zimg.jp *.zucks.co.jp ta-adquick.info nend.net *.rtbhouse.com *.ad-gate.net securepubads.g.doubleclick.net *.geniee.jp blob: https://*.chatplus.jp; frame-ancestors 'self' https://*.fantia.jp *.toranoana.jp toranoana.jp *.yumenosora.co.jp yumenosora.co.jp *.toranoana.co.jp toranoana.co.jp; form-action 'self' https://*.fantia.jp; report-to report-server; report-uri https://csp-report-ij4goxpsha-an.a.run.app/api/v1/csp_report; 1 object-src 'none';base-uri 'self';script-src 'nonce-GC8_XpbmsJ6BvMMXGnC1YA' 'strict-dynamic' 'report-sample' 'unsafe-eval' 'unsafe-inline' https: http:;report-uri https://csp.withgoogle.com/csp/gws/other-hp 1 require-trusted-types-for 'script'; report-uri https://csp.withgoogle.com/csp/uxe-owners-acl/safety_google 1 object-src 'none';base-uri 'self';script-src 'nonce-arqcKHS1wpeSlABYTSrqpQ' 'strict-dynamic' 'report-sample' 'unsafe-eval' 'unsafe-inline' https: http:;report-uri https://csp.withgoogle.com/csp/gws/other-hp 1 default-src 'self'; frame-src 'self' https://*.hsforms.net https://www.googletagmanager.com https://forms.hsforms.com https://*.chilipiper.com https://js.datadome.co https://dnaz0af4um3to.cloudfront.net https://cdn.cookielaw.org https://www.facebook.com https://calendly.com https://www.youtube-nocookie.com https://www.youtube.com https://*.captcha-delivery.com; img-src * 'self' data: https:; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://*.hsforms.net https://www.googletagmanager.com https://forms.hsforms.com https://*.chilipiper.com https://js.datadome.co https://dnaz0af4um3to.cloudfront.net https://cdn.cookielaw.org https://googleads.g.doubleclick.net https://snap.licdn.com https://bat.bing.com https://www.google-analytics.com https://www.redditstatic.com https://tracking.g2crowd.com https://connect.facebook.net https://cdn.cr-relay.com https://cdn.vector.co https://*.claydar.com https://*.hs-scripts.com https://cdn.userway.org https://*.matomo.cloud https://fast.wistia.com https://analytics.ahrefs.com https://*.hsadspixel.net https://*.hs-banner.com https://*.hs-analytics.net https://*.captcha-delivery.com https://*.hubspot.com https://static.hsappstatic.net https://assets.calendly.com https://browser.sentry-cdn.com https://www.youtube.com https://cdn-4.convertexperiments.com; font-src 'self' https://fonts.gstatic.com https://fonts.googleapis.com https://fast.wistia.net data:; style-src 'self' 'unsafe-inline' https://*.hsforms.net https://forms.hsforms.com https://*.chilipiper.com https://dnaz0af4um3to.cloudfront.net https://fonts.googleapis.com https://cdn.userway.org https://assets.calendly.com https://*.captcha-delivery.com; connect-src *; media-src * blob:; worker-src 'self' blob:; report-to csp-report 1 script-src 'report-sample' 'nonce-QnrweIuiy_fIjROgelLkzQ' 'unsafe-inline' 'unsafe-eval';object-src 'none';base-uri 'self';worker-src 'self';report-uri /us/_/BgcMiscSites/cspreport 1 object-src 'none';base-uri 'self';script-src 'nonce-4HKPt4n-QTsFoGqsT2nHuw' 'strict-dynamic' 'report-sample' 'unsafe-eval' 'unsafe-inline' https: http:;report-uri https://csp.withgoogle.com/csp/gws/other-hp 1 default-src 'self' wwwv2.tailscale.com; script-src 'self' wwwv2.tailscale.com bat.bing.com cdn.rudderlabs.com www.google-analytics.com www.googletagmanager.com www.google.com *.mutinycdn.com js.hs-scripts.com js.hs-banner.com js.hubspot.com js.hs-analytics.com *.hsforms.net unpkg.com snap.licdn.com www.redditstatic.com https://bwa.marketplace.awsstatic.com widget.kapa.ai; connect-src 'self' wwwv2.tailscale.com login.tailscale.com bat.bing.com *.mutinyhq.io *.mutinycdn.com analytics.google.com www.google-analytics.com cdn.sanity.io unpkg.com *.rudderstack.com *.hubspot.com www.redditstatic.com pixel-config.reddit.com px.ads.linkedin.com https://medley.prod.irtysh.dubai.aws.dev proxy.kapa.ai kapa-widget-proxy-la7dkmplpq-uc.a.run.app metrics.kapa.ai; img-src 'self' wwwv2.tailscale.com cdn.sanity.io lh3.googleusercontent.com www.google-analytics.com *.hsforms.com alb.reddit.com px.ads.linkedin.com bat.bing.com track.hubspot.com; frame-ancestors 'none'; form-action 'self' wwwv2.tailscale.com; base-uri 'self' wwwv2.tailscale.com; block-all-mixed-content; object-src 'self' wwwv2.tailscale.com; report-to csp-endpoint; report-uri https://login.tailscale.com/csp-report; 1 child-src 'self' https://*.qualified.com; default-src 'self'; frame-src 'self' https://9628652.fls.doubleclick.net https://td.doubleclick.net https://js.driftt.com https://*.qualified.com https://a8447815042.cdn-pci.optimizely.com https://ct.pinterest.com https://tealium-f.squarecdn.com; worker-src 'self' blob:; connect-src 'self' https://assets.ctfassets.net https://api.broadway.squareup.com https://campaign-hub-production-f.squarecdn.com https://api.squareup.com/v1/cdp/batch https://api.squarestagingexternal.com/v1/cdp/batch https://api.squarestagingexternal.com https://api.squareup.com https://api.squareupstaging.com *.contentsquare.net https://capi.squareup.com https://browser-intake-datadoghq.com https://*.browser-intake-datadoghq.com https://stats.g.doubleclick.net https://facebook.com https://www.facebook.com https://googleads.g.doubleclick.net http://www.google-analytics.com https://www.google-analytics.com https://google.com https://www.google.com https://us-central1-sq-sgtm-prod.cloudfunctions.net https://www.googletagmanager.com http://images.ctfassets.net https://images.ctfassets.net http://424-iab-218.mktoresp.com https://424-iab-218.mktoresp.com https://xms2-marketo.beta.stage.sqprod.co https://424-iab-218.mktoutil.com https://cdn.cookielaw.org https://geolocation.onetrust.com https://privacyportal.onetrust.com https://logx.optimizely.com https://ct.pinterest.com https://conversions-config.reddit.com https://pixel-config.reddit.com https://www.redditstatic.com *.ingest.us.sentry.io *.6sc.co https://api.sprig.com https://squareupstaging.com https://visitor-scoring-new.marketlinc.com https://api.chilipiper.com https://squareinc-sandbox.chilipiper.com https://squareinc.chilipiper.com https://www.workwithsquare.com wss://*.qualified.com https://*.qualified.com https://pw-renderer-production-c.squarecdn.com localhost:*; font-src 'self' https://cash-f.squarecdn.com https://square-fonts-production-f.squarecdn.com; img-src 'self' data: blob: https://ib.adnxs.com https://assets.ctfassets.net https://cdn.blisspointmedia.com https://campaign-hub-production-f.squarecdn.com *.contentsquare.net https://ad.doubleclick.net https://facebook.com https://www.facebook.com https://google.com https://www.google.com https://adservice.google.com https://googleads.g.doubleclick.net http://www.google-analytics.com https://www.google-analytics.com https://*.g.doubleclick.net https://www.googletagmanager.com http://images.ctfassets.net https://images.ctfassets.net https://px.ads.linkedin.com https://cdn.cookielaw.org https://pixel.pointmediatracker.com https://alb.reddit.com *.6sc.co https://api.squareup.com https://api.squareupstaging.com https://insight.adsrvr.org https://match.adsrvr.org https://*.qualified.com https://pw-renderer-production-c.squarecdn.com; manifest-src 'self' https://pw-renderer-production-c.squarecdn.com; media-src 'self' mediastream: https://assets.ctfassets.net https://js.driftt.com http://videos.ctfassets.net https://videos.ctfassets.net https://*.qualified.com; script-src 'self' *.contentsquare.net https://www.datadoghq-browser-agent.com https://js.driftt.com https://*.qualified.com https://connect.facebook.net https://www.googleadservices.com https://googleads.g.doubleclick.net http://www.google-analytics.com https://www.google-analytics.com https://www.googletagmanager.com https://campaign-hub-production-f.squarecdn.com https://lift-ai-js.marketlinc.com https://martech-development-c.squarecdn.com https://martech-production-c.squarecdn.com https://martech-staging-c.squarecdn.com http://munchkin.marketo.net https://munchkin.marketo.net https://cdn.cookielaw.org https://a8447815042.cdn-pci.optimizely.com https://s.pinimg.com https://ct.pinterest.com https://pw-renderer-production-c.squarecdn.com https://pw-renderer-staging-c.squarecdn.com https://pwt-production-c.squarecdn.com https://pwt-staging-c.squarecdn.com https://sales-bridge-production-c.squarecdn.com https://sales-bridge-staging-c.squarecdn.com https://squareinc-sandbox.chilipiper.com https://squareinc.chilipiper.com https://www.workwithsquare.com https://www.redditstatic.com *.6sc.co https://cdn.sprig.com https://xms-production-f.squarecdn.com https://www.youtube.com https://pw-renderer-production-c.squarecdn.com 'nonce-tmrLNRM+Nx+ytL6kurRs/w=='; style-src 'self' https://square-fonts-production-f.squarecdn.com https://sales-bridge-production-c.squarecdn.com https://sales-bridge-staging-c.squarecdn.com 'unsafe-inline' https://*.qualified.com https://pw-renderer-production-c.squarecdn.com; frame-ancestors 'self' https://app.contentful.com; report-uri https://browser-intake-datadoghq.com/api/v2/logs?dd-api-key=pubd9af00759e65a48ba7ee3ff1dfa4260b&dd-evp-origin=content-security-policy&ddsource=csp-report; report-to browser-intake-datadoghq 1 default-src 'self' blob: data: 'unsafe-inline' 'unsafe-eval' *.zijieimg.com *.helo-app.com *.toutiaopage.com *.zjurl.cn *.pstatp.com *.bytecdn.cn *.isnssdk.com *.byteoversea.com *.365yg.com *.ks-cdn.com *.ipstatp.com *.amemv.com *.ibytedtos.com *.ixigua.com *.ixiguavideo.com *.hypstarcdn.com *.tiktokcdn.com *.topbuzzcdn.com *.lemocamcdn.com *.musical.ly *.muscdn.com *.ulikecam.mobi *.faceu.mobi *.wukongwenda.com *.wukongwenda.cn *.toutiao13.com *.toutiaoribao.cn *.ribaoapi.com *.dongchediapp.com *.huoshanzhibo.com *.huoshanxiaoshipin.cn *.huoshanxiaoshipin.net *.huoshanvideo.cn *.huoshanvideo.net *.ieshuodong.cn *.ieshuodong.net *.byteoversea.com *.topbuzz.com *.hypstar.com *.tiktokv.com *.byted.org *.bytedance.net *.bytedance.com *.bytedance.cn *.toutiaocloud.com *.snssdk.com *.toutiao.com *.neihanshequ.com *.wukong.com *.huoshan.com *.douyin.com *.everphoto.cn *.jinritemai.com *.tuchong.com *.stock.tuchong.com *.luckycalendar.cn *.bcy.net *.feishu.cn *.dcdapp.com *.oceanengine.com *.chengzijianzhan.com *.byteimg.com *.google-analytics.com 1 frame-ancestors 'self' https://ss.datasconsole.com; worker-src 'self' blob:; object-src 'none'; script-src 'self' 'unsafe-inline' 'unsafe-eval' blob: https://*.coinmarketcap.com https://cdn.fuseplatform.net https://cdn.adx.ws https://cdn.cookielaw.org https://cdn4.buysellads.net https://btloader.com https://script.4dex.io https://www.google.com https://*.googlesyndication.com https://securepubads.g.doubleclick.net https://googleads.g.doubleclick.net https://ep2.adtrafficquality.google https://www.youtube.com https://s3.tradingview.com https://organizer.bizzabo.com https://telegram.org https://staticrecap.cgicgi.io https://unpkg.com/vconsole/dist/vconsole.min.js https://browser.sentry-cdn.com https://ajax.googleapis.com/ajax/libs/jquery/ https://www.recaptcha.net/recaptcha/; report-uri https://o230231.ingest.us.sentry.io/api/1773863/security/?sentry_key=f6a79779d88945e5bf5c2b7e74ee1ed8 1 default-src data: 'unsafe-inline' 'unsafe-eval' https: blob: http://*.files.wordpress.com wss://www.rollingstone.com; report-uri https://pmcuri.report-uri.com/r/d/csp/reportOnly 1 default-src 'self'; script-src 'self' https://*.posthog.com https://www.youtube.com https://fast.wistia.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; img-src 'self' data: https://*.posthog.com https://res.cloudinary.com https://www.gravatar.com https://raw.githubusercontent.com https://obuldanrptloktxcffvn.supabase.co https://cdn.shopify.com https://i.ytimg.com https://embed-ssl.wistia.com https://fast.wistia.com https://cdn.jsdelivr.net https://user-images.githubusercontent.com https://brandbadge.clearbit.com; font-src 'self' data: https://d27nj4tzr3d5tm.cloudfront.net https://res.cloudinary.com https://fonts.gstatic.com https://r2cdn.perplexity.ai https://fast.wistia.com https://use.typekit.net; connect-src 'self' https://*.posthog.com https://api.github.com https://lottie.host https://better-animal-d658c56969.strapiapp.com https://forms.default.com https://posthog.myshopify.com https://*.algolia.net https://*.algolianet.com https://api.io.inkeep.com https://fast.wistia.net https://fast.wistia.com https://embed-cloudfront.wistia.com https://api.inkeep.com; media-src 'self' https://d1hovhsvet4m1p.cloudfront.net https://res.cloudinary.com blob:; frame-src 'self' https://www.youtube-nocookie.com https://hogwars.vercel.app https://hedgehog-mode-playground.vercel.app; worker-src 'self' blob:; child-src 'self' blob:; object-src 'none'; frame-ancestors 'none'; report-uri https://us.i.posthog.com/report/?token=sTMFPsFhdP1Ssg&sample_rate=0.1&v=1; report-to posthog 1 default-src https: 'self' data: blob:; script-src https: 'self' data: 'unsafe-inline' 'unsafe-eval' blob:; style-src https: 'self' 'unsafe-inline' blob:; report-uri https://services.fandom.com/csp-logger/csp/upstream 1 default-src 'self' 846-hel-222.mktoresp.com 173-dti-322.mktoresp.com 059-alg-683.mktoresp.com js.zi-scripts.com static.addtoany.com stats.g.doubleclick.net tracking-api.g2.com play.google.com www.google.com; connect-src 'self' 846-hel-222.mktoweb.com analytics.google.com c.6sc.co ipv6.6sc.co cdn.cookielaw.org distillery.wistia.com fast.wistia.com pipedream.wistia.com geolocation.onetrust.com epsilon.6sense.com secure.adnxs.com ws.zoominfo.com px.ads.linkedin.com www.google.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net jnn-pa.googleapis.com api.simplecast.com cdn.simplecast.com givebutter.com umsafoundation.org www.youtube.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com pagead2.googlesyndication.com google.com stats.g.doubleclick.net js.zi-scripts.com privacyportal-eu.onetrust.com 846-hel-222.mktoresp.com app.qualified.com tracking-api.g2.com tr.capterra.com 173-dti-322.mktoresp.com embed-cloudfront.wistia.com *.clarity.ms 173-dti-322.mktoutil.com www.google.com.co; font-src 'self' www.perforce.com www.blazemeter.com www.gliffy.com www.jrebel.com www.openlogic.com www.zend.com www.puppet.com www.perfecto.io fonts.gstatic.com cdn.simplecast.com data: fast.wistia.com use.typekit.net www.gartner.com; frame-src 'self' 846-hel-222.mktoweb.com 173-dti-322.mktoresp.com 059-alg-683.mktoresp.com resources.perforce.com static.addtoany.com www.googletagmanager.com www.perforce.com www.blazemeter.com www.gliffy.com www.jrebel.com www.openlogic.com www.zend.com www.puppet.com www.perfecto.io fast.wistia.net player.simplecast.com www.youtube.com umsafoundation.org live-totalview.pantheonsite.io live-imsl.pantheonsite.io www.google.com app.qualified.com fast.wistia.com player.vimeo.com player.captivate.fm 605957.extforms.netsuite.com www.gartner.com; img-src 'self' data: b.6sc.co c.bing.com bat.bing.com *.clarity.ms cdn.cookielaw.org cdn2.hubspot.net embed-ssl.wistia.com f.hubspotusercontent00.net pic.trendemon.com px.ads.linkedin.com trackingapi.trendemon.com analytics.twitter.com cdn.bizible.com cdn.bizibly.com googleads.g.doubleclick.net t.co track.hubspot.com www.facebook.com www.gliffy.com www.google.com www.linkedin.com www.perforce.com www.blazemeter.com www.jrebel.com www.openlogic.com www.zend.com www.puppet.com www.perfecto.io umsafoundation.org live-mondrian.pantheonsite.io i.ytimg.com image.simplecastcdn.com yt3.ggpht.com fast.wistia.net googletagmanager.com ssl.gstatic.com www.gstatic.com *.google-analytics.com *.googletagmanager.com www.googletagmanager.com pagead2.googlesyndication.com www.googleadservices.com google.com www.google.com.tw www.google.mn fast.wistia.com www.google.co.uk www.google.com.br www.google.no fonts.gstatic.com www.google.co.in www.google.com.ec www.google.pl; manifest-src 'self' 846-hel-222.mktoresp.com 173-dti-322.mktoresp.com 059-alg-683.mktoresp.com js.zi-scripts.com static.addtoany.com stats.g.doubleclick.net tracking-api.g2.com play.google.com www.google.com www.perforce.com www.blazemeter.com www.gliffy.com www.jrebel.com www.openlogic.com www.zend.com www.puppet.com www.perfecto.io; media-src 'self' blob: app.qualified.com fast.wistia.com embed-ssl.wistia.com data: embed-fastly.wistia.com embed-cloudfront.wistia.com; object-src 'self'; script-src 'self' 'report-sample' 'unsafe-eval' 846-hel-222.mktoweb.com assets.trendemon.com browser.sentry-cdn.com cdn.cookielaw.org cdn.jsdelivr.net cdnjs.cloudflare.com fast.wistia.com fast.wistia.net googleads.g.doubleclick.net j.6sc.co js.zi-scripts.com munchkin.marketo.net resources.perforce.com *.clarity.ms snap.licdn.com static.addtoany.com static.cloudflareinsights.com trackingapi.trendemon.com tracking.g2crowd.com ct.capterra.com cdn.bizible.com cdn.getmoreproof.com js.hs-analytics.net js.hs-banner.com js.hs-scripts.com connect.facebook.net static.ads-twitter.com p-js.s3.amazonaws.com player.simplecast.com widgets.givebutter.com www.google.com www.googletagmanager.com www.perforce.com www.blazemeter.com www.gliffy.com www.jrebel.com www.openlogic.com www.zend.com www.puppet.com www.perfecto.io umsafoundation.org www.youtube.com googletagmanager.com tagmanager.google.com *.googletagmanager.com www.googleadservices.com pagead2.googlesyndication.com https://cdn.ckeditor.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://code.highcharts.com https://fast.wistia.com https://resources.perforce.com https://resources.roguewave.com https://static.addtoany.com https://unpkg.com info.perforce.com 'nonce-cTd2RiiSrSPd99O5ncRnNQ'; script-src-elem 'self' feedback.perforce.com js.qualified.com cdn.cookielaw.org googleads.g.doubleclick.net ct.capterra.com gist.github.com j.6sc.co munchkin.marketo.net trackingapi.trendemon.com scripts.clarity.ms js.zi-scripts.com cdnjs.cloudflare.com https://cdn.ckeditor.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://code.highcharts.com https://fast.wistia.com https://resources.perforce.com https://resources.roguewave.com https://static.addtoany.com https://unpkg.com info.perforce.com resources.perforce.com 'nonce-cTd2RiiSrSPd99O5ncRnNQ'; style-src 'self' 'report-sample' 'unsafe-inline' 846-hel-222.mktoweb.com cdnjs.cloudflare.com resources.perforce.com www.perforce.com www.blazemeter.com www.gliffy.com www.jrebel.com www.openlogic.com www.zend.com www.puppet.com www.perfecto.io fonts.googleapis.com www.youtube.com googletagmanager.com tagmanager.google.com app-ab48.marketo.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://code.highcharts.com https://unpkg.com; style-src-elem 'self' feedback.perforce.com resources.perforce.com www.googletagmanager.com cdnjs.cloudflare.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://code.highcharts.com https://unpkg.com; webrtc 'block'; worker-src 'self' blob:; base-uri 'self'; form-action 'self' https://feedback.perforce.com; frame-ancestors 'self' www.perforce.com 1 script-src 'nonce-b20930f29ffa4a9cb50c605b3d261894' 'strict-dynamic' 'wasm-unsafe-eval' 'unsafe-eval' *.bdxiguastatic.com *.bytescm.com *.bytetos.com *.toutiao.com *.ibytedapm.com bdxiguastatic.com *.bytegoofy.com;img-src blob: data: *.douyinstatic.com *.toutiaoimg.com *.bdxiguastatic.com *.bdxiguaimg.com *.bytexservice.com *.bytednsdoc.com *.douyinpic.com *.byteeffecttos.com *.byteacctimg.com *.byteimg.com *.bytecdn.cn http: *.ixigua.com *.itoutiaoimg.com *.toutiaostatic.com s.360.cn *.bytescm.com *.byted.org pos.baidu.com www.gstatic.com jonypractic.net wx.qlogo.cn;report-to slardar-endpoint;style-src blob: 'self' pwm-image.trendmicro.com www.gstatic.com cdn.jsdelivr.net plugin.newmorehot.com *.bytedance.net lib.baomitu.com *.bdxiguastatic.com 'unsafe-inline';manifest-src *.bytednsdoc.com;frame-src wo.laiwoshop.com pwm-image.trendmicro.com a.safen100.com c.safen110.com m.youtube.com code.woqrcode.com api.xiaoduis.com *.ixigua.com cdn.hunong.xyz cha.chaweather.com cx.chacizus.com v2.maoyinews.xyz *.summer5188.com tj.shshinfo.com www.mgtv.com vip.zhanyangsh.cn; 1 script-src https://accounts.google.com/gsi/client; frame-src https://accounts.google.com/gsi/; connect-src https://accounts.google.com/gsi/; 1 script-src 'self' https: https://www.google-analytics.com https://cdn.amplitude.com 'unsafe-eval' 'unsafe-inline' data: 'nonce-Juk9uDqUrmEeRJM3OXtjxA=='; worker-src blob: data:; report-uri https://us.sentry.io/api/4506690010480640/security/?sentry_key=aab2498373841041d6b48d721aefbdc1&sentry_environment=production&sentry_release=312e67e0aa502302182a302da01d0d575a66735d 1 script-src 'unsafe-eval' blob: 'self' meta.wikimedia.org *.wikimedia.org *.wikipedia.org *.wikinews.org *.wiktionary.org *.wikibooks.org *.wikiversity.org *.wikisource.org wikisource.org *.wikiquote.org *.wikidata.org *.wikifunctions.org *.wikivoyage.org *.mediawiki.org 'unsafe-inline' auth.wikimedia.org; default-src 'self' data: blob: upload.wikimedia.org https://commons.wikimedia.org meta.wikimedia.org *.wikimedia.org *.wikipedia.org *.wikinews.org *.wiktionary.org *.wikibooks.org *.wikiversity.org *.wikisource.org wikisource.org *.wikiquote.org *.wikidata.org *.wikifunctions.org *.wikivoyage.org *.mediawiki.org wikimedia.org en.wikipedia.org en.wikibooks.org en.wikinews.org en.wikiquote.org en.wikiversity.org en.wikivoyage.org en.wiktionary.org www.mediawiki.org api.wikimedia.org commons.wikimedia.org foundation.wikimedia.org incubator.wikimedia.org species.wikimedia.org wikimania.wikimedia.org www.wikidata.org www.wikifunctions.org auth.wikimedia.org; style-src 'self' data: blob: upload.wikimedia.org https://commons.wikimedia.org meta.wikimedia.org *.wikimedia.org *.wikipedia.org *.wikinews.org *.wiktionary.org *.wikibooks.org *.wikiversity.org *.wikisource.org wikisource.org *.wikiquote.org *.wikidata.org *.wikifunctions.org *.wikivoyage.org *.mediawiki.org wikimedia.org 'unsafe-inline'; object-src 'none'; report-uri /w/api.php?action=cspreport&format=json&reportonly=1 1 frame-ancestors 'self' https://*.webflow.com https://webflow.com https://app.intellimize.com; connect-src 'self' https://webflow.com https://*.webflow.com https://browser-intake-datadoghq.com https://api.sprig.com https://api.knock.app https://api.goentri.com https://prodregistryv2.org https://grsm.io https://partnerlinks.io https://app.clearbit.com https://cloudflare-dns.com https://050-lkc-745.mktoutil.com https://px.ads.linkedin.com https://pixel-config.reddit.com https://www.facebook.com https://www.googleservices.com https://*.google.com wss://api.knock.app https://*.doubleclick.net https://beyondwickedmapping.org https://api.claydar.com https://sockr.birdie.so https://cdn.birdie.so https://c.6sc.co https://ipv6.6sc.co https://050-lkc-745.mktoresp.com https://featureassets.org https://api.segment.io https://webflow-prod-assets.s3.amazonaws.com https://webflow-tmp-csv-import-production.s3.amazonaws.com https://webflow-assets.s3.us-east-1.amazonaws.com https://telemetry.us.transcend.io https://transcend-cdn.com wss://sockr.birdie.so https://d3e54v103j8qbb.cloudfront.net https://statsigapi.net https://cf.birdie.so wss://sock.birdie.so https://distillery.wistia.com https://pipedream.wistia.com https://fast.wistia.com https://embed-cloudfront.wistia.com https://app.qualified.com https://tzm.px-cloud.net https://cdn.dreamdata.cloud https://*.clarity.ms https://bat.bing.net https://bat.bing.com wss://ws7.qualified.com https://www.googleadservices.com https://tracking.goentri.com https://sock.birdie.so https://log.intellimize.co https://q.quora.com https://cdn.prod.website-files.com https://www.google-analytics.com https://api.intellimize.co https://dhygzobemt712.cloudfront.net https://*.px-cloud.net https://*.px-cdn.net https://*.pxchk.net https://*.px-client.net; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://d3e54v103j8qbb.cloudfront.net https://accounts.google.com https://cdn.birdie.so https://www.gstatic.com https://dhygzobemt712.cloudfront.net https://cdn.jsdelivr.net https://cdn.prod.website-files.com; img-src 'self' https://*.webflow.com https://d3e54v103j8qbb.cloudfront.net https://webflow-assets.s3.us-east-1.amazonaws.com https://account-assets.knock.app https://q.quora.com https://cdn.prod.website-files.com; report-uri https://webflow.report-uri.com/r/t/csp/reportOnly 1 script-src https://www.airtable.com https://airtable-marketing.herokuapp.com https://airtable.com https://static.airtable.com/ 'unsafe-eval' 'unsafe-inline' 'report-sample' https: blob:; style-src 'unsafe-inline' https:; block-all-mixed-content; object-src //pages.airtable.com; base-uri 'none'; report-uri https://airtable.com/.csp/report 1 child-src 'self' https://*.qualified.com; default-src 'self'; frame-src 'self' https://9628652.fls.doubleclick.net https://td.doubleclick.net https://js.driftt.com https://*.qualified.com https://a8447815042.cdn-pci.optimizely.com https://ct.pinterest.com https://tealium-f.squarecdn.com; worker-src 'self' blob:; connect-src 'self' https://assets.ctfassets.net https://api.broadway.squareup.com https://campaign-hub-production-f.squarecdn.com https://api.squareup.com/v1/cdp/batch https://api.squarestagingexternal.com/v1/cdp/batch https://api.squarestagingexternal.com https://api.squareup.com https://api.squareupstaging.com *.contentsquare.net https://capi.squareup.com https://browser-intake-datadoghq.com https://*.browser-intake-datadoghq.com https://stats.g.doubleclick.net https://facebook.com https://www.facebook.com https://googleads.g.doubleclick.net http://www.google-analytics.com https://www.google-analytics.com https://google.com https://www.google.com https://us-central1-sq-sgtm-prod.cloudfunctions.net https://www.googletagmanager.com http://images.ctfassets.net https://images.ctfassets.net http://424-iab-218.mktoresp.com https://424-iab-218.mktoresp.com https://xms2-marketo.beta.stage.sqprod.co https://424-iab-218.mktoutil.com https://cdn.cookielaw.org https://geolocation.onetrust.com https://privacyportal.onetrust.com https://logx.optimizely.com https://ct.pinterest.com https://conversions-config.reddit.com https://pixel-config.reddit.com https://www.redditstatic.com *.ingest.us.sentry.io *.6sc.co https://api.sprig.com https://squareupstaging.com https://visitor-scoring-new.marketlinc.com https://api.chilipiper.com https://squareinc-sandbox.chilipiper.com https://squareinc.chilipiper.com https://www.workwithsquare.com wss://*.qualified.com https://*.qualified.com https://pw-renderer-production-c.squarecdn.com localhost:*; font-src 'self' https://cash-f.squarecdn.com https://square-fonts-production-f.squarecdn.com; img-src 'self' data: blob: https://ib.adnxs.com https://assets.ctfassets.net https://cdn.blisspointmedia.com https://campaign-hub-production-f.squarecdn.com *.contentsquare.net https://ad.doubleclick.net https://facebook.com https://www.facebook.com https://google.com https://www.google.com https://adservice.google.com https://googleads.g.doubleclick.net http://www.google-analytics.com https://www.google-analytics.com https://*.g.doubleclick.net https://www.googletagmanager.com http://images.ctfassets.net https://images.ctfassets.net https://px.ads.linkedin.com https://cdn.cookielaw.org https://pixel.pointmediatracker.com https://alb.reddit.com *.6sc.co https://api.squareup.com https://api.squareupstaging.com https://insight.adsrvr.org https://match.adsrvr.org https://*.qualified.com https://pw-renderer-production-c.squarecdn.com; manifest-src 'self' https://pw-renderer-production-c.squarecdn.com; media-src 'self' mediastream: https://assets.ctfassets.net https://js.driftt.com http://videos.ctfassets.net https://videos.ctfassets.net https://*.qualified.com; script-src 'self' *.contentsquare.net https://www.datadoghq-browser-agent.com https://js.driftt.com https://*.qualified.com https://connect.facebook.net https://www.googleadservices.com https://googleads.g.doubleclick.net http://www.google-analytics.com https://www.google-analytics.com https://www.googletagmanager.com https://campaign-hub-production-f.squarecdn.com https://lift-ai-js.marketlinc.com https://martech-development-c.squarecdn.com https://martech-production-c.squarecdn.com https://martech-staging-c.squarecdn.com http://munchkin.marketo.net https://munchkin.marketo.net https://cdn.cookielaw.org https://a8447815042.cdn-pci.optimizely.com https://s.pinimg.com https://ct.pinterest.com https://pw-renderer-production-c.squarecdn.com https://pw-renderer-staging-c.squarecdn.com https://pwt-production-c.squarecdn.com https://pwt-staging-c.squarecdn.com https://sales-bridge-production-c.squarecdn.com https://sales-bridge-staging-c.squarecdn.com https://squareinc-sandbox.chilipiper.com https://squareinc.chilipiper.com https://www.workwithsquare.com https://www.redditstatic.com *.6sc.co https://cdn.sprig.com https://xms-production-f.squarecdn.com https://www.youtube.com https://pw-renderer-production-c.squarecdn.com 'nonce-eSYNiygfaapZTM9YvimS4A=='; style-src 'self' https://square-fonts-production-f.squarecdn.com https://sales-bridge-production-c.squarecdn.com https://sales-bridge-staging-c.squarecdn.com 'unsafe-inline' https://*.qualified.com https://pw-renderer-production-c.squarecdn.com; frame-ancestors 'self' https://app.contentful.com; report-uri https://browser-intake-datadoghq.com/api/v2/logs?dd-api-key=pubd9af00759e65a48ba7ee3ff1dfa4260b&dd-evp-origin=content-security-policy&ddsource=csp-report; report-to browser-intake-datadoghq 1 script-src 'self' 'unsafe-inline' 'unsafe-eval' 50339659.hs-sites.com 1003891.track.convertexperiments.com app.hubspot.com cdn-3.convertexperiments.com cdn-4.convertexperiments.com *.metrics.convertexperiments.com *.signals.convertexperiments.com logs.convertexperiments.com *.convertexperiments.com cdn.pdst.fm connect.facebook.net js.hs-analytics.net js.hs-banner.com js.hsforms.net js.hsleadflows.net js.hubspotfeedback.com js.usemessages.com play.vidyard.com script.hotjar.com snap.licdn.com static.hotjar.com static.hsappstatic.net www.google-analytics.com www.googletagmanager.com www.recaptcha.net code.highcharts.com www.youtube.com js.hubspot.com www.dropbox.com widget.altrulabs.com www.google.com maps.googleapis.com wt-assets.hubteam.com cdn2.hubspot.net www.redditstatic.com cdn.veritonic.com gosniply.com d.impactradius-event.com test.test.com js.hubspot.com analytics.tiktok.com 'strict-dynamic' 'nonce-cnHMHTJhKz4p7Zl4WM358g=='; report-uri https://send.hsbrowserreports.com/csp/report 1 script-src 'unsafe-eval' 'wasm-unsafe-eval' 'report-sample' 'strict-dynamic' 'nonce-_P9HnbEjQagNnsk52vMWP' *.bytescm.com *.bytednsdoc.com *.ibytedapm.com *.snssdk.com *.yhgfb-cn-static.com *.bytetos.com *.byte-gslb.com *.bytegoofy.com *.bytecdn.cn *.toutiaostatic.com;style-src 'self' 'unsafe-inline' *.toutiaoimg.com *.bdxiguaimg.com *.bytescm.com *.bytegoofy.com *.douyinstatic.com *.toutiao.com *.toutiaostatic.com *.bytedance.net cdn.bootcss.com;connect-src 'self' wss: ws: data: blob: http://localhost:* toutiao.govwza.cn *.bytedance.net *.bytedance.com *.snssdk.com *.toutiaostatic.com *.bytescm.com *.toutiao.com *.bytetcc.com *.zijieapi.com *.yhgfb-cn-static.com *.toutiaovod.com *.bytednsdoc.com *.ibytedapm.com *.bytedanceapi.com *.google-analytics.com *.douyinstatic.com *.douyinvod.com *.bytegoofy.com *.bytetos.com *.toutiaoimg.com *.huoshanstatic.com *.idouyinvod.com:* *.volcsiriusbd.com:* *.volcsirius.com:* *.tt.x.bsgslb.cn:* *.dy.zzcdnx.com:* *.qc.bsccdn.net:* *.smtcdns.com:* *.ugslb.com:* *.livehwc3.cn:* *.smtcdns.net:* *.bytefcdnrd.com:* *.ksyungslb.com:* *.ksyungslb2.com:* *.ourdvsss.com:* *.tbcache.com:* *.jomodns.com:* *.douyincdn.com:* *.ixigua.com:* *.bdxigualive.com:* *.pstatp.com:* *.douyinliving.com:* *.picovr.com:* *.huoshanlive.com:* *.ihuoshanlive.com:* *.volccdn.com:* *.bestv.com.cn:* *.bytefcdn.com:* *.qnqcdn.net:* *.jomoxc.com *.jomoxd.com *.a.bdycdn.cn *.hiecheimaetu.com:* *.ppio.cloud:* *.weilayun.com:* *.saxysec.com:* *.saxyit.com:* *.saxydc.com:* *.sjxysec.com:* *.sjxydc.com:* *.vegslb.com:*;upgrade-insecure-requests;frame-ancestors 'self' *.bytedance.net *.snssdk.com shiqu.cn *.shiqu.cn zhan.vivo.com wukong.vivo.com.cn *.feishuapp.cn *.toutiao.com *.bytescm.com *.jiyunhudong.com *.bytedance.com *.feishu.cn;report-uri https://mon.zijieapi.com/log/sentry/v2/api/slardar/main/?ev_type=csp&bid=toutiao_web_pc;report-to main-endpoint 1 script-src 'self' 'unsafe-inline' 'unsafe-eval' hubspot.mintlify.dev app.hubspot.com cdn-3.convertexperiments.com cdnjs.cloudflare.com connect.facebook.net cta-service-cms2.hubspot.com js.hsforms.net js.hs-analytics.net js.hs-banner.com js.hsleadflows.net js.hubspotfeedback.com js.usemessages.com platform.twitter.com play.vidyard.com run.pstmn.io script.crazyegg.com script.hotjar.com static.hotjar.com static.hsappstatic.net use.typekit.net www.googletagmanager.com www.google-analytics.com www.hubspot.com 'strict-dynamic' 'nonce-KJHbfFFrAPeIOK/b5+QwdA=='; report-uri https://send.hsbrowserreports.com/csp/report 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://*.stripe.com https://*.paddle.com https://www.google.com https://www.gstatic.com https://maps.gstatic.com https://maps.googleapis.com https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/; style-src 'self' 'unsafe-inline' https://*.paddle.com https://fonts.gstatic.com https://fonts.googleapis.com; img-src 'self' data: https://ipapi.co https://maps.gstatic.com https://maps.googleapis.com https://*.stripe.com; font-src 'self' data: https://fonts.gstatic.com https://fonts.googleapis.com; frame-src 'self' https://www.google.com https://*.stripe.com https://*.paddle.com https://www.google.com/recaptcha/ https://recaptcha.google.com/recaptcha/; connect-src 'self' https://ipapi.co/ https://*.paddle.com https://*.stripe.com https://maps.googleapis.com https://www.google.com/recaptcha/; object-src 'none'; frame-ancestors 'none'; base-uri 'self'; form-action 'self'; 1 base-uri 'self';connect-src 'self' https: https://www.recaptcha.net https://challenges.cloudflare.com wss:;default-src 'self' https: wss: blob: data:;form-action 'self' https:;img-src 'self' https: http://iea.imgix.net https://iea.imgix.net data:;media-src 'self' https: data: http://iea.imgix.net https://iea.imgix.net;object-src 'none';script-src 'self' 'unsafe-eval' https://www.google.com https://www.googletagmanager.com https://www.youtube.com https://www.google-analytics.com https://www.recaptcha.net https://challenges.cloudflare.com https://snap.licdn.com https://www.gstatic.com https://stats.g.doubleclick.net https://p.adsymptotic.com https://px.ads.linkedin.com 'sha256-l/3fcn6MZG0SSVJq6fOLe49ZKIjbWdNzhreJz7KQ/1M=' 'sha256-+MedjqNIfWWYUGuHJ53XLEjzmGDCp9Om50MVUO/C/zo=' https://ieatest.blob.core.windows.net https://iea.blob.core.windows.net 'nonce-Pr3Z7jp9EasPeY2PVUkeqBo2cvFxGCJZ';style-src 'self' https: 'unsafe-inline';worker-src https://ieatest.blob.core.windows.net https://iea.blob.core.windows.net;frame-ancestors 'self' 1 script-src 'unsafe-eval' blob: 'self' meta.wikimedia.org *.wikimedia.org *.wikipedia.org *.wikinews.org *.wiktionary.org *.wikibooks.org *.wikiversity.org *.wikisource.org wikisource.org *.wikiquote.org *.wikidata.org *.wikifunctions.org *.wikivoyage.org *.mediawiki.org 'unsafe-inline' auth.wikimedia.org; default-src 'self' data: blob: upload.wikimedia.org https://commons.wikimedia.org meta.wikimedia.org *.wikimedia.org *.wikipedia.org *.wikinews.org *.wiktionary.org *.wikibooks.org *.wikiversity.org *.wikisource.org wikisource.org *.wikiquote.org *.wikidata.org *.wikifunctions.org *.wikivoyage.org *.mediawiki.org wikimedia.org en.wikipedia.org en.wikibooks.org en.wikinews.org en.wikiquote.org en.wikisource.org en.wikiversity.org en.wikivoyage.org en.wiktionary.org api.wikimedia.org commons.wikimedia.org foundation.wikimedia.org incubator.wikimedia.org species.wikimedia.org wikimania.wikimedia.org www.wikidata.org www.wikifunctions.org auth.wikimedia.org; style-src 'self' data: blob: upload.wikimedia.org https://commons.wikimedia.org meta.wikimedia.org *.wikimedia.org *.wikipedia.org *.wikinews.org *.wiktionary.org *.wikibooks.org *.wikiversity.org *.wikisource.org wikisource.org *.wikiquote.org *.wikidata.org *.wikifunctions.org *.wikivoyage.org *.mediawiki.org wikimedia.org 'unsafe-inline'; object-src 'none'; report-uri /w/api.php?action=cspreport&format=json&reportonly=1 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' blob: *.a.net *.6sc.co *.ads-twitter.com *.bing.com *.bizible.com *.cloudflare.com *.doubleclick.net *.google-analytics.com *.google.com *.googletagmanager.com *.hs-analytics.net *.hs-banner.com *.hsadspixel.net *.hsappstatic.net *.hscollectedforms.net *.hsforms.com *.hsforms.net *.hsleadflows.net *.hs-scripts.com *.hubspot.com *.hubspot.net *.hubspotfeedback.com *.hubspotusercontent00.net *.hubspotusercontent10.net *.hubspotusercontent20.net *.hubspotusercontent30.net *.hubspotusercontent40.net *.jsdelivr.net *.ktxlytics.io *.linkedin.com *.redditstatic.com *.salesloft.com *.sentry-cdn.com *.stackadapt.com *.twitter.com *.usemessages.com *.varonis.com *.wistia.com *.wistia.net *.zi-scripts.com plausible.io qvdt3feo.com/events.js *.licdn.com/li.lms-analytics/insight.min.js unpkg.com *.jsdelivr.net unpkg.com/react@17.0.2/umd/react.production.min.js unpkg.com/react-dom@17.0.2/umd/react-dom.production.min.js js.hscta.net js-eu1.hscta.net static.hsappstatic.net feedback.hubapi.com feedback-eu1.hubapi.com 'strict-dynamic' 'nonce-o6a8dPajTk8W5gr6rhbqSA=='; script-src-elem 'self' *.jsdelivr.net *.google.com *.google.com; style-src 'self' 'unsafe-inline' *.cloudflare.com *.google.com *.googleapis.com *.hsappstatic.net *.hubspot.net *.hubspotusercontent00.net *.hubspotusercontent10.net *.hubspotusercontent20.net *.hubspotusercontent30.net *.hubspotusercontent40.net *.jsdelivr.net *.stackadapt.com *.varonis.com cdn2.hubspot.net; img-src 'self' data: blob: *.6sc.co *.adnxs.com *.adsrvr.org *.bing.com *.bizible.com *.doubleclick.net *.google-analytics.com *.google.com google.com *.hubspot.com *.hubspot.net *.hubspotusercontent00.net *.hubspotusercontent10.net *.hubspotusercontent20.net *.hubspotusercontent30.net *.hubspotusercontent40.net *.hubspotusercontent-na1.net *.hsforms.com *.hsforms.net js.hscta.net js-eu1.hscta.net no-cache.hubspot.com static.hsappstatic.net *.linkedin.com *.facebook.com *.reddit.com *.twitter.com *.youtube.com https://t.co *.ktxlytics.io *.googletagmanager.com *.varonis.com *.wistia.com *.wistia.net; font-src 'self' data: *.gstatic.com *.googleapis.com *.hubspotusercontent-na1.net *.hsappstatic.net *.varonis.com *.wistia.com *.wistia.net; connect-src 'self' *.g2.com https://unpkg.com https://cdn.jsdelivr.net *.6sc.co *.cloudflare.com *.doubleclick.net *.google-analytics.com *.google.com google.com *.hubapi.com *.hubspot.com *.hubspotusercontent-na1.net *.hs-banner.com *.hscollectedforms.net *.hsforms.com *.js.zi-scripts.com https://js.zi-scripts.com https://epsilon.6sense.com https://plausible.io *.ktxlytics.io *.litix.io *.linkedin.com *.reddit.com *.redditstatic.com *.salesloft.com *.stackadapt.com *.varonis.com *.wistia.com *.wistia.net *.zoominfo.com js.hscta.net js-eu1.hscta.net; media-src 'self' blob: *.varonis.com *.wistia.com *.wistia.net *.youtube.com *.ytimg.com; object-src 'none'; frame-src 'self' *.hubspot.com *.hubspot.net *.hs-sites.com *.hs-sites-eu1.com *.hsforms.com *.hsforms.net *.podcasts.apple.com *.twitter.com *.vimeo.com *.varonis.com *.wistia.com *.wistia.net *.youtube.com *.yt.com play-eu1.hubspotvideo.com play.hubspotvideo.com *.facebook.com; worker-src 'self' *.hsforms.com; base-uri 'self'; form-action 'self' *.hsforms.com *.hsforms.net; frame-ancestors 'none'; upgrade-insecure-requests; block-all-mixed-content 1 object-src 'none';base-uri 'self';script-src 'nonce-sXdN0vUZaisWsY-wXAeoYA' 'strict-dynamic' 'report-sample' 'unsafe-eval' 'unsafe-inline' https: http:;report-uri https://csp.withgoogle.com/csp/gws/other-hp 1 object-src 'none';base-uri 'self';script-src 'nonce-MycGvoizT9XCQn1xRFba_A' 'strict-dynamic' 'report-sample' 'unsafe-eval' 'unsafe-inline' https: http:;report-uri https://csp.withgoogle.com/csp/gws/other-hp 1 object-src 'none';base-uri 'self';script-src 'nonce-FKFneUNRosLowZfHDOEGWQ' 'strict-dynamic' 'report-sample' 'unsafe-eval' 'unsafe-inline' https: http:;report-uri https://csp.withgoogle.com/csp/gws/other-hp 1 object-src 'none';base-uri 'self';script-src 'nonce-C47Y2YjQJPLvwqGE9dEovg' 'strict-dynamic' 'report-sample' 'unsafe-eval' 'unsafe-inline' https: http:;report-uri https://csp.withgoogle.com/csp/gws/other-hp 1 object-src 'none';base-uri 'self';script-src 'nonce-7qS0eqo-eElhpBHij97B3w' 'strict-dynamic' 'report-sample' 'unsafe-eval' 'unsafe-inline' https: http:;report-uri https://csp.withgoogle.com/csp/gws/other-hp 1 object-src 'none';base-uri 'self';script-src 'nonce-vqohWZ2cC9VSZnO4lXBd4A' 'strict-dynamic' 'report-sample' 'unsafe-eval' 'unsafe-inline' https: http:;report-uri https://csp.withgoogle.com/csp/gws/other-hp 1 object-src 'none';base-uri 'self';script-src 'nonce-rqnBm3pBbRDlZs2W1mGs2A' 'strict-dynamic' 'report-sample' 'unsafe-eval' 'unsafe-inline' https: http:;report-uri https://csp.withgoogle.com/csp/gws/other-hp 1 object-src 'none';base-uri 'self';script-src 'nonce-k5QHXWrxWRsulXZG7DxSYA' 'strict-dynamic' 'report-sample' 'unsafe-eval' 'unsafe-inline' https: http:;report-uri https://csp.withgoogle.com/csp/gws/other-hp 1 object-src 'none';base-uri 'self';script-src 'nonce-BSkmm49BYx_AsasX5t298w' 'strict-dynamic' 'report-sample' 'unsafe-eval' 'unsafe-inline' https: http:;report-uri https://csp.withgoogle.com/csp/gws/other-hp 1 object-src 'none';base-uri 'self';script-src 'nonce-cMvrH6tdzZkYxRNCl1lGFQ' 'strict-dynamic' 'report-sample' 'unsafe-eval' 'unsafe-inline' https: http:;report-uri https://csp.withgoogle.com/csp/gws/other-hp 1 object-src 'none';base-uri 'self';script-src 'nonce-xeecqwOyvGhlOblFuEtmiA' 'strict-dynamic' 'report-sample' 'unsafe-eval' 'unsafe-inline' https: http:;report-uri https://csp.withgoogle.com/csp/gws/other-hp 1 default-src 'self'; base-uri 'self'; font-src 'self' fonts.gstatic.com *.atlassian.com data:; worker-src blob:; media-src 'self' api.media.atlassian.com *.atlassian.com; img-src data: blob: 'self' *.badgen.net *.youtube.com atlassian.wpengine.netdna-cdn.com global.discourse-cdn.com img.shields.io *.atlassian.net *.google.com *.google.ad *.google.ae *.google.com.af *.google.com.ag *.google.com.ai *.google.al *.google.am *.google.co.ao *.google.com.ar *.google.as *.google.at *.google.com.au *.google.az *.google.ba *.google.com.bd *.google.be *.google.bf *.google.bg *.google.com.bh *.google.bi *.google.bj *.google.com.bn *.google.com.bo *.google.com.br *.google.bs *.google.bt *.google.co.bw *.google.by *.google.com.bz *.google.ca *.google.cd *.google.cf *.google.cg *.google.ch *.google.ci *.google.co.ck *.google.cl *.google.cm *.google.cn *.google.com.co *.google.co.cr *.google.com.cu *.google.cv *.google.com.cy *.google.cz *.google.de *.google.dj *.google.dk *.google.dm *.google.com.do *.google.dz *.google.com.ec *.google.ee *.google.com.eg *.google.es *.google.com.et *.google.fi *.google.com.fj *.google.fm *.google.fr *.google.ga *.google.ge *.google.gg *.google.com.gh *.google.com.gi *.google.gl *.google.gm *.google.gr *.google.com.gt *.google.gy *.google.com.hk *.google.hn *.google.hr *.google.ht *.google.hu *.google.co.id *.google.ie *.google.co.il *.google.im *.google.co.in *.google.iq *.google.is *.google.it *.google.je *.google.com.jm *.google.jo *.google.co.jp *.google.co.ke *.google.com.kh *.google.ki *.google.kg *.google.co.kr *.google.com.kw *.google.kz *.google.la *.google.com.lb *.google.li *.google.lk *.google.co.ls *.google.lt *.google.lu *.google.lv *.google.com.ly *.google.co.ma *.google.md *.google.me *.google.mg *.google.mk *.google.ml *.google.com.mm *.google.mn *.google.ms *.google.com.mt *.google.mu *.google.mv *.google.mw *.google.com.mx *.google.com.my *.google.co.mz *.google.com.na *.google.com.ng *.google.com.ni *.google.ne *.google.nl *.google.no *.google.com.np *.google.nr *.google.nu *.google.co.nz *.google.com.om *.google.com.pa *.google.com.pe *.google.com.pg *.google.com.ph *.google.com.pk *.google.pl *.google.pn *.google.com.pr *.google.ps *.google.pt *.google.com.py *.google.com.qa *.google.ro *.google.ru *.google.rw *.google.com.sa *.google.com.sb *.google.sc *.google.se *.google.com.sg *.google.sh *.google.si *.google.sk *.google.com.sl *.google.sn *.google.so *.google.sm *.google.sr *.google.st *.google.com.sv *.google.td *.google.tg *.google.co.th *.google.com.tj *.google.tl *.google.tm *.google.tn *.google.to *.google.com.tr *.google.tt *.google.com.tw *.google.co.tz *.google.com.ua *.google.co.ug *.google.co.uk *.google.com.uy *.google.co.uz *.google.com.vc *.google.co.ve *.google.vg *.google.co.vi *.google.com.vn *.google.vu *.google.ws *.google.rs *.google.co.za *.google.co.zm *.google.co.zw *.google.cat www.gstatic.com *.wp.com cdn.cookielaw.org *.clicktale.net *.doubleclick.net https://googleads.g.doubleclick.net images.ctfassets.net *.public.atl-paas.net trello.com trello-backgrounds.s3.amazonaws.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com *.google.co.in *.google.com *.atlassian.com *.gravatar.com; frame-src 'self' *.atlassian.com *.atl-paas.net *.googletagmanager.com player.vimeo.com trello.com www.youtube.com www.figma.com; connect-src 'self' *.googletagmanager.com *.algolianet.com *.algolia.net *.clicktale.net *.launchdarkly.com *.trello.com *.doubleclick.net *.qualtrics.com *.onetrust.com *.sentry.io cdn.segment.com api.segment.io www.google-analytics.com cdn.cookielaw.org *.atlassian.com *.algolia.io *.google.com; report-uri https://web-security-reports.services.atlassian.com/csp-report/dac; object-src 'none'; style-src 'self' *.trellocdn.com *.atlassian.com 'unsafe-inline'; script-src 'nonce-ukzlLAWlOeSaF6p62ll5MAE83vl5n2lhec6LYpXcXbE=' 'self' 'sha256-Nt9ereHaxV04RZ20OLtdR3uuFr1X0/Pbt5KbGls/wXg=' https://www.googleadservices.com https://player.vimeo.com/api/player.js *.segment.com *.clicktale.net mscgen.js.org *.qualtrics.com *.trellocdn.com *.atlassian.com www.googletagmanager.com www.google-analytics.com https://cdn.cookielaw.org https://cdn.jsdelivr.net/npm/search-insights@2.2.1 https://run.pstmn.io/button.js *.atl-paas.net https://srm.bf.contentsquare.net/exist 1 object-src 'none';base-uri 'self';script-src 'nonce-f1WdlCJYwHX6hL-ewdeo_Q' 'strict-dynamic' 'report-sample' 'unsafe-eval' 'unsafe-inline' https: http:;report-uri https://csp.withgoogle.com/csp/gws/other-hp 1 object-src 'none';base-uri 'self';script-src 'nonce-qEMw2S-eskCjZITkEKPxfg' 'strict-dynamic' 'report-sample' 'unsafe-eval' 'unsafe-inline' https: http:;report-uri https://csp.withgoogle.com/csp/gws/other-hp 1 object-src 'none';base-uri 'self';script-src 'nonce-7UB2jY5JXz5EBb68i283eA' 'strict-dynamic' 'report-sample' 'unsafe-eval' 'unsafe-inline' https: http:;report-uri https://csp.withgoogle.com/csp/gws/other-hp 1 script-src 'report-sample' 'nonce-YzY1MzdiNzItYTAyMi00YTZkLWE4N2ItNzU4ZWQzZTZiZTZh' 'sha256-csrVWp8CMHoRM1BNkwrZ4oBNVfUGJISZyfZ1clrdEjY=' 'sha256-h5LVzK0ijAigetqSxWVza5zUamL4ovsgDFoUjQnl9Oo=' 'sha256-KZ5aOlccpgH2A5kDzmoM6CtWgVDwxped5zBvrmTP3sU=' 'sha256-rZCMKkBIutDugPHWhQk7o6TCRCo4O577/TWutRjSwVg=' 'sha256-DywUU9xjLyCO4tzNLPijzuVQs028sGTOW3aU9NizW+E=' 'sha256-+Jx0BAXcVQjxwcOOSVwwUBKi509Ydrjig+H8pCn1cOY=' 'sha256-kiMAdJCDJrcN5E+xF+tflCbd5hjeVXH0NoZ+09uqW40=' 'strict-dynamic' 'unsafe-inline' http: https:; object-src 'none'; base-uri 'none' 1 object-src 'none';base-uri 'self';script-src 'nonce-dqvA6iHN1SYwHY8qv_fdFA' 'strict-dynamic' 'report-sample' 'unsafe-eval' 'unsafe-inline' https: http:;report-uri https://csp.withgoogle.com/csp/gws/other-hp 1 object-src 'none';base-uri 'self';script-src 'nonce-ivRC3JqcOWCWmlRoBlvcUg' 'strict-dynamic' 'report-sample' 'unsafe-eval' 'unsafe-inline' https: http:;report-uri https://csp.withgoogle.com/csp/gws/other-hp 1 require-trusted-types-for 'script'; report-uri https://csp.withgoogle.com/csp/uxe-owners-acl/chrome 1 report-to slardar-endpoint; upgrade-insecure-requests ; frame-ancestors 'self' *.toutiao.com *.douyin.com *.bytedance.com *.bytedance.net tcs.jiyunhudong.com aup.jijixiangshangabc.com chrome-extension://dbjibobgilijgolhjdcbdebjhejelffo chrome-extension://molcibnmfbjmmfbefjfcafdeabfniobi chrome-extension://capohkkfagimodmlpnahjoijgooocdjhd chrome-extension://mijalhmcgaaaggjfhkliffkanfhimhch chrome-extension://obkcimipmjdkghadnfcjojepocldeggd chrome-extension://epjhdbhhoeemcbbbgkimcfndcbjapdaa safari-web-extension:; script-src 'nonce-68fae8a41e84988dd38820ad3fe5b817-argus' blob: data: 'self' 'unsafe-eval' 'report-sample' 'strict-dynamic' 'unsafe-inline' https:; base-uri 'self'; object-src 'self'; frame-src 'self' *.toutiao.com *.douyin.com *.bytedance.com *.bytedance.net tcs.jiyunhudong.com aup.jijixiangshangabc.com;report-uri https://mon.zijieapi.com/monitor_browser/collect/batch/security/?bid=flow_web; 1 style-src 'self' 'unsafe-inline' data: *.ebay.com *.ebay.com.au *.ebay.au *.ebaystatic.com *.ebaystatic.com.au *.ebaystatic.au *.ebaystatic.cn *.gstatic.com *.fontawesome.com blob: *.googleapis.com; connect-src 'self' *.ebay.com *.ebay.com.au *.ebay.au *.ebaystatic.com *.ebaystatic.com.au *.ebaystatic.au data: *.google-analytics.com *.doubleclick.net *.avalon.perfdrive.com *.ebayimg.com *.ucweb.com *.akamaihd.net *.ucads.ucweb.com *.analytics.google.com *.g.doubleclick.net *.googletagmanager.com *.pinterest.com *.snapchat.com *.criteo.com *.facebook.com *.googleapis.com *.googleadservices.com blob: analytics.google.com *.us.shoplive.cloud www.facebook.com *.bing.com www.googletagmanager.com google.com *.google.com *.graphitevault.com *.amplitude.com wss://127.0.0.1:* www.redditstatic.com *.reddit.com *.quantummetric.com; script-src 'self' 'unsafe-eval' 'unsafe-inline' https://* blob: data:; frame-ancestors 'self' *.ebay.com *.ebay.com.au *.ebay.au *.ebaystatic.com *.ebaystatic.com.au *.ebaystatic.au; img-src 'self' data: blob: https://*; default-src 'self' blob: data: wss: mediastream: https://*; report-uri https://monitor.ebay.com/csp-report/discoveryplatformweb/HomePage?id=2939504940913871808&rid=t6gludlscuzujfwciunrce00%3C%3Dgludlscuzujfwciunrce00%2Bee%3C%3F371d0.qctp%3C2*o0djk-19c35c02861-0x1604#pd 1 default-src 'self' https://cdn.ampproject.org https://snap.licdn.com https://www.youtube.com *.youtube.com *.google-analytics.com https://www.googletagmanager.com https://consent.bumble.com *.typeform.com *.doubleclick.net *.taboola.com; script-src 'self' 'unsafe-inline' 'report-sample' 'nonce-RvE2JYx3VUMRyrNvxhWRZQ==' https://cdn.ampproject.org https://snap.licdn.com https://www.youtube.com *.youtube.com *.google-analytics.com https://www.googletagmanager.com https://consent.bumble.com *.typeform.com *.doubleclick.net *.taboola.com; style-src 'self' 'unsafe-inline' *.typeform.com; connect-src 'self' https://cdn.ampproject.org https://consent.bumble.com https://www.googletagmanager.com *.google-analytics.com *.analytics.google.com https://stats.g.doubleclick.net https://googleads.g.doubleclick.net https://www.google.com/pagead *.googlesyndication.com *.typeform.com *.typeformcdn.com; child-src 'self'; font-src 'self' data:; manifest-src 'self'; base-uri 'self'; frame-src 'self' https://cdn.ampproject.org https://snap.licdn.com https://www.youtube.com *.youtube.com *.google-analytics.com https://www.googletagmanager.com https://consent.bumble.com *.typeform.com *.doubleclick.net *.taboola.com; img-src * data: blob: www.googletagmanager.com; media-src * data: blob:; report-uri /jss/csp_report.phtml?token=bumble_team_site&env=production; 1 style-src 'self' 'unsafe-inline' data: *.ebay.com *.ebay.ca *.ebaystatic.com *.ebaystatic.ca *.ebaystatic.cn *.gstatic.com *.fontawesome.com blob: *.googleapis.com; connect-src 'self' *.ebay.com *.ebay.ca *.ebaystatic.com *.ebaystatic.ca data: *.google-analytics.com *.doubleclick.net *.avalon.perfdrive.com *.ebayimg.com *.ucweb.com *.akamaihd.net *.ucads.ucweb.com *.analytics.google.com *.g.doubleclick.net *.googletagmanager.com *.pinterest.com *.snapchat.com *.criteo.com *.facebook.com *.googleapis.com *.googleadservices.com blob: analytics.google.com *.us.shoplive.cloud www.facebook.com *.bing.com www.googletagmanager.com google.com *.google.com *.graphitevault.com *.amplitude.com wss://127.0.0.1:* www.redditstatic.com *.reddit.com *.quantummetric.com; script-src 'self' 'unsafe-eval' 'unsafe-inline' https://* blob: data:; frame-ancestors 'self' *.ebay.com *.ebay.ca *.ebaystatic.com *.ebaystatic.ca; img-src 'self' data: blob: https://*; default-src 'self' blob: data: wss: mediastream: https://*; report-uri https://monitor.ebay.com/csp-report/discoveryplatformweb/HomePage?id=2939504940913871808&rid=t6gludlscuzujfwciunrce00%3C%3Dgludlscuzujfwciunrce00%2Bee%3C%3F371d0.qctp44%3E.aew7a-19c35cad456-0x2605#pd 1 default-src https://www.oreilly.com/92daw_/WAGe/e/-/q-vAwe4oXvtH/trittt3Vr9/ZQgCBX07Kg/Y2o7Mk/Y4Mx1t https://www.oreilly.com/92daw_/WAGe/e/-/q-vAwe4oXvtH/trittt3Vr9/ZQgCBX07Kg/Y2o7Mk/Y4Mx1t https://www.oreilly.com/92daw_/WAGe/e/-/q-vAwe4oXvtH/iNitttb6t4JXDX5Y/UHp9BH07Kg/MB4oSx/4XDA4B https://www.oreilly.com * 'unsafe-inline' 'unsafe-eval' data: blob: android-webview-video-poster: moz-extension: ms-browser-extension: chrome-extension: ios-log:; report-uri https://csp-report.browser-intake-datadoghq.com/api/v2/logs?dd-api-key=pubb898c25826db9d251f99fdcece943792&dd-evp-origin=content-security-policy&ddsource=csp-report&ddtags=service:wordpress-prod-cluster; 1 default-src 'self'; connect-src 'self' https://*.polymarket.com https://*.polymarket.dev wss://*.polymarket.com wss://*.polymarket.dev https://*.walletconnect.com wss://*.walletconnect.com https://*.walletconnect.org wss://*.walletconnect.org https://*.amplitude.com https://*.alchemy.com https://*.alchemyapi.io https://api.goldsky.com https://api.goldsky.io https://assets.vercel.com https://vercel.live https://vercel.com https://cdp.customer.io https://*.magic.link https://*.intercom.io wss://*.intercom.io https://polymarket-upload.s3.us-east-2.amazonaws.com https://polymarket-next-assets.s3.amazonaws.com https://*.polymarket.io https://*.coinbase.com https://*.vercel-scripts.com https://*.google-analytics.com https://js.intercomcdn.com https://*.facebook.com https://*.facebook.net https://*.redditstatic.com https://*.reddit.com https://analytics.tiktok.com wss://ws-us3.pusher.com https://polygon-rpc.com https://browser-intake-datadoghq.eu https://browser-intake-datadoghq.com https://static.ads-twitter.com https://sentry.io https://api.moonpay.com https://*.fun.xyz wss://*.fun.xyz https://*.quiknode.pro https://*.base.org https://*.zksync.io https://*.daimo.com https://pay-api.daimo.xyz https://s3-us-west-2.amazonaws.com wss://*.walletlink.org https://rp.liadm.com https://analytics-ipv6.tiktokw.us data:; script-src 'self' 'unsafe-eval' https://*.intercom.io https://js.intercomcdn.com https://www.redditstatic.com https://connect.facebook.net https://widget.intercom.io https://va.vercel-scripts.com https://vercel.live https://*.magic.link https://static.moonpay.com https://s3-us-west-2.amazonaws.com; script-src-elem 'self' 'unsafe-inline' https://*.intercom.io https://js.intercomcdn.com https://www.redditstatic.com https://connect.facebook.net https://widget.intercom.io https://va.vercel-scripts.com https://vercel.live https://*.magic.link https://static.moonpay.com https://static.ads-twitter.com https://s3-us-west-2.amazonaws.com https://analytics.tiktok.com https://cdp.customer.io https://www.dubcdn.com https://www.googletagmanager.com https://*.doubleclick.net https://tr.snapchat.com https://b-code.liadm.com 'sha256-FZPlDlMTeqDORmlYE10RC9clHRS4T0hmr3qmUImTEgM=' 'sha256-LpaSOWbberseWm9imoaC+ysCWgKfj1BqQTvkK+3f49U=' 'sha256-VeMw0YWTQ3B/16lvulSWfWmvFDJ6h/Dh0ZlaDcC6Xsg=' 'sha256-5mcCoB7D4UCld/T8vawEJRBqmowLOddOT7MoIsyvG1Q=' 'sha256-s23mNx29vpBL+sMthBuNE6eQyH+nT28yGSujSemXoW4=' 'sha256-cQXoeQJyWFzxs/64P04eR53fqnjvuHN85IDxz3ajsXs=' 'sha256-Qk1NsNsPdFh6yJ3r/NrwdbvPty9pxQ+4Vy/HZQsFLJ8=' 'sha256-AwKpW/rVb+QKvpxfNraZn5UIDD5I87FHdwCxl6U8IqU=' 'sha256-KmWJKVKEZLyBcE4VQaphHWdW1ApiMVRN/t/9TtZD9/g=' 'sha256-3ENvm2kYNR7adex9zHzAvBeVf6xAkV7O7lZ2SlTCByE='; frame-src 'self' https://*.youtube.com https://*.walletconnect.com https://*.walletconnect.org https://*.magic.link https://vercel.live https://*.polymarket.com https://*.polymarket.dev https://*.googletagmanager.com; frame-ancestors 'self' https://auth.magic.link; style-src 'self' 'unsafe-inline' https://vercel.live; img-src 'self' blob: data: https://polymarket-upload.s3.us-east-2.amazonaws.com https://assets.vercel.com https://*.walletconnect.com https://alb.reddit.com https://ib.adnxs.com https://www.facebook.com https://vercel.com https://analytics.twitter.com https://t.co https://sdk-cdn.fun.xyz https://pbs.twimg.com https://www.google.com https://www.googleadservices.com; font-src 'self' data: https://assets.vercel.com https://fonts.intercomcdn.com https://vercel.live https://unpkg.com; worker-src 'self' blob:; object-src 'none'; base-uri 'self'; form-action 'self' https://*.polymarket.com https://*.polymarket.dev 1 script-src 'report-sample' 'nonce-oY_Kyne-TS2tKiDExuZ47g' 'unsafe-inline' 'unsafe-eval';object-src 'none';base-uri 'self';worker-src 'self';report-uri /us/_/ThinkWithGoogle/cspreport 1 style-src 'self' 'unsafe-inline' data: *.ebay.com *.ebay.fr *.ebaystatic.com *.ebaystatic.fr *.ebaystatic.cn *.gstatic.com *.fontawesome.com blob: *.googleapis.com; connect-src 'self' *.ebay.com *.ebay.fr *.ebaystatic.com *.ebaystatic.fr data: *.google-analytics.com *.doubleclick.net *.avalon.perfdrive.com *.ebayimg.com *.ucweb.com *.akamaihd.net *.ucads.ucweb.com *.analytics.google.com *.g.doubleclick.net *.googletagmanager.com *.pinterest.com *.snapchat.com *.criteo.com *.facebook.com *.googleapis.com *.googleadservices.com blob: analytics.google.com *.us.shoplive.cloud www.facebook.com *.bing.com www.googletagmanager.com google.com *.google.com *.graphitevault.com *.amplitude.com wss://127.0.0.1:* www.redditstatic.com *.reddit.com *.quantummetric.com; script-src 'self' 'unsafe-eval' 'unsafe-inline' https://* blob: data:; frame-ancestors 'self' *.ebay.com *.ebay.fr *.ebaystatic.com *.ebaystatic.fr; img-src 'self' data: blob: https://*; default-src 'self' blob: data: wss: mediastream: https://*; report-uri https://monitor.ebay.com/csp-report/discoveryplatformweb/HomePage?id=2939504940913871808&rid=t6gludlscuzujfwciunrce00%3C%3Dgludlscuzujfwciunrce00%2Bee%3C%3F371d0.qctp%3C2*tq%7C1p-19c35e921a9-0x2704#pd 1 default-src 'self' 'unsafe-inline' *.epfl.ch; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.epfl.ch https://*.cast.switch.ch https://ajax.googleapis.com https://cdnjs.cloudflare.com https://connect.facebook.net https://platform.twitter.com https://player.vimeo.com https://www.google-analytics.com https://www.googletagmanager.com https://www.instagram.com https://www.youtube.com; object-src 'none'; connect-src 'self' *.epfl.ch https://*.cast.switch.ch https://*.cloudfront.net https://*.google-analytics.com https://api.cdnjs.com https://stats.g.doubleclick.net https://www.google-analytics.com; frame-src 'self' *.epfl.ch https://api.cast.switch.ch https://datawrapper.dwcdn.net https://platform.twitter.com https://player.vimeo.com https://www.instagram.com https://www.youtube.com; style-src-elem 'self' 'unsafe-inline' *.epfl.ch https://fonts.googleapis.com; font-src 'self' data: *.epfl.ch https://fonts.gstatic.com; media-src 'self' data: *.epfl.ch https://*.cloudfront.net; img-src * data: https://s.w.org https://syndication.twitter.com https://www.google-analytics.com; worker-src 'none' blob:; report-uri https://report-uri.epfl.ch/csp-report; 1 script-src 'unsafe-inline' 'unsafe-eval' blob: data: https://www.googleadservices.com/pagead/conversion/ https://www.googletagmanager.com/gtag/js https://www.googletagmanager.com/gtag/destination https://www.google.com/js/bg/ https://www.gstatic.com/external_hosted/highlightjs/highlight.pack.js https://www.gstatic.com/monaco_editor/ https://fonts.gstatic.com/s/e/notoemoji/search/wrapper.js https://www.youtube.com/iframe_api https://translate.google.com/translate_a/element.js https://www-onepick-opensocial.googleusercontent.com/gadgets/js/rpc.js https://www.gstatic.com/_/mss/boq-one-google/_/ https://www.gstatic.com/og/_/js/ https://apis.google.com/js/api.js https://apis.google.com/js/client.js https://www.google.com/tools/feedback/chat_load.js https://www.google.com/tools/feedback/help_api.js https://www.google.com/tools/feedback/load.js https://www.google.com/tools/feedback/open.js https://www.google.com/tools/feedback/open_to_help_guide_lazy.js https://www.gstatic.com/feedback/js/ https://www.gstatic.com/feedback/js/help/prod/service/lazy.min.js https://www.gstatic.com/inproduct_help/api/main.min.js https://www.gstatic.com/inproduct_help/chatsupport/chatsupport_button_v2.js https://www.gstatic.com/inproduct_help/service/lazy.min.js https://www.gstatic.com/uservoice/feedback/client/web/live/ https://www.gstatic.com/uservoice/surveys/resources/prod/js/survey/ https://maps.googleapis.com/maps/api/js https://www.gstatic.com/_/mss/boq-bard-web/_/js/k=boq-bard-web.BardChatUi.en_US.GzqaIrI2Fhc.2018.O/ https://apis.google.com/_/scs/abc-static/_/js/ https://maps.googleapis.com/maps-api-v3/api/js/ https://maps.googleapis.com/maps/vt https://maps.googleapis.com/maps/api/js/ https://maps.googleapis.com/maps/api/place/js/ https://www.youtube.com/s/player/ https://translate.googleapis.com/_/translate_http/_/js/;report-uri /_/BardChatUi/cspreport/fine-allowlist 1 script-src 'nonce-ZsyXWY8ThgmRhA1pgb0b6A==' 'strict-dynamic' 'unsafe-eval' 'unsafe-inline' https: 'report-sample'; base-uri 'none'; report-uri https://events.mercadolibre.com/csp/reports?identifier=w1qeU4XKVwGbQGBuEKyE3KhFBIpr5IZSIaRiTowMc8UG7kU18vRsmBTEKL2krAj23LIS&policy_id=26548&user_id=&request_id=8b63e40e-5d99-41ce-b6b1-2536efb97c42; report-to csp-endpoint-wqeuxkvwgbqgbuekyekhfbiprizsiaritowmcugkuvrsmbteklkrajlis; object-src https://http2.mlstatic.com/ https://mlstaticquic-a.akamaihd.net/; frame-ancestors 'self' https://*.mercadolibre.cl:* https://*.mercadolibre.com:* https://*.mercadolibre.com.ve:* https://*.mercadolibre.com.ar:* https://*.mercadolivre.com.br:* https://*.mercadolibre.com.co:* https://*.mercadolibre.com.ec:* https://*.mercadolibre.com.mx:* https://*.mercadolibre.com.pe:* https://*.mercadolibre.com.uy:* https://*.mercadopago.cl:* https://*.mercadopago.com.ar:* https://*.mercadopago.com.br:* https://*.mercadopago.com.co:* https://*.mercadopago.com.mx:* https://*.mercadopago.com.pe:* https://*.mercadopago.com.uy:* https://*.mercadopago.com.ve:* https://*.mercadopago.com:* https://*.adminml.com:* https://*.mercadolibre.co.cr:* https://*.mercadolibre.com.pa:* https://*.mercadolibre.com.do:* https://*.mercadolibre.com.bo:* https://*.mercadolibre.com.py:* https://*.mercadolibre.com.gt:* https://*.mercadolibre.com.hn:* https://*.mercadolibre.com.ni:* https://*.mercadolibre.com.sv:* https://*.mercadopago.com.ec:* https://*.portalinmobiliario.com:* https://*.mercadolivre.com:* 1 require-trusted-types-for 'script'; report-uri https://csp.withgoogle.com/csp/uxe-owners-acl/chromebook 1 base-uri 'none'; default-src 'self'; script-src 'report-sample' 'self' 'unsafe-inline' https://cdn.heapanalytics.com https://distillery.wistia.com/x https://matillion.ddev.site:3000/ wss://matillion.ddev.site:3000 https://fast.wistia.com https://www.googletagmanager.com https://cdn.heapanalytics.com/js/heap-1873293713.js https://cdn.iubenda.com/cs/iubenda_cs.js https://connect.facebook.net/en_US/fbevents.js https://content.cdntwrk.com/components/website-widget/v1/118604/widget.js https://fast.wistia.com/assets/external/E-v1.js https://googleads.g.doubleclick.net/pagead/viewthroughconversion/848565924/ https://in.ml314.com/ud.ashx https://js.driftt.com/include/1688577300000/vh948h8ntehg.js https://js.intercomcdn.com/vendor-modern.255c4d36.js https://lift-ai-js.marketlinc.com/www.matillion.com/deployment.js https://ml314.com/tag.aspx https://munchkin.marketo.net/munchkin.js https://okt.to/ping https://pages.matillion.com/js/forms2/js/forms2.min.js https://script.hotjar.com/modules.832d10fb416834285523.js https://snap.licdn.com/li.lms-analytics/insight.beta.min.js https://static.ads-twitter.com/uwt.js https://static.hotjar.com/c/hotjar-2386626.js https://static.oktopost.com/oktrk.js https://tag.demandbase.com/00a4b81bfa345e5b.min.js https://tracking.g2crowd.com/attribution_tracking/conversions/5351.js https://widget.intercom.io/widget/rjk6vrpn https://www.google-analytics.com/analytics.js https://www.googleadservices.com/pagead/conversion/848565924/ https://www.googletagmanager.com/gtag/js https://www.iubenda.com/cookie-solution/confs/js/48216078.js https://www.redditstatic.com/ads/pixel.js; style-src 'self' 'unsafe-inline' https://p.typekit.net https://pages.matillion.com https://use.typekit.net; img-src 'self' data: 'self' data: https://alb.reddit.com https://analytics.twitter.com https://embed-ssl.wistia.com https://fast.wistia.com https://googleads.g.doubleclick.net https://heapanalytics.com https://id.rlcdn.com https://insight.adsrvr.org https://pubads.g.doubleclick.net https://px.ads.linkedin.com https://t.co https://www.facebook.com https://www.google-analytics.com https://www.google.com; connect-src 'self' https://992-uiw-731.mktoresp.com https://analytics.google.com https://api-iam.intercom.io https://api.company-target.com https://content.hotjar.io https://distillery.wistia.com https://fast.wistia.com https://fg8vvsvnieiv3ej16jby.litix.io https://google.com https://hits-i.iubenda.com https://in.hotjar.com https://metrics.hotjar.io https://stats.g.doubleclick.net https://tag-logger.demandbase.com https://v2.api.uberflip.com https://visitor-scoring-c.marketlinc.com https://www.google-analytics.com https://www.google.com wss://nexus-websocket-a.intercom.io wss://ws.hotjar.com; font-src 'self' 'self' data: https://fast.wistia.com https://use.typekit.net; media-src 'self' blob:; frame-src 'self' 'self' https://12420912.fls.doubleclick.net https://js.driftt.com https://pages.matillion.com https://s.company-target.com https://www.facebook.com; 1 script-src 'self' addtocalendar.com cdn.amcharts.com cdn.jsdelivr.net https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://stage-unifiedsearch.geapps.io https://unifiedsearch.geapps.io https://www.google.com; script-src-attr 'self'; style-src 'self' addtocalendar.com cdn.jsdelivr.net cdnjs.cloudflare.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://stage-unifiedsearch.geapps.io https://unifiedsearch.geapps.io maxcdn.bootstrapcdn.com; style-src-attr 'self'; frame-ancestors 'self' 1 default-src 'self' 'unsafe-inline'; connect-src *; font-src 'self' data:; frame-src *; img-src 'self' data: https://core-renderer-tiles.maps.yandex.net https://yandex.ru/ https://api-maps.yandex.ru https://mc.yandex.ru/; script-src 'self' 'unsafe-eval' 'unsafe-inline' https://api-maps.yandex.ru https://mc.yandex.ru/metrika/tag.js https://cdn.redoc.ly; script-src-elem 'self' 'unsafe-eval' 'unsafe-inline' https://core-renderer-tiles.maps.yandex.net https://yastatic.net https://api-maps.yandex.ru/ https://mc.yandex.ru/metrika/tag.js https://smartcaptcha.yandexcloud.net/captcha.js https://cdn.redoc.ly; object-src none; report-uri https://csp.nspk.ru/report; 1 script-src 'unsafe-eval' blob: 'self' meta.wikimedia.org *.wikimedia.org *.wikipedia.org *.wikinews.org *.wiktionary.org *.wikibooks.org *.wikiversity.org *.wikisource.org wikisource.org *.wikiquote.org *.wikidata.org *.wikifunctions.org *.wikivoyage.org *.mediawiki.org 'unsafe-inline' auth.wikimedia.org; default-src 'self' data: blob: upload.wikimedia.org https://commons.wikimedia.org meta.wikimedia.org *.wikimedia.org *.wikipedia.org *.wikinews.org *.wiktionary.org *.wikibooks.org *.wikiversity.org *.wikisource.org wikisource.org *.wikiquote.org *.wikidata.org *.wikifunctions.org *.wikivoyage.org *.mediawiki.org wikimedia.org en.wikipedia.org en.wikibooks.org en.wikinews.org en.wikiquote.org en.wikisource.org en.wikiversity.org en.wikivoyage.org en.wiktionary.org www.mediawiki.org api.wikimedia.org commons.wikimedia.org foundation.wikimedia.org incubator.wikimedia.org species.wikimedia.org wikimania.wikimedia.org www.wikifunctions.org auth.wikimedia.org; style-src 'self' data: blob: upload.wikimedia.org https://commons.wikimedia.org meta.wikimedia.org *.wikimedia.org *.wikipedia.org *.wikinews.org *.wiktionary.org *.wikibooks.org *.wikiversity.org *.wikisource.org wikisource.org *.wikiquote.org *.wikidata.org *.wikifunctions.org *.wikivoyage.org *.mediawiki.org wikimedia.org 'unsafe-inline'; object-src 'none'; report-uri /w/api.php?action=cspreport&format=json&reportonly=1 1 default-src 'nonce-edde1d0db60d4d5e97dfb3c8ed678596' 'self' data: https: blob:; img-src 'self' data: https: http: blob:; script-src 'nonce-edde1d0db60d4d5e97dfb3c8ed678596' 'self' 'nonce-A318B756DBF3ABFFF9D9AC2AA2112D83F3B77468683C8983C4A75141DAC7DEC9' *.enable-now.cloud.sap *.salesforceliveagent.com *.siteintercept.qualtrics.com *.walkme.com *.liveperson.net *.ssl.ak.dynamic.tiles.virtualearth.net *.concursolutions.com *.sapdas-staging.cloud.sap *.sapdas.cloud.sap code.jquery.com consent.trustarc.com dev.virtualearth.net storage.glancecdn.net www.glancecdn.net www.google-analytics.com assets.adobedtm.com bam.nr-data.net maps.googleapis.com www.google-analytics.com www.googletagmanager.com siteintercept.qualtrics.com ajax.googleapis.com static.contextall.com *.bing.com www.vfmii.com blob:; style-src 'self' 'unsafe-inline' https: blob:; connect-src wss://*.glance.net 'self' https:; report-uri https://concursolutions.report-uri.com/r/t/csp/reportOnly; report-to report-only 1 object-src 'none';base-uri 'self';script-src 'nonce-TiKJh8jUBz6_Zhh_kMlkJQ' 'strict-dynamic' 'report-sample' 'unsafe-eval' 'unsafe-inline' https: http:;report-uri https://csp.withgoogle.com/csp/gws/other-hp 1 default-src * 'unsafe-inline' 'unsafe-eval' data: blob:; worker-src 'self' blob:; script-src 'unsafe-inline' 'unsafe-eval' 'self' static.prdg.io/ ucontent.prdg.io *.mogl.com swagbucks.7eer.net/js/799/1700/irv2.js *.abtasty.com *.adsafeprotected.com *.amplitude.com appleid.cdn-apple.com cdn.auryc.com js.authorize.net completr-v2.appspot.com sugg.search.yahoo.net/sg/ bat.bing.com www.clarity.ms tags.clickagy.com t.contentsquare.net app.contentsquare.com cdn.cookielaw.org swagbucks.disqus.com/embed.js swagbucks-qa.disqus.com/embed.js googleads.g.doubleclick.net *.doubleverify.com www.dwin1.com pf.entertainow.com load.exelator.com connect.facebook.net gwiqcdn.globalwebindex.net accounts.google.com/gsi/client apis.google.com/js/ translate.google.com www.google.com/jsapi www.google.com/pagead/ www.google.com/recaptcha/ *.google-analytics.com www.googleadservices.com maps.googleapis.com storage.googleapis.com/pollfish_production/ tpc.googlesyndication.com www.googletagmanager.com www.googletagservices.com www.gstatic.com/recaptcha/ *.equalweb.com cdn.us.heap-api.com cdn.heapanalytics.com heapanalytics.com cdn.hellosign.com hideout.tv script.hotjar.com static.hotjar.com mpsnare.iesnare.com d.impactradius-event.com cso2.imperium.com secure-gl.imrworldwide.com secure.insightexpressai.com surveys.insightexpressai.com media-cdn.ipredictive.com app.lifesight.io/personica.js global.localizecdn.com api.maruusurv-serving.com img.macromill.com privacyportal-cdn.onetrust.com on-device.com www.paypalobjects.com aalert.peanutlabs.com pix.pub api.prsrvy.com rules.quantcount.com secure.quantserve.com idsync.reson8.com publishers.revenueuniverse.com wsdk.rokt.com cn.rtclx.com *.scorecardresearch.com classic.slingo.com js.stripe.com jsd.supersonicads.com js.swagbucks.com cdn.taboola.com analytics.tiktok.com transcend-cdn.com widget.trustpilot.com platform.twitter.com web-sdk.urbanairship.com *.voicefive.com *.visualwebsiteoptimizer.com app.vwo.com cdn.pushcrew.com useruploads.vwo.io cdn.wootric.com static.zdassets.com assets.zendesk.com www.p.zjptg.com/tag/ cdnjs.cloudflare.com/ajax/libs/crypto-js/ cdnjs.cloudflare.com/ajax/libs/intl-tel-input/ cdnjs.cloudflare.com/ajax/libs/inputmask/4.0.8/inputmask/inputmask.min.js cdnjs.cloudflare.com/polyfill/ d33wwcok8lortz.cloudfront.net/js/799/ d3op16id4dloxg.cloudfront.net/CSOWrapperAjax3.js d3op16id4dloxg.cloudfront.net/RelevantID4.js *.verisoul.ai *.zendesk.com; script-src-elem 'unsafe-inline' 'unsafe-eval' 'self' static.prdg.io/ ucontent.prdg.io *.mogl.com swagbucks.7eer.net/js/799/1700/irv2.js *.abtasty.com *.adsafeprotected.com *.amplitude.com appleid.cdn-apple.com cdn.auryc.com js.authorize.net completr-v2.appspot.com sugg.search.yahoo.net/sg/ bat.bing.com www.clarity.ms tags.clickagy.com t.contentsquare.net app.contentsquare.com cdn.cookielaw.org swagbucks.disqus.com/embed.js swagbucks-qa.disqus.com/embed.js googleads.g.doubleclick.net *.doubleverify.com www.dwin1.com pf.entertainow.com load.exelator.com connect.facebook.net gwiqcdn.globalwebindex.net accounts.google.com/gsi/client apis.google.com/js/ translate.google.com www.google.com/jsapi www.google.com/pagead/ www.google.com/recaptcha/ *.google-analytics.com www.googleadservices.com maps.googleapis.com storage.googleapis.com/pollfish_production/ tpc.googlesyndication.com www.googletagmanager.com www.googletagservices.com www.gstatic.com/recaptcha/ *.equalweb.com cdn.us.heap-api.com cdn.heapanalytics.com heapanalytics.com cdn.hellosign.com hideout.tv script.hotjar.com static.hotjar.com mpsnare.iesnare.com d.impactradius-event.com cso2.imperium.com secure-gl.imrworldwide.com secure.insightexpressai.com surveys.insightexpressai.com media-cdn.ipredictive.com app.lifesight.io/personica.js global.localizecdn.com api.maruusurv-serving.com img.macromill.com privacyportal-cdn.onetrust.com on-device.com www.paypalobjects.com aalert.peanutlabs.com pix.pub api.prsrvy.com rules.quantcount.com secure.quantserve.com idsync.reson8.com publishers.revenueuniverse.com wsdk.rokt.com cn.rtclx.com *.scorecardresearch.com classic.slingo.com js.stripe.com jsd.supersonicads.com js.swagbucks.com cdn.taboola.com analytics.tiktok.com transcend-cdn.com widget.trustpilot.com platform.twitter.com web-sdk.urbanairship.com *.voicefive.com *.visualwebsiteoptimizer.com app.vwo.com cdn.pushcrew.com useruploads.vwo.io cdn.wootric.com static.zdassets.com assets.zendesk.com www.p.zjptg.com/tag/ cdnjs.cloudflare.com/ajax/libs/crypto-js/ cdnjs.cloudflare.com/ajax/libs/intl-tel-input/ cdnjs.cloudflare.com/ajax/libs/inputmask/4.0.8/inputmask/inputmask.min.js cdnjs.cloudflare.com/polyfill/ d33wwcok8lortz.cloudfront.net/js/799/ d3op16id4dloxg.cloudfront.net/CSOWrapperAjax3.js d3op16id4dloxg.cloudfront.net/RelevantID4.js *.verisoul.ai *.zendesk.com; report-uri https://csp.prodege.workers.dev/report 1 object-src 'none';base-uri 'self';script-src 'nonce-zPisetxw5QXB2tmYjvOK6A' 'strict-dynamic' 'report-sample' 'unsafe-eval' 'unsafe-inline' https: http:;report-uri https://csp.withgoogle.com/csp/gws/other-hp 1 object-src 'none'; script-src-elem 'self' 'unsafe-inline' 'unsafe-eval' https://*.kolesa.kz https://kolesa.kz wss://*.kolesa.kz https://sentry-common.kolesa.team yastatic.net *.adfox.ru *.yandex.ru *.yandex.net *.yandex.kz *.yandex.com yandex.ru yandex.kz yandex.com yandexadexchange.net *.ftd.agency *.google-analytics.com *.googletagmanager.com *.doubleclick.net *.google.com *.google.kz *.google.co.uz *.googlesyndication.com *.googleadservices.com *.gstatic.com *.ampproject.org *.segmentstream.com *.facebook.net *.facebook.com *.tiktok.com *.youtube.com; report-to csp-endpoint 1 script-src 'nonce-iPMRH/GiRJcOoxPr4lOHxg==' 'strict-dynamic' 'unsafe-eval' 'unsafe-inline' https: 'report-sample'; base-uri 'none'; report-uri https://events.mercadolibre.com/csp/reports?identifier=w1qeU4XKVwGbQGBuEKyE3KhFBIpr5IZSIaRiTowMc8UG7kU18vRsmBTEKL2krAj23LIS&policy_id=26548&user_id=&request_id=568f81e1-2ae7-4e15-8001-600069836203; report-to csp-endpoint-wqeuxkvwgbqgbuekyekhfbiprizsiaritowmcugkuvrsmbteklkrajlis; object-src https://http2.mlstatic.com/ https://mlstaticquic-a.akamaihd.net/; frame-ancestors 'self' https://*.mercadolibre.cl:* https://*.mercadolibre.com:* https://*.mercadolibre.com.ve:* https://*.mercadolibre.com.ar:* https://*.mercadolivre.com.br:* https://*.mercadolibre.com.co:* https://*.mercadolibre.com.ec:* https://*.mercadolibre.com.mx:* https://*.mercadolibre.com.pe:* https://*.mercadolibre.com.uy:* https://*.mercadopago.cl:* https://*.mercadopago.com.ar:* https://*.mercadopago.com.br:* https://*.mercadopago.com.co:* https://*.mercadopago.com.mx:* https://*.mercadopago.com.pe:* https://*.mercadopago.com.uy:* https://*.mercadopago.com.ve:* https://*.mercadopago.com:* https://*.adminml.com:* https://*.mercadolibre.co.cr:* https://*.mercadolibre.com.pa:* https://*.mercadolibre.com.do:* https://*.mercadolibre.com.bo:* https://*.mercadolibre.com.py:* https://*.mercadolibre.com.gt:* https://*.mercadolibre.com.hn:* https://*.mercadolibre.com.ni:* https://*.mercadolibre.com.sv:* https://*.mercadopago.com.ec:* https://*.portalinmobiliario.com:* https://*.mercadolivre.com:* 1 object-src 'none'; script-src 'self' 'unsafe-inline' 'unsafe-eval' adform.net *.adform.net betano.com *.betano.com betgenius.com *.betgenius.com bing.com *.bing.com cloudflare.com *.cloudflare.com cookielaw.org *.cookielaw.org creativecdn.com *.creativecdn.com facebook.net *.facebook.net fullstory.com *.fullstory.com gmlinteractive.com *.gmlinteractive.com googletagmanager.com *.googletagmanager.com kaizengaming.com *.kaizengaming.com kameleoon.eu *.kameleoon.eu kameleoon.io *.kameleoon.io optimove.net *.optimove.net sportradar.com *.sportradar.com cloudflareinsights.com *.cloudflareinsights.com app.delivery *.app.delivery bet.br *.bet.br google-analytics.com *.google-analytics.com lgrckt-in.com *.lgrckt-in.com tostarsbuilding.com *.tostarsbuilding.com sportradarserving.com *.sportradarserving.com; report-uri https://csp-reporting.cloudflare.com/cdn-cgi/script_monitor/report?m=RCNNrdpkU19ME6tZphYtaBPvQOCIlcBvPbn7rTCUJjg-1770426819-1.0.1.1-1h5ONDUexD5E81vU9Q5URE4BTx1VVmrz1JSnkjENy.O_XQlkFk5uNpb0bYqguXZrzmA0kJRH9AKSSwsPcmZNhiti1Nh9C9FIDIpa2v8RqjhQaIUcXfHL2XARVzU5pZbcW4wpU7W5NaIA6Cw8iTYxpnc4QPCKjcgOHgV3LvIt4Pl20aFXZ9oVhHC__YAkj.fqlf2QcqqVXknYOIMhCbb_Dg; report-to cf-buwbjdkhsoeenlwv 1 frame-ancestors 'none'; object-src 'none'; report-to https://browser-intake-datadoghq.eu/api/v2/logs?dd-api-key=pub5b9d250bbda65cde913b47e33482ee7e&dd-evp-origin=content-security-policy&ddsource=csp-report&ddtags=env%3Aprod%2Cservice%3Aameno%2Cversion%3Abrlm_1.67.3; 1 base-uri 'self'; connect-src https: wss: blob:; default-src 'none'; font-src https: data:; frame-src https: blob:; img-src https: data: blob:; manifest-src 'self'; media-src https:; object-src 'none'; script-src 'report-sample' 'self' 'unsafe-inline' 'unsafe-eval' https://api.compass.com https://app-glide.compass.com https://cdn.heapanalytics.com https://heapanalytics.com https://cdn.segment.com https://connect.facebook.net https://edge.fullstory.com/s/ https://maps.googleapis.com/maps/api/js/ https://static.zdassets.com/ekr/snippet.js https://static.filestackapi.com https://web-sdk.aptrinsic.com/api/aptrinsic.js https://www.datadoghq-browser-agent.com https://www.google-analytics.com https://www.googleadservices.com https://www.google.com/recaptcha/ https://maps.googleapis.com https://apis.google.com https://www.gstatic.com https://www.googletagmanager.com https://js.stripe.com https://stats.pusher.com https://widget.intercom.io https://js.intercomcdn.com https://boards.greenhouse.io https://siteintercept.qualtrics.com https://zn0feyon15oqdwcu1-compass.siteintercept.qualtrics.com https://www.youtube.com https://googleads.g.doubleclick.net https://snap.licdn.com https://js.hubspot.com https://js.hs-analytics.net https://js.hs-scripts.com https://js.hsadspixel.net https://js.hs-banner.com https://fast.wistia.com https://js.userpilot.io https://deploy.userpilot.io https://t.contentsquare.net https://consent.trustarc.com https://api.compass.com https://ajax.googleapis.com https://cdnjs.cloudflare.com https://unpkg.com https://cdn.jsdelivr.net https://code.jquery.com; script-src-elem 'report-sample' 'self' 'unsafe-inline' 'unsafe-eval' https://api.compass.com https://app-glide.compass.com https://cdn.heapanalytics.com https://heapanalytics.com https://cdn.segment.com https://connect.facebook.net https://edge.fullstory.com/s/ https://maps.googleapis.com/maps/api/js/ https://static.zdassets.com/ekr/snippet.js https://static.filestackapi.com https://web-sdk.aptrinsic.com/api/aptrinsic.js https://www.datadoghq-browser-agent.com https://www.google-analytics.com https://www.googleadservices.com https://www.google.com/recaptcha/ https://maps.googleapis.com https://apis.google.com https://www.gstatic.com https://www.googletagmanager.com https://js.stripe.com https://stats.pusher.com https://widget.intercom.io https://js.intercomcdn.com https://boards.greenhouse.io https://siteintercept.qualtrics.com https://zn0feyon15oqdwcu1-compass.siteintercept.qualtrics.com https://www.youtube.com https://googleads.g.doubleclick.net https://snap.licdn.com https://js.hubspot.com https://js.hs-analytics.net https://js.hs-scripts.com https://js.hsadspixel.net https://js.hs-banner.com https://fast.wistia.com https://js.userpilot.io https://deploy.userpilot.io https://t.contentsquare.net https://consent.trustarc.com https://api.compass.com https://ajax.googleapis.com https://cdnjs.cloudflare.com https://unpkg.com https://cdn.jsdelivr.net https://code.jquery.com; style-src 'report-sample' 'self' 'unsafe-inline' https://uc-frontend-assets.compass.com https://app-glide.compass.com https://www.google-analytics.com https://www.googletagmanager.com https://fonts.googleapis.com https://static.filestackapi.com https://web-sdk.aptrinsic.com https://www.gstatic.com https://cdnjs.cloudflare.com https://cdn.jsdelivr.net https://unpkg.com blob:; worker-src 'self' blob:; report-uri /csp-report/?key=new 1 default-src data: 'unsafe-inline' 'unsafe-eval' https: blob: http://*.files.wordpress.com wss://www.indiewire.com; report-uri https://pmcuri.report-uri.com/r/d/csp/reportOnly 1 default-src 'self' lesta.ru *.lesta.ru tanki.su *.tanki.su *.edgevideo.ru https://www.youtube.com ; script-src 'self' 'unsafe-inline' 'unsafe-eval' tanki.su *.tanki.su lesta.ru *.lesta.ru *.tvsquared.com *.soloway.ru *.cookielaw.org *.onetrust.com *.outbrain.com *.snapchat.com *.edgevideo.ru https://image.sendsay.ru https://top-fwz1.mail.ru https://privacy-cs.mail.ru https://vk.com https://sc-static.net https://ob.cheqzone.com https://analytics.google.com https://www.google.com https://*.adform.net https://www.googleoptimize.com https://www.googletagmanager.com https://*.google-analytics.com https://*.analytics.google.com https://www.googleadservices.com https://*.yandex.ru https://*.yandex.net https://*.yandex.ua https://*.yandex.by https://*.yandex.kz https://*.yandex.com.tr http://*.yandex.ru http://*.yandex.net http://*.yandex.ua http://*.yandex.by http://*.yandex.kz http://*.yandex.com.tr https://*.yandex.st https://*.yandex.com https://*.yandex.fr https://yandex.st https://u360.d-bi.fr https://bat.bing.com https://connect.ok.ru https://*.vk.com https://googleads.g.doubleclick.net https://*.adroll.com https://*.addthis.com https://*.addthisedge.com https://tag.marinsm.com https://pixel-geo.prfct.co https://static.criteo.net https://stackadapt.com https://*.creative-serving.com https://*.criteo.com https://*.vihub.ru https://*.cloudfront.net https://js.gleam.io https://a1.adform.net https://ajax.googleapis.com https://www.youtube.com https://animate.adobe.com https://inv-dmp.admixer.net ; style-src 'self' 'unsafe-inline' lesta.ru *.lesta.ru tanki.su *.tanki.su https://fonts.googleapis.com ; img-src 'self' data: android-webview-video-poster: * ; connect-src 'self' lesta.ru *.lesta.ru tanki.su *.tanki.su *.edgevideo.ru *.cookielaw.org *.onetrust.com *.outbrain.com *.snapchat.com https://privacy-cs.mail.ru https://sendsay.ru https://sc-static.net https://ob.cheqzone.com https://analytics.google.com https://www.google.com wss://lesta.ru wss://tanki.su wss://*.lstprod.net https://stats.g.doubleclick.net https://*.yandex.ru https://*.yandex.net https://*.yandex.ua https://*.yandex.by https://*.yandex.kz https://*.yandex.com.tr http://*.yandex.ru http://*.yandex.net http://*.yandex.ua http://*.yandex.by http://*.yandex.kz http://*.yandex.com.tr https://*.yandex.st https://*.yandex.com https://*.yandex.fr https://*.addthis.com https://*.google-analytics.com https://*.analytics.google.com https://ymetrica1.com https://*.cloudfront.net https://google.com https://google.ru https://google.com.ua https://google.by https://www.googleoptimize.com https://google.pl https://*.doubleclick.net https://*.googleapis.com ; font-src 'self' lesta.ru *.lesta.ru *.tanki.su https://fonts.gstatic.com ; media-src 'self' lesta.ru *.lesta.ru tanki.su *.tanki.su *.edgevideo.ru ; frame-src 'self' lesta.ru *.lesta.ru tanki.su *.tanki.su *.edgevideo.ru https://*.yandex.ru https://webwisor.com https://metrika.yandex.ru https://metrika.yandex.by https://metrica.yandex.com https://metrica.yandex.com.tr https://tr.snapchat.com https://creativecdn.com https://*.adform.net https://ad3.adfarm1.adition.com https://www.youtube.com https://bid.g.doubleclick.net https://*.criteo.com https://yastatic.net https://*.addthis.com https://gleam.io https://aax-eu.amazon-adsystem.com ; frame-ancestors 'self' https://webwisor.com https://metrika.yandex.ru https://metrika.yandex.by https://metrica.yandex.com https://metrica.yandex.com.tr ; object-src 'self' lesta.ru *.lesta.ru tanki.su *.tanki.su *.edgevideo.ru https://www.youtube.com ; report-uri https://cspreport.lesta.ru/cspreport 1 object-src 'none'; script-src 'self' 'report-sample' addtocalendar.com cdnjs.cloudflare.com https://cdn.jsdelivr.net https://cdn.knightlab.com https://cdnjs.cloudflare.com https://code.jquery.com https://science-catalog.fws.gov https://touchpoints.app.cloud.gov https://unpkg.com https://www.google.com maps.google.com unpkg.com; style-src 'self' 'report-sample' addtocalendar.com cdnjs.cloudflare.com fonts.googleapis.com https://cdn.jsdelivr.net https://cdn.knightlab.com https://cdnjs.cloudflare.com https://fonts.googleapis.com https://science-catalog.fws.gov https://unpkg.com unpkg.com; webrtc 'block'; worker-src 'self'; base-uri 'self'; form-action 'self'; frame-ancestors 'self' 1 default-src https: wss: data: blob: 'unsafe-eval' 'unsafe-inline'; frame-ancestors 'self'; report-uri /_/csp-reports 1 frame-ancestors 'self' https://www.rferl.org/embed https://www.rferl.org/embed/player https://www.rferl.org/embed/player/0 https://www.rferl.org/embed/player/1 https://www.rferl.org/ext https://www.rferl.org/widget; report-uri https://csp.pangeadigital.io/cspreport 1 script-src 'strict-dynamic' 'self' https: 'nonce-6bbc5685f87d82d081c1dc87fcedc1cfb6b45f31'; script-src-elem 'self' 'nonce-6bbc5685f87d82d081c1dc87fcedc1cfb6b45f31'; object-src 'none'; base-uri 'none'; report-to csp-report; frame-ancestors 'self' 1 default-src 'self'; script-src 'self' 'unsafe-inline' https://cdnjs.cloudflare.com https://client-registry.mutinycdn.com https://js.qualified.com/ https://unpkg.com/ https://analytics.ahrefs.com https://fast.wistia.com https://connect.facebook.net https://browser.sentry-cdn.com;style-src 'self' 'unsafe-inline'; img-src 'self' https://logicmonitor.com https://www.logicmonitor.com https://d21y75miwcfqoq.cloudfront.net https://fast.wistia.com https://embed-ssl.wistia.com; media-src 'self' blob:; font-src 'self' data: https://fast.wistia.com; object-src 'none'; base-uri 'self'; form-action 'none'; frame-ancestors 'self' https://*.logicmonitor.com; frame-src 'self' https://logicmonitor.com https://www.logicmonitor.com ; connect-src 'self' https://app.qualified.com wss://ws2.qualified.com https://fast.wistia.com https://pipedream.wistia.com https://distillery.wistia.com https://embed-cloudfront.wistia.com https://fg8vvsvnieiv3ej16jby.litix.io;upgrade-insecure-requests; report-uri /wp-json/lm/v1/csp-report; report-to csp_report; 1 default-src 'self' data: blob: https://*.bamboohr.com https://*.bamboohr.co.uk https://*.trustarc.com https://secure.feed5mown.com https://cdn.bizible.com https://bat.bing.com https://connect.facebook.com https://connect.facebook.net https://dbm.demdex.net https://bamboohr.demdex.net https://*.licdn.com https://*.hotjar.com https://tracking.g2crowd.com https://static.ads-twitter.com https://script.googleusercontent.com https://munchkin.marketo.com https://munchkin.marketo.net https://cdn.abrankings.com https://a.quora.com https://q.quora.com https://*.clarity.ms https://*.thebrightforks.com https://dx.mountain.com https://tag.clearbitscripts.com https://cdn.pdst.fm https://x.clearbitjs.com https://app.clearbitjs.com https://www.googletagmanager.com https://www.redditstatic.com https://snap.licdn.com https://www.google-analytics.com https://assets.adobedtm.com https://activitymap.adobe.com https://www.googleoptimize.com https://googleads.g.doubleclick.net https://abm-tracking.demandscience.com https://cdnjs.cloudflare.com https://cdn.jsdelivr.net https://match.prod.bidr.io https://bamboohr.zendesk.com https://*.zdassets.com https://assets.screensteps.com https://fast.wistia.com https://fast.wistia.net https://unpkg.com https://*.convertexperiments.com https://js.intercomcdn.com https://cdn.readme.io https://*.tiktok.com https://fonts.gstatic.com https://fonts.googleapis.com https://edge.adobedc.net https://adobedc.demdex.net https://stats.g.doubleclick.net https://www.google.com https://analytics.google.com https://*.mktoresp.com https://*.clearbit.com https://*.linkedin.com https://t.co https://*.twitter.com https://*.facebook.com https://tracking.contanuity.com https://c.bing.com https://*.hlx.page https://*.hlx.live https://bamboohr--webchat.sandbox.my.site.com https://bamboohr--webchat.sandbox.my.salesforce-scrt.com https://bamboohr.my.site.com https://bamboohr.my.salesforce-scrt.com https://js.driftt.com https://static.cloudflareinsights.com https://script.crazyegg.com https://rc-widget-frame.js.driftt.com https://arttrk.com https://intentstream.contanuity.com https://td.doubleclick.net https://bamboohr.com wss://ws.hotjar.com https://*.hotjar.io https://*.gstatic.com https://*.leandata.com https://195-loz-515.mktoutil.com https://*.bizibly.com https://*.google.com.ua https://www.google.ca https://www.getapp.com https://*.wistia.com https://*.honey.io https://boards.greenhouse.io https://*.ucweb.com https://qvdt3feo.com https://*.srv.stackadapt.com https://ct.capterra.com https://*.youtube.com https://*.googleadservices.com https://hook.us1.make.celonis.com https://bamboohr.formstack.com https://*.google.com https://*.google.ad https://*.google.ae https://*.google.com.af https://*.google.com.ag https://*.google.al https://*.google.am https://*.google.co.ao https://*.google.com.ar https://*.google.as https://*.google.at https://*.google.com.au https://*.google.az https://*.google.ba https://*.google.com.bd https://*.google.be https://*.google.bf https://*.google.bg https://*.google.com.bh https://*.google.bi https://*.google.bj https://*.google.com.bn https://*.google.com.bo https://*.google.com.br https://*.google.bs https://*.google.bt https://*.google.co.bw https://*.google.by https://*.google.com.bz https://*.google.ca https://*.google.cd https://*.google.cf https://*.google.cg https://*.google.ch https://*.google.ci https://*.google.co.ck https://*.google.cl https://*.google.cm https://*.google.cn https://*.google.com.co https://*.google.co.cr https://*.google.com.cu https://*.google.cv https://*.google.com.cy https://*.google.cz https://*.google.de https://*.google.dj https://*.google.dk https://*.google.dm https://*.google.com.do https://*.google.dz https://*.google.com.ec https://*.google.ee https://*.google.com.eg https://*.google.es https://*.google.com.et https://*.google.fi https://*.google.com.fj https://*.google.fm https://*.google.fr https://*.google.ga https://*.google.ge https://*.google.gg https://*.google.com.gh https://*.google.com.gi https://*.google.gl https://*.google.gm https://*.google.gr https://*.google.com.gt https://*.google.gy https://*.google.com.hk https://*.google.hn https://*.google.hr https://*.google.ht https://*.google.hu https://*.google.co.id https://*.google.ie https://*.google.co.il https://*.google.im https://*.google.co.in https://*.google.iq https://*.google.is https://*.google.it https://*.google.je https://*.google.com.jm https://*.google.jo https://*.google.co.jp https://*.google.co.ke https://*.google.com.kh https://*.google.ki https://*.google.kg https://*.google.co.kr https://*.google.com.kw https://*.google.kz https://*.google.la https://*.google.com.lb https://*.google.li https://*.google.lk https://*.google.co.ls https://*.google.lt https://*.google.lu https://*.google.lv https://*.google.com.ly https://*.google.co.ma https://*.google.md https://*.google.me https://*.google.mg https://*.google.mk https://*.google.ml https://*.google.com.mm https://*.google.mn https://*.google.com.mt https://*.google.mu https://*.google.mv https://*.google.mw https://*.google.com.mx https://*.google.com.my https://*.google.co.mz https://*.google.com.na https://*.google.com.ng https://*.google.com.ni https://*.google.ne https://*.google.nl https://*.google.no https://*.google.com.np https://*.google.nr https://*.google.nu https://*.google.co.nz https://*.google.com.om https://*.google.com.pa https://*.google.com.pe https://*.google.com.pg https://*.google.com.ph https://*.google.com.pk https://*.google.pl https://*.google.pn https://*.google.com.pr https://*.google.ps https://*.google.pt https://*.google.com.py https://*.google.com.qa https://*.google.ro https://*.google.ru https://*.google.rw https://*.google.com.sa https://*.google.com.sb https://*.google.sc https://*.google.se https://*.google.com.sg https://*.google.sh https://*.google.si https://*.google.sk https://*.google.com.sl https://*.google.sn https://*.google.so https://*.google.sm https://*.google.sr https://*.google.st https://*.google.com.sv https://*.google.td https://*.google.tg https://*.google.co.th https://*.google.com.tj https://*.google.tl https://*.google.tm https://*.google.tn https://*.google.to https://*.google.com.tr https://*.google.tt https://*.google.com.tw https://*.google.co.tz https://*.google.com.ua https://*.google.co.ug https://*.google.co.uk https://*.google.com.uy https://*.google.co.uz https://*.google.com.vc https://*.google.co.ve https://*.google.co.vi https://*.google.com.vn https://*.google.vu https://*.google.ws https://*.google.rs https://*.google.co.za https://*.google.co.zm https://*.google.co.zw https://*.google.cat https://*.qualified.com https://js.qualified.com https://app.qualified.com https://*.6sc.co https://*.zi-scripts.com https://mapixl.com https://*.metadata.io https://tvspix.com https://*.ipify.org https://*.6sense.com https://*.zoominfo.com https://*.cloudinary.com https://*.googlesyndication.com https://*.adsrvr.org https://*.clickagy.com 'unsafe-inline' 'unsafe-eval'; report-uri https://app.bamboohr.com/ajax/parse_csp_report.php; report-to https://app.bamboohr.com/ajax/parse_csp_report.php; 1 default-src 'self' 'nonce-Z2lyJDDcYQ86bNvIjNYQyMN10UBU1kuyZc49kWPAFVc=' 'strict-dynamic' https:; script-src 'nonce-Z2lyJDDcYQ86bNvIjNYQyMN10UBU1kuyZc49kWPAFVc=' 'sha512-gU7kztaQEl7SHJyraPfZLQCNnrKdaQi5ndOyt4L4UPL/FHDd/uB9Je6KDARIqwnNNE27hnqoWLBq+Kpe4iHfeQ==' 'sha512-DXYctkkhmMYJ4vYp4Dm6jprD4ZareZ7ud/d9mGCKif/Dt3FnN95SjogHvwKvxXHoMAAkZX6EO6ePwpDIR1Y8jw==' 'sha512-mz4SrGyk+dtPY9MNYOMkD81gp8ajViZ4S0VDuM/Zqg40cg9xgIBYSiL5fN79Htbz4f2+uR9lrDO6mgcjM+NAXA==' 'sha512-pnt8OPBTOklRd4/iSW7msOiCVO4uvffF17Egr3c7AaN0h3qFnSu7L6UmdZJUCednMhhruTLRq7X9WbyAWNBegw==' 'strict-dynamic' https:; font-src 'self' https://res-1.cdn.office.net/files/fabric-cdn-prod_20221201.001/assets/fonts/ https://res-1.cdn.office.net/files/fabric-cdn-prod_20221201.001/assets/icons/ 'nonce-Z2lyJDDcYQ86bNvIjNYQyMN10UBU1kuyZc49kWPAFVc='; base-uri 'none'; form-action 'self' 'nonce-Z2lyJDDcYQ86bNvIjNYQyMN10UBU1kuyZc49kWPAFVc='; style-src 'self' 'nonce-Z2lyJDDcYQ86bNvIjNYQyMN10UBU1kuyZc49kWPAFVc='; report-uri ; object-src 'none'; frame-ancestors 'none'; 1 object-src 'none';base-uri 'self';script-src 'nonce-i2mKNKgJFr4zG3SUc9F4gA' 'strict-dynamic' 'report-sample' 'unsafe-eval' 'unsafe-inline' https: http:;report-uri https://csp.withgoogle.com/csp/gws/other-hp 1 object-src 'none';base-uri 'self';script-src 'nonce-MfOt92_YfOwIc45PBe7y7A' 'strict-dynamic' 'report-sample' 'unsafe-eval' 'unsafe-inline' https: http:;report-uri https://csp.withgoogle.com/csp/gws/other-hp 1 object-src 'none';base-uri 'self';script-src 'nonce-uIYGVPNr8Hjz8E3F6x6Kvg' 'strict-dynamic' 'report-sample' 'unsafe-eval' 'unsafe-inline' https: http:;report-uri https://csp.withgoogle.com/csp/gws/other-hp 1 object-src 'none';base-uri 'self';script-src 'nonce-B_JTxNvY0VUgwyvwD5Qy-w' 'strict-dynamic' 'report-sample' 'unsafe-eval' 'unsafe-inline' https: http:;report-uri https://csp.withgoogle.com/csp/gws/other-hp 1 object-src 'none';base-uri 'self';script-src 'nonce-X3hU68vAVdcKia4pfzfEvw' 'strict-dynamic' 'report-sample' 'unsafe-eval' 'unsafe-inline' https: http:;report-uri https://csp.withgoogle.com/csp/gws/other-hp 1 base-uri 'self';script-src-elem 'self' https://snap.licdn.com/ https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://js.hs-analytics.net/analytics/ https://www.googletagmanager.com/gtag/ https://js.hs-banner.com/ https://js.hsadspixel.net/ https://x.clearbitjs.com/ https://reveal.clearbit.com/ https://tag.clearbitscripts.com/ https://cdn.koala.live/ https://app.leandata.com/ https://www.datadoghq-browser-agent.com/ https://cdn.jsdelivr.net/ https://browser.sentry-cdn.com/ https://client.crisp.chat/ 'nonce-7dee35629bd2db1f';report-uri /api/report_csp_violation;object-src 'self';form-action 'self'; 1 object-src 'none';base-uri 'self';script-src 'nonce-RJFVqFGkXigNaNYJyyb7xg' 'strict-dynamic' 'report-sample' 'unsafe-eval' 'unsafe-inline' https: http:;report-uri https://csp.withgoogle.com/csp/gws/other-hp 1 object-src 'none';base-uri 'self';script-src 'nonce-TRqGvIt8-x1wxbdGG4hwwg' 'strict-dynamic' 'report-sample' 'unsafe-eval' 'unsafe-inline' https: http:;report-uri https://csp.withgoogle.com/csp/gws/other-hp 1 default-src 'unsafe-eval' 'unsafe-inline' 'self' http: https: data: wss: blob: chrome-extension ; report-uri /cgi-bin/csp-reports.cgi 1 default-src 'self' 'unsafe-inline' 'unsafe-eval' https: data: *.icrc.org; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.icrc.org www.gstatic.com www.googletagmanager.com www.google-analytics.com www.googleadservices.com googleads.g.doubleclick.net *.youtube.com *.vimeo.com *.vimeocdn.com js.hs-analytics.net *.hs-scripts.com *.hs-banner.com js.hsleadflows.net *.facebook.net *.bing.com *.getblue.io *.adnxs.com js.usemessages.com js.hsadspixel.net *.googlesyndication.com *.ads-twitter.com *.cloudflare.com *.licdn.com hcaptcha.com https://hcaptcha.com api.mapbox.com unpkg.com *.hubspot.com *.usercentrics.eu *.cmp.usercentrics.eu https://*.usercentrics.eu *.hotjar.com *.facebook.com; object-src 'self' 'unsafe-inline' 'unsafe-eval' *.icrc.org *.usercentrics.eu https://*.usercentrics.eu https://hcaptcha.com; style-src 'self' 'unsafe-inline' fonts.googleapis.com api.mapbox.com web.cmp.usercentrics.eu app.usercentrics.eu *.usercentrics.eu https://hcaptcha.com; img-src 'self' data: icrc.org *.icrc.org *.usercentrics.eu hcaptcha.com *.bing.com *.facebook.com *.google.com *.google.ch analytics.twitter.com *.linkedin.com *.doubleclick.net *.hubspot.com ; media-src icrc.org *.icrc.org *.usercentrics.eu hcaptcha.com; frame-src 'self' icrc.org *.icrc.org *.youtube.com *.vimeo.com *.youku.com *.getblue.io www.googletagmanager.com *.googletagmanager.com *.hcaptcha.com td.doubleclick.net *.usercentrics.eu hcaptcha.com; frame-ancestors 'self' icrc.org *.icrc.org *.usercentrics.eu hcaptcha.com *.googletagmanager.com; child-src 'self' blob: icrc.org *.icrc.org *.usercentrics.eu hcaptcha.com; font-src 'self' fonts.gstatic.com fonts.gstatic.com *.usercentrics.euhcaptcha.com; connect-src 'self' icrc.org *.icrc.org *.linkedin.com *.hubspot.com *.bing.com api.hubapi.com *.google-analytics.com *.googlesyndication.com *.google.com *.google.ch google-analytics.com bat.bing.net *.adnxs.com *.hcaptcha.com hcaptcha.com *.mapbox.com *.arcgis.com *.visualstudio.com *.usercentrics.eu; upgrade-insecure-requests 1 default-src 'self' *.iheartmedia.com data: blob: https:; img-src 'self' data: https:; font-src https: data:; style-src 'self' 'unsafe-inline' https:; script-src 'self' 'unsafe-inline' 'unsafe-eval' https:; frame-src 'self' data: https:; child-src https:; media-src https:; object-src 'none'; connect-src 'self' wss: https:; report-uri https://csp.qw.iheartmedia.com/api/report 1 default-src bam.nr-data.net cdn.growthbook.io cdn-ukwest.onetrust.com geolocation.onetrust.com pagead2.googlesyndication.com privacyportal-uk.onetrust.com prod.global-fragments-server.green.which.co.uk tpc.googlesyndication.com *.safeframe.googlesyndication.com www.googletagmanager.com ep2.adtrafficquality.google which-group.my.site.com 'unsafe-inline' 'self' https://*.which.co.uk;script-src a.quora.com ajax.googleapis.com bat.bing.com c.amazon-adsystem.com cdn-magiclinks.trackonomics.net cdn-ukwest.onetrust.com cdn.amplitude.com cdn.jsdelivr.net connect.facebook.net ct.pinterest.com cdn.growthbook.io googleads.g.doubleclick.net manifest.prod.boltdns.net maps.googleapis.com pagead2.googlesyndication.com platform.twitter.com player.captivate.fm players.brightcove.net prod.global-fragments-server.green.which.co.uk public.flourish.studio pym.nprapps.org region1.google-analytics.com s.pinimg.com siteintercept.qualtrics.com static-ssl.responsetap.com static.ads-twitter.com static.digidip.net t.contentsquare.net tpc.googlesyndication.com track.omguk.com which.resultspage.com www.google-analytics.com www.googleadservices.com www.googletagmanager.com www.redditstatic.com yksbw1yr.micpn.com zeta-live.getsquirrel.co znbiyguoobqgm5gwu-which.siteintercept.qualtrics.com which-group.my.site.com 'unsafe-inline' 'self' https://*.which.co.uk 'nonce-8530007ba96ced79b54d58c5d8eca21a61a1122198b321be007ff050f521528f';style-src aaf1a18515da0e792f78-c27fdabe952dfc357fe25ebf5c8897ee.ssl.cf5.rackcdn.com cdn.jsdelivr.net flo.uri.sh fonts.googleapis.com pagead2.googlesyndication.com player.captivate.fm public.flourish.studio service.force.com zeta-live.getsquirrel.co which.resultspage.com which-group.my.site.com 'unsafe-inline' 'self' https://*.which.co.uk;font-src fonts-which-co-uk.s3.amazonaws.com player.captivate.fm public.flourish.studio 'unsafe-inline' 'self' https://*.which.co.uk;img-src abs-0.twimg.com ad.doubleclick.net ade.googlesyndication.com adservice.google.com alb.reddit.com analytics.twitter.com artwork.captivate.fm bat.bing.com c.contentsquare.net cdn-ukwest.onetrust.com cf-images.eu-west-1.prod.boltdns.net ct.pinterest.com googleads.g.doubleclick.net house-fastly-signed-eu-west-1-prod.brightcovecdn.com maps.gstatic.com media.which.gpp.io metrics.brightcove.com pagead2.googlesyndication.com pbs.twimg.com q.quora.com s3-eu-west-1.amazonaws.com securepubads.g.doubleclick.net siteintercept.qualtrics.com storage.googleapis.com syndication.twitter.com t.co tpc.googlesyndication.com tracking.audio.thisisdax.com trx-hub.com www.facebook.com www.google-analytics.com www.google.co.uk www.google.com yksbw1yr.micpn.com ep1.adtrafficquality.google 'unsafe-inline' 'self' https://*.which.co.uk;connect-src region1.google-analytics.com which-group.my.salesforce-scrt.com cdn.growthbook.io cdn-ukwest.onetrust.com geolocation.onetrust.com pagead2.googlesyndication.com ep1.adtrafficquality.google ep2.adtrafficquality.google 'unsafe-inline' 'self' https://*.which.co.uk;base-uri 'self';form-action 'self';frame-ancestors 'self';object-src 'none';script-src-attr 'none' 1 script-src 'self' 'unsafe-inline' 'unsafe-eval' data: agadata.online apis.google.com apps.rokt.com bat.bing.com cdn.cookielaw.org cdn.jsdelivr.net cdnjs.cloudflare.com code.jquery.com colegiodiocesanosantaclara.imtlazarus.com:6443 connect.facebook.net data1.blamap.com get663.com google-analytics.com googleads.g.doubleclick.net googletagmanager.com instagram.com js.ipredictive.com lf16-tiktok-web.tiktokcdn-us.com mountain.com nrdcapps.org pagespeed-mod.com pixel.byspotify.com platform.instagram.com platform.twitter.com public.tableau.com qvdt3feo.com s.yimg.com sc-static.net scrible.com scripts.clarity.ms snapchat.com tags.srv.stackadapt.com tiktok.com tp88trk.com translate-pa.googleapis.com translate.google.com translate.googleapis.com try.abtasty.com unpkg.com vimeo.com youtube.com https://static.cloudflareinsights.com/* https://www.googletagmanager.com/* https://cdnjs.cloudflare.com; script-src-elem 'self' 'unsafe-inline' data: agadata.online apis.google.com apps.rokt.com bat.bing.com cdn.cookielaw.org cdn.jsdelivr.net cdnjs.cloudflare.com code.jquery.com colegiodiocesanosantaclara.imtlazarus.com:6443 connect.facebook.net data1.blamap.com get663.com google-analytics.com googleads.g.doubleclick.net googletagmanager.com instagram.com js.ipredictive.com lf16-tiktok-web.tiktokcdn-us.com mountain.com nrdcapps.org pagespeed-mod.com pixel.byspotify.com platform.instagram.com platform.twitter.com public.tableau.com qvdt3feo.com s.yimg.com sc-static.net scrible.com scripts.clarity.ms snapchat.com tags.srv.stackadapt.com tiktok.com tp88trk.com translate-pa.googleapis.com translate.google.com translate.googleapis.com try.abtasty.com unpkg.com vimeo.com youtube.com https://www.googletagmanager.com https://static.cloudflareinsights.com https://analytics.tiktok.com https://snap.licdn.com https://www.tp88trk.com https://px.mountain.com https://dx.mountain.com https://tr.snapchat.com https://gs.mountain.com https://googleads.g.doubleclick.net https://connect.facebook.net https://bat.bing.com https://www.nrdcapps.org https://platform.instagram.com https://js.ipredictive.com https://sc-static.net https://tags.srv.stackadapt.com https://try.abtasty.com https://apps.rokt.com https://www.instagram.com https://s.yimg.com https://cdn.cookielaw.org https://cdn.clinch.co blob: https://unpkg.com https://www.youtube.com https://infird.com https://www.tiktok.com https://ff.kis.v2.scr.kaspersky-labs.com *.mountain.com https://static.cloudflareinsights.com/ https://googleads.g.doubleclick.net/* https://cdnjs.cloudflare.com; style-src 'self' 'unsafe-inline' cdn.honey.io tags.srv.stackadapt.com www.gstatic.com cdn.jsdelivr.net fonts.googleapis.com https://cdnjs.cloudflare.com; style-src-attr 'self' 'unsafe-inline'; style-src-elem 'self' 'unsafe-inline' blob: cdn.honey.io lf16-tiktok-web.tiktokcdn-us.com nrdcapps.org sf16-website-login.neutral.ttwstatic.com tags.srv.stackadapt.com www.googletagmanager.com www.gstatic.com www.nrdcapps.org www.scrible.com https://tags.srv.stackadapt.com/sa.css https://adblockers.opera-mini.net cdn.jsdelivr.net fonts.googleapis.com https://cdnjs.cloudflare.com; worker-src 'self' blob:; frame-ancestors 'self' 1 font-src *.dedeman.ro data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com maps.google.com *.recaptcha.net *.dedeman.ro applepay.cdn-apple.com *.gigya.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.dedeman.ro maps.gstatic.com *.google-analytics.com *.googletagmanager.com server.arcgisonline.com a.tile.openstreetmap.org b.tile.openstreetmap.org c.tile.openstreetmap.org applepay.cdn-apple.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com *.gigya.com 'self' data: 'unsafe-inline' data: data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://rum.hlx.page *.nr-ext.net *.nr-assets.net *.dedeman.ro *.googleapis.com *.google-analytics.com *.google.com *.recaptcha.net *.facebook.com applepay.cdn-apple.com *.plugins.emarsys.net *.scarabresearch.com chimpstatic.com downloads.mailchimp.com *.list-manage.com *.gigya.com https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.dedeman.ro downloads.mailchimp.com 'unsafe-inline' data: 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src *.dedeman.ro 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com *.dedeman.ro maps.googleapis.com *.google-analytics.com cdns.eu1.gigya.com apple-pay-gateway.apple.com apple-pay-gateway-cert.apple.com apple.com *.scarabresearch.com *.eservice.emarsys.net 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.dedeman.ro maps.googleapis.com *.google-analytics.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src blob: https://*.mhcache.com;font-src 'self' https://*.myheritage.com https://*.mhcache.com https://fonts.gstatic.com;frame-src 'self' https://*.mhcache.com https://portal.allyable.com https://mh-site-files-5c53d6a9947c.s3.amazonaws.com https://myheritage-container.com https://www.myheritage-partners.com https://www.myheritage.com https://*.mk-sense.com https://player.vimeo.com https://*.facebook.com https://*.googleapis.com https://*.google.com https://tpc.googlesyndication.com https://*.doubleclick.net https://accounts.google.com/gsi/;script-src https://accounts.google.com/gsi/client https://www.datadoghq-browser-agent.com https://*.googleapis.com https://appleid.cdn-apple.com 'unsafe-eval' 'nonce-8e202c1a70b5bd8cbd200e9930042743' 'strict-dynamic';style-src data: blob: 'unsafe-inline' 'self' https://*.myheritage.com https://*.mhcache.com https://fonts.googleapis.com https://accounts.google.com/gsi/style;connect-src data: 'self' https://*.myheritage.com https://portal.allyable.com https://*.mhcache.com https://adservice.google.com https://*.logs.datadoghq.com https://*.browser-intake-datadoghq.com https://browser-intake-datadoghq.com https://sentry.io https://*.bing.com https://*.facebook.com https://*.doubleclick.net https://*.mk-sense.com https://*.filae.com https://accounts.google.com/gsi/ https://www.google.com/pagead/landing https://*.googleapis.com https://maps.googleapis.com/maps/api/mapsjs/gen_204 https://translate.googleapis.com https://www.google.com/ccm/collect https://cdn.builder.io;media-src 'self' https://*.myheritage.com https://*.mhcache.com;frame-ancestors 'self' https://builder.io;img-src * data:;object-src 'none';base-uri 'self' https://*.mhcache.com;report-uri /FP/API/ContentSecurityPolicy/report-violation.php?report_mode=report&canonical_page_id=/company/home/ 1 script-src 'self' 'unsafe-inline' 'unsafe-eval' 50339659.hs-sites.com 1003891.track.convertexperiments.com app.hubspot.com cdn-3.convertexperiments.com cdn-4.convertexperiments.com *.metrics.convertexperiments.com *.signals.convertexperiments.com logs.convertexperiments.com *.convertexperiments.com cdn.pdst.fm connect.facebook.net js.hs-analytics.net js.hs-banner.com js.hsforms.net js.hsleadflows.net js.hubspotfeedback.com js.usemessages.com play.vidyard.com script.hotjar.com snap.licdn.com static.hotjar.com static.hsappstatic.net www.google-analytics.com www.googletagmanager.com www.recaptcha.net code.highcharts.com www.youtube.com js.hubspot.com www.dropbox.com widget.altrulabs.com www.google.com maps.googleapis.com wt-assets.hubteam.com cdn2.hubspot.net www.redditstatic.com cdn.veritonic.com gosniply.com d.impactradius-event.com test.test.com js.hubspot.com analytics.tiktok.com 'strict-dynamic' 'nonce-9ij5WvSZnsLjxvmLwOo/Xg=='; report-uri https://send.hsbrowserreports.com/csp/report 1 frame-ancestors 'self'; object-src 'self' 'unsafe-inline'; media-src *.salesforce-sites.com *.lightning.force.com *.storyblok.com *.zdassets.com *.doofinder.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; form-action https://www.facebook.com https://druni.my.salesforce-sites.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com https://store.plumrocket.com www.paycomet.com api.paycomet.com 'self' 'unsafe-inline'; frame-src http://fast.amc.demdex.net https://www.youtube.com https://www.facebook.com https://app3.salesmanago.pl https://10138016.fls.doubleclick.net https://insight.adsrvr.org https://td.doubleclick.net https://druni.my.salesforce-sites.com https://www.googletagmanager.com https://pay.google.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ https://js.checkout.com *.klarna.com https://store.plumrocket.com www.paycomet.com api.paycomet.com instantcredit.net test.instantcredit.net https://sandbox.sequracdn.com https://live.sequracdn.com *.salesforce-sites.com *.lightning.force.com *.hotjar.com *.oct8ne.com *.pinterest.com *.doofinder.com *.empathybroker.com *.empathy.co *.criteo.com 'self' 'unsafe-inline'; connect-src https://dpm.demdex.net http://dpm.demdex.net https://www.paypal.com https://eu1-search.doofinder.com https://shops-si.trustedshops.com https://api.trustedshops.com https://trustbadge.api.etrusted.com https://storytech.io https://analytics.tiktok.com https://region1.analytics.google.com https://vc-service.saleago.com https://api.swogo.net https://content.syndigo.com https://tracking.swogo.net https://www.google.com https://bat.bing.com https://druni.my.salesforce-sites.com https://pay.google.com https://cdn.equalweb.com https://analytics-ipv6.tiktokw.us https://www.googletagmanager.com https://vc-service.salesmanago.pl https://app3.salesmanago.es https://www.facebook.com https://war.salesmanago.com https://capig.stape.org www.google-analytics.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://js.checkout.com *.klarnaevt.com *.doofinder.com wss://*.doofinder.com instantcredit.net *.instantcredit.net https://sandbox.sequracdn.com https://live.sequracdn.com https://maps.googleapis.com https://player.vimeo.com *.salesforce-sites.com *.lightning.force.com *.oct8ne.com *.zendesk.com *.zopim.com *.doubleclick.net *.hotjar.com *.hotjar.io *.clarity.ms *.smartsuppcdn.com *.googleapis.com *.gstatic.com *.google-analytics.com *.google.es *.connectif.cloud *.klaviyo.com *.photoslurp.com *.zdassets.com *.pinterest.com *.nosto.com *.empathybroker.com *.empathy.co 'self' 'unsafe-inline'; img-src data: http://cm.everesttech.net http://amcglobal.sc.omtrdc.net https://asistentecosmeticatest1.herokuapp.com https://ad.doubleclick.net https://p1.zemanta.com https://www.storytech.io https://cdnstory.com https://insight.adsrvr.org https://www.druni.es https://event.syndigo.cloud https://ui.swogo.net https://googleads.g.doubleclick.net https://tau.collect.igodigital.com https://www.googletagmanager.com https://analytics.tiktok.com https://app3.salesmanago.es https://c.clarity.ms https://connect.facebook.net widgets.magentocommerce.com www.googleadservices.com www.google-analytics.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com cdn.doofinder.com instantcredit.net test.instantcredit.net https://sandbox.sequracdn.com https://live.sequracdn.com https://images.unsplash.com *.salesforce-sites.com *.lightning.force.com *.facebook.com *.google.com *.google.es widgets.trustedshops.com *.twitter.com t.co *.azureedge.net *.pinterest.com *.doofinder.com *.bing.com 'self' data: data: 'self' 'unsafe-inline'; font-src http://widgets.trustedshops.com http://maxcdn.bootstrapcdn.com https://fonts.gstatic.com https://asistentecosmeticatest1.herokuapp.com https://cdn.checkout.com instantcredit.net test.instantcredit.net maxcdn.bootstrapcdn.com *.salesforce-sites.com *.lightning.force.com fonts.gstatic.com *.azureedge.net *.doofinder.com *.typekit.net *.googleapis.com *.gstatic.com 'self' data: data: 'self' 'unsafe-inline'; style-src http://fonts.googleapis.com http://maxcdn.bootstrapcdn.com https://asistentecosmeticatest1.herokuapp.com https://storytech.io https://druni.my.salesforce-sites.com https://access.equalweb.com https://cdn.checkout.com *.doofinder.com instantcredit.net test.instantcredit.net maxcdn.bootstrapcdn.com *.salesforce-sites.com *.lightning.force.com *.photoslurp.com *.nosto.com *.klaviyo.com *.typekit.net *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; script-src http://widgets.trustedshops.com http://www.gstatic.com http://www.google.com https://www.googletagmanager.com https://www.dwin1.com https://eu1-search.doofinder.com https://cdn.doofinder.com https://asistentecosmeticatest1.herokuapp.com https://cdnjs.cloudflare.com/ https://ui.swogo.net https://analytics.tiktok.com https://storytech.io https://bucket.cdnwebcloud.com https://js.adsrvr.org https://js-tag.zemanta.com https://content.syndigo.com https://ct.pinterest.com https://fonts.googleapis.com https://druni.my.salesforce-sites.com https://536005834.collect.igodigital.com https://cdn.equalweb.com https://access.equalweb.com https://app3.salesmanago.es www.googleadservices.com www.google-analytics.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://*.checkout.com *.klarnacdn.net cdn.doofinder.com www.paycomet.com api.paycomet.com instantcredit.net test.instantcredit.net code.jquery.com https://sandbox.sequracdn.com https://live.sequracdn.com https://maps.googleapis.com *.salesforce-sites.com *.lightning.force.com www.googletagmanager.com *.googleoptimize.com widgets.trustedshops.com static-eu.oct8ne.com static.zdassets.com *.facebook.net *.tradedoubler.com *.doubleclick.net *.hotjar.com *.ads-twitter.com smct.co *.bsmartdata.com *.retargeted.co *.bing.com *.clarity.ms *.smartsuppcdn.com *.smartsuppchat.com *.smartsupp.com *.connectif.cloud *.klaviyo.com *.photoslurp.com *.pinimg.com *.nosto.com *.doofinder.com *.empathybroker.com *.unpkg.com *.google.com *.gstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; 1 connect-src 'self' *.cdn.content.amplience.net *.staging.bigcontent.io *.algolia.net direct-collect.dy-api.eu rcom-eu.dynamicyield.com st-eu.dynamicyield.com async-px-eu.dynamicyield.com direct.dy-api.eu *.algolianet.com *.worldline-solutions.com *.ingenico.com *.ideal-postcodes.co.uk *.criteo.com www.bing.com dev.virtualearth.net t.ssl.ak.dynamic.tiles.virtualearth.net insights.algolia.io *.scoota.co *.criteo.net adobedc.demdex.net edge.adobedc.net ns.adobe.com *.onetrust.com *.accdab.net apps.bazaarvoice.com display.ugc.bazaarvoice.com static.cloudflareinsights.com staging-uk.cdn-net.com uk.cdn-net.com six.cdn-net.com https://api-eu.jdadelivers.com collection.decibelinsight.net cdn.decibelinsight.net *.decibel.com wss://collection.decibelinsight.net wss://cdn.decibelinsight.net *.digital-cloud.medallia.eu bam.nr-data.net ingressteam.cloudflareaccess.com *.google-analytics.com analytics.tiktok.com sghs.asda.com www.mczbf.com *.dotomi.com connect.facebook.net www.facebook.com bat.bing.com www.sc-static.net tr.snapchat.com www.redditstatic.com pixel-config.reddit.com analytics.twitter.com ads-api.twitter.com www.ads-twitter.com *.doubleclick.net *.googlesyndication.com www.googleadservices.com www.googletagmanager.com googletagmanager.com *.googletagmanager.com *.analytics.google.com www.google.com google.com api2.asda.com ghs-mm.asda.com https://cdn-eu.dynamicyield.com/scripts/2.74.0/dy-coll-nojq-min.js https://cdn-eu.dynamicyield.com/scripts/2.72.0/dy-coll-nojq-min.js https://cdn-eu.dynamicyield.com/scripts/2.68.0/dy-coll-nojq-min.js https://cdn-eu.dynamicyield.com/scripts/2.66.0/dy-coll-nojq-min.js cdn-eu.dynamicyield.com api.bazaarvoice.com bat.bing.net; default-src 'self'; font-src 'self' fonts.gstatic.com; frame-src 'self' *; frame-ancestors 'self' *.amplience.net; img-src 'self' *.commercecloud.salesforce.com *.media.amplience.net data: asda.a.bigcontent.io asdagroceries.scene7.com *.assets-asda.com *.dynamicyield.com *.criteo.com retailmedia-static.azureedge.net staticassets-creator-design.criteo.net t.ssl.ak.dynamic.tiles.virtualearth.net www.bing.com *.scoota.co adobedc.demdex.net edge.adobedc.net ns.adobe.com *.onetrust.com analytics.tiktok.com region1.analytics.google.com www.google.co.uk fonts.gstatic.com sghs.asda.com www.mczbf.com *.dotomi.com connect.facebook.net www.facebook.com bat.bing.com www.sc-static.net tr.snapchat.com www.redditstatic.com pixel-config.reddit.com analytics.twitter.com ads-api.twitter.com www.ads-twitter.com *.doubleclick.net *.googlesyndication.com www.googleadservices.com adservice.google.com www.googletagmanager.com googletagmanager.com *.googletagmanager.com ssl.gstatic.com www.gstatic.com *.google-analytics.com www.google.com google.com d3dh5c7rwzliwm.cloudfront.net d32106rlhdcogo.cloudfront.net dgf0rw7orw6vf.cloudfront.net gum.criteo.com x.bidswitch.net r.casalemedia.com cm.g.doubleclick.net secure.adnxs.com simage2.pubmatic.com pixel.rubiconproject.com sync-criteo.ads.yieldmo.com hb.yahoo.net sync-t1.taboola.com haq81g6w.micpn.com *.bazaarvoice.com d1fd8aj8bhyfe9.cloudfront.net; media-src 'self' asdagroceries.scene7.com s7d2.scene7.com *.scoota.co static.criteo.net; script-src 'self' 'unsafe-inline' 'unsafe-eval' apps.rokt.com storage.googleapis.com *.algolia.net cdn-eu.dynamicyield.com st-eu.dynamicyield.com *.worldline-solutions.com *.ingenico.com assets.adobedtm.com www.bing.com r.bing.com dev.virtualearth.net *.scoota.co asdagroceries.scene7.com ui.assets-asda.com d3dh5c7rwzliwm.cloudfront.net d32106rlhdcogo.cloudfront.net dgf0rw7orw6vf.cloudfront.net adobedc.demdex.net edge.adobedc.net ns.adobe.com *.onetrust.com *.accdab.net *.criteo.com *.hlserve.com apps.bazaarvoice.com display.ugc.bazaarvoice.com stg.api.bazaarvoice.com static.cloudflareinsights.com mpsnare.iesnare.com collection.decibelinsight.net cdn.decibelinsight.net *.decibel.com blob: *.digital-cloud.medallia.eu staging-uk.cdn-net.com uk.cdn-net.com six.cdn-net.com js-agent.newrelic.com ingressteam.cloudflareaccess.com www.googletagmanager.com *.google-analytics.com analytics.tiktok.com sghs.asda.com www.mczbf.com *.dotomi.com connect.facebook.net www.facebook.com bat.bing.com www.sc-static.net tr.snapchat.com www.redditstatic.com pixel-config.reddit.com analytics.twitter.com ads-api.twitter.com www.ads-twitter.com *.doubleclick.net *.googlesyndication.com www.googleadservices.com tagmanager.google.com googletagmanager.com *.googletagmanager.com www.google.com google.com haq81g6w.micpn.com migroceries.asda.com asda-promotions.co.uk api.bazaarvoice.com *.criteo.net *.d3dh5c7rwzliwm.cloudfront.net *.mpsnare.iesnare.com https://analytics-static.ugc.bazaarvoice.com/prod/static/3/bv-analytics.js; style-src 'self' https: 'unsafe-inline' *.bazaarvoice.com ssl.gstatic.com www.gstatic.com tagmanager.google.com fonts.googleapis.com; report-uri https://csp-reporting.cloudflare.com/cdn-cgi/script_monitor/report?m=CwUfyX9UbI4sK9jvnD_kmllbuLkO63gLbkmbuW9c0Rg-1770431307-1.0.1.1-wSVx41o4Wz6gXLzbPTgnYbm0in0Kud8LpnuYvbxqdK48tIuLayNCeYDLYrwmlM.4Y0ZeXiUw_9F8s2W3gOpNP.Alx_uinN9GaEOeNovqlHkO6WBZ6h6VDkXz_g4kISup9zQ2.Hp0ql6TdjtmmB.OjX5bB2UsJe1Dr.ZoHQ48zF6I3Xvq1.LEa4Y74y7n3MZCdluzA.V56USf3.uvE_Ba3Q; report-to cf-vtkyfhhduhplyteg 1 child-src 'self' https://*.qualified.com; default-src 'self'; frame-src 'self' https://9628652.fls.doubleclick.net https://td.doubleclick.net https://js.driftt.com https://*.qualified.com https://a8447815042.cdn-pci.optimizely.com https://ct.pinterest.com https://tealium-f.squarecdn.com; worker-src 'self' blob:; connect-src 'self' https://assets.ctfassets.net https://api.broadway.squareup.com https://campaign-hub-production-f.squarecdn.com https://api.squareup.com/v1/cdp/batch https://api.squarestagingexternal.com/v1/cdp/batch https://api.squarestagingexternal.com https://api.squareup.com https://api.squareupstaging.com *.contentsquare.net https://capi.squareup.com https://browser-intake-datadoghq.com https://*.browser-intake-datadoghq.com https://stats.g.doubleclick.net https://facebook.com https://www.facebook.com https://googleads.g.doubleclick.net http://www.google-analytics.com https://www.google-analytics.com https://google.com https://www.google.com https://us-central1-sq-sgtm-prod.cloudfunctions.net https://www.googletagmanager.com http://images.ctfassets.net https://images.ctfassets.net http://424-iab-218.mktoresp.com https://424-iab-218.mktoresp.com https://xms2-marketo.beta.stage.sqprod.co https://424-iab-218.mktoutil.com https://cdn.cookielaw.org https://geolocation.onetrust.com https://privacyportal.onetrust.com https://logx.optimizely.com https://ct.pinterest.com https://conversions-config.reddit.com https://pixel-config.reddit.com https://www.redditstatic.com *.ingest.us.sentry.io *.6sc.co https://api.sprig.com https://squareupstaging.com https://visitor-scoring-new.marketlinc.com https://api.chilipiper.com https://squareinc-sandbox.chilipiper.com https://squareinc.chilipiper.com https://www.workwithsquare.com wss://*.qualified.com https://*.qualified.com https://pw-renderer-production-c.squarecdn.com localhost:*; font-src 'self' https://cash-f.squarecdn.com https://square-fonts-production-f.squarecdn.com; img-src 'self' data: blob: https://ib.adnxs.com https://assets.ctfassets.net https://cdn.blisspointmedia.com https://campaign-hub-production-f.squarecdn.com *.contentsquare.net https://ad.doubleclick.net https://facebook.com https://www.facebook.com https://google.com https://www.google.com https://adservice.google.com https://googleads.g.doubleclick.net http://www.google-analytics.com https://www.google-analytics.com https://*.g.doubleclick.net https://www.googletagmanager.com http://images.ctfassets.net https://images.ctfassets.net https://px.ads.linkedin.com https://cdn.cookielaw.org https://pixel.pointmediatracker.com https://alb.reddit.com *.6sc.co https://api.squareup.com https://api.squareupstaging.com https://insight.adsrvr.org https://match.adsrvr.org https://*.qualified.com https://pw-renderer-production-c.squarecdn.com; manifest-src 'self' https://pw-renderer-production-c.squarecdn.com; media-src 'self' mediastream: https://assets.ctfassets.net https://js.driftt.com http://videos.ctfassets.net https://videos.ctfassets.net https://*.qualified.com; script-src 'self' *.contentsquare.net https://www.datadoghq-browser-agent.com https://js.driftt.com https://*.qualified.com https://connect.facebook.net https://www.googleadservices.com https://googleads.g.doubleclick.net http://www.google-analytics.com https://www.google-analytics.com https://www.googletagmanager.com https://campaign-hub-production-f.squarecdn.com https://lift-ai-js.marketlinc.com https://martech-development-c.squarecdn.com https://martech-production-c.squarecdn.com https://martech-staging-c.squarecdn.com http://munchkin.marketo.net https://munchkin.marketo.net https://cdn.cookielaw.org https://a8447815042.cdn-pci.optimizely.com https://s.pinimg.com https://ct.pinterest.com https://pw-renderer-production-c.squarecdn.com https://pw-renderer-staging-c.squarecdn.com https://pwt-production-c.squarecdn.com https://pwt-staging-c.squarecdn.com https://sales-bridge-production-c.squarecdn.com https://sales-bridge-staging-c.squarecdn.com https://squareinc-sandbox.chilipiper.com https://squareinc.chilipiper.com https://www.workwithsquare.com https://www.redditstatic.com *.6sc.co https://cdn.sprig.com https://xms-production-f.squarecdn.com https://www.youtube.com https://pw-renderer-production-c.squarecdn.com 'nonce-QvhYyhi+uNyke6d6oDrLXg=='; style-src 'self' https://square-fonts-production-f.squarecdn.com https://sales-bridge-production-c.squarecdn.com https://sales-bridge-staging-c.squarecdn.com 'unsafe-inline' https://*.qualified.com https://pw-renderer-production-c.squarecdn.com; frame-ancestors 'self' https://app.contentful.com; report-uri https://browser-intake-datadoghq.com/api/v2/logs?dd-api-key=pubd9af00759e65a48ba7ee3ff1dfa4260b&dd-evp-origin=content-security-policy&ddsource=csp-report; report-to browser-intake-datadoghq 1 object-src 'none'; script-src 'self' 'unsafe-inline' 'unsafe-eval' adform.net *.adform.net betano.com *.betano.com betano.pe *.betano.pe betgenius.com *.betgenius.com cookielaw.org *.cookielaw.org facebook.net *.facebook.net fullstory.com *.fullstory.com gmlinteractive.com *.gmlinteractive.com googletagmanager.com *.googletagmanager.com kameleoon.eu *.kameleoon.eu optimove.net *.optimove.net sportradar.com *.sportradar.com sportradarserving.com *.sportradarserving.com cloudflareinsights.com *.cloudflareinsights.com app.delivery *.app.delivery cloudflare.com *.cloudflare.com lgrckt-in.com *.lgrckt-in.com tostarsbuilding.com *.tostarsbuilding.com; report-uri https://csp-reporting.cloudflare.com/cdn-cgi/script_monitor/report?m=talQ3k4kuB2oWfGPH2qmXX8sNZcgFRns2J344xjOI_4-1770431465-1.0.1.1-0q5ieR9cX8y0N3N.3lreAiWKxZhXtNhBOkZZxG6pCuMWqKciquIYQwsa72BJml_iciqQi4FSAbNiVEoHKLyquxfL1RwNLlXRUmdRvMd0onP61SMtEQ2KuZaTF3KGSg0iSdZ7V5ge7bihLyaEBDhu2sAnAKedsmaIu3H0HatcQkXU_mYy7rC17XkvdApVIqLkA3sCQtZHds4Lb0avW.7Jcw; report-to cf-okbquagnmddvtsdp 1 object-src 'none'; script-src 'self' 'unsafe-inline' 'unsafe-eval' adform.net *.adform.net betano.com *.betano.com betgenius.com *.betgenius.com cloudflare.com *.cloudflare.com cookielaw.org *.cookielaw.org facebook.net *.facebook.net fullstory.com *.fullstory.com gmlinteractive.com *.gmlinteractive.com creativecdn.com *.creativecdn.com googletagmanager.com *.googletagmanager.com kaizengaming.com *.kaizengaming.com kameleoon.eu *.kameleoon.eu optimove.net *.optimove.net sportradar.com *.sportradar.com bing.com *.bing.com stoiximan.gr *.stoiximan.gr cloudflareinsights.com *.cloudflareinsights.com betano.bet.ar *.betano.bet.ar geocomply.com *.geocomply.com kameleoon.io *.kameleoon.io ads-twitter.com *.ads-twitter.com app.delivery *.app.delivery google-analytics.com *.google-analytics.com lgrckt-in.com *.lgrckt-in.com tostarsbuilding.com *.tostarsbuilding.com; report-uri https://csp-reporting.cloudflare.com/cdn-cgi/script_monitor/report?m=hW3SfWaJVkYEdUwOl.HgvR9dqHNkcVM5Wb1Kw7uKPV0-1770431569-1.0.1.1-NayG9EstCZghPmxTu9pFi5SWKg2wTFcsUwtSYbHYj24v_Ee8kW.VZXo.MO.MtL8h15QmrdxKyMSw3tU6Yr0Z1.5SrTYYl.9D75F0jlztu2tixKLNDF3C.xdeRDQTP7NwoY2XLNAWydOAIlpb28IApb2JuuLQMSvk2TarEPk15llmBvLN4hv9x_DBZ275xqZDzw0F0NsdXQZr85VIxHzFMA; report-to cf-ghrjsyheyiuqfkou 1 font-src fonts.gstatic.com use.typekit.net self data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.adyen.com pay.google.com payments-eu.amazon.com *.amazon.de https://store.plumrocket.com pal-test.adyen.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.adyen.com pay.google.com *.paypal.com self *.doubleclick.net *.criteo.com *.easydmp.net *.snapchat.com https://store.plumrocket.com https://accounts.google.com checkoutshopper-test.adyen.com pal-test.adyen.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io *.adyen.com pay.google.com *.payments-amazon.com *.media-amazon.com *.paypalobjects.com self *.bing.com *.paypal.com *.google.fr *.electrodepot.fr *.electrodepot.be *.electrodepot.es *.cookielaw.org *.snapchat.com checkoutshopper-test.adyen.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com self sc-static.net *.abtasty.com *.jsdelivr.net *.gstatic.com *.facebook.net *.tiktok.com *.googleapis.com *.easydmp.net *.vzbl.eu *.aticdn.net *.m1by1.com *.woosmap.com *.doubleclick.net *.cookielaw.org *.snapchat.com *.valiuz.com *.mediarithmics.com *.prediggo.services https://accounts.google.com checkoutshopper-test.adyen.com 'self' 'unsafe-eval' 'nonce-aHF1bzRrbHY4MnRtd2twdTJkbmVhMXRib3VnMjhlNDM=' 'sha256-W5akSSK6LD5BjIlNICMcXaUObQSRAaj6bs7JHADURBA=' 'sha256-3qVqeAdyxxTdPkkRzqapjGkAUYLahxSrB7Mdup+GPQ0=' 'sha256-2rvfFrggTCtyF5WOiTri1gDS8Boibj4Njn0e+VCBmDI=' 'sha256-p8MCfMHqrovsjRYU9z0bU17dd0z81k/fVbGrtBBiM9g=' 'sha256-0pk2s4oXwBELlC6IBVb3nNaM2PjfjwI2N6OGIX5lx8Y=' 'sha256-nkEZknO0IxNxY/CkTMBhjNhwPvglpYumjx31B4fjkY8='; style-src *.adobe.com fonts.googleapis.com self *.gstatic.com *.electrodepot.fr *.electrodepot.be *.electrodepot.es *.snapchat.com https://accounts.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.adyen.com *.google.com google.com payments-eu.amazon.com *.paypal.com self *.snapchat.com *.cookielaw.org *.abtasty.com *.googleapis.com *.vzbl.eu *.criteo.com *.easydmp.net *.xiti.com *.valiuz.com *.doubleclick.net *.mediarithmics.com https://accounts.google.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.electrodepot.fr *.electrodepot.be *.electrodepot.es *.bing.com *.criteo.net *.snapchat.com *.netvigie.com *.xiti.com *.valiuz.com *.googletagmanager.com *.google.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 connect-src *.bundesregierung.de analytics.bundesregierung.de https://hls-hd.myrasec.de *.stage.bio ; style-src *.bundesregierung.de 'unsafe-inline' ; script-src *.bundesregierung.de ; script-src-elem *.bundesregierung.de 'nonce-8hSiaKTzANrLBi3iNkjAGlulmMbmDUEdz2tvPkjSRQLGOnfmOC29seU37JvEy0a1wL+rT7nqB8IffIrGFSpzTzZAqHsQ819hk9uO2MqJCn0hWLwncySc4VIPCSWSTc9eHJTnUKJP1s8oAZYsnbKqDgKtHR0VIyrFI5rkK3VOQHk=' *.stage.bio ; frame-src *.bundesregierung.de ; media-src *.bundesregierung.de http://video.bundesregierung.de https://zdf-hls-18.akamaized.net *.stage.bio ; frame-ancestors *.bundesregierung.de ; img-src *.bundesregierung.de *.bundeskanzler.de https://*.tile.openstreetmap.de data: *.stage.bio ; default-src *.bundesregierung.de ; font-src *.bundesregierung.de ; report-uri https://www.bundesregierung.de/service/csp-report ; 1 frame-ancestors https://*.workable.com/; report-uri https://browser-intake-datadoghq.com/api/v2/logs?dd-api-key=pubcbe8d2ef0966e8645a91099cfac490bb&dd-evp-origin=content-security-policy&ddsource=csp-report&ddtags=%40http.headers.cfray%3A9c9f90f9ac0f7a73 1 object-src 'none';base-uri 'self';script-src 'nonce-KF5ew_0r1emT-nvsKc4Z_w' 'strict-dynamic' 'report-sample' 'unsafe-eval' 'unsafe-inline' https: http:;report-uri https://csp.withgoogle.com/csp/gws/other-hp 1 object-src 'none';base-uri 'self';script-src 'nonce-solkLh8eUE71tkedLCtwPw' 'strict-dynamic' 'report-sample' 'unsafe-eval' 'unsafe-inline' https: http:;report-uri https://csp.withgoogle.com/csp/gws/other-hp 1 block-all-mixed-content; report-uri https://www.warau.jp/mixedcontentreport.php 1 object-src 'none';base-uri 'self';script-src 'nonce-h03Q4f8BvBvR0HIit6MMUQ' 'strict-dynamic' 'report-sample' 'unsafe-eval' 'unsafe-inline' https: http:;report-uri https://csp.withgoogle.com/csp/gws/other-hp 1 object-src 'none';base-uri 'self';script-src 'nonce-hRyj9q6iZbBMv3XjY670-g' 'strict-dynamic' 'report-sample' 'unsafe-eval' 'unsafe-inline' https: http:;report-uri https://csp.withgoogle.com/csp/gws/other-hp 1 object-src 'none';base-uri 'self';script-src 'nonce-ILwIrm5bHmjECGxvEH6c_w' 'strict-dynamic' 'report-sample' 'unsafe-eval' 'unsafe-inline' https: http:;report-uri https://csp.withgoogle.com/csp/gws/other-hp 1 object-src 'none';base-uri 'self';script-src 'nonce-vHM24c5IPJDXjHO0TO5KGQ' 'strict-dynamic' 'report-sample' 'unsafe-eval' 'unsafe-inline' https: http:;report-uri https://csp.withgoogle.com/csp/gws/other-hp 1 object-src 'none';base-uri 'self';script-src 'nonce-yVRo83fphMuXPLMI8JvsYA' 'strict-dynamic' 'report-sample' 'unsafe-eval' 'unsafe-inline' https: http:;report-uri https://csp.withgoogle.com/csp/gws/other-hp 1 object-src 'none';base-uri 'self';script-src 'nonce-o4t1Z10vVZNOxzTvsg9IGg' 'strict-dynamic' 'report-sample' 'unsafe-eval' 'unsafe-inline' https: http:;report-uri https://csp.withgoogle.com/csp/gws/other-hp 1 object-src 'none';base-uri 'self';script-src 'nonce-tA5bbY-MPCaiKtErDKr4mQ' 'strict-dynamic' 'report-sample' 'unsafe-eval' 'unsafe-inline' https: http:;report-uri https://csp.withgoogle.com/csp/gws/other-hp 1 report-uri https://csp.withgoogle.com/csp/youtube_main/strict;base-uri 'self';object-src 'none';script-src 'report-sample' 'nonce-lX2bXoHpYUhIV-UnCMJsSA' 'unsafe-inline' 'strict-dynamic' https: http: 'unsafe-eval' 1 object-src 'none';base-uri 'self';script-src 'nonce-O5A2HGC7ZszW7AaPNfUXnw' 'strict-dynamic' 'report-sample' 'unsafe-eval' 'unsafe-inline' https: http:;report-uri https://csp.withgoogle.com/csp/gws/other-hp 1 object-src 'none';base-uri 'self';script-src 'nonce-GkkbW9mAXW8Wh4Ih1rCQ-A' 'strict-dynamic' 'report-sample' 'unsafe-eval' 'unsafe-inline' https: http:;report-uri https://csp.withgoogle.com/csp/gws/other-hp 1 object-src 'none';base-uri 'self';script-src 'nonce-iEq5X1qRBNjWOJiJu0ZLMw' 'strict-dynamic' 'report-sample' 'unsafe-eval' 'unsafe-inline' https: http:;report-uri https://csp.withgoogle.com/csp/gws/other-hp 1 default-src https: data: https://www.uptodate.com https://www.uptodate.cn; child-src https: data: blob: edge: brave: puffin:; img-src data: https: blob: https://www.uptodate.com https://www.uptodate.cn https://*.d.aa.online-metrix.net https://cdn.cookielaw.org https://app.pendo.uptodate.com https://cdn.wolterskluwer.io; font-src https: data: https://www.uptodate.com https://www.uptodate.cn; worker-src blob: brave: edge: puffin: https://www.uptodate.com https://www.uptodate.cn; media-src data: https: https://www.uptodate.com https://www.uptodate.cn; connect-src data: https: wss: https://www.uptodate.com https://www.uptodate.cn https://geolocation.onetrust.com https://cdn.cookielaw.org https://app.pendo.uptodate.com https://privacyportal-de.onetrust.com; script-src 'unsafe-inline' 'unsafe-eval' https: https://www.uptodate.com https://www.uptodate.cn https://cdn.cookielaw.org https://cdn.pendo.uptodate.com https://www.googletagmanager.com https://tmx.uptodate.com https://rollouts.cdn.uptodate.com https://www.google-analytics.com https://code.jquery.com; style-src 'unsafe-inline' https: https://www.uptodate.com https://www.uptodate.cn https://cdn.pendo.uptodate.com; frame-src https: https://www.uptodate.com https://www.uptodate.cn baiduboxapp: ms-appx-web:; report-uri /services/app/content-security-policy-report/report/json;frame-ancestors *; 1 require-trusted-types-for 'script'; report-uri https://csp.withgoogle.com/csp/uxe-owners-acl/googleorg 1 script-src 'self' 'unsafe-inline' 'unsafe-eval' 50339659.hs-sites.com 1003891.track.convertexperiments.com app.hubspot.com cdn-3.convertexperiments.com cdn-4.convertexperiments.com *.metrics.convertexperiments.com *.signals.convertexperiments.com logs.convertexperiments.com *.convertexperiments.com cdn.pdst.fm connect.facebook.net js.hs-analytics.net js.hs-banner.com js.hsforms.net js.hsleadflows.net js.hubspotfeedback.com js.usemessages.com play.vidyard.com script.hotjar.com snap.licdn.com static.hotjar.com static.hsappstatic.net www.google-analytics.com www.googletagmanager.com www.recaptcha.net code.highcharts.com www.youtube.com js.hubspot.com www.dropbox.com widget.altrulabs.com www.google.com maps.googleapis.com wt-assets.hubteam.com cdn2.hubspot.net www.redditstatic.com cdn.veritonic.com gosniply.com d.impactradius-event.com test.test.com js.hubspot.com analytics.tiktok.com 'strict-dynamic' 'nonce-4tzxqgPKFqJ0x8LlS0Jbmg=='; report-uri https://send.hsbrowserreports.com/csp/report 1 default-src 'self' ; connect-src 'self' https://*.clarity.ms https://www.google.com https://analytics.google.com https://pixelconnector.pixeltracker.co https://www.google-analytics.com https://insight.adsrvr.org https://tr.snapchat.com https://app.heyhalda.com https://analytics.heyhalda.com https://tr6.snapchat.com https://o.clarity.ms https://analytics.tiktok.com https://ip.veritonicmetrics.com https://mgln.ai https://atr.veritonicmetrics.com https://pixels.spotify.com https://px.ads.linkedin.com; script-src 'self' 'unsafe-inline' https://use.typekit.net https://www.googletagmanager.com https://platform.twitter.com https://www.youtube.com https://tracker.pixeltracker.co https://sc-static.net https://js.adsrvr.org https://googleads.g.doubleclick.net https://siteimproveanalytics.com https://connect.facebook.net https://app.heyhalda.com https://snap.licdn.com https://analytics.tiktok.com https://js.ipredictive.com https://cdn.veritonic.com https://pixel.byspotify.com https://cdn.mgln.ai https://www.clarity.ms https://tr.snapchat.com; script-src-elem 'self' 'unsafe-inline' https://www.google-analytics.com https://app.heyhalda.com https://www.googletagmanager.com https://use.typekit.net https://platform.twitter.com https://www.youtube.com https://sc-static.net https://connect.facebook.net https://js.adsrvr.org https://snap.licdn.com https://tracker.pixeltracker.co https://analytics.tiktok.com https://js.ipredictive.com https://cdn.veritonic.com https://pixel.byspotify.com https://cdn.mgln.ai https://googleads.g.doubleclick.net https://clarity.ms https://siteimproveanalytics.com https://tr.snapchat.com https://www.clarity.ms; style-src 'self' 'unsafe-inline' https://use.typekit.net; font-src 'self' https://use.typekit.net; img-src 'self' data: https://*.cdninstagram.com https://instagram.f* https://graph.instagram.com https://www.linkedin.com https://c.clarity.ms https://s.gravatar.com https://*.wp.com https://cdn.auth0.com https://p.typekit.net https://tvspix.com https://www.google.com https://tr.snapchat.com https://66356254.global.siteimproveanalytics.io https://www.facebook.com https://px.ads.linkedin.com https://www.googletagmanager.com https://mgln.ai https://pixel.tapad.com https://us.mgln.ai; frame-src 'self' https://www.youtube.com https://www.google.com https://www.googletagmanager.com https://platform.twitter.com https://insight.adsrvr.org https://ad.ipredictive.com; media-src 'self' https://*.cdninstagram.com https://instagram.f* https://graph.instagram.com; object-src 'self'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'; upgrade-insecure-requests; block-all-mixed-content; 1 default-src data: 'unsafe-inline' 'unsafe-eval' https: blob: http://*.files.wordpress.com wss://www.sheknows.com; report-uri https://pmcuri.report-uri.com/r/d/csp/reportOnly 1 base-uri 'self'; default-src 'self' 'unsafe-inline' 'unsafe-eval' blob: data: chrome: https:; worker-src 'self' data: blob:; child-src 'self' blob:; frame-src 'self' *.consumeraffairs.com *.google.com *.googletagmanager.com *.googleapis.com *.facebook.com *.youtube.com *.px-cloud.net i.liadm.com; connect-src 'self' *.consumeraffairs.com wss://ws.hotjar.com https://ws.hotjar.com *.px-cloud.net api.segment.io https:; report-uri https://stderr.consumeraffairs.com/api/40/security/?sentry_key=7cf6b3564e4343f68a310b937a3d823e&sentry_environment=production&sentry_release=ms-2025.12.23.00; 1 frame-ancestors https: canvas.uts.edu.au; report-uri https://www.uts.edu.au/api/reporting/; report-to csp-endpoint; 1 object-src 'none';base-uri 'self';script-src 'nonce-GG6Cu5C-Hwp66GSTxFDutg' 'strict-dynamic' 'report-sample' 'unsafe-eval' 'unsafe-inline' https: http:;report-uri https://csp.withgoogle.com/csp/gws/other-hp 1 script-src 'unsafe-eval' blob: 'self' https: 'self' data: 'unsafe-inline' 'unsafe-eval' blob: 'unsafe-inline' internal-soap.wikia.com internal-soap.fandom.com internal-soap.wikia.org internal-soap.gamepedia.com www.fandom.com www.wikia.com www.wikia.org www.gamepedia.com; default-src 'self' data: blob: https: 'self' data: blob: internal-soap.wikia.com internal-soap.fandom.com internal-soap.wikia.org internal-soap.gamepedia.com www.fandom.com www.wikia.com www.wikia.org www.gamepedia.com; style-src 'self' data: blob: https: 'self' data: blob: internal-soap.wikia.com internal-soap.fandom.com internal-soap.wikia.org internal-soap.gamepedia.com www.fandom.com www.wikia.com www.wikia.org www.gamepedia.com 'unsafe-inline'; img-src * data: blob:; object-src 'none'; report-uri https://services.fandom.com/csp-logger/csp/ucp; worker-src 'self' blob: 1 object-src 'none';base-uri 'self';script-src 'nonce-6Z9NmUi-54NCuZUHqGUxpw' 'strict-dynamic' 'report-sample' 'unsafe-eval' 'unsafe-inline' https: http:;report-uri https://csp.withgoogle.com/csp/gws/other-hp 1 object-src 'none';base-uri 'self';script-src 'nonce-QX_FNOOx7pZN7DI-gKzZgw' 'strict-dynamic' 'report-sample' 'unsafe-eval' 'unsafe-inline' https: http:;report-uri https://csp.withgoogle.com/csp/gws/other-hp 1 object-src 'none';base-uri 'self';script-src 'nonce-hq1VJ1NbUMVpiXu7IViCRw' 'strict-dynamic' 'report-sample' 'unsafe-eval' 'unsafe-inline' https: http:;report-uri https://csp.withgoogle.com/csp/gws/other-hp 1 object-src 'none';base-uri 'self';script-src 'nonce-DPL7PE8Z4In0nlhRJgyLPg' 'strict-dynamic' 'report-sample' 'unsafe-eval' 'unsafe-inline' https: http:;report-uri https://csp.withgoogle.com/csp/gws/other-hp 1 object-src 'none';base-uri 'self';script-src 'nonce-_-MBzukKplbSfY1GP7CtWA' 'strict-dynamic' 'report-sample' 'unsafe-eval' 'unsafe-inline' https: http:;report-uri https://csp.withgoogle.com/csp/gws/other-hp 1 report-uri https://mon-ttp.lemon8-app.us/monitor_browser/collect/batch/security/?bid=tiktok_pns&ev_type=csp&p=a2ER8eALdqWH8mbn5n3bkT&v=4&s=587&b=oab; report-to csp-endpoint; script-src 'report-sample' 'unsafe-eval' *.tiktokcdn-us.com connect.facebook.net ct.pinterest.com; worker-src 'self' 1 style-src 'self' 'unsafe-inline' data: *.ebay.com *.ebay.es *.ebaystatic.com *.ebaystatic.es *.ebaystatic.cn *.gstatic.com *.fontawesome.com blob: *.googleapis.com; connect-src 'self' *.ebay.com *.ebay.es *.ebaystatic.com *.ebaystatic.es data: *.google-analytics.com *.doubleclick.net *.avalon.perfdrive.com *.ebayimg.com *.ucweb.com *.akamaihd.net *.ucads.ucweb.com *.analytics.google.com *.g.doubleclick.net *.googletagmanager.com *.pinterest.com *.snapchat.com *.criteo.com *.facebook.com *.googleapis.com *.googleadservices.com blob: analytics.google.com *.us.shoplive.cloud www.facebook.com *.bing.com www.googletagmanager.com google.com *.google.com *.graphitevault.com *.amplitude.com wss://127.0.0.1:* www.redditstatic.com *.reddit.com *.quantummetric.com; script-src 'self' 'unsafe-eval' 'unsafe-inline' https://* blob: data:; frame-ancestors 'self' *.ebay.com *.ebay.es *.ebaystatic.com *.ebaystatic.es; img-src 'self' data: blob: https://*; default-src 'self' blob: data: wss: mediastream: https://*; report-uri https://monitor.ebay.com/csp-report/discoveryplatformweb/HomePage?id=2939504940913871808&rid=t6gludlscuzujfwciunrce00%3C%3Dgludlscuzujfwciunrce00%2Bee%3C%3F371d0.qctp01*7k2lh-19c359f1a11-0x2604#pd 1 default-src 'self' ; script-src 'self' 'unsafe-eval' 'unsafe-inline' 'nonce-2342bb36-ffaf-41e9-990c-b6c967c8dc99' https: data: https://js.sentry-cdn.com https://fast.wistia.com https://fast.wistia.net https://siteintercept.qualtrics.com https://browser.sentry-cdn.com https://*.siteintercept.qualtrics.com https://www.googletagmanager.com https://js.monitor.azure.com; style-src 'self' 'unsafe-inline' https://fast.wistia.com https://cdn.jsdelivr.net https://more.suse.com; img-src 'self' https: data: https://fast.wistia.com https://embed-ssl.wistia.com https://cdn.cookielaw.org https://embed-ssl.wistia.com https://fast.wistia.net https://fast.wistia.com https://cdn.cookielaw.org https://embed-ssl.wistia.com https://embed-ssl.wistia.com https://cdn.cookielaw.org https://embed-ssl.wistia.com; connect-src 'self' https: wss: https://cdn.cookielaw.org https://distillery.wistia.com https://siteintercept.qualtrics.com https://dc.services.visualstudio.com https://fast.wistia.com https://fast.wistia.net https://pipedream.wistia.com wss://ws.qualified.com https://embed-ssl.wistia.com https://apple.dxcloud.episerver.net https://cdn.jsdelivr.net https://js.monitor.azure.com wss://ws.qualified.com; font-src 'self' https: data: https://fonts.gstatic.com https://fast.wistia.net; object-src 'none' ; media-src 'self' https: blob: ; frame-src 'self' https: ; form-action 'self' https://suselinux.fra1.qualtrics.com; frame-ancestors 'self' ; base-uri 'none' ; report-uri https://www.suse.com/api/reporting/; report-to csp-endpoint; 1 script-src 'nonce-SBWw+HXnuk3vBwrhtMR+gA==' 'strict-dynamic' 'unsafe-eval' 'unsafe-inline' https: 'report-sample'; base-uri 'none'; report-uri https://events.mercadolibre.com/csp/reports?identifier=w1qeU4XKVwGbQGBuEKyE3KhFBIpr5IZSIaRiTowMc8UG7kU18vRsmBTEKL2krAj23LIS&policy_id=26548&user_id=&request_id=1f537b71-32ca-40ae-a08f-6a664c9f9125; report-to csp-endpoint-wqeuxkvwgbqgbuekyekhfbiprizsiaritowmcugkuvrsmbteklkrajlis; object-src https://http2.mlstatic.com/ https://mlstaticquic-a.akamaihd.net/; frame-ancestors 'self' https://*.mercadolibre.cl:* https://*.mercadolibre.com:* https://*.mercadolibre.com.ve:* https://*.mercadolibre.com.ar:* https://*.mercadolivre.com.br:* https://*.mercadolibre.com.co:* https://*.mercadolibre.com.ec:* https://*.mercadolibre.com.mx:* https://*.mercadolibre.com.pe:* https://*.mercadolibre.com.uy:* https://*.mercadopago.cl:* https://*.mercadopago.com.ar:* https://*.mercadopago.com.br:* https://*.mercadopago.com.co:* https://*.mercadopago.com.mx:* https://*.mercadopago.com.pe:* https://*.mercadopago.com.uy:* https://*.mercadopago.com.ve:* https://*.mercadopago.com:* https://*.adminml.com:* https://*.mercadolibre.co.cr:* https://*.mercadolibre.com.pa:* https://*.mercadolibre.com.do:* https://*.mercadolibre.com.bo:* https://*.mercadolibre.com.py:* https://*.mercadolibre.com.gt:* https://*.mercadolibre.com.hn:* https://*.mercadolibre.com.ni:* https://*.mercadolibre.com.sv:* https://*.mercadopago.com.ec:* https://*.portalinmobiliario.com:* https://*.mercadolivre.com:* 1 frame-ancestors 'self'; report-uri https://www.heraldsun.com.au/csp-reports 1 base-uri 'self'; connect-src 'self' https://*.clarity.ms/collect https://*.google-analytics.com/g/collect https://*.launchdarkly.com https://ad.doubleclick.net https://amplify.outbrain.com https://analytics.google.com https://analytics.tiktok.com https://api.segment.io https://aplo-evnt.com https://bat.bing.com https://bat.bing.net https://browser-intake-datadoghq.eu https://cdn.segment.com https://content.hotjar.io https://conversions-config.reddit.com https://cookie-cdn.cookiepro.com https://geolocation.onetrust.com https://graphql.contentful.com https://id.sage.com https://maps.googleapis.com https://pagead2.googlesyndication.com https://pagesense-collect.zoho.in https://pixel-config.reddit.com https://pixel.quantserve.com https://pixels.spotify.com https://postcodes.io https://privacyportal.cookiepro.com https://px.ads.linkedin.com https://rum-http-intake.logs.datadoghq.eu https://stats.g.doubleclick.net https://tide.api.kustomerapp.com https://tr.outbrain.com https://widget.trustpilot.com https://www.cloudflare.com https://www.facebook.com https://www.google-analytics.com https://www.google.com https://www.googleadservices.com https://www.redditstatic.com https://z.clarity.ms; default-src 'none'; font-src 'self' https://cdn.kustomerapp.com https://fonts.gstatic.com https://web-assets.tide.co; frame-ancestors 'self' https://uniclient-demo.web.app; frame-src 'self' https://14663405.fls.doubleclick.net https://forms.zohopublic.in https://widget.trustpilot.com https://www.googletagmanager.com https://www.youtube.com; img-src 'self' https://ade.googlesyndication.com https://bat.bing.net https://c.clarity.ms https://cdn.prod2.kustomerhostedcontent.com https://downloads.ctfassets.net https://heapanalytics.com https://images.ctfassets.net https://impressions.onelink.me https://px.ads.linkedin.com/collect https://q.quora.com https://web-assets.tide.co https://www.facebook.com https://www.google.co.in https://www.google.com; manifest-src 'self'; media-src 'self' https://videos.ctfassets.net; object-src 'none'; report-to csp-reporting-endpoint; report-uri https://csp-report.browser-intake-datadoghq.eu/api/v2/logs?dd-api-key=pubd4258020965cc5258eee35ac618e9586&dd-evp-origin=content-security-policy&ddsource=csp-report; script-src 'self' 'unsafe-inline' https://a.quora.com https://amplify.outbrain.com https://analytics.tiktok.com/ https://assets.apollo.io/ https://bat.bing.com https://cdn-in.pagesense.io https://cdn.datatables.net https://cdn.heapanalytics.com https://cdn.jsdelivr.net https://cdn.kustomerapp.com https://cdn.segment.com/ https://cdnjs.cloudflare.com/ajax/libs/ https://code.jquery.com https://connect.facebook.net/ https://cookie-cdn.cookiepro.com/ https://d34r8q7sht0t9k.cloudfront.net https://d38xvr37kwwhcm.cloudfront.net https://geotargetly-api-2.com https://googleads.g.doubleclick.net https://googleusercontent.com https://js.stripe.com https://kit.fontawesome.com https://payments.tide.co https://pixel.byspotify.com/ https://rules.quantcount.com https://script.hotjar.com https://scripts.clarity.ms https://scripts.clarity.ms/ https://secure.quantserve.com https://snap.licdn.com https://stackpath.bootstrapcdn.com https://static.ads-twitter.com https://static.hotjar.com https://tr.outbrain.com https://wave.outbrain.com https://web-assets.tide.co/ https://widget.trustpilot.com/ https://www.clarity.ms https://www.datadoghq-browser-agent.com https://www.google-analytics.com https://www.googletagmanager.com/ https://www.gstatic.com https://www.redditstatic.com; style-src 'self' 'unsafe-inline' https://cdn.jsdelivr.net https://cdnjs.cloudflare.com/ajax/libs https://fonts.googleapis.com/css https://stackpath.bootstrapcdn.com https://use.typekit.net; worker-src 'self' 1 default-src 'self' blob:; script-src 'self' 'unsafe-inline' 'unsafe-eval' https: *.addthis.com *.akamai.net *.convertexperiments.com *.flickr.com *.hotjar.com *.google.com *.sierraclub.org *.twitter.com cdn.ampproject.org cdn.hypemarks.com cdn.jsdelivr.net cdn.optimizely.com connect.facebook.net google-analytics.com google.com googletagmanager.com instagram.com js.maxmind.com maps.googleapis.com partner.googleadservices.com pixel.sitescout.com public.tableau.com reddit.com scribd.com snap.licdn.com unpkg.com v1.addthisedge.com widgets.pinterest.com z.moatads.com; object-src 'self'; style-src 'self' 'unsafe-inline' https: *.sierraclub.org cdn.honey.io cdn.jsdelivr.net cdn.knightlab.com cdnjs.cloudflare.com cloud.typography.com *.hotjar.com fonts.googleapis.com google.com pro.fontawesome.com; img-src * 'unsafe-inline' blob: data: https:; media-src 'self' data:; frame-src 'self' https: *.addthis.com *.doubleclick.net *.fls.doubleclick.net *.ggusd.us *.google.com *.hotjar.com *.optimizely.com *.s3.amazonaws.com *.sierraclub.org *.stpsb.org *.twitter.com block.opendns.com blocked.goguardian.com calendar.google.com cdn.bannersnack.com ckreport.lisd.net clubvolunteer.org facebook.com funnyordie.com gateway.zscalertwo.net global.acs.prismaaccess.com googletagmanager.com instagram.com m.facebook.com maphub.net meetup.com mozbar.moz.com player.vimeo.com public.tableau.com quorum.us rcm-na.amazon-adsystem.com s7.addthis.com spur.maps.arcgis.com static.contextall.com trustpoint-lax.northcentraltrust.com vpn.myips.org web.facebook.com youtube-nocookie.com youtube.com driveelectricweek.org; frame-ancestors 'self' https: blob: sierraclub.org driveelectricweek.org; child-src 'self' https: blob: sierraclub.org driveelectricweek.org; font-src 'self' data: https: *.sierraclub.org at.alicdn.com cdn.honey.io cdn.jsdelivr.net *.hotjar.com fonts.gstatic.com pro.fontawesome.com slant.co; connect-src 'self' https: *.doubleclick.net *.google-analytics.com *.google.com *.hotjar.com *.hotjar.io wss://*.hotjar.com *.optimizely.com *.sierraclub.org cdn.linkedin.oribi.io csp.withgoogle.com facebook.com geoip-js.com google-analytics.com googletagmanager.com logx.optimizely.com maps.googleapis.com sharethis.com secure.geonames.org stats.g.doubleclick.net *.osano.com; report-uri /report-csp-violation; upgrade-insecure-requests 1 default-src 'self'; connect-src https:; font-src 'self' data: cms.zdv.uni-mainz.de cms-cdn.zdv.uni-mainz.de; img-src blob: data: https:; script-src 'self' 'unsafe-inline' 'unsafe-eval' cms.zdv.uni-mainz.de cms-cdn.zdv.uni-mainz.de; style-src 'self' 'unsafe-inline' cms.zdv.uni-mainz.de cms-cdn.zdv.uni-mainz.de; worker-src 'self' blob:; 1 default-src data: https: 'unsafe-inline' 'unsafe-eval'; report-uri https://track.buyma.com/csp/report.json 1 default-src 'self'; script-src 'self' 'nonce-nonce-d51147356f0b1ff8e16e7d2f03f1c755'; img-src 'self' data: https:; font-src 'self' https:; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'none'; block-all-mixed-content 1 require-trusted-types-for 'script'; report-uri https://csp.withgoogle.com/csp/panoramio 1 worker-src blob: 'self';font-src data: https: 'self';img-src data: https: 'self';media-src https: 'self';connect-src https://*.google.com https://cea.formstack.com https://consent.cookie-script.com/ https://cookie-script.com https://edge.api.brightcove.com https://house-fastly-signed-us-east-1-prod.brightcovecdn.com https://manifest.prod.boltdns.net https://metrics.brightcove.com https://pixel-config.reddit.com https://px.ads.linkedin.com https://stats.g.doubleclick.net https://www.google.com https://www.redditstatic.com 'self';script-src https://*.google.com https://cdn.clinch.co https://cea.formstack.com https://connect.facebook.net https://consent.cookie-script.com/ https://cookie-script.com https://edge.api.brightcove.com https://players.brightcove.net https://snap.licdn.com https://static.formstack.com https://www.google.com https://www.googletagmanager.com/ https://www.gstatic.com/ 'self' 'sha256-DsBFEDeAVB8NfiULTlZ50vO8T1PBE1Z23d41C/l2PuY=' 'sha256-P6r4MES3B1SQPyCLTBrmNBJPZsVpoEzrg/Dzfu8xk/w=' 'sha256-yTjADT6NV2O6PKU2MuEDM2Na3ABcSUsRuRkMDHUsvjQ=' 'unsafe-eval' 'unsafe-hashes';style-src https://fonts.googleapis.com 'self' 'unsafe-hashes' 'unsafe-inline';frame-src https://player.cohostpodcasting.com https://www.google.com 'self';base-uri 'self';default-src 'self';manifest-src 'self' 1 default-src 'self'; font-src * data:; img-src * data:; media-src * data: blob:; frame-src *; script-src 'nonce-496f47db366fc624355ce79b11f2c868' 'unsafe-hashes' 'sha256-qwP4QCno5UAWneuNeQYFyvAiDvTfkg75J5D14cZjCDA=' 'sha256-S5xKDgI7S06g6YwGoh/T/JTDbndl/QB9P/WrrdygaUU=' 'sha256-lfXlPY3+MCPOPb4mrw1Y961+745U3WlDQVcOXdchSQc=' 'sha256-rRMdkshZyJlCmDX27XnL7g3zXaxv7ei6Sg+yt4R3svU=' 'sha256-kbHtQyYDQKz4SWMQ8OHVol3EC0t3tHEJFPCSwNG9NxQ=' 'sha256-F2FIxepkuC0NOVNSk0vN01FYQmWDYl4CITiGrDxcpZs=' 'sha256-2rvfFrggTCtyF5WOiTri1gDS8Boibj4Njn0e+VCBmDI=' 'sha256-MhtPZXr7+LpJUY5qtMutB+qWfQtMaPccfe7QXtCcEYc=' 'sha256-1tjffMrOxPdkP4w/XDnQFquGVJ+hRMdaRnvL6y+/CtQ=' 'unsafe-eval' https://actionnetwork.org/includes/js/ https://cdn.basejump.ai/js/ https://app.basejump.ai/static/ https://cdn.jsdelivr.net/npm/emojione@3.1.2/; worker-src 'self' blob:; style-src * 'unsafe-inline'; style-src-attr 'unsafe-inline'; object-src 'none'; connect-src https:; report-uri /_/csp-reports; report-to local-csp-reports; 1 script-src 'nonce-LCqnysmNBL4r6p5e91se0Q==' 'strict-dynamic' 'unsafe-eval' 'unsafe-inline' https: 'report-sample'; base-uri 'none'; report-uri https://events.mercadolibre.com/csp/reports?identifier=w1qeU4XKVwGbQGBuEKyE3KhFBIpr5IZSIaRiTowMc8UG7kU18vRsmBTEKL2krAj23LIS&policy_id=26548&user_id=&request_id=23f08239-7340-4971-bb6a-433332c5c0af; report-to csp-endpoint-wqeuxkvwgbqgbuekyekhfbiprizsiaritowmcugkuvrsmbteklkrajlis; object-src https://http2.mlstatic.com/ https://mlstaticquic-a.akamaihd.net/; frame-ancestors 'self' https://*.mercadolibre.cl:* https://*.mercadolibre.com:* https://*.mercadolibre.com.ve:* https://*.mercadolibre.com.ar:* https://*.mercadolivre.com.br:* https://*.mercadolibre.com.co:* https://*.mercadolibre.com.ec:* https://*.mercadolibre.com.mx:* https://*.mercadolibre.com.pe:* https://*.mercadolibre.com.uy:* https://*.mercadopago.cl:* https://*.mercadopago.com.ar:* https://*.mercadopago.com.br:* https://*.mercadopago.com.co:* https://*.mercadopago.com.mx:* https://*.mercadopago.com.pe:* https://*.mercadopago.com.uy:* https://*.mercadopago.com.ve:* https://*.mercadopago.com:* https://*.adminml.com:* https://*.mercadolibre.co.cr:* https://*.mercadolibre.com.pa:* https://*.mercadolibre.com.do:* https://*.mercadolibre.com.bo:* https://*.mercadolibre.com.py:* https://*.mercadolibre.com.gt:* https://*.mercadolibre.com.hn:* https://*.mercadolibre.com.ni:* https://*.mercadolibre.com.sv:* https://*.mercadopago.com.ec:* https://*.portalinmobiliario.com:* https://*.mercadolivre.com:* 1 default-src 'self'; media-src 'self'; connect-src 'self' https://vpncdn.protonweb.com https://account.proton.me https://account.protonvpn.com https://telemetry.protonvpn.com *.metrics.convertexperiments.com logs.convertexperiments.com *.convertexperiments.com; script-src 'self' blob: 'unsafe-eval' 'unsafe-inline' https://vpncdn.protonweb.com; style-src 'self' 'unsafe-inline' https://vpncdn.protonweb.com; font-src 'self' https://vpncdn.protonweb.com; img-src 'self' data: blob: https:; frame-src 'self' data: blob: https://www.youtube-nocookie.com https://www.openstreetmap.org; object-src 'self' data: blob:; child-src 'self' data: blob:; report-uri https://reports.proton.me/reports/csp; frame-ancestors 'self'; 1 frame-ancestors 'self' prd.hdmx.now.hclsoftware.cloud:* *.prd.hdmx.now.hclsoftware.cloud:* *.homedepot.com.mx; frame-src 'self' prd.hdmx.now.hclsoftware.cloud:* *.prd.hdmx.now.hclsoftware.cloud:* *.creativecdn.com *.youtube.com *.doubleclick.net *.googletagmanager.com *.bazaarvoice.com *.roomvo.com *.criteo.com ct.pinterest.com *.creativecdn.com *.criteo.net *.demdex.net; default-src 'self' prd.hdmx.now.hclsoftware.cloud:* *.prd.hdmx.now.hclsoftware.cloud:* blob:; child-src 'self' prd.hdmx.now.hclsoftware.cloud:* *.prd.hdmx.now.hclsoftware.cloud:* blob: *.homedepot.com.mx *.youtube.com; script-src 'self' prd.hdmx.now.hclsoftware.cloud:* *.prd.hdmx.now.hclsoftware.cloud:* 'unsafe-inline' 'unsafe-eval' *.googletagmanager.com *.google-analytics.com assets.adobedtm.com *.adobedc.net cm.everesttech.net *.demdex.net *.hotjar.com *.hotjar.io *.criteo.com *.criteo.net *.bing.com *.revjet.com *.accenture.com *.accenture.vntana.com *.bazaarvoice.com unpkg.com *.roomvo.com *.adobe.com *.cybersource.com *.paypal.com *.openpay.mx *.liveperson.net btttag.com *.btttag.com *.scarabresearch.com *.googleapis.com *.google.com *.creativecdn.com *.facebook.net analytics.tiktok.com s.pinimg.com tag.rmp.rakuten.com static.ads-twitter.com *.sprinklr.com svht.afftrk1.com *.doubleclick.net ct.pinterest.com *.homedepot.com.mx *.go-mpulse.net; connect-src 'self' prd.hdmx.now.hclsoftware.cloud:* *.prd.hdmx.now.hclsoftware.cloud:* wss://prod2-live-chat-tier2-mqtt.sprinklr.com *.hotjar.io *.doubleclick.net *.googleapis.com *.google.com *.googleadservices.com *.googletagmanager.com *.google-analytics.com *.scarabresearch.com cm.everesttech.net *.demdex.net api.digitalfemsa.io h.online-metrix.net *.liveperson.net *.openpay.mx *.creativecdn.com ct.pinterest.com *.sprinklr.com webchannel-content.eservice.emarsys.net *.btttag.com ct.pinterest.com *.bing.com *.homedepot.com.mx *.akamaihd.net *.akstat.io *.go-mpulse.net *.tiktok.com *.tiktokw.us *.bazaarvoice.com; style-src 'self' prd.hdmx.now.hclsoftware.cloud:* *.prd.hdmx.now.hclsoftware.cloud:* 'unsafe-inline' data: *.googleapis.com *.homedepot.com.mx; font-src 'self' prd.hdmx.now.hclsoftware.cloud:* *.prd.hdmx.now.hclsoftware.cloud:* data: *.gstatic.com *.google.com *.google.ca *.sprinklr.com *.homedepot.com.mx *.bazaarvoice.com; img-src 'self' prd.hdmx.now.hclsoftware.cloud:* *.prd.hdmx.now.hclsoftware.cloud:* data: blob: ct.pinterest.com *.bing.com analytics.tiktok.com s.pinimg.com static.ads-twitter.com *.doubleclick.net *.googleadservices.com *.facebook.com *.facebook.net *.twitter.com x.bidswitch.net *.adnxs.com r.casalemedia.com ad.360yield.com i.liadm.com contextual.media.net exchange.mediavine.com jadserve.postrelease.com sync.outbrain.com *.pubmatic.com trends.revcontent.com pixel.rubiconproject.com rtb-csync.smartadserver.com sync-t1.taboola.com criteo-sync.teads.tv criteo-partners.tremorhub.com ade.clmbtech.com eb2.3lift.com *.1rx.io ads.stickyadstv.com partner.mediawallahscript.com user-sync.fwmrm.net *.creativecdn.com *.agkn.com *.unrulymedia.com *.adsrvr.org *.rezync.com *.dmxleo.com quickchart.io *.sprinklr.com placehold.co *.scarabresearch.com www.google.com.mx *.google.com *.google.ca assets.adobedtm.com tag.rmp.rakuten.com svht.afftrk1.com webchannel-content.eservice.emarsys.net www.gstatic.com *.accenture.com *.bazaarvoice.com unpkg.com s3.amazonaws.com *.tiktokw.us akamaihd.net akstat.io go-mpulse.net online-metrix.net rtbhouse.com *.publitas.com *.surveymonkey.com *.adobe.com *.cybersource.com *.paypal.com api.digitalfemsa.io *.openpay.mx h.online-metrix.net cs.media.net p.rfihub.com pubmatic.com *.zemanta.com *.stackadapt.com sync.crwdcntrl.net *.liveperson.net *.lpsnmedia.net t.co *.criteo.com *.rlcdn.com *.demdex.net *.youtube.com *.homedepot.com.mx *.hclsoftware.cloud *.liftdsp.com *.criteo.net *.rkdms.com *.outbrain.com *.everesttech.net; 1 default-src * data: blob: filesystem: about: ws: wss: 'unsafe-inline' 'unsafe-eval';frame-ancestors 'self';report-uri /csp.php 1 require-trusted-types-for 'script'; report-uri https://csp.withgoogle.com/csp/uxe-owners-acl/admob_google_com 1 default-src 'self' https:; script-src 'self' https: 'unsafe-inline' 'unsafe-eval'; style-src 'self' https: 'unsafe-inline'; img-src 'self' https: data: blob:; media-src 'self' https: data: blob:; object-src 'none'; frame-ancestors 'self' https://experience.adobe.com https://infopoint.audi.it; connect-src 'self' https: wss://e0k754.acquire.io; base-uri 'self'; font-src 'self' https: data:; worker-src 'self' blob:; report-uri https://www.audi.com/api/csp-report; report-to csp-endpoint 1 default-src 'self' 'unsafe-inline' 'unsafe-eval'; font-src 'self' https://fonts.googleapis.com https://fonts.gstatic.com data:; style-src-elem 'self' 'unsafe-inline' https://fonts.googleapis.com; script-src-elem 'self' 'unsafe-inline' 'unsafe-eval' https://a.usbrowserspeed.com https://pg.feroot.com https://static.hsappstatic.net https://js.hs-scripts.com https://js.hubspot.com https://js-na1.hs-scripts.com https://js.hs-banner.com https://js.hs-analytics.net https://js.usemessages.com https://unpkg.com https://cdn.cookielaw.org https://js.hsforms.net https://tag.trovo-tag.com https://www.clarity.ms https://cdn.cookielaw.org https://www.googletagmanager.com https://www.statcounter.com https://s3-us-west-2.amazonaws.com https://r2.leadsy.ai https://api.hubspot.com; img-src 'self' 'unsafe-inline' data: https://www.googletagmanager.com https://c.clarity.ms https://track.hubspot.com https://cdn.cookielaw.org https://perf-na1.hsforms.com https://forms-na1.hsforms.com; connect-src 'self' https://pro.ip-api.com https://geolocation.onetrust.com https://pageguard.feroot.com https://api.hubspot.com https://cta-service-cms2.hubspot.com wss://statcounter.io https://s.clarity.ms https://n.clarity.ms https://cdn.cookielaw.org https://forms.hsforms.com https://c.statcounter.com https://www.google-analytics.com https://stats.g.doubleclick.net; worker-src blob:; frame-src https://meetings.hubspot.com https://app.hubspot.com https://www.facebook.com; report-uri https://csp.ferootstage.com/18b81144-3bd3-4865-a794-a12c61fe5488/277c4f84-de2d-44c9-9079-40f8187028cb/collect; 1 connect-src 'self' https: 'unsafe-eval' https://*.zoom.us wss://zpns.zoom.us wss://widget-mediator.zopim.com; default-src 'self' https:; font-src 'self' https: data: data: source.zoom.us; img-src 'self' https: data: blob: *.zoom.us https://v2assets.zopim.io https://static.zdassets.com; media-src 'self' https: *.zoom.us; object-src 'none'; script-src 'self' https: 'unsafe-inline' 'unsafe-eval' blob: http://zoom.us *.zoom.us; style-src 'self' https: 'unsafe-inline'; worker-src 'self' https: blob:; report-uri /csp-report 1 report-uri https://www.yelp.com/csp_report_only?id=f99303a95f01cef0&page=csp_report_frame_directives%2Cfull_site_ssl_csp_report_directives&policy_hash=41d0c45536d2a082f11d1cd0e00fde7f&site=www×tamp=1770427502; frame-ancestors 'self' https://*.yelp.com; default-src https:; img-src https: data: blob:; script-src https: data: 'unsafe-inline' 'unsafe-eval' blob:; style-src https: 'unsafe-inline' data:; font-src data: https:; child-src https: yelp-webview://* yelp://* data:; object-src 'none'; worker-src blob: https:; base-uri 'self'; form-action https: 1 default-src https: data: 'unsafe-inline' 'unsafe-eval'; child-src https: data: blob:; connect-src https: data: blob:; font-src https: data:; img-src https: data:; media-src blob: data: https:; object-src https:; script-src https: data: blob: 'unsafe-inline' 'unsafe-eval'; style-src https: 'unsafe-inline'; block-all-mixed-content; frame-ancestors 'self'; report-uri https://leafgroup.report-uri.com/r/d/csp/wizard 1 script-src 'nonce-Ql0my5krQZuXHTtN8e8P1w==' 'strict-dynamic' 'unsafe-eval';script-src-elem 'nonce-Ql0my5krQZuXHTtN8e8P1w==' 'strict-dynamic' 'unsafe-eval';script-src-attr 'nonce-Ql0my5krQZuXHTtN8e8P1w==' 'strict-dynamic' 'unsafe-eval';connect-src 'self' *.edpuzzle.com *.edpuzzle.dev *.edpuzzle.net images.edpuzzle.com https://*.awswaf.com *.nr-data.net *.mxpnl.com *.mixpanel.com https://service.mtcaptcha.com https://service2.mtcaptcha.com *.google-analytics.com *.googleapis.com *.googleusercontent.com accounts.google.com login.microsoftonline.com wss://5uj9b5geqb.execute-api.us-east-1.amazonaws.com wss://5k3vufy1vh.execute-api.us-east-1.amazonaws.com wss://api.appcues.com wss://api.appcues.net *.appcues.com *.appcues.net audio-uploads-us-standard.s3.amazonaws.com audio-uploads-us-standard.s3.us-east-1.amazonaws.com test-audio-uploads-us-standard.s3.amazonaws.com test-audio-uploads-us-standard.s3.us-east-1.amazonaws.com uploaded-profile-images-us-standard.s3.amazonaws.com test-uploaded-profile-images.s3.amazonaws.com edpuzzle-dev-student-images-cdk.s3.amazonaws.com edpuzzle-dev-student-images-cdk.s3.us-east-1.amazonaws.com edpuzzle-prod-student-images-cdk.s3.amazonaws.com edpuzzle-prod-student-images-cdk.s3.us-east-1.amazonaws.com edpuzzle-dev-teacher-images-cdk.s3.amazonaws.com edpuzzle-dev-teacher-images-cdk.s3.us-east-1.amazonaws.com edpuzzle-prod-teacher-images-cdk.s3.amazonaws.com edpuzzle-prod-teacher-images-cdk.s3.us-east-1.amazonaws.com edpuzzle-dev-teacher-files-cdk.s3.amazonaws.com edpuzzle-dev-teacher-files-cdk.s3.us-east-1.amazonaws.com edpuzzle-dev-student-files-cdk.s3.amazonaws.com edpuzzle-dev-student-files-cdk.s3.us-east-1.amazonaws.com edpuzzle-prod-teacher-files-cdk.s3.amazonaws.com edpuzzle-prod-teacher-files-cdk.s3.us-east-1.amazonaws.com edpuzzle-prod-student-files-cdk.s3.amazonaws.com edpuzzle-prod-student-files-cdk.s3.us-east-1.amazonaws.com res.cdn.office.net video-uploads-us-standard.s3.amazonaws.com test-video-uploads-us-standard.s3.amazonaws.com uploaded-images-us-standard.s3.amazonaws.com test-uploaded-images-dev-us-standard.s3.amazonaws.com test-thumbnails-delivery-us-standard.s3.amazonaws.com thumbnails-delivery-us-standard.s3.amazonaws.com vimeo.com *.browser-intake-datadoghq.com browser-intake-datadoghq.com https://*.googletagmanager.com;frame-ancestors 'self';frame-src *;img-src * 'self' data: blob:;style-src * 'unsafe-inline' 'self';media-src * 'self' blob:;report-to csp-endpoint;report-uri https://browser-intake-datadoghq.com/api/v2/logs?dd-api-key=pubf89cdec407bbb96fdd48a9726f00e7be&dd-evp-origin=content-security-policy&ddsource=csp-report&ddtags=service%3Aedpuzzle-server%2Cenv%3Aproduction%2Cversion%3A7.47.16;default-src 'self';base-uri 'self';font-src 'self' https: data:;form-action * 'self';object-src 'none';worker-src 'self' blob:;upgrade-insecure-requests 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://www.googletagmanager.com https://www.google-analytics.com https://cmp.inmobi.com https://cdn.intergient.com https://*.doubleclick.net https://cdn.intergi.com http://cdn.intergient.com https://btloader.com https://c.amazon-adsystem.com https://*.googlesyndication.com https://mowgoats.com; connect-src 'self' https://*.analytics.google.com https://*.google-analytics.com https://jamie-oliver-2.commercelayer.io https://*.googlesyndication.com https://*.doubleclick.net https://*.sentry.io https://*.playwire.com https://*.amazon-adsystem.com https://api.btloader.com https://*.algolia.net https://*.algolianet.com https://auth.commercelayer.io https://*.auth0.com https://csi.gstatic.com https://simple-save.jamieoliver.workers.dev https://s5g.jamieoliver.workers.dev; img-src 'self' https://asset.jamieoliver.com https://www.google.co.uk https://www.google-analytics.com https://px.moatads.com https://ad-delivery.net https://ad.doubleclick.net https://www.googletagmanager.com https://img.youtube.com https://i.ytimg.com https://s.gravatar.com https://*.auth0.com https://*.googlesyndication.com https://csi.gstatic.com https://cdn.sanity.io https://*.wp.com data:; media-src 'self' data:; frame-src 'self' https://td.doubleclick.net https://www.googletagmanager.com https://cdn.intergient.com https://www.youtube.com https://www.youtube-nocookie.com; worker-src 'self' blob:; object-src 'none'; style-src 'self' 'unsafe-inline' https://config.playwire.com; frame-ancestors 'none'; 1 script-src https://faq.wadax.ne.jp https://taj1.ebis.ne.jp/SFQ4WWMM/cmt.js 'unsafe-inline' 'self' https://payments.salesforce.com/ https://stats.g.doubleclick.net https://gmocloudcommunity.force.com https://checkoutshopper-test.adyen.com/ https://pal-test.adyen.com https://googleads.g.doubleclick.net/pagead/viewthroughconversion/779117373/ https://am.yahoo.co.jp/rt/ https://b99.yahoo.co.jp/pagead/conversion_async.js https://checkoutshopper-live.adyen.com/ https://www.wadax.ne.jp https://cdn.content.aws-prod1-useast1.aws.sfdc.cl/ https://www.googletagmanager.com/ https://taj2.ebis.ne.jp/SFQ4WWMM/cmt.js https://cache.img.gmo.jp https://pay.google.com https://www.gstatic.com/recaptcha/ https://uip.canary.lwc.dev https://cdn.content.aws-dev2-uswest2.aws.sfdc.cl/ blob: https://www.googletagmanager.com/gtag/js https://www.google.com/recaptcha/ https://js.stripe.com/ https://support.gmocloud.com import: https://www.google-analytics.com *.salesforce.com https://www.paypal.com/sdk/js 'report-sample' https://service.force.com/embeddedservice/ https://s.yimg.jp/images/listing/tool/cv/ytag.js 'unsafe-eval'; report-to sfdc-csp-ep; report-uri https://gmogshd-ch.lightning.force.com/_/ContentDomainCSPNoAuth?tenantId=00D10000000Hq6P&networkId=0DM5F00000001rL&type=communities 1 report-uri https://www.feedingamerica.org/report-uri/reportOnly 1 default-src 'self'; style-src * 'unsafe-inline'; img-src * data:; font-src * data:; frame-src *; worker-src blob:; script-src 'self' erli.pl 'unsafe-inline' 'unsafe-eval' https://*.erli.pl https://*.erli.tech https://*.prod.erli.tech https://bat.bing.com/bat.js https://bat.bing.com/p/action/134629556.js *.px-cloud.net *.px-cdn.net https://static.hotjar.com/c/hotjar-1742207.js https://script.hotjar.com/modules.*.js https://www.googletagmanager.com/gtm.js https://www.googletagmanager.com/gtag/js https://www.googletagmanager.com/gtag/destination https://analytics.optimalpeople.fr/js/rd-o-sdk.js https://analytics.tiktok.com/i18n/pixel/events.js https://analytics.tiktok.com/i18n/pixel/static/main.* https://analytics.tiktok.com/i18n/pixel/static/identify_935b0d03.js https://cdngazeta.pl/pixel/ID-625573 https://connect.facebook.net/en_US/fbevents.js https://connect.facebook.net/signals/config/306722670488438 https://googleads.g.doubleclick.net/pagead/viewthroughconversion/655077238 https://googleads.g.doubleclick.net/pagead/viewthroughconversion/466746092 https://pixel.wp.pl/w/tr.js https://pixel.wp.pl/w/WP-ERLI-SOFQW-AHA/ir.js https://fpx.wp.pl/web/v3/geBqSFMxQ5V57gTthkuL/loader_v3.11.0.js https://swrap.tradedoubler.com/wrap https://ams.creativecdn.com/tags/v2 https://ams.creativecdn.com/ig-membership https://tags.creativecdn.com/J05AnhvDIxGtgSQnpWbK.js https://www.artfut.com/static/tagtag.min.js https://www.artfut.com/static/tracking.min.js https://www.artfut.com/static/crossdevice.min.js https://www.google.com/pagead/1p-conversion/655077238 https://www.googleadservices.com/pagead/conversion/655077238; script-src-elem 'self' 'unsafe-inline' erli.pl *.erli.pl *.erli.tech *.prod.erli.tech connect.facebook.net maps.googleapis.com www.googleadservices.com www.gstatic.com www.google.com fpx.wp.pl bat.bing.com *.px-cloud.net *.px-cdn.net static.hotjar.com script.hotjar.com www.googletagmanager.com analytics.optimalpeople.fr analytics.tiktok.com cdngazeta.pl connect.facebook.net googleads.g.doubleclick.net pixel.wp.pl fpx.wp.pl swrap.tradedoubler.com ams.creativecdn.com tags.creativecdn.com www.artfut.com; connect-src 'self' erli.pl *.erli.pl *.erli.tech *.prod.erli.tech *.px-cloud.net *.px-cdn.net *.pxchk.net *.px-client.net *.google-analytics.com *.analytics.google.com *.googleadservices.com https://storage.googleapis.com/images-temp-erli-pl/ https://storage.googleapis.com/external-offers-import-erli-pl/ www.google.pl www.google.com maps.googleapis.com *.hotjar.io pixel.wp.pl fpx.wp.pl bat.bing.com forms.fcc-online.pl analytics.tiktok.com pos.bliskapaczka.pl clk.leadexpert.pl analytics.optimalpeople.fr ams.creativecdn.com stats.g.doubleclick.net www.facebook.com pixel-router.gazeta.pl; report-to 'csp-endpoint' 1 default-src 'self' mitel.io *.mitel.io mitel.com *.mitel.com; require-trusted-types-for 'script'; object-src 'self' mitel.io *.mitel.io mitel.com *.mitel.com; 1 default-src https: data: 'unsafe-eval' 'unsafe-inline'; report-uri /csp_reports 1 form-action 'self'; manifest-src 'self'; report-uri https://csp-flkt.domdog.io/report-uri/flipkart.com/3/2-1 1 style-src 'self' 'unsafe-inline' https://*.google.com; require-trusted-types-for 'script'; trusted-types sanitizer unsafe dompurify scriptHelper 1 default-src 'self'; script-src 'nonce-pMxmowPcdByEDr/q5Q59TQ==' 'strict-dynamic' https: 'unsafe-inline'; style-src 'self' 'unsafe-inline' blob: https://app.getbeamer.com https://assets.openlearning.com https://*.ssl.cf4.rackcdn.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://fonts.googleapis.com; object-src 'none'; base-uri 'self'; connect-src 'self' https://*.openlearning.com https://oluploadslive.blob.core.windows.net https://front-us-rest.ably.io https://api.amplitude.com https://api.hubapi.com https://api.hubspot.com https://api.ipify.org https://backend.getbeamer.com https://chat.frontapp.com https://www.facebook.com https://find.userpilot.io https://forms.hubspot.com https://iframe.ly https://in.hotjar.com https://learningtime.servicebus.windows.net https://pythonutilityfunctions.azurewebsites.net https://python-util-funcs-c2dzg6bdbrdbd0g6.australiaeast-01.azurewebsites.net https://sentry.io https://stats.g.doubleclick.net https://us-west-1-chat-server.frontapp.com https://vc.hotjar.io https://www.google-analytics.com https://pagead2.googlesyndication.com https://static.userguiding.com https://metrics.userguiding.com wss://analytex.userpilot.io wss://front-us-realtime.ably.io wss://*.openlearning.com; font-src 'self' data: https://*.ssl.cf4.rackcdn.com https://assets.openlearning.com https://cdnjs.cloudflare.com https://fonts.gstatic.com https://maxcdn.bootstrapcdn.com; frame-src 'self' https:; img-src 'self' data: blob: https:; manifest-src 'self' https://*.ssl.cf4.rackcdn.com; media-src 'self' https://dev-uploads.openlearning.com https://uploads.openlearning.com https://qencode.blob.core.windows.net; worker-src 'none'; child-src blob:; 1 default-src data: 'unsafe-inline' 'unsafe-eval' https: blob: http://*.files.wordpress.com wss://hollywoodlife.com; report-uri https://pmcuri.report-uri.com/r/d/csp/reportOnly 1 base-uri 'none'; object-src 'none'; script-src 'unsafe-inline' 'unsafe-eval' 'strict-dynamic' https: http: 'nonce-qoILFYM+xTTMcA1SKGk0Yw==' 1 default-src 'self' https://*.sugarondemand.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://*.avery.com https://*.osano.com https://analytics.tiktok.com https://www.google-analytics.com https://s.pinimg.com https://*.bazaarvoice.com https://*.dynamicyield.com https://js.squarecdn.com https://*.usablenet.com https://www.googletagmanager.com https://*.livechatinc.com https://unpkg.com/web-vitals/dist/web-vitals.iife.js https://*.google.com https://*.debugbear.com https://cdnjs.cloudflare.com/ajax/libs/picturefill/3.0.3/picturefill.min.js https://cdn.jsdelivr.net/npm/jquery@3.5.1/dist/jquery.slim.min.js https://cdn.jsdelivr.net/npm/bootstrap@4.1.3/dist/js/bootstrap.min.js https://cdnjs.cloudflare.com/ajax/libs/tether/1.4.0/js/tether.min.js https://*.salesloft.com https://*.bc0a.com https://*.attn.tv https://*.lrkt-in.com https://connect.facebook.net https://www.gstatic.com https://ct.pinterest.com https://*.curalate.com https://www.redditstatic.com https://*.doubleclick.net https://*.bing.com https://cdn.dashhudson.com/web/js/board-carousel-embed.js https://cdn.jsdelivr.net/npm/swiper@11/ https://*.cloudinary.com https://ajax.googleapis.com/ajax/libs/jquery/3.2.1/jquery.min.js https://cdn.jsdelivr.net/npm/popper.js@1.16.1/dist/umd/popper.min.js https://cdnjs.cloudflare.com/ajax/libs/lightbox2/2.11.5/js/lightbox-plus-jquery.min.js 'wasm-unsafe-eval' https://*.glance.net https://*.glancecdn.net https://*.amazon-adsystem.com https://container.pepperjam.com https://cdn.lgrckt-in.com/logger-1.min.js *.udev1a.net *.usablenet.com https://cdn.jsdelivr.net/npm/beerslider@1.0.3/dist/BeerSlider.js; style-src 'self' 'unsafe-inline' https://*.avery.com https://fonts.googleapis.com https://*.dynamicyield.com https://cdnjs.cloudflare.com/ajax/libs/font-awesome/4.7.0/css/font-awesome.min.css https://*.typekit.net https://cdn.jsdelivr.net/npm/swiper@11/swiper-bundle.min.css https://cdnjs.cloudflare.com/ajax/libs/lightbox2/2.11.5/css/lightbox.min.css https://*.glance.net https://*.glancecdn.net https://avery-static-tailwind.s3.us-east-1.amazonaws.com/ *.udev1a.net *.usablenet.com https://cdn.jsdelivr.net/npm/beerslider@1.0.3/dist/BeerSlider.css; img-src 'self' data: https://*.avery.com https://www.google-analytics.com https://www.googletagmanager.com https://*.afterpay.com https://*.bazaarvoice.com https://*.doubleclick.net https://*.usablenet.com https://www.facebook.com https://*.dynamicyield.com https://*.livechatinc.com https://s3.amazonaws.com https://*.gstatic.com https://*.sugarondemand.com https://i.ytimg.com https://*.reddit.com https://*.bing.com https://*.cloudfront.net https://likeshop.me https://images.dashsocial.com https://images.dashhudson.com https://*.google.com https://*.glance.net https://*.glancecdn.net https://tvspix.com https://arttrk.com https://*.attentivemobile.com; font-src 'self' data: https://*.avery.com https://fonts.gstatic.com https://*.dynamicyield.com https://cdnjs.cloudflare.com https://*.squarecdn.com https://*.bazaarvoice.com https://*.typekit.net https://likeshop.me https://*.glance.net https://*.glancecdn.net; connect-src 'self' https://*.avery.com https://*.dynamicyield.com https://*.doubleclick.net https://dy-api.com https://www.google-analytics.com https://*.osano.com https://ct.pinterest.com https://analytics.tiktok.com https://*.bazaarvoice.com https://*.salesloft.com https://*.lrkt-in.com https://*.bc0a.com https://events.attentivemobile.com https://*.attn.tv https://*.afterpay.com https://server-side-tagging-ykzfrilmoq-uc.a.run.app https://*.amplitude.com https://*.google.com https://*.salsify.com https://salsify-ecdn.com https://*.curalate.com https://ls.chatid.com/events https://*.reddit.com https://www.redditstatic.com https://*.debugbear.com https://*.bing.com https://www.googleadservices.com https://api.likeshop.me/gallery-more https://www.facebook.com *.livechatinc.com wss://*.glance.net https://*.glance.net https://*.glancecdn.net https://direct-collect.dy-api.com https://*.amazon-adsystem.com https://ara.paa-reporting-advertising.amazon https://analytics-ipv6.tiktokw.us https://google.com https://r.lgrckt-in.com/i https://*.braintreegateway.com https://*.braintree-api.com; frame-src 'self' https://*.avery.com https://ct.pinterest.com https://*.google.com https://*.dynamicyield.com https://*.doubleclick.net https://*.livechatinc.com https://*.afterpay.com https://*.attn.tv https://www.facebook.com https://salsify-ecdn.com https://www.youtube.com https://server-side-tagging-ykzfrilmoq-uc.a.run.app https://www.googletagmanager.com https://*.amazon-adsystem.com https://*.cloudinary.com https://*.sugarondemand.com https://*.glance.net https://*.braintreegateway.com; frame-ancestors 'self' https://*.avery.com https://*.google.com; worker-src 'self' blob:; object-src 'none'; report-uri /_api/csp-report; report-to csp-endpoint; 1 default-src * 'unsafe-eval' 'unsafe-inline' 'unsafe-dynamic' data: filesystem: about: blob: ws: wss: report-uri https://o1151714.ingest.us.sentry.io/api/4509640700461056/security/?sentry_key=74a33d973a69190986eba8f4bca540d2; report-to csp-endpoint; 1 frame-ancestors 'self'; report-uri /scapi/danskespil/security/csp/testreport; 1 font-src fonts.gstatic.com use.typekit.net maxcdn.bootstrapcdn.com *.fontawesome.com fonts.googleapis.com https://fonts.gstatic.com https://www.google.com https://www.gstatic.com http2.mlstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.magerocket.com *.gocuotas.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.mercadolibre.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com mldp.mercadopago.com www.mercadolibre.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.magerocket.com *.gocuotas.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net imgmp.mlstatic.com *.mlstatic.com *.mercadopago.com *.mercadolibre.com *.mercadolivre.com.br *.mercadolibre.com.mx *.mercadolibre.com.ar *.mercadolivre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br www.mercadolibre.com www.mercadolibre.com.mx www.mercadolibre.com.ar www.mercadolibre.com.br a248.e.akamai.net mercadolivre.com.br www.mercadolivre.com.br www.mercadolivre.com.mx www.mercadolivre.com.ar www.mercadopago.com secure.mlstatic.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.magerocket.com *.gocuotas.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com www.mercadopago.com.ar www.mercadopago.cl *.google.com *.online-metrix.net *.groovinads.com *.g.doubleclick.net *.clarity.ms *.bing.com *.google.com.ar data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com amcglobal.sc.omtrdc.net commerce.adobe.net use.typekit.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-ds.com *.braindw.com *.mlstatic.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br http2.mlstatic.com secure.mlstatic.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.magerocket.com *.gocuotas.com *.googleapis.com *.google.com *.gstatic.com *.avada.io js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://live.decidir.com h.online-metrix.net https://merchants.playdigital.com.ar/ https://merchants.preprod.playdigital.com.ar/ https://ecommerce-modal.modo.com.ar/ https://ecommerce-modal.preprod.modo.com.ar/ i.k-analytix.com rum-static.pingdom.net live.decidir.com *.newrelic.com bam-cell.nr-data.net https://api.wcx.cloud https://static-s.braindw.com https://f.wcentrix.com https://ads01.groovinads.com https://static.hotjar.com https://script.hotjar.com https://connect.facebook.net https://googleads.g.doubleclick.net *.groovinads.com *.online-metrix.net *.bing.com *.clarity.ms *.cloudfront.net *.force.com *.la1-core1.sfdc-lywfpd.salesforceliveagent.com *.varify.io *.collect.igodigital.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com maxcdn.bootstrapcdn.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.fontawesome.com *.googleapis.com *.google.com *.gstatic.com unsafe-inline assets.braintreegateway.com https://ecommerce-modal.modo.com.ar/ https://ecommerce-modal.preprod.modo.com.ar/ http2.mlstatic.com *.force.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io commerce.adobe.net qa-api.magedevteam.com *.sentry.io *.braindw.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com api.mercadopago.com events.mercadopago.com www.mercadolibre.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.magerocket.com *.gocuotas.com http://dpm.demdex.net https://www.google.com https://www.gstatic.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com https://developers.decidir.com/ https://merchants.playdigital.com.ar/ https://merchants.preprod.playdigital.com.ar/ https://ecommerce-modal.modo.com.ar/ https://ecommerce-modal.preprod.modo.com.ar/ *.google-analytics.com i.konduto.com rum-collector-2.pingdom.net *.mercadolibre.com.ar *.decidir.com bam-cell.nr-data.net https://stats.g.doubleclick.net https://s.braindw.com https://a.braindw.com https://api.wcx.cloud https://f.wcentrix.com *.g.doubleclick.net *.nr-data.net *.clarity.ms *.online-metrix.net *.varify.io *.bing.com *.amazonaws.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src maxcdn.bootstrapcdn.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 script-src 'unsafe-eval' 'unsafe-inline' https: 'nonce-f753e76b6252279069b85579e3c84e50' 'strict-dynamic'; report-uri /api/fb/cspLogs; script-src-attr 'sha256-bwK6T5wZVTANitXbrTsel7kl/PyCjCd/Dq5Qoz3imjM=' 'unsafe-hashes'; 1 report-to cf-csp-endpoint 1 object-src 'none'; script-src 'self' 'unsafe-inline' 'unsafe-eval' adform.net *.adform.net betano.bg *.betano.bg betano.com *.betano.com betgenius.com *.betgenius.com cloudflare.com *.cloudflare.com cookielaw.org *.cookielaw.org facebook.net *.facebook.net fullstory.com *.fullstory.com gmlinteractive.com *.gmlinteractive.com creativecdn.com *.creativecdn.com googletagmanager.com *.googletagmanager.com kaizengaming.com *.kaizengaming.com kameleoon.eu *.kameleoon.eu optimove.net *.optimove.net sportradar.com *.sportradar.com sportradarserving.com *.sportradarserving.com cloudflareinsights.com *.cloudflareinsights.com app.delivery *.app.delivery google-analytics.com *.google-analytics.com lgrckt-in.com *.lgrckt-in.com tostarsbuilding.com *.tostarsbuilding.com; report-uri https://csp-reporting.cloudflare.com/cdn-cgi/script_monitor/report?m=lw52lqT5WIP3MvSCfaQSYPR8qd1jmDf3_9aSV6GFbv0-1770429920-1.0.1.1-58Z2YdRz6MfnzUIccH_vjh1DZnYS_dOE7kvsr6mTTqOkIVxlUdOPRo2No5CxAkudtnhjjEyyqJxVklg0isvUGDR1s.uvKXfecxcbg40FzIYyB_l7cRqup84D2xFVEiy3.sNn4bxnCNOhAbzt.PpVKFu40SsY4c3.G2nWhOPok810vgXxNrBa3tzkM4mrBPxar1YncpTP57DQ0X7BfJ65VA; report-to cf-lofwwyspuvsolqdi 1 default-src 'self' https:; script-src 'self' https: 'unsafe-inline' 'unsafe-eval'; style-src 'self' https: 'unsafe-inline'; img-src 'self' https: data: blob:; media-src 'self' https: data: blob:; object-src 'none'; frame-ancestors 'self' https://experience.adobe.com https://infopoint.audi.it; connect-src 'self' https: wss://e0k754.acquire.io; base-uri 'self'; font-src 'self' https: data:; worker-src 'self' blob:; report-uri https://www.audi.de/api/csp-report; report-to csp-endpoint 1 default-src 'self' https:; script-src 'self' 'unsafe-eval' https://www.googletagmanager.com https://*.google-analytics.com https://*.googleadservices.com https://*.company-target.com https://a.omappapi.com https://stage-cms-portal.quest.com https://www.quest.com https://*.qualified.com https://*.ddev.site https://cdn.cookielaw.org https://app.qualified.com https://*.qualified.com https://cdn.cookielaw.org https://s.company-target.com 'nonce-q9fsNkeur6n6CFWDAUx4xZ4jt0xzjyYp'; object-src 'none'; style-src 'self' 'unsafe-inline' *.google.com *.userway.org *.googleapis.com *.analysis.windows.net *.twitter.com *.nr-data.net *.youtube.com *.youtube-nocookie.com *.vimeo.com *.pagespeed-mod.com *.googletagmanager.com *.gstatic.com *.sharethis.com *.gleap.io *.cloudflare.com *.jsdelivr.net *.gitbook.com *.omappapi.com/; img-src 'self' 'unsafe-inline' https: data: quest.com *.quest.com blob:; media-src 'self' 'unsafe-inline' quest.com *.quest.com; frame-src 'self' 'unsafe-inline' *.webp *.twitter.com *.youtube.com *.youtube-nocookie.com *.facebook.com facebook.com *.nr-data.net *.youtube.com *.vimeo.com *.googletagmanager.com *.gleap.io *.company-target.com players.brightcove.net *.gitbook.io https://app.qualified.com; frame-ancestors 'self' *.google.com *.google-analytics.com *.analysis.windows.net *.googleapis.com *.twitter.com *.nr-data.net *.youtube.com *.youtube-nocookie.com *.vimeo.com *.pagespeed-mod.com *.googletagmanager.com *.gstatic.com *.sharethis.com *.gleap.io *.company-target.com; child-src *; font-src 'self' *.googleapis.com *.typekit.net *.userway.org *.analysis.windows.net *.gstatic.com *.twitter.com *.nr-data.net *.youtube.com *.youtube-nocookie.com *.vimeo.com *.pagespeed-mod.com *.googletagmanager.com data *.sharethis.com *.google.com *.gleap.io *.jsdelivr.net *.cloudflare.com; connect-src 'self' *.google-analytics.com *.vardot.com https: *.gleap.io 1 default-src 'self'; connect-src 'self' https://*.google-analytics.com https://analytics.google.com https://*.analytics.google.com https://pagesense-collect.zoho.com https://stats.g.doubleclick.net https://translate.googleapis.com https://www.googletagmanager.com https://www.google-analytics.com; font-src 'self' data: https://fonts.gstatic.com; frame-src 'self' https://connect.facebook.net https://m.facebook.com https://maps.google.com https://maps.googleapis.com https://mobile.facebook.com https://platform.twitter.com https://static.addtoany.com https://web.facebook.com https://www.facebook.com https://www.google.com https://www.googletagmanager.com https://www.youtube.com; img-src 'self' data: blob: https://*.google-analytics.com https://*.analytics.google.com https://fonts.gstatic.com https://pagesense-collect.zoho.com https://*.fbcdn.net https://stats.g.doubleclick.net https://translate.google.com https://translate.googleapis.com https://www.gcis.gov.za https://www.google.com https://www.google.co.za https://www.googletagmanager.com https://www.gov.za https://www.gstatic.com https://www.publicsectormanager.gov.za https://www.sanews.gov.za https://www.vukuzenzele.gov.za https://*.openstreetmap.org https://*.ytimg.com https://www.google-analytics.com; object-src 'none'; script-src 'self' 'report-sample' 'unsafe-inline' 'unsafe-eval' https://*.google-analytics.com https://cdn.pagesense.io https://connect.facebook.net https://maps.googleapis.com https://platform.twitter.com https://static.addtoany.com https://www.google.com https://www.googletagmanager.com https://www.gstatic.com; style-src 'self' 'report-sample' 'unsafe-inline' https://fonts.googleapis.com https://www.gstatic.com https://platform.twitter.com; worker-src 'self'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'; report-uri https://www.gov.za/system/reporting/default; report-to default 1 object-src 'none';base-uri 'self';script-src 'nonce-MotjYs7G+g8ekH2AbHml' 'unsafe-inline' 'unsafe-eval' 'strict-dynamic' https: http: 'report-sample';report-uri https://csp.withgoogle.com/csp/scfe 1 script-src 'unsafe-inline' 'unsafe-eval' *.alicdn.com *.aliyun.com *.alyasset.com *.alcasset.com *.alipay.com log.mmstat.com ynuf.aliapp.org *.alipayobjects.com local.alipcsec.com:6691 appx appx-t2; style-src 'unsafe-inline' *.alicdn.com *.aliyun.com *.alipay.com *.alipayobjects.com; font-src data: *.alicdn.com *.aliyun.com *.alipayobjects.com; frame-src *.aliyun.com *.alicdn.com *.aliyuncs.com *.alipay.com *.taobao.com *.alibabacloud.com *.1688.com xstore.insights.1688.com; report-uri //www.aliyun.com/api/log/csp-report 1 default-src 'self'; script-src 'self' addevent.com cdn.jsdelivr.net https://cdnjs.cloudflare.com https://challenges.cloudflare.com https://polyfill-fastly.io static.addtoany.com; style-src 'self' addtocalendar.com cdn.jsdelivr.net fonts.googleapis.com https://cdnjs.cloudflare.com 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://cdn.galvia.ai https://helper.portsmouth.galvia.ai www-embed-player.js *.cookiebot.com *.cookiefirst.com *.google-analytics.com www.instagram.com *.facebook.net *.tiktok.com *.ads-twitter.com *.twitter.com lf16-tiktok-web.ttwstatic.com cdn.unibuddy.co *.googletagmanager.com bat.bing.com w.soundcloud.com s.yimg.com sc-static.net snap.licdn.com www.googleadservices.com *.doubleclick.net siteimproveanalytics.com www.youtube.com *.hotjar.com *.linkedin.com service.force.com *.salesforceliveagent.com universityofportsmouth.my.salesforce.com *.formstack.com *.googleapis.com cdn.jsdelivr.net www.google.ie sfapi.formstack.io az416426.vo.msecnd.net discoveruni.gov.uk *.discoveruni.gov.uk *.matterport.com webteamuop.github.io *.port.ac.uk *.secure.force.com portsmouthuni.h5p.com *.go-mpulse.net js-agent.newrelic.com *.algolia.net *.jquery.com bot.ivy.ai bam.nr-data.net *.force.com *.clarity.ms dev.visualwebsiteoptimizer.com artsthread.com tr.snapchat.com tags.srv.stackadapt.com https://rv-vepple-embed.web.app https://builder.lift.acquia.com universityofportsmouth.my.salesforce-sites.com vimeo.com https://player.vimeo.com universityofportsmouth--chatbotdv2.sandbox.my.salesforce.com universityofportsmouth--chatbotdv2.sandbox.my.salesforce-sites.com universityofportsmouth--chatbotdv2.sandbox.lightning.force.com universityofportsmouth.tfaforms.net universityofportsmouth--qa.sandbox.my.site.com https://*.sandbox.lightning.force.com https://*.sandbox.my.salesforce.com universityofportsmouth.my.site.com universityofportsmouth.my.salesforce-scrt.com https://d8ejoa1fys2rk.cloudfront.net https://js-agent.newrelic.com; object-src 'self' https://discoveruni.gov.uk; style-src 'self' 'unsafe-inline' https://helper.portsmouth.galvia.ai modernizr.min.js *.googleapis.com platform.twitter.com lf16-tiktok-web.ttwstatic.com *.force.com static.formstack.com formsprod.azureedge.net sfapi.formstack.io port.formstack.com *.cookiefirst.com webteamuop.github.io *.port.ac.uk *.googletagmanager.com artsthread.com tags.srv.stackadapt.com *.visualwebsiteoptimizer.com app.vwo.com cdn.pushcrew.com s3.amazonaws.com universityofportsmouth.my.salesforce-sites.com embed.tawk.to *.tawk.to cdn.jsdelivr.net builder.lift.acquia.com *.formstack.io universityofportsmouth--chatbotdv2.sandbox.my.salesforce-sites.com universityofportsmouth.my.salesforce.com https://universityofportsmouth--qa.sandbox.my.site.com universityofportsmouth.tfaforms.net universityofportsmouth.my.site.com https://cdnjs.cloudflare.com; img-src 'self' data: *.google-analytics.com i.vimeocdn.com i.ytimg.com *.googletagmanager.com jadserve.postrelease.com bat.bing.com sp.analytics.yahoo.com *.siteimproveanalytics.io *.facebook.com *.facebook.net *.twitter.com t.co *.doubleclick.net googleads.g.doubleclick.net *.linkedin.com uks-prd-xp2-cd.azurewebsites.net ormsprod.azureedge.net port.formstack.com maps.gstatic.com *.googleapis.com lh3.ggpht.com www.google.ie *.cookiefirst.com formsprod.azureedge.net discoveruni.gov.uk *.force.com *.universityofportsmouth.my.salesforce.com *.salesforce.com *.port.ac.uk bot.ivy.ai *.clarity.ms *.bing.com dev.visualwebsiteoptimizer.com *.visualwebsiteoptimizer.com cdn.pushcrew.com chart.googleapis.com wingify-assets.s3.amazonaws.com app.vwo.com *.google.com *.google.ad *.google.ae *.google.com.af *.google.com.ag *.google.com.ai *.google.al *.google.am *.google.co.ao *.google.com.ar *.google.as *.google.at *.google.com.au *.google.az *.google.ba *.google.com.bd *.google.be *.google.bf *.google.bg *.google eat2mpk5ajg.exactdn.com *.eat2mpk5ajg.exactdn.com blob: https://egopbtuk8gz.exactdn.com *.egopbtuk8gz.exactdn.com *.frontdoorcdn.formstack.io https://frontdoorcdn.formstack.io images.artsthread.com *.google.co.uk https://cdn.galvia.ai/portsmouth/nellie-helper.js https://helper.portsmouth.galvia.ai https://*.ivy-cdn.com; media-src 'self'; frame-src 'self' https://www.googletagmanager.com https://helper.portsmouth.galvia.ai player.vimeo.com www.youtube.com *.linkedin.com portsmouthuni.h5p.com w.soundcloud.com viewer.joomag.com *.cookiebot.com www.instagram.com *.facebook.com *.tiktok.com *.twitter.com embed.acast.com unibuddy.co popcard.unibuddy.co tr.snapchat.com *.doubleclick.net view.genial.ly service.force.com *.hotjar.com *.matterport.com webteamuop.github.io universityofportsmouth.force.com *.port.ac.uk *.secure.force.com open.spotify.com *.google.com port.cloud.panopto.eu bot.ivy.ai app.nearpod.com *.visualwebsiteoptimizer.com universityofportsmouth.my.salesforce-sites.com *.tawk.to https://cdn.galvia.ai/portsmouth/nellie-helper.js universityofportsmouth.my.salesforce.com https://*.sandbox.lightning.force.com https://*.sandbox.my.salesforce.com https://universityofportsmouth--qa.sandbox.my.site.com https://universityofportsmouth--qa.sandbox.my.site.com https://universityofportsmouth.my.site.com https://outlook.office365.com https://discoveruni.gov.uk; frame-ancestors 'self' portsmouthuni.h5p.com; child-src 'self' blob:; font-src 'self' data: fonts.gstatic.com use.typekit.net *.modernizr.min.js static.formstack.com fonts.googleapis.com bot.ivy.ai cdn.scite.ai embed.tawk.to *.tawk.to res-1.cdn.office.net https://cdnjs.cloudflare.com; connect-src 'self' *.google-analytics.com www.googletagmanager.com marketing.port.ac.uk sentry10.bynder.cloud www.ucas.com *.tiktok.com tr.snapchat.com *.doubleclick.net s.yimg.com *.linkedin.com *.secure.force.com sfapi.formstack.io *.googleapis.com *.algolia.net *.cookiefirst.com ohpuem12fk-3.algolianet.com *.facebook.com vc.hotjar.io dc.services.visualstudio.com prod-discoveruni.azure-api.net cdn.linkedin.oribi.io webteamuop.github.io *.algolianet.com *.go-mpulse.net bam.nr-data.net *.akstat.io *.akamaihd.net *.hotjar.com plugin.ucads.ucweb.com *.clarity.ms tags.srv.stackadapt.com *.visualwebsiteoptimizer.com app.vwo.com *.port.ac.uk vimeo.com universityofportsmouth.my.salesforce-sites.com artsthread.com eu.perz-api.cloudservices.acquia.io *.google.com va.tawk.to embed.tawk.to *.tawk.to wss://*.tawk.to insights.algolia.io virtual.port.ac.uk *.virtual.port.ac.uk *.analytics.pangle-ads.com https://api.portsmouth.rvhosted.com eat2mpk5ajg.exactdn.com *.eat2mpk5ajg.exactdn.com https://google.com blob: https://analytics.pangle-ads.com https://egopbtuk8gz.exactdn.com *.egopbtuk8gz.exactdn.com universityofportsmouth--chatbotdv2.sandbox.my.salesforce-sites.com https://*.sandbox.lightning.force.com https://*.sandbox.my.salesforce.com https://universityofportsmouth--qa.sandbox.my.salesforce-scrt.com https://universityofportsmouth.my.site.com https://*.my.site.com https://cdn.jsdelivr.net https://universityofportsmouth.my.salesforce-scrt.com https://fonts.gstatic.com https://universityofportsmouth.my.salesforce.com https://d.la11-core1.sfdc-cehfhs.salesforceliveagent.com https://universityofportsmouth.tfaforms.net *.jquery.com code.jquery.com https://bot.ivy.ai https://cdn.galvia.ai/portsmouth/portia-helper.js 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' blob: *.a.net *.6sc.co *.ads-twitter.com *.bing.com *.bizible.com *.cloudflare.com *.doubleclick.net *.google-analytics.com *.google.com *.googletagmanager.com *.hs-analytics.net *.hs-banner.com *.hsadspixel.net *.hsappstatic.net *.hscollectedforms.net *.hsforms.com *.hsforms.net *.hsleadflows.net *.hs-scripts.com *.hubspot.com *.hubspot.net *.hubspotfeedback.com *.hubspotusercontent00.net *.hubspotusercontent10.net *.hubspotusercontent20.net *.hubspotusercontent30.net *.hubspotusercontent40.net *.jsdelivr.net *.ktxlytics.io *.linkedin.com *.redditstatic.com *.salesloft.com *.sentry-cdn.com *.stackadapt.com *.twitter.com *.usemessages.com *.varonis.com *.wistia.com *.wistia.net *.zi-scripts.com plausible.io qvdt3feo.com/events.js *.licdn.com/li.lms-analytics/insight.min.js unpkg.com *.jsdelivr.net unpkg.com/react@17.0.2/umd/react.production.min.js unpkg.com/react-dom@17.0.2/umd/react-dom.production.min.js js.hscta.net js-eu1.hscta.net static.hsappstatic.net feedback.hubapi.com feedback-eu1.hubapi.com 'strict-dynamic' 'nonce-DrXOUSEwt9LPoFmyu1fBNw=='; script-src-elem 'self' *.jsdelivr.net *.google.com *.google.com; style-src 'self' 'unsafe-inline' *.cloudflare.com *.google.com *.googleapis.com *.hsappstatic.net *.hubspot.net *.hubspotusercontent00.net *.hubspotusercontent10.net *.hubspotusercontent20.net *.hubspotusercontent30.net *.hubspotusercontent40.net *.jsdelivr.net *.stackadapt.com *.varonis.com cdn2.hubspot.net; img-src 'self' data: blob: *.6sc.co *.adnxs.com *.adsrvr.org *.bing.com *.bizible.com *.doubleclick.net *.google-analytics.com *.google.com google.com *.hubspot.com *.hubspot.net *.hubspotusercontent00.net *.hubspotusercontent10.net *.hubspotusercontent20.net *.hubspotusercontent30.net *.hubspotusercontent40.net *.hubspotusercontent-na1.net *.hsforms.com *.hsforms.net js.hscta.net js-eu1.hscta.net no-cache.hubspot.com static.hsappstatic.net *.linkedin.com *.facebook.com *.reddit.com *.twitter.com *.youtube.com https://t.co *.ktxlytics.io *.googletagmanager.com *.varonis.com *.wistia.com *.wistia.net; font-src 'self' data: *.gstatic.com *.googleapis.com *.hubspotusercontent-na1.net *.hsappstatic.net *.varonis.com *.wistia.com *.wistia.net; connect-src 'self' *.g2.com https://unpkg.com https://cdn.jsdelivr.net *.6sc.co *.cloudflare.com *.doubleclick.net *.google-analytics.com *.google.com google.com *.hubapi.com *.hubspot.com *.hubspotusercontent-na1.net *.hs-banner.com *.hscollectedforms.net *.hsforms.com *.js.zi-scripts.com https://js.zi-scripts.com https://epsilon.6sense.com https://plausible.io *.ktxlytics.io *.litix.io *.linkedin.com *.reddit.com *.redditstatic.com *.salesloft.com *.stackadapt.com *.varonis.com *.wistia.com *.wistia.net *.zoominfo.com js.hscta.net js-eu1.hscta.net; media-src 'self' blob: *.varonis.com *.wistia.com *.wistia.net *.youtube.com *.ytimg.com; object-src 'none'; frame-src 'self' *.hubspot.com *.hubspot.net *.hs-sites.com *.hs-sites-eu1.com *.hsforms.com *.hsforms.net *.podcasts.apple.com *.twitter.com *.vimeo.com *.varonis.com *.wistia.com *.wistia.net *.youtube.com *.yt.com play-eu1.hubspotvideo.com play.hubspotvideo.com *.facebook.com; worker-src 'self' *.hsforms.com; base-uri 'self'; form-action 'self' *.hsforms.com *.hsforms.net; frame-ancestors 'none'; upgrade-insecure-requests; block-all-mixed-content 1 default-src 'self'; connect-src *; img-src * data:; script-src 'self' cdn.bizible.com kit.fontawesome.com; style-src 'self' 'unsafe-inline' https://404-tpa-276.mktoweb.com/ https://*.qualified.com; font-src 'self' kit.fontawesome.com ka-p.fontawesome.com https://fast.wistia.net/ data:; form-action 'self'; object-src 'none'; media-src 'self' blob: mediastream: https://*.qualified.com; frame-src https://www.googletagmanager.com https://td.doubleclick.net/ https://gtm.mycase.com/ https://insight.adsrvr.org/ https://match.adsrvr.org/ https://404-tpa-276.mktoweb.com/ https://*.qualified.com; child-src https://*.qualified.com; frame-ancestors demo.affinipay.com; upgrade-insecure-requests; block-all-mixed-content 1 script-src 'self' 'unsafe-inline' 'unsafe-eval' *.drmartens.com *.adyen.com *.google.com *.onetrust.com *.monetate.net js-agent.newrelic.com *.cloudflare.com static.cloudflareinsights.com *.paypal.com *.klaviyo.com js.afterpay.com cdn.attraqt.io *.forter.com dlthst9q2beh8.cloudfront.net d2nww8zpyj5pk0.cloudfront.net d2w2nqfk3z9hdt.cloudfront.net *.global-e.com www.googletagmanager.com www.google-analytics.com x.klarnacdn.net js.klarna.com assets.ntcacdn.net cdn-widgetsrepository.yotpo.com staticw2.yotpo.com www.recaptcha.net maps.googleapis.com www.googleadservices.com googleads.g.doubleclick.net pagead2.googlesyndication.com ad.doubleclick.net www.gstatic.com connect.facebook.net connect.facebook.net static.srcspot.com analytics.tiktok.com cdn.userway.org bat.bing.com *.attn.tv c.amazon-adsystem.com photorankstatics-a.akamaihd.net widgets.olapic-cdn.com s.pinimg.com ct.pinterest.com *.contentsquare.net tr.snapchat.com sc-static.net *.upsellit.com tag.rmp.rakuten.com www.redditstatic.com api.myunidays.com cdn.unidays.world rum-static.pingdom.net *.storystream.ai ucarecdn.com; worker-src 'self'; report-uri /cdn-cgi/script_monitor/report?m=cmb4UDfJkHsewvr74_vAhOzF3xT6mXKZ1phvJ1aeYwE-1770430777.0703137-1.0.1.1-s0RjJAgHpHFMb4AFricsSH_7dPLBvVXUI8akS8J73uxdLH_PSodflgmT8kolHGpj2j04ojGLKEf.MTGgPbHSke7nHpuhCCBgLXToAD8aQ4nsG8Vjohc4xmK724EUKLNQMqzuiIVjFKhhhpynfs7GIDlneCEcHfnA_ooTczXeshwdWZRdlgbdiTIro3xaFNMqEWbIBafC7_6MnpjBz8c4Qw; report-to cf-wrvrsuxomuccyjbv 1 object-src 'none';base-uri 'self';script-src 'nonce-meGjCwsaGNVqvLzdc_jfcA' 'strict-dynamic' 'report-sample' 'unsafe-eval' 'unsafe-inline' https: http:;report-uri https://csp.withgoogle.com/csp/gws/other-hp 1 script-src 'report-sample' 'nonce-Nwe58BgtAYxG726wsJForA' 'unsafe-inline' 'unsafe-eval';object-src 'none';base-uri 'self';worker-src 'self';report-uri /us/_/BgcMiscSites/cspreport 1 font-src *.fontawesome.com *.cloudflare.com *.twitter.com *.gstatic.com *.typekit.net *.twimg.com *.trustedshops.com *.googleapis.com *.google.com *.youtube.com maps.googleapis.com *.seeedstudio.com static-cdn.seeedstudio.com media-cdn.seeedstudio.com relstatic-cdn.seeedstudio.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com *.twitter.com *.google.com *.youtube.com maps.googleapis.com googleads.g.doubleclick.net *.seeedstudio.com stats.g.doubleclick.net *.facebook.com disqus.com *.disqus.com *.taboola.com seeedstudio.us11.list-manage.com static-cdn.seeedstudio.com relstatic-cdn.seeedstudio.com *.sandbox.braintree-api.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.meetanshi.com googleads.g.doubleclick.net *.seeedstudio.com stats.g.doubleclick.net *.facebook.com disqus.com *.disqus.com *.taboola.com https://bid.g.doubleclick.net seeedstudio.us11.list-manage.com *.sandbox.braintree-api.com *.paypal.com *.certcapture.com; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net https://www.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.google.com *.google.com/ *.meetanshi.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com *.twitter.com *.google.com maps.googleapis.com *.facebook.com disqus.com *.disqus.com https://bid.g.doubleclick.net googleads.g.doubleclick.net stats.g.doubleclick.net *.taboola.com seeedstudio.us11.list-manage.com *.seeedstudio.com static-cdn.seeedstudio.com relstatic-cdn.seeedstudio.com *.sandbox.braintree-api.com *.weltpixel.com *.certcapture.com *.oscato.com; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://www.magezon.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com *.meetanshi.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.seeedstudio.com *.klarna.com *.googleadservices.com *.google-analytics.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.google.com maps.googleapis.com *.google.com.tw bat.bing.com *.facebook.com *.linkedin.com disqus.com *.disqus.com *.amazonaws.com *.taboola.com *.scorecardresearch.com *.viglink.com p.adsymptotic.com static-cdn.seeedstudio.com media-cdn.seeedstudio.com relstatic-cdn.seeedstudio.com static.cloudflareinsights.com *.gstatic.com *.certcapture.com https://hnd.stats.paypal.com *.oscato.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.google.com/recaptcha/ www.gstatic.com/recaptcha/ chimpstatic.com downloads.mailchimp.com *.list-manage.com *.avada.io *.google.com/ *.meetanshi.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com *.cloudflare.com *.twitter.com *.google-analytics.com *.twimg.com *.gstatic.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.google.com maps.googleapis.com bazaar-upgrade.seeed.local bat.bing.com connect.facebook.net snap.licdn.com stats.g.doubleclick.net disqus.com *.disqus.com *.disquscdn.com seeedsite.disqus.com *.taboola.com *.scorecardresearch.com *.seeedstudio.com static-cdn.seeedstudio.com media-cdn.seeedstudio.com relstatic-cdn.seeedstudio.com retcode.alicdn.com *.sandbox.braintree-api.com static.cloudflareinsights.com https://www.googletagmanager.com tagmanager.google.com *.certcapture.com https://assets.optile.net *.oscato.com utt.impactcdn.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com downloads.mailchimp.com *.fontawesome.com unsafe-inline *.seeedstudio.com *.googleapis.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.google.com *.youtube.com maps.googleapis.com static-cdn.seeedstudio.com media-cdn.seeedstudio.com relstatic-cdn.seeedstudio.com nwzimg.wezhan.net *.sandbox.braintree-api.com *.paypal.com tagmanager.google.com *.certcapture.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://get.geojs.io *.avada.io *.meetanshi.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.seeedstudio.com *.twitter.com *.twimg.com *.google.com *.youtube.com maps.googleapis.com googleads.g.doubleclick.net stats.g.doubleclick.net *.facebook.com disqus.com *.disqus.com https://bid.g.doubleclick.net *.taboola.com static-cdn.seeedstudio.com media-cdn.seeedstudio.com relstatic-cdn.seeedstudio.com retcode.alicdn.com arms-retcode.aliyuncs.com/ *.sandbox.braintree-api.com static.cloudflareinsights.com mc.yandex.ru https://www.google-analytics.com *.certcapture.com *.oscato.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com *.certcapture.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 frame-ancestors 'self'; report-uri https://www.adelaidenow.com.au/csp-reports 1 default-src https: data: blob: wss: 'unsafe-inline' 'unsafe-eval'; frame-src 'self' https://pp.ephapay.net/ https://pp.eshapay.net/ https://scripts.agilone.com/ https://widget.trustpilot.com/ https://edigitalsurvey.com/ https://static.addtoany.com/ https://c.paypal.com/ https://www.paypal.com https://www.paypalobjects.com/ https://www.sandbox.paypal.com/ https://www.zenaps.com/ https://www.youtube.com/ https://*.doubleclick.net/ https://gum.criteo.com/ https://www.facebook.com/ https://*.hotjar.com/ https://s.salecycle.com https://www.googletagmanager.com/ https://www.google.com https://*.customizer.cadesignform.dk/ https://static.criteo.net/ https://www.youtube-nocookie.com/ https://d16fk4ms6rqz1v.cloudfront.net/ https://*.arcot.com/ https://www.securesuite.co.uk/ https://www.clicksafe.lloydstsb.com/ https://secure.barclaycard.co.uk https://*.photorank.me/ https://pay.google.com/ https://js.playground.klarna.com/ https://js.klarna.com/ https://placement-api-sandbox.clearpay.co.uk/ https://placement-api.clearpay.co.uk/ https://portal.sandbox.clearpay.co.uk/ https://portal.clearpay.co.uk/; report-uri https://csp-violations.external.wickes.co.uk 1 default-src 'self'; frame-src 'self' https://replicate-search-prototype-production.replicate.workers.dev https://www.googletagmanager.com https://jobs.ashbyhq.com/replicate/; worker-src https://static.replicateassets.com; connect-src 'self' https://api.replicate.com https://stream.replicate.com https://replicate.delivery https://*.replicate.delivery https://api.us.svix.com https://*.sentry.io https://*.usepylon.com https://*.posthog.com https://pylon-avatars.s3.us-west-1.amazonaws.com https://d3vl36l12sfx26.cloudfront.net https://og.replicateassets.com https://static.replicateassets.com https://*.pusher.com https://www.googletagmanager.com https://*.googletagmanager.com https://*.google-analytics.com https://*.analytics.google.com https://www.replicatestatus.com https://replicate-search-prototype-production.replicate.workers.dev; font-src 'self' data: https://*.usepylon.com https://*.posthog.com https://pylon-avatars.s3.us-west-1.amazonaws.com https://d31rfu1d3w8e4q.cloudfront.net https://d3vl36l12sfx26.cloudfront.net https://fonts.replicateassets.com https://*.pusher.com https://fonts.gstatic.com https://replicate-search-prototype-production.replicate.workers.dev; img-src 'self' blob: data: https://replicate.delivery https://*.replicate.delivery https://og.replicateassets.com https://static.replicateassets.com https://d31rfu1d3w8e4q.cloudfront.net https://d3vl36l12sfx26.cloudfront.net https://*.githubusercontent.com https://github.com https://www.googletagmanager.com https://ssl.gstatic.com https://www.gstatic.com https://*.google-analytics.com https://*.googletagmanager.com https://replicate-search-prototype-production.replicate.workers.dev https://replicateassets.com/cdn-cgi/image/; media-src 'self' https://replicate.delivery https://*.replicate.delivery https://static.replicateassets.com https://d31rfu1d3w8e4q.cloudfront.net https://d3vl36l12sfx26.cloudfront.net https://*.sentry.io https://replicate-search-prototype-production.replicate.workers.dev https://replicateassets.com/cdn-cgi/media/; script-src 'report-sample' 'self' 'nonce-Y2FiOGNiODUtNzJjOS00NTlkLTkxY2ItMTk1OGI3NTQ1NDFh' https://*.usepylon.com https://*.posthog.com https://pylon-avatars.s3.us-west-1.amazonaws.com https://d31rfu1d3w8e4q.cloudfront.net https://d3vl36l12sfx26.cloudfront.net https://static.replicateassets.com https://*.pusher.com https://www.googletagmanager.com https://tagmanager.google.com https://*.googletagmanager.com https://replicate-search-prototype-production.replicate.workers.dev https://jobs.ashbyhq.com/replicate/embed https://challenges.cloudflare.com; style-src 'self' https://*.usepylon.com https://*.posthog.com https://pylon-avatars.s3.us-west-1.amazonaws.com https://d31rfu1d3w8e4q.cloudfront.net https://d3vl36l12sfx26.cloudfront.net https://static.replicateassets.com https://*.pusher.com https://googletagmanager.com https://tagmanager.google.com https://fonts.googleapis.com https://replicate-search-prototype-production.replicate.workers.dev; frame-ancestors 'self'; report-to csp-endpoint; 1 img-src slack-imgs-mil-dev.com https://stats.g.doubleclick.net https://img.youtube.com https://payments.salesforce.com/icons/ https://login.salesforce.com/icons/ https://xeago.maps.arcgis.com *.slack-edge-gov.com https://assets.adobedtm.com *.cloudinary.com https://www.google.com http://adobedtm.com *.amazonaws.com https://experience.arcgis.com https://20844768p.rfihub.com http://googleadservices.com https://region1.analytics.google.com https://20844767p.rfihub.com https://20844766p.rfihub.com https://20844765p.rfihub.com https://data.instrumentation.getconga.com https://ssl.gstatic.com https://xcelnew--c.vf.force.com https://xcel.allegiancetech.com *.allegiancetech.com https://www.paypal.com https://xcelnew.my.salesforce.com slack-imgs-gov.com https://d046-124-us-ashburn-1.api.decibel.com *.salesforce-experience.com https://fonts.gstatic.com https://*.my.xcelenergy.com https://*.reddit.com slack-imgs-gov-dev.com *.slack-edge.com https://cdn.content.aws-prod1-useast1.aws.sfdc.cl/icons/ slack-mil-dev.com https://beacon.lynx.cognitivlabs.com https://tagmanager.google.com https://www.gstatic.com/recaptcha/ https://arttrk.com https://tags.tiqcdn.com https://a.rfihub.com https://www.google.com/recaptcha/ *.slack-edge.mil https://www.sandbox.paypal.com https://www.googletagmanager.com storage.cloud.kargo.com https://www.google-analytics.com *.salesforce.com https://*.adyen.com data: https://xcelnew.file.force.com *.force.com https://content.instrumentation.getconga.com https://c.amazon-adsystem.com https://optimize.google.com 'self' https://opengraph.io https://www.facebook.com https://ads.undertone.com https://xcelnew--xeteam3.sandbox.my.site.com https://www.gstatic.com http://api.ipstack.com https://www.google.ca https://xcelnew.my.site.com https://composer.congamerge.com *.my-salesforce.com https://idsync.rlcdn.com https://b.videoamp.com *.medallia.com https://www.googleoptimize.com https://analytics.google.com https://events.api.boomtrain.com blob: https://usa494.sfdc-lywfpd.salesforce.com/icons/ https://accounts.google.com https://insight.adsrvr.org *.kargo.com slack-imgs.com slack-gov-dev.com *.sfdcstatic.com *.twimg.com http://doubleclick.net trkn.us https://xcelnew.my.salesforce-scrt.com *.slack.com https://pdx-col.eum-appdynamics.com https://people.api.boomtrain.com *.slack-imgs.com https://i.ytimg.com https://cdn.content.aws-dev2-uswest2.aws.sfdc.cl/icons/ https://cdn.appdynamics.com *.kampyle.com https://twin-iq.kickfire.com http://kickfire.com https://fonts.googleapis.com https://ad.doubleclick.net https://td.doubleclick.net https://www.google.co.in https://www.google.com.ph https://i.vimeocdn.com https://*.my.salesforce-scrt.com https://www.outagemap-xcelenergy.com slack-imgs.mil https://*.my.site.com; report-to sfdc-csp-ep; report-uri https://xcelnew.lightning.force.com/_/ContentDomainCSPNoAuth?tenantId=00D1U0000011ttV&networkId=0DM2R000000CbkT&type=communities 1 base-uri 'self'; default-src 'self'; img-src 'self' data: https: img.part-kom.ru mc.yandex.ru; font-src 'self' data: https:; style-src 'self' 'unsafe-inline' https:; script-src 'self' 'unsafe-inline' 'unsafe-eval' http: mc.yandex.ru yastatic.net; connect-src 'self' https: wss: mc.yandex.ru livechatv2.chat2desk.com; media-src 'self' https: livechatv2.chat2desk.com; frame-src 'self' https: wss: b2b.part-kom.ru mc.yandex.ru smartcaptcha.yandexcloud.net; report-uri https://part-kom.ru/-/reporting-api/; report-to default; 1 script-src 'nonce-zpGiObRVvqjQ0ZbgmXuSYQ==' 'strict-dynamic' 'unsafe-eval' 'unsafe-inline' https: 'report-sample'; base-uri 'none'; report-uri https://events.mercadolibre.com/csp/reports?identifier=w1qeU4XKVwGbQGBuEKyE3KhFBIpr5IZSIaRiTowMc8UG7kU18vRsmBTEKL2krAj23LIS&policy_id=26548&user_id=&request_id=8e4af038-63a4-432f-bb22-9ef096ae167d; report-to csp-endpoint-wqeuxkvwgbqgbuekyekhfbiprizsiaritowmcugkuvrsmbteklkrajlis; object-src https://http2.mlstatic.com/ https://mlstaticquic-a.akamaihd.net/; frame-ancestors 'self' https://*.mercadolibre.cl:* https://*.mercadolibre.com:* https://*.mercadolibre.com.ve:* https://*.mercadolibre.com.ar:* https://*.mercadolivre.com.br:* https://*.mercadolibre.com.co:* https://*.mercadolibre.com.ec:* https://*.mercadolibre.com.mx:* https://*.mercadolibre.com.pe:* https://*.mercadolibre.com.uy:* https://*.mercadopago.cl:* https://*.mercadopago.com.ar:* https://*.mercadopago.com.br:* https://*.mercadopago.com.co:* https://*.mercadopago.com.mx:* https://*.mercadopago.com.pe:* https://*.mercadopago.com.uy:* https://*.mercadopago.com.ve:* https://*.mercadopago.com:* https://*.adminml.com:* https://*.mercadolibre.co.cr:* https://*.mercadolibre.com.pa:* https://*.mercadolibre.com.do:* https://*.mercadolibre.com.bo:* https://*.mercadolibre.com.py:* https://*.mercadolibre.com.gt:* https://*.mercadolibre.com.hn:* https://*.mercadolibre.com.ni:* https://*.mercadolibre.com.sv:* https://*.mercadopago.com.ec:* https://*.portalinmobiliario.com:* https://*.mercadolivre.com:* 1 default-src data: 'unsafe-inline' 'unsafe-eval' https: blob: http://*.files.wordpress.com wss://www.blogher.com; report-uri https://pmcuri.report-uri.com/r/d/csp/reportOnly 1 style-src 'self' 'unsafe-inline' data: *.ebay.com *.ebay.com.sg *.ebay.sg *.ebaystatic.com *.ebaystatic.com.sg *.ebaystatic.sg *.ebaystatic.cn *.gstatic.com *.fontawesome.com blob: *.googleapis.com; connect-src 'self' *.ebay.com *.ebay.com.sg *.ebay.sg *.ebaystatic.com *.ebaystatic.com.sg *.ebaystatic.sg data: *.google-analytics.com *.doubleclick.net *.avalon.perfdrive.com *.ebayimg.com *.ucweb.com *.akamaihd.net *.ucads.ucweb.com *.analytics.google.com *.g.doubleclick.net *.googletagmanager.com *.pinterest.com *.snapchat.com *.criteo.com *.facebook.com *.googleapis.com *.googleadservices.com blob: analytics.google.com *.us.shoplive.cloud www.facebook.com *.bing.com www.googletagmanager.com google.com *.google.com *.graphitevault.com *.amplitude.com wss://127.0.0.1:* www.redditstatic.com *.reddit.com *.quantummetric.com; script-src 'self' 'unsafe-eval' 'unsafe-inline' https://* blob: data:; frame-ancestors 'self' *.ebay.com *.ebay.com.sg *.ebay.sg *.ebaystatic.com *.ebaystatic.com.sg *.ebaystatic.sg; img-src 'self' data: blob: https://*; default-src 'self' blob: data: wss: mediastream: https://*; report-uri https://monitor.ebay.com/csp-report/discoveryplatformweb/HomePage?id=2939504940913871808&rid=t6gludlscuzujfwciunrce0%3F%3Ccjvehu%60t~sigsejtjt%60d4.32e52e%3Ea0%2Bsfvu67%3D%2Bj%60awp-19c3614eb6a-0x1802#pd 1 object-src 'none';base-uri 'self';script-src 'nonce-59xMwGK0fryfj68e3zf94A' 'strict-dynamic' 'report-sample' 'unsafe-eval' 'unsafe-inline' https: http:;report-uri https://csp.withgoogle.com/csp/gws/other-hp 1 default-src data: 'unsafe-inline' 'unsafe-eval' https: blob: http://*.files.wordpress.com wss://www.vibe.com; report-uri https://pmcuri.report-uri.com/r/d/csp/reportOnly 1 base-uri 'none'; object-src 'none'; script-src 'unsafe-inline' 'unsafe-eval' 'strict-dynamic' https: http: 'nonce-8gjHAx74CMaRMwRW+Ouq+A==' 1 default-src 'self' https://*.firstcitizens.com; script-src 'self' https://*.firstcitizens.com https://cdn.cookielaw.org https://assets.adobedtm.com https://acrobatservices.adobe.com https://cds-sdkcfg.onlineaccess1.com https://www.googletagmanager.com https://s.go-mpulse.net https://connect.facebook.net https://bat.bing.com https://snap.licdn.com https://js-cdn.dynatrace.com https://googleads.g.doubleclick.net https://td.doubleclick.net https://www.googleadservices.com https://px.ads.linkedin.com https://edge.adobedc.net https://www.facebook.com https://px4.ads.linkedin.com https://siteimproveanalytics.com https://www.clarity.ms https://www.google.com https://google.com https://2884.global.siteimproveanalytics.io https://c.go-mpulse.net https://zndhwk2nlgcbvdel3-firstcitizensbank.siteintercept.qualtrics.com https://t.contentsquare.net https://munchkin.marketo.net https://siteintercept.qualtrics.com https://296-cpx-295.mktoresp.com https://894-itd-344.mktoresp.com https://284-lbb-572.mktoresp.com https://151-fhs-046.mktoresp.com https://412-tmw-562.mktoresp.com https://u.clarity.ms https://c.contentsquare.net https://173bf10e.akstat.io https://k-aus1.contentsquare.net https://trial-eum-clientnsv4-s.akamaihd.net https://eyaqbbekafz5ajqacqnryaaabbtmzouy-p2jke9-59ac193c4-clienttons-s.akamaihd.net https://daaisiixzsmj6zwmxkma-p2jke9-1aa48d9c7-clientnsv4-s.akamaihd.net https://assets.sitescdn.net https://answers.yext-pixel.com https://analytics.google.com https://embed-ssl.wistia.com https://pipedream.wistia.com https://js.sentry-cdn.com https://distillery.wistia.com https://embed-cloudfront.wistia.com https://srm.bf.contentsquare.net https://www.gstatic.com https://app.fintelconnect.com https://browser.sentry-cdn.com https://*.cit.com https://answers-embed.firstcitizens.com.pagescdn.com https://info.onewestbank.com https://rum.hlx.page https://script.crazyegg.com https://js.adsrvr.org https://bat.bing.com https://scripts.clarity.ms https://dvract3a1itr1.cloudfront.net https://c.amazon-adsystem.com https://s.amazon-adsystem.com https://ad.doubleclick.net; connect-src 'self' https://*.firstcitizens.com https://cdn.cookielaw.org https://analytics.google.com https://answers.yext-pixel.com https://ad.doubleclick.net https://stats.g.doubleclick.net https://adobedc.demdex.net https://viewlicense.adobe.io https://www.google.com https://www.google-analytics.com https://dpm.demdex.net https://edge.adobedc.net https://px.ads.linkedin.com https://siteintercept.qualtrics.com https://cds-sdkcfg.onlineaccess1.com https://prod-cdn.us.yextapis.com https://ipapi.co https://api.openweathermap.org https://296-cpx-295.mktoutil.com https://script.crazyegg.com https://tracking.crazyegg.com https://pagestates-tracking.crazyegg.com https://assets-tracking.crazyegg.com https://insight.adsrvr.org https://dayintegrationintern.tt.omtrdc.net https://www.googleadservices.com https://business.linkedin.com https://openknowledge.worldbank.org https://acrobatservices.adobe.com https://assets.sitescdn.net https://bat.bing.com https://scripts.clarity.ms https://smetrics.firstcitizens.com https://browser.sentry-cdn.com https://mpc-prod-2-1053047382554.us-central1.run.app https://demo-1.conversionsapigateway.com https://graph.facebook.com https://c.amazon-adsystem.com https://s.amazon-adsystem.com https://fls.doubleclick.net; worker-src 'self'; style-src 'self' https://*.firstcitizens.com https://fonts.googleapis.com https://assets.sitescdn.net; style-src-elem 'self' https://*.firstcitizens.com https://assets.sitescdn.net https://*.cit.com https://info.onewestbank.com https://fonts.googleapis.com https://www.googletagmanager.com; img-src 'self' https://*.firstcitizens.com https://cdn.cookielaw.org https://2884.global.siteimproveanalytics.io px.ads.linkedin.com https://px4.ads.linkedin.com https://cm.everesttech.net https://dpm.demdex.net https://www.linkedin.com https://www.googletagmanager.com https://www.facebook.com https://googleads.g.doubleclick.net https://*.cit.com https://www.google.com https://google.com https://info.onewestbank.com https://siteintercept.qualtrics.com https://fonts.gstatic.com https://ad.doubleclick.net https://insight.adsrvr.org https://ib.adnxs.com https://cm.g.doubleclick.net https://match.adsrvr.org https://pixel.rubiconproject.com https://www.googleadservices.com https://c.amazon-adsystem.com https://s.amazon-adsystem.com https://fls.doubleclick.net; frame-src 'self' https://*.firstcitizens.com https://acrobatservices.adobe.com https://td.doubleclick.net https://firstcitizens.demdex.net https://www.google.com https://www.citrail.com https://answers-embed.firstcitizens.com.pagescdn.com https://*.cit.com https://info.onewestbank.com https://www.googletagmanager.com https://insight.adsrvr.org https://privacyportaluat.onetrust.com https://privacyportal.onetrust.com https://match.adsrvr.org https://fintactix.com https://14741597.fls.doubleclick.net https://fast.wistia.net https://15758689.fls.doubleclick.net https://ad.doubleclick.net; frame-ancestors 'self' https://www.google.com https://9808-sbx.btbanking.com https://*.firstcitizens.com https://*.fcbint.net; media-src 'self'; font-src 'self'; 1 default-src 'self' *.ctfassets.net *.trackjs.com *.demdex.net; font-src 'self' *.gstatic.com; img-src 'self' *.ctfassets.net *.trackjs.com costalimited.d3.sc.omtrdc.net *.gstatic.com data: *.onetrust.com cm.everesttech.net *.googleapis.com; connect-src 'self' *.go-mpulse.net cdn-ukwest.onetrust.com trial-eum-clientnsv4-s.akamaihd.net trial-eum-clienttons-s.akamaihd.net *.akstat.io *.demdex.net costalimited.d3.sc.omtrdc.net *.onetrust.io *.trackjs.com maps.googleapis.com; script-src 'self'; script-src-elem 'self' 'unsafe-inline' assets.adobedtm.com *.go-mpulse.net cdn-ukwest.onetrust.com maps.googleapis.com fonts.googleapis.com; style-src-attr 'self' 'unsafe-inline'; style-src 'self'; style-src-elem 'self' 'unsafe-inline' fonts.googleapis.com; script-src-attr 'self' 'unsafe-inline'; frame-ancestors 'self'; report-to https://costa.report-uri.com/r/t/csp/reportOnly 1 default-src 'self' image.spreadshirtmedia.com ; script-src 'self' 'unsafe-inline' 'unsafe-eval' data: https: *.go-mpulse.net apis.google.com assets.adobedtm.com *.cloudfront.net nxtck.com ssl.gstatic.com ws.sessioncam.com *.spreadshirt.net *.spreadshirt.com www.google-analytics.com www.google.com googleads.g.doubleclick.net connect.facebook.net www.googleadservices.com adtm.spreadshirts.net *.spreadshirt.com ; img-src 'self' data: https: image.spreadshirtmedia.net image.spreadshirtmedia.net *.gstatic.com rtb-csync.smartadserver.com pixel.rubiconproject.com pixel.advertising.com dsum-sec.casalemedia.com cotads.adscale.de www.google-analytics.com eu-u.openx.net ih.adscale.de *.akstat.io www.facebook.com dsum-sec.casalemedia.com ad.yieldlab.net secure.adnxs.com mapping.nxtck.com stats.g.doubleclick.net www.google.com www.google.de cm.g.doubleclick.net ads.yahoo.com sync.ligadx.com eb2.3lift.com s.sspqns.com x.bidswitch.net image2.pubmatic.com sync.outbrain.com nxtck.com *.google-analytics.com *.analytics.google.com *.zdassets.com sanalytics.spreadshirt.com *.spreadshirt.com ; connect-src 'self' https: *.spreadshirt.net *.spreadshirt.com www.google-analytics.com www.google.com *.go-mpulse.net *.akstat.io/ *.google-analytics.com *.analytics.google.com wss://*.zendesk.com *.spreadshirt.com ; font-src 'self' https: data: *.spreadshirt.com ; style-src 'self' data: 'unsafe-inline' https: *.spreadshirt.com ; object-src 'none' ; media-src image.spreadshirtmedia.com ; frame-src 'self' https: www.google.com accounts.google.com *.spreadshirt.com ; report-uri https://csp.spreadshirts.net/csp/reportOnly ; 1 default-src 'self' https:; script-src 'self' https: 'unsafe-inline' 'unsafe-eval'; style-src 'self' https: 'unsafe-inline'; img-src 'self' https: data: blob:; media-src 'self' https: data: blob:; object-src 'none'; frame-ancestors 'self' https://experience.adobe.com https://infopoint.audi.it; connect-src 'self' https: wss://e0k754.acquire.io; base-uri 'self'; font-src 'self' https: data:; worker-src 'self' blob:; report-uri https://www.audiusa.com/api/csp-report; report-to csp-endpoint 1 object-src 'none';base-uri 'self';script-src 'nonce-KEieL4HVBIvnODPAONL77Q' 'strict-dynamic' 'report-sample' 'unsafe-eval' 'unsafe-inline' https: http:;report-uri https://csp.withgoogle.com/csp/gws/other-hp 1 object-src 'none';base-uri 'self';script-src 'nonce-QyBTQkXovwl57Py4yu3Hng' 'strict-dynamic' 'report-sample' 'unsafe-eval' 'unsafe-inline' https: http:;report-uri https://csp.withgoogle.com/csp/gws/other-hp 1 font-src 'self' www.firefox.com; object-src 'none'; connect-src 'self' basket.mozilla.org cdn.transcend.io https://accounts.firefox.com/ https://basket.mozilla.org o1069899.ingest.sentry.io o1069899.ingest.us.sentry.io o1069899.sentry.io region1.google-analytics.com telemetry.transcend.io telemetry.us.transcend.io transcend-cdn.com www.firefox.com www.google-analytics.com www.googletagmanager.com; form-action 'self' https://accounts.firefox.com/ https://basket.mozilla.org; frame-ancestors 'none'; frame-src 'self' accounts.firefox.com www.google-analytics.com www.googletagmanager.com www.youtube-nocookie.com www.youtube.com; default-src 'self' www.firefox.com; upgrade-insecure-requests; style-src 'self' 'unsafe-inline' cdn.transcend.io transcend-cdn.com www.firefox.com; script-src 'self' 'unsafe-eval' 'unsafe-inline' cdn.transcend.io s.ytimg.com tagmanager.google.com transcend-cdn.com www.firefox.com www.google-analytics.com www.googletagmanager.com www.youtube.com; media-src 'self' assets.mozilla.net videos.cdn.mozilla.net www.firefox.com www.mozilla.org; img-src 'self' data: www.firefox.com www.google-analytics.com www.googletagmanager.com www.mozilla.org; base-uri 'none' 1 report-uri https://csp-report.browser-intake-datadoghq.com/api/v2/logs?dd-api-key=pubff54dddb981c8cd140e740408494c84d&dd-evp-origin=content-security-policy&ddsource=csp-report&ddtags=env%3Aproduction 1 default-src 'self';script-src 'self' 'unsafe-inline' 'unsafe-eval' https://cdn-web.zinio.com https://js-agent.newrelic.com https://*.nr-data.net https://www.googleadservices.com https://www.google.com https://www.googleadservices.com https://googleads.g.doubleclick.net https://*.paypal.com https://www.paypalobjects.com https://*.braintreegateway.com https://*.cardinalcommerce.com https://www.googletagmanager.com https://www.google-analytics.com https://zinio-sjc.gravityrd-services.com https://*.zopim.com https://static.zdassets.com https://d1fc8wv8zag5ca.cloudfront.net/2.10.2/sp.js https://cdn.jsdelivr.net https://recaptcha.net https://www.gstatic.com https://connect.facebook.net https://www.facebook.com https://sleeknotecustomerscripts.sleeknote.com https://sleeknotestaticcontent.sleeknote.com https://app.vwo.com;style-src 'self' 'unsafe-inline' https://*.audiencemedia.com data: https://app.vwo.com;img-src 'self' data: blob: https://*.ziniopro.com https://*.audiencemedia.com https://googleads.g.doubleclick.net https://www.google.com https://*.paypal.com https://*.braintreegateway.com https://v2assets.zopim.io https://discover.zinio.com https://sleeknotestaticcontent.sleeknote.com https://analytics.sleeknote.com https://www.google-analytics.com https://www.facebook.com https://www.googletagmanager.com https://dev.visualwebsiteoptimizer.com;media-src 'self' https://static.zdassets.com;connect-src 'self' https://*.audiencemedia.com https://*.ziniopro.com https://*.nr-data.net https://googleads.g.doubleclick.net https://adservice.google.com https://cdn.jsdelivr.net https://*.braintree-api.com https://*.braintreegateway.com https://*.cardinalcommerce.com https://www.paypal.com https://ekr.zdassets.com https://zinio.zendesk.com wss://widget-mediator.zopim.com wss://zinio.zendesk.com https://*.google-analytics.com https://*.analytics.google.com https://analytics.google.com https://collector.datacloud.zinio.com https://www.facebook.com https://cdnjs.cloudflare.com https://fonts.googleapis.com https://images.sleeknote.com https://sleeknotestaticcontent.sleeknote.com https://sleeknotecustomerscripts.sleeknote.com https://dev.visualwebsiteoptimizer.com https://sdk.iad-07.braze.com;font-src 'self' https://*.audiencemedia.com https://fonts.gstatic.com https://sleeknotestaticcontent.sleeknote.com;frame-src 'self' https://td.doubleclick.net https://*.paypal.com https://*.braintreegateway.com https://recaptcha.net https://www.facebook.com https://web.facebook.com https://*.sleeknote.com https://app.vwo.com;frame-ancestors none 1 default-src data: 'unsafe-inline' 'unsafe-eval' https: blob: http://*.files.wordpress.com wss://www.sportico.com; report-uri https://pmcuri.report-uri.com/r/d/csp/reportOnly 1 object-src 'none'; base-uri 'self'; script-src 'self' 'nonce-vqrGbcAOSezJrCbLPGX4LA' 'unsafe-inline' 'unsafe-eval' https://*.msauth.net https://*.msftauth.net https://*.msftauthimages.net https://*.msauthimages.net https://*.msidentity.com https://*.microsoftonline-p.com https://*.microsoftazuread-sso.com https://*.azureedge.net https://*.outlook.com https://*.office.com https://*.office365.com https://*.microsoft.com https://*.bing.com 'report-sample'; report-uri https://csp.microsoft.com/report/ESTS-UX-All 1 default-src 'self' media1.jpc.de www.jpc.de; frame-ancestors 'none'; object-src 'none'; base-uri 'self'; script-src 'self' media1.jpc.de www.jpc.de 'nonce-bEc7TOTOyEdounAicVJaGMgLU5ypXn5bpEWkLrfRinol6ZLiyrq5kREwPIVBejPilxNFlsecA4ibE7t/WEfYGw==' 'report-sample'; style-src 'self' media1.jpc.de www.jpc.de 'report-sample' 'unsafe-inline'; font-src 'self' media1.jpc.de www.jpc.de; img-src 'self' media1.jpc.de www.jpc.de data:; connect-src 'self' media1.jpc.de www.jpc.de https://use.jpc.de; report-uri /csp/; report-to csp-endpoint 1 object-src 'none'; script-src 'self' 'unsafe-inline' connect.facebook.net platform.linkedin.com platform.twitter.com cdn.matomo.cloud cdn.gtranslate.net translate.google.com translate.googleapis.com https://static.hotjar.com https://script.hotjar.com cdn.rawgit.com cdnjs.cloudflare.com https://cdn.ckeditor.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com https://www.google.com; style-src 'self' 'unsafe-inline' cdnjs.cloudflare.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com 1 default-src 'self'; script-src 'self' 'unsafe-inline' blob: https://cdn.prod.website-files.com https://www.googletagmanager.com https://widget.intercom.io https://smartpass.referralrock.com https://js.navattic.com https://js.hs-scripts.com https://global.localizecdn.com https://js.intercomcdn.com https://js.refiner.io https://embed.lu.ma https://app.posthog.com https://static.cloudflareinsights.com https://smartpass.instatus.com; style-src 'self' https://cdn.prod.website-files.com https://embed.lu.ma https://fonts.googleapis.com https://rsms.me/inter/ 'unsafe-inline'; font-src 'self' https://rsms.me/inter/font-files/ https://fonts.gstatic.com; img-src 'self' data: https://smartpass.app https://*.smartpass.app https://cdn.prod.website-files.com https://storage.googleapis.com/sp-img-cdn/ https://global.localizecdn.com https://www.googletagmanager.com https://widget.intercom.io https://smartpass.referralrock.com https://js.navattic.com https://js.hs-scripts.com; connect-src 'self' https://smartpass.app wss://smartpass.app https://global.localizecdn.com https://firebaseinstallations.googleapis.com https://fcmregistrations.googleapis.com https://*.ingest.sentry.io https://cdn.prod.website-files.com https://www.googletagmanager.com https://*.intercom.io wss://*.intercom.io https://smartpass.referralrock.com https://js.navattic.com https://js.hs-scripts.com https://*.refiner.io https://api.instatus.com; frame-src 'self' https://js.refiner.io 1 script-src 'self' data: 'unsafe-inline' 'unsafe-hashes' 'unsafe-eval' app.contentsquare.com t.contentsquare.net *.heapanalytics.com *.2mdn.net *.33across.com *.acexchange.co.kr *.ad-generation.jp *.adagio.io *.addthis.com *.addthisedge.com *.adform.com *.adiiix.com *.adingo.jp *.admanmedia.com *.admixer.com *.admixer.net *.adtech.com *.adtiming.com *.advangelists.com *.advertising.com *.adyoulike.com *.amazon-adsystem.com *.amazon.com *.ampproject.org *.amxrtb.com *.aniview.com *.aol.com *.appnexus.com *.aps.amazon.com *.aralego.com *.avantisvideo.com *.axonix.com *.beachfront.com *.behave.com *.betweendigital.com *.bidmachine.io *.bidstreammedia.com *.bidtellect.com *.bing.com *.blis.com *.braintreegateway.com *.brid.tv *.brightcove.com *.brightcove.net *.chocolateplatform.com *.clarity.ms *.cloudflare.com *.cloudfront.net *.consumable.com *.contextweb.com *.conversantmedia.com *.crazyegg.com *.criteo.com *.criteo.net *.districtm.io *.doubleclick.net *.doubleverify.com *.e-planning.net *.e-volution.ai *.emxdgt.com *.engagebdr.com *.eskimi.com *.exponential.com *.facebook.com *.facebook.net *.fastclick.net *.freewheel.tv *.google-analytics.com *.google.ad *.google.ae *.google.al *.google.am *.google.as *.google.at *.google.az *.google.ba *.google.be *.google.bf *.google.bg *.google.bi *.google.bj *.google.bs *.google.bt *.google.by *.google.ca *.google.cat *.google.cd *.google.cf *.google.cg *.google.ch *.google.ci *.google.cl *.google.cm *.google.cn *.google.co.ao *.google.co.bw *.google.co.ck *.google.co.cr *.google.co.id *.google.co.il *.google.co.in *.google.co.jp *.google.co.ke *.google.co.kr *.google.co.ls *.google.co.ma *.google.co.mz *.google.co.nz *.google.co.th *.google.co.tz *.google.co.ug *.google.co.uk *.google.co.uz *.google.co.ve *.google.co.vi *.google.co.za *.google.co.zm *.google.co.zw *.google.com *.google.com.af *.google.com.ag *.google.com.ai *.google.com.ar *.google.com.au *.google.com.bd *.google.com.bh *.google.com.bn *.google.com.bo *.google.com.br *.google.com.bz *.google.com.co *.google.com.cu *.google.com.cy *.google.com.do *.google.com.ec *.google.com.eg *.google.com.et *.google.com.fj *.google.com.gh *.google.com.gi *.google.com.gt *.google.com.hk *.google.com.jm *.google.com.kh *.google.com.kw *.google.com.lb *.google.com.ly *.google.com.mm *.google.com.mt *.google.com.mx *.google.com.my *.google.com.na *.google.com.ng *.google.com.ni *.google.com.np *.google.com.om *.google.com.pa *.google.com.pe *.google.com.pg *.google.com.ph *.google.com.pk *.google.com.pr *.google.com.py *.google.com.qa *.google.com.sa *.google.com.sb *.google.com.sg *.google.com.sl *.google.com.sv *.google.com.tj *.google.com.tr *.google.com.tw *.google.com.ua *.google.com.uy *.google.com.vc *.google.com.vn *.google.cv *.google.cz *.google.de *.google.dj *.google.dk *.google.dm *.google.dz *.google.ee *.google.es *.google.fi *.google.fm *.google.fr *.google.ga *.google.ge *.google.gg *.google.gl *.google.gm *.google.gr *.google.gy *.google.hn *.google.hr *.google.ht *.google.hu *.google.ie *.google.im *.google.iq *.google.is *.google.it *.google.je *.google.jo *.google.kg *.google.ki *.google.kz *.google.la *.google.li *.google.lk *.google.lt *.google.lu *.google.lv *.google.md *.google.me *.google.mg *.google.mk *.google.ml *.google.mn *.google.ms *.google.mu *.google.mv *.google.mw *.google.ne *.google.nl *.google.no *.google.nr *.google.nu *.google.pl *.google.pn *.google.ps *.google.pt *.google.ro *.google.rs *.google.ru *.google.rw *.google.sc *.google.se *.google.sh *.google.si *.google.sk *.google.sm *.google.sn *.google.so *.google.sr *.google.st *.google.td *.google.tg *.google.tl *.google.tm *.google.tn *.google.to *.google.tt *.google.vg *.google.vu *.google.ws *.googleadservices.com *.googleapis.com *.googlesyndication.com *.googletagmanager.com *.googletagservices.com *.gstatic.com *.gumgum.com *.id5-sync.com *.improvedigital.com *.indexexchange.com *.infolinks.com *.inmobi.com *.inskinmedia.com *.instagram.com *.insticator.com *.jquery.com *.kargo.com *.launchdarkly.com *.lemmatechnologies.com *.lijit.com *.lkqd.com *.lkqd.net *.logan.ai *.loopme.com *.marketo.net *.media.net *.mediago.io *.mediatradecraft.com *.moatads.com *.mobfox.com *.mobileadtrading.com *.my.com *.my6sense.com *.narrativ.com *.nativo.com *.newrelic.com *.nr-data.net *.ogury.com *.onetag.com *.openexchangerates.org *.openx.com *.outbrain.com *.playbuzz.com *.pokkt.com *.prodooh.com *.proper.io *.pubmatic.com *.pubnative.net *.px-cdn.net *.quantcount.com *.quantserve.com *.realself.com *.revcontent.com *.rhythmone.com *.richaudience.com *.risecodes.com *.rlcdn.com *.rsdev.co *.rubiconproject.com *.s-onetag.com *.sharethrough.com *.smaato.com *.smartadserver.com *.smartclip.net *.smartyads.com *.snapengage.com *.somoaudience.com *.sonobi.com *.sovrn.com *.speedcurve.com *.spotx.tv *.spotxchange.com *.springserve.com *.ssp.e-volution.ai *.ssp.logan.ai *.stackadapt.com *.synacor.com *.target.my.com *.teads.tv *.telaria.com *.themediagrid.com *.tremorhub.com *.tribalfusion.com *.triplelift.com *.typekit.net *.ucfunnel.com *.undertone.com *.unrulymedia.com *.vdopia.com *.velismedia.com *.verve.com *.video.unrulymedia.com *.vidoomy.com *.yahoo.com *.yieldmo.com *.zencdn.net btloader.com openexchangerates.org ep2.adtrafficquality.google blob:; worker-src 'self' blob:; frame-ancestors *; form-action *; report-uri https://api.realself.com/v1/rs-csp-sc/csp-info; report-to security-report 1 default-src data: blob: https: gap: gap-iab: 'unsafe-inline' 'unsafe-eval'; form-action https:; report-uri https://dailyvoice.report-uri.com/r/d/csp/reportOnly 1 script-src 'report-sample' 'nonce-t0EuumCQn2eGIeg8mt2s2g==' https: 'self' https://*.moneylion.com https://*.moneylion.dev https://www.googletagmanager.com; 1 default-src https: 'unsafe-inline' 'unsafe-eval'; img-src https: 'unsafe-inline' 'unsafe-eval' data: ; report-uri https://booklog.report-uri.io/r/default/csp/reportOnly 1 default-src data: blob:; script-src 'unsafe-inline' 'unsafe-eval' 'self' https://*.vtbbo.ru; style-src data: blob: 'unsafe-inline' https://*; img-src data: blob: https://*; connect-src blob: 'self' https://*.vtbbo.ru wss://*.vtbbo.ru https://*.vtbbo.ru wss://chat7.vtb.ru https://chat7.vtb.ru; object-src blob: 'self' https://*; font-src data: blob: 'self' https://*; worker-src blob: 'self' https://*.vtbbo.ru; media-src data: blob: filesystem: 'self' https://*; manifest-src 'self' 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://cdn.jsdelivr.net https://*.cloudflare.com https://*.googletagmanager.com https://*.google.com https://*.google-analytics.com https://stats.g.doubleclick.net https://connect.facebook.net https://*.mczbf.com https://*.kdukvh.com https://*.emjcd.com https://*.jdoqocy.com https://*.dotomi.com https://*.cj.com https://*.sjwoe.com https://*.clarity.ms https://onelinksmartscript.appsflyer.com https://*.apple-mapkit.com https://embed.reddit.com https://static.zdassets.com https://platform.twitter.com https://www.instagram.com; style-src 'self' 'unsafe-inline' https://cdn.jsdelivr.net https://*.cloudflare.com https://*.googleoptimize.com https://*.googletagmanager.com https://www.gstatic.com https://fonts.googleapis.com; img-src 'self' data: https://cdn.jsdelivr.net https://*.cloudflare.com https://*.googletagmanager.com https://*.google.com https://*.google-analytics.com https://stats.g.doubleclick.net https://storage.googleapis.com https://fonts.gstatic.com https://purecatamphetamine.github.io http://purecatamphetamine.github.io https://www.facebook.com https://connect.facebook.net https://*.clarity.ms https://googleads.g.doubleclick.net https://*.googleusercontent.com https://storage.googleapis.com https://secure.gravatar.com https://*.apple-mapkit.com https://syndication.twitter.com https://s0.wp.com https://*.bing.com; font-src 'self' data: https://cdn.jsdelivr.net https://fonts.gstatic.com https://s0.wp.com https://applepay.cdn-apple.com; worker-src 'self'; frame-src 'self' https://www.youtube.com https://*.googletagmanager.com https://embed.reddit.com https://platform.twitter.com https://www.instagram.com; connect-src 'self' https://cdn.jsdelivr.net https://*.cloudflare.com https://lown4qvbisme2qafgzvjetqzzy0tbyyr.lambda-url.us-west-2.on.aws https://analytics.google.com https://*.analytics.google.com https://www.google.com https://stats.g.doubleclick.net https://www.google-analytics.com https://*.mczbf.com https://*.kdukvh.com https://*.emjcd.com https://*.jdoqocy.com https://*.dotomi.com https://*.cj.com https://*.sjwoe.com https://www.facebook.com https://*.clarity.ms https://*.apple-mapkit.com https://*.mydnsip.com https://www.googleadservices.com https://engagements.appsflyer.com https://meta.veepn.com https://ekr.zdassets.com; media-src 'self'; frame-ancestors 'self'; object-src 'none'; report-to csp-endpoint; 1 default-src 'self'; script-src 'self' 'unsafe-eval' https: http: 'nonce-NDM2NjhmZTItZjMxMi00ZTY5LWFjNWUtNDA2MWFiMDQ5ZGJm' 'strict-dynamic'; script-src-elem 'unsafe-inline' https://yamap.com https://www.googletagmanager.com https://js.stripe.com; style-src 'self' 'unsafe-inline'; font-src 'self' data:; img-src 'self' https: blob: data:; object-src 'none'; form-action 'self'; connect-src 'self' https://*; report-uri https://zk6bsphzgvpliawi65sbwjdx6m0xhmnc.lambda-url.ap-northeast-1.on.aws/; frame-src https://docs.google.com/forms; 1 default-src https://www.honeybadger.io; connect-src 'self' data: https://*.savvycal.com/ https://*.frontapp.com/ https://*.fontawesome.com/ https://*.typekit.net/ https://*.honeybadger.io https://*.convertkit.com/ https://*.convertexperiments.com/ https://*.profitwell.com https://*.usefathom.com/ https://*.wistia.com/ https://fg8vvsvnieiv3ej16jby.litix.io https://pipedream.wistia.com/mput https://embedwistia-a.akamaihd.net/ https://cdnjs.cloudflare.com; font-src 'self' data: https://use.typekit.net https://cdnjs.cloudflare.com https://*.fontawesome.com; frame-src https://savvycal.com/ https://player.vimeo.com https://platform.twitter.com https://syndication.twitter.com https://fast.wistia.com; img-src 'self' data: https:; script-src 'self' 'unsafe-eval' 'unsafe-inline' https://*.gstatic.com/ https://*.savvycal.com/ https://*.frontapp.com/ https://*.fontawesome.com/ https://*.typekit.net/ https://*.profitwell.com https://*.usefathom.com/ https://*.honeybadger.io/ https://*.convertkit.com/ https://*.convertexperiments.com/ https://gist.github.com https://*.wistia.com https://cdn.syndication.twimg.com https://platform.twitter.com https://fast.wistia.com/ https://identity.netlify.com/v1/netlify-identity-widget.js https://cdnjs.cloudflare.com; style-src 'self' 'unsafe-inline' blob: https://*.gstatic.com/ https://*.fontawesome.com https://*.typekit.net https://github.githubassets.com/ https://platform.twitter.com https://ton.twimg.com https://cdnjs.cloudflare.com; media-src 'self' data: https://embedwistia-a.akamaihd.net https://*.wistia.com; manifest-src https://www.honeybadger.io ; report-uri https://api.honeybadger.io/v1/browser/csp?api_key=c2f13350&report_only=true&env=production 1 connect-src 'self' https://checkoutshopper-live.adyen.com https://www.facebook.com https://www.google.com https://googleads.g.doubleclick.net https://www.googleoptimize.com https://*.hotjar.com https://*.mparticle.com https://beacon.krxd.net https://*.tre.se https://vercel.live https://api.usabilla.com https://dc.services.visualstudio.com https://stats.g.doubleclick.net https://www.google-analytics.com https://api.customersaas.com https://vc.hotjar.io wss://ws.hotjar.com https://cdn.linkedin.oribi.io https://adservice.google.com https://fonts.gstatic.com https://content.hotjar.io https://*.optimizely.com https://region1.google-analytics.com wss://ws-us3.pusher.com; default-src 'self' https://*.tre.se; font-src 'self' data: https://static.customersaas.com https://vercel.live https://assets.vercel.com; frame-src 'self' https://checkoutshopper-live.adyen.com https://6142836.fls.doubleclick.net https://www.facebook.com https://www.google.com https://www.googletagmanager.com https://widget.trustpilot.com https://d6tizftlrpuof.cloudfront.net https://vercel.live https://www.youtube.com https://cdn.krxd.net https://cloud.epost.tre.se https://coverage.tre.se https://tre.workbuster.com https://vars.hotjar.com https://td.doubleclick.net; img-src 'self' data: https://checkoutshopper-live.adyen.com https://6142836.fls.doubleclick.net https://www.facebook.com https://clients1.google.com https://www.google.com https://googleads.g.doubleclick.net https://www.gstatic.com https://www.googletagmanager.com https://beacon.krxd.net https://*.tre.se https://d6tizftlrpuof.cloudfront.net https://vercel.live http://images.ctfassets.net https://images.ctfassets.net https://jslog.krxd.net/ https://t.co https://w.usabilla.com https://www.google-analytics.com/collect https://www.google.se https://www.google.dk https://i.ytimg.com https://img.youtube.com https://new-collect.albacross.com https://d35v9wsdymy32b.cloudfront.net https://px.ads.linkedin.com https://ad.doubleclick.net https://vercel.com blob:; manifest-src 'self'; media-src 'self' https://videos.ctfassets.net; object-src 'none'; report-uri https://www.tre.se/logger/csp-report; script-src 'report-sample' 'self' 'unsafe-inline' 'unsafe-eval' https://static.customersaas.com https://clients1.google.com https://www.googleoptimize.com https://www.google.com https://googleads.g.doubleclick.net https://www.gstatic.com https://www.googletagmanager.com https://*.hotjar.com https://*.mparticle.com https://widget.trustpilot.com https://d6tizftlrpuof.cloudfront.net https://vercel.live https://www.youtube.com https://*.adtr.io https://*.krxd.net https://adtr.io https://analytics.twitter.com https://api.usabilla.com https://az416426.vo.msecnd.net/scripts/a/ai.0.js https://bat.bing.com https://cdn.bannerflow.com https://cdn.tre.se https://cdnn.tre.se https://connect.facebook.net https://cse.google.com https://gtm.adt313.net/jsTag https://hi3gscriptbucket.blob.core.windows.net https://rules.quantcount.com https://s.ytimg.com https://secure.quantserve.com https://ssl.google-analytics.com https://static.ads-twitter.com https://tagmanager.google.com https://w.usabilla.com/ https://www.google-analytics.com https://www.googleadservices.com https://serve.albacross.com https://tre.workbuster.com https://region1.analytics.google.com https://cdn.amplitude.com https://treva.boost.ai; style-src 'report-sample' 'self' 'unsafe-inline' https://static.customersaas.com https://www.google.com https://d6tizftlrpuof.cloudfront.net https://vercel.live https://d1r5etm691cejh.cloudfront.net; 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.hotjar.com *.amplitude.com *.ads-twitter.com use.typekit.net *.googletagmanager.com *.google-analytics.com *.googleadservices.com *.segment.com *.doubleclick.net sc-static.net *.google.com *.gstatic.com *.googlesyndication.com connect.facebook.net js.stripe.com cdn.seon.io www.redditstatic.com analytics.tiktok.com bat.bing.com *.checkout.com; font-src 'self' data: fonts.gstatic.com use.typekit.net frontend-assets.sorare.tech frontend-assets.sorare.com frontend-assets.sorare.dev; media-src 'self' *.ctfassets.net frontend-assets.sorare.com frontend-assets.sorare.tech frontend-assets.sorare.dev assets.sorare.com assets.sorare.tech assets.sorare.dev; style-src 'self' 'unsafe-inline' fonts.googleapis.com cdn.jsdelivr.net use.typekit.net use.fontawesome.com blob:; connect-src *; img-src * data:; frame-src *; manifest-src 'self' https://sorare.cloudflareaccess.com; object-src 'none'; worker-src blob:; 1 report-uri /upload/csp/csp.php; report-to csp-endpoints 1 default-src https:; script-src https: 'unsafe-eval' 'unsafe-inline' blob:; style-src https: 'unsafe-inline'; img-src https: data:; font-src https: data:; connect-src 'self' ws: https://suggestions.dadata.ru https://www.google.com; worker-src blob:; report-uri /csp-report 1 default-src 'self' 846-hel-222.mktoresp.com 173-dti-322.mktoresp.com 059-alg-683.mktoresp.com js.zi-scripts.com static.addtoany.com stats.g.doubleclick.net tracking-api.g2.com play.google.com www.google.com; connect-src 'self' 846-hel-222.mktoweb.com analytics.google.com c.6sc.co ipv6.6sc.co cdn.cookielaw.org distillery.wistia.com fast.wistia.com pipedream.wistia.com geolocation.onetrust.com epsilon.6sense.com secure.adnxs.com ws.zoominfo.com px.ads.linkedin.com www.google.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net jnn-pa.googleapis.com api.simplecast.com cdn.simplecast.com givebutter.com umsafoundation.org www.youtube.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com pagead2.googlesyndication.com google.com stats.g.doubleclick.net js.zi-scripts.com privacyportal-eu.onetrust.com 846-hel-222.mktoresp.com app.qualified.com tracking-api.g2.com tr.capterra.com 173-dti-322.mktoresp.com embed-cloudfront.wistia.com *.clarity.ms 173-dti-322.mktoutil.com www.google.com.co; font-src 'self' www.perforce.com www.blazemeter.com www.gliffy.com www.jrebel.com www.openlogic.com www.zend.com www.puppet.com www.perfecto.io fonts.gstatic.com cdn.simplecast.com data: fast.wistia.com use.typekit.net www.gartner.com; frame-src 'self' 846-hel-222.mktoweb.com 173-dti-322.mktoresp.com 059-alg-683.mktoresp.com resources.perforce.com static.addtoany.com www.googletagmanager.com www.perforce.com www.blazemeter.com www.gliffy.com www.jrebel.com www.openlogic.com www.zend.com www.puppet.com www.perfecto.io fast.wistia.net player.simplecast.com www.youtube.com umsafoundation.org live-totalview.pantheonsite.io live-imsl.pantheonsite.io www.google.com app.qualified.com fast.wistia.com player.vimeo.com player.captivate.fm 605957.extforms.netsuite.com www.gartner.com; img-src 'self' data: b.6sc.co c.bing.com bat.bing.com *.clarity.ms cdn.cookielaw.org cdn2.hubspot.net embed-ssl.wistia.com f.hubspotusercontent00.net pic.trendemon.com px.ads.linkedin.com trackingapi.trendemon.com analytics.twitter.com cdn.bizible.com cdn.bizibly.com googleads.g.doubleclick.net t.co track.hubspot.com www.facebook.com www.gliffy.com www.google.com www.linkedin.com www.perforce.com www.blazemeter.com www.jrebel.com www.openlogic.com www.zend.com www.puppet.com www.perfecto.io umsafoundation.org live-mondrian.pantheonsite.io i.ytimg.com image.simplecastcdn.com yt3.ggpht.com fast.wistia.net googletagmanager.com ssl.gstatic.com www.gstatic.com *.google-analytics.com *.googletagmanager.com www.googletagmanager.com pagead2.googlesyndication.com www.googleadservices.com google.com www.google.com.tw www.google.mn fast.wistia.com www.google.co.uk www.google.com.br www.google.no fonts.gstatic.com www.google.co.in www.google.com.ec www.google.pl; manifest-src 'self' 846-hel-222.mktoresp.com 173-dti-322.mktoresp.com 059-alg-683.mktoresp.com js.zi-scripts.com static.addtoany.com stats.g.doubleclick.net tracking-api.g2.com play.google.com www.google.com www.perforce.com www.blazemeter.com www.gliffy.com www.jrebel.com www.openlogic.com www.zend.com www.puppet.com www.perfecto.io; media-src 'self' blob: app.qualified.com fast.wistia.com embed-ssl.wistia.com data: embed-fastly.wistia.com embed-cloudfront.wistia.com; object-src 'self'; script-src 'self' 'strict-dynamic' 'unsafe-eval' 846-hel-222.mktoweb.com assets.trendemon.com browser.sentry-cdn.com cdn.cookielaw.org cdn.jsdelivr.net cdnjs.cloudflare.com fast.wistia.com fast.wistia.net googleads.g.doubleclick.net j.6sc.co js.zi-scripts.com munchkin.marketo.net resources.perforce.com *.clarity.ms snap.licdn.com static.addtoany.com static.cloudflareinsights.com trackingapi.trendemon.com tracking.g2crowd.com ct.capterra.com cdn.bizible.com cdn.getmoreproof.com js.hs-analytics.net js.hs-banner.com js.hs-scripts.com connect.facebook.net static.ads-twitter.com p-js.s3.amazonaws.com player.simplecast.com widgets.givebutter.com www.google.com www.googletagmanager.com www.perforce.com www.blazemeter.com www.gliffy.com www.jrebel.com www.openlogic.com www.zend.com www.puppet.com www.perfecto.io umsafoundation.org www.youtube.com googletagmanager.com tagmanager.google.com *.googletagmanager.com www.googleadservices.com pagead2.googlesyndication.com https://cdn.ckeditor.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://code.highcharts.com https://fast.wistia.com https://resources.perforce.com https://resources.roguewave.com https://static.addtoany.com https://unpkg.com info.perforce.com 'nonce-th9hikPqQr_CZ6JBwo1oZw'; script-src-elem 'self' feedback.perforce.com js.qualified.com cdn.cookielaw.org googleads.g.doubleclick.net ct.capterra.com gist.github.com j.6sc.co munchkin.marketo.net trackingapi.trendemon.com scripts.clarity.ms js.zi-scripts.com cdnjs.cloudflare.com https://cdn.ckeditor.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://code.highcharts.com https://fast.wistia.com https://resources.perforce.com https://resources.roguewave.com https://static.addtoany.com https://unpkg.com info.perforce.com resources.perforce.com 'nonce-th9hikPqQr_CZ6JBwo1oZw'; style-src 'self' 'report-sample' 'unsafe-inline' 846-hel-222.mktoweb.com cdnjs.cloudflare.com resources.perforce.com www.perforce.com www.blazemeter.com www.gliffy.com www.jrebel.com www.openlogic.com www.zend.com www.puppet.com www.perfecto.io fonts.googleapis.com www.youtube.com googletagmanager.com tagmanager.google.com app-ab48.marketo.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://code.highcharts.com https://unpkg.com; style-src-elem 'self' 'report-sample' feedback.perforce.com resources.perforce.com www.googletagmanager.com https://cdnjs.cloudflare.com/ajax/libs/photoswipe/5.4.4/photoswipe.min.css cdnjs.cloudflare.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://code.highcharts.com https://unpkg.com; webrtc 'block'; worker-src 'self' blob:; base-uri 'self'; form-action 'self' https://feedback.perforce.com; frame-ancestors 'self' www.perforce.com; report-uri https://uk3hg0f8.uriports.com/reports/report 1 default-src https://*.amazon.com https://*.media-amazon.com https://*.ssl-images-amazon.com https://*.amazon-adsystem.com; script-src https://*.amazon.com https://*.media-amazon.com https://*.ssl-images-amazon.com https://*.amazon-adsystem.com 'unsafe-inline' 'unsafe-eval'; style-src https://*.amazon.com https://*.media-amazon.com https://*.ssl-images-amazon.com https://*.amazon-adsystem.com 'unsafe-inline'; report-uri /1/batch/2/OE/mid=ATVPDKIKX0DER:sid=132-7354583-0084835:rid=H06XWJR8N2P00BNRBMJF:sn=kdp.amazon.com 1 default-src data: 'unsafe-inline' 'unsafe-eval' https: blob: http://*.files.wordpress.com wss://www.artforum.com; report-uri https://pmcuri.report-uri.com/r/d/csp/reportOnly 1 default-src 'self' *.fabfitfun.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.fabfitfun.com *.recurly.com *.amazonaws.com *.ada.support www.dwin1.com *.google-analytics.com *.doubleclick.net www.googleadservices.com www.googletagmanager.com *.hcaptcha.com hcaptcha.com *.exitintel.com *.facebook.net *.facebook.com *.tiktok.com *.cookielaw.org *.segment.com *.tvsquared.com *.onetrust.com *.adsrvr.org sc-static.net *.zdassets.com *.crrnt.app *.pixlee.com *.roeyecdn.com *.amplitude.com *.bing.com *.googleapis.com *.exitintel.com *.jsdelivr.net *.datadoghq-browser-agent.com *.gladly.com *.braintreegateway.com *.paypal.com *.cloudflare.com *.hotjar.com *.clarity.ms accessibilityserver.org *.userway.org *.tryamped.com *.pinimg.com *.ads-twitter.com *.amped.io *.visualwebsiteoptimizer.com *.amazon-adsystem.com blob:; style-src * 'unsafe-inline' data: blob:; connect-src *; frame-src *; img-src * 'unsafe-inline' data: blob:; font-src * 'unsafe-inline' data: blob:; media-src * blob:; object-src 'none'; 1 img-src https: data:; connect-src https:; report-uri https://csp-reports.yesware.com/new 1 style-src 'self' 'unsafe-inline' https://*.assets.post.at https://*.azureedge.net https://bpanel.streamdiver.com https://webcast.a1.net https://*.gstatic.com; report-to default; 1 script-src 'self' *.adyen.com *.allsaints.com *.bing.com *.cquotient.com *.forter.com *.g.doubleclick.net *.global-e.com *.google-analytics.com *.google.com *.googleapis.com *.googlesyndication.com *.gstatic.com *.klarnaservices.com *.parcellab.com *.pcapredict.com *.scarabresearch.com *.squarecdn.com *.tribalfusion.com *.yotpo.com access.myunidays.com ajax.cloudflare.com allsaints.api.highstreetapp.com analytics.tiktok.com api.soreto.com appleid.cdn-apple.com assets.ntcacdn.net cdn-ukwest.onetrust.com cdn.jsdelivr.net cdn.optimizely.com cdnapisec.kaltura.com challenges.cloudflare.com chat.digitalgenius.com code.jquery.com connect.facebook.net ct.pinterest.com d.ratepay.com dnn0yrbagrg.cloudfront.net duvgq8bw.cloudfront.net edge.eu.fullstory.com js-agent.newrelic.com js.klarna.com lottingem.com platform.communicatorcorp.com player.vimeo.com rgneujpc.micpn-eu.com s.pinimg.com sc-static.net secured-pixel.com services.postcodeanywhere.co.uk static.cloudflareinsights.com statse.webtrendslive.com t.contentsquare.net tag.rmp.rakuten.com tags.creativecdn.com tr.snapchat.com tracker.marinsm.com unpkg.com widgets.trustedshops.com www.googletagmanager.com www.paypal.com www.recaptcha.net www.redditstatic.com x.klarnacdn.net; report-uri https://csp-reporting.cloudflare.com/cdn-cgi/script_monitor/report?m=KS0Ixi5yTvxrgUAfgfiypXyUwSFzq73VxVfay69PvHA-1770427852-1.0.1.1-6gj6enjuppvI4ig9ybG8SiDbXvLgVXheXPKk7HRLSZ3wiIue0xEA3ogrzNxXAUppA_sNRCuNrpEc06JnejmElXlI3m9UUC607YzpIMLi2NDA_Tzi73y7mV6GHndR0hyGMm2Svp0TN0eOBR1Ploktk0mcwbQC_GWPKCNUrHlDACPZ1TfIqTTp8U2W17P0MpvNbe75PU9Osvi9s600ZNNWLw; report-to cf-kaaopiuxhtobhgfo 1 default-src 'self'; frame-src 'self' https://datawrapper.dwcdn.net https://js.chargebee.com https://js.stripe.com https://datawrapper-test.chargebee.com https://youtube-nocookie.com https://platform.twitter.com; worker-src blob:; connect-src 'self' data: https://ifconfig.me/ip wss://ws.datawrapper.de https://pwk.datawrapper.de https://js.chargebee.com https://*.cloudfront.net https://*.sentry.io https://*.gstatic.com https://static.dwcdn.net https://datawrapper.dwcdn.net https://comments.datawrapper.de https://staging-chart-tests.s3.eu-central-1.amazonaws.com https://fonts.googleapis.com/ https://app.datawrapper.de https://api.fontsource.org/v1/fonts/ app.datawrapper.de ; font-src 'self' data: https://static.dwcdn.net https://fonts.gstatic.com https://fonts.dwcdn.net ; img-src * data: blob:; media-src * data:; script-src 'self' 'unsafe-eval' https://appsforoffice.microsoft.com https://datawrapper.dwcdn.net https://pwk.datawrapper.de 'nonce-pO5bYhNZC7BYF4g5V52O6g=='; script-src-elem 'self' https://pwk.datawrapper.de https://js.chargebee.com https://js.stripe.com https://appsforoffice.microsoft.com https://platform.twitter.com https://pt.dwcdn.net https://datawrapper.dwcdn.net/ https://pwk.datawrapper.de https://app.datawrapper.de https://comments.datawrapper.de 'nonce-pO5bYhNZC7BYF4g5V52O6g=='; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://datawrapper.dwcdn.net https://static.dwcdn.net https://pt.dwcdn.net; style-src-elem 'self' 'unsafe-inline' https://static.dwcdn.net https://js.chargebee.com https://fonts.googleapis.com https://pt.dwcdn.net https://datawrapper.dwcdn.net https://js.chargebee.com/assets/; report-uri %%CSP_REPORT_URI%% 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://www.googletagmanager.com https://static.hotjar.com https://snap.licdn.com https://js.monitor.azure.com https://js.qualified.com https://cdn.hockeystack.com https://*.marketo.com https://*.bizible.com https://*.vwo.com https://*.drift.com https://*.demandbase.com https://*.conductor.com https://*.seismic.com; connect-src 'self' https://*.marketo.com https://*.bizible.com https://*.google-analytics.com https://*.hotjar.com https://*.qualified.com https://*.demandbase.com https://*.vwo.com https://*.hockeystack.com https://*.drift.com https://*.conductor.com https://*.seismic.com; img-src 'self' data: https://*.googleusercontent.com https://*.gravatar.com https://*.marketo.com https://*.bizible.com https://*.qualified.com https://*.hockeystack.com https://*.conductor.com https://*.seismic.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; font-src 'self' https://fonts.gstatic.com; frame-ancestors 'self'; 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' 'report-sample' https://www.googletagmanager.com https://www.google-analytics.com https://www.google.com https://www.googleadservices.com https://www.gstatic.com https://pi.pardot.com https://cdn.pardot.com https://snap.licdn.com https://connect.facebook.net https://widget.instabot.io https://widgetapi.instabot.io https://addevent.com https://cdn.addevent.com https://cookie-cdn.cookiepro.com https://kit.fontawesome.com https://cdn.jsdelivr.net https://cdn.evgnet.com https://d2i34c80a0ftze.cloudfront.net https://d2iiunr5ws5ch1.cloudfront.net https://d2wy8f7a9ursnm.cloudfront.net https://www.youtube.com https://player.vimeo.com https://tag.demandbase.com https://amd.sellingsimplified.net https://explore.parexel.com https://lottie.host https://assets2.lottiefiles.com https://static.hotjar.com https://script.hotjar.com https://googleads.g.doubleclick.net https://www.googleadservices.com https://www.clarity.ms https://clarity.ms https://bat.bing.com https://sidebar.bugherd.com https://www.bugherd.com https://static.cloudflareinsights.com; style-src 'self' 'unsafe-inline' 'report-sample' https://fonts.googleapis.com https://translate.googleapis.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://code.jquery.com https://d2iiunr5ws5ch1.cloudfront.net https://form.asana.com https://lottie.host https://assets2.lottiefiles.com; img-src 'self' data: blob: https://*.google.com https://*.googletagmanager.com https://*.google-analytics.com https://*.gstatic.com https://*.doubleclick.net https://*.googlesyndication.com https://*.linkedin.com https://*.licdn.com https://*.facebook.com https://*.fbcdn.net https://*.ytimg.com https://*.youtube.com https://*.twitter.com https://*.twimg.com https://cookie-cdn.cookiepro.com https://static.instabot.io https://tag.demandbase.com https://*.demandbase.com https://lottie.host https://*.lottiefiles.com https://d2iiunr5ws5ch1.cloudfront.net https://*.bugherd.com https://*.amazonaws.com; font-src 'self' data: https://fonts.gstatic.com https://ka-p.fontawesome.com https://cdnjs.cloudflare.com https://d2iiunr5ws5ch1.cloudfront.net https://at.alicdn.com; connect-src 'self' https://analytics.google.com https://www.google-analytics.com https://region1.analytics.google.com https://region1.google-analytics.com https://stats.g.doubleclick.net https://ad.doubleclick.net https://googleads.g.doubleclick.net https://adservice.google.com https://pagead2.googlesyndication.com https://www.google.com https://*.google.com https://*.google.co.uk https://*.google.de https://*.google.fr https://*.google.es https://*.google.it https://*.google.nl https://*.google.co.jp https://*.google.com.au https://px.ads.linkedin.com https://cdn.linkedin.oribi.io https://*.hotjar.com https://*.hotjar.io wss://ws.hotjar.com https://widget.instabot.io https://widgetapi.instabot.io https://static.instabot.io https://chat.instabot.io https://livechat.instabot.io wss://chat.instabot.io https://cookie-cdn.cookiepro.com https://geolocation.onetrust.com https://privacyportal.cookiepro.com https://tag.demandbase.com https://tag-logger.demandbase.com https://segments.company-target.com https://api.company-target.com https://amd.sellingsimplified.net https://st.fullcircleinsights.com https://*.clarity.ms https://ipinfo.io https://geodata.solutions https://maps.googleapis.com https://sessions.bugsnag.com https://notify.bugsnag.com https://www.bugherd.com wss://ws-mt1.pusher.com wss://ws.pusherapp.com https://lottie.host https://assets2.lottiefiles.com https://cdn.jsdelivr.net https://ka-p.fontawesome.com https://cloudflareinsights.com https://static.cloudflareinsights.com; frame-src 'self' https://www.youtube.com https://player.vimeo.com https://www.facebook.com https://www.google.com https://www.googletagmanager.com https://insight.adsrvr.org https://td.doubleclick.net https://s.company-target.com https://vars.hotjar.com https://www.podbean.com https://player.simplecast.com https://form.asana.com https://content.cdntwrk.com https://explore.parexel.com https://lottie.host https://sidebar.bugherd.com https://d1eoo1tc6rr5e.cloudfront.net; media-src 'self' https://download-video.akamaized.net https://player.vimeo.com https://mcdn.podbean.com https://www.youtube.com https://lottie.host https://assets2.lottiefiles.com; object-src 'none'; frame-ancestors 'self'; form-action 'self' https://pi.pardot.com https://explore.parexel.com; base-uri 'self'; upgrade-insecure-requests 1 default-src 'self' 'unsafe-inline' https://*.banrisul.com.br/ https://*.clarity.ms; script-src 'self' 'unsafe-inline' https://*.banrisul.com.br/ https://*.googletagmanager.com https://*.securiti.ai/ https://*.google.com.br/ads/ https://*.clarity.ms; script-src-elem 'self' 'unsafe-inline' https://*.banrisul.com.br/ https://www.googletagmanager.com https://*.securiti.ai/ https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://*.google.com.br/ads/ https://analytics.google.com https://*.google-analytics.com/ https://connect.facebook.net/ https://s.pinimg.com/ https://ct.pinterest.com/ https://*.clarity.ms https://www.splash-screen.net/ https://www.youtube.com/iframe_api; img-src 'self' data: https://*.banrisul.com.br/ https://*.google.com.br/ads/ https://*.facebook.com https://ct.pinterest.com https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://*.g.doubleclick.net https://*.google.com https://*.google.com.br https://*.clarity.ms; font-src 'self' 'unsafe-inline' https://*.banrisul.com.br/ https://fonts.gstatic.com/ https://*.clarity.ms; style-src-elem 'self' 'unsafe-inline' https://*.banrisul.com.br/ https://*.securiti.ai/ https://*.clarity.ms; connect-src 'self' https://api.banrisul.com.br https://*.securiti.ai/ https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://analytics.google.com https://*.g.doubleclick.net https://*.google.com https://*.google.com.br https://ct.pinterest.com https://*.clarity.ms; frame-src 'self' 'unsafe-inline' https://*.banrisul.com.br/ https://www.youtube.com/ https://finansite-a.ae.com.br/ https://www.google.com/recaptcha/ https://recaptcha.google.com/recaptcha/ https://assets.pinterest.com https://ct.pinterest.com https://*.clarity.ms https://td.doubleclick.net/; frame-ancestors 'self' https://*.corp.banrisul.com.br/; 1 default-src 'self' https://fonts.googleapis.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://js.stripe.com https:// connect.facebook.net/ https://www.google-analytics.com/analytics.js https://www.googletagmanager.com/gtag/js https://api.sardine.ai https://static.zdassets.com/ https://ekr.zdassets https://ekr.zendesk.com https://*.zopim.com wss://demonifty.zendesk.com wss://*.zopim.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://edge.fullstory.com/s/ https://static.ads-twitter.com/uwt.js https://sc-static.net/ https://googleads.g.doubleclick.net/ https://tr.snapchat.com; style-src 'self' 'unsafe-inline' 'wasm-unsafe-eval' https://fonts.googleapis.com *.live-video.net; script-src-elem 'self' 'unsafe-inline' https://js.stripe.com https://api.dev.sardine.ai https://edge.fullstory.com https://www.googletagmanager.com/gtag/js https://connect.facebook.net https://static.ads-twitter.com/uwt.js https://sc-static.net/scevent.min.js https://www.google.com/recaptcha/ https://static.zdassets.com/ https://www.gstatic.com/recaptcha/ https://tr.snapchat.com/ https://www.google-analytics.com/ https://www.googleadservices.com https://googleads.g.doubleclick.net https://api.sardine.ai https://unpkg.com/@google/model-viewer/dist/model-viewer.min.js https://www.youtube.com https://www.googleoptimize.com https://www.clarity.ms *.live-video.net; img-src https: blob: data:; connect-src https://browser-intake-datadoghq.com https://www.niftygateway.com https://niftygateway.com https://analytics.google.com https://*.clarity.ms https://niftygateway.zendesk.com https://api.niftygateway.com https://odysseymarket.niftygateway.com https://api.sandbox.niftygateway.com https://stats.g.doubleclick.net https://www.facebook.com/tr/ https://www.google-analytics.com https://www.clarity.ms wss://widget-mediator.zopim.com https://nifty-qa100.service.aws-qa.sd.gem.link https://demonifty.zendesk.com https://ekr.zdassets.com https://encrypted-tbn0.gstatic.com/images https://lh3.googleusercontent.com https://tr.snapchat.com https://eth-goerli.alchemyapi.io https://search-api-staging.s-niftygateway-001-use1.svc.gem.link https://search-api.niftygateway.com https://search-api-dev.d-niftygateway-001-use1.svc.gem.link https://ipfs.io https://rs.fullstory.com https://session-replay.browser-intake-datadoghq.com https://eth-mainnet.alchemyapi.io https://api.cloudinary.com/v1_1/nifty_gateway/auto/upload https://openseauserdata.com https://rum.browser-intake-datadoghq.com https://api.x.immutable.com https://i.seadn.io https://cdn.optimizely.com https://img.seadn.io https://storage.opensea.io https://api.opensea.io https://sdk.iad-03.braze.com *.live-video.net ; font-src https://fonts.gstatic.com https://use.typekit.net/ 'self'; object-src 'self'; media-src https://media.niftygateway.com https://static.zdassets.com https://openseauserdata.com https://storage.opensea.io https://res.cloudinary.com blob:; frame-src https://js.stripe.com https://www.google.com https://api.sardine.ai https://api.dev.sardine.ai https://tr.snapchat.com/ https://www.youtube.com https://webusprd01.ihsmtaxsolutions.com/Nifty/ https://td.doubleclick.net/; frame-ancestors 'self'; worker-src blob:; 1 default-src 'self' www.youtube.com *.stripe.com *.addthis.com; script-src 'self' assets.sutori.com *.twitter.com *.twimg.com 'unsafe-inline' *.stripe.com apis.google.com 'unsafe-eval' maps.googleapis.com *.crisp.chat *.crisp.im www.youtube.com *.ytimg.com *.addthis.com *.addthisedge.com data: z.moatads.com *.pinterest.com *.iubenda.com cdn.thinglink.me http://ajax.googleapis.com/ajax/libs/jquery/1.11.3/jquery.min.js https://www.thinglink.com *.instagram.com connect.facebook.net *.imgur.com *.flickr.com blob: cdn.headwayapp.co risk.clearbit.com teams.microsoft.com https://cdnjs.cloudflare.com/ajax/libs/lamejs/1.2.0/lame.min.js; script-src-elem assets.sutori.com *.twitter.com *.twimg.com 'unsafe-inline' *.googletagmanager.com *.stripe.com https://apis.google.com/ accounts.google.com 'unsafe-eval' maps.googleapis.com *.crisp.chat *.crisp.im www.youtube.com *.ytimg.com *.addthis.com *.addthisedge.com data: z.moatads.com *.pinterest.com *.iubenda.com cdn.thinglink.me http://ajax.googleapis.com/ajax/libs/jquery/1.11.3/jquery.min.js https://www.thinglink.com *.instagram.com connect.facebook.net *.imgur.com *.flickr.com blob: cdn.headwayapp.co risk.clearbit.com teams.microsoft.com play.vidyard.com challenges.cloudflare.com; worker-src blob: data:; font-src 'self' data: assets.sutori.com fonts.gstatic.com https://client.crisp.chat; connect-src 'self' https://www.googleapis.com wss://www.sutori.com assets.sutori.com s3.amazonaws.com/assets.sutori.com *.google-analytics.com *.stripe.com accounts.google.com maps.googleapis.com api.amplitude.com wss://*.crisp.chat https://*.crisp.chat *.addthis.com https://syndication.twitter.com/settings https://*.wikipedia.org geo.query.yahoo.com *.flickr.com risk.clearbit.com login.microsoftonline.com blob:; img-src 'self' data: * maps.googleapis.com https://maps.gstatic.com/mapfiles/api-3/images/ https://csi.gstatic.com/ https://i.ytimg.com *.addthis.com *.pinterest.com *.iubenda.com; style-src 'self' assets.sutori.com platform.twitter.com 'unsafe-inline' accounts.google.com *.googleapis.com https://client.crisp.chat *.iubenda.com cdn.thinglink.me https://ton.twimg.com cdn.headwayapp.co; media-src 'self' assets.sutori.com https://client.crisp.chat blob:; child-src 'self' * https://www.sutori.com *.stripe.com https://www.google.com/ https://www.youtube-nocookie.com/embed/ https://www.youtube.com/embed/ *.addthis.com *.pinterest.com blob:; manifest-src assets.sutori.com; 1 default-src 'self' https://*.prime.diftech.org ; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://www.googletagmanager.com; worker-src 'self' blob:; style-src 'self' 'unsafe-inline'; img-src 'self' blob: data:; font-src 'self'; object-src 'none'; base-uri 'self'; form-action 'self'; report-uri /api/v1/pl-landing/csp-report 1 frame-src 'self' https://embed.widencdn.net/ https://www.youtube.com/ https://youtube.com/ https://static.addtoany.com/ https://www.facebook.com/plugins/post.php https://www.instagram.com/ https://bestfriends.widen.net/ https://player.vimeo.com/ https://www.tiktok.com/embed https://js.stripe.com/ https://player.captivate.fm/ https://embed.vhx.tv/ https://giphy.com/embed https://platform.twitter.com/widgets https://quiz.tryinteract.com/ https://tgbwidget.com/ https://tockify.com/best.friends.animal https://www.giftcalcs.com/giftcalcs.php https://www.google.com/recaptcha https://10ay.bestfriends.org/ https://*.fls.doubleclick.net/ https://batchgeo.com/ https://giphy.com/ https://p2a.co/ https://platform.twitter.com/ https://td.doubleclick.net/ https://www.facebook.com/ https://www.google.com/ https://www.googletagmanager.com/ https://www.tiktok.com/ https://*.adsrvr.org/ https://bestfriends.quorum.us/ https://ct.pinterest.com/ https://www.paypal.com/ https://pay.google.com/; object-src 'self'; script-src 'self' 'report-sample' 'unsafe-inline' 'unsafe-eval' https://public.tableau.com https://openfpcdn.io/botd/v1 https://app.five9.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://js.hs-scripts.com https://unpkg.com https://www.google.com cdn-4.convertexperiments.com https://cdn.givechariot.com https://www.googletagmanager.com https://snap.licdn.com https://connect.facebook.net https://services.xg4ken.com https://js.adsrvr.org https://apps.rokt.com https://cdn.datasteam.io https://api.datasteam.io https://r.turn.com https://analytics.tiktok.com https://www.youtube.com https://resources.xg4ken.com https://cdn.domdog.io https://cdn.fundraiseup.com https://static.fundraiseup.com https://js.hs-banner.com https://js.hs-analytics.net https://js.hubspot.com https://aa.agkn.com/ https://app.podscribe.ai/ https://app.podscribe.com/ https://doublethedonation.com/ https://i.tryinteract.com/ https://js.dev.shift4.com/ https://js.stripe.com/ https://lf16-tiktok-web.tiktokcdn-us.com/ https://p2a.co/ https://platform.instagram.com/ https://platform.twitter.com/ https://public.tockify.com/ https://s3.amazonaws.com/ https://static.addtoany.com/ https://storage.googleapis.com/ https://tgbwidget.com/ https://wisepops.net/ https://www.giftcalcs.com/ https://www.instagram.com/ https://www.petfinder.com/ https://www.snapengage.com/ https://www.tiktok.com/ https://ads.nextdoor.com/ https://s.pinimg.com/ https://*.mountain.com/ https://*.amazon-adsystem.com/ https://apps.rokt-api.com/ https://ct.pinterest.com/ https://www.paypal.com/ https://pay.google.com/ https://d3js.org; script-src-elem 'self' 'report-sample' 'unsafe-inline' 'unsafe-eval' https://public.tableau.com https://openfpcdn.io/botd/v1 https://app.five9.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://js.hs-scripts.com https://unpkg.com https://www.google.com cdn-4.convertexperiments.com https://cdn.givechariot.com https://www.googletagmanager.com https://snap.licdn.com https://connect.facebook.net https://services.xg4ken.com https://js.adsrvr.org https://apps.rokt.com https://cdn.datasteam.io https://api.datasteam.io https://r.turn.com https://analytics.tiktok.com https://www.youtube.com https://resources.xg4ken.com https://cdn.domdog.io https://cdn.fundraiseup.com https://static.fundraiseup.com https://js.hs-banner.com https://js.hs-analytics.net https://js.hubspot.com https://aa.agkn.com/ https://app.podscribe.ai/ https://app.podscribe.com/ https://doublethedonation.com/ https://i.tryinteract.com/ https://js.dev.shift4.com/ https://js.stripe.com/ https://lf16-tiktok-web.tiktokcdn-us.com/ https://p2a.co/ https://platform.instagram.com/ https://platform.twitter.com/ https://public.tockify.com/ https://s3.amazonaws.com/ https://static.addtoany.com/ https://storage.googleapis.com/ https://tgbwidget.com/ https://wisepops.net/ https://www.giftcalcs.com/ https://www.instagram.com/ https://www.petfinder.com/ https://www.snapengage.com/ https://www.tiktok.com/ https://ads.nextdoor.com/ https://s.pinimg.com/ https://*.mountain.com/ https://*.amazon-adsystem.com/ https://apps.rokt-api.com/ https://ct.pinterest.com/ https://www.paypal.com/ https://pay.google.com/ https://d3js.org; style-src 'self' 'report-sample' 'unsafe-inline' https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com https://app.five9.com https://cdn-images.mailchimp.com/ https://doublethedonation.com/ https://fonts.googleapis.com/ https://lf16-tiktok-web.tiktokcdn-us.com/; style-src-elem 'self' 'report-sample' 'unsafe-inline' https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com https://app.five9.com https://cdn-images.mailchimp.com/ https://doublethedonation.com/ https://fonts.googleapis.com/ https://lf16-tiktok-web.tiktokcdn-us.com/; worker-src 'self'; base-uri 'self'; form-action 'self'; frame-ancestors 'self' https://www.google.com/; block-all-mixed-content 1 default-src 'self' dev-5847984.okta.com sso.app.elationemr.com *.oktacdn.com; connect-src 'self' dev-5847984.okta.com dev-5847984-admin.okta.com sso.app.elationemr.com *.oktacdn.com *.mixpanel.com *.mapbox.com dev-5847984.kerberos.okta.com https://oinmanager.okta.com data: *.ingest.sentry.io; script-src 'unsafe-inline' 'unsafe-eval' 'self' 'report-sample' dev-5847984.okta.com sso.app.elationemr.com *.oktacdn.com; style-src 'unsafe-inline' 'self' 'report-sample' dev-5847984.okta.com sso.app.elationemr.com *.oktacdn.com; frame-src 'self' dev-5847984.okta.com dev-5847984-admin.okta.com sso.app.elationemr.com login.okta.com *.vidyard.com; img-src 'self' dev-5847984.okta.com sso.app.elationemr.com *.oktacdn.com *.tiles.mapbox.com *.mapbox.com *.vidyard.com data: blob:; font-src 'self' dev-5847984.okta.com sso.app.elationemr.com data: *.oktacdn.com fonts.gstatic.com; frame-ancestors 'self' https://elationemr.com 1 default-src 'self';img-src 'self' data: https://flickr.com https://*.flickr.com https://s.gravatar.com https://s.gravatar.com/avatar https://secure.gravatar.com/avatar https://i1.wp.com/cdn.auth0.com/avatars https://cdn.auth0.com/avatars https://g.stripe.com/ https://ssl.google-analytics.com https://pagead2.googlesyndication.com https://pbs.twimg.com/profile_images/ https://farm66.static.flickr.com https://www.google-analytics.com https://tpc.googlesyndication.com https://pbs.twimg.com https://securepubads.g.doubleclick.net https://*.amazon-adsystem.com https://fundingchoicesmessages.google.com https://*.3lift.com https://ams-pageview-public.s3.amazonaws.com https://www.google.com https://syndication.twitter.com https://image8.pubmatic.com https://googleads.g.doubleclick.net https://*.googleusercontent.com;base-uri 'self';font-src 'self' https: data:;frame-ancestors 'self';frame-src https://js.stripe.com https://platform.twitter.com/ https://syndication.twitter.com/ https://tpc.googlesyndication.com/ https://*.safeframe.googlesyndication.com/ https://www.google.com/ https://googleads.g.doubleclick.net/;connect-src 'self' https: https://securepubads.g.doubleclick.net/pagead/ppub_config https://bam.nr-data.net/events/1/cb925c8058;object-src none;script-src 'self' 'unsafe-inline' report-sample https://js.stripe.com/v3/ https://code.jquery.com/jquery-1.12.4.min.js https://code.jquery.com/jquery-3.4.1.slim.min.js https://code.jquery.com/jquery-migrate-1.4.1.min.js https://cdn.jsdelivr.net/npm/popper.js@1.16.0/dist/umd/popper.min.js https://stackpath.bootstrapcdn.com/bootstrap/4.4.1/js/bootstrap.min.js https://cdnjs.cloudflare.com/ajax/libs/validate.js/0.13.1/validate.min.js https://cdnjs.cloudflare.com/ajax/libs/underscore.js/1.8.3/underscore-min.js https://cdnjs.cloudflare.com/ajax/libs/list.js/1.5.0/list.min.js https://www.googletagmanager.com/gtag/js https://www.googletagmanager.com/ https://ssl.google-analytics.com/ga.js https://js-agent.newrelic.com/nr-spa-1184.min.js https://fundingchoicesmessages.google.com https://bam.nr-data.net https://securepubads.g.doubleclick.net https://www.googletagservices.com https://adservice.google.com https://cdnjs.cloudflare.com/ajax/libs/tether/1.4.0/js/tether.min.js https://cdnjs.cloudflare.com/ajax/libs/popper.js/1.12.9/umd/popper.min.js https://cdn.jsdelivr.net/npm/clipboard@2.0.8/dist/clipboard.min.js https://platform.twitter.com/widgets.js https://cdnjs.cloudflare.com/ajax/libs/howler/2.1.1/howler.min.js https://cdnjs.cloudflare.com/ajax/libs/validator/10.9.0/validator.min.js https://*.safeframe.googlesyndication.com/ https://*.googlesyndication.com/ https://platform.twitter.com/js/ https://cdn.ampproject.org http://www.google-analytics.com https://adservice.google.be https://adservice.google.ca https://adservice.google.co.id https://adservice.google.co.mz https://adservice.google.co.th https://adservice.google.co.uk https://adservice.google.co.za https://adservice.google.com.au https://adservice.google.com.ec https://adservice.google.com.hk https://adservice.google.com.ng https://adservice.google.com.np https://adservice.google.com.ph https://adservice.google.com.sa https://adservice.google.de https://adservice.google.es https://adservice.google.fi https://adservice.google.fr https://adservice.google.ie https://adservice.google.it https://adservice.google.lk https://adservice.google.lt https://adservice.google.nl https://adservice.google.no https://adservice.google.rs https://googleads.g.doubleclick.net;script-src-attr none;style-src 'self' https: 'unsafe-inline' report-sample;report-uri https://5f9d927665d1a16209ba908c.endpoint.csper.io 1 default-src 'self' *.wargaming.net *.wgprod.net https://*.wgcdn.co https://*.gcdn.co https://www.youtube.com ; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.wargaming.net *.wgprod.net *.tvsquared.com *.cookielaw.org *.onetrust.com *.outbrain.com *.snapchat.com *.redditstatic.com https://sc-static.net https://ob.cheqzone.com https://analytics.google.com https://www.google.com https://www.google.com.cy https://*.adform.net https://partner.worldoftanks.com https://*.wgcdn.co https://*.gcdn.co https://www.googletagmanager.com https://*.google-analytics.com https://*.analytics.google.com https://www.googleadservices.com https://www.googleoptimize.com https://u360.d-bi.fr https://bat.bing.com https://connect.facebook.net https://googleads.g.doubleclick.net https://*.adroll.com https://*.addthis.com https://*.addthisedge.com https://tag.marinsm.com https://pixel-geo.prfct.co https://static.criteo.net https://stackadapt.com https://*.creative-serving.com https://*.criteo.com https://*.cloudfront.net https://js.gleam.io https://a1.adform.net https://ajax.googleapis.com https://www.youtube.com https://animate.adobe.com https://*.stackadapt.com https://pagead2.googlesyndication.com https://secure.quantserve.com https://rules.quantcount.com https://*.clarity.ms cdn.taboola.com ; style-src 'self' 'unsafe-inline' *.wargaming.net *.wgprod.net https://fonts.googleapis.com https://tags.srv.stackadapt.com https://*.wgcdn.co https://*.gcdn.co ; img-src 'self' data: android-webview-video-poster: * ; connect-src 'self' *.wargaming.net *.wgprod.net *.cookielaw.org *.onetrust.com *.outbrain.com *.snapchat.com https://*.worldoftanks.com https://*.worldoftanks.eu https://*.worldoftanks.asia https://*.wgcdn.co https://sc-static.net https://ob.cheqzone.com https://analytics.google.com https://www.google.com https://www.googleoptimize.com wss://worldoftanks.eu wss://worldoftanks.asia wss://worldoftanks.com https://*.stackadapt.com https://*.facebook.com https://*.addthis.com https://*.google-analytics.com https://*.analytics.google.com https://ymetrica1.com https://*.cloudfront.net https://google.com https://google.com.ua https://google.pl https://*.doubleclick.net https://*.googleapis.com https://pagead2.googlesyndication.com https://*.clarity.ms https://collect.worldoftanks.com https://content-wg.gcdn.co https://api.worldoftanks.com https://bat.bing.com ; font-src 'self' *.wargaming.net *.wgprod.net https://fonts.gstatic.com https://*.wgcdn.co https://*.gcdn.co ; media-src 'self' *.wargaming.net *.wgprod.net https://*.wgcdn.co https://*.gcdn.co ; frame-src 'self' *.wargaming.net *.wgprod.net https://tr.snapchat.com https://creativecdn.com https://*.adform.net https://*.facebook.com https://ad3.adfarm1.adition.com https://connect.facebook.net https://www.youtube.com https://bid.g.doubleclick.net https://*.criteo.com https://*.addthis.com https://gleam.io https://*.gcdn.co https://*.wgcdn.co https://aax-eu.amazon-adsystem.com ; object-src 'self' *.wargaming.net *.wgprod.net https://*.gcdn.co https://www.youtube.com ; report-uri https://cspreport.wargaming.net/cspreport 1 default-src 'self' nmu.edu *.nmu.edu nmu-media.org *.nmu-media.org; script-src 'self' 'unsafe-inline' 'unsafe-eval' nmu.edu *.nmu.edu nmu-media.org *.nmu-media.org *.fontawesome.com *.googleapis.com *.google.com prod.ally.ac embed.tawk.to koi-3qnsq8wl5y.marketingautomation.services www.googletagmanager.com *.doubleclick.net dk5d4tajy4btb.cloudfront.net media.twiliocdn.com *.adobe.com www.google-analytics.com *.adtrafficquality.google snap.licdn.com connect.facebook.net tags.srv.stackadapt.com js.adsrvr.org insight.adsrvr.org partner.googleadservices.com cdn.jsdelivr.net *.nutrislice.com www.imleagues.com public.tableau.com maxcdn.bootstrapcdn.com *.snapchat.com sc-static.net js.ipredictive.com ad.ipredictive.com cdn.flipsnack.com cdnjs.cloudflare.com developers.panopto.com; style-src 'self' 'unsafe-inline' nmu.edu *.nmu.edu nmu-media.org *.nmu-media.org *.googleapis.com use.typekit.net p.typekit.net *.fontawesome.com prod.ally.ac embed.tawk.to *.google.com tags.srv.stackadapt.com insight.adsrvr.org *.nutrislice.com maxcdn.bootstrapcdn.com hello.myfonts.net cdnjs.cloudflare.com *.snapchat.com sc-static.net ad.ipredictive.com js.ipredictive.com www.gstatic.com; font-src 'self' nmu.edu *.nmu.edu nmu-media.org *.nmu-media.org fonts.gstatic.com use.typekit.net p.typekit.net *.fontawesome.com embed.tawk.to data: maxcdn.bootstrapcdn.com cdn.scite.ai cdnjs.cloudflare.com; img-src 'self' nmu.edu *.nmu.edu nmu-media.org *.nmu-media.org data: https: blob: tags.srv.stackadapt.com insight.adsrvr.org *.cdninstagram.com px.ads.linkedin.com *.adobe.com; connect-src 'self' nmu.edu *.nmu.edu nmu-media.org *.nmu-media.org api.instagram.com graph.instagram.com *.cdninstagram.com *.fontawesome.com embed.tawk.to va.tawk.to *.tawk.to wss://*.tawk.to *.googleapis.com koi-3qnsq8wl5y.marketingautomation.services *.google.com www.googletagmanager.com www.google-analytics.com api.edsights.io *.doubleclick.net *.adtrafficquality.google px.ads.linkedin.com www.facebook.com connect.facebook.net tags.srv.stackadapt.com insight.adsrvr.org www.googleadservices.com *.snapchat.com sc-static.net ad.ipredictive.com js.ipredictive.com api.ebsco.io; frame-src 'self' nmu.edu *.nmu.edu nmu-media.org *.nmu-media.org www.youtube.com youtube.com player.vimeo.com vimeo.com *.google.com embed.tawk.to player.flipsnack.com www.googletagmanager.com syndicatedsearch.goog *.adtrafficquality.google match.adsrvr.org insight.adsrvr.org tags.srv.stackadapt.com kuula.co nmuwildcast.hosted.panopto.com www.imleagues.com public.tableau.com scribehow.com www.canva.com mixlr.com *.nutrislice.com cdn.flipsnack.com *.snapchat.com sc-static.net ad.ipredictive.com js.ipredictive.com prod.ally.ac s3.amazonaws.com *.googleapis.com; media-src 'self' nmu.edu *.nmu.edu nmu-media.org *.nmu-media.org s3.amazonaws.com embed.tawk.to insight.adsrvr.org tags.srv.stackadapt.com; base-uri 'none'; form-action 'self' nmu.edu *.nmu.edu insight.adsrvr.org tags.srv.stackadapt.com; object-src 'none'; report-uri /csp-reporting-endpoint; 1 default-src https://*.amazon.com https://*.media-amazon.com https://*.ssl-images-amazon.com https://*.amazon-adsystem.com; script-src https://*.amazon.com https://*.media-amazon.com https://*.ssl-images-amazon.com https://*.amazon-adsystem.com 'unsafe-inline' 'unsafe-eval'; style-src https://*.amazon.com https://*.media-amazon.com https://*.ssl-images-amazon.com https://*.amazon-adsystem.com 'unsafe-inline'; report-uri /1/batch/2/OE/mid=AF2M0KC94RCEA:sid=144-5631009-3411024:rid=QAB33GD4TWH2TX2A1A56:sn=www.acx.com 1 report-uri https://csp.withgoogle.com/csp/youtube_main/strict;base-uri 'self';object-src 'none';script-src 'report-sample' 'nonce-3YrizBwWkhTzGd4VnU84rw' 'unsafe-inline' 'strict-dynamic' https: http: 'unsafe-eval' 1 frame-ancestors 'self'; block-all-mixed-content; default-src 'self'; script-src 'self' 'sha256-5s1UCPQTqKWc18lk0CbkMG0IYokX1utP9ZMQQYiuwXk=' 'sha256-G5NvPksjkp09uU+DikUdTcBXp0UV/362J6blwWczw5I=' 'sha256-HLwLpFPvuHKI0X/UFMhOHQNt1eedIdJGTPML3b+GfWo=' 'sha256-MM3CG7szGAeVIKY58JGR+X+7xTDccDemqcIY0lQLrX8=' 'sha256-OifdWXgFw+IPMAs6Nnr1te5UDPoRIbkDLB1lXZmmRP8=' 'sha256-oh6ZTSefRfIBPlcye8dBjlQBkC0A32V1QIb2htJq7ao=' 'report-sample' 'unsafe-inline' 'unsafe-eval' https://*.containers.piwik.pro https://*.wistia.com https://*.wistia.net https://maps.google.com https://maps.googleapis.com https://src.litix.io https://use.typekit.net; script-src-elem 'self' 'report-sample' https: *.containers.piwik.pro *.wistia.com *.wistia.net maps.google.com maps.googleapis.com src.litix.io use.typekit.net 'unsafe-inline'; style-src 'self' 'report-sample' 'unsafe-inline' blob: *.typekit.net fonts.googleapis.com fast.wistia.com; object-src embedwistia-a.akamaihd.net; frame-src 'self' https: blob: *.wistia.net *.wistia.com maps.google.com maps.googleapis.com uwhealth.formstack.com; child-src 'self' blob:; img-src 'self' data: blob: *.wistia.net *.wistia.com *.typekit.net *.gstatic.com *.ggpht.com *.googleapis.com embedwistia-a.akamaihd.net images.ctfassets.net maps.google.com maps.googleapis.com res.cloudinary.com swedishamericanmychart.org i.ytimg.com; font-src 'self' data: *.wistia.net *.wistia.com fonts.googleapis.com fonts.gstatic.com res.cloudinary.com use.typekit.net; connect-src 'self' microservices.uwhealth.dev microservices.uwhealth.org *.wistia.com *.typekit.net *.litix.io *.cloud.coveo.com embedwistia-a.akamaihd.net fonts.googleapis.com fonts.gstatic.com fast.wistia.net images.ctfassets.net maps.google.com maps.googleapis.com noembed.com res.cloudinary.com uwhealth.piwik.pro pnapi.invoca.net; manifest-src 'self'; base-uri 'self'; form-action 'self'; media-src 'self' data: blob: *.wistia.net *.wistia.com embedwistia-a.akamaihd.net res.cloudinary.com; prefetch-src 'self'; worker-src 'self' blob:; report-to testing 1 default-src 'self' https://www.madavi.de; font-src 'self' data: https://www.madavi.de; img-src 'self' insecure.madavi.de https://www.madavi.de; script-src 'self' 'unsafe-eval' 'unsafe-inline' cdn.ampproject.org https://www.madavi.de; style-src 'self' 'unsafe-inline' https://www.madavi.de; report-uri https://www.madavi.de/wp-json/wpcsp/v1/route/LogPolicyViolation?_wpnonce=e1c120f377 1 default-src *.kuajingmaihuo.com *.cdnfe.com wss://seller.kuajingmaihuo.com *.jumio.ai blob: data: 'unsafe-eval' 'unsafe-inline'; report-uri /api/sec-csp/110000010/report 1 default-src 'self' cedars.okta.com myportal.cshs.org *.oktacdn.com; connect-src 'self' cedars.okta.com cedars-admin.okta.com myportal.cshs.org *.oktacdn.com *.mixpanel.com *.mapbox.com cedars.kerberos.okta.com cedars.mtls.okta.com *.authenticatorlocalprod.com:8769 http://localhost:8769 http://127.0.0.1:8769 *.authenticatorlocalprod.com:65111 http://localhost:65111 http://127.0.0.1:65111 *.authenticatorlocalprod.com:65121 http://localhost:65121 http://127.0.0.1:65121 *.authenticatorlocalprod.com:65131 http://localhost:65131 http://127.0.0.1:65131 *.authenticatorlocalprod.com:65141 http://localhost:65141 http://127.0.0.1:65141 *.authenticatorlocalprod.com:65151 http://localhost:65151 http://127.0.0.1:65151 https://oinmanager.okta.com data: *.ingest.sentry.io; script-src 'unsafe-inline' 'unsafe-eval' 'self' 'report-sample' cedars.okta.com myportal.cshs.org *.oktacdn.com; style-src 'unsafe-inline' 'self' 'report-sample' cedars.okta.com myportal.cshs.org *.oktacdn.com; frame-src 'self' cedars.okta.com cedars-admin.okta.com myportal.cshs.org login.okta.com *.vidyard.com com-okta-authenticator: api-98a8a037.duosecurity.com; img-src 'self' cedars.okta.com myportal.cshs.org *.oktacdn.com *.tiles.mapbox.com *.mapbox.com *.vidyard.com data: blob:; font-src 'self' cedars.okta.com myportal.cshs.org data: *.oktacdn.com fonts.gstatic.com; frame-ancestors 'self' https://*.csmc.edu https://*.cloud.infor.com https://*.rhythm360.io 1 script-src 'nonce-2sT2Xi09VUaKMP0tcrdqKQ==' 'strict-dynamic' 'unsafe-eval' 'unsafe-inline' https: 'report-sample'; base-uri 'none'; report-uri https://events.mercadolibre.com/csp/reports?identifier=w1qeU4XKVwGbQGBuEKyE3KhFBIpr5IZSIaRiTowMc8UG7kU18vRsmBTEKL2krAj23LIS&policy_id=26548&user_id=&request_id=1389cb44-db8e-448e-86eb-69ffb53b77fd; report-to csp-endpoint-wqeuxkvwgbqgbuekyekhfbiprizsiaritowmcugkuvrsmbteklkrajlis; object-src https://http2.mlstatic.com/ https://mlstaticquic-a.akamaihd.net/; frame-ancestors 'self' https://*.mercadolibre.cl:* https://*.mercadolibre.com:* https://*.mercadolibre.com.ve:* https://*.mercadolibre.com.ar:* https://*.mercadolivre.com.br:* https://*.mercadolibre.com.co:* https://*.mercadolibre.com.ec:* https://*.mercadolibre.com.mx:* https://*.mercadolibre.com.pe:* https://*.mercadolibre.com.uy:* https://*.mercadopago.cl:* https://*.mercadopago.com.ar:* https://*.mercadopago.com.br:* https://*.mercadopago.com.co:* https://*.mercadopago.com.mx:* https://*.mercadopago.com.pe:* https://*.mercadopago.com.uy:* https://*.mercadopago.com.ve:* https://*.mercadopago.com:* https://*.adminml.com:* https://*.mercadolibre.co.cr:* https://*.mercadolibre.com.pa:* https://*.mercadolibre.com.do:* https://*.mercadolibre.com.bo:* https://*.mercadolibre.com.py:* https://*.mercadolibre.com.gt:* https://*.mercadolibre.com.hn:* https://*.mercadolibre.com.ni:* https://*.mercadolibre.com.sv:* https://*.mercadopago.com.ec:* https://*.portalinmobiliario.com:* https://*.mercadolivre.com:* 1 default-src * data: blob: filesystem: about: ws: wss: 'unsafe-inline' 'unsafe-eval'; script-src * data: blob: 'unsafe-inline' 'unsafe-eval'; connect-src * data: blob: 'unsafe-inline'; img-src * data: blob: 'unsafe-inline'; frame-src * data: blob: ; style-src * data: blob: 'unsafe-inline'; font-src * data: blob: 'unsafe-inline'; frame-ancestors *.unionesarda.it s.clickiocdn.com *.ampproject.org *.google.com; report-uri /csp-report 1 script-src https: blob: 'unsafe-inline' 'unsafe-eval' 'self';base-uri 'self';report-uri https://reporting-api.gannettinnovation.com 1 default-src 'self' blob:; base-uri 'self'; frame-ancestors 'self'; form-action 'self' https://*.furnishedfinder.com https://*.facebook.com https://www.facebook.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' data: blob: https:; script-src-attr 'unsafe-inline'; connect-src 'self' blob: data: https: wss://chat.stream-io-api.com wss://chat.furnishedfinder.com wss://*.tawk.to wss://*.rp.secure.iproov.me; img-src * data: blob:; font-src 'self' data: https:; frame-src 'self' blob: https:; style-src 'self' 'unsafe-inline' blob: https:; style-src-attr 'self' 'unsafe-inline'; worker-src 'self' blob:; child-src 'self' blob:; media-src 'self' data: blob: https:; object-src 'none'; manifest-src 'self' https:; report-uri https://o4507018827071488.ingest.us.sentry.io/api/4510343205421056/security/?sentry_key=1faef7d9a5760350ce11e10419c510e3&sentry_release=v0.1.8; report-to csp-endpoint-v2 1 script-src 'unsafe-inline' 'nonce-f363b253b8e21b60457576f4fcc5fc79' *.fontawesome.com *.klaviyo.com connect.facebook.com analytics.tiktok.com www.youtube.com 1 default-src data: 'unsafe-inline' 'unsafe-eval' https: blob: http://*.files.wordpress.com wss://www.goldderby.com; report-uri https://pmcuri.report-uri.com/r/d/csp/reportOnly 1 style-src 'self' 'unsafe-inline' data: *.ebay.com *.ebaystatic.com *.ebaystatic.cn *.gstatic.com *.fontawesome.com blob: *.googleapis.com; connect-src 'self' *.ebay.com *.ebaystatic.com data: *.google-analytics.com *.doubleclick.net *.avalon.perfdrive.com *.ebayimg.com *.ucweb.com *.akamaihd.net *.ucads.ucweb.com *.analytics.google.com *.g.doubleclick.net *.googletagmanager.com *.pinterest.com *.snapchat.com *.criteo.com *.facebook.com *.googleapis.com *.googleadservices.com blob: analytics.google.com *.us.shoplive.cloud www.facebook.com *.bing.com www.googletagmanager.com google.com *.google.com *.graphitevault.com *.amplitude.com wss://127.0.0.1:* www.redditstatic.com *.reddit.com *.quantummetric.com; script-src 'self' 'unsafe-eval' 'unsafe-inline' https://* blob: data:; frame-ancestors 'self' *.ebay.com *.ebaystatic.com; img-src 'self' data: blob: https://*; default-src 'self' blob: data: wss: mediastream: https://*; report-uri https://monitor.ebay.com/csp-report/discoveryplatformweb/HomePage?id=2939504940913871808&rid=t6gludlscuzujfwciunrce00%3C%3Dgludlscuzujfwciunrce00%2Bee%3C%3F371d0.qctp%3C2*%3B%7Fvoi-19c35d7738d-0x2704#pd 1 font-src fonts.gstatic.com use.typekit.net *.cloudflare.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com * www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com 'self' 'unsafe-inline'; frame-ancestors *.certcapture.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.demdex.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.certcapture.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.certcapture.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.gstatic.com *.facebook.com s3-sa-east-1.amazonaws.com *.google.com.mx *.bing.com *.collect.igodigital.com https://static.elfsight.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com assets.adobedtm.com *.adobe.io s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com *.magento-ds.com https://rum.hlx.page www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.certcapture.com utt.impactcdn.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.equalweb.com *.sandbox.my.site.com/ *.sandbox.my.salesforce-scrt.com/ *.facebook.net *.tiktok.com/ *.cardinalcommerce.com *.ccdc02.com unpkg.com cdn.jsdelivr.net *.g.doubleclick.net commerce.adobe.net magento-recs-sdk.adobe.net *.bolt.com *.commerce-quick-checkout.com localhost:8082 www.gstatic.com www.google.com *.braintreegateway.com *.sandbox.my.site.com *.sandbox.my.salesforce-scrt.com *.tiktok.com *.clarity.ms *.bing.com *.collect.igodigital.com *.amazon.com https://cdn.equalweb.com https://static.elfsight.com https://unicomer.my.site.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.magento-datasolutions.com *.magento-ds.com *.certcapture.com unsafe-inline assets.braintreegateway.com *.cloudflare.com *.sandbox.my.site.com/ *.adobedtm.com *.cardinalcommerce.com *.ccdc02.com unpkg.com cdn.jsdelivr.net commerce.adobedtm.com www.googleadservices.com www.google-analytics.com *.g.doubleclick.net analytics.google.com www.googletagmanager.com use.typekit.net *.adobe.io *.sentry.io *.sentry-cdn.com *.newrelic.com *.nr-data.net *.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com assets.adobedtm.com commerce.adobe.net magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.bolt.com *.commerce-quick-checkout.com localhost:8082 www.gstatic.com www.google.com js.braintreegateway.com c.paypal.com pay.google.com *.braintreegateway.com *.equalweb.com *.sandbox.my.site.com *.sandbox.my.salesforce-scrt.com *.facebook.net *.tiktok.com *.clarity.ms https://unicomer.my.site.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.snplow.net commerce.adobedc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.magento.com *.adobe.io performance.typekit.net *.magento-datasolutions.com *.magento-ds.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.certcapture.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.adobedc.net *.equalweb.com *.sandbox.my.salesforce-scrt.com/ *.sandbox.my.site.com/ *.tiktok.com/ *.adobedtm.com *.adobe.com *.ccdc02.com unpkg.com cdn.jsdelivr.net commerce.adobedtm.com *.g.doubleclick.net use.typekit.net t.paypal.com assets.adobedtm.com commerce.adobe.net magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com www.vimeo.com *.vimeocdn.com *.youtube.com *.bolt.com *.commerce-quick-checkout.com localhost:8082 www.gstatic.com www.google.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com *.braintreegateway.com *.sandbox.my.site.com *.sandbox.my.salesforce-scrt.com *.facebook.net *.tiktok.com *.clarity.ms *.bing.com https://cdn.equalweb.com https://static.elfsight.com https://access.equalweb.com 'self' 'unsafe-inline'; child-src *.certcapture.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com *.narvar.com *.narvar.qa *.sitevibes.com sitevibes.com *.yotpo.com *.googleapis.com dhv2ziothpgrr.cloudfront.net *.acquiadam.net *.acquiadamcdn.net data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.adyen.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.sitevibes.com sitevibes.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors www.google.com flexreceipts.go2cloud.org 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com *.adyen.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.affirm.com *.affirm.ca *.sitevibes.com sitevibes.com *.trustpilot.com *.yotpo.com https://oc-cdn-ocprod.azureedge.net/livechatwidget/ *.acquiadam.net *.acquiadamcdn.net https://community.511tactical.com/ https://locator.511tactical.com/ *.doubleclick.net *.liadm.com assets.bounceexchange.com flexreceipts.go2cloud.org https://tally.so/ *.pinterest.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.adyen.com *.tiktok.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.affirm.com *.affirm.ca https://s3.amazonaws.com/idme/ https://www.unifaunonline.se https://*.tile.openstreetmap.org/ *.narvar.com *.narvar.qa *.sitevibes.com sitevibes.com *.yotpo.com dhv2ziothpgrr.cloudfront.net *.dynamicyield.com *.riskified.com https://oc-cdn-ocprod.azureedge.net/livechatwidget/ *.acquiadam.net *.acquiadamcdn.net *.511tactical.com *.usablenet.com *.cookielaw.org *.bing.com *.googlesyndication.com *.contextweb.com *.creativecdn.com *.bouncex.net *.pippio.com *.nextdoor.com *.linkedin.com *.twitter.com *.x.com t.co *.lightboxcdn.com *.cdnwidget.com *.attentivemobile.com *.cartfulsolutions.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.adyen.com *.tiktok.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.affirm.com *.affirm.ca https://api.unifaun.com *.sitevibes.com sitevibes.com *.trustpilot.com *.yotpo.com dhv2ziothpgrr.cloudfront.net *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com d18eg7dreypte5.cloudfront.net *.dynamicyield.com *.riskified.com https://oc-cdn-ocprod.azureedge.net/livechatwidget/ *.acquiadam.net *.acquiadamcdn.net *.googleapis.com https://unpkg.com *.cookielaw.org https://rum.hlx.page *.clarity.ms js-agent.newrelic.com bam.nr-data.net *.bing.com *.boomtrain.com *.bounceexchange.com *.rezync.com *.nextdoor.com *.attn.tv events.attentivemobile.com *.pinterest.com s.pinimg.com *.liadm.com *.lightboxcdn.com *.usablenet.com *.wknd.ai *.cartfulsolutions.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com *.sitevibes.com sitevibes.com *.trustpilot.com *.yotpo.com *.googleapis.com dhv2ziothpgrr.cloudfront.net https://oc-cdn-ocprod.azureedge.net/livechatwidget/ *.acquiadam.net *.acquiadamcdn.net *.typekit.net *.googletagmanager.com https://tagmanager.google.com *.bounceexchange.com *.lightboxcdn.com *.cartfulsolutions.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.narvar.com *.narvar.qa *.acquiadam.net *.acquiadamcdn.net 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.adyen.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io *.tiktok.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.affirm.com *.affirm.ca *.sitevibes.com sitevibes.com *.yotpo.com dhv2ziothpgrr.cloudfront.net *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com *.dynamicyield.com *.riskified.com *.trustpilot.com *.acquiadam.net *.acquiadamcdn.net *.googleapis.com *.cookielaw.org *.clarity.ms bam.nr-data.net *.bing.org *.bing.com *.boomtrain.com *.creativecdn.com *.attn.tv *.attentivemobile.com *.tiktokw.us *.linkedin.com *.pinterest.com *.spotify.com *.cartfulsolutions.com 'self' 'unsafe-inline'; child-src flexreceipts.go2cloud.org http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://a4f7e632-ca01-49b1-9c8a-cdf130c36284.sansec.watch/; report-to report-endpoint; 1 default-src https:; script-src https: 'unsafe-inline' https://challenges.cloudflare.com https://cdnjs.cloudflare.com; style-src https: 'unsafe-inline'; frame-src https: https://challenges.cloudflare.com; connect-src https: https://challenges.cloudflare.com https://*.hubspot.com https://*.hsforms.com https://*.hs-scripts.com https://*.hubapi.com; 1 frame-ancestors 'self'; base-uri 'none'; upgrade-insecure-requests; report-uri https://o38422.ingest.sentry.io/api/1381643/security/?sentry_key=035194ae1605493c99dd66c2a7b2ca98; 1 default-src https: 'unsafe-inline' 'unsafe-eval'; img-src https: 'self' data:; font-src https: 'self' data:; 1 default-src 'self' https://*.googleapis.com https://*.google.com https://google.com https://googleads.g.doubleclick.net https://*.doubleclick.net https://stats.g.doubleclick.net https://region1.google-analytics.com https://region1.analytics.google.com https://*.hubspot.com https://app.hubspot.com https://api.hubspot.com https://*.hs-scripts.com https://js-na1.hs-scripts.com https://*.hs-banner.com https://js.hs-banner.com https://*.hscollectedforms.net https://forms.hscollectedforms.net https://*.hs-analytics.net https://*.hsadspixel.net https://*.website-files.com https://cdn.prod.website-files.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://assets.calendly.com https://*.linkedin.com https://get.geojs.io https://api.hubapi.com https://api.murf.ai https://login.murf.ai https://murf.ai https://d3e54v103j8qbb.cloudfront.net https://www.googletagmanager.com https://js.hscollectedforms.net https://js.hsadspixel.net https://js.hs-analytics.net https://js.usemessages.com https://snap.licdn.com https://tracking.g2crowd.com https://tracking-api.g2.com https://www.googleadservices.com https://pagead2.googlesyndication.com https://api.factors.ai https://app.factors.ai https://*.clarity.ms https://bat.bing.com https://bat.bing.net https://www.google-analytics.com https://connect.facebook.net https://www.gstatic.com https://cdn.embedly.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' blob: https://*.googleapis.com https://*.google.com https://google.com https://googleads.g.doubleclick.net https://*.doubleclick.net https://stats.g.doubleclick.net https://region1.google-analytics.com https://region1.analytics.google.com https://*.hubspot.com https://app.hubspot.com https://*.hs-scripts.com https://js-na1.hs-scripts.com https://*.website-files.com https://cdn.prod.website-files.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://assets.calendly.com https://*.linkedin.com https://login.murf.ai https://d3e54v103j8qbb.cloudfront.net https://www.googletagmanager.com https://js.hscollectedforms.net https://js.hsadspixel.net https://js.hs-analytics.net https://js.hs-banner.com https://js.usemessages.com https://snap.licdn.com https://tracking.g2crowd.com https://www.googleadservices.com https://app.factors.ai https://*.clarity.ms https://bat.bing.com https://bat.bing.net https://connect.facebook.net https://www.gstatic.com https://cdn.embedly.com; style-src 'self' 'unsafe-inline' https://*.googleapis.com https://*.google.com https://accounts.google.com https://*.website-files.com https://cdn.prod.website-files.com https://assets.calendly.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://www.gstatic.com https://cdn.embedly.com; font-src 'self' data: https:; img-src 'self' data: https: blob:; media-src 'self' data: blob: https://murf.ai; connect-src 'self' blob: data: https://*.googleapis.com https://*.google.com https://google.com https://stats.g.doubleclick.net https://region1.google-analytics.com https://region1.analytics.google.com https://*.hubspot.com https://app.hubspot.com https://api.hubspot.com https://*.hs-scripts.com https://*.hs-banner.com https://js.hs-banner.com https://*.hscollectedforms.net https://forms.hscollectedforms.net https://*.linkedin.com https://get.geojs.io https://api.hubapi.com https://api.murf.ai https://login.murf.ai https://murf.ai https://cdn.prod.website-files.com https://tracking-api.g2.com https://www.googleadservices.com https://pagead2.googlesyndication.com https://api.factors.ai https://*.clarity.ms https://bat.bing.com https://bat.bing.net https://www.google-analytics.com https://connect.facebook.net https://cdn.embedly.com https://webflow.com; frame-src 'self' https://*.google.com https://www.googletagmanager.com https://googleads.g.doubleclick.net https://*.doubleclick.net https://*.hubspot.com https://app.hubspot.com https://assets.calendly.com https://calendly.com https://login.murf.ai https://cdn.embedly.com; report-uri https://o4504603155759104.ingest.us.sentry.io/api/4509798552305664/security/?sentry_key=05d6eb750229178df61a908e1a0ed8fd; report-to csp-endpoint 1 require-trusted-types-for 'script'; report-uri https://csp.withgoogle.com/csp/youtube-marketing/about_youtube 1 default-src 'self' *.booztlet.com; script-src 'self' data: blob: bat.bing.com t.contentsquare.net geolocation.onetrust.com *.datadoghq.eu *.g.doubleclick.net cdn.taggstar.com cdn.cookielaw.org www.googletagmanager.com chat.kindlycdn.com *.sleeknote.com www.google.com *.hotjar.com www.snapengage.com 7276579.collect.igodigital.com *.trustpilot.com static.cloudflareinsights.com *.liveshopper.net sleeknotestaticcontent.sleeknote.com cdn.avo.app *.criteo.com track.adform.net *.klarnacdn.net *.criteo.net connect.facebook.net maps.googleapis.com *.hotjar.io cdn.noibu.com www.googleoptimize.com *.datadog.eu *.booztcdn.com *.kronor.io www.datadoghq-browser-agent.com *.google-analytics.com www.googleadservices.com s2.adform.net dev.visualwebsiteoptimizer.com svht.tradedoubler.com sdk.privacy-center.org analytics.tiktok.com sleeknotecustomerscripts.sleeknote.com 'unsafe-eval' 'unsafe-inline'; font-src 'self' *.booztcdn.com fonts.gstatic.com *.booztlet.com *.booztx.com chat.kindlycdn.com fonts.googleapis.com data: ; img-src optimize.google.com https: data: blob: 'unsafe-inline'; connect-src 'self' data: *.visualwebsiteoptimizer.com *.datadoghq.eu *.kronor.io wss://*.kronor.io *.google-analytics.com www.googleadservices.com www.googleoptimize.com api.mkmediaworks.com www.googletagmanager.com api.taggstar.com bat.bing.com *.contentsquare.net kronor.io api.liveshopper.net analytics.tiktok.com cdn.avo.app wss://kronor.io input.noibu.com *.hotjar.com www.google.com www.googleadservices.com stats.g.doubleclick.net www.facebook.com geolocation.onetrust.com *.datadog.eu cdn.cookielaw.org *.hotjar.io *.hotjar.com browser-intake-datadoghq.eu wss://input.noibu.com pagead2.googlesyndication.com *.booztlet.com *.sleeknote.com *.klarnacdn.net *.trustpilot.com *.g.doubleclick.net www.snapengage.com ws.hotjar.com chat.kindlycdn.com *.booztcdn.com www.datadoghq-browser-agent.com *.booztlet.com *.browser-intake-datadoghq.eu dev.visualwebsiteoptimizer.com; child-src 'self' www.googletagmanager.com *.freshchat.com fpt.booztlet.com *.google-analytics.com *.criteo.net www.booztlet.com www.facebook.com *.trustpilot.com blob: ; frame-src 'self' *.kronor.io *.criteo.com *.criteo.com *.sleeknote.com www.googletagmanager.com www.facebook.com *.trustpilot.com *.klarnacdn.net *.hotjar.com connect.facebook.net; style-src 'self' *.sleeknote.com *.booztlet.com cdn.taggstar.com *.booztcdn.com *.kronor.io chat.kindlycdn.com data: blob: 'unsafe-inline'; manifest-src 'self' *.booztlet.com; media-src 'self' data: *.booztcdn.com *.booztlet.com storage.googleapis.com; frame-ancestors 'self' ; report-uri /csp-report/; report-to csp-reports 1 report-uri /csp/report 'self'; default-src 'self'; script-src 'self' *.googleapis.com *.gstatic.com www.google.com apis.google.com *.google-analytics.com connect.facebook.net ajax.aspnetcdn.com https://www.youtube.com platform.twitter.com https://syndication.twitter.com/ https://s.ytimg.com https://publish.twitter.com *.twimg.com platform.linkedin.com http://platform.stumbleupon.com/1/widgets.js https://*.googletagmanager.com cdnjs.cloudflare.com 'unsafe-inline' 'unsafe-eval' web-chat.nativechat.com cdn.ampproject.org; style-src 'self' *.googleapis.com *.gstatic.com netdna.bootstrapcdn.com kendo.cdn.telerik.com www.google.com platform.twitter.com/css/ *.twimg.com 'unsafe-inline' web-chat.nativechat.com; img-src *.gstatic.com *.googleapis.com platform.tumblr.com web.facebook.com www.facebook.com www.redditstatic.com www.linkedin.com i.ytimg.com https://syndication.twitter.com https://static.licdn.com/scds/common/u/images/apps/connect/sprites/sprite_connect_v14.png pbs.twimg.com platform.twitter.com/css/ *.twimg.com data: blob: https://*.googletagmanager.com https://*.onetrust.com https://www.google-analytics.com 'self' web-chat.nativechat.com; font-src 'self' fonts.gstatic.com kendo.cdn.telerik.com netdna.bootstrapcdn.com data:; frame-src 'self' https://platform.twitter.com/ https://syndication.twitter.com/ https://www.youtube.com/ https://www.youtube-nocookie.com https://player.vimeo.com/ https://w.soundcloud.com/ apis.google.com accounts.google.com staticxx.facebook.com www.facebook.com web.facebook.com badge.stumbleupon.com web-chat.nativechat.com; connect-src 'self' data: accounts.google.com *.google-analytics.com *.gstatic.com https://*.googletagmanager.com https://*.analytics.google.com https://*.onetrust.com https://stats.g.doubleclick.net https://*.googlesyndication.com https://www.google.com; media-src 'self' data: blob:; child-src 'self' web-chat.nativechat.com; script-src-elem 'unsafe-inline' https://cdnjs.cloudflare.com *.googletagmanager.com https://ajax.aspnetcdn.com https://googleads.g.doubleclick.net https://*.onetrust.com https://www.clarity.ms https://s.pinimg.com https://connect.facebook.net https://cdn-images.mailchimp.com https://www.google-analytics.com https://platform-api.sharethis.com 'self'; style-src-elem 'unsafe-inline' https://cdn-images.mailchimp.com 'self'; frame-ancestors 'self'; worker-src blob 'self' 1 object-src 'none';base-uri 'self';script-src 'nonce-AThOm7X0yCHXZYym2RJIpw' 'strict-dynamic' 'report-sample' 'unsafe-eval' 'unsafe-inline' https: http:;report-uri https://csp.withgoogle.com/csp/gws/other-hp 1 worker-src blob:; font-src fonts.gstatic.com *.kxcdn.com *.fontawesome.com principiaskin.com *.principiaskin.com https://fonts.gstatic.com https://www.google.com https://www.gstatic.com *.gstatic.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.facebook.com *.pinterest.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ facebook.com www.facebook.com *.kxcdn.com youtube.com www.youtube.com platform.twitter.com google.com *.addthis.com *.mercadolibre.com *.weltpixel.com connect.facebook.net graph.facebook.com business.facebook.com *.facebook.com *.authorize.net *.google.com *.paypal.com *.freshchat.com *.pagseguro.uol.com.br *.doubleclick.net *.pinterest.com *.principiacosmeticos.com principiaskin.com *.principiaskin.com *.googletagmanager.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com *.ftcdn.net *.behance.net *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io scontent.cdninstagram.com *.kxcdn.com *.twitter.com *.googleapis.com google.com *.gstatic.com *.mlstatic.com *.mercadopago.com *.mercadolibre.com *.mercadolivre.com.br *.mercadolibre.com.mx *.mercadolibre.com.ar www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.apptrian.com *.instagram.com *.magentocommerce.com *.ytimg.com s.ytimg.com *.pinterest.com *.googleadservices.com *.google.com *.google.com.br *.google.it *.google-analytics.com www.paypalobjects.com *.paypalobjects.com *.paypal.com www.paypal.com t.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.ftcdn.com *.behance.com *.pagseguro.com/ *.apptrian.com *.mercadolivre.com *.yotpo.com *.adobedtm.com *.demdex.net *.everesttech.net assets.braintreegateway.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com c.paypal.com checkout.paypal.com https://pagseguro.uol.com.br https://sandbox.pagseguro.uol.com.br https://stc.pagseguro.uol.com.br https://sandbox.stc.pagseguro.uol.com.br *.doubleclick.net *.onesignal.com *.principiacosmeticos.com principiaskin.com *.principiaskin.com *.googletagmanager.com https://principiacosmeticos.com/mtracking.gif https://www.google.com.ar/ads/ga-audiences https://www.google.com.ar/pagead/1p-user-list/700931334/ https://principiaskincare.com.br/mtracking.gif https://t.co/1/i/adsct *.facebook.com content.app-us1.com cdn.jsdelivr.net *.cloudfront.net *.hsforms.net *.hsforms.com 'self' data: data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.googleapis.com google.com *.gstatic.com cdn.ampproject.org connect.facebook.net www.googletagmanager.com googletagmanager.com *.kxcdn.com platform.twitter.com *.addthis.com *.addthisedge.com *.moatads.com *.mlstatic.com www.facebook.com graph.facebook.com business.facebook.com www.apptrian.com *.freshchat.com *.google.com *.google-analytics.com *.facebook.com *.adobedtm.com *.authorize.net *.braintreegateway.com *.cardinalcommerce.com *.paypal.com www.paypal.com *.ytimg.com *.googleadservices.com *.paypalobjects.com www.paypalobjects.com *.vimeo.com www.youtube.com *.viacep.com.br *.apptrian.com *.polyfill.io *.cloudflare.com *.pagseguro.uol.com.br *.tiktok.com *.pinimg.com *.mercadopago.com *.doubleclick.net *.ccdc02.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com cdn.dnky.co api.comapi.com webchat.dotdigital.com *.avada.io pay.google.com *.yotpo.com *.onesignal.com https://onesignal.com/api/v1/sync/980b27db-f331-407d-8b91-7ea1ff79c577/web *.principiacosmeticos.com https://principiacosmeticos.com/mtc.js *.k-analytix.com principiaskin.com *.principiaskin.com *.cloudflareinsights.com https://designestylelab.com/css/ https://analytics-manager.com/an https://analytics-manager.com/an/ https://principiaskincare.com.br/mtc.js https://static.cloudflareinights.com/beacon.min.js/v52afc6f149f6479b8c77fa569edb01181681764108816 *.ads-twitter.com/uwt.js *.pinterest.com diffuser-cdn.app-us1.com prism.app-us1.com *.activehosted.com trackcmp.net cdn.jsdelivr.net *.hsforms.net *.hsforms.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.googleapis.com google.com *.kxcdn.com *.gstatic.com *.fontawesome.com *.freshchat.com fonts.googleapis.com *.mercadopago.com getfirebug.com cdn.dnky.co webchat.dotdigital.com *.yotpo.com *.onesignal.com https://onesignal.com/sdks/OneSignalSDKStyles.css *.principiacosmeticos.com principiaskin.com *.principiaskin.com *.googletagmanager.com *.google.com cdn.jsdelivr.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com https://www.paypal.com/xoplatform/logger/api/logger cdn.ampproject.org *.kxcdn.com *.mercadopago.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.rastreio.alfatracking.com.br *.tracking.totalexpress.com.br *.rastreio.fmtransportes.com.br *.correios.com.br www.apptrian.com *.instagram.com *.pinterest.com *.apptrian.com *.polyfill.io *.cloudflare.com *.paypal.com *.pinimg.com *.tiktok.com *.google.com *.google.com.br *.google.it https://www.google.com.br/ads/ga-audiences https://www.google.it/ads/ga-audiences *.google-analytics.com *.doubleclick.net *.yotpo.com *.mercadolibre.com *.onesignal.com https://onesignal.com/api/v1/apps/980b27db-f331-407d-8b91-7ea1ff79c577/icon *.principiacosmeticos.com https://principiacosmeticos.com/mtc/event *.konduto.com principiaskin.com *.principiaskin.com *.googleapis.com *.viacep.com.br https://viacep.com.br/ws/ viacep.com.br/ws *.amcglobal.sc.omtrdc.net *.geostag.cardinalcommerce.com *.geo.cardinalcommerce.com *.1eafstag.cardinalcommerce.com *.1eaf.cardinalcommerce.com *.centinelapistag.cardinalcommerce.com *.centinelapi.cardinalcommerce.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com *.api.comapi.com *.webchat.dotdigital.com *.ekr.zdassets.com *.braintreegateway.com *.braintree-api.com https://principiaskincare.com.br/mtc/event https://pagead2.googlesyndication.com/pagead/buyside_topics/set/ analytics.pangle-ads.com https://google.com/ccm/form-data/700931334 https://google.com/pagead/form-data/700931334 analytics-ipv6.tiktokw.us http://dpm.demdex.net https://www.google.com https://www.gstatic.com https://get.geojs.io *.avada.io *.activehosted.com t.elasticsuite.io *.hsforms.net *.hsforms.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri csp-reporting/; report-to report-endpoint; 1 font-src *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com player.vimeo.com https://www.google.com/recaptcha/ 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.b0e8.com magefan.com cm.magefan.com *.bc0a.com *.elotouch.com www.elotouch.com elotouch.com *.google.lv data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.b0e8.com *.bc0a.com *.recaptcha.net *.simpli.fi *.zi-scripts.com siteimproveanalytics.com *.pardot.com *.elotouch.com *.jsdelivr.net unpkg.com *.cloudflare.com *.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.fontawesome.com hello.myfonts.net *.cloudflare.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.elotouch.com elotouch.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.doubleclick.net *.zi-scripts.com *.zoominfo.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.googleapis.com *.gstatic.com 'unsafe-inline' data: https://www.googletagmanager.com maxcdn.bootstrapcdn.com apps.mypurecloud.com use.typekit.net static.klaviyo.com *.silencershop.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.authorize.net *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.credova.com *.authorize.net 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.google.com *.credova.com * *.authorize.net c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com https://www.youtube.com https://c.paypal.com/ https://*.online-metrix.net https://imgs.signifyd.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.gstatic.com *.googleapis.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ magefan.com cm.magefan.com store.paradoxlabs.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.silencershop.com *.signifyd.com *.online-metrix.net/ data.adxcel-ec2.com engine.gettopple.com trkn.us *.cloudfront.net https://b.stats.paypal.com/ https://slc.stats.paypal.com/ https://c.paypal.com/ https://imgs.signifyd.com https://*.online-metrix.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.googleapis.com *.gstatic.com tagmanager.google.com https://www.googletagmanager.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.credova.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ cdn.jsdelivr.net *.authorize.net js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.silencershop.com apps.usw2.pure.cloud *.signifyd.com delivery.gettopple.com *.online-metrix.net d14jnfavjicsbe.cloudfront.net sleeknotecustomerscripts.sleeknote.com sleeknotestaticcontent.sleeknote.com sec.webeyez.com widget.trustpilot.com *.fontawesome.com *.google-analytics.com https://bam.nr-data.net https://bam-cell.nr-data.net https://c.paypal.com https://cdn-scripts.signifyd.com https://imgs.signifyd.com https://h64.online-metrix.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://www.googletagmanager.com tagmanager.google.com *.googleapis.com https://static.klaviyo.com cdn.jsdelivr.net maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com apps.mypurecloud.com use.typekit.net p.typekit.net *.silencershop.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io *.googleapis.com https://www.google-analytics.com *.credova.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ api.addressy.com *.authorize.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.silencershop.com *.signifyd.com invitejs.trustpilot.com send.webeyez.com sec.webeyez.com *.google-analytics.com https://bam.nr-data.net https://bam-cell.nr-data.net https://payments.sandbox.braintree-api.com/ https://origin-analytics-sand.sandbox.braintree-api.com/ https://imgs.signifyd.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://smartsolutions.report-uri.com/r/d/csp/reportOnly; report-to report-endpoint; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://*.gstatic.com *.fontawesome.com *.alicdn.com *.rockler.com *.slant.co data: 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.adyen.com pay.google.com payments-eu.amazon.com *.amazon.de *.cordialdev.com *.cordial.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com 'self' 'unsafe-inline'; frame-ancestors *.certcapture.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com *.adyen.com pay.google.com *.certcapture.com *.cordialdev.com *.cordial.com *.cordial.io www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com c.paypal.com checkout.paypal.com assets.braintreegateway.com *.cardinalcommerce.com * photos.pixlee.co https://photos.pixlee.co landofcoder.com *.weltpixel.com *.googletagmanager.com *.doubleclick.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.adyen.com pay.google.com *.payments-amazon.com *.media-amazon.com *.paypalobjects.com https://*.gstatic.com *.certcapture.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.googleapis.com *.disqus.com https://img.youtube.com store.paradoxlabs.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com wac.edgecastcdn.net *.lightboxcdn.com https://hello.zonos.com https://a.tile.openstreetmap.org https://b.tile.openstreetmap.org https://c.tile.openstreetmap.org *.facebook.com *.reddit.com *.google-analytics.com *.googletagmanager.com *.doubleclick.net *.google.com *.1rx.io *.360yield.com *.3lift.com *.adnxs.com *.attentivemobile.com *.attn.tv *.bing.com *.bing.net *.casalemedia.com *.clarity.ms *.cookiebot.com *.cordial.com *.creativecdn.com d3cgm8py10hi0z.cloudfront.net *.facebook.net *.ggpht.com *.googleadservices.com www.google.ad www.google.ae www.google.al www.google.am www.google.at www.google.az www.google.ba www.google.be www.google.bf www.google.bg www.google.bj www.google.bs www.google.bt www.google.by www.google.ca www.google.cd www.google.cg www.google.ch www.google.ci www.google.cl www.google.cm www.google.co.ao www.google.co.bw www.google.co.cr www.google.co.id www.google.co.il www.google.co.in www.google.co.jp www.google.co.ke www.google.co.kr www.google.co.ls www.google.co.ma www.google.com.ag www.google.com.ar www.google.com.au www.google.com.bd www.google.com.bh www.google.com.bn www.google.com.bo www.google.com.br www.google.com.bz www.google.com.co www.google.com.cy www.google.com.do www.google.com.ec www.google.com.eg www.google.com.et www.google.com.fj www.google.com.gh www.google.com.gi www.google.com.gt www.google.com.hk www.google.com.jm www.google.com.kh www.google.com.kw www.google.com.lb www.google.com.ly www.google.com.mm www.google.com.mt www.google.com.mx www.google.com.my www.google.com.na www.google.com.ng www.google.com.ni www.google.com.np www.google.com.om www.google.com.pa www.google.com.pe www.google.com.pg www.google.com.ph www.google.com.pk www.google.com.pr www.google.com.py www.google.com.qa www.google.com.sa www.google.com.sg www.google.com.sl www.google.com.sv www.google.com.tr www.google.com.tw www.google.com.ua www.google.com.uy www.google.com.vc www.google.com.vn www.google.co.mz www.google.co.nz www.google.co.th www.google.co.tz www.google.co.ug www.google.co.uk www.google.co.uz www.google.co.ve www.google.co.vi www.google.co.za www.google.co.zm www.google.co.zw www.google.cz www.google.de www.google.dk www.google.dm www.google.dz www.google.ee www.google.es www.google.fi www.google.fm www.google.fr www.google.ga www.google.ge www.google.gg www.google.gl www.google.gm www.google.gr www.google.gy www.google.hn www.google.hr www.google.ht www.google.hu www.google.ie www.google.im www.google.iq www.google.is www.google.it www.google.je www.google.jo www.google.ki www.google.kz www.google.la www.google.li www.google.lk www.google.lt www.google.lu www.google.lv www.google.md www.google.me www.google.mg www.google.mk www.google.ml www.google.mn www.google.mu www.google.mv www.google.mw www.google.nl www.google.no www.google.nr www.google.pl www.google.ps www.google.pt www.google.ro www.google.rs www.google.ru www.google.rw www.google.sc www.google.se www.google.sh www.google.si www.google.sk www.google.sn www.google.so www.google.sr www.google.tg www.google.tm www.google.tn www.google.tt google.com *.googlesyndication.com *.gumgum.com *.inmobi.com *.lijit.com *.media.net *.nexx360.io *.openx.net *.opera.com *.outbrain.com *.pinterest.com *.pubmatic.com *.rakuten.com *.rockler.com *.rubiconproject.com *.searchspring.io *.searchspring.net *.sharethrough.com *.smaato.net *.smartadserver.com *.sonobi.com *.taboola.com *.teads.tv *.turnto.com yastatic.net *.yieldmo.com *.ytimg.com *.zonos.com data: 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com *.attn.tv events.attentivemobile.com *.certcapture.com *.cordialdev.com *.cordial.com track.cordial.io www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com maps.googleapis.com utt.impactcdn.com *.disqus.com *.authorize.net js.braintreegateway.com assets.braintreegateway.com c.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com *.googleapis.com https://cdn.searchspring.net *.turnto.com https://checkoutshopper-test.adyen.com *.lightboxcdn.com *.news.rockler.com https://hello.zonos.com cdn.searchspring.net https://widgets.turnto.com we.turnto.com landofcoder.com *.googletagmanager.com *.googleadservices.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com unpkg.com *.doubleclick.net *.bing.com *.blackfire.io *.clarity.ms *.cookiebot.com *.crazyegg.com *.creativecdn.com *.googlesyndication.com *.mountain.com *.pinimg.com *.pinterest.com *.rockler.com *.searchspring.io *.searchspring.net *.vimeo.com *.zonos.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; style-src *.adobe.com fonts.googleapis.com https://fonts.googleapis.com/ *.certcapture.com *.gstatic.com *.googleapis.com *.fontawesome.com assets.braintreegateway.com *.turnto.com cdn.searchspring.net https://widgets.turnto.com *.tagmanager.google.com *.googletagmanager.com *.lightboxcdn.com *.rockler.com *.searchspring.net 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; object-src landofcoder.com 'self' 'unsafe-inline'; media-src *.adobe.com *.gstatic.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.adyen.com payments-eu.amazon.com *.attn.tv events.attentivemobile.com *.certcapture.com *.cordialdev.com *.cordial.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com maps.googleapis.com *.authorize.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.turnto.com apay-us.amazon.com *.google-analytics.com https://hello.zonos.com https://*.a.searchspring.io https://cdn-ws.turnto.com landofcoder.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.doubleclick.net *.run.app *.rockler.com 100.20.58.101 18.210.229.244 3.212.39.155 34.215.155.61 35.160.46.251 44.212.189.233 44.228.85.26 44.238.122.172 52.22.50.55 52.71.121.170 54.156.2.105 *.alicdn.com *.attentivemobile.com *.bing.com *.bing.net *.clarity.ms *.cookiebot.com *.crazyegg.com *.creativecdn.com *.facebook.com *.googleadservices.com *.googleapis.com www.google.ae www.google.al www.google.am www.google.at www.google.az www.google.ba www.google.be www.google.bf www.google.bg www.google.bj www.google.bs www.google.bt www.google.by www.google.ca www.google.cd www.google.ch www.google.ci www.google.cl www.google.cm www.google.co.ao www.google.co.bw www.google.co.cr www.google.co.id www.google.co.il www.google.co.in www.google.co.jp www.google.co.ke www.google.co.kr www.google.co.ls www.google.co.ma www.google.com.ag www.google.com.ar www.google.com.au www.google.com.bd www.google.com.bh www.google.com.bn www.google.com.bo www.google.com.br www.google.com.bz www.google.com.co www.google.com.cy www.google.com.do www.google.com.ec www.google.com.eg www.google.com.et www.google.com.fj www.google.com.gh www.google.com.gi www.google.com.gt www.google.com.hk www.google.com.jm www.google.com.kh www.google.com.kw www.google.com.lb www.google.com.mm www.google.com.mt www.google.com.mx www.google.com.my www.google.com.na www.google.com.ng www.google.com.ni www.google.com.np www.google.com.om www.google.com.pa www.google.com.pe www.google.com.pg www.google.com.ph www.google.com.pk www.google.com.pr www.google.com.py www.google.com.qa www.google.com.sa www.google.com.sg www.google.com.sv www.google.com.tr www.google.com.tw www.google.com.ua www.google.com.uy www.google.com.vc www.google.com.vn www.google.co.mz www.google.co.nz www.google.co.th www.google.co.tz www.google.co.ug www.google.co.uk www.google.co.uz www.google.co.ve www.google.co.vi www.google.co.za www.google.co.zm www.google.co.zw www.google.cz www.google.de www.google.dk www.google.dm www.google.dz www.google.ee www.google.es www.google.fi www.google.fm www.google.fr www.google.ga www.google.ge www.google.gg www.google.gl www.google.gm www.google.gr www.google.gy www.google.hn www.google.hr www.google.hu www.google.ie www.google.iq www.google.is www.google.it www.google.je www.google.jo www.google.kz www.google.li www.google.lk www.google.lt www.google.lu www.google.lv www.google.md www.google.me www.google.mg www.google.mk www.google.mn www.google.mu www.google.mv www.google.nl www.google.no www.google.pl www.google.ps www.google.pt www.google.ro www.google.rs www.google.ru www.google.rw www.google.sc www.google.se www.google.sh www.google.si www.google.sk www.google.sn www.google.so www.google.sr www.google.tg www.google.tm www.google.tt *.googlesyndication.com *.gstatic.com *.lightboxcdn.com *.pinterest.com *.searchspring.io *.searchspring.net *.zonos.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; child-src *.certcapture.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://a5cc4e91-2050-4411-835a-70713844fbf7.sansec.watch/; report-to report-endpoint; 1 default-src https://*.amazon.com https://*.media-amazon.com https://*.ssl-images-amazon.com https://*.amazon-adsystem.com https://*.paa-reporting-advertising.amazon https://*.twitch.tv https://*.amazongamestudios.com https://*.amazongames.com https://*.awsstatic.com https://amazonwebservices.d2.sc.omtrdc.net https://amazongamestudios.d2.sc.omtrdc.net https://*.viddler.com https://*.ctfassets.net https://chat.amazon.eu https://chat.amazon.co.jp https://sentry.amazongames.com https://d13pe3bn1jpqwf.cloudfront.net; script-src 'nonce-9d56b42da3de474c881c803f556aa243' https://*.amazon.com https://*.media-amazon.com https://*.ssl-images-amazon.com https://*.amazon-adsystem.com https://*.paa-reporting-advertising.amazon https://*.twitch.tv https://*.amazongamestudios.com https://*.amazongames.com https://*.awsstatic.com https://amazonwebservices.d2.sc.omtrdc.net https://amazongamestudios.d2.sc.omtrdc.net https://*.viddler.com https://*.ctfassets.net https://chat.amazon.eu https://chat.amazon.co.jp https://sentry.amazongames.com https://d13pe3bn1jpqwf.cloudfront.net; style-src 'self' 'nonce-9d56b42da3de474c881c803f556aa243' https://*.amazon.com https://*.media-amazon.com https://*.ssl-images-amazon.com https://*.amazon-adsystem.com https://*.paa-reporting-advertising.amazon https://*.twitch.tv https://*.amazongamestudios.com https://*.amazongames.com https://*.awsstatic.com https://amazonwebservices.d2.sc.omtrdc.net https://amazongamestudios.d2.sc.omtrdc.net https://*.viddler.com https://*.ctfassets.net https://chat.amazon.eu https://chat.amazon.co.jp https://sentry.amazongames.com https://d13pe3bn1jpqwf.cloudfront.net; img-src 'self' data: https://*.amazon.com https://*.media-amazon.com https://*.ssl-images-amazon.com https://*.amazon-adsystem.com https://*.paa-reporting-advertising.amazon https://*.twitch.tv https://*.amazongamestudios.com https://*.amazongames.com https://*.awsstatic.com https://amazonwebservices.d2.sc.omtrdc.net https://amazongamestudios.d2.sc.omtrdc.net https://*.viddler.com https://*.ctfassets.net https://chat.amazon.eu https://chat.amazon.co.jp https://sentry.amazongames.com https://d13pe3bn1jpqwf.cloudfront.net https://*.twimg.com https://player.twitch.tv/ https://*.ytimg.com; media-src 'self' data: https://*.amazon.com https://*.media-amazon.com https://*.ssl-images-amazon.com https://*.amazon-adsystem.com https://*.paa-reporting-advertising.amazon https://*.twitch.tv https://*.amazongamestudios.com https://*.amazongames.com https://*.awsstatic.com https://amazonwebservices.d2.sc.omtrdc.net https://amazongamestudios.d2.sc.omtrdc.net https://*.viddler.com https://*.ctfassets.net https://chat.amazon.eu https://chat.amazon.co.jp https://sentry.amazongames.com https://d13pe3bn1jpqwf.cloudfront.net https://*.twimg.com https://player.twitch.tv/ https://www.youtube.com https://youtube.com https://*.googlevideo.com; frame-src https://www.youtube.com https://youtube.com https://*.googlevideo.com https://*.twimg.com https://player.twitch.tv/ https://*.amazon.com https://*.media-amazon.com https://*.ssl-images-amazon.com https://*.amazon-adsystem.com https://*.paa-reporting-advertising.amazon https://*.twitch.tv https://*.amazongamestudios.com https://*.amazongames.com https://*.awsstatic.com https://amazonwebservices.d2.sc.omtrdc.net https://amazongamestudios.d2.sc.omtrdc.net https://*.viddler.com https://*.ctfassets.net https://chat.amazon.eu https://chat.amazon.co.jp https://sentry.amazongames.com https://d13pe3bn1jpqwf.cloudfront.net; report-uri https://www.amazon.com/1/batch/2/OE/mid=ATVPDKIKX0DER:sid=135-6905109-3288869:rid=A45E377D75264A46B67E:sn=www.amazongamestudios.com 1 script-src 'self' 'unsafe-eval' 'unsafe-hashes' 'unsafe-inline' https://www.google.com/recaptcha/api.js https://www.googletagmanager.com https://polyfill.io https://www.youtube.com https://iframe.dacast.com https://vimeo.com https://player.vimeo.com https://cdn.usefathom.com/script.js https://cc.cdn.civiccomputing.com/9/cookieControl-9.x.min.js https://analytics.ahrefs.com/analytics.js https://wttc.activehosted.com 'nonce-lkV4NIRgJ/dsf1E5nw1wZ5/aWzr1VOUfmUoBJrvmbAg='; img-src 'self' https:; connect-src 'self' https:; frame-src 'self' https://www.google.com https://www.youtube.com https://iframe.dacast.com https://vimeo.com https://player.vimeo.com https://gtm-knbshpt-zmy5y.uc.r.appspot.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com/css2 https://use.typekit.net https://p.typekit.net https://fonts.bunny.net; font-src 'self' https: data: 1 default-src 'self'; script-src 'self' 'nonce-PTQZykm0mFTcuxcSpaUxmw==' 'unsafe-eval' cdn.sidefx.com static.sidefx.com media.sidefx.com d2wvmrjymyrujw.cloudfront.net *.googleapis.com www.gstatic.com www.google.com cse.google.com *.facebook.net api.instagram.com cdnjs.cloudflare.com unpkg.com cdn.jsdelivr.net *.googletagmanager.com tagmanager.google.com www.google-analytics.com stats.g.doubleclick.net analytics.google.com vimeo.com *.vimeo.com *.vimeocdn.com *.newrelic.com *.nr-data.net www.youtube.com www.paypal.com www.sandbox.paypal.com sidefx.bamboohr.com https://hcaptcha.com https://*.hcaptcha.com forms.copper.com; frame-src 'self' data: static.sidefx.com media.sidefx.com www.google.com connect.facebook.net www.facebook.net www.facebook.com docs.google.com maps.google.com www.youtube.com lists.sidefx.com *.vimeo.com *.vimeocdn.com www.sandbox.paypal.com www.paypal.com https://hcaptcha.com https://*.hcaptcha.com; style-src 'self' 'unsafe-inline' cdn.sidefx.com static.sidefx.com d2wvmrjymyrujw.cloudfront.net media.sidefx.com fonts.googleapis.com www.google.com tagmanager.google.com *.vimeocdn.com www.gstatic.com https://hcaptcha.com https://*.hcaptcha.com; font-src 'self' data: cdn.sidefx.com static.sidefx.com media.sidefx.com fonts.gstatic.com; img-src 'self' data: cdn.sidefx.com static.sidefx.com media.sidefx.com d2wvmrjymyrujw.cloudfront.net *.cdninstagram.com *.gravatar.com www.facebook.com static.lulu.com www.gstatic.com ssl.gstatic.com www.googleapis.com i.ytimg.com *.vimeocdn.com www.paypal.com t.paypal.com www.paypalobjects.com placekitten.com http://dummyimage.com resources.bamboohr.com connect.facebook.com connect.facebook.net placehold.co *.google.com www.googletagmanager.com www.google-analytics.com stats.g.doubleclick.net; connect-src 'self' *.google-analytics.com *.google.com *.googletagmanager.com stats.g.doubleclick.net www.facebook.com ig.instant-tokens.com graph.instagram.com vimeo.com www.sandbox.paypal.com www.paypal.com sidefx.bamboohr.com https://hcaptcha.com https://*.hcaptcha.com forms.copper.com; media-src www.sidefx.com cdn.sidefx.com static.sidefx.com media.sidefx.com d2wvmrjymyrujw.cloudfront.net; report-uri /csp-report/ 1 font-src fonts.gstatic.com use.typekit.net *.googleadservices.com *.googleapis.com *.fontawesome.com *.gstatic.com *.rezync.com *.nothingbundtcakes.com tags-prod.nothingbundtcakes.com *.toasttab.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.demdex.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.google.com www.googletagmanager.com *.rezync.com *.googleadservices.com *.doubleclick.net *.vimeo.com *.facebook.com *.nothingbundtcakes.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net *.googleadservices.com *.google.com *.google.com.ca *.google.com.co *.googleapis.com *.gstatic.com *.vimeo.com *.cdn-apple.com *.cookielaw.org *.usablenet.com *.usablenet.dev *.doubleclick.net *.contentsquare.net *.nothingbundtcakes.com *.pmg.com *.pinimg.com *.adroll.com *.facebook.net *.bing.com *.redditstatic.com *.amazonaws.com *.cognitivlabs.com *.reddit.com *.facebook.com *.adnxs.com *.magentosite.cloud *.monetate.net *.rfihub.com *.eyeota.net *.rezync.com *.attn.tv *.yimg.com *.boomtrain.com *.linkedin.com *.yahoo.com *.pubmatic.com *.openx.net *.media.net *.rtactivate.com *.casalemedia.com *.rlcdn.com *.addthis.com *.tremorhub.com *.bidswitch.net *.adsrvr.org *.prf.hn prf.hn *.taggrs.io taggrs.io *.ml314.com ml314.com *.tapad.com tapad.com tags-prod.nothingbundtcakes.com *.toasttab.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.gstatic.com https://www.google.com/recaptcha/ assets.adobedtm.com *.magento-datasolutions.com *.magento-ds.com *.attn.tv events.attentivemobile.com *.googleadservices.com *.googleapis.com *.cdn-apple.com *.cookielaw.org *.usablenet.com *.usablenet.dev *.contentsquare.net *.nothingbundtcakes.com *.pmg.com *.pinimg.com *.adroll.com *.facebook.net *.bing.com *.redditstatic.com *.tiktok.com *.bttrack.com *.adsrvr.org *.pinterest.com *.facebook.com *.magentosite.cloud *.monetate.net *.appboycdn.com *.rfihub.com *.everesttech.net *.eyeota.net *.rezync.com *.yimg.com *.boomtrain.com *.yahoo.com *.kargo.com *.licdn.com *.inpwrd.net bttrack.com *.adnxs.com *.rfihub.net cdn.bttrack.com tags-prod.nothingbundtcakes.com *.toasttab.com https://gateway.moneris.com https://gatewayt.moneris.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.magento-datasolutions.com *.magento-ds.com *.googleadservices.com *.googleapis.com *.fontawesome.com *.usablenet.com *.usablenet.dev *.rezync.com *.nothingbundtcakes.com tags-prod.nothingbundtcakes.com *.toasttab.com https://gateway.moneris.com https://gatewayt.moneris.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.magento.com performance.typekit.net *.magento-datasolutions.com *.magento-ds.com *.adobe.io *.attn.tv events.attentivemobile.com *.googleadservices.com *.googleapis.com *.vimeo.com *.cdn-apple.com *.cookielaw.org *.onetrust.com *.usablenet.com *.usablenet.dev *.contentsquare.net *.doubleclick.net *.nothingbundtcakes.com *.pmg.com *.pinimg.com *.adroll.com *.facebook.net *.bing.com *.redditstatic.com *.tiktok.com *.bttrack.com *.adsrvr.org *.amazonaws.com *.cognitivlabs.com *.reddit.com *.pinterest.com *.facebook.com *.adnxs.com *.gstatic.com *.rlcdn.com *.magentosite.cloud *.monetate.net *.everesttech.net *.eyeota.net *.rezync.com *.yimg.com *.boomtrain.com *.yahoo.com *.kargo.com *.linkedin.com tags-prod.nothingbundtcakes.com *.toasttab.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' 'unsafe-inline'; script-src 'self' 'unsafe-eval' 'unsafe-inline'; style-src 'self' 'unsafe-inline'; img-src * data: blob:; 1 default-src 'self' https: data: blob:; script-src 'self' https: 'unsafe-inline' 'unsafe-eval' blob:; style-src 'self' https: 'unsafe-inline' data: blob:; img-src 'self' https: data: blob:; font-src 'self' https: data: blob: chrome-extension: moz-extension: ms-browser-extension: safari-extension:; connect-src 'self' https: wss:; frame-ancestors 'self'; form-action 'self'; report-uri /api_v2/csp/report 1 default-src 'self'; connect-src 'self' *.hotjar.com *.hotjar.io c.amazon-adsystem.com *.wistia.net *.wistia.com js.monitor.azure.com snap.licdn.com www.googletagmanager.com www.google.com *.doubleclick.net analytics.google.com *.givchariot.com d.adroll.com dc.services.visualstudio.com insight.adsrvr.org *.linkedin.com s.amazon-adsystem.com doublethedonation.com js.monitor.azure.com; font-src 'self' data: cdn.givechariot.com fast.wistia.net doublethedonation.com; frame-src 'self' *.adsrvr.org *.adroll.com www.googletagmanager.com www.gstatic.com *.doubleclick.net *.wistia.net *.ceros.com wwp.mysalesforce-sites.com www.careerarc.com www.google.com www.youtube.com wwp.my.salesforce-sites.com; img-src 'self' data: *.adroll.com *.doubleclick.net *.lightboxcdn.com *.wistia.com *.wistia.net ad.ipredictive.com analytics.twitter.com bat.bing.com cdn.givechariot.com cdn.jsdelivr.net doublethedonation.com fast.wistia.net *.adsrvr.org media.sabio.us *.collect.igodigital.com p1.parsely.com px.adentifi.com *.linkedin.com t.co um.simpli.fi woundedwarriorprojectsite.secure.force.com wwp.my.salesforce-sites.com www.facebook.com *.google.com www.googleadservices.com www.googletagmanager.com x.bidswitch.net media.sabio.us aa.agkn.com ads.stickyadstv.com analytics.twitter.com attrk.com bat.bing.com bcp.crwdcntrl.net ce.lijit.com cs.admanmedia.com dsum-sec.casalemedia.com eb2.3lift.com fei.pro-market.net ib.adnxs.com idsync.rlcdn.com image2.pubmatic.com loadm.exelator.com ml314.com *.igodigital.com pippio.com pixel.locker2.com pixel.rubiconproject.com pixel.tapad.com ps.eyeota.net px.adentifi.com s.ad.smaato.net simplifi.partners.tremorhub.com sync.1rx.io sync.bfmio.com sync.intentiq.com sync.outbrain.com sync.taboola.com trkn.us ups.analytics.yahoo.com us-u.openx.net arttrk.com media.sabio.us um.simpli.fi; script-src 'self' *.hotjar.com bat.bing.com *.salesforceliveagent.com cdn.givechariot.com connect.facebook.net *.wistia.com *.wistia.net *.adroll.com tag.simpli.fi www.google.com www.googleadservices.com *.googletagmanager.com *.google-analytics.com *.lightboxcdn.com www.youtube.com *.collect.igodigital.com aa.trkn.us browser.sentry-cdn.com cdn.c212.net cdn.parsely.com doublethedonation.com *.doubleclick.net js.adsrvr.org js.monitor.azure.com script.crazyegg.com snap.licdn.com tags.wdsvc.net *.ceros.com www.gstatic.com www.youtube.com; style-src 'self' cdn.givechariot.com *.wistia.com *.wistia.net js.adsrvr.org s.adroll.com www.googletagmanager.com www.lightboxcdn.com doublethedonation.com; 1 frame-ancestors 'self' https://stage.lovdata.no https://smia.lovdata.no/ 1 frame-ancestors 'self' https://app.datadoghq.com/; report-uri https://browser-intake-datadoghq.com/api/v2/logs?dd-api-key=pubce3f3f19a3c7fcb81c0e6b27dbde95e1&dd-evp-origin=content-security-policy&ddsource=csp-report&ddtags=env%3Agrow-monolith-prod; report-to csp-endpoint 1 script-src 'nonce-DBsgV9QXyaG6s3hfu15mjQ' 'report-sample' 'strict-dynamic' 'unsafe-eval' 'unsafe-inline' http: https:; object-src 'none'; report-uri https://csp.withgoogle.com/csp/static-on-bigtable; base-uri 'none' 1 default-src 'self' data: 'unsafe-inline' 'unsafe-eval' *.lge.co.kr https://browser-intake-datadoghq.com https://*.browser-intake-datadoghq.com *.datadoghq-browser-agent.com *.googletagmanager.com *.doubleclick.net *.facebook.net *.criteo.com *.creativecdn.com *.naver.net *.pstatic.net *.daangn.com *.stclab.com *.google.com *.creativecdn.com *.google-analytics.com *.simpli.fi *.sauceflex.com *.facebook.com *.google.co.kr *.widerplanet.com *.daumcdn.net *.useinsider.com *.attractt.com *.criteo.net; connect-src 'self' *.lge.co.kr https://browser-intake-datadoghq.com https://*.browser-intake-datadoghq.com *.datadoghq-browser-agent.com *.googletagmanager.com *.doubleclick.net *.facebook.net *.criteo.com *.creativecdn.com *.naver.net *.pstatic.net *.daangn.com *.stclab.com *.google.com *.creativecdn.com *.google-analytics.com *.simpli.fi *.sauceflex.com *.facebook.com *.google.co.kr *.widerplanet.com *.daumcdn.net *.useinsider.com *.attractt.com *.criteo.net; 1 default-src 'self' motul.com *.cdninstagram.com *.elfsightcdn.com; script-src 'self' 'unsafe-eval' *.axept.io *.elfsight.com https://*.googletagmanager.com *.hotjar.com *.facebook.net 'unsafe-inline' *.googleapis.com *.channelsight.com js.monitor.azure.com *.explorify.com *.elfsightcdn.com *.youtube.com; img-src 'self' staging-cms.motul.com axeptio.imgix.net www.google.com *.gstatic.com data: *.elfsight.com *.facebook.com *.elfsightcdn.com *.googleapis.com *.hotjar.com *.cdninstagram.com *.motul.com *.amazonaws.com *.channelsight.com cscoreproweustor.blob.core.windows.net motul.incony.de *.explorify.com https://i.ytimg.com/ https://*.googleusercontent.com/places https://*.google-analytics.com https://*.googletagmanager.com; child-src 'self' motul.com *.hotjar.com *.youtube.com https://*.googletagmanager.com *.youtube-nocookie.com;; style-src 'self' 'unsafe-inline' *.elfsight.com *.googleapis.com *.channelsight.com *.explorify.com; font-src 'self' *.gstatic.com *.hotjar.com *.channelsight.com *.explorify.com data:; report-uri /api/v2/security-headers; connect-src 'self' *.axept.io axeptio.imgix.net *.spinque.com *.elfsight.com *.facebook.net https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://*.google.com *.hotjar.com *.googleapis.com *.azurewebsites.net *.motul.com *.hotjar.io wss://ws4.hotjar.com *.channelsight.com https://cms.motul.com/search/api; frame-ancestors 'self' *.motul.com 1 script-src 'unsafe-eval' 'unsafe-inline' https: 'nonce-2a0fcf9a12b1f1d06bbb6a05' 'strict-dynamic' 'report-sample' https://*.criteo.com https://static.criteo.net https://*.facebook.com https://connect.facebook.net https://*.hotjar.com js.braintreegateway.com assets.braintreegateway.com www.paypalobjects.com *.paypal.com songbird.cardinalcommerce.com *.googletagmanager.com ; worker-src 'self'; object-src 'none'; base-uri 'none'; frame-ancestors 'none'; report-uri https://csp.tourradar.com 1 default-src 'self'; style-src 'self'; script-src 'self' https://maps.googleapis.com https://googletagmanager.com https://munchkin.marketo.net https://script.crazyegg.com https://www.influ2.com https://bat.bing.com https://ws.zoominfo.com https://www.clickcease.com https://tracking.g2crowd.com https://go.qgenda.com https://cdn.bizible.com https://j.6sc.co https://googleads.g.doubleclick.net; connect-src 'self' https://maps.googleapis.com https://script.crazyegg.com https://761-yjz-981.mktoresp.com https://www.google-analytics.com https://t.influ2.com https://c.6sc.co https://ipv6.6sc.co https://stats.g.doubleclick.net https://tracking.g2crowd.com https://ws.zoominfo.com https://realtime.ramblechat.com; img-src 'self' https://www.google.com https://bat.bing.com; font-src 'self' https://fonts.gstatic.com; frame-src 'self' https://td.doubleclick.net; object-src 'self'; upgrade-insecure-requests; 1 default-src 'self'; script-src 'self' 'nonce-NMtjPe/Ul4CjW315M3Iexg==' https://www.google-analytics.com https://widget.trustpilot.com http://widget.trustpilot.com https://*.sentry.io https://*.firebase.googleapis.com https://static.zdassets.com https://www.redditstatic.com/ads/pixel.js https://snap.licdn.com/li.lms-analytics/insight.min.js ; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' https://content-api.bento.capital https://content-api.changenow.io https://content-api-spb1.btc-bnb.com https://widget.trustpilot.com https://changenow.io https://front.bento.capital https://front-spb1.btc-bnb.com https://explorer-api.walletconnect.com https://alb.reddit.com/rp.gif; connect-src 'self' https://l.changenow.org https://*.zdassets.com https://www.google-analytics.com https://vip-api.bento.capital https://vip-api.changenow.io https://vip-api-spb1.btc-bnb.com https://content-api.bento.capital https://content-api.changenow.io https://content-api-spb1.btc-bnb.com https://changenow.io https://front.bento.capital https://front-spb1.btc-bnb.com https://affiliate-backend.changenow.io https://api.changenow.io https://explorer-api.walletconnect.com https://verify.walletconnect.com https://changenow.zendesk.com https://px.ads.linkedin.com/collect ; base-uri 'self'; form-action 'self'; frame-ancestors 'self'; object-src 'none'; frame-src 'self' https://widget.trustpilot.com http://widget.trustpilot.com https://changenow.io https://front.bento.capital https://front-spb1.btc-bnb.com https://youtube.com https://verify.walletconnect.com https://www.youtube.com ; report-uri https://l.changenow.org/api/3/security/?sentry_key=caf1b4c4d55fac9fb827b0fc4c20f664 1 object-src 'none'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://www.google.com/ https://cse.google.com/ https://www.eventbrite.com/ https://player.vimeo.com/ https://www.googletagmanager.com/ https://www.gstatic.com https://fonts.googleapis.com/ https://cdn.curator.io/ https://www.juicer.io/ https://www.google-analytics.com/ https://js.hsforms.net/ https://cdn.cookielaw.org/ https://js.adsrvr.org/ https://connect.facebook.net/ https://analytics.tiktok.com/ https://snap.licdn.com/ cdnjs.cloudflare.com https://cdnjs.cloudflare.com https://static.addtoany.com https://unpkg.com; script-src-attr 'self' 'unsafe-inline'; script-src-elem 'self' 'unsafe-inline' https://www.google.com/ https://cse.google.com/ https://www.eventbrite.com/ https://player.vimeo.com/ https://www.googletagmanager.com/ https://www.gstatic.com https://fonts.googleapis.com/ https://cdn.curator.io/ https://www.juicer.io/ https://www.google-analytics.com/ https://js.hsforms.net/ https://cdn.cookielaw.org/ https://js.adsrvr.org/ https://connect.facebook.net/ https://analytics.tiktok.com/ https://snap.licdn.com/ cdnjs.cloudflare.com https://cdnjs.cloudflare.com https://static.addtoany.com https://unpkg.com; style-src 'self' 'unsafe-inline' https://www.google.com/ https://cse.google.com/ https://www.eventbrite.com/ https://player.vimeo.com/ https://www.googletagmanager.com/ https://www.gstatic.com https://fonts.googleapis.com/ https://cdn.curator.io/ https://www.juicer.io/ https://www.google-analytics.com/ https://js.hsforms.net/ https://cdn.cookielaw.org/ https://js.adsrvr.org/ https://connect.facebook.net/ https://analytics.tiktok.com/ https://snap.licdn.com/ cdnjs.cloudflare.com https://cdnjs.cloudflare.com; style-src-attr 'self' 'unsafe-inline'; frame-ancestors 'self' https://www.google.com/ https://cse.google.com/ https://www.eventbrite.com/ https://player.vimeo.com/ https://www.googletagmanager.com/ https://www.gstatic.com https://fonts.googleapis.com/ https://cdn.curator.io/ https://www.juicer.io/ https://www.google-analytics.com/ https://js.hsforms.net/ https://cdn.cookielaw.org/ https://js.adsrvr.org/ https://connect.facebook.net/ https://analytics.tiktok.com/ https://snap.licdn.com/ 1 default-src 'self' https://*.wistia.net https://*.wistia.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' blob: https://cdn.jsdelivr.net https://analytics.sayprimer.com https://scripts.clarity.ms https://js-de.sentry-cdn.com https://*.wistia.net https://*.wistia.com https://assets.production.linktr.ee https://www.youtube.com https://assets.calendly.com https://growth.services.beekeeper.io https://connect.facebook.net https://a.omappapi.com https://tracking.g2crowd.com https://cdn-prod.eu.securiti.ai https://www.beekeeper.io https://*.zoominfo.com https://*.zi-scripts.com https://acsbapp.com https://browser.sentry-cdn.com https://js.sentry-cdn.com https://fast.wistia.com https://js.hsforms.net https://forms.hsforms.com https://hubspot-forms-static-embed.s3.amazonaws.com https://boards.greenhouse.io https://www.bugherd.com https://sidebar.bugherd.com https://cdn.cookielaw.org https://fast.wistia.net https://www.googletagmanager.com https://www.google-analytics.com https://snap.licdn.com https://bat.bing.com https://trk.techtarget.com https://www.influ2.com https://tags.srv.stackadapt.com https://lltrck.com https://www.clarity.ms https://googleads.g.doubleclick.net https://j.6sc.co https://d10lpsik1i8c69.cloudfront.net https://tracking.intentsify.io https://pi.pardot.com https://a.usbrowserspeed.com https://a.remarketstats.com https://i.liadm.com https://a.clickcertain.com https://static.cloudflareinsights.com https://www.google.com/recaptcha/ https://*.hotjar.com https://content.p3nd0.beekeeper.io https://www.gstatic.com https://dev.visualwebsiteoptimizer.com https://js.hs-analytics.net https://js.hsadspixel.net https://js.hs-scripts.com https://js.hs-banner.com https://js.hscollectedforms.net https://js.hsleadflows.net https://js.usemessages.com https://*.hubspot.com; style-src 'self' 'unsafe-inline' https://fast.wistia.com https://assets.calendly.com https://cdn-prod.eu.securiti.ai https://a.omappapi.com https://www.beekeeper.io https://fonts.googleapis.com https://d10lpsik1i8c69.cloudfront.net https://tags.srv.stackadapt.com; connect-src 'self' data: blob: https://pagead2.googlesyndication.com https://n.clarity.ms https://e.clarity.ms https://*.litix.io https://*.wistia.com https://web-script.api.sayprimer.com https://*.wistia.net https://*.algolia.net wss://ws.hotjar.com https://ltp.linktr.ee https://calendly.com https://fast.wistia.net https://selfservice-java.beekeeper.io http://pricing.services.beekeeper.io https://stats.g.doubleclick.net https://secure.adnxs.com https://tracking-api.g2.com https://app.securiti.ai https://api.omappapi.com https://app.eu.securiti.ai https://cdn-prod.eu.securiti.ai https://analytics.google.com https://forms.hubspot.com https://*.zoominfo.com https://*.zi-scripts.com https://acsbapp.com https://*.acsbapp.com https://notify.bugsnag.com https://sidebar.bugherd.com/binoculars wss://ws-mt1.pusher.com https://sockjs.pusher.com https://fg8vvsvnieiv3ej16jby.litix.io https://forms-na1.hubspot.com https://forms.hsforms.com https://hubspot-forms-static-embed.s3.amazonaws.com https://*.influ2.com https://c.6sc.co https://sessions.bugsnag.com https://cdn.cookielaw.org https://geolocation.onetrust.com https://*.wistia.com https://yoast.com https://www.google-analytics.com https://ipv6.6sc.co https://tags.srv.stackadapt.com https://settings.luckyorange.net https://px.ads.linkedin.com https://ibc-flow.techtarget.com https://t.clarity.ms https://static.cloudflareinsights.com https://o8540.ingest.sentry.io https://*.hotjar.io wss://ws.hotjar.com/api https://*.hubspot.com https://forms.hscollectedforms.net https://api.hubapi.com https://region1.analytics.google.com https://www.google.com; font-src 'self' data: https://*.wistia.com https://fast.wistia.com https://fonts.gstatic.com https://t.influ2.com https://www.google.com; frame-src 'self' data: blob: https://fast.wistia.com https://fast.wistia.net https://www.google.com https://calendly.com http://pricing.services.beekeeper.io https://www.youtube.com https://privacy-central.eu.securiti.ai https://forms.hsforms.com https://www.youtube-nocookie.com https://boards.greenhouse.io https://*.bugherd.com https://*.wistia.com https://*.wistia.net https://open.spotify.com https://td.doubleclick.net https://www.google.com/recaptcha https://iab-eu-tcf.securiti.ai https://job-boards.greenhouse.io https://privacy-central.eu.securiti.ai https://www.googletagmanager.com; img-src 'self' data: https://*.wistia.net https://*.wistia.com https://www.google.de https://plugin-updates.wpengine.com https://assets.calendly.com https://lh7-us.googleusercontent.com https://f.hubspotusercontent10.net https://www.linkedin.com https://www.googletagmanager.com https://www.facebook.com https://sidebar.bugherd.com https://bugherd-attachments.s3.amazonaws.com https://d2iiunr5ws5ch1.cloudfront.net https://i.ytimg.com https://fast.wistia.com https://embed-ssl.wistia.com https://forms-na1.hsforms.com https://cdn.cookielaw.org https://ps.w.org https://s.w.org https://secure.adnxs.com https://ib.adnxs.com https://t.influ2.com https://px.ads.linkedin.com https://www.google.com https://bat.bing.com https://www.google-analytics.com https://lltrck.com https://b.6sc.co https://px4.ads.linkedin.com blob: https://c.clarity.ms https://c.bing.com https://dev.visualwebsiteoptimizer.com https://track.hubspot.com https://*.hsforms.com/embed/; media-src 'self' blob: https://fast.wistia.com https://*.wistia.net https://embed-cloudfront.wistia.com; worker-src 'self' blob: https://beeke25stg.eight25.xyz; frame-ancestors 'self' https://www.google.com https://privacy-central.eu.securiti.ai https://open.spotify.com https://adgen-dev.spotify.com https://local.spotify.net https://*.spotify.net https://*.spotify.com; report-to csp-violation-report-endpoint ; 1 worker-src 'none'; img-src blob: data: *; default-src 'none'; base-uri 'none'; object-src 'none'; frame-ancestors 'none'; media-src *; script-src 'self' 'unsafe-inline' 'report-sample' 'nonce-hthZ/bG9NdwrJHARsh5ZUw=='; font-src 'self' data:; connect-src 'self' *.algolia.net *.algolianet.com *.algolia.io; style-src 'unsafe-inline' * 1 default-src 'self' 'unsafe-inline' 'unsafe-eval' data: https://aau.edu.jo https://*.aau.edu.jo *.googleusercontent.com *.jsdelivr.net *.gstatic.com *.bootstrapcdn.com *.googleapis.com *.google.com; report-uri //report-csp-violation 1 base-uri 'self'; default-src 'self' 'nonce-3c5060fbd17893812dcfc9a61d1159b7' https://cdn.shopify.com https://shopify.com; frame-ancestors 'none'; style-src self https://*.yotpo.com https://*.googleapis.com https://*.bootstrapcdn.com 'self' 'unsafe-inline' https://cdn.shopify.com; connect-src 'self' https://*.sentry.io https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://*.yotpo.com http://*.impactradius-event.com https://*.impactradius-event.com http://*.mountain.com https://*.mountain.com http://*.outbrain.com https://*.outbrain.com https://*.clickcease.com https://*.pinterest.com https://*.facebook.net https://*.facebook.com https://*.google.com https://*.linkedin.com https://*.ads.linkedin.com https://*.pinimg.com https://*.bing.com https://*.hsforms.net https://*.hsforms.com https://*.doubleclick.net https://*.affirm.com https://*.adscale.com https://*.reddit.com https://*.redditstatic.com https://*.privacy-mgmt.com https://*.edge.sdk.awswaf.com https://*.bazaarvoice.com https://*.clarity.ms https://*.hubspot.com https://*.hubapi.com https://*.hs-banner.com https://*.hscollectedforms.net https://*.codexade.com https://*.adroll.com https://*.visualwebsiteoptimizer.com https://*.googleadservices.com https://*.mczbf.com https://*.google.rs https://*.google.by https://*.company-target.com https://*.google.com.kh https://*.google.com.bd https://*.google.co.th 'self' https://cdn.shopify.com/ https://monorail-edge.shopifysvc.com https://shop-gl-eur.iqair.com https://iqair-global-eur.myshopify.com; img-src 'self' data: https://*.airvisual.net https://cdn.shopify.com https://*.iqair.com https://*.yotpo.com http://*.yotpo.com https://*.facebook.com https://*.linkedin.com https://*.ads.linkedin.com https://*.bing.com https://*.hsforms.com https://*.google.com https://*.googleusercontent.com https://*.googletagmanager.com https://*.doubleclick.net https://*.adroll.com https://*.reddit.com https://iqair-global-eur.myshopify.com https://iqair.myshopify.com https://iqair-china.myshopify.com https://iqair-test.myshopify.com https://*.bazaarvoice.com https://*.hubspot.com https://*.hubspotusercontent-na1.net https://*.visualwebsiteoptimizer.com https://ui-avatars.com https://*.clarity.ms https://*.rlcdn.com https://*.baidu.com https://*.outbrain.com https://*.truemed.com https://airvisual-public-node-reviews-images.s3-ap-northeast-1.amazonaws.com https://*.google.lu https://*.google.rs https://*.google.sk https://*.google.am https://*.google.by https://*.google.pl https://*.google.nl https://*.google.kg https://*.google.de https://*.google.ca https://*.google.kz https://*.google.co.th https://*.google.co.in https://*.google.co.uz https://*.google.com.au https://*.google.com.bd https://*.google.com.ua https://*.google.com.vn; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://cdn.shopify.com https://*.googletagmanager.com https://*.bazaarvoice.com https://*.yotpo.com https://*.hs-scripts.com https://cdn.bc0a.com http://*.impactradius-event.com https://*.impactradius-event.com http://*.mountain.com https://*.mountain.com http://*.outbrain.com https://*.outbrain.com https://*.clickcease.com https://*.pinterest.com https://*.facebook.net https://*.pinimg.com https://*.bing.com https://*.hsforms.net https://*.affirm.com https://*.demandbase.com https://*.adroll.com https://*.redditstatic.com https://*.mczbf.com https://*.privacy-mgmt.com https://*.edge.sdk.awswaf.com https://*.clarity.ms https://*.licdn.com https://*.youtube.com https://*.hubspot.com https://*.hsadspixel.net https://*.hs-analytics.net https://*.hs-banner.com https://*.hscollectedforms.net https://*.usemessages.com https://*.tableau.com https://*.company-target.com https://unpkg.com https://*.jquery.com https://*.cloudflare.com https://*.doubleclick.net https://truemed-public.s3.us-west-1.amazonaws.com 'nonce-3c5060fbd17893812dcfc9a61d1159b7'; frame-src 'self' https://*.googletagmanager.com https://*.pinterest.com https://*.doubleclick.net https://*.adroll.com https://*.company-target.com https://*.hs-sites.com https://*.privacy-mgmt.com https://*.youtube.com http://*.hs-sites.com https://*.tableau.com https://*.twitter.com https://*.hubspot.com https://*.google.com; font-src self data: font/woff2 data: font/woff https://*.yotpo.com https://*.gstatic.com; worker-src 'self' blob:; report-uri https://o446702.ingest.us.sentry.io/api/4508132736892928/security/?sentry_key=8e3aea2ba071c511ad8e9f1d0b91dd04; report-to csp-endpoint 1 default-src 'self' blob: data: 'unsafe-inline' 'unsafe-eval' *.adobedtm.com *.amazon-adsystem.com *.appdemostore.com *.atdmt.com *.avocet.io *.blubrry.com *.clicktale.net *.craftyclicks.co.uk *.chatcora.natwest.com *.doubleclick.net *.everesttech.net *.facebook.com *.facebook.net *.fca.org.uk *.google.co.uk *.google.com *.googleadservices.com *.jwpcdn.com *.liveperson.net *.linkedin.com *.lpsnmedia.net *.neolane.net *.omguk.com *.omtrdc.net *.pinimg.com *.pinterest.com *.raptmedia.com *.rbos.com *.rbs.co.uk *.rbs.com *.rbsdigital.com *.supportcentre-rbs.co.uk *.snapchat.com *.userzoom.com *.youtube.com *.ytimg.com analytics.twitter.com api.swiftype.com dcs.demdex.net dpm.demdex.net fast.demdex.net fast.rbs.demdex.net jwpltx.com rbs.demdex.net sc-static.net search-rbs.co.uk static.ads-twitter.com t.co www.brightedge.com *.everesttech.net *.everestjs.net cdn.cookielaw.org; upgrade-insecure-requests; report-uri https://rbspersonal.report-uri.com/r/t/csp/reportOnly 1 default-src 'self'; script-src 'self' https://cdnjs.cloudflare.com https://www.googletagmanager.com https://www.google-analytics.com https://s7.addthis.com https://googleads.g.doubleclick.net 'unsafe-inline' 'unsafe-eval'; style-src 'self' https://fonts.googleapis.com https://cdn.jsdelivr.net 'unsafe-inline'; img-src 'self' data: https://www.google.com https://widgets.guidestar.org https://googleads.g.doubleclick.net https://www.googletagmanager.com; font-src 'self' https://fonts.gstatic.com https://cdn.jsdelivr.net; connect-src 'self' https://www.google.com; object-src 'none'; frame-src https://www.googletagmanager.com https://googleads.g.doubleclick.net; base-uri 'self'; 1 report-uri https://endpoint2.collection.us2.sumologic.com/receiver/v1/http/ZaVnC4dhaV3VOE24ov0vchYgO3uoxKHdePxnKoFiICkeq1Vt2reRBEg4zYmpS2XL1UJS-0Ova9gUiV2PUH3EvuXcIOdrBPvAUgkIP-ZRbRMryNUY6YGqAQ== ; block-all-mixed-content ; default-src 'report-sample' 'self' https://*.videoask.com https://*.videoask.live ; script-src 'report-sample' 'self' 'unsafe-eval' https://*.videoask.com https://*.videoask.live 'unsafe-inline' https://js.stripe.com https://www.dropbox.com https://*.calendly.com https://*.oncehub.com https://cdn.amplitude.com https://cdn.cookielaw.org https://cdn.rollbar.com https://cdn.segment.com https://connect.facebook.net https://fast.wistia.com https://script.crazyegg.com https://snap.licdn.com https://snippet.growsumo.com https://www.google-analytics.com https://www.googletagmanager.com https://www.googleadservices.com https://cdn.optimizely.com https://js.partnerstack.com https://edge.fullstory.com https://a.quora.com https://static.ads-twitter.com https://analytics.tiktok.com https://tags.srv.stackadapt.com ; base-uri 'report-sample' 'self' ; img-src 'report-sample' 'self' data: blob: android-webview-video-poster: https: ; media-src 'report-sample' 'self' blob: data: https: ; connect-src 'report-sample' 'self' blob: https://*.videoask.com https://*.videoask.live wss://*.videoask.live wss://*.videoask.com https://videoask-media-dev.s3-accelerate.amazonaws.com https://videoask-media-prod.s3-accelerate.amazonaws.com https://videoask-uploads-dev.s3-accelerate.amazonaws.com https://videoask-uploads-prod.s3-accelerate.amazonaws.com https://videoask-uploads-dev.s3.amazonaws.com https://videoask-uploads-prod.s3.amazonaws.com https://videoask.eu.auth0.com https://dev-videoask.eu.auth0.com https://*.launchdarkly.com https://*.pexels.com https://*.wistia.com https://embedwistia-a.akamaihd.net https://api.rollbar.com https://api.segment.io https://api.amplitude.com https://*.g.doubleclick.net https://www.google-analytics.com https://*.crazyegg.com https://p.adsymptotic.com https://www.facebook.com https://track.segmetrics.io https://*.google.com https://rs.fullstory.com https://cdn.segment.com https://edge.fullstory.com https://js.partnerstack.com https://grsm.io https://cdn.cookielaw.org https://*.onetrust.com https://*.contentful.com https://videoask.zendesk.com https://*.optimizely.com https://region1.google-analytics.com https://analytics.tiktok.com https://partnerlinks.io ; style-src 'report-sample' 'self' https://font.typeform.com 'unsafe-inline' https://fonts.googleapis.com https://tagmanager.google.com https://cdn.cookielaw.org https://cdn.quilljs.com ; font-src 'report-sample' 'self' data: https://font.typeform.com https://fonts.gstatic.com ; frame-src 'report-sample' 'self' https://*.videoask.com https://*.videoask.live https://calendly.com https://app.acuityscheduling.com https://*.oncehub.com https://js.stripe.com https://videoask.eu.auth0.com https://dev-videoask.eu.auth0.com https://*.wistia.com https://www.facebook.com https://*.doubleclick.net https://6g4qf7txd07m.statuspage.io https://*.optimizely.com ; frame-ancestors * ; object-src 'none' ; 1 default-src 'self'; script-src 'self' 'unsafe-inline' https://*.googletagmanager.com https://*.google-analytics.com https://*.google.com https://connect.facebook.net https://*.stripe.com https://*.braintreegateway.com https://cdn.cookielaw.org https://geolocation.onetrust.com https://*.youtube.com https://s.ytimg.com https://*.weeecdn.com https://*.weeecdn.net https://*.tiktok.com https://*.clarity.ms https://*.cloudfront.net https://*.awswaf.com; style-src 'self' 'unsafe-inline' https://*.googleapis.com https://*.weeecdn.com https://*.weeecdn.net; img-src 'self' data: blob: https://*.weeecdn.com https://*.weeecdn.net https://weee.pics https://*.masgusto.net https://*.google-analytics.com https://*.doubleclick.net https://*.facebook.com https://*.stripe.com https://*.youtube.com https://*.ytimg.com https://cdn.cookielaw.org https://*.anycart.com https://*.sayweee.com https://*.sayweee.net https://static.weeecdn.com https://static.weeecdn.net; font-src 'self' data: https://fonts.gstatic.com https://*.weeecdn.com https://*.weeecdn.net; connect-src 'self' wss://*.sayweee.com https://*.sayweee.com wss://*.sayweee.net https://*.sayweee.net wss://*.masgusto.com https://*.masgusto.com wss://*.masgusto.net https://*.masgusto.net https://*.google-analytics.com https://*.google.com https://region1.google-analytics.com https://*.facebook.com https://*.stripe.com https://*.braintreegateway.com https://*.onetrust.com https://*.googleapis.com https://*.gstatic.com https://*.tiktok.com https://*.weeecdn.com https://*.weeecdn.net https://cdn.cookielaw.org https://*.cloudflare.com https://*.awswaf.com https://*.clarity.ms https://*.sayweee.com https://*.sayweee.net https://www.sayweee.com https://click.sayweee.com; media-src 'self' https://*.sayweeecdn.com https://*.youtube.com https://*.tiktok.com; object-src 'none'; frame-src https://*.stripe.com https://hooks.stripe.com https://assets.braintreegateway.com https://*.youtube.com https://*.google.com https://*.facebook.com https://*.tiktok.com https://cdn.cookielaw.org; frame-ancestors 'none'; form-action 'self'; base-uri 'self'; worker-src 'self' blob:; manifest-src 'self'; upgrade-insecure-requests; report-uri https://api.sayweee.net/ec/bff/report/csp-violation; report-to csp-endpoint 1 frame-ancestors 'self'; upgrade-insecure-requests; report-uri https://5b99b19026a35ad04db5bcf778a03938.report-uri.com/r/d/csp/reportOnly 1 default-src 'self' http: https: data: blob: 'unsafe-eval' 'unsafe-inline'; frame-ancestors 'self'; 1 report-uri /csp-log.php; report-to csp-log-endpoint; default-src 'none'; img-src 'self' data: https://werbung.leipzig.de/ https://data.leipzig.de/ https://static.leipzig.de/ https://www.gstatic.com/images/; script-src 'self' 'unsafe-inline' https://www.leipzig.de/ https://static.leipzig.de/ https://werbung.leipzig.de/delivery/ https://vrweb15.linguatec.org/VoiceReaderWeb15User/player20/scripts/ https://dev.lehst.de/ https://static.conword.io/; style-src 'self' 'unsafe-inline' https://static.leipzig.de/ https://vrweb15.linguatec.org/VoiceReaderWeb15User/player/styles/ https://dev.lehst.de/; font-src 'self' https://static.leipzig.de/ https://fonts.gstatic.com/; media-src 'self' https://static.leipzig.de/ https://vrweb15.linguatec.org/VoiceReaderWeb15User/player20/scripts/; connect-src 'self' https://vrweb15.linguatec.org/VoiceReaderWeb15WebService/ https://dev.lehst.de/ https://www.leipzig.de/; frame-src https://www.youtube-nocookie.com/embed/ https://tnv.leipzig.de https://s-leipzig.maps.arcgis.com https://geoportal.leipzig.de https://www.blitzvideoserver.de https://tportal.toubiz.de https://kwis-web.leipzig.de; 1 default-src 'self' https://3sspw4l2.tinifycdn.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://3sspw4l2.tinifycdn.com https://a.plerdy.com https://challenges.cloudflare.com https://connect.facebook.net https://d.plerdy.com https://googleads.g.doubleclick.net https://js.stripe.com https://maps.googleapis.com https://notifications.nic.ua https://www.googletagmanager.com https://www.paypal.com https://www.paypalobjects.com; script-src-elem 'self' 'unsafe-inline' blob: https://3sspw4l2.tinifycdn.com https://a.plerdy.com https://challenges.cloudflare.com https://connect.facebook.net https://d.plerdy.com https://js.stripe.com https://maps.googleapis.com https://notifications.nic.ua https://www.googletagmanager.com https://www.paypal.com https://www.paypalobjects.com https://googleads.g.doubleclick.net *.nicnames.com; script-src-attr 'self' 'unsafe-inline'; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://3sspw4l2.tinifycdn.com; style-src-elem 'self' 'unsafe-inline' https://3sspw4l2.tinifycdn.com https://fonts.googleapis.com https://pt.wisernotify.com https://themes.googleusercontent.com https://www.gstatic.com; style-src-attr 'self' 'unsafe-inline'; font-src 'self' data: https://fonts.gstatic.com https://3sspw4l2.tinifycdn.com https://cdn.megabonus.com *.nicnames.com https://static.hsappstatic.net; img-src * data: blob:; connect-src 'self' https://3sspw4l2.tinifycdn.com https://api.locize.app https://api.nicnames.com wss://d.plerdy.com https://d.plerdy.com https://jexi.ai https://maps.googleapis.com https://nicnames.com https://ns.wisermapp.com https://overbridgenet.com https://region1.google-analytics.com https://strapi.nicnames.com https://ts-wn-log-bmggb9bcacbsd6df.westus-01.azurewebsites.net https://www.facebook.com https://www.googleadservices.com https://www.google-analytics.com https://www.google.com https://www.paypal.com; frame-src 'self' https://assets.braintreegateway.com https://challenges.cloudflare.com https://c.paypal.com https://js.stripe.com https://td.doubleclick.net https://www.facebook.com https://www.googletagmanager.com https://www.paypal.com; worker-src 'self' blob:; object-src 'none'; base-uri 'self'; frame-ancestors 'self'; report-uri https://nicnames.com/csp-reports; 1 object-src * ; report-uri https://www.sunlife.ca/slfreporting/reportUri 1 default-src 'self'; script-src 'self' 'strict-dynamic' 'sha256-B2ijbidY/36WiZeOQ4feQK1E4pzvkySGJgi1+p+fzS0=' 'sha256-FqS75La0kucsCzYdPk70EY2E06leY4l2dj/lGHD2UBQ=' 'sha256-wS4j3xASxiV4ccFi6gFW3nQyl8HE9x9++SauQVmC2MI=' 'sha256-oSFIklmLVCmyLR2UGe+6s9BhIe+E98h+Qla6zUXZxYo=' 'sha256-4vHUiCbq6VWyfJ9HG36ClOfUtwF3YPmnGEMFLF02GSk=' 'sha256-CqS4mELSYVqNHgOX6Z3Rz3pc5BBQNvRBUX6l5mggx5s=' 'sha256-C9cjnt95nyjzeA165CXH33Y4dGPsuv7EPq+sskBKh24=' 'sha256-oVBJC84KeqkWD8YKwRhi7YulNpfCMatZ/AtBueJiJBw=' 'sha256-snSgSI0BjjybXXT5XjMlMnfGtaSL6JDTXJrb0Qa6MgY=' 'sha256-I5pzwNlOsuYvwtJ6gNrB/+EpALSuDnWzq2Vy8SQCoig=' 'sha256-65p00hdANpBG3OjFooizMqNwdxQFSbNbk8yNEThP0cU=' 'sha256-JKLpqIvSXexbwW4WCYKjnFFiX54Sdjs0p8wzlpX5Tas=' 'sha256-Nzf2PnbPY4FS30IBC+WcjRB5FM5xr6Vcf4UkYeoiUfY=' 'sha256-YK/s6V2LXII6euS3Z4rtkEEDkW7h0ZnQ93S79n013B4=' 'sha256-DAHhL2KL4/D0N95FcV2rt4kuyJqUtUFXcQ+Rgrm8n8k=' 'sha256-BDJw56hOSYkqXW5f6kYD/BThM/Ac6Kw6PY3UiOb9Ogk=' 'sha256-GXBifbBfbyuYZEXso+B6IJsm/SkFzw+kRei2aHzKOnA=' 'sha256-VApnDE2LCHgeJMjH6jRHsqEhgc+o2MSl7W6AUB7tuzY=' 'sha256-2QxNyaIYbBzc7I4msHTwUA2iiFsKDvWj9+/BXLKtWy8=' 'sha256-KA7+joXuYqEpX5+V0Zm1SOaMNG4V4xCkHQTTvF3F9qc=' 'sha256-/uQVytL3+4KdrEyU6ZN6U8oqI0M9RTsTtPCq6bOx5SQ=' 'sha256-MP90K9Avg8++m7OkTjp60jtpNs8/lCc6FnKk3tw+X80=' 'sha256-uQX+J7ZMG/e3smFDCAZgOheFUBw7OtgGYTkl1N8KtdA=' 'sha256-uq+S3TmH2Dmbw0Gvny3wweYrn9T5ejjcvzPBOhGSHY8=' 'sha256-S6bbqUAop5FICaJyKCmur1Al2x6bvGboacTP1wLsJ70=' 'sha256-qIftNP435pUnkDISzeZcJ1JnzDkqjmE2yIOXF2gU0Us=' 'sha256-U2rVut1H+wyabNOI8QvjSyLdUyImOYDJEZJv7pJDAYg=' 'sha256-/eRcQkiza5IIqG3IGs1tTLPxjZCAjMuEkB9Pr71zbN0='; connect-src 'self' www.google.com stats.g.doubleclick.net analytics.google.com *.analytics.google.com www.googleadservices.com www.google.ad www.google.ae www.google.com.af www.google.com.ag www.google.al www.google.am www.google.co.ao www.google.com.ar www.google.as www.google.at www.google.com.au www.google.az www.google.ba www.google.com.bd www.google.be www.google.bf www.google.bg www.google.com.bh www.google.bi www.google.bj www.google.com.bn www.google.com.bo www.google.com.br www.google.bs www.google.bt www.google.co.bw www.google.by www.google.com.bz www.google.ca www.google.cd www.google.cf www.google.cg www.google.ch www.google.ci www.google.co.ck www.google.cl www.google.cm www.google.cn www.google.com.co www.google.co.cr www.google.com.cu www.google.cv www.google.com.cy www.google.cz www.google.de www.google.dj www.google.dk www.google.dm www.google.com.do www.google.dz www.google.com.ec www.google.ee www.google.com.eg www.google.es www.google.com.et www.google.fi www.google.com.fj www.google.fm www.google.fr www.google.ga www.google.ge www.google.gg www.google.com.gh www.google.com.gi www.google.gl www.google.gm www.google.gr www.google.com.gt www.google.gy www.google.com.hk www.google.hn www.google.hr www.google.ht www.google.hu www.google.co.id www.google.ie www.google.co.il www.google.im www.google.co.in www.google.iq www.google.is www.google.it www.google.je www.google.com.jm www.google.jo www.google.co.jp www.google.co.ke www.google.com.kh www.google.ki www.google.kg www.google.co.kr www.google.com.kw www.google.kz www.google.la www.google.com.lb www.google.li www.google.lk www.google.co.ls www.google.lt www.google.lu www.google.lv www.google.com.ly www.google.co.ma www.google.md www.google.me www.google.mg www.google.mk www.google.ml www.google.com.mm www.google.mn www.google.com.mt www.google.mu www.google.mv www.google.mw www.google.com.mx www.google.com.my www.google.co.mz www.google.com.na www.google.com.ng www.google.com.ni www.google.ne www.google.nl www.google.no www.google.com.np www.google.nr www.google.nu www.google.co.nz www.google.com.om www.google.com.pa www.google.com.pe www.google.com.pg www.google.com.ph www.google.com.pk www.google.pl www.google.pn www.google.com.pr www.google.ps www.google.pt www.google.com.py www.google.com.qa www.google.ro www.google.ru www.google.rw www.google.com.sa www.google.com.sb www.google.sc www.google.se www.google.com.sg www.google.sh www.google.si www.google.sk www.google.com.sl www.google.sn www.google.so www.google.sm www.google.sr www.google.st www.google.com.sv www.google.td www.google.tg www.google.co.th www.google.com.tj www.google.tl www.google.tm www.google.tn www.google.to www.google.com.tr www.google.tt www.google.com.tw www.google.co.tz www.google.com.ua www.google.co.ug www.google.co.uk www.google.com.uy www.google.co.uz www.google.com.vc www.google.co.ve www.google.co.vi www.google.com.vn www.google.vu www.google.ws www.google.rs www.google.co.za www.google.co.zm www.google.co.zw www.google.ca www.google.com www.googletagmanager.com www.google-analytics.com api.statsig.com featuregates.org statsigapi.net events.statsigapi.net api.statsigcdn.com featureassets.org assetsconfigcdn.org prodregistryv2.org cloudflare-dns.com beyondwickedmapping.org www.googletagmanager.com *.google-analytics.com www.googleadservices.com consent.cookie-script.com join.com um.join.com *.clarity.ms device.maxmind.com *.mmapiws.com api.refiner.io cdn.join.com www.youtube.com www.tiktok.com/node/ *.ttwstatic.com *.tiktokv.com *.tiktokv.eu *.tiktokw.eu www.linkedin.com *.amplitude.com px.ads.linkedin.com; style-src 'self' 'unsafe-inline' cdn.join.com *.neutral.ttwstatic.com; img-src 'self' data: c.bing.com c.clarity.ms www.googleadservices.com www.google.ad www.google.ae www.google.com.af www.google.com.ag www.google.al www.google.am www.google.co.ao www.google.com.ar www.google.as www.google.at www.google.com.au www.google.az www.google.ba www.google.com.bd www.google.be www.google.bf www.google.bg www.google.com.bh www.google.bi www.google.bj www.google.com.bn www.google.com.bo www.google.com.br www.google.bs www.google.bt www.google.co.bw www.google.by www.google.com.bz www.google.ca www.google.cd www.google.cf www.google.cg www.google.ch www.google.ci www.google.co.ck www.google.cl www.google.cm www.google.cn www.google.com.co www.google.co.cr www.google.com.cu www.google.cv www.google.com.cy www.google.cz www.google.de www.google.dj www.google.dk www.google.dm www.google.com.do www.google.dz www.google.com.ec www.google.ee www.google.com.eg www.google.es www.google.com.et www.google.fi www.google.com.fj www.google.fm www.google.fr www.google.ga www.google.ge www.google.gg www.google.com.gh www.google.com.gi www.google.gl www.google.gm www.google.gr www.google.com.gt www.google.gy www.google.com.hk www.google.hn www.google.hr www.google.ht www.google.hu www.google.co.id www.google.ie www.google.co.il www.google.im www.google.co.in www.google.iq www.google.is www.google.it www.google.je www.google.com.jm www.google.jo www.google.co.jp www.google.co.ke www.google.com.kh www.google.ki www.google.kg www.google.co.kr www.google.com.kw www.google.kz www.google.la www.google.com.lb www.google.li www.google.lk www.google.co.ls www.google.lt www.google.lu www.google.lv www.google.com.ly www.google.co.ma www.google.md www.google.me www.google.mg www.google.mk www.google.ml www.google.com.mm www.google.mn www.google.com.mt www.google.mu www.google.mv www.google.mw www.google.com.mx www.google.com.my www.google.co.mz www.google.com.na www.google.com.ng www.google.com.ni www.google.ne www.google.nl www.google.no www.google.com.np www.google.nr www.google.nu www.google.co.nz www.google.com.om www.google.com.pa www.google.com.pe www.google.com.pg www.google.com.ph www.google.com.pk www.google.pl www.google.pn www.google.com.pr www.google.ps www.google.pt www.google.com.py www.google.com.qa www.google.ro www.google.ru www.google.rw www.google.com.sa www.google.com.sb www.google.sc www.google.se www.google.com.sg www.google.sh www.google.si www.google.sk www.google.com.sl www.google.sn www.google.so www.google.sm www.google.sr www.google.st www.google.com.sv www.google.td www.google.tg www.google.co.th www.google.com.tj www.google.tl www.google.tm www.google.tn www.google.to www.google.com.tr www.google.tt www.google.com.tw www.google.co.tz www.google.com.ua www.google.co.ug www.google.co.uk www.google.com.uy www.google.co.uz www.google.com.vc www.google.co.ve www.google.co.vi www.google.com.vn www.google.vu www.google.ws www.google.rs www.google.co.za www.google.co.zm www.google.co.zw www.google.ca www.google.com www.googletagmanager.com www.google-analytics.com cdn-public-assets.join.com cdn.join.com *.ttwstatic.com *.tiktokcdn.com *.tiktokcdn-eu.com *.tiktokcdn-us.com *.ytimg.com www.linkedin.com *.googleusercontent.com px.ads.linkedin.com; frame-src www.googletagmanager.com js.refiner.io www.youtube.com www.youtube-nocookie.com www.tiktok.com www.linkedin.com li.protechts.net quiz.tryinteract.com *.spotify.com tenor.com; font-src 'self' data: cdn.join.com *.neutral.ttwstatic.com fonts.gstatic.com; script-src-elem 'self' js.refiner.io join.com um.join.com scripts.clarity.ms device.maxmind.com googleads.g.doubleclick.net cdn.jsdelivr.net/npm/@statsig/ widget.join.com www.clarity.ms cdn.cookie-script.com www.googletagmanager.com www.youtube.com *.neutral.ttwstatic.com *.neutral.tiktokcdn-eu.com www.tiktok.com/embed.js tenor.com *.tenor.com *.amplitude.com snap.licdn.com 'sha256-7PO9Sf8E8Z6CI+XugBIVArS8kyVNIn7bMXYo4t7CPBk=' 'sha256-WzulH+JUQNOvXkAcuOQYHBLjsZEB8IDMH1Eo767Majs=' 'sha256-g/Ot9ViYMe/nTRaPD9Zqlze0e4ougD8rfFmIupGCa78=' 'sha256-LdH1VQvG32ftmjqWaXEpHBfdfuaKErChemW6fp+mgoE=' 'sha256-qY1+jSYP/QTeB46l+FBnfHfxoeuW7gZLMeucRtWBVMM=' 'sha256-z+StzS/qtI8dbtHUSgyscJFEl73eypDMffbLNjzvp4c=' 'sha256-B2ijbidY/36WiZeOQ4feQK1E4pzvkySGJgi1+p+fzS0=' 'sha256-FqS75La0kucsCzYdPk70EY2E06leY4l2dj/lGHD2UBQ=' 'sha256-wS4j3xASxiV4ccFi6gFW3nQyl8HE9x9++SauQVmC2MI=' 'sha256-oSFIklmLVCmyLR2UGe+6s9BhIe+E98h+Qla6zUXZxYo=' 'sha256-4vHUiCbq6VWyfJ9HG36ClOfUtwF3YPmnGEMFLF02GSk=' 'sha256-CqS4mELSYVqNHgOX6Z3Rz3pc5BBQNvRBUX6l5mggx5s=' 'sha256-C9cjnt95nyjzeA165CXH33Y4dGPsuv7EPq+sskBKh24=' 'sha256-oVBJC84KeqkWD8YKwRhi7YulNpfCMatZ/AtBueJiJBw=' 'sha256-snSgSI0BjjybXXT5XjMlMnfGtaSL6JDTXJrb0Qa6MgY=' 'sha256-I5pzwNlOsuYvwtJ6gNrB/+EpALSuDnWzq2Vy8SQCoig=' 'sha256-65p00hdANpBG3OjFooizMqNwdxQFSbNbk8yNEThP0cU=' 'sha256-JKLpqIvSXexbwW4WCYKjnFFiX54Sdjs0p8wzlpX5Tas=' 'sha256-Nzf2PnbPY4FS30IBC+WcjRB5FM5xr6Vcf4UkYeoiUfY=' 'sha256-YK/s6V2LXII6euS3Z4rtkEEDkW7h0ZnQ93S79n013B4=' 'sha256-DAHhL2KL4/D0N95FcV2rt4kuyJqUtUFXcQ+Rgrm8n8k=' 'sha256-BDJw56hOSYkqXW5f6kYD/BThM/Ac6Kw6PY3UiOb9Ogk=' 'sha256-GXBifbBfbyuYZEXso+B6IJsm/SkFzw+kRei2aHzKOnA=' 'sha256-VApnDE2LCHgeJMjH6jRHsqEhgc+o2MSl7W6AUB7tuzY=' 'sha256-2QxNyaIYbBzc7I4msHTwUA2iiFsKDvWj9+/BXLKtWy8=' 'sha256-KA7+joXuYqEpX5+V0Zm1SOaMNG4V4xCkHQTTvF3F9qc=' 'sha256-/uQVytL3+4KdrEyU6ZN6U8oqI0M9RTsTtPCq6bOx5SQ=' 'sha256-MP90K9Avg8++m7OkTjp60jtpNs8/lCc6FnKk3tw+X80=' 'sha256-uQX+J7ZMG/e3smFDCAZgOheFUBw7OtgGYTkl1N8KtdA=' 'sha256-uq+S3TmH2Dmbw0Gvny3wweYrn9T5ejjcvzPBOhGSHY8=' 'sha256-S6bbqUAop5FICaJyKCmur1Al2x6bvGboacTP1wLsJ70=' 'sha256-qIftNP435pUnkDISzeZcJ1JnzDkqjmE2yIOXF2gU0Us=' 'sha256-U2rVut1H+wyabNOI8QvjSyLdUyImOYDJEZJv7pJDAYg=' 'sha256-/eRcQkiza5IIqG3IGs1tTLPxjZCAjMuEkB9Pr71zbN0='; media-src 'self' cdn-public-assets.join.com *.tiktokcdn-eu.com *.tiktok.com; base-uri 'self'; form-action 'self' api.refiner.io; frame-ancestors www.google.com 1 frame-ancestors 'self' https://www.bing.com https://www.google.at https://www.google.de https://*.search.yahoo.com; report-uri https://www.tudorwatch.com/csp-reports/?req_id=2c670de4 1 default-src https: data: blob: 'unsafe-inline' 'unsafe-eval' ; report-uri https://events.ocdn.eu/v2/csp-report?_ac=events&_fv=www.forbes.pl::PROD_V2 1 default-src 'none'; script-src 'self' 'unsafe-inline' 'unsafe-eval' cdn.paddle.com connect.facebook.net mc.yandex.com mc.yandex.ru quantcast.mgr.consensu.org rules.quantcount.com secure.quantserve.com ssl.google-analytics.com translate.google.com translate.googleapis.com translate-pa.googleapis.com www.google-analytics.com www.googletagmanager.com cmp.auslogics.com; style-src 'self' 'unsafe-inline' fonts.googleapis.com cdn.paddle.com use.fontawesome.com www.iubenda.com translate.googleapis.com; img-src 'self' data: cms.quantserve.com mc.webvisor.org mc.yandex.by mc.yandex.com mc.yandex.com.tr mc.yandex.fr mc.yandex.kz mc.yandex.ru mc.yandex.ua mc.yandex.uz pixel.quantcount.com pixel.quantserve.com ssl.google-analytics.com ssl.gstatic.com translate.google.com translate.googleapis.com www.facebook.com *.google.ae *.google.al *.google.am *.google.at *.google.az *.google.ba *.google.be *.google.bf *.google.bg *.google.bj *.google.bs *.google.by *.google.ca *.google.cd *.google.ch *.google.ci *.google.cl *.google.cm *.google.cn *.google.co.ao *.google.co.bw *.google.co.cr *.google.co.id *.google.co.il *.google.co.in *.google.co.jp *.google.co.ke *.google.co.kr *.google.co.ls *.google.co.ma *.google.co.nz *.google.co.th *.google.co.tz *.google.co.ug *.google.co.uk *.google.co.uz *.google.co.ve *.google.co.za *.google.co.zm *.google.co.zw *.google.com *.google.com.af *.google.com.ar *.google.com.au *.google.com.bd *.google.com.bh *.google.com.bn *.google.com.bo *.google.com.br *.google.com.bz *.google.com.co *.google.com.cu *.google.com.cy *.google.com.do *.google.com.ec *.google.com.eg *.google.com.et *.google.com.gh *.google.com.gt *.google.com.hk *.google.com.jm *.google.com.kh *.google.com.kw *.google.com.lb *.google.com.ly *.google.com.mm *.google.com.mt *.google.com.mx *.google.com.my *.google.com.na *.google.com.ng *.google.com.ni *.google.com.np *.google.com.om *.google.com.pa *.google.com.pe *.google.com.pg *.google.com.ph *.google.com.pk *.google.com.pr *.google.com.py *.google.com.qa *.google.com.sa *.google.com.sg *.google.com.sv *.google.com.tj *.google.com.tr *.google.com.tw *.google.com.ua *.google.com.uy *.google.com.vc *.google.com.vn *.google.cv *.google.cz *.google.de *.google.dk *.google.dz *.google.ee *.google.es *.google.fi *.google.fr *.google.ge *.google.gr *.google.gy *.google.hn *.google.hr *.google.ht *.google.hu *.google.ie *.google.im *.google.iq *.google.is *.google.it *.google.jo *.google.kg *.google.kz *.google.la *.google.lk *.google.lt *.google.lu *.google.lv *.google.md *.google.me *.google.mg *.google.mk *.google.mn *.google.mu *.google.mv *.google.mw *.google.ne *.google.nl *.google.no *.google.pl *.google.ps *.google.pt *.google.ro *.google.rs *.google.ru *.google.se *.google.si *.google.sk *.google.sm *.google.sn *.google.sr *.google.tn *.google.tt *.google.td *.google.je *.google.ws *.google.rw *.google.co.mz *.google.sc *.google.tm *.google.ga *.google.tg *.google.com.ag *.google.co.in *.google.ad *.google.ml *.google.cg www.google-analytics.com www.googletagmanager.com www.gstatic.com yastatic.net; connect-src 'self' audit-tcfv2.quantcast.mgr.consensu.org code.jquery.com mc.yandex.by mc.yandex.com mc.yandex.com.tr mc.yandex.fr mc.yandex.kz mc.yandex.md mc.yandex.ru mc.yandex.ua mc.yandex.uz quantcast.mgr.consensu.org translate.googleapis.com www.google-analytics.com stats.g.doubleclick.net est.quantcast.mgr.consensu.org *.google.ae *.google.al *.google.am *.google.at *.google.az *.google.ba *.google.be *.google.bf *.google.bg *.google.bj *.google.bs *.google.by *.google.ca *.google.cd *.google.ch *.google.ci *.google.cl *.google.cm *.google.cn *.google.co.ao *.google.co.bw *.google.co.cr *.google.co.id *.google.co.il *.google.co.in *.google.co.jp *.google.co.ke *.google.co.kr *.google.co.ls *.google.co.ma *.google.co.nz *.google.co.th *.google.co.tz *.google.co.ug *.google.co.uk *.google.co.uz *.google.co.ve *.google.co.za *.google.co.zm *.google.co.zw *.google.com *.google.com.af *.google.com.ar *.google.com.au *.google.com.bd *.google.com.bh *.google.com.bn *.google.com.bo *.google.com.br *.google.com.bz *.google.com.co *.google.com.cu *.google.com.cy *.google.com.do *.google.com.ec *.google.com.eg *.google.com.et *.google.com.gh *.google.com.gt *.google.com.hk *.google.com.jm *.google.com.kh *.google.com.kw *.google.com.lb *.google.com.ly *.google.com.mm *.google.com.mt *.google.com.mx *.google.com.my *.google.com.na *.google.com.ng *.google.com.ni *.google.com.np *.google.com.om *.google.com.pa *.google.com.pe *.google.com.pg *.google.com.ph *.google.com.pk *.google.com.pr *.google.com.py *.google.com.qa *.google.com.sa *.google.com.sg *.google.com.sv *.google.com.tj *.google.com.tr *.google.com.tw *.google.com.ua *.google.com.uy *.google.com.vc *.google.com.vn *.google.cv *.google.cz *.google.de *.google.dk *.google.dz *.google.ee *.google.es *.google.fi *.google.fr *.google.ge *.google.gr *.google.gy *.google.hn *.google.hr *.google.ht *.google.hu *.google.ie *.google.im *.google.iq *.google.is *.google.it *.google.jo *.google.kg *.google.kz *.google.la *.google.lk *.google.lt *.google.lu *.google.lv *.google.md *.google.me *.google.mg *.google.mk *.google.mn *.google.mu *.google.mv *.google.mw *.google.ne *.google.nl *.google.no *.google.pl *.google.ps *.google.pt *.google.ro *.google.rs *.google.ru *.google.se *.google.si *.google.sk *.google.sm *.google.sn *.google.sr *.google.tn *.google.tt *.google.td *.google.je *.google.ws *.google.rw *.google.co.mz *.google.sc *.google.tm *.google.ga *.google.tg *.google.com.ag *.google.co.in *.google.ad *.google.ml *.google.cg cmp.auslogics.com; font-src 'self' fonts.gstatic.com use.fontawesome.com; object-src 'self'; media-src 'self'; form-action 'self'; frame-src 'self' m.youtube.com mc.yandex.com web.facebook.com www.facebook.com *.google.com www.googletagmanager.com www.youtube.com youtube.com; child-src 'self' www.facebook.com; worker-src 'self'; manifest-src 'self'; report-uri /secure-headers/report/r/d/csp/enforce; block-all-mixed-content; upgrade-insecure-requests 1 default-src 'none'; form-action 'none'; frame-ancestors 'none'; connect-src 'self' web-analytics.intelliscapesolutions.com analytics.intelliscapesolutions.com; font-src 'self' fonts.gstatic.com; frame-src www.google.com; img-src 'self' web-analytics.intelliscapesolutions.com analytics.intelliscapesolutions.com; manifest-src 'self'; script-src-elem 'self' 'unsafe-inline' donorbox.org web-analytics.intelliscapesolutions.com analytics.intelliscapesolutions.com www.google.com www.gstatic.com cdn.jsdelivr.net static.cloudflareinsights.com; script-src 'unsafe-eval' 'self' 'unsafe-inline' donorbox.org web-analytics.intelliscapesolutions.com analytics.intelliscapesolutions.com www.google.com www.gstatic.com; style-src-attr 'unsafe-inline'; style-src-elem 'self' 'unsafe-inline' fonts.googleapis.com; style-src 'self' 'unsafe-eval' 'unsafe-inline' fonts.googleapis.com; report-uri https://intelliscape.report-uri.com/r/d/csp/wizard 1 default-src data: https: 'unsafe-inline' 'unsafe-eval'; report-uri https://kontur.ru/csp 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.afterpay.com/ *.afterpaycdn.com *.squarecdn.com *.cash.app *.googleapis.com 'self' data: *.doubleclick.net *.facebook.com *.bing.com *.bing.net *.abtasty.com *.alicdn.com *.bootstrapcdn.com *.cdnfonts.com *.fontawesome.com *.googleusercontent.com *.slant.co zip-co-media.s3.ap-southeast-2.amazonaws.com *.zip.co *.qantas.com unpkg.com *.cloudflare.com *.totaltools.com.au *.afterpay.com *.zipmoney.com.au *.zohocdn.com *.jsdelivr.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com 'self' connect.facebook.net graph.facebook.com business.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.afterpay.com *.afterpaycdn.com *.squarecdn.com *.cash.app c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.doubleclick.net *.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com *.googletagmanager.com www.xtento.com zip.co static.zip.co sandbox.zip.co zipmoney.com.au sandbox.zipmoney.com.au checkout.gb.zip.co checkout.quadpay.com checkout-sandbox.quadpay.com https://*.online-metrix.net https://imgs.signifyd.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.afterpay.com/ *.afterpaycdn.com *.squarecdn.com *.cash.app www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.googleapis.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com magefan.com cm.magefan.com *.disqus.com connect.facebook.net graph.facebook.com business.facebook.com *.abtasty.com *.adroll.com *.adsrvr.org *.bing.com *.clarity.ms *.googleusercontent.com *.online-metrix.net *.openstreetmap.org *.quantcount.com *.quantserve.com *.signifyd.com *.unbxdapi.com *.zip.co *.afterpay.com *.tapad.com *.rubiconproject.com x.bidswitch.net pixel.tapad.com *.rlcdn.com *.openx.net *.yahoo.com *.pubmatic.com s3.amazonaws.com *.casalemedia.com *.adnxs.com *.amazon-adsystem.com *.stackadapt.com *.spotify.com *.sharethis.com *.bluekai.com *.contextweb.com *.kargo.com *.twitter.com *.addthis.com www.google.ae www.google.al www.google.am www.google.at www.google.az www.google.ba www.google.be www.google.bf www.google.bj www.google.bs www.google.bt www.google.by www.google.ca www.google.cd www.google.cg www.google.ch www.google.ci www.google.cl www.google.cm www.google.co.ao www.google.co.bw www.google.co.ck www.google.co.cr www.google.co.id www.google.co.il www.google.co.in www.google.co.jp www.google.co.ke www.google.co.kr www.google.co.ls www.google.co.ma www.google.co.nz www.google.co.th www.google.co.tz www.google.co.ug www.google.co.uk www.google.co.uz www.google.co.ve www.google.co.vi www.google.co.za www.google.co.zm www.google.co.zw www.google.com.ag www.google.com.ar www.google.com.au www.google.com.bd www.google.com.bh www.google.com.bn www.google.com.bo www.google.com.br www.google.com.bz www.google.com.co www.google.com.cy www.google.com.do www.google.com.ec www.google.com.eg www.google.com.et www.google.com.fj www.google.com.gh www.google.com.gt www.google.com.hk www.google.com.jm www.google.com.kh www.google.com.kw www.google.com.lb www.google.com.ly www.google.com.mm www.google.com.mt www.google.com.mx www.google.com.my www.google.com.na www.google.com.np www.google.com.om www.google.com.pa www.google.com.pe www.google.com.pg www.google.com.ph www.google.com.pk www.google.com.pr www.google.com.py www.google.com.qa www.google.com.sa www.google.com.sb www.google.com.sg www.google.com.sl www.google.com.sv www.google.com.tr www.google.com.tw www.google.com.ua www.google.com.uy www.google.com.vc www.google.cz www.google.de www.google.dk www.google.dz www.google.ee www.google.es www.google.fi www.google.fr www.google.ge www.google.gr www.google.gy www.google.hn www.google.hr www.google.hu www.google.ie www.google.im www.google.iq www.google.is www.google.it www.google.je www.google.jo www.google.kg www.google.ki www.google.kz www.google.la www.google.lk www.google.lt www.google.lu www.google.lv www.google.md www.google.me www.google.mg www.google.mk www.google.ml www.google.mn www.google.mu www.google.mv www.google.mw www.google.nl www.google.no www.google.nr www.google.pl www.google.ps www.google.pt www.google.ro www.google.rs www.google.ru www.google.rw www.google.sc www.google.se www.google.si www.google.sk www.google.sn www.google.so www.google.sr www.google.tg www.google.tl www.google.tm www.google.tn www.google.to www.google.tt www.google.vu www.google.ws link.totaltools.com.au render.barcodes.systems *.bing.net www.google.ad www.google.as www.google.co.mz www.google.com.cu www.google.com.vn www.google.cv www.google.dj www.google.ga www.google.gl www.google.gm www.google.ht www.google.sh www.google.td zip.co *.microsofttranslator.com *.totaltools.com.au 127.0.0.1 www.google.cf www.google.com.af www.google.com.gi www.google.com.ng www.google.com.ni www.google.com.tj www.google.dm www.google.fm www.google.gg *.baidu.com *.crwdcntrl.net *.google-analytics.com *.googleadservices.com *.jquery.com *.linksynergy.com *.paypalobjects.com *.scorecardresearch.com *.ytimg.com google.com www.google.nu *.alicdn.com *.imgur.com www.google.bi www.google.li www.google.ne www.google.pn www.google.sm www.google.st *.jsdelivr.net *.adform.net *.agkn.com *.amazon.com *.bidr.io *.clickagy.com *.criteo.com *.everesttech.net *.exelator.com *.icons8.com *.lijit.com *.linkedin.com *.mathtag.com *.rezync.com *.rfihub.com *.simpli.fi *.sitescout.com *.taboola.com www.xtento.com cdn.xtento.com t.zip.co static.zipmoney.com.au static.zip.co https://imgs.signifyd.com https://*.online-metrix.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.afterpay.com *.afterpaycdn.com *.squarecdn.com *.cash.app js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googleapis.com *.gstatic.com *.google.bg *.googletagmanager.com www.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.plugins.emarsys.net *.scarabresearch.com *.disqus.com connect.facebook.net graph.facebook.com business.facebook.com https://platform.cloud.coveo.com https://api.cloud.coveo.com https://search.cloud.coveo.com cdn-4.convertexperiments.com *.abtasty.com *.addthis.com *.adroll.com *.adsrvr.org *.bing.com *.clarity.ms d21gpk1vhmjuf5.cloudfront.net d3mewz86hy02zo.cloudfront.net *.emarsys.net *.online-metrix.net *.pricespider.com *.quantcount.com *.quantserve.com *.signifyd.com *.wufoo.com *.zip.co *.zdassets.com nexuspublications.com.au *.jsdelivr.net https://unpkg.com *.cloudflare.com *.microsofttranslator.com *.totaltools.com.au 127.0.0.1 googletagmanager.com unpkg.com *.fullstory.com *.googleadservices.com *.hotjar.com *.zipmoney.com.au sc-static.net rum.hlx.page translate.google.cn nominatim.openstreetmap.org api.smooch.io *.smooch.io *.coveo.com *.segment.com localhost *.cloudflareinsights.com *.nosto.com *.trackedlink.net https://hosted.mastersoftgroup.com/harmony/rest/v2/address/find https://hosted.mastersoftgroup.com/harmony/rest/au/generateID www.xtento.com cdn.xtento.com static.zipmoney.com.au static.zip.co zip.co https://cdn-scripts.signifyd.com https://imgs.signifyd.com https://h64.online-metrix.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.afterpay.com/ *.afterpaycdn.com *.squarecdn.com *.cash.app assets.braintreegateway.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.abtasty.com *.fontawesome.com *.typekit.net *.zip.co *.bing.com https://unpkg.com unpkg.com *.totaltools.com.au 127.0.0.1 *.bigcommerce.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.gstatic.com *.zdassets.com *.google.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.afterpay.com *.afterpay-beta.com *.afterpaycdn.com *.squarecdn.com *.cash.app api.lab.amplitude.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.googleapis.com *.google-analytics.com *.facebook.com *.facebook.net *.scarabresearch.com *.eservice.emarsys.net connect.facebook.net graph.facebook.com business.facebook.com https://platform.cloud.coveo.com https://api.cloud.coveo.com https://search.cloud.coveo.com *.abtasty.com *.addthis.com *.adroll.com *.adsrvr.org *.amplitude.com *.bing.com *.bing.net *.clarity.ms *.doubleclick.net *.emarsys.net *.gstatic.com *.pricespider.com *.quantcount.com *.quantserve.com *.samsung.com *.typekit.net *.unbxd.io *.zipmoney.com.au *.zip.co d21gpk1vhmjuf5.cloudfront.net d3mewz86hy02zo.cloudfront.net *.mastersoftgroup.com *.zendesk.com *.zopim.com wss://widget-mediator.zopim.com www.google.ae www.google.al www.google.am www.google.at www.google.az www.google.ba www.google.be www.google.bg www.google.bj www.google.bs www.google.bt www.google.ca www.google.cg www.google.ch www.google.ci www.google.cl www.google.co.ck www.google.co.cr www.google.co.id www.google.co.il www.google.co.in www.google.co.jp www.google.co.ke www.google.co.kr www.google.co.ma www.google.co.nz www.google.co.th www.google.co.tz www.google.co.ug www.google.co.uk www.google.co.ve www.google.co.za www.google.co.zm www.google.com.ar www.google.com.au www.google.com.bd www.google.com.bn www.google.com.bo www.google.com.br www.google.com.co www.google.com.cy www.google.com.ec www.google.com.eg www.google.com.et www.google.com.fj www.google.com.gh www.google.com.gt www.google.com.hk www.google.com.jm www.google.com.kh www.google.com.kw www.google.com.mm www.google.com.mx www.google.com.my www.google.com.na www.google.com.np www.google.com.om www.google.com.pa www.google.com.pe www.google.com.pg www.google.com.ph www.google.com.pk www.google.com.pr www.google.com.qa www.google.com.sa www.google.com.sb www.google.com.sg www.google.com.sv www.google.com.tr www.google.com.tw www.google.com.ua www.google.com.uy www.google.com.vn www.google.cz www.google.de www.google.dk www.google.ee www.google.es www.google.fi www.google.fr www.google.ge www.google.gr www.google.gy www.google.hr www.google.hu www.google.ie www.google.im www.google.iq www.google.it www.google.jo www.google.kg www.google.lk www.google.lt www.google.lu www.google.lv www.google.md www.google.me www.google.mg www.google.mk www.google.mn www.google.mu www.google.mv www.google.mw www.google.nl www.google.no www.google.nr www.google.pl www.google.pt www.google.ro www.google.rs www.google.ru www.google.se www.google.si www.google.tl www.google.to www.google.tt www.google.vu *.zdassets.com nominatim.openstreetmap.org www.google.bf www.google.by www.google.cd www.google.cm www.google.co.ao www.google.co.bw www.google.co.ls www.google.co.mz www.google.co.vi www.google.co.zw www.google.com.ag www.google.com.bh www.google.com.bz www.google.com.cu www.google.com.do www.google.com.lb www.google.com.mt www.google.com.sl www.google.com.vc www.google.dj www.google.dz www.google.gm www.google.hn www.google.ki www.google.kz www.google.la www.google.sh www.google.sk www.google.sr www.google.tg www.google.ws zip.co 127.0.0.1 www.google.ad www.google.com.ng www.google.com.tj www.google.ga www.google.is www.google.ml www.google.rw www.google.sc www.google.sn www.google.so www.google.tn *.alicdn.com *.googleadservices.com *.hotjar.com *.jquery.com www.google.as www.google.co.uz www.google.com.af www.google.com.ly www.google.com.ni www.google.com.py www.google.dm www.google.ht www.google.je www.google.nu www.google.ps *.openstreetmap.org *.signifyd.com *.totaltools.com.au rum.hlx.page www.google.bi www.google.fm www.google.gg www.google.li www.google.ne www.google.sm www.google.td *.baidu.com *.gstatic-cache.com *.coveo.com *.linkedin.com *.mixpanel.com *.segment.com *.segment.io localhost www.google.com.gi www.google.cv totaltoolsnonproduction1b9a600cn.org.coveo.com totaltoolsproduction1tptz1hbe.org.coveo.com totaltoolsnonproduction1b9a600cn.analytics.org.coveo.com totaltoolsproduction1tptz1hbe.analytics.org.coveo.com platform-au.cloud.coveo.com https://imgs.signifyd.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri *.adroll.com *.clarity.ms *.doubleclick.net *.google.com 'self' 'unsafe-inline'; report-uri https://f4c824ea-9c0b-4131-a2e2-886e99df7154.sansec.watch/; report-to report-endpoint; 1 script-src 'unsafe-inline' 'unsafe-eval' 'self' *.sleekplan.com *.mspbackups.com https://unpkg.com/ionicons@4.5.10-0/dist/ionicons/ d1f8f9xcsvx3ha.cloudfront.net posthog.mon.mspbackups.com https://salesiq.zohopublic.com https://static.zohocdn.com https://js.zohocdn.com https://momentjs.com/downloads/moment-timezone-with-data.min.js https://momentjs.com/downloads/moment.js https://code.jquery.com/jquery-3.5.1.min.js https://accounts.google.com/gsi/client https://alcdn.msauth.net/browser/2.28.1/js/msal-browser.min.js; report-uri /csp-violation-report-endpoint/ 1 default-src 'self'; object-src 'none'; base-uri 'self'; frame-ancestors 'none'; upgrade-insecure-requests 1 default-src 'self' image.spreadshirtmedia.net ; script-src 'self' 'unsafe-inline' 'unsafe-eval' data: https: *.go-mpulse.net apis.google.com assets.adobedtm.com *.cloudfront.net nxtck.com ssl.gstatic.com ws.sessioncam.com *.spreadshirt.net *.spreadshirt.com www.google-analytics.com www.google.com googleads.g.doubleclick.net connect.facebook.net www.googleadservices.com adtm.spreadshirts.net *.spreadshirt.de ; img-src 'self' data: https: image.spreadshirtmedia.net *.gstatic.com rtb-csync.smartadserver.com pixel.rubiconproject.com pixel.advertising.com dsum-sec.casalemedia.com cotads.adscale.de www.google-analytics.com eu-u.openx.net ih.adscale.de *.akstat.io www.facebook.com dsum-sec.casalemedia.com ad.yieldlab.net secure.adnxs.com mapping.nxtck.com stats.g.doubleclick.net www.google.com www.google.de cm.g.doubleclick.net ads.yahoo.com sync.ligadx.com eb2.3lift.com s.sspqns.com x.bidswitch.net image2.pubmatic.com sync.outbrain.com nxtck.com *.google-analytics.com *.analytics.google.com *.zdassets.com sanalytics.spreadshirt.de *.spreadshirt.de ; connect-src 'self' https: *.spreadshirt.net *.spreadshirt.com www.google-analytics.com www.google.com *.go-mpulse.net *.akstat.io/ dpm.demdex.net *.google-analytics.com *.analytics.google.com wss://*.zendesk.com *.spreadshirt.de ; font-src 'self' https: data: *.spreadshirt.de ; style-src 'self' data: 'unsafe-inline' https: *.spreadshirt.de ; object-src 'none' ; media-src image.spreadshirtmedia.net ; frame-src 'self' https: www.google.com accounts.google.com *.spreadshirt.de ; report-uri https://csp.spreadshirts.net/csp/reportOnly ; 1 connect-src analytics.tiktok.com *.google-analytics.com 'self' 'unsafe-inline' wss:;default-src 'self' 'unsafe-inline' wss:;form-action 'self' 'unsafe-inline' wss:;frame-src *.soundcloud.com 'self' 'unsafe-inline' 'unsafe-eval' *.cookiebot.com *.wearekura.com *.google-analytics.com;img-src *.siteimproveanalytics.io analytics.tiktok.com *.google-analytics.com 'self' 'unsafe-inline' 'unsafe-eval' *.cookiebot.com *.wearekura.com *.google-analytics.com;object-src 'none';script-src *.googletagmanager.com siteimproveanalytics.com analytics.tiktok.com 'self' 'unsafe-inline' 'unsafe-eval' *.cookiebot.com *.wearekura.com *.google-analytics.com;style-src 'self' 'unsafe-inline' 'unsafe-eval' *.cookiebot.com *.wearekura.com *.google-analytics.com 'self' 'unsafe-inline' wss: 1 worker-src https://www.googletagmanager.com; font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com *.klarnacdn.net maxcdn.bootstrapcdn.com https://geowidget.easypack24.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.adyen.com pay.google.com payments-eu.amazon.com *.amazon.de sandbox.przelewy24.pl secure.przelewy24.pl 'self' 'unsafe-inline'; frame-ancestors pay.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net https://www.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.adyen.com pay.google.com consentcdn.cookiebot.com consentcdn.cookiebot.eu *.google.com/ *.klarna.com *.packeta.com apm.przelewy24.pl secure.payu.com merch-prod.snd.payu.com https://geowidget-app.inpost.pl/ https://sandbox-easy-geowidget.easypack24.net/ 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.adyen.com pay.google.com *.payments-amazon.com *.media-amazon.com *.paypalobjects.com https://images.unsplash.com imgsct.cookiebot.com imgsct.cookiebot.eu magefan.com cm.magefan.com *.disqus.com https://www.magezon.com *.klarna.com *.klarnaevt.com *.klarnacdn.net tile.openstreetmap.org mapa.orlenpaczka.pl ruch-osm.sysadvisors.pl https://img.youtube.com static.przelewy24.pl www.gstatic.com gstatic.com static.payu.com https://geowidget.easypack24.net *.easypack24.net *.inpost.pl *.openstreetmap.org data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com https://maps.googleapis.com https://cdn.jsdelivr.net/npm/@ryangjchandler/spruce@2.x.x/dist/spruce.umd.js consent.cookiebot.com consent.cookiebot.eu *.disqus.com https://cdn.jsdelivr.net *.google.com/ *.klarna.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com mapa.orlenpaczka.pl *.packeta.com sandbox.przelewy24.pl secure.przelewy24.pl apm.przelewy24.pl secure.payu.com secure.snd.payu.com https://geowidget.easypack24.net *.easypack24.net *.inpost.pl *.openstreetmap.org unpkg.com *.snrbox.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com https://cdn.jsdelivr.net *.klarnacdn.net maxcdn.bootstrapcdn.com *.googleapis.com https://geowidget.easypack24.net https://geowidget.inpost.pl *.snrcdn.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com https://geowidget.easypack24.net 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.adyen.com payments-eu.amazon.com https://maps.googleapis.com https://player.vimeo.com consentcdn.cookiebot.com consentcdn.cookiebot.eu consent.cookiebot.com consent.cookiebot.eu *.klarnaevt.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.klarna.com nominatim.openstreetmap.org *.packeta.com sandbox.przelewy24.pl secure.przelewy24.pl wss://sandbox-ws.przelewy24.pl wss://secure-ws.przelewy24.pl apple-pay-gateway.apple.com apm.przelewy24.pl www.google.com pay.google.com secure.payu.com merch-prod.snd.payu.com *.easypack24.net *.inpost.pl *.openstreetmap.org *.snrbox.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' 'unsafe-inline' *.stripe.com data: *.alicdn.com *.clientgear.com *.pinterest.com *.doubleclick.net *.stripe.com *.googletagmanager.com *.bing.com *.pinimg.com *.taboola.com *.criteo.com *.criteo.net *.facebook.com omnisnippet1.com *.facebook.net *.soundestlink.com *.zdassets.com *.google-analytics.com *.pubmatic.com *.revcontent.com *.sharethrough.com *.smaato.net *.tremorhub.com *.clmbtech.com *.tpmn.co.kr *.vieldmo.com *.emxdgt.com *.bidswitch.net *.adnxs.com *.mediawallahscript.com contextual.media.net *.rubiconproject.com *.samrtadserver.com *.teads.tv *.31ift.com *.yahoo.com *.omnitagjs.com *.casalemedia.com *.stickyadstv.com *.360yield.com *.liadm.com *.tpmn.io *.mediavine.com *.postrelease.com *.outbrain.com *.tapad.com *.tapad.com *.yieldmo.com *.smartadserver.com *.demdex.net 'unsafe-eval' *.sentry.io *.imgdb.cn *.superbed.cn *.3lift.com *.rezync.com *.rfihub.com *.bluekai.com *.pippio.com *.turn.com *.zendesk.com *.google.com *.klaviyo.com *.googleadservices.com *.socdm.com *.adtdp.com *.dable.io *.adingo.jp *.rlcdn.com *.krxd.net *.yahoo.net *.recaptcha.net *.gstatic.com *.fridayparts.com *.tiktok.com *.paypal.com *.mczbf.com *.googleusercontent.com *.paypalobjects.com *.twitter.com *.ads-twitter.com *.omnisendlink.com *.impactcdn.com *.dotomi.com *.emjcd.com *.clarity.ms *.agkn.com *.adgrx.com *.aralego.com *.aralego.net *.targeting.unrulymedia.com *.1rx.io fridayparts.sjv.io *.jeeda.net *.bxtag.com *.youtube.com dev.visualwebsiteoptimizer.com 1 default-src 'self' blob: https://data.stbuttons.click/data https://challenges.cloudflare.com https://vod-progressive-ak.vimeocdn.com https://cdn.simplecast.com https://cdn.cookielaw.org https://geolocation.onetrust.com https://apps.sitecore.net https://stackpath.bootstrapcdn.com https://cdnjs.cloudflare.com https://code.jquery.com http://ajax.googleapis.com https://maps.googleapis.com https://geoip-js.com https://www.google-analytics.com https://cdn.siteimprove.net https://player.simplecast.com https://cdnjs.cloudflare.com https://my2.siteimprove.com https://id.siteimprove.com https://unpkg.com https://platform-api.sharethis.com https://l.sharethis.com/ https://player.vimeo.com https://extend.vimeocdn.com https://vod-progressive.akamaized.net https://download-video.akamaized.net https://cdn.yoshki.com https://download-video-ak.vimeocdn.com 'unsafe-inline' 'unsafe-eval'; img-src 'self' data: https://cdn.cookielaw.org https://www.googletagmanager.com https://www.google-analytics.com https://maps.googleapis.com https://maps.gstatic.com https://61281927.global.siteimproveanalytics.io/ https://cdn.yoshki.com https://61281927.global.siteimproveanalytics.io/ https://l.sharethis.com; style-src 'self' https://fonts.googleapis.com https://stackpath.bootstrapcdn.com https://cdn.jsdelivr.net https://unpkg.com 'unsafe-inline'; font-src 'self' data: https://fonts.gstatic.com 'unsafe-inline'; block-all-mixed-content; script-src 'self' https://buttons-config.sharethis.com https://challenges.cloudflare.com https://cdn.cookielaw.org https://www.googletagmanager.com https://maps.googleapis.com https://js.maxmind.com https://cdnjs.cloudflare.com/polyfill/ https://siteimproveanalytics.com https://www.google-analytics.com https://platform-api.sharethis.com https://extend.vimeocdn.com https://cdn.siteimprove.net http://ajax.googleapis.com https://code.jquery.com https://cdn.jsdelivr.net https://unpkg.com https://stackpath.bootstrapcdn.com https://cdnjs.cloudflare.com 'unsafe-inline' 'unsafe-eval'; connect-src 'self' https://cdn.cookielaw.org https://l.sharethis.com https://www.googletagmanager.com https://www.google-analytics.com https://data.stbuttons.click/data https://region1.google-analytics.com/g/collect https://www.googletagmanager.com/td; frame-ancestors 'self' https://www.independentsector.org; report-uri https://233122823c47f119af0143cbea7853d6.report-uri.com/r/d/csp/reportOnly; 1 block-all-mixed-content 1 default-src 'self' 'unsafe-inline' 'unsafe-eval'; report-uri https://csp-reporting.cloudflare.com/cdn-cgi/script_monitor/report?m=bEvmql5kkjk9y0FBoTTJFgkRwMjGRgNGYKaX3HLGn2s-1770429979-1.0.1.1-MCA0tAJC1NB3tyyN35QOTYcxNsA2l37W66x6eWORnfJsNL6WsFx0J.ToNlPL8eCj1EwVrnkeFdX3JywhtcPJMNHPV7rAgERtraVaJ4icOnGndQ9kTEymqzzRk2rKZOe0IX4nbGod8jstcGqt9D8b.0.GdR1B_ZKrV79W4fNd2DBzCPKRuK88MLUvHV2w8OjG; report-to cf-ambckxkouexouyjx 1 default-src blob: data: https: 'self'; style-src blob: https: 'self' 'unsafe-inline'; media-src blob: data: https: 'self'; connect-src blob: data: https: 'self' 'unsafe-inline' wss://*.hotjar.com; frame-ancestors 'self'; script-src blob: 'unsafe-eval' 'unsafe-inline' 'self' https://*.adform.net/ https://*.hotjar.com/ https://*.go-mpulse.net https://*.outbrain.com/ https://*.volvo.com/ https://*.volvotrucks.com/ https://ajax.googleapis.com/ajax/libs/jquery https://assets.adobedtm.com/ https://cdn.cookielaw.org/ https://connect.facebook.net/ https://documentservices.adobe.com/ https://googleads.g.doubleclick.net/ https://*.scene7.com/ https://script.e-space.se/ https://snap.licdn.com/ https://static.ads-twitter.com/ https://www.googletagmanager.com/ https://www.youtube.com/; report-to csp-endpoint; report-uri https://knxzhhty06.execute-api.eu-west-1.amazonaws.com/prod/browser-reporting/csp; 1 connect-src *.affirm.com https://tracker.affirm.com https://assets.braintreegateway.com *.braintreegateway.com *.braintree-api.com *.braze.com https://sdk.iad-05.braze.com/api/v3/data/ *.datadoghq.com *.browser-intake-us5-datadoghq.com https://browser-intake-us5-datadoghq.com https://session-replay.browser-intake-us5-datadoghq.com/api/v2/replay https://www.facebook.com https://connect.facebook.net https://www.facebook.com/tr/ *.forter.com wss://cdn0.forter.com https://d2o5idwacg3gyw.cloudfront.net https://dz8rit8v72mig.cloudfront.net https://db7q4jg5rkhk8.cloudfront.net https://1.1.1.1 https://d94qwxh6czci4.cloudfront.net https://dr6vcclmzwk74.cloudfront.net https://d6rak4b14t5gp.cloudfront.net https://d3k4bt74u9esq1.cloudfront.net https://d1ezzflfzltk6e.cloudfront.net https://d3nocrch4qti4v.cloudfront.net https://duuytoqss3gu4.cloudfront.net https://df45ay5pw60dy.cloudfront.net *.google.com https://www.google.com https://www.google-analytics.com https://www.google-analytics.com/j/collect https://www.gstatic.com https://www.google.com.mx https://www.googletagmanager.com https://google.com/pay https://adservice.google.com https://pay.google.com https://pay.google.com/about/redirect/ https://analytics.google.com https://fonts.gstatic.com https://www.googleadservices.com https://www.googletagmanager.com https://maps.googleapis.com https://googleads.g.doubleclick.net/ *.gr4vy.app https://paypal.com https://www.paypal.com/sdk/js https://checkout.paypal.com https://www.paypalobjects.com *.paypal.com https://ipv4.podscribe.com/ https://d34r8q7sht0t9k.cloudfront.net *.pusher.com https://sockjs-mt1.pusher.com wss://ws-mt1.pusher.com https://sandbox.affirm.com https://sandbox.affirm.com/fonts https://www.sandbox.paypal.com/ *.sentry.io *.ingest.sentry.io *.ingest.us.sentry.io api.statsig.com api.statsigcdn.com assetsconfigcdn.org beyondwickedmapping.org cdn.console.statsig.com cloudflare-dns.com console.statsig.com console.statsigcdn.com events.statsigapi.net featureassets.org featuregates.org idliststorage.blob.core.windows.net prodregistryv2.org statsigapi.net https://*.tiktok.com https://*.tiktokw.us *.amazonaws.com https://api.buttercms.com https://pixels.spotify.com bat.bing.com *.cloudfront.net *.doubleclick.net https://gametime.hnyj8s.net *.gametime.co/ https://boards-api.greenhouse.io/v1/boards/gametimeunited/departments https://global.ketchcdn.com *.mparticle.com *.riskified.com 'self';default-src 'self';font-src 'self' data: https://sandbox.affirm.com https://sandbox.affirm.com/fonts https://www.sandbox.paypal.com/ *.google.com https://www.google.com https://www.google-analytics.com https://www.google-analytics.com/j/collect https://www.gstatic.com https://www.google.com.mx https://www.googletagmanager.com https://google.com/pay https://adservice.google.com https://pay.google.com https://pay.google.com/about/redirect/ https://analytics.google.com https://fonts.gstatic.com https://www.googleadservices.com https://www.googletagmanager.com https://maps.googleapis.com https://googleads.g.doubleclick.net/ https://fp.affirm-stage.com https://use.fontawesome.com;form-action 'self' https://www.facebook.com https://connect.facebook.net https://www.facebook.com/tr/;frame-src https://assets.braintreegateway.com *.braintreegateway.com *.braintree-api.com https://www.facebook.com https://connect.facebook.net https://www.facebook.com/tr/ *.google.com https://www.google.com https://www.google-analytics.com https://www.google-analytics.com/j/collect https://www.gstatic.com https://www.google.com.mx https://www.googletagmanager.com https://google.com/pay https://adservice.google.com https://pay.google.com https://pay.google.com/about/redirect/ https://analytics.google.com https://fonts.gstatic.com https://www.googleadservices.com https://www.googletagmanager.com https://maps.googleapis.com https://googleads.g.doubleclick.net/ *.gr4vy.app https://paypal.com https://www.paypal.com/sdk/js https://checkout.paypal.com https://www.paypalobjects.com *.paypal.com https://sandbox.affirm.com https://sandbox.affirm.com/fonts https://www.sandbox.paypal.com/ bytedance: https://player.vimeo.com/ https://www.affirm.com sslocal: *.doubleclick.net 'self';img-src 'self' data: blob: *.gametime.co/ https://*.tiktok.com https://*.tiktokw.us *;manifest-src 'self' *.google.com https://www.google.com https://www.google-analytics.com https://www.google-analytics.com/j/collect https://www.gstatic.com https://www.google.com.mx https://www.googletagmanager.com https://google.com/pay https://adservice.google.com https://pay.google.com https://pay.google.com/about/redirect/ https://analytics.google.com https://fonts.gstatic.com https://www.googleadservices.com https://www.googletagmanager.com https://maps.googleapis.com https://googleads.g.doubleclick.net/;script-src *.affirm.com https://tracker.affirm.com https://assets.braintreegateway.com *.braintreegateway.com *.braintree-api.com *.braze.com https://sdk.iad-05.braze.com/api/v3/data/ https://www.facebook.com https://connect.facebook.net https://www.facebook.com/tr/ *.forter.com https://dlthst9q2beh8.cloudfront.net https://d2nww8zpyj5pk0.cloudfront.net https://d2w2nqfk3z9hdt.cloudfront.net *.google.com https://www.google.com https://www.google-analytics.com https://www.google-analytics.com/j/collect https://www.gstatic.com https://www.google.com.mx https://www.googletagmanager.com https://google.com/pay https://adservice.google.com https://pay.google.com https://pay.google.com/about/redirect/ https://analytics.google.com https://fonts.gstatic.com https://www.googleadservices.com https://www.googletagmanager.com https://maps.googleapis.com https://googleads.g.doubleclick.net/ *.gr4vy.app https://paypal.com https://www.paypal.com/sdk/js https://checkout.paypal.com https://www.paypalobjects.com *.paypal.com https://ipv4.podscribe.com/ https://d34r8q7sht0t9k.cloudfront.net *.sentry.io *.ingest.sentry.io *.ingest.us.sentry.io https://*.tiktok.com https://*.tiktokw.us https://app.link https://cdn.ketchjs.com https://cdn.sift.com/s.js https://utt.impactcdn.com https://applepay.cdn-apple.com bat.bing.com blob: https://global.ketchcdn.com *.mparticle.com 'report-sample' *.riskified.com 'self' 'unsafe-eval' 'unsafe-inline';style-src 'self' 'report-sample' 'unsafe-inline' https://fonts.googleapis.com https://use.fontawesome.com https://www.googletagmanager.com;worker-src 'self' blob: 1 report-to slardar-endpoint; script-src 'unsafe-eval' 'report-sample' 'nonce-85c198df5b92fc49e653f46b759ac5b1-argus' 'strict-dynamic'; 1 default-src 'self'; script-src 'self' 'nonce-MDc2Mjc0ZWYtYzBiMS00ZmY0LWI0OTktMzYyN2QyNTlhMzRh' 'strict-dynamic'; style-src 'self' https://fonts.googleapis.com https://www.googletagmanager.com https://d10lpsik1i8c69.cloudfront.net https://use.fontawesome.com 'unsafe-inline'; img-src 'self' https://storage.googleapis.com/bfile-prod-assets-img/ https://storage.googleapis.com/bfile-prod-assets-orig/ https://docserv.bstock.com https://*.bstock.com https://bstock.com https://*.bstock.com:443 https://bstock.com:443 https://liquidations.walmart.com https://liquidations.walmart.com:443 https://facebook.com https://www.facebook.com https://www.google.com https://*.google-analytics.com https://*.google-analytics.com:443 https://www.googletagmanager.com https://*.googlesyndication.com https://*.googlesyndication.com:443 https://*.linkedin.com https://bat.bing.com https://bat.bing.com:443 https://d10lpsik1i8c69.cloudfront.net https://*.cookielaw.org https://data.pendo.bstock.com data:; connect-src 'self' https://account.bstock.com https://docserv.bstock.com https://order.bstock.com https://location.bstock.com https://risk.bstock.com https://shipment.bstock.com https://payments-transactions.bstock.com https://bridge.bstock.com https://saved-search.bstock.com https://erp.bstock.com https://contract.bstock.com https://payments-methods.bstock.com https://ingestion.bstock.com https://auction.bstock.com https://search.bstock.com https://dispute.bstock.com https://order-process.bstock.com https://notification.bstock.com https://listing.bstock.com https://offering.bstock.com https://subscription.bstock.com https://auth.bstock.com https://bapi.bstock.com https://logs.browser-intake-datadoghq.com https://browser-intake-datadoghq.com https://*.launchdarkly.com https://*.bstock.com https://*.bstock.com:443 https://liquidations.walmart.com https://liquidations.walmart.com:443 https://use.fontawesome.com https://api.segment.io https://cdn.segment.com https://checkout-v2.sandbox.getbalance.com https://*.getbalance.com https://content-discoveryengine.googleapis.com https://www.google.com https://www.google.com:443 https://*.google-analytics.com https://*.google-analytics.com:443 https://analytics.google.com https://*.analytics.google.com https://www.googleadservices.com https://*.googlesyndication.com https://*.googlesyndication.com:443 https://px.ads.linkedin.com https://*.doubleclick.net https://*.doubleclick.net:443 https://bat.bing.com https://bat.bing.com:443 https://*.luckyorange.net https://*.luckyorange.com https://pubsub.googleapis.com https://*.nice-incontact.com https://*.mktoresp.com https://*.mktoutil.com ws://visitors.live ws://*.visitors.live https://sdk.iad-07.braze.com https://*.pusher.com ws://*.pusher.com https://data.pendo.bstock.com https://api.stripe.com https://maps.googleapis.com https://www.googletagmanager.com https://*.cookielaw.org https://*.onetrust.com; font-src 'self' https://fonts.gstatic.com https://fonts.gstatic.com:443 https://use.fontawesome.com; media-src 'self' https://d10lpsik1i8c69.cloudfront.net; frame-src 'self' https://www.google.com https://www.googletagmanager.com https://*.doubleclick.net https://*.js.stripe.com https://js.stripe.com https://hooks.stripe.com https://*.getbalance.com https://checkout-v2.sandbox.getbalance.com https://*.nice-incontact.com; report-uri /home-portal/api/csp-report; report-to csp 1 font-src fonts.gstatic.com use.typekit.net cash-f.squarecdn.com https://*.gstatic.com *.googleapis.com https://www.gstatic.com https://fonts.gstatic.com https://widgets.trustedshops.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com * *.adyen.com api.bazaarvoice.com stg.api.bazaarvoice.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.demdex.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ * *.adyen.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com https://*.google.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com https://www.googletagmanager.com/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com photos.pixlee.co 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net * https://*.gstatic.com *.adyen.com *.googleapis.com display.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com network-a.bazaarvoice.com network-stg-a.bazaarvoice.com photos-uat-us.bazaarvoice.com img.youtube.com https://*.google.com https://*.googleapis.com https://*.googleusercontent.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ *.webtrekk.net *.wt-eu02.net https://fbc.wcfbc.net https://*.flx1.com/ https://dmp.adform.net/ www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.pixlee.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net assets.adobedtm.com *.adobe.io www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com *.magento-ds.com *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com *.cash.app *.visa.com *.mastercard.com https://rum.hlx.page *.googleapis.com https://*.gstatic.com apps.bazaarvoice.com apps.nexus.bazaarvoice.com apps-stg.nexus.bazaarvoice.com analytics-static.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com mpsnare.iesnare.com https://*.google.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ https://responder.wt-safetag.com https://*.flx1.com/ https://www.googletagmanager.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com *.pxlecdn.com *.pixlee.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.magento-datasolutions.com *.magento-ds.com *.cash.app https://fonts.googleapis.com/ display.ugc.bazaarvoice.com https://fonts.googleapis.com https://hcaptcha.com https://*.hcaptcha.com unsafe-inline assets.braintreegateway.com https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.magento-datasolutions.com *.magento-ds.com * *.adyen.com *.googleapis.com api.bazaarvoice.com stg.api.bazaarvoice.com apps.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com api.addressy.com https://ipinfo.io https://*.google.com https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ https://*.flx1.com/ https://jamie.g.shortest-route.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com https://inbound-analytics.pixlee.com *.trustedshops.com *.etrusted.com https://integrations.etrusted.site 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://87a2b74d-7ec7-4aa0-9269-eab6629cdda1.sansec.watch/; report-to report-endpoint; 1 object-src 'none'; script-src 'self' 'report-sample' 'unsafe-eval' www.youtube.com vimeo.com cdnjs.cloudflare.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://player.vimeo.com https://unpkg.com; style-src 'self' 'report-sample' 'unsafe-inline' https://cdnjs.cloudflare.com https://unpkg.com; worker-src 'self'; base-uri 'self'; form-action 'self' https://login.microsoftonline.com; frame-ancestors 'self' 1 default-src * 'self' data: blob: 'unsafe-inline' 'unsafe-eval'; frame-ancestors 'self' cactusvpn.com www.cactusvpn.com billing.cactusvpn.com; report-uri https://75943a29954faa0d1b365a52c248c905.report-uri.com/r/d/csp/reportOnly; 1 default-src 'self' primericaonline.okta.com login.primericaonline.com *.oktacdn.com *.primerica.com *.primericaonline.com cdn.cookielaw.org kit.fontawesome.com *.contentstack.io; connect-src 'self' primericaonline.okta.com primericaonline-admin.okta.com login.primericaonline.com *.oktacdn.com *.mixpanel.com *.mapbox.com primericaonline.kerberos.okta.com primericaonline.mtls.okta.com *.authenticatorlocalprod.com:8769 http://localhost:8769 http://127.0.0.1:8769 *.authenticatorlocalprod.com:65111 http://localhost:65111 http://127.0.0.1:65111 *.authenticatorlocalprod.com:65121 http://localhost:65121 http://127.0.0.1:65121 *.authenticatorlocalprod.com:65131 http://localhost:65131 http://127.0.0.1:65131 *.authenticatorlocalprod.com:65141 http://localhost:65141 http://127.0.0.1:65141 *.authenticatorlocalprod.com:65151 http://localhost:65151 http://127.0.0.1:65151 https://oinmanager.okta.com data: *.primerica.com *.primericaonline.com cdn.cookielaw.org kit.fontawesome.com *.contentstack.io; script-src 'unsafe-inline' 'unsafe-eval' 'self' 'report-sample' primericaonline.okta.com login.primericaonline.com *.oktacdn.com *.primerica.com *.primericaonline.com cdn.cookielaw.org kit.fontawesome.com *.contentstack.io; style-src 'unsafe-inline' 'self' 'report-sample' primericaonline.okta.com login.primericaonline.com *.oktacdn.com *.primerica.com *.primericaonline.com cdn.cookielaw.org kit.fontawesome.com *.contentstack.io; frame-src 'self' primericaonline.okta.com primericaonline-admin.okta.com login.primericaonline.com login.okta.com *.vidyard.com com-okta-authenticator: *.primerica.com *.primericaonline.com cdn.cookielaw.org kit.fontawesome.com *.contentstack.io; img-src 'self' primericaonline.okta.com login.primericaonline.com *.oktacdn.com *.tiles.mapbox.com *.mapbox.com *.vidyard.com data: *.primerica.com *.primericaonline.com cdn.cookielaw.org kit.fontawesome.com *.contentstack.io blob:; font-src 'self' primericaonline.okta.com login.primericaonline.com data: *.oktacdn.com fonts.gstatic.com *.primerica.com *.primericaonline.com cdn.cookielaw.org kit.fontawesome.com *.contentstack.io; frame-ancestors 'self' https://mob.primericaonline.com https://*.primericaonline.com 1 default-src 'self'; script-src 'self' 'unsafe-eval'; connect-src 'self'; img-src 'self' data: www.pkobp.pl; style-src 'self' 'unsafe-inline'; font-src 'self'; report-uri /ikd_img/skins/ipko/grcv; 1 font-src fonts.googleapis.com fonts.gstatic.com *.googleapis.com *.gstatic.com data: oct8necdneu.azureedge.net *.trustedshops.com *.analytrix-tool.it *.convalytrix.it *.caast.tv *.efarma.dna-ai.dnafactory.it *.hotjar.com https://fonts.gstatic.com *.klarnacdn.net https://widgets.trustedshops.com *.yotpo.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.adyen.com sis-t.redsys.es:* sis.redsys.es sis-t.sermepa.es:* sis.sermepa.es * *.reskyt.com *.bing.com *.pinterest.com *.creativecdn.com *.tiktok.com *.t.co *.twitter.co *.doubleclick.net t.co *.twitter.com *.byspotify.com *.syndigo.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors *.googleapis.com https://www.salesmanago.pl https://api.clerk.io https://cdn.clerk.io 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.adyen.com *.vimeo.com *.oct8ne.com * *.cookiebot.com *.cookiebot.eu *.reskyt.com *.bing.com *.pinterest.com *.creativecdn.com *.tiktok.com *.t.co *.twitter.co *.doubleclick.net t.co *.twitter.com *.byspotify.com *.syndigo.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com *.klarna.com shein.m2e.cloud *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.adyen.com maps.googleapis.com maps.gstatic.com *.gstatic.com *.googleapis.com https://images.unsplash.com *.google.com *.google.es *.google.com.br *.googletagmanager.com *.google-analytics.com *.g.doubleclick.net oct8necdneu.azureedge.net *.trustedshops.com *.bynder.com analytics.tiktok.com *.clerk.io assets.atida.com connect.facebook.net *.cookiebot.eu efarma-supercraft.s3.eu-south-1.amzonaws.com dwin1.com facebook.com google.com google.it googletagmanager.com *.doubleclick.net yotpo.com *.zdassets.com gastatic.com *.yotpo.com *.analytrix-tool.it *.convalytrix.it *.efarma.dna-ai.dnafactory.it *.atida.com *.dosfarma.com *.facebook.com *.zenaps.com *.awin1.com *.reskyt.com *.bing.com *.pinterest.com *.creativecdn.com *.tiktok.com *.t.co t.co *.twitter.co *.twitter.com *.cloudfront.net *.byspotify.com *.cookiebot.com *.googlesyndication.com *.syndigo.com *.assets.efarma.com efarma-supercraft.s3.eu-south-1.amazonaws.com *.efarma.com *.bing.net *.usercentrics.eu *.hotjar.com *.content.aimatch.com *.efarma.req-api.cruxo.io *.mastercard.com *.visa.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.salesmanago.pl *.salesmanago.es *.salesmanago.com *.ggpht https://cdn.clerk.io *.klarna.com *.klarnaevt.com *.klarnacdn.net https://widgets.trustedshops.com https://widgets-qa.trustedshops.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.adyen.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.googleapis.com *.gstatic.com https://maps.googleapis.com https://player.vimeo.com https://cdn.jsdelivr.net/npm/@ryangjchandler/spruce@2.x.x/dist/spruce.umd.js polyfill.io *.google.com *.google.es *.google.com.br *.googletagmanager.com *.google-analytics.com *.g.doubleclick.net *.cookiebot.com *.oct8ne.com *.trustedshops.com *.analytrix-tool.it *.convalytrix.it *.caast.tv *.efarma.dna-ai.dnafactory.it *.clerk.io *.cloudfront.net *.zdassets.com *.zendesk.com *.api.smooch.io *.connectif.cloud *.atida.com *.dosfarma.com *.newrelic.com *.nr-data.net *.dwin1.com *.pinimg.com *.ads-twitter.com *.tiktok.com *.kk-resources.com *.bing.com *.creativecdn.com *.facebook.net *.googlesyndication.com *.awin1.com *.zenaps.com *.facebook.com *.wepowerconnections.com *.sciencebehindecommerce.com *.reskyt.com *.pinterest.com *.t.co *.twitter.co *.doubleclick.net t.co *.twitter.com *.byspotify.com *.syndigo.com *.cookiebot.eu stapecdn.com *.efarma.com *.hotjar.com *.content.aimatch.com *.efarma.req-api.cruxo.io *.mastercard.com *.visa.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.salesmanago.pl *.salesmanago.es *.salesmanago.com cdn.scalapay.com b2c-cdn.scalapay.com https://api.clerk.io https://cdn.clerk.io widget.freshworks.com m2epro.freshdesk.com *.klarna.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.trustedshops.com *.analytrix-tool.it *.convalytrix.it *.caast.tv *.efarma.dna-ai.dnafactory.it *.googletagmanager.com *.reskyt.com *.bing.com *.pinterest.com *.creativecdn.com *.tiktok.com *.t.co *.twitter.co *.doubleclick.net t.co *.twitter.com *.byspotify.com *.syndigo.com *.hotjar.com *.mastercard.com *.visa.com unsafe-inline assets.braintreegateway.com https://api.clerk.io https://cdn.clerk.io widget.freshworks.com m2epro.freshdesk.com https://fonts.googleapis.com *.klarnacdn.net https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.yotpo.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adyen.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.googleapis.com https://maps.googleapis.com https://player.vimeo.com *.google.com *.google.es *.google.com.br *.googletagmanager.com *.google-analytics.com *.g.doubleclick.net *.oct8ne.com *.google.com/pay *.analytrix-tool.it *.convalytrix.it *.clerk.io *.caast.tv *.efarma.dna-ai.dnafactory.it *.api.smooch.io *.zdassets.com *.zendesk.com *.connectif.cloud *.atida.com *.dosfarma.com *.algolia.io *.cookiebot.com *.cookiebot.eu *.nr-data.net google.com *.googlesyndication.com *.awin1.com *.zenaps.com *.facebook.com *.wepowerconnections.com *.sciencebehindecommerce.com *.reskyt.com *.bing.com *.pinterest.com *.creativecdn.com *.tiktok.com *.t.co *.twitter.co *.doubleclick.net t.co *.twitter.com *.byspotify.com *.syndigo.com *.bing.net *.efarma.com *.hotjar.com *.hotjar.io wss://ws.hotjar.com *.content.aimatch.com *.efarma.req-api.cruxo.io *.mastercard.com *.visa.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.salesmanago.pl *.salesmanago.es *.salesmanago.com widget.freshworks.com m2epro.freshdesk.com *.klarnaevt.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.klarna.com *.trustedshops.com *.etrusted.com https://integrations.etrusted.site *.yotpo.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.salesmanago.pl *.salesmanago.es *.salesmanago.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'none'; font-src 'self' fonts.gstatic.com data:; img-src * 'self' data: https: https://*.usepylon.com https://pylon-avatars.s3.us-west-1.amazonaws.com https://d3vl36l12sfx26.cloudfront.net; script-src 'self' 'unsafe-inline' *.clickhouse-dev.com:* *.clickhouse-staging.com:* *.clickhouse.cloud:* clickhouse.com discover.clickhouse.com statuspage.incident.io www.recaptcha.net recaptcha.net munchkin.marketo.net www.google.com google.com *.googletagmanager.com *.licdn.com www.gstatic.com js.stripe.com *.fullstory.com vercel.live https://widget.usepylon.com; style-src 'self' 'unsafe-inline' clickhouse.com discover.clickhouse.com fonts.googleapis.com vercel.live https://*.usepylon.com; object-src 'none'; worker-src 'self' blob:; connect-src 'self' 'unsafe-inline' clickhouse.com discover.clickhouse.com wss: *.clickhouse-dev.com:* *.clickhouse-staging.com:* *.clickhouse.cloud:* statuspage.incident.io www.recaptcha.net recaptcha.net *.us-east-2.amazonaws.com *.google-analytics.com *.linkedin.oribi.io *.mktoresp.com s3.eu-west-1.amazonaws.com *.fullstory.com *.auth0.com vercel.live https://*.usepylon.com wss://*.pusher.com; frame-src *.clickhouse-dev.com:* *.clickhouse-staging.com:* *.clickhouse.cloud:* clickhouse.com discover.clickhouse.com www.recaptcha.net recaptcha.net https://www.google.com https://www.googletagmanager.com https://js.stripe.com https://player.vimeo.com *.auth0.com vercel.live; frame-ancestors 'none'; 1 font-src *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.cloudflare.com *.cookiebot.com fonts.gstatic.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.feedaty.com https://firebasestorage.googleapis.com *.gumlet.io *.cookiebot.com *.google.it stileo.it *.adnxs.com *.sharethrough.com *.doubleclick.net *.bidswitch.net *.smartadserver.com *.taboola.com *.omnitagjs.com *.casalemedia.com *.criteo.com *.media.net *.mediavine. *.postrelease.com *.outbrain.com *.pubmatic.com *.rubiconproject.com *.teads.tv *.tremorhub.com *.ivitrack.com *.3lift.com *.yieldlab.net ad.360yield.com id5-sync.com sync.1rx.io sync-criteo.ads.yieldmo.com *.emxdgt.com *.servenobid.com *.unrulymedia.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.gstatic.com *.facebook.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.feedaty.com *.avada.io *.shopify.com https://widget.feedaty.com https://insights.algolia.io *.cookiebot.com *.dwin1.com *.criteo.com glamipixel.com *.cookieless-data.com *.cloudfront.net *.datnova.com *.sddan.com fonts.googleapis.com consent.cookiebot.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://www.googletagmanager.com tagmanager.google.com *.facebook.net unpkg.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.feedaty.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com https://widget.feedaty.com *.cloudflare.com *.cookiebot.com fonts.googleapis.com unsafe-inline assets.braintreegateway.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.algolia.net *.algolia.com *.algolianet.com insights.algolia.io *.feedaty.com https://get.geojs.io *.avada.io https://widget.feedaty.com *.cookiebot.com wss://ws.salecycle.com *.salecycle.com *.criteo.com *.doubleclick.net *.fontawesome.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.google-analytics.com *.facebook.net 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 script-src 'none'; report-uri https://csp-reporting.cloudflare.com/cdn-cgi/script_monitor/report?m=aM82FE2a9MJVIXvHJKuKRpeS_67cpg_zyMe4anHN7GE-1770426643.3857138-1.0.1.1-xkB67_2QcX1GeNRkhFn.JDh4r8ztcI4.wfku_JsU7eF2noILevz9Rlz14UITl8bHNxYeqXhTUHUgDwEQhJWro5hrJ3YK0KqpDLgr3pgXDYukm.m1swx5kkb4h0gd8BkSlieGXMQS8WuJPPFIIU5YoJ6OGMUi.xOjM_YVez71qsA; report-to cf-csp-endpoint 1 upgrade-insecure-requests; base-uri 'self'; object-src 'none'; script-src 'nonce-grWQTNu4b2AoLNbsVLEg1wEEj' 'strict-dynamic' 'report-sample'; report-uri https://blenderartists.org/csp_reports; frame-ancestors 'self'; manifest-src 'self' 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com cdn.jsdelivr.net cdn.almapay.com https://fonts.gstatic.com https://ws.colissimo.fr *.sagepay.com *.opayo.eu.elavon.com https://cdnjs.cloudflare.com 'self' data: static.sensefuel.live data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.sips-services.com *.sagepay.com *.opayo.eu.elavon.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com https://www.youtube.com *.youtube-nocookie.com bid.g.doubleclick.net www.googletagmanager.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.getalma.eu *.almapay.com/ *.stripe.com/ *.checkout.com/ *.adyen.com/ *.truefitcorp.com *.weltpixel.com https://form.typeform.com *.sagepay.com *.opayo.eu.elavon.com *.google.com/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.ftcdn.net *.behance.net *.paypal.com *.typekit.net *.gstatic.com *.afd.co.uk t.powerreviews.com assets-manager.abtasty.com https://maps.googleapis.com https://maps.gstatic.com https://ws.colissimo.fr https://*.tile.openstreetmap.fr https://*.onyourmap.com https://google.fr https://www.magezon.com *.sagepay.com *.opayo.eu.elavon.com ebizmarts-website.s3.amazonaws.com *.openstreetmap.org www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.hsforms.net *.hsforms.com 'self' data: data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.afd.co.uk cdn.jsdelivr.net js-agent.newrelic.com party.spockee.io app.ekoo.co ui.powerreviews.com *.truefitcorp.com https://maps.googleapis.com https://www.google.com https://www.gstatic.com https://ws.colissimo.fr https://api.mapbox.com https://*.typeform.com widget.proximis.com *.sagepay.com *.opayo.eu.elavon.com https://cdnjs.cloudflare.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com songbird.cardinalcommerce.com *.hsforms.net *.hsforms.com *.gstatic.com https://www.googletagmanager.com tagmanager.google.com tag.search.sensefuel.live pdata.damart.fr try.abtasty.com 'self' 'unsafe-eval' 'nonce-cW01bTkwYm03eHQwbzUwMzRoNjRkMmZ2bnd3cnZuYnA=' 'sha256-W5akSSK6LD5BjIlNICMcXaUObQSRAaj6bs7JHADURBA=' 'sha256-3qVqeAdyxxTdPkkRzqapjGkAUYLahxSrB7Mdup+GPQ0=' 'sha256-2rvfFrggTCtyF5WOiTri1gDS8Boibj4Njn0e+VCBmDI=' 'sha256-p8MCfMHqrovsjRYU9z0bU17dd0z81k/fVbGrtBBiM9g=' 'sha256-0pk2s4oXwBELlC6IBVb3nNaM2PjfjwI2N6OGIX5lx8Y=' 'sha256-nkEZknO0IxNxY/CkTMBhjNhwPvglpYumjx31B4fjkY8='; style-src *.adobe.com fonts.googleapis.com cdn.jsdelivr.net ui.powerreviews.com https://fonts.googleapis.com https://ws.colissimo.fr https://api.mapbox.com https://*.typeform.com *.sagepay.com *.opayo.eu.elavon.com https://cdnjs.cloudflare.com assets.braintreegateway.com *.googleapis.com *.gstatic.com tagmanager.google.com tag.search.sensefuel.live 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net vimeo.com www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.afd.co.uk *.getalma.eu *.almapay.com api.spockee.io backoffice-api.spockee.io ui.powerreviews.com display.powerreviews.com app.ekoo.co maps.googleapis.com https://ws.colissimo.fr https://maps.googleapis.com https://nominatim.openstreetmap.org https://*.onyourmap.com https://*.mapbox.com *.sagepay.com *.opayo.eu.elavon.com *.openstreetmap.org api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com c.search.sensefuel.live 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 upgrade-insecure-requests; frame-ancestors 'self' https://*.sensibull.com https://kite.zerodha.com; report-uri https://7eae552da389ebb083bedadbd9428ed2.report-uri.com/r/d/csp/reportOnly 1 default-src https: data: 'unsafe-inline' 'unsafe-eval'; img-src 'self' https://www.gpb.org https://ping.chartbeat.net https://tpc.googlesyndication.com https://googleads.g.doubleclick.net https://www.google.com https://ep1.adtrafficquality.google https://pagead2.googlesyndication.com https://securepubads.g.doubleclick.net https://*.pbs.org https://*.cdn.pbs.org https://image.isu.pub https://www.googletagmanager.com https://ads.adventive.com https://assets.adventivecdn.com https://cdn.wisepops.com data:; media-src 'self' https: http://cpa.ds.npr.org; font-src 'self' https://www.gpb.org https://fonts.gstatic.com data:; connect-src 'self' https://ping.chartbeat.net https://www.googletagmanager.com https://googleads.g.doubleclick.net https://script.crazyegg.com https://securepubads.g.doubleclick.net https://www.google.com https://*.googlesyndication.com https://wisepops.net https://*.wisepops.net https://www.google-analytics.com https://activity.wisepops.com https://ep1.adtrafficquality.google https://www.googleadservices.com https://onesignal.com https://*.crazyegg.com https://*.ingest.sentry.io https://bam.nr-data.net https://csi.gstatic.com https://tracking.wisepops.com; worker-src 'self' blob: https://script.crazyegg.com ; report-uri /report-csp-violation 1 default-src 'self' https://*.qiagen.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' blob: https://*.qiagen.com https://www.google.com https://www.gstatic.com https://www.recaptcha.net https://assets.adobedtm.com https://*.2o7.net https://*.omtrdc.net https://*.demdex.net https://cm.everesttech.net https://*.adobe.com https://tagmanager.google.com https://www.googletagmanager.com https://ads.google.com https://www.youtube.com https://view.ceros.com https://static.ceros.com https://sdk.ceros.com https://*.hotjar.com https://connect.facebook.net https://rum-static.pingdom.net https://vidassets.terminus.services https://ssl.google-analytics.com https://snap.licdn.com https://img.en25.com https://*.adroll.com https://bat.bing.com https://bat.bing.net https://*.twitter.com https://static.ads-twitter.com https://t.co https://*.reddit.com https://www.redditstatic.com https://www.gstatic.cn https://s7.addthis.com https://onesignal.com https://cdn.onesignal.com https://cdnjs.cloudflare.com https://cdn.mouseflow.com https://app.playable.com https://az416426.vo.msecnd.net https://*.eloqua.com https://www.googleadservices.com https://qiagen.my.site.com https://googleads.g.doubleclick.net https://pagead2.googlesyndication.com https://*.lumessetalentlink.com https://*.recruitmentplatform.com https://www.linkedin.com https://platform.linkedin.com https://cdn.jsdelivr.net https://*.criteo.com https://files.cdn.leadfamly.com https://unpkg.com; connect-src 'self' https://*.qiagen.com wss://*.qiagen.com https://*.applicationinsights.azure.com https://*.azurewebsites.net https://www.google.com https://www.gstatic.com https://www.recaptcha.net https://assets.adobedtm.com https://*.2o7.net https://*.omtrdc.net https://*.demdex.net https://cm.everesttech.net https://*.adobe.com https://edge.adobedc.net https://tagmanager.google.com https://www.googletagmanager.com https://ads.google.com https://windsor.ai https://www.linkedin.com https://px.ads.linkedin.com https://www.facebook.com https://x.com https://www.instagram.com https://view.ceros.com https://*.hotjar.com https://*.hotjar.io wss://ws.hotjar.com https://*.pingdom.net https://bat.bing.com https://bat.bing.net https://googleads.g.doubleclick.net https://pagead2.googlesyndication.com https://www.googleadservices.com https://dc.services.visualstudio.com https://api.b2b-qiagen.com https://t.co https://*.adroll.com https://*.reddit.com https://www.redditstatic.com https://*.twitter.com https://*.q4web.com https://graph.microsoft.com https://login.microsoftonline.com https://qiagen.my.salesforce-scrt.com https://*.lumessetalentlink.com https://*.recruitmentplatform.com https://onesignal.com https://geneglobe.b2b-qiagen.com https://journey-service.tb.lumesse.com https://eu01.rec.mouseflow.com; img-src 'self' data: https://*.qiagen.com https://www.google.com https://www.google.pl https://www.google.com.ph https://www.google.co.jp https://www.google.com.au https://www.google.co.kr https://www.google.com.vn https://www.google.com.br https://www.google.ca https://www.google.com.co https://www.google.pt https://www.google.ch https://www.google.de https://www.google.fr https://www.google.com.hk https://www.google.it https://www.google.com.ng https://www.google.co.mz https://www.google.co.in https://www.google.com.cy https://www.google.com.sa https://www.google.lk https://www.google.es https://www.google.co.uk https://www.google.tn https://www.google.com.my https://www.google.co.ke https://www.google.se https://www.google.com.tw https://www.google.at https://www.google.com.qa https://www.google.fi https://www.google.co.th https://www.google.cl https://www.google.co.id https://www.google.com.tr https://www.google.dz https://www.google.si https://www.google.co.il https://www.google.be https://www.google.dk https://www.google.jo https://www.google.com.gt https://www.google.com.sg https://www.google.by https://www.google.co.ao https://www.google.com.ar https://www.google.com.pk https://www.google.ae https://www.google.nl https://www.google.com.ua https://www.google.co.za https://www.google.com.eg https://www.google.rs https://www.google.iq https://www.google.no https://www.google.ro https://www.google.ru https://www.google.com.lb https://www.google.co.nz https://www.google.gr https://www.google.sk https://www.google.mk https://www.google.co.ma https://www.google.cz https://www.google.am https://www.google.lv https://www.google.co.tz https://www.google.co.zm https://www.gstatic.com https://www.googletagmanager.com https://www.googleadservices.com https://assets.adobedtm.com https://*.2o7.net https://*.omtrdc.net https://*.demdex.net https://cm.everesttech.net https://*.adobe.com https://www.facebook.com https://www.instagram.com https://x.com https://www.linkedin.com https://px.ads.linkedin.com https://www.youtube.com https://windsor.ai https://view.ceros.com https://static.ceros.com https://*.hotjar.com https://*.hotjar.io https://ssl.google-analytics.com https://snap.licdn.com https://bat.bing.com https://bat.bing.net https://assets.msn.com https://www.bing.com https://googleads.g.doubleclick.net https://cm.g.doubleclick.net https://pixel.tapad.com https://t.co https://*.adroll.com https://*.twitter.com https://*.reddit.com https://alb.reddit.com https://www.redditstatic.com https://translate.google.com https://*.eloqua.com https://*.q4cdn.com https://connect.facebook.net https://fonts.gstatic.com https://img.en25.com https://*.lumessetalentlink.com https://i.vimeocdn.com https://pagead2.googlesyndication.com https://yastatic.net https://qiagen-images.picturepark.com https://img.onesignal.com https://analytics.twitter.com; style-src 'self' 'unsafe-inline' https://*.qiagen.com https://www.gstatic.com https://tagmanager.google.com https://www.googletagmanager.com https://static.ceros.com https://fonts.googleapis.com https://maxcdn.bootstrapcdn.com https://qiagen.my.site.com https://*.lumessetalentlink.com https://*.recruitmentplatform.com https://onesignal.com; font-src 'self' data: https://*.qiagen.com https://*.hotjar.com https://fonts.gstatic.com https://fonts.googleapis.com https://maxcdn.bootstrapcdn.com https://cdn-ui.lumessetalentlink.com https://cdn.scite.ai; frame-src 'self' https://*.qiagen.com https://www.google.com https://recaptcha.google.com https://www.recaptcha.net https://*.demdex.net https://www.youtube.com https://player.vimeo.com https://www.facebook.com https://www.linkedin.com https://www.googletagmanager.com https://tagmanager.google.com https://view.ceros.com https://*.hotjar.com https://qiagen-marketing.videomarketingplatform.co https://login.microsoftonline.com https://qiagen.my.site.com https://*.worldpay.com https://*.criteo.com https://qiagen.leadfamly.com; media-src 'self' data: https://*.qiagen.com; report-uri https://o4510510210744320.ingest.de.sentry.io/api/4510510224441424/security/?sentry_key=aa80f7f205212fef130f4b0bfc9bfa4c; 1 connect-src 'self' https://nx.nav.com https://www.google.com https://px.ads.linkedin.com https://bat.bing.com https://*.clarity.ms https://pixel-config.reddit.com https://www.redditstatic.com https://conversions-config.reddit.com https://analytics.tiktok.com https://app.launchdarkly.com https://consentcdn.cookiebot.com https://events.launchdarkly.com https://*.intercom.io wss://*.intercom.io https://*.bugsnag.com https://analytics-ipv6.tiktokw.us https://analytics.tiktok.com https://www.facebook.com https://pagead2.googlesyndication.com https://www.buzzsprout.com 44.238.122.172 100.20.58.101 35.85.84.151 44.228.85.26 34.215.155.61 35.160.46.251 52.71.121.170 18.210.229.244 44.212.189.233 3.212.39.155 52.22.50.55 54.156.2.105; font-src 'self' https://design-assets.nav.com https://nav-web-static.nav.com https://fonts.googleapis.com https://fonts.gstatic.com *.intercomcdn.com; frame-src 'self' *.nav.com https://www.googletagmanager.com https://td.doubleclick.net https://consentcdn.cookiebot.com https://www.youtube.com https://job-boards.greenhouse.io https://www.buzzsprout.com https://www.google.com https://flo.uri.sh; script-src-elem 'self' 'strict-dynamic' 'unsafe-eval' https://nav-web-static.nav.com https://consentcdn.cookiebot.com https://px.mountain.com https://connect.facebook.net https://*.clarity.ms https://bat.bing.com https://www.buzzsprout.com 'nonce-d06a62ef28a7d5258d65cf219bebbccd'; style-src 'self' 'unsafe-inline' https://nav-web-static.nav.com https://fonts.googleapis.com; media-src 'self' https://nav-web-static.nav.com https://design-assets.nav.com https://nav-cms-assets.nav.com; base-uri 'none'; img-src * data: blob:; report-to csp-endpoint 1 default-src data: 'unsafe-inline' 'unsafe-eval' https: blob: http://*.files.wordpress.com wss://sourcingjournal.com; report-uri https://pmcuri.report-uri.com/r/d/csp/reportOnly 1 base-uri 'self'; child-src https://share.intercom.io https://intercom-sheets.com https://www.intercom-reporting.com https://www.youtube.com https://player.vimeo.com https://fast.wistia.net; connect-src 'self' https://*.cliniko.com https://stats.g.doubleclick.net https://www.google-analytics.com https://api.honeybadger.io https://*.intercom.io wss://*.intercom.io https://uploads.intercomcdn.com https://uploads.intercomusercontent.com; default-src 'self'; font-src 'self' data: https://*.cloudfront.net https://js.intercomcdn.com; form-action 'self' https://intercom.help https://api-iam.intercom.io; frame-ancestors 'none'; img-src 'self' data: https:; manifest-src 'self'; media-src: https://js.intercomcdn.com; script-src 'self' 'report-sample' 'unsafe-eval' 'unsafe-inline' https://www.google-analytics.com https://ssl.google-analytics.com https://app.intercom.io https://widget.intercom.io https://js.intercomcdn.com https://www.google.com/recaptcha/api.js https://www.gstatic.com; style-src 'self' 'report-sample' 'unsafe-inline'; report-uri https://fa4a51a09d12751e5d532cfce80751aa.report-uri.com/r/d/csp/reportOnly; 1 default-src 'self' thumbtack.okta.com *.oktacdn.com; connect-src 'self' thumbtack.okta.com thumbtack-admin.okta.com *.oktacdn.com *.mixpanel.com *.mapbox.com thumbtack.kerberos.okta.com thumbtack.mtls.okta.com *.authenticatorlocalprod.com:8769 http://localhost:8769 http://127.0.0.1:8769 *.authenticatorlocalprod.com:65111 http://localhost:65111 http://127.0.0.1:65111 *.authenticatorlocalprod.com:65121 http://localhost:65121 http://127.0.0.1:65121 *.authenticatorlocalprod.com:65131 http://localhost:65131 http://127.0.0.1:65131 *.authenticatorlocalprod.com:65141 http://localhost:65141 http://127.0.0.1:65141 *.authenticatorlocalprod.com:65151 http://localhost:65151 http://127.0.0.1:65151 https://oinmanager.okta.com data: *.ingest.sentry.io; script-src 'unsafe-inline' 'nonce-alhzAG8YMibjRiRY8MHN2A' 'unsafe-eval' 'self' 'report-sample' thumbtack.okta.com *.oktacdn.com; style-src 'unsafe-inline' 'nonce-alhzAG8YMibjRiRY8MHN2A' 'self' 'report-sample' thumbtack.okta.com *.oktacdn.com; frame-src 'self' thumbtack.okta.com thumbtack-admin.okta.com login.okta.com *.vidyard.com com-okta-authenticator:; img-src 'self' thumbtack.okta.com *.oktacdn.com *.tiles.mapbox.com *.mapbox.com *.vidyard.com data: blob:; font-src 'self' thumbtack.okta.com data: *.oktacdn.com fonts.gstatic.com; frame-ancestors 'self' https://idp.thumbtack.io 1 default-src 'self'; script-src 'self' 'unsafe-inline' https:; style-src 'self' 'unsafe-inline' https:; font-src 'self' https: data:; img-src 'self' https: data: blob:; connect-src 'self' https:; frame-src https:; frame-ancestors 'none':; base-uri 'self'; form-action https:; object-src 'none'; upgrade-insecure-requests; report-uri https://api.fwicloud.com/common/v1/csp-reports; report-to csp-endpoint 1 font-src fonts.gstatic.com use.typekit.net *.fontawesome.com https://cdnjs.cloudflare.com *.gstatic.com 'self' data: data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.adyen.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.adyen.com *.awin1.com *.zenaps.com *.fls.doubleclick.net account.wmf.com accountuat.wmf.com ad4m.at ct.pinterest.com fledge.eu.criteo.com groupe-seb.my.salesforce-sites.com gum.criteo.com service.force.com static.criteo.com static.criteo.net td.doubleclick.net www.paypalobjects.com www.sovendus-connect.com backoffice-eu.oct8ne.com static.trbo.com collect.trbo.com track2.trbo.com charger-v2.trbo.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io *.adyen.com *.awin1.com *.zenaps.com *.wepowerconnections.com magefan.com cm.magefan.com https://images.unsplash.com *.disqus.com https://img.youtube.com * https://api.mapbox.com *.hsforms.net *.hsforms.com 'self' data: *.contentsquare.net static.trbo.com collect.trbo.com track2.trbo.com data: 'self' 'unsafe-inline'; script-src www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.adyen.com *.awin1.com *.dwin1.com *.zenaps.com *.wepowerconnections.com https://the.sciencebehindecommerce.com lantern.roeyecdn.com *.disqus.com * https://cdnjs.cloudflare.com *.hsforms.net *.hsforms.com *.google.com *.gstatic.com *.contentsquare.net *.contentsquare.com halc.iadvize.com static.trbo.com api-v4.trbo.com charger-v2.trbo.com https://www.dwin1.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com *.fontawesome.com https://fonts.googleapis.com https://cdnjs.cloudflare.com *.googleapis.com *.gstatic.com service.force.com static.trbo.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.adyen.com *.wepowerconnections.com https://the.sciencebehindecommerce.com https://maps.googleapis.com autocomplete2.postdirekt.de t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com *.contentsquare.net app.contentsquare.com api.paypal.com ariane.abtasty.com bat.bing.com cdn.cookielaw.org content.hotjar.io ct.pinterest.com dcinfos-cache.abtasty.com geolocation.onetrust.com googleads.g.doubleclick.net identification-api.sovendus.com maps.googleapis.com measurement-api.criteo.com pagead2.googlesyndication.com privacyportal-eu.onetrust.com region1.analytics.google.com stats.g.doubleclick.net tag.commander1.com try.abtasty.com ws.hotjar.com www.google.com www.google.de www.pinterest.com halc.iadvize.com data.trbo.com newsletter-api.trbo.com api-v4.trbo.com 'self' 'unsafe-inline'; child-src *.awin1.com *.zenaps.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; script-src 'unsafe-inline' 'self' 'unsafe-eval' blob: bat.bing.net *.speedcurve.com network-eu.bazaarvoice.com api.bazaarvoice.com www.googleadservices.com *.cdn.parcellab.com www.mczbf.com googleads.g.doubleclick.net t.contentsquare.net analytics-static.ugc.bazaarvoice.com x.klarnacdn.net www.paypal.com static-eu.payments-amazon.com cdn-ukwest.onetrust.com om.ordergroove.com stg.api.bazaarvoice.com display-stg.ugc.bazaarvoice.com display.ugc.bazaarvoice.com services.postcodeanywhere.co.uk c.zmags.com maps.googleapis.com pagead2.googlesyndication.com www.googleadservices.com cdn.ometria.com ct.pinterest.com api.bounceexchange.com js.smct.io d.impactradius-event.com script.hotjar.com js.adsrvr.org static.ads-twitter.com ad.doubleclick.net smct.co platform.twitter.com analytics.tiktok.com static.hotjar.com bat.bing.com s.pinimg.com assets.bounceexchange.com cdn.parcellab.com intentclientscriptslon.s3.eu-west-2.amazonaws.com unpkg.com tag.wknd.ai unpkg.com cdn.particularaudience.com intentclientscriptslon.s3.eu-west-2.amazonaws.com unpkg.com cdn.cookielaw.org cdn.jsdelivr.net www.google-analytics.com e.cquotient.com p.cquotient.com static.ordergroove.com cdn.cquotient.com www.gstatic.com hotelchocolat.whoson.com cas.zma.gs hotel11113.pcapredict.com cdn-ukwest.onetrust.com www.googletagmanager.com www.google.com try.abtasty.com js.klarna.com; font-src data: x.klarnacdn.net fonts.gstatic.com smc-fonts.s3-eu-west-1.amazonaws.com images.getfastr.com maxcdn.bootstrapcdn.com c.zmags.com; style-src 'self' 'unsafe-inline' hotelchocolat.whoson.com *.cdn.parcellab.com display.ugc.bazaarvoice.com assets.bounceexchange.com x.klarnacdn.net styledisplay.ugc.bazaarvoice.com smc-fonts.s3-eu-west-1.amazonaws.com cdn.parcellab.com icons.parcellab.com services.postcodeanywhere.co.uk c.zmags.com fonts.googleapis.com maxcdn.bootstrapcdn.com cas.zma.gs; connect-src 'self' *.speedcurve.com *.algolianet.com *.contentsquare.net ad.doubleclick.net *.algolia.net wss://*.hotjar.com *.hotjar.com bat.bing.net *.hotjar.io *.ometria.com google.com www.paypal.com region1.google-analytics.com cdn-ukwest.onetrust.com region1.analytics.google.com www.mczbf.com q-aeu1.contentsquare.net www.pinterest.com api.parcellab.com events.bouncex.net storage.googleapis.com srm.ba.contentsquare.net k-aeu1.contentsquare.net adservice.google.com cognito-identity.eu-west-1.amazonaws.com ids.cdnwidget.com pd.cdnwidget.com view.cdnbasket.net page.cdnbasket.net data.cdnbasket.net js.smct.io stats.g.doubleclick.net analytics.google.com ssgtm.hotelchocolat.com c.contentsquare.net ad.doubleclick.net dcinfos-cache.abtasty.com geolocation.onetrust.com eu.playground.klarnaevt.com www.sandbox.paypal.com payments-eu.amazon.com om.ordergroove.com restapi.ordergroove.com services.postcodeanywhere.co.uk privacyportal-uk.onetrust.com na.klarnaevt.com insights.algolia.io stfgatlncw-dsn.algolia.net c.zmags.com pagead2.googlesyndication.com maps.googleapis.com googleads4.g.doubleclick.net www.googleadservices.com insight.adsrvr.org bat.bing.com www.google.com firehose.eu-west-1.amazonaws.com ep.smct.co ct.pinterest.com analytics.tiktok.com ct.pinterest.com ct.pinterest.com ipl.smct.io main.inference.madewithintent.ai recs-us-e1a.particularaudience.com cdn.cookielaw.org googleads4.g.doubleclick.net insight.adsrvr.org eu.klarnaevt.com cdn-ukwest.onetrust.com js.klarna.com try.abtasty.com cas.zma.gs www.google-analytics.com ariane.abtasty.com; img-src 'self' *.speedcurve.com data: www.googleadservices.com icons.parcellab.com www.google.co.uk bat.bing.net cj.dotomi.com tbs.tradedoubler.com www.emjcd.com googleads.g.doubleclick.net match.adsrvr.org insight.adsrvr.org api.bounceexchange.com network-eu-stg-a.bazaarvoice.com network-eu.bazaarvoice.com hotelchocolat.whoson.com events.smct.co www.google-analytics.com assets.bounceexchange.com l.contentsquare.net www.google.com trk.ometria.com c.contentsquare.net ad.doubleclick.net network-eu-stg.bazaarvoice.com static-eu.payments-amazon.com www.hotelchocolat.com m.media-amazon.com www.paypalobjects.com om.ordergroove.com blog.hotelchocolat.com services.postcodeanywhere.co.uk images.creator-prod.zmags.com www.googletagmanager.com maps.gstatic.com maps.googleapis.com *.cdnwidget.com events.bouncex.net bat.bing.com analytics.twitter.com t.co cdn.cookielaw.org images.getfastr.com img.creator-prod.zmags.com cdn-ukwest.onetrust.com; frame-src 'self' 6933631.fls.doubleclick.net 13586967.fls.doubleclick.net https://online.flippingbook.com match.adsrvr.org ssgtm.hotelchocolat.com td.doubleclick.net cnc-api.zmags.com www.sandbox.paypal.com www.paypal.com testsecureacceptance.cybersource.com www.google.com www.youtube.com ls.smct.io d2d7do8qaecbru.cloudfront.net www.googleadservices.com assets.bounceexchange.com ct.pinterest.com insight.adsrvr.org www.googletagmanager.com www.google.co.uk 1 object-src 'none';base-uri 'self';script-src 'nonce-SeQvYCC8AejzRPzShHAssw' 'strict-dynamic' 'report-sample' 'unsafe-eval' 'unsafe-inline' https: http:;report-uri https://csp.withgoogle.com/csp/gws/other-hp 1 object-src 'none'; script-src 'self' 'unsafe-inline' 'unsafe-eval' adform.net *.adform.net betano.com *.betano.com betano.de *.betano.de betgenius.com *.betgenius.com bing.com *.bing.com cloudflare.com *.cloudflare.com cookielaw.org *.cookielaw.org creativecdn.com *.creativecdn.com facebook.net *.facebook.net gmlinteractive.com *.gmlinteractive.com googletagmanager.com *.googletagmanager.com kaizengaming.com *.kaizengaming.com optimove.net *.optimove.net sportradar.com *.sportradar.com sportradarserving.com *.sportradarserving.com cloudflareinsights.com *.cloudflareinsights.com app.delivery *.app.delivery clarity.ms *.clarity.ms lgrckt-in.com *.lgrckt-in.com tostarsbuilding.com *.tostarsbuilding.com; report-uri https://csp-reporting.cloudflare.com/cdn-cgi/script_monitor/report?m=wI6MogfgzMx7MlZGToZ8WYyutMGGqvEYvwkgTIfhDAg-1770434769-1.0.1.1-PpvGQeUXVopKg48xnwcC.oLu5jAOu7Ga5L85e4hxat0JrZR.u4A.SycsR7KjFYFSYJfqvzQVe9vkHENvXV4zxEhwQjJIzket8NN2TBds9emblWKPTdQtX1aG6MRPcyJFxfiW0xqxFY37wuxaYvhsJVGv0.VZyJpDxvgaUYXfCm_Sxe9xYvwEUWZvBqkkf1.vJLrCPWcW.465edRN4fbf_Q; report-to cf-jkdrkzmscsioxmjc 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com https://fonts.bunny.net *.hotjar.com data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.authorize.net *.facebook.com 'self' 'unsafe-inline'; frame-ancestors *.certcapture.com *.authorize.net 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com *.braintreegateway.com *.paypal.com google.com *.google.com *.certcapture.com *.authorize.net challenges.cloudflare.com data: *.hotjar.com *.gstatic.com *.doubleclick.net *.facebook.com *.brand-display.com *.sitescout.com *.addthis.com *.metalocator.com *.googletagmanager.com *.medallia.com *.adsrvr.org *.ipredictive.com *.spotify.com *.byspotify.com *.weltpixel.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.certcapture.com magefan.com cm.magefan.com *.disqus.com https://firebasestorage.googleapis.com *.magentocommerce.com *.facebook.com *.doubleclick.net *.google.com *.brand-display.com *.sitescout.com *.googletagmanager.com *.googleapis.com *.analytics.yahoo.com *.ktxlytics.io *.adnxs.com *.metalocator.com *.scooterscoffee.com *.kampyle.com *.ipredictive.com *.spotify.com *.byspotify.com *.reddit.com *.ads-twitter.com t.co *.twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.certcapture.com *.disqus.com *.avada.io *.shopify.com *.authorize.net challenges.cloudflare.com *.bluecore.com *.facebook.net *.googleapis.com *.hotjar.com *.googletagmanager.com *.doubleclick.net *.gstatic.com *.brand-display.com *.cloudflare.com *.sitescout.com up.pixel.ad *.xg4ken.com *.usersnap.com chimpstatic.com data: *.ktxlytics.io *.app-us1.com *.amazonaws.com *.addthis.com *.addthisedge.com trackcmp.net *.moatads.com *.metalocator.com *.jsdelivr.net *.medallia.com *.snapchat.com *.trackedweb.net *.appboycdn.com sc-static.net *.adsrvr.org *.ipredictive.com *.spotify.com *.byspotify.com *.braze.com *.googleadservices.com *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.bing.com *.clarity.ms *.klaviyo.com unpkg.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.certcapture.com *.fontawesome.com https://fonts.bunny.net *.googleapis.com *.mailchimp.com *.typekit.net *.tagmanager.google.com *.googletagmanager.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.certcapture.com https://get.geojs.io *.avada.io *.authorize.net *.bluecore.com *.googleapis.com *.hotjar.com *.hotjar.io *.doubleclick.net *.ktxlytics.io *.medallia.com *.snapchat.com *.trackedweb.net *.appboycdn.com sc-static.net *.kampyle.com *.ipredictive.com *.spotify.com *.byspotify.com *.braze.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.run.app 'self' 'unsafe-inline'; child-src *.certcapture.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://scooterscoffee.com/; report-to report-endpoint; 1 default-src 'self' data: 'unsafe-inline' 'unsafe-eval' https:; report-uri https://usercontent.mobileread.org/csp-report 1 require-trusted-types-for 'script'; report-uri https://csp.withgoogle.com/csp/gfiber-static-marketing-jt-team 1 font-src *.google.com *.googletagmanager.com *.googleapis.com fonts.gstatic.com *.shareasale.com *.shareasale-analytics.com shareasale.com shareasale-analytics.com *.amazonaws.com *.shop.pe shop.pe *.juicer.io *.cloudfront.net v2.zopim.com data: *.bootstrapcdn.com *.yotpo.com *.kaltura.com *.nytrng.com nytrng.com *.dynamicyield.com https://*.gladly.com https://*.smooch.io https://d1fc8wv8zag5ca.cloudfront.net https://media.fbot.me *.gstatic.com dhv2ziothpgrr.cloudfront.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.google.com *.googletagmanager.com *.googleapis.com *.gstatic.com *.shareasale.com *.shareasale-analytics.com shareasale.com shareasale-analytics.com www.facebook.com *.amazonaws.com *.juicer.io shop.pe *.yotpo.com *.kaltura.com *.nytrng.com nytrng.com https://*.gladly.com https://*.smooch.io https://d1fc8wv8zag5ca.cloudfront.net *.authorize.net *.facebook.com 'self' 'unsafe-inline'; frame-ancestors *.authorize.net 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.googletagmanager.com *.dotdigital-pages.com *.dotdigital.com www.google.com *.googletagmanager.com *.googleapis.com *.gstatic.com *.shareasale.com *.shareasale-analytics.com shareasale.com shareasale-analytics.com *.amazonaws.com *.juicer.io *.shop.pe shop.pe *.criteo.com assets.bounceexchange.com vars.hotjar.com www.facebook.com imgs.signifyd.com h.online-metrix.net vendor1.leasestation.com amc.demdex.net nsg.symantec.com *.paypalobjects.com www.paypalobjects.com *.yotpo.com *.kaltura.com *.nytrng.com nytrng.com *.pinterest.com https://nl.fatquartershop.com https://widget.fbot.me *.dynamicyield.com https://*.gladly.com https://*.smooch.io https://d1fc8wv8zag5ca.cloudfront.net cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com *.authorize.net *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.trackedlink.net store.paradoxlabs.com *.google.com *.googletagmanager.com *.googleapis.com *.gstatic.com *.shareasale.com *.shareasale-analytics.com shareasale.com shareasale-analytics.com *.amazonaws.com *.juicer.io *.shop.pe shop.pe *.fatquartershop.com pixel.voltn.com v2.zopim.com www.google.co.in *.pinterest.com www.facebook.com *.cdnwidget.com u.cdnwidget.com bat.bing.com nsg.symantec.com events.bouncex.net pippio.com p.brsrvr.com connect.facebook.net imgs.signifyd.com events.cdnwidget.com api.bounceexchange.com amc.demdex.net *.e.aa.online-metrix.net match.adsrvr.org yotpo-editor-production.s3.amazonaws.com *.cdninstagram.com *.yotpo.com *.kaltura.com *.nytrng.com nytrng.com *.clarity.ms *.rqtrk.eu *.dynamicyield.com https://chat-assets.cdn.gladly.com https://chat-assets.cdn.gladly.qa maps.gstatic.com *.facebook.com dhv2ziothpgrr.cloudfront.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com www.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://rum.hlx.page *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal https://cnstrc.com/js/cust/fat-quarter-shop_Orxy5R.js www.google.com *.googletagmanager.com *.googleapis.com www.gstatic.com *.shareasale.com *.shareasale-analytics.com shareasale.com shareasale-analytics.com addshoppers.s3.amazonaws.com *.juicer.io *.traversedlp.com *.pinimg.com v2.zopim.com *.shop.pe shop.pe *.criteo.net *.criteo.com *.zdassets.com/ loader.wisepops.com *.cloudfront.net fatquartershop-com-dev.ecomm-nav.com connect.facebook.net vendor1.quickspark.com nsg.symantec.com script.crazyegg.com bat.bing.com tag.bounceexchange.com assets.bounceexchange.com cdn.brcdn.com imgs.signifyd.com cdns.brsrvr.com bam.nr-data.net js-agent.newrelic.com mc.s10.exacttarget.com *.hotjar.com bam-cell.nr-data.net *.yotpo.com *.kaltura.com *.nytrng.com nytrng.com *.staticw2.yotpo.com https://nl.fatquartershop.com *.rqtrk.eu *.clarity.ms https://static.fbot.me https://campaign.fbot.me *.dynamicyield.com *.zendesk.com https://cnstrc.com https://cdnjs.cloudflare.com/ajax/libs/Swiper/4.4.6/js/swiper.js https://*.gladly.com https://*.smooch.io https://d1fc8wv8zag5ca.cloudfront.net https://cdnjs.cloudflare.com https://chat-sdk.cdn.gladly.com https://chat-sdk.cdn.gladly.qa d2mjzob2nc713b.cloudfront.net fatquartershop.cdn1.safeopt.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com *.authorize.net maps.googleapis.com https://www.googletagmanager.com tagmanager.google.com *.facebook.net unpkg.com dhv2ziothpgrr.cloudfront.net *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com d18eg7dreypte5.cloudfront.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.google.com *.googletagmanager.com fonts.googleapis.com *.gstatic.com *.shareasale.com *.shareasale-analytics.com shareasale.com shareasale-analytics.com *.amazonaws.com *.juicer.io *.shop.pe shop.pe events.bouncex.net stats.g.doubleclick.net www.google-analytics.com *.cloudfront.net *.addshoppers.com *.bootstrapcdn.com *.yotpo.com *.kaltura.com *.nytrng.com nytrng.com *.staticw2.yotpo.com *.dynamicyield.com https://*.gladly.com https://*.smooch.io https://d1fc8wv8zag5ca.cloudfront.net https://chat-sdk.cdn.gladly.com https://chat-sdk.cdn.gladly.qa cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com tagmanager.google.com *.googleapis.com dhv2ziothpgrr.cloudfront.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'unsafe-inline' data: 'unsafe-inline' blob: *.yotpo.com *.kaltura.com *.nytrng.com nytrng.com *.dynamicyield.com *.zdassets.com/ https://chat-sdk.cdn.gladly.com https://chat-sdk.cdn.gladly.qa 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com *.google.com *.googletagmanager.com *.googleapis.com *.gstatic.com *.shareasale.com *.shareasale-analytics.com shareasale.com shareasale-analytics.com bat.bing.com *.amazonaws.com *.juicer.io *.shop.pe shop.pe ekr.zdassets.com script.crazyegg.com *.pinterest.com stats.g.doubleclick.net wss: manager.eu.smartlook.cloud in.hotjar.com staging-core.dxpapi.com core.dxpapi.com imgs.signifyd.com bt.signifyd.com:11103 data.cdnbasket.net ids.cdnwidget.com pd.cdnwidget.com page.cdnbasket.net/ view.cdnbasket.net bam.nr-data.net vc.hotjar.io bam-cell.nr-data.net api.traversedlp.com *.paypal.com *.yotpo.com *.kaltura.com *.nytrng.com nytrng.com *.clarity.ms https://public.fbot.me *.dynamicyield.com *.zendesk.com zendesk-eu.my.sentry.io *.cnstrc.com https://cdnjs.cloudflare.com/ajax/libs/Swiper/4.4.6/js/swiper.js https://*.gladly.com https://*.smooch.io https://d1fc8wv8zag5ca.cloudfront.net https://api.us-1.gladly.chat wss://ws.us-1.gladly.chat https://chat-assets.cdn.gladly.com https://chat-sdk.cdn.gladly.com https://api.us-uat.gladly.chat wss://ws.us-uat.gladly.chat https://chat-assets.cdn.gladly.qa https://chat-sdk.cdn.gladly.qa webchat.dotdigital.com webchat.staging.dotdigital.com *.authorize.net *.google-analytics.com *.facebook.net dhv2ziothpgrr.cloudfront.net *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src https: data: 'unsafe-inline' 'unsafe-eval' blob: wss:; report-uri https://464b711251f54c909b7a68dbb569ad3b.myssl-uri.com/api/csp-report 1 object-src 'none'; base-uri 'self'; script-src 'self' 'nonce-INlwanoXPK-YVOOs1p1wbQ' 'unsafe-inline' 'unsafe-eval' https://*.msauth.net https://*.msftauth.net https://*.msftauthimages.net https://*.msauthimages.net https://*.msidentity.com https://*.microsoftonline-p.com https://*.microsoftazuread-sso.com https://*.azureedge.net https://*.outlook.com https://*.office.com https://*.office365.com https://*.microsoft.com https://*.bing.com 'report-sample'; report-uri https://csp.microsoft.com/report/ESTS-UX-All 1 report-uri https://events.mercadolibre.com/csp/reports?identifier=SLMtHrhW3n-t8TXZUYgM-FQS_0LBBFQQRWLVBFkM864QkUR52OOKFmx5QIqC4krk36A=&policy_id=71&user_id=&request_id=c13cc1d0-0c1a-4421-982e-6f0949560957; report-to csp-endpoint-slmthrhwnttxzuygmfqslbbfqqrwlvbfkmqkurookfmxqiqckrka; frame-ancestors 'none' 1 font-src fonts.gstatic.com use.typekit.net *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com maxcdn.bootstrapcdn.com *.pushpushgo.com *.klevu.com data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.facebook.com *.googlesyndication.com *.constructor.com *.constructor.dev 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com player.vimeo.com https://www.google.com/recaptcha/ *.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.gstatic.com *.googlesyndication.com *.roeye.com *.pushpushgo.com *.klevu.com *.constructor.com *.constructor.dev data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com https://browser.sentry-cdn.com *.pushpushgo.com *.klevu.com *.constructor.com *.constructor.dev 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com maxcdn.bootstrapcdn.com *.klevu.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.adobe.io performance.typekit.net *.sentry.io *.google-analytics.com *.facebook.com *.facebook.net *.google.com *.doubleclick.net *.googlesyndication.com https://*.ingest.sentry.io *.constructor.com *.constructor.dev *.cnstrc.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 frame-src https://www.google.com/ https://optimize.google.com https://*.paddle.com https://www.recaptcha.net/; report-uri /api/v1/reports; script-src 'unsafe-inline' 'unsafe-eval' 'self' https://docs.staticstream.org https://*.google-analytics.com https://google-analytics.com https://www.googletagmanager.com https://tagmanager.google.com https://optimize.google.com https://www.googleoptimize.com https://www.recaptcha.net https://www.gstatic.com/recaptcha/ https://*.paddle.com https://*.zopim.com https://*.zdassets.com https://browser.sentry-cdn.com https://*.ingest.sentry.io https://cdn.jsdelivr.net https://code.jquery.com,; connect-src 'self' https://docs.staticstream.org https://*.google-analytics.com https://*.paddle.com https://browsec.zendesk.com wss://*.zopim.com https://*.zopim.com https://*.zdassets.com https://*.ingest.sentry.io https://bash.ws/ https://*.bash.ws/; 1 default-src 'self' blob: data: 'unsafe-inline' 'unsafe-eval' *.adobedtm.com *.amazon-adsystem.com *.appdemostore.com *.atdmt.com *.avocet.io *.blubrry.com *.clicktale.net *.craftyclicks.co.uk *.chatcora.natwest.com *.doubleclick.net *.everesttech.net *.facebook.com *.facebook.net *.fca.org.uk *.google.co.uk *.google.com *.google.ie *.googleadservices.com *.jwpcdn.com *.liveperson.net *.linkedin.com *.lpsnmedia.net *.neolane.net *.omguk.com *.omtrdc.net *.pinimg.com *.pinterest.com *.snapchat.com *.ulsterbank.co.uk *.ulsterbank.com *.ulsterbankanytimebanking.co.uk *.userzoom.com *.youtube.com *.ytimg.com analytics.twitter.com api.swiftype.com dcs.demdex.net dpm.demdex.net fast.demdex.net fast.rbs.demdex.net jwpltx.com rbs.demdex.net sc-static.net static.ads-twitter.com t.co www.brightedge.com; upgrade-insecure-requests; block-all-mixed-content; report-uri https://ulsterbankni.report-uri.com/r/t/csp/reportOnly 1 require-trusted-types-for 'script'; report-uri https://csp.withgoogle.com/csp/uxe-owners-acl/families_google 1 default-src 'self' http: https: wss: data: blob: 'unsafe-inline'; connect-src 'self' *.mypurecloud.com.au lifeline.payments2us.com *.typeform.com stockist.co *.youtube.com *.spotify.com *.vimeo.com vimeo.com cdn.usefathom.com *.hotjar.com *.clarity.ms *.google.com *.googletagmanager.com *.googleapis.com *.google-analytics.com *.gstatic.com connect.facebook.net lifeline.serviceseeker.com.au us-central1-stockist-prod.cloudfunctions.net *.bugherd.com; report-uri /report-csp-violation 1 script-src 'self' 'unsafe-inline' 'unsafe-eval' js.datadome.co ct.captcha-delivery.com *.onetrust.com *.googletagmanager.com *.cookielaw.org *.qualtrics.com *.salesforce.com *.en25.com *.segment.com *.amplitude.com *.salesforceliveagent.com *.sandbox.my.site.com reuters.my.site.com; script-src-elem 'self' 'unsafe-inline' www.datadoghq-browser-agent.com *.thomsonreuters.com reuters.my.site.com *.sandbox.my.site.com *.cookielaw.org *.amplitude.com *.segment.com *.googletagmanager.com js.datadome.co js.zuora.com ssl.p.jwpcdn.com; connect-src 'self' api-js.datadome.co *.onetrust.com *.cookielaw.org wss://*.rcp-api.reutersconnect.com *.reuters.com *.reutersconnect.com *.qualtrics.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com *.segment.io *.amplitude.com *.thomsonreuters.com *.segment.com browser-intake-datadoghq.com *.sandbox.my.salesforce-scrt.com reuters.my.salesforce-scrt.com cdn.jwplayer.com drmtd540xpi1f.cloudfront.net d3cgfqae8o6oiw.cloudfront.net d1qvkrpvk32u24.cloudfront.net d2tpo79pi2fb76.cloudfront.net d1uprxlryo4sfl.cloudfront.net d1s0weg9xjt2n5.cloudfront.net; frame-src 'self' geo.captcha-delivery.com *.onetrust.com *.salesforce.com *.sandbox.my.site.com reuters.my.site.com *.thomsonreuters.com d1hbvbum0y1xmw.cloudfront.net *.reuters.com; worker-src 'self' https://*.reutersconnect.com; report-uri https://reuters.report-uri.com/r/t/csp/reportOnly; report-to report-uri 1 default-src 'self'; connect-src *; img-src * data:; script-src 'nonce-0EViuBfMHnkxFn6PAhI18EvI0CW12ATo' 'unsafe-eval' 'strict-dynamic' 'unsafe-inline' 'self' https: http: 'self' cdn.bizible.com; style-src 'self' 'unsafe-inline' https://404-tpa-276.mktoweb.com/ https://*.qualified.com; font-src 'self' kit.fontawesome.com https://ka-p.fontawesome.com/ https://fast.wistia.com/ data:; form-action 'self'; object-src 'none'; media-src 'self' blob: mediastream: https://*.qualified.com; frame-src https://www.googletagmanager.com https://td.doubleclick.net/ https://gtm.casepeer.com/ https://gtm.mycase.com/ https://insight.adsrvr.org/ https://app.netlify.com/ https://404-tpa-276.mktoweb.com/ https://*.qualified.com; child-src https://*.qualified.com; frame-ancestors demo.affinipay.com ka-p.fontawesome.com; upgrade-insecure-requests; block-all-mixed-content; report-uri /.netlify/functions/__csp-violations 1 font-src * data: 'self'; img-src * blob: data: 'self'; script-src * data: wasm-eval: 'self' 'unsafe-eval' 'unsafe-inline' 'report-sample'; worker-src * blob: 'self'; frame-src * 'self'; default-src *; child-src * blob:; form-action * 'self'; object-src 'none'; style-src * 'unsafe-inline' 'self' data:; connect-src * 'self'; upgrade-insecure-requests; report-uri https://o166208.ingest.sentry.io/api/1238795/security/?sentry_key=eebe259ebaa846d39aaae0e3404505ab&sentry_environment=production 1 default-src 'self' aipoweredmarketer.okta.com login.goacoustic.com *.oktacdn.com www.acoustic.com app.goacoustic.com consent.trustarc.com; connect-src 'self' aipoweredmarketer.okta.com aipoweredmarketer-admin.okta.com login.goacoustic.com *.oktacdn.com *.mixpanel.com *.mapbox.com aipoweredmarketer.kerberos.okta.com aipoweredmarketer.mtls.okta.com https://oinmanager.okta.com data: www.acoustic.com app.goacoustic.com consent.trustarc.com *.ingest.sentry.io; script-src 'unsafe-inline' 'unsafe-eval' 'self' 'report-sample' aipoweredmarketer.okta.com login.goacoustic.com *.oktacdn.com www.acoustic.com app.goacoustic.com consent.trustarc.com; style-src 'unsafe-inline' 'self' 'report-sample' aipoweredmarketer.okta.com login.goacoustic.com *.oktacdn.com www.acoustic.com app.goacoustic.com consent.trustarc.com; frame-src 'self' aipoweredmarketer.okta.com aipoweredmarketer-admin.okta.com login.goacoustic.com login.okta.com *.vidyard.com www.acoustic.com app.goacoustic.com consent.trustarc.com; img-src 'self' aipoweredmarketer.okta.com login.goacoustic.com *.oktacdn.com *.tiles.mapbox.com *.mapbox.com *.vidyard.com data: www.acoustic.com app.goacoustic.com consent.trustarc.com blob:; font-src 'self' aipoweredmarketer.okta.com login.goacoustic.com data: *.oktacdn.com fonts.gstatic.com www.acoustic.com app.goacoustic.com consent.trustarc.com; frame-ancestors 'self' 1 default-src 'self' 'unsafe-inline' 'unsafe-eval' data: blob: play.google.com admin.google.com accounts.google.com www.google.com drive.google.com translate.google.com translate.googleapis.com www.edmonton.ca edmonton.ca data.edmonton.ca maps.edmonton.ca gis.edmonton.ca transforming.edmonton.ca webdocs.edmonton.ca portal-onecity.edmonton.ca coewebops.com www.youtube.com edmonton.box.com edmonton.app.box.com edmonton.box.com cdn01.boxcdn.net api.box.com public.boxcloud.com www.boxcdn.net www.boxcloud.com maps.googleapis.com fonts.googleapis.com www.googletagmanager.com cdn.ckeditor.com cdn.rawgit.com cdn.datatables.net cdn.siteimprove.net www.siteimprove.com my2.siteimprove.com identity.siteimprove.com cdnjs.cloudflare.com cdn.jsdelivr.net svc.webspellchecker.net momentjs.com connect.facebook.net www.facebook.net unpkg.com www.google-analytics.com *.youtube.com fonts.gstatic.com maps.gstatic.com www.gstatic.com maxcdn.bootstrapcdn.com www.pingdom.net siteimproveanalytics.com www.siteimproveanalytics.com script.crazyegg.com code.jquery.com pagestates-tracking.crazyegg.com tracking.crazyegg.com assets-tracking.crazyegg.com www.escribemeetings.com www.tfaforms.com api.recollect.net assets.ca.recollect.net recollect-images.global.ssl.fastly.net recollect.a.ssl.fastly.net prismjs.net prismjs.com cdn.curator.io api.curator.io curator-assets.b-cdn.net www.facebook.com www.youtube-nocookie.com www.escribemeetings.com www.ytimg.com media1.giphy.com wdi-prod.yellowdev.net www.datatables.net visionservicerequests.rehrigpacific.com cdn.honey.io player.vimeo.com walkinto.in pwm-image.trendmicro.com ajax.aspnetcdn.com calendar.google.com portal.edmonton.ca infird.com www.google.ca feedback.coewebops.com region1.google-analytics.com w.soundcloud.com stackpath.bootstrapcdn.com www.global.siteimproveanalytics.io public.tableau.com edmonton.maps.arcgis.com cdn-uicons.flaticon.com overbridgenet.com ka-p.fontawesome.com use.fontawesome.com kit.fontawesome.com 550744.global.siteimproveanalytics.io ajax.googleapis.com sheets.googleapis.com curatorio.s3.amazonaws.com assets.us.recollect.net pub-edmonton.escribemeetings.com sc-static.net i.ytimg.com api.privacy-protector-adblocker.com dl.boxcloud.com *.global.siteimproveanalytics.io cdn.toolszen.com 3001.scriptcdn.net www.slant.co cdn.megabonus.com api.mapbox.com; report-uri /report-csp-violation 1 default-src * data: 'unsafe-inline' 1 default-src 'self'; script-src 'self' 'unsafe-eval' 'unsafe-inline' https://site-bundle.chibbis.ru; script-src-elem 'self' 'unsafe-inline' blob: data: https://widget.me-talk.ru wss://widget.me-talk.ru https://mc.yandex.ru https://mc.yandex.com https://smartcaptcha.yandexcloud.net https://api-maps.yandex.ru https://yastatic.net https://api-maps.yandex.ru https://lcab.talk-me.ru https://checkout.cloudpayments.ru https://site-static.chibbis.ru https://site-bundle.chibbis.ru https://sentry.chibbis.ru; style-src 'self' data: 'unsafe-inline' https://site-bundle.chibbis.ru https://site-static.chibbis.ru; img-src 'self' data: https://static-featured-set-actual-production.chibbis.ru https://static-actual-production.chibbis.ru https://scdn.chibbis.ru https://static.chibbis.ru https://static.me-talk.ru https://core-renderer-tiles.maps.yandex.net https://mc.yandex.ru https://mc.yandex.com https://mc.yandex.kz https://mc.yandex.by https://qr.nspk.ru https://pic.me-talk.ru https://site-static.chibbis.ru; font-src 'self' https://site-static.chibbis.ru; manifest-src 'self' https://site-static.chibbis.ru; media-src 'self' https://widget.me-talk.ru; frame-src 'self' *; connect-src 'self' https://mc.yandex.ru https://mc.yandex.com wss://mc.yandex.ru wss://mc.yandex.com https://mc.yandex.kz https://mc.yandex.by https://mc.yandex.md https://yandex.ru https://yastatic.net https://core-renderer-tiles.maps.yandex.net https://api-maps.yandex.ru https://geocode-maps.yandex.ru https://static.me-talk.ru https://lcab.talk-me.ru https://widget.me-talk.ru wss://widget.me-talk.ru https://checkout.cloudpayments.ru https://api.cloudpayments.ru https://sentry.chibbis.ru; worker-src 'self' 'unsafe-inline' blob: data: https://widget.me-talk.ru wss://widget.me-talk.ru https://mc.yandex.ru https://mc.yandex.com https://smartcaptcha.yandexcloud.net https://api-maps.yandex.ru https://yastatic.net https://api-maps.yandex.ru https://lcab.talk-me.ru https://checkout.cloudpayments.ru https://site-static.chibbis.ru https://site-bundle.chibbis.ru https://sentry.chibbis.ru; base-uri 'self'; report-uri /health/csp; report-to default 1 font-src fonts.gstatic.com use.typekit.net data: *.hotjar.com github.com cdn.honey.io *.photoslurp.com *.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.redsys.es facebook.com *.adyen.com *.redsys.com *.pinterest.com sas.redsys.es *.facebook.com sas.redsys.com checkoutshopper-live.adyen.com checkoutshopper-test.adyen.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.hotjar.com *.google.com *.addthis.com *.kampyle.com facebook.com docs.google.com *.facebook.com *.pinterest.es *.pinterest.com service.force.com *.criteo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io *.ftcdn.net *.behance.net magefan.com cm.magefan.com *.disqus.com blob: *.w3.org *.bing.com c.bing.com *.hotjar.com *.paypal.com bat.bing.com *.clarity.ms *.google.fr facebook.com *.kampyle.com *.gstatic.com *.ladybird.nl *.google.com *.fbcdn.net *.cookiepro.com *.pinterest.com *.pronovias.com *.facebook.com *.google.es *.photoslurp.com *.googleapis.com *.sanpatrick.com *.nicolemilano.com *.cdninstagram.com instagram.com *.verawangbride.com *.whiteonebridal.com *.googletagmanager.com scontent.fmad7-1.fna.fbcdn.net click.s50.exacttarget.com * data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.disqus.com unpkg.com *.force.com bat.bing.com *.adyen.com *.pinimg.com *.google.com *.hotjar.com *.tiktok.com dropbox.com gstatic.com *.clarity.ms *.moatads.com *.addthis.com *.kampyle.com *.gstatic.com *.dropbox.com *.cookiepro.com *.facebook.net *.facebook.com facebook.net *.photoslurp.com *.googleapis.com *.salesforce.com *.addthisedge.com *.secure.force.com http://polyfill.io service.force.com bam.eu01.nr-data.net *.nicolemilano.com *.empathybroker.com x.empathy.co x.staging.empathy.co *.lightning.force.com analytics.tiktok.com *.googletagmanager.com googletagmanager.com *.salesforceliveagent.com static.lightning.force.com *.la3-c1cs-fra.salesforceliveagent.com d.la3-c1cs-fra.salesforceliveagent.com pronoviasgroup.my.salesforce.com *.pinterest.com player.vimeo.com *.surveymonkey.com *.criteo.com ct.pinterest.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.honey.io *.kampyle.com *.force.com *.photoslurp.com service.force.com *.nicolemilano.com gstatic.com *.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.vimeo.com *.akamaized.net *.photoslurp.com player.vimeo.com vod-progressive.akamaized.net 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net *.tt.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com *.adobe.io performance.typekit.net *.sentry.io wss: bat.bing.com *.force.com *.tiktok.com *.google.com *.hotjar.io *.clarity.ms *.vimeo.com d.clarity.ms h.clarity.ms *.kampyle.com *.hotjar.com google.com vc.hotjar.io ws7.hotjar.com *.instagram.com *.cookiepro.com *.pinterest.com *.amazonaws.com client.rum.us-east-1.amazonaws.com sts.eu-west-1.amazonaws.com ws16.hotjar.com ws20.hotjar.com ws22.hotjar.com ws23.hotjar.com ws33.hotjar.com ws34.hotjar.com *.facebook.com *.googleapis.com *.photoslurp.com *.secure.force.com bam.eu01.nr-data.net *.empathybroker.com x.empathy.co x.staging.empathy.co stats.g.doubleclick.net *.google-analytics.com api.empathybroker.com api.empathy.co api.staging.empathy.co *.cardinalcommerce.com api-staging.empathybroker.com pronoviasgroupcti.secure.force.com analytics.pangle-ads.com properties *.criteo.com *.onetrust.com *.pangle-ads.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 frame-src 'self' https://widget.mercuryo.io https://*.sumsub.com https://gwa.pgalta.com; report-uri 'https://sentry.walletbot.me/api/38/security/?sentry_key=544a92e441a24f17aa6b08e34e728ed2&sentry_environment=production'; report-to csp-endpoint; 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' cdn.pubnub.com www.googletagmanager.com cdn.sift.com scripts.clarity.ms www.clarity.ms unpkg.com *.clarity.ms googleads.g.doubleclick.net www.gstatic.com ssljscdn.airbrake.io www.google.com cdn.jsdelivr.net/npm/tinymce@5.4.1/; style-src 'self' 'unsafe-inline' fonts.googleapis.com self womp.me www.gstatic.com cdn.jsdelivr.net netdna.bootstrapcdn.com; img-src * data: blob:; font-src 'self' data: fonts.gstatic.com wompme.blob.core.windows.net netdna.bootstrapcdn.com use.typekit.net img1.wsimg.com; connect-src 'self' analytics.google.com *.clarity.ms www.google.com *.pndsn.com www.googletagmanager.com region1.analytics.google.com stats.g.doubleclick.net fu-tango.niteflirt.com www.google-analytics.com forum.niteflirt.com files.niteflirt.com api.airbrake.io www.google.ca www.google.co.uk; media-src *; frame-src 'self' www.googletagmanager.com platphorm.zendesk.com support.niteflirt.com t.niteflirt.com www.google.com j3lme1u30b.execute-api.us-west-2.amazonaws.com www.youtube.com; worker-src 'self' blob:; report-uri https://siteuri.report-uri.com/r/t/csp/reportOnly 1 frame-ancestors *.sbazar.cz 'self' *.seznam.cz *.sdn.cz https://pay.google.com https://connect-js.stripe.com https://js.stripe.com; script-src *.sbazar.cz 'self' 'unsafe-inline' 'unsafe-eval' *.seznam.cz *.sdn.cz *.szn.cz *.pszn.cz *.im.cz *.mapy.cz *.mapy.com https://gacz.hit.gemius.pl https://scz.hit.gemius.pl https://ls.hit.gemius.pl https://login.szn.cz https://notifikace.seznam.cz https://www.googletagmanager.com https://region1.google-analytics.com https://www.google-analytics.com https://connect.facebook.net https://*.hotjar.com https://*.hotjar.io wss://*.hotjar.com https://widget.packeta.com https://connect-js.stripe.com https://js.stripe.com *.adform.net *.adnxs.com *.adnxs-simple.com *.adsafeprotected.com *.consensu.org *.doubleclick.net *.doubleverify.com *.googlesyndication.com *.googletagservices.com *.imedia.cz *.imedia.dev.dszn.cz *.pliing.com *.pubmatic.com *.sbeta.cz *.sdn.szn.cz *.serving-sys.com *.sklik.cz ads.celtra.com *.2mdn.net ams.creativecdn.com cdn.id5-sync.com tags.crwdcntrl.net id5-sync.com/gm/v3 dis.criteo.com tracker.adnami.io script.adnami.io macro.adnami.io assets.adnami.io functions.adnami.io directive.adnami.io rmb.adnami.io https://www.sbazar.cz https://c.imedia.cz https://im.cz https://chat.sbazar.cz *.seznam.dev.dszn.cz *.seznam.test.dszn.cz; report-uri https://sentry.pszn.cz/api/232/security/?sentry_key=c74f7db661ae4cad8d94282c184d08f9 1 default-src 'self'; connect-src *; img-src * data:; script-src 'nonce-wUY/ZlwG+OgmVZmeI60Xb6+V8ruKdfMO' 'unsafe-eval' 'strict-dynamic' 'unsafe-inline' 'self' https: http: 'self' cdn.bizible.com; style-src 'self' 'unsafe-inline' https://404-tpa-276.mktoweb.com/ https://*.qualified.com; font-src 'self' kit.fontawesome.com ka-p.fontawesome.com https://fast.wistia.com/ https://fast.wistia.net/ data:; form-action 'self'; object-src 'none'; media-src 'self' blob: mediastream: https://*.qualified.com; frame-src https://www.googletagmanager.com https://td.doubleclick.net/ https://gtm.lawpay.com/ https://gtm.mycase.com/ https://insight.adsrvr.org/ https://app.netlify.com/ https://404-tpa-276.mktoweb.com/ https://*.qualified.com; child-src https://*.qualified.com; frame-ancestors demo.affinipay.com ka-p.fontawesome.com; upgrade-insecure-requests; block-all-mixed-content; report-uri /.netlify/functions/__csp-violations 1 default-src 'self' *.ctfassets.net *.trackjs.com *.demdex.net; script-src 'self' 'unsafe-eval' 'unsafe-inline' *.googletagmanager.com *.onetrust.com assets.adobedtm.com script.hotjar.com *.googleapis.com; script-src-elem 'self' 'unsafe-inline' *.hotjar.com assets.adobedtm.com *.go-mpulse.net cdn-ukwest.onetrust.com maps.googleapis.com fonts.googleapis.com static.hotjar.com *.googletagmanager.com; script-src-attr 'self' 'unsafe-inline'; style-src 'self' *.googleapis.com; style-src-elem 'self' 'unsafe-inline' cdn.honey.io *.googleapis.com *.googletagmanager.com; style-src-attr 'self' 'unsafe-inline'; img-src 'self' data: mdm-assets.integration.costacoffee.com *.demdex.net *.ctfassets.net *.trackjs.com costalimited.d3.sc.omtrdc.net *.gstatic.com *.onetrust.com cm.everesttech.net *.googleapis.com; font-src 'self' *.gstatic.com; connect-src 'self' web.costa-loyalty-platform.com ws://ws27.hotjar.com *.hotjar.com *.hotjar.io *.onetrust.com *.go-mpulse.net trial-eum-clientnsv4-s.akamaihd.net trial-eum-clienttons-s.akamaihd.net *.akstat.io *.demdex.net costalimited.d3.sc.omtrdc.net costalimited.tt.omtrdc.net *.onetrust.io *.trackjs.com maps.googleapis.com *.techlab-cdn.com login.costa.co.uk *.google-analytics.com wss://ws.hotjar.com; frame-ancestors 'self'; frame-src costalimited.demdex.net *.hotjar.com; report-uri https://costa.report-uri.com/r/t/csp/reportonly; report-to default 1 default-src 'self'; connect-src 'self' https://go.taxjar.com https://*.segment.io https://*.segment.com https://k.clarity.ms https://e.clarity.ms/collect https://q.clarity.ms/collect https://px.ads.linkedin.com https://bat.bing.com https://806-qbe-674.mktoresp.com https://806-qbe-674.mktoutil.com https://consent.trustarc.com https://www.google.com https://www.google-analytics.com https://analytics.google.com https://stats.g.doubleclick.net/g/ https://www.googletagmanager.com https://www2.profitwell.com https://services.postcodeanywhere.co.uk/Capture/Interactive/ https://taxjar.netlify.app https://yoast.com https://js.zi-scripts.com https://ws.zoominfo.com https://taxjar.widget.insent.ai https://fast.wistia.com/embed/captions/g4uankig3j.json https://fast.wistia.com/embed/medias/g4uankig3j.json https://fast.wistia.com/embed/medias/g4uankig3j.m3u8 https://embed-cloudfront.wistia.com/deliveries/7fa66650516dc3a087a4dacd4154fb30f54da9ea.m3u8 https://embed-cloudfront.wistia.com/deliveries/7fa66650516dc3a087a4dacd4154fb30f54da9ea.m3u8/seg-1-v1-a1.ts https://embed-cloudfront.wistia.com/deliveries/7fa66650516dc3a087a4dacd4154fb30f54da9ea.m3u8/seg-2-v1-a1.ts https://embed-cloudfront.wistia.com/deliveries/7fa66650516dc3a087a4dacd4154fb30f54da9ea.m3u8/seg-3-v1-a1.ts https://embed-cloudfront.wistia.com/deliveries/7fa66650516dc3a087a4dacd4154fb30f54da9ea.m3u8/seg-4-v1-a1.ts https://embed-cloudfront.wistia.com/deliveries/7fa66650516dc3a087a4dacd4154fb30f54da9ea.m3u8/seg-5-v1-a1.ts https://embed-cloudfront.wistia.com/deliveries/7fa66650516dc3a087a4dacd4154fb30f54da9ea.m3u8/seg-6-v1-a1.ts https://embed-cloudfront.wistia.com/deliveries/7fa66650516dc3a087a4dacd4154fb30f54da9ea.m3u8/seg-7-v1-a1.ts https://embed-cloudfront.wistia.com/deliveries/7fa66650516dc3a087a4dacd4154fb30f54da9ea.m3u8/seg-8-v1-a1.ts https://embed-cloudfront.wistia.com/deliveries/7fa66650516dc3a087a4dacd4154fb30f54da9ea.m3u8/seg-9-v1-a1.ts https://embed-cloudfront.wistia.com/deliveries/7fa66650516dc3a087a4dacd4154fb30f54da9ea.m3u8/seg-10-v1-a1.ts https://embed-cloudfront.wistia.com/deliveries/7fa66650516dc3a087a4dacd4154fb30f54da9ea.m3u8/seg-11-v1-a1.ts https://embed-cloudfront.wistia.com/deliveries/7fa66650516dc3a087a4dacd4154fb30f54da9ea.m3u8/seg-12-v1-a1.ts https://embed-cloudfront.wistia.com/deliveries/7fa66650516dc3a087a4dacd4154fb30f54da9ea.m3u8/seg-13-v1-a1.ts https://embed-cloudfront.wistia.com/deliveries/7fa66650516dc3a087a4dacd4154fb30f54da9ea.m3u8/seg-14-v1-a1.ts https://embed-cloudfront.wistia.com/deliveries/7fa66650516dc3a087a4dacd4154fb30f54da9ea.m3u8/seg-15-v1-a1.ts https://embed-cloudfront.wistia.com/deliveries/7fa66650516dc3a087a4dacd4154fb30f54da9ea.m3u8/seg-16-v1-a1.ts https://embed-cloudfront.wistia.com/deliveries/7fa66650516dc3a087a4dacd4154fb30f54da9ea.m3u8/seg-17-v1-a1.ts https://distillery.wistia.com/x https://pipedream.wistia.com/mput https://*.hotjar.io https://*.hotjar.com wss://ws.hotjar.com https://browser.sentry-cdn.com; font-src 'self' https://fonts.googleapis.com https://fonts.gstatic.com https://consent.trustarc.com https://fast.wistia.com; frame-src 'self' https://*.taxjar.com https://www.googletagmanager.com https://clarity.microsoft.com https://consent-pref.trustarc.com https://taxjar.widget.insent.ai https://privacy-central.securiti.ai; img-src 'self' blob: https://*.linkedin.com https://www.facebook.com https://consent.trustarc.com https://www.google.com/pagead/1p-user-list/ https://googleads.g.doubleclick.net/pagead/viewthroughconversion/975686394/ https://www.googletagmanager.com https://bat.bing.com https://c.bing.com https://embed-ssl.wistia.com/deliveries/ https://fast.wistia.com/assets/images/ https://secure.gravatar.com https://*.clarity.ms; media-src 'self' blob:; script-src 'self' 'unsafe-inline' 'unsafe-eval' blob: https://go.taxjar.com https://*.segment.com https://*.clarity.ms https://public.profitwell.com https://cdn.jsdelivr.net/npm/slick-carousel@1.8.1/slick/slick.min.js https://www.googletagmanager.com https://googleads.g.doubleclick.net/pagead/viewthroughconversion/975686394/ https://www.google-analytics.com https://snap.licdn.com https://munchkin.marketo.net https://my.hellobar.com https://static.hotjar.com https://connect.facebook.net https://script.hotjar.com https://bat.bing.com https://*.cloudfront.net/js/profitwell.js https://consent.trustarc.com https://browser.sentry-cdn.com https://api.addressy.com/js/ https://code.jquery.com https://fast.wistia.com/embed/medias/853xo00tjc.jsonp https://fast.wistia.com/embed/medias/yu81g7udgk.jsonp https://fast.wistia.com/embed/medias/hcgep638gh.jsonp https://fast.wistia.com/embed/medias/oehrrl4f31.jsonp https://fast.wistia.com/embed/medias/3how0hex6q.jsonp https://fast.wistia.com/embed/medias/z87muv02ls.jsonp https://fast.wistia.com/assets/external/E-v1.js https://fast.wistia.com/assets/external/captions.js https://fast.wistia.com/assets/external/playPauseLoadingControl.js https://fast.wistia.com/assets/external/interFontFace.js https://fast.wistia.com/assets/external/engines/hls_video.js https://fast.wistia.com/assets/external/vulcanV2Player/video/ui_components/Storyboard.js https://js.zi-scripts.com ws-assets.zoominfo.com https://taxjar.widget.insent.ai; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://go.taxjar.com; 1 report-uri https://csp.withgoogle.com/csp/youtube_main/strict;base-uri 'self';object-src 'none';script-src 'report-sample' 'nonce-0_97PGB5GBt5xOckhEk-rQ' 'unsafe-inline' 'strict-dynamic' https: http: 'unsafe-eval' 1 default-src 'self' 'report-sample'; connect-src 'self' https://matomo.psi.ch/; font-src 'self' data: player.podigee-cdn.net assets.brevo.com; frame-src 'self' *.ddev.site *.psi.ch player.vimeo.com www.youtube-nocookie.com feeds.sirop.org maps.google.com www.jove.com player.podigee-cdn.net cdnapisec.kaltura.com www.google.com www.srf.ch www.youtube.com psi.mediaspace.cast.switch.ch; img-src 'self' data: gfa-status.web.psi.ch share.web.psi.ch webcam.switch.ch; media-src 'self' *.ethz.ch data:; object-src 'none'; script-src 'self' 'report-sample' 'unsafe-inline' 'unsafe-eval' https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://maps.googleapis.com https://polyfill-fastly.io https://unpkg.com https://matomo.psi.ch/; script-src-elem 'self' 'unsafe-inline' test-t6dnbai-3bjapdgtwdrsg.eu-2.platformsh.site www.gstatic.com *.psi.ch www.google.com player.podigee-cdn.net sibforms.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://maps.googleapis.com https://polyfill-fastly.io https://unpkg.com; style-src 'self' 'report-sample' 'unsafe-inline' www.gstatic.com player.podigee-cdn.net sibforms.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com; webrtc 'block'; worker-src 'self'; base-uri 'self'; form-action 'self' www.google.com; frame-ancestors 'self'; report-uri https://www.psi.ch/de/log-report-uri/reportOnly 1 frame-ancestors 'self'; report-uri https://ordermygear.report-uri.com/r/t/csp/wizard 1 object-src 'none';base-uri 'self';script-src 'nonce-jQelzXCidh-nT5ZmHM0twA' 'strict-dynamic' 'report-sample' 'unsafe-eval' 'unsafe-inline' https: http:;report-uri https://csp.withgoogle.com/csp/gws/other-hp 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com cash-f.squarecdn.com *.googleapis.com data: *.bic.com *.shopbic.com *.bazaarvoice.com *.googleusercontent.com *.slant.co *.aws.projects.clever-age.net *.fontawesome.com fonts.googleapis.com https://cdnjs.cloudflare.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com * *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de api.bazaarvoice.com stg.api.bazaarvoice.com *.facebook.com *.wlp-acs.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.authorize.net assets.secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com pay.google.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.certcapture.com *.authorize.net assets.secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com pay.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com * www.google.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.certcapture.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com *.bic.com *.shopbic.com *.adsrvr.org *.amazon-adsystem.com *.criteo.com *.doubleclick.net *.googletagmanager.com *.pinterest.com *.sitescout.com *.snapchat.com *.tradedoubler.com *.wlp-acs.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com *.authorize.net assets.secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com pay.google.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net * *.googleapis.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.payments-amazon.com *.certcapture.com display.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com network-a.bazaarvoice.com network-stg-a.bazaarvoice.com photos-uat-us.bazaarvoice.com img.youtube.com *.bic.com *.shopbic.com *.aws.projects.clever-age.net *.adsrvr.org *.bazaarvoice.com *.bing.com *.clarity.ms *.contentsquare.net *.criteo.net *.doubleclick.net *.facebook.com *.facebook.net *.google.com *.googlesyndication.com *.googletagmanager.com *.googleusercontent.com *.ipredictive.com *.linkedin.com *.outbrain.com *.privacy-center.org *.sitescout.com *.tiktok.com s3.amazonaws.com www.google.ca www.google.es www.google.fr www.google.it www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.openstreetmap.org maps.googleapis.com maps.gstatic.com *.authorize.net assets.secure.checkout.visa.com sandbox.secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com pay.google.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com *.cash.app *.visa.com *.mastercard.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.certcapture.com apps.bazaarvoice.com apps.nexus.bazaarvoice.com apps-stg.nexus.bazaarvoice.com analytics-static.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com mpsnare.iesnare.com *.bic.com *.shopbic.com *.aws.projects.clever-age.net *.abtasty.com *.adsrvr.org *.amazon-adsystem.com *.bazaarvoice.com *.bing.com *.clarity.ms *.contentsquare.net *.criteo.com *.criteo.net *.doubleclick.net *.facebook.net *.googlesyndication.com *.googletagmanager.com *.licdn.com *.noibu.com *.outbrain.com *.pinimg.com *.pinterest.com *.pixel.ad *.privacy-center.org *.skeepers.io *.snapchat.com *.tiktok.com sc-static.net targetemsecure.blob.core.windows.net www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com https://widgets.rr.skeepers.io/ https://api-product-reviews.cxr.skeepers.io/ https://cl-ppr.rr.skeepers.io/ https://cl-pbr.cxr.skeepers.io/ https://cdnjs.cloudflare.com *.authorize.net assets.secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.cash.app *.certcapture.com display.ugc.bazaarvoice.com *.bic.com *.shopbic.com *.aws.projects.clever-age.net *.bazaarvoice.com *.googletagmanager.com *.typekit.net *.fontawesome.com https://fonts.googleapis.com https://cdnjs.cloudflare.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.bic.com *.shopbic.com *.bing.com *.gstatic.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com * *.googleapis.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.certcapture.com api.bazaarvoice.com stg.api.bazaarvoice.com apps.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com *.bic.com *.shopbic.com *.aws.projects.clever-age.net *.abtasty.com *.adsrvr.org *.amazon-adsystem.com *.bazaarvoice.com *.bing.com *.clarity.ms *.contentsquare.net *.criteo.com *.doubleclick.net *.facebook.com *.google-analytics.com *.googlesyndication.com *.gstatic.com *.linkedin.com *.noibu.com *.outbrain.com *.paa-reporting-advertising.amazon *.pinterest.com *.privacy-center.org *.samsung.com *.skeepers.io *.slgnt.eu *.snapchat.com *.tiktok.com *.typekit.net www.google.ca www.google.es www.google.fr www.google.it www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com maps.googleapis.com https://widgets.rr.skeepers.io/ https://api-product-reviews.cxr.skeepers.io/ https://cl-ppr.rr.skeepers.io/ https://cl-pbr.cxr.skeepers.io/ *.authorize.net assets.secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com pay.google.com 'self' 'unsafe-inline'; child-src *.certcapture.com http: https: blob: 'self' 'unsafe-inline'; default-src *.bic.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://b5d2d853-cb54-412f-93ec-9e1c49a8e581.sansec.watch/; report-to report-endpoint; 1 report-uri /csp-report.php; 1 default-src 'self';script-src 'self' 'unsafe-inline' 'unsafe-eval' https://www.googletagmanager.com https://www.google-analytics.com https://googleads.g.doubleclick.net https://www.googleadservices.com https://www.google.com https://static.hotjar.com https://script.hotjar.com https://js.adsrvr.org https://connect.facebook.net https://siteimproveanalytics.com https://static.ads-twitter.com https://cdn.taboola.com https://trc.taboola.com https://psb.taboola.com https://snap.licdn.com https://munchkin.marketo.net https://widget.tagembed.com https://cdn.tagembed.com https://cdn.theaccessplatform.com https://code.jquery.com https://platform.twitter.com https://www.youtube.com;style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://p.typekit.net https://use.typekit.net https://cdn.tagembed.com https://widget.tagembed.com https://cdn.theaccessplatform.com;object-src 'none';base-uri 'self';connect-src 'self' https://delivery-cqucontenthub.stylelabs.cloud https://fb.cqu.edu.au https://www-search.cqu.edu.au https://dxp-au-search.funnelback.squiz.cloud https://www.google-analytics.com https://analytics.google.com https://www.google.com.au https://google.com https://www.googletagmanager.com https://www.google.com https://adservice.google.com https://stats.g.doubleclick.net https://px.ads.linkedin.com https://pips.taboola.com https://cds.taboola.com https://622-hhc-246.mktoresp.com https://622-hhc-246.mktoutil.com https://www.facebook.com https://trc-events.taboola.com https://s3.us-west-1.wasabisys.com wss://ws.hotjar.com https://content.hotjar.io https://vc.hotjar.io https://psb.taboola.com https://api.theaccessplatform.com https://munchkin.marketo.net https://api.intentiq.com https://cdn.taboola.com https://region1.analytics.google.com https://widget.tagembed.com https://metrics.hotjar.io https://web.tagembed.com https://analytics.cqu.edu.au https://insight.adsrvr.org https://www.googleadservices.com;font-src 'self' data https://fonts.gstatic.com https://use.typekit.net https://cdn.theaccessplatform.com https://cdn.tagembed.com;frame-src 'self' https://www.googletagmanager.com https://insight.adsrvr.org https://9389440.fls.doubleclick.net https://www.youtube.com https://td.doubleclick.net https://www.facebook.com https://platform.twitter.com https://match.adsrvr.org https://tsdtocl.com https://player.vimeo.com https://eap.ascentone.com;img-src 'self' https://staff-profiles.cqu.edu.au https://delivery-cqucontenthub.stylelabs.cloud https://www.google-analytics.com https://www.google.com.au https://www.google.com https://www.googletagmanager.com https://www.google.com.co https://www.google.com.pe https://www.google.com.bd https://www.google.co.in https://www.google.com.ng https://www.google.com.np https://www.google.lk https://www.google.co.uk https://www.google.com.sg https://googleads.g.doubleclick.net https://www.googleadservices.com https://analytics.twitter.com https://px.ads.linkedin.com https://www.facebook.com https://78858.global.siteimproveanalytics.io https://t.co https://www.linkedin.com https://i.ytimg.com https://aumejtoqen.cloudimg.io https://ui-avatars.com https://fs.theambassadorplatform.com https://sync.intentiq.com https://cdn.taboola.com https://media.tagembed.com https://au-gmtdmp.mookie1.com https://secure.adnxs.com https://analytics.google.com https://i.vimeocdn.com https://stats.g.doubleclick.net https://connect.facebook.net;manifest-src 'self';media-src 'self' https://delivery-cqucontenthub.stylelabs.cloud;worker-src 'none';report-uri https://wwwcqu.report-uri.com/r/d/csp/reportOnly; 1 default-src 'self' https:; font-src 'self' https: data:; img-src 'self' https: data: https://*.stripe.com; object-src 'none'; script-src 'self' https: https://connect-js.stripe.com https://js.stripe.com https://*.js.stripe.com https://maps.googleapis.com 'nonce-wm82VlC7SoN4Zg10ilmHGg=='; style-src 'self' https: 'nonce-wm82VlC7SoN4Zg10ilmHGg=='; frame-src 'self' https://connect-js.stripe.com https://js.stripe.com https://*.js.stripe.com https://hooks.stripe.com; connect-src 'self' https://api.stripe.com https://maps.googleapis.com; report-uri /systems/csp_report 1 default-src 'self'; child-src 'self'; connect-src 'self' cdnjs.cloudflare.com *.algolia.net *.algolianet.com *.flickr.com *.googleapis.com *.google-analytics.com *.gstatic-cache.com *.typekit.com *.typekit.net https://www.google-analytics.com https://www.googletagmanager.com https://o15468.ingest.sentry.io/api/6068037/envelope/; font-src 'self' cdnjs.cloudflare.com *.typekit.net fonts.gstatic.com app.everviz.com/static/fonts/; frame-src 'self' maps.google.com *.typekit.net player.vimeo.com translate.googleapis.com *.twitter.com www.google.com www.googletagmanager.com *.youtube.com; img-src 'self' data: cdnjs.cloudflare.com *.staticflickr.com *.twitter.com *.typekit.net *.googletagmanager.com fonts.gstatic.com translate.google.com production-new-commonwealth-files.s3.eu-west-2.amazonaws.com staging-new-commonwealth-files.s3.eu-west-2.amazonaws.com testing-new-commonwealth-files.s3.eu-west-2.amazonaws.com https://www.google-analytics.com https://www.googletagmanager.com; media-src 'self' production-new-commonwealth-files.s3.eu-west-2.amazonaws.com staging-new-commonwealth-files.s3.eu-west-2.amazonaws.com testing-new-commonwealth-files.s3.eu-west-2.amazonaws.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' apis.google.com code.highcharts.com connect.facebook.net embedr.flickr.com player.vimeo.com unpkg.com www.googletagmanager.com www.gstatic.com app.everviz.com/resources/js/ app.everviz.com/inject cdn.jsdelivr.net cdnjs.cloudflare.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://nomoredirectory.org https://unpkg.com; script-src-attr 'self'; script-src-elem 'self' 'unsafe-inline' *.googletagmanager.com player.vimeo.com cdn.jsdelivr.net cdnjs.cloudflare.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://nomoredirectory.org https://unpkg.com; style-src 'self' 'unsafe-inline' code.highcharts.com *.typekit.net *.googleapis.com unpkg.com www.gstatic.com app.everviz.com/static/fonts/ app.everviz.com/resources/css/ cdn.jsdelivr.net cdnjs.cloudflare.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://nomoredirectory.org https://unpkg.com; style-src-attr 'self' 'unsafe-inline'; style-src-elem 'self' 'unsafe-inline' *.typekit.net cdn.jsdelivr.net cdnjs.cloudflare.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://nomoredirectory.org https://unpkg.com; frame-ancestors 'self'; report-uri https://thecommonwealth.org/log-report-uri/reportOnly 1 default-src 'self'; script-src 'self' https://trusted-scripts.com; style-src 'self' 'unsafe-inline'; img-src 'self' data: https://trusted-images.com; font-src 'self'; frame-src 'self' https://forms.office.com; object-src 'none'; base-uri 'self'; form-action 'self'; report-uri https://your-reporting-endpoint.com/report-csp; 1 default-src 'self'; script-src 'self' 'unsafe-eval' 'unsafe-inline' blob: dvngeac8rg9mb.cloudfront.net js.stripe.com www.gstatic.com *.googleapis.com ws.zoominfo.com www.google.com www.googletagmanager.com compilers.widgets.sphere-engine.com kit.fontawesome.com d34s7xanp5e5sf.cloudfront.net; connect-src 'self' api.stripe.com *.googleapis.com *.fontawesome.com wss://push.piazza.com; img-src 'self' data: http: https:; object-src 'none'; font-src 'self' data: *.typekit.net *.gstatic.com *.fontawesome.com; style-src 'self' 'unsafe-inline' blob: *.typekit.net *.gstatic.com *.googleapis.com dvngeac8rg9mb.cloudfront.net; frame-src 'self' www.youtube.com www.youtube-nocookie.com www.vimeo.com player.vimeo.com www.facebook.com youtu.be gfycat.com www.google.com giphy.com docs.google.com calendar.google.com www.desmos.com www.geogebra.org js.stripe.com; report-uri /security/csp_report 1 default-src 'self'; script-src 'self' 'nonce-LqRakfACtrV64+VXxXZVgw==' https://cdn-cookieyes.com https://www.google-analytics.com https://www.googletagmanager.com https://static.hotjar.com https://stats.xovis.com https://www.youtube.com; style-src 'self' 'nonce-LqRakfACtrV64+VXxXZVgw=='; style-src-attr 'unsafe-inline'; img-src 'self' data: blob: https://www.googletagmanager.com https://cdn-cookieyes.com https://api.xovis.com; media-src 'self' data: https://api.xovis.com; font-src 'self' data:; connect-src 'self' https://*.google-analytics.com https://stats.xovis.com https://*.hotjar.io https://cdn-cookieyes.com https://*.cookieyes.com https://api.xovis.com; frame-src 'self' http://iframely.net https://go.xovis.com https://www.youtube-nocookie.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'; report-uri /csp-report 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' www.google-analytics.com www.googletagmanager.com *.googleapis.com static.cloudflareinsights.com unpkg.com translate.googleapis.com; object-src 'self'; style-src 'self' 'unsafe-inline' fonts.googleapis.com unpkg.com; img-src 'self' data: www.google-analytics.com www.googletagmanager.com v1.sahistory.org.za http://v1.sahistory.org.za http://www.v1.sahistory.org.za https://v1.sahistory.org.za *.tile.openstreetmap.org unpkg.com http://www.sahistory.org.za http://sahistory.org.za https://www.sahistory.org.za translate.google.com translate.googleapis.com fonts.gstatic.com; media-src 'self'; frame-src 'self' www.youtube.com youtube.com; frame-ancestors 'self'; child-src 'self'; font-src 'self' fonts.gstatic.com data:; connect-src 'self' *.google-analytics.com www.google-analytics.com www.googletagmanager.com translate.googleapis.com; report-uri /report-csp-violation; upgrade-insecure-requests 1 default-src 'self'; style-src 'self' 'unsafe-inline' https://stackpath.bootstrapcdn.com https://fonts.googleapis.com https://cdn.jsdelivr.net https://optimize.google.com https://fonts.googleapis.com; script-src 'self' https://*.smallcase.com https://www.google-analytics.com https://ssl.google-analytics.com https://www.googletagmanager.com https://app.link https://script.hotjar.com https://static.hotjar.com https://www.youtube.com https://s.ytimg.com https://apis.google.com https://connect.facebook.net https://*.razorpay.com https://*.gateway-tt.in https://cdn.segment.com https://cdn.amplitude.com https://cdn.moengage.com https://stackpath.bootstrapcdn.com https://a.quora.com https://q.quora.com 'unsafe-eval' 'unsafe-inline' https://appleid.cdn-apple.com https://optimize.google.com https://www.googleoptimize.com https://*.googlesyndication.com https://partner.googleadservices.com https://www.googletagservices.com https://adservice.google.com https://adservice.google.co.in https://*.tickertape.in https://*.vmax.com https://*.smartyads.com https://*.itdsmr.com https://*.google.com https://www.gstatic.com https://*.nexum.smallcase.com https://securepubads.g.doubleclick.net https://cms.stag.smallcase.com https://tally.so/widgets/embed.js https://www.clarity.ms https://bfin.creditcase.in; img-src 'self' data: https://*.tickertape.in http://*.tickertape.in https://*.smallcase.com https://*.cloudfront.net https://s3.ap-south-1.amazonaws.com https://s3.amazonaws.com https://www.google-analytics.com https://stats.g.doubleclick.net https://www.googletagmanager.com https://www.google.com https://www.google.co.in https://pocket-image-cache.com https://*.ytimg.com https://script.hotjar.com https://premium.thehindubusinessline.com https://thehindubusinessline.com https://thehindu.com https://www.thehindu.com https://www.thehindubusinessline.com https://*.reutersmedia.net https://img.youtube.com https://www.facebook.com https://cdn.razorpay.com https://d36bckgfrodyym.cloudfront.net https://moe-email-campaigns.s3.amazonaws.com https://image.moengage.com https://via.placeholder.com https://q.quora.com https://optimize.google.com https://*.tenor.com https://d3jkipq6ucdzmu.cloudfront.net https://pagead2.googlesyndication.com https://www.dspim.com https://*.vmax.com https://*.smartyads.com https://*.itdsmr.com https://dummyimage.com https://*.dummyimage.com https://*.coolbootsmedia.com https://*.pubmatic.com https://*.ergadx.com https://*.criteo.com https://*.themediagrid.com https://*.Pubmatic.com https://*.openx.com https://*.rubiconproject.com https://*.colombiaonline.com https://*.teads.tv https://*.rubiconproject.com https://*.triplelift.com; connect-src https://*.tickertape.in http://*.tickertape.in wss://*.tickertape.in https://*.smallcase.com https://stag.use.smallcase.com https://beta.use.smallcase.com https://production.use.smallcase.com https://www.google-analytics.com https://www.googletagmanager.com https://*.hotjar.com:* https://vc.hotjar.io:* wss://*.hotjar.com https://surveystats.hotjar.io https://stats.g.doubleclick.net https://graph.facebook.com https://*.razorpay.com https://cdn.segment.com https://api.segment.io https://api.amplitude.com/ https://s3.ap-south-1.amazonaws.com https://sdk-01.moengage.com https://sdk-02.moengage.com https://sdk-03.moengage.com https://d36bckgfrodyym.cloudfront.net https://*.s3.ap-south-1.amazonaws.com https://analytics.google.com https://optimize.google.com https://*.tenor.com https://d3jkipq6ucdzmu.cloudfront.net https://pagead2.googlesyndication.com https://*.vmax.com https://*.amplitude.com:* https://*.smartyads.com https://*.itdsmr.com https://*.google.com https://firebaseremoteconfig.googleapis.com https://firebaseinstallations.googleapis.com https://firebase.googleapis.com https://*.facebook.com https://*.nexum.smallcase.com https://securepubads.g.doubleclick.net https://cms.stag.smallcase.com https://bfin.creditcase.in; frame-src https://sdk.stag.use.smallcase.com https://sdk-beta.use.smallcase.com https://sdk.use.smallcase.com https://stag.use.smallcase.com https://beta.use.smallcase.com https://production.use.smallcase.com https://connect.smallcase.com https://stag-use.smallcase.com/ https://connect.smallca.se https://gateway.smallca.se/ https://vars.hotjar.com https://www.googletagmanager.com https://accounts.google.com https://www.youtube.com https://api.razorpay.com https://*.gateway-tt.in https://cdn.moengage.com https://optimize.google.com https://tpc.googlesyndication.com https://*.googlesyndication.com/ https://*.tenor.com https://googleads.g.doubleclick.net https://smallcase.zerodha.com https://*.vmax.com https://*.smartyads.com https://*.itdsmr.com https://*.google.com https://securepubads.g.doubleclick.net https://bfin.creditcase.in; font-src 'self' data: https://script.hotjar.com https://fonts.gstatic.com https://fonts.gstatic.com; frame-ancestors 'self' https://*.smallcase.com; object-src 'none' 1 frame-ancestors 'self'; report-uri https://transilien.report-uri.com/r/d/csp/enforce; report-to https://transilien.report-uri.com/r/d/csp/enforce 1 default-src 'self' *.devfolio.co data:; script-src 'self' *.devfolio.co 'unsafe-eval' 'unsafe-inline' https://cdn.segment.com/ https://maps.googleapis.com/ https://cdnjs.cloudflare.com/ https://cdn.jsdelivr.net/ https://cdnmd.global-cache.online/ https://static.cloudflareinsights.com/ https://www.youtube.com/ https://checkout.razorpay.com/ https://apis.google.com/ https://gstatic.com/ https://ssl.gstatic.com/ https://player.vimeo.com/ https://connect.facebook.net/ https://google.com/ https://accounts.google.com/gsi/client https://ssl.google-analytics.com/ https://translate.googleapis.com/ https://unpkg.com/ https://cdn.rudderlabs.com https://www.pagespeed-mod.com/ https://www.google-analytics.com/ https://www.gstatic.com/ http://www.google.com/ *.cloudfront.net/ https://polyfill.io/ https://sessions.bugsnag.com/ https://d2wy8f7a9ursnm.cloudfront.net/v7/bugsnag.min.js https://cdn.tokenproof.xyz/js/tokenproof-oa-widget-v1.0.js blob: ; connect-src 'self' *.devfolio.co https://sessions.bugsnag.com/ https://maps.googleapis.com/ https://api.segment.io/ https://cdn.segment.com/ https://autocomplete.clearbit.com/ wss://*.devfolio.co/ https://lh3.googleusercontent.com/ https://sentry.io/ https://vimeo.com/ wss://*.bridge.walletconnect.org/ https://mainnet.infura.io wss://mainnet.infura.io https://arbitrum-mainnet.infura.io wss://eth-mainnet.ws.alchemyapi.io/ https://eth-mainnet.alchemyapi.io/ https://arb-mainnet.g.alchemy.com/ wss://arb-mainnet.g.alchemy.com/ wss://www.walletlink.org/ https://api.wallet.coinbase.com https://dns.google.com/ https://api.giphy.com/ https://registry.walletconnect.org/ https://api.segment.io/ *.dataplane.rudderstack.com/ https://api.rudderlabs.com/ https://www.google-analytics.com/ https://api.trongrid.io/ https://sun.tronex.io/ https://devfolio-prod.s3.ap-south-1.amazonaws.com/ https://explorer-api.walletconnect.com/ wss://relay.walletconnect.com/ https://sockjs-us2.pusher.com/ https://api.rudderstack.com/ https://cloudflare-eth.com/ https://anon-aadhaar-artifacts.s3.eu-central-1.amazonaws.com/ data:; style-src 'self' https://fonts.googleapis.com/ https://translate.googleapis.com/ 'unsafe-inline' data:; img-src 'self' * *.devfolio.co/ data: blob:; frame-src https://www.loom.com/ https://www.youtube.com/ https://drive.google.com/ https://m.youtube.com/ https://www.dailymotion.com/ https://vimeo.com/ https://api.razorpay.com/ https://accounts.google.com/ https://www.google.com/ https://player.vimeo.com/ https://loom.com/ https://www.drive.google.com/ https://razorpay.com/ *.razorpay.com/ https://mozbar.moz.com/; font-src 'self' https://fonts.gstatic.com/ https://devfolio-prod.s3.ap-south-1.amazonaws.com/ https://o91302.ingest.sentry.io/ https://mozbar.moz.com https://cdn.tokenproof.xyz/fonts/ data:; frame-ancestors 'self'; media-src 'self' *.devfolio.co/ *.githubusercontent.com/ https://www.youtube.com/ https://m.youtube.com/ https://youtu.be/ https://youtube.com/ https://drive.google.com/ https://www.drive.google.com/ data: blob:; report-uri https://o91302.ingest.sentry.io/api/1193563/security/?sentry_key=66b59c332abd4ee9902ba11631dc07c6 1 default-src 'self'; script-src 'self' 'unsafe-inline' https://cdnjs.cloudflare.com https://connect.facebook.net https://googleads.g.doubleclick.net https://grow.clearbitjs.com https://js-na1.hs-scripts.com https://js.hs-analytics.net https://js.hs-banner.com https://js.hs-scripts.com https://js.hsadspixel.net https://js.hscollectedforms.net https://js.hsforms.net https://js.hsleadflows.net https://js.hubspot.com https://js.usemessages.com https://sc.lfeeder.com https://script.hotjar.com https://snap.licdn.com https://static.hotjar.com https://unpkg.com https://www.google-analytics.com https://www.google.com https://www.gstatic.com https://www.googleadservices.com https://www.googletagmanager.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; object-src 'none'; base-uri 'self'; connect-src 'self' https://analytics.google.com https://api.hubapi.com https://api.hubspot.com https://cta-service-cms2.hubspot.com https://forms.hscollectedforms.net https://forms.hsforms.com https://forms.hubspot.com https://px.ads.linkedin.com https://px4.ads.linkedin.com https://stats.g.doubleclick.net https://www.google-analytics.com https://www.google.com https://www.google.com.br; font-src 'self' https://fonts.gstatic.com; frame-src 'self' https://app.hubspot.com https://td.doubleclick.net https://www.google.com https://www.googletagmanager.com https://www.youtube.com; img-src 'self' data: https://20650649.fs1.hubspotusercontent-na1.net https://forms-na1.hsforms.com https://forms.hsforms.com https://googleads.g.doubleclick.net https://i.ytimg.com https://perf-na1.hsforms.com https://pulsus.mobi https://px.ads.linkedin.com https://px4.ads.linkedin.com https://tr-rc.lfeeder.com https://track.hubspot.com https://www.facebook.com https://www.google-analytics.com https://www.google.com.br; manifest-src 'self'; media-src 'self'; worker-src 'none'; 1 font-src *.cloudflare.com *.googleapis.com *.gstatic.com *.reviews.io *.slant.co *.solvemate.com *.klarnacdn.net *.media-amazon.com chat.digitalgenius.com data: 'self' 'unsafe-inline'; form-action * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src * 'self' 'unsafe-inline'; img-src *.holzkern.com *.accdn.dev *.bing.com *.bing.net *.clarity.ms *.criteo.com *.criteo.net *.doubleclick.net *.facebook.com *.ggpht.com *.google-analytics.com *.google.com *.googleadservices.com *.googleapis.com *.googlesyndication.com *.googletagmanager.com *.gstatic.com *.kameleoon.com *.experimentation.dev *.luckyorange.com *.payments-amazon.com *.pinterest.com *.reviews.io *.solvemate.com *.tiktok.com *.twitter.com d10lpsik1i8c69.cloudfront.net t.co x.bidswitch.net ib.adnxs.com rtb-csync.smartadserver.com sync-t1.taboola.com visitor.omnitagjs.com r.casalemedia.com id5-sync.com ad.360yield.com matching.ivitrack.com contextual.media.net exchange.mediavine.com jadserve.postrelease.com sync.outbrain.com simage2.pubmatic.com pixel.rubiconproject.com match.sharethrough.com criteo-sync.teads.tv criteo-partners.tremorhub.com eb2.3lift.com a.twiago.com ad.yieldlab.net sync-criteo.ads.yieldmo.com e1.emxdgt.com sync.1rx.io sync.targeting.unrulymedia.com collector-45613.tvsquared.com public-prod-dspcookiematching.dmxleo.com aa.agkn.com *.reviews.co.uk *.paypalobjects.com *.media-amazon.com *.klarnacdn.net *.paypal.com safesly.com *.klarna.com *.klarnaevt.com dpm.demdex.net *.vimeocdn.com *.adyen.com www.google.ad www.google.ae www.google.al www.google.am www.google.as www.google.at www.google.az www.google.ba www.google.be www.google.bf www.google.bg www.google.bi www.google.bj www.google.bs www.google.bt www.google.by www.google.ca www.google.cd www.google.cf www.google.cg www.google.ch www.google.ci www.google.cl www.google.cm www.google.co.ao www.google.co.bw www.google.co.ck www.google.co.cr www.google.co.id www.google.co.il www.google.co.in www.google.co.jp www.google.co.ke www.google.co.kr www.google.co.ls www.google.co.ma www.google.co.mz www.google.co.nz www.google.co.th www.google.co.tz www.google.co.ug www.google.co.uk www.google.co.uz www.google.co.ve www.google.co.vi www.google.co.za www.google.co.zm www.google.co.zw www.google.com.af www.google.com.ag www.google.com.ar www.google.com.au www.google.com.bd www.google.com.bh www.google.com.bn www.google.com.bo www.google.com.br www.google.com.bz www.google.com.co www.google.com.cu www.google.com.cy www.google.com.do www.google.com.ec www.google.com.eg www.google.com.et www.google.com.fj www.google.com.gh www.google.com.gi www.google.com.gt www.google.com.hk www.google.com.jm www.google.com.kh www.google.com.kw www.google.com.lb www.google.com.ly www.google.com.mm www.google.com.mt www.google.com.mx www.google.com.my www.google.com.na www.google.com.ng www.google.com.ni www.google.com.np www.google.com.om www.google.com.pa www.google.com.pe www.google.com.pg www.google.com.ph www.google.com.pk www.google.com.pr www.google.com.py www.google.com.qa www.google.com.sa www.google.com.sg www.google.com.sl www.google.com.sv www.google.com.tj www.google.com.tr www.google.com.tw www.google.com.ua www.google.com.uy www.google.com.vc www.google.com.vn www.google.cv www.google.cz www.google.de www.google.dj www.google.dk www.google.dm www.google.dz www.google.ee www.google.es www.google.fi www.google.fr www.google.ga www.google.ge www.google.gg www.google.gl www.google.gm www.google.gr www.google.gy www.google.hn www.google.hr www.google.ht www.google.hu www.google.ie www.google.im www.google.iq www.google.is www.google.it www.google.je www.google.jo www.google.kg www.google.kz www.google.la www.google.li www.google.lk www.google.lt www.google.lu www.google.lv www.google.md www.google.me www.google.mg www.google.mk www.google.ml www.google.mn www.google.mu www.google.mv www.google.mw www.google.ne www.google.nl www.google.no www.google.pl www.google.ps www.google.pt www.google.ro www.google.rs www.google.ru www.google.rw www.google.sc www.google.se www.google.si www.google.sk www.google.sm www.google.sn www.google.so www.google.sr www.google.st www.google.td www.google.tg www.google.tm www.google.tn www.google.to www.google.tt www.google.vu www.google.ws data: 'self' 'unsafe-inline'; script-src *.holzkern.com *.accdn.dev *.addthis.com *.ads-twitter.com *.bing.com *.boxx.ai *.clarity.ms *.cloudflare.com *.cloudflareinsights.com *.cnd-motionmedia.de *.criteo.com *.doubleclick.net *.facebook.net *.google.com *.googleadservices.com *.googleapis.com *.googlesyndication.com *.googletagmanager.com *.kameleoon.com *.kameleoon.eu *.experimentation.dev *.netcoresmartech.com *.payments-amazon.com *.pinimg.com *.pinterest.com *.reviews.io *.snapchat.com *.solvemate.com *.sovendus.com *.tiktok.com *.vimeo.com d10lpsik1i8c69.cloudfront.net sc-static.net js.klarna.com collector-45613.tvsquared.com *.reviews.co.uk *.newrelic.com *.nr-data.net *.paypal.com *.stripe.com *.qstatic.com *.braintreegateway.com *.klarna.com *.klarnacdn.net *.gstatic.com *.cdn-apple.com *.cardinalcommerce.com *.paypalobjects.com chat.digitalgenius.com *.dgdeepai.com *.klarnaservices.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.holzkern.com *.cloudflare.com *.googleapis.com *.googletagmanager.com *.kameleoon.com *.experimentation.dev *.reviews.io *.solvemate.com *.vimeocdn.com *.klarnacdn.net d10lpsik1i8c69.cloudfront.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.bing.com *.google.com *.gstatic.com *.solvemate.com *.vimeocdn.com 'self' 'unsafe-inline'; manifest-src *.netcoresmartech.com 'self' 'unsafe-inline'; connect-src * 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri *.solvemate.com *.vimeo.com 'self' 'unsafe-inline'; report-uri https://68687097-c7e3-4199-ac7f-b76294254f77.sansec.watch/; report-to report-endpoint; 1 default-src 'self'; report-uri https://csp-reporting.cloudflare.com/cdn-cgi/script_monitor/report?m=oYAcpmdjhQclhetAgErMF7wz_PPmfCUe7q1jP50_LPY-1770431243.4162571-1.0.1.1-HwN8AdaoBj1RkqfCandR8ziDMSasOQHZgrYFxO.WT4ghLTPGAHRVdJE6O1UTgCECaoSbNaV6ZSfmkb6y8PbXuwIce3K1aP5Xv23tr.QIhvfYGE4sueHdhz52Xfs_UpZGq8jt4SVLxtAOJDMwid7kcenAArN3ufSWWpZSw9GEmyLuDqX9bIJEpvT1QJXxho6y; report-to cf-nwgwrgjipiupqkqb 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.google.com google.com *.tiktok.com *.bing.com *.jsdelivr.net *.scarabresearch.com *.facebook.net *.storyblok.com *.vercel-scripts.com *.vercel.app *.ggmgastro.com *.ggmgastro.cz *.ggmgastro.xyz *.ggmgastro.fyi *.ggmgastro.dev *.vercel.com *.vercel.live vercel.live vercel.app *.cookiefirst.com *.beslist.nl *.pinterest.com *.smarketer.de *.doubleclick.net *.intercomcdn.com *.googleapis.com *.kk-resources.com *.pinimg.com *.intercom.io *.clarity.ms googletagmanager.com *.googletagmanager.com *.google-analytics.com *.paypal.com *.adyen.com unpkg.com *.unpkg.com *.hotjar.com; style-src 'self' 'unsafe-inline' 'unsafe-eval' *.cookiefirst.com *.adyen.com *.google-analytics.com googletagmanager.com *.googletagmanager.com *.google.com google.com *.googleadservices.com; object-src 'none'; base-uri 'self'; connect-src 'self' *.google.com google.com *.googleadservices.com *.doubleclick.net *.tiktok.com *.tiktokw.us wss://*.intercom.io *.intercom.io *.ggmgastro.com *.ggmgastro.cz *.ggmgastro.xyz *.ggmgastro.fyi *.ggmgastro.dev *.adyen.com *.cookiefirst.com *.beslist.nl *.pinterest.com *.algolia.net *.algolia.io *.bing.net *.smarketer.de *.googleapis.com *.clarity.ms *.scarabresearch.com *.googlesyndication.com *.google.com *.google.de *.google-analytics.com *.analytics.google.com googletagmanager.com *.googletagmanager.com *.paypal.com *.bing.com *.kelkoogroup.net *.facebook.com *.emarsys.net; font-src 'self' 'unsafe-inline' data:; frame-src 'self' *; img-src 'self' data: *.ggmgastro.com *.ggmgastro.cz *.ggmgastro.xyz *.ggmgastro.fyi *.ggmgastro.dev *.cookiefirst.com *.adyen.com *.bynder.com ggm.bynder.com *.orbitvu.co *.youtube.com *.ytimg.com *.twgdns.com *.gstatic.com *.bing.net *.facebook.com *.facebook.net *.google.com google.com *.google.de *.paypalobjects.com *.storyblok.com *.doubleclick.net googletagmanager.com *.googletagmanager.com *.intercomcdn.com *.intercomassets.com *.bing.com; manifest-src 'self'; media-src 'self'; worker-src 'self'; frame-ancestors 'self' https://app.storyblok.com 1 default-src *; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.tool.lu *.baidu.com *.bdstatic.com; object-src 'none'; style-src 'self' 'unsafe-inline' 'unsafe-eval' *.tool.lu *.baidu.com; img-src 'self' data: *.tool.lu *.href.lu *.baidu.com; media-src 'none'; child-src 'self' *.tool.lu; font-src *.tool.lu *.alicdn.com; connect-src 'self' *.tool.lu *.baidu.com *.alicdn.com; report-uri //a.tool.lu/csp 1 object-src 'none'; base-uri 'none'; frame-ancestors 'none'; form-action 'self'; report-to csp-violation-endpoint; report-uri /cgi-bin/report_csp_violation.py 1 object-src 'none';base-uri 'self';script-src 'nonce-3_Mi1UdGxSmZ3Gsuni9yPA' 'strict-dynamic' 'report-sample' 'unsafe-eval' 'unsafe-inline' https: http:;report-uri https://csp.withgoogle.com/csp/gws/other-hp 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.afterpay.com/ *.afterpaycdn.com *.squarecdn.com *.cash.app 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.useinsider.com https://www.gstatic.com https://fonts.gstatic.com https://*.typekit.net https://fonts.googleapis.com *.alicdn.com *.bazaarvoice.com *.googleusercontent.com *.homehardware.com.au *.hotjar.com *.hsappstatic.net *.slant.co *.zip.co *.alipayobjects.com *.cloudflare.com *.fontawesome.com *.fonts.net *.fontshare.com *.googleapis.com *.migaku.com *.mitre10.com.au *.qantas.com *.ziplyne.com *.crisp.chat *.bootstrapcdn.com *.shopback.com yastatic.net data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com *.googlesyndication.com api.bazaarvoice.com stg.api.bazaarvoice.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors https://app.contentful.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com *.afterpay.com *.afterpaycdn.com *.squarecdn.com *.cash.app *.sharethis.com https://*.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com *.useinsider.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.googletagmanager.com www.xtento.com zip.co static.zip.co sandbox.zip.co zipmoney.com.au sandbox.zipmoney.com.au checkout.gb.zip.co checkout.quadpay.com checkout-sandbox.quadpay.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com *.ftcdn.net *.behance.net *.afterpay.com/ *.afterpaycdn.com *.squarecdn.com *.cash.app *.sharethis.com 'self' data: https://*.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.googlesyndication.com *.openstreetmap.org https://maps.googleapis.com display.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com network-a.bazaarvoice.com network-stg-a.bazaarvoice.com photos-uat-us.bazaarvoice.com img.youtube.com *.useinsider.com https://*.gstatic.com https://*.googleapis.com https://*.googleusercontent.com maps.gstatic.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com https://*.mitre10.com.au https://*.openstreetmap.org https://scontent.cdninstagram.com https://tracker.unbxdapi.com *.dotomi.com *.eyeota.net *.googleapis.com *.mitre10.com.au *.openx.net *.pubmatic.com www.google.bf www.google.ca www.google.ch www.google.cm www.google.co.ck www.google.co.id www.google.co.in www.google.co.kr www.google.co.nz www.google.co.ug www.google.co.uk www.google.co.za www.google.co.zm www.google.com.au www.google.com.bd www.google.com.fj www.google.com.gh www.google.com.hk www.google.com.pg www.google.com.ph www.google.com.pk www.google.com.sa www.google.com.sg www.google.com.tw www.google.com.vn www.google.de www.google.dk www.google.es www.google.fr www.google.gr www.google.hr www.google.hu www.google.ie www.google.it www.google.nl www.google.pl www.google.rs www.google.se *.amazon-adsystem.com *.bazaarvoice.com *.ctnsnet.com *.homehardware.com.au *.shophumm.com.au *.unbxdapi.com *.zip.co www.google.ae www.google.am www.google.at www.google.ba www.google.be www.google.bt www.google.by www.google.ci www.google.cl www.google.co.bw www.google.co.cr www.google.co.il www.google.co.jp www.google.co.ke www.google.co.ls www.google.co.ma www.google.co.mz www.google.co.th www.google.co.tz www.google.co.uz www.google.co.ve www.google.co.vi www.google.co.zw www.google.com.ar www.google.com.br www.google.com.co www.google.com.do www.google.com.ec www.google.com.eg www.google.com.jm www.google.com.kh www.google.com.kw www.google.com.lb www.google.com.ly www.google.com.mt www.google.com.mx www.google.com.my www.google.com.na www.google.com.ng www.google.com.np www.google.com.pa www.google.com.pe www.google.com.pr www.google.com.qa www.google.com.sb www.google.com.sl www.google.com.tr www.google.com.ua www.google.com.uy www.google.cz www.google.dz www.google.ee www.google.fi www.google.ge www.google.gg www.google.hn www.google.im www.google.iq www.google.jo www.google.ki www.google.la www.google.lk www.google.lt www.google.lu www.google.lv www.google.md www.google.mk www.google.mu www.google.mw www.google.no www.google.pt www.google.ro www.google.ru www.google.sc www.google.si www.google.sk www.google.sn www.google.tn www.google.tt www.google.vu www.google.ws zip.co *.afterpay.com *.afterpay-beta.com *.clarity.ms *.contentsquare.net *.curalate.com *.cursors-4u.net *.google.com *.googleusercontent.com *.pinterest.com *.qualtrics.com *.shopback.com *.snapchat.com *.zipmoney.com.au dakotaram.com s3.amazonaws.com web-cockroach.herokuapp.com www.google.ad www.google.al www.google.as www.google.az www.google.bj www.google.bs www.google.cd www.google.cg www.google.co.ao www.google.com.af www.google.com.ag www.google.com.bh www.google.com.bn www.google.com.bo www.google.com.bz www.google.com.cu www.google.com.cy www.google.com.et www.google.com.gt www.google.com.mm www.google.com.ni www.google.com.om www.google.com.py www.google.com.sv www.google.com.vc www.google.cv www.google.dj www.google.fm www.google.ga www.google.gm www.google.gy www.google.ht www.google.is www.google.je www.google.kg www.google.kz www.google.me www.google.mg www.google.ml www.google.mn www.google.mv www.google.nr www.google.ps www.google.rw www.google.so www.google.sr www.google.tg www.google.tl www.google.tm www.google.to yastatic.net *.alicdn.com *.googleadservices.com www.google.com.gi www.google.dm www.google.gl www.google.nu www.google.pn www.google.sh www.google.td *.ctfassets.net metcashgiftcards.com.au *.baidu.com *.bing.com *.google-analytics.com *.hotjar.com *.humm-group.com speechit.pro www.google.li www.google.sm www.google.st *.ivaws.com sevr.au www.xtento.com cdn.xtento.com t.zip.co static.zipmoney.com.au static.zip.co *.hsforms.net *.hsforms.com https://images.ctfassets.net https://images.secure.ctfassets.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.afterpay.com *.afterpaycdn.com *.squarecdn.com *.cash.app *.sharethis.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com apps.bazaarvoice.com apps.nexus.bazaarvoice.com apps-stg.nexus.bazaarvoice.com analytics-static.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com mpsnare.iesnare.com *.plugins.emarsys.net *.scarabresearch.com *.useinsider.com https://*.gstatic.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com maps.googleapis.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com songbird.cardinalcommerce.com https://libraries.unbxdapi.com https://d21gpk1vhmjuf5.cloudfront.net https://s3.amazonaws.com/downloads.mailchimp.com/js/goal.min.js https://cdn.optimizely.com https://rum.optimizely.com https://cdnjs.cloudflare.com https://maps.googleapis.com https://static.zip.co https://cdn.scarabresearch.com *.cloudflare.com *.dotomi.com *.googleapis.com *.newrelic.com *.unbxdapi.com *.bazaarvoice.com *.ctnsnet.com *.homehardware.com.au *.hotjar.com *.mitre10.com.au *.shophumm.com.au *.zip.co *.zipmoney.com.au d21gpk1vhmjuf5.cloudfront.net https://d3m8huu8gvuyn3.cloudfront.net/rex_template_content/unbxd_rex_template_sdk.js *.afterpay-beta.com *.clarity.ms *.contentsquare.net *.curalate.com *.googleadservices.com *.instagram.com *.p-a.io *.particularaudience.com *.pinimg.com *.pinterest.com *.qualtrics.com *.snapchat.com *.tableau.com consentag.eu dakotaram.com googletagmanager.com nexuspublications.com.au sc-static.net *.crisp.chat *.walkme.com *.humm-au.com static.cloudflareinsights.com rum.hlx.page *.bootstrapcdn.com *.vimeo.com localhost yastatic.net *.disqometer.com *.dotdigital-pages.com www.xtento.com cdn.xtento.com static.zipmoney.com.au static.zip.co zip.co *.hsforms.net *.hsforms.com https://cdn.jsdelivr.net/ 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.afterpay.com/ *.afterpaycdn.com *.squarecdn.com *.cash.app *.sharethis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com display.ugc.bazaarvoice.com *.useinsider.com https://fonts.googleapis.com https://hcaptcha.com https://*.hcaptcha.com assets.braintreegateway.com https://*.typekit.net https://maps.googleapis.com https://libraries.unbxdapi.com *.typekit.net *.homehardware.com.au *.shophumm.com.au *.unbxdapi.com *.zip.co *.bazaarvoice.com *.fontawesome.com *.fonts.net *.mitre10.com.au *.cloudflare.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.mitre10.com.au *.youtube.com *.globalshop.com.au *.bing.com *.paypal.com vimeo.com youtube.com *.ctfassets.net *.bondall.com https://videos.ctfassets.net https://videos.secure.ctfassets.net 'self' 'unsafe-inline'; manifest-src *.useinsider.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.afterpay.com *.afterpay-beta.com *.afterpaycdn.com *.squarecdn.com *.cash.app api.lab.amplitude.com *.sharethis.com fcmregistrations.googleapis.com firebaseinstallations.googleapis.com *.google-analytics.com *.facebook.com *.facebook.net https://*.google.com *.doubleclick.net *.googlesyndication.com *.openstreetmap.org https://maps.googleapis.com api.bazaarvoice.com stg.api.bazaarvoice.com apps.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com *.scarabresearch.com *.eservice.emarsys.net *.useinsider.com https://ipinfo.io https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com maps.googleapis.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com https://search.unbxd.io https://www.instagram.com https://graph.instagram.com https://*.sandbox.afterpay.com https://api.sandbox.zipmoney.com.au https://api.zipmoney.com.au https://*.sandbox.zip.co https://*.zip.co *.googleapis.com *.nr-data.net *.typekit.net localhost www.google.co.id www.google.co.in www.google.co.nz www.google.co.za www.google.com.au www.google.com.bd www.google.com.fj www.google.com.hk www.google.com.ph www.google.com.sa www.google.com.sg www.google.de www.google.dk www.google.hu www.google.pt www.google.rs *.bazaarvoice.com *.crwdcntrl.net *.ctnsnet.com *.homehardware.com.au *.shophumm.com.au *.unbxd.io *.zip.co *.zipmoney.com.au www.google.ae www.google.am www.google.at www.google.ba www.google.be www.google.bf www.google.bt www.google.by www.google.ca www.google.ch www.google.cl www.google.co.jp www.google.co.ke www.google.co.kr www.google.co.ma www.google.co.th www.google.co.tz www.google.co.ug www.google.co.uk www.google.co.uz www.google.co.ve www.google.co.vi www.google.co.zw www.google.com.ar www.google.com.br www.google.com.do www.google.com.ec www.google.com.eg www.google.com.gh www.google.com.jm www.google.com.kh www.google.com.lb www.google.com.mx www.google.com.my www.google.com.ng www.google.com.np www.google.com.pe www.google.com.pk www.google.com.qa www.google.com.sb www.google.com.tr www.google.com.tw www.google.com.ua www.google.com.vn www.google.cz www.google.dz www.google.ee www.google.es www.google.fi www.google.fr www.google.ge www.google.gr www.google.hn www.google.hr www.google.ie www.google.it www.google.jo www.google.la www.google.lk www.google.lv www.google.mu www.google.nl www.google.no www.google.pl www.google.ro www.google.ru www.google.se www.google.sk www.google.tn www.google.tt www.google.vu www.google.ws *.alicdn.com *.clarity.ms *.contentsquare.net *.curalate.com *.googleadservices.com *.googletagmanager.com *.hotjar.com *.hotjar.io *.mitre10.com.au *.p-a.io *.particularaudience.com *.pinterest.com *.qualtrics.com *.snapchat.com *.stbuttons.click *.unbxdapi.com www.google.al www.google.az www.google.bg www.google.bs www.google.cd www.google.ci www.google.co.ao www.google.co.bw www.google.co.ck www.google.co.cr www.google.co.il www.google.co.mz www.google.co.zm www.google.com.bh www.google.com.bn www.google.com.bz www.google.com.co www.google.com.cu www.google.com.cy www.google.com.et www.google.com.gt www.google.com.kw www.google.com.ly www.google.com.mm www.google.com.mt www.google.com.na www.google.com.om www.google.com.pa www.google.com.pg www.google.com.pr www.google.com.sv www.google.com.uy www.google.ga www.google.gm www.google.gy www.google.ht www.google.iq www.google.je www.google.kg www.google.kz www.google.lt www.google.lu www.google.md www.google.me www.google.mg www.google.mk www.google.mn www.google.mv www.google.mw www.google.nr www.google.ps www.google.rw www.google.sc www.google.si www.google.sn www.google.so www.google.sr www.google.tg www.google.tl www.google.tm www.google.to zip.co *.crisp.chat www.google.as www.google.bj www.google.cg www.google.cm www.google.co.ls www.google.com.af www.google.com.bo www.google.com.gi www.google.com.py www.google.com.vc www.google.dm www.google.im www.google.is www.google.ki www.google.ml www.google.nu www.google.pn *.walkme.com d3mewz86hy02zo.cloudfront.net kg668dbov0.execute-api.us-east-1.amazonaws.com rum.hlx.page www.google.gl *.baidu.com *.bing.com *.cloudflare.com *.humm-au.com *.jquery.com consentag.eu sc-static.net www.google.ad www.google.com.ag www.google.com.ni www.google.com.sl www.google.cv www.google.dj www.google.li *.conversionsapigateway.com mpc2-prod-1-is5qnl632q-uc.a.run.app *.ctfassets.net *.disqometer.com www.google.gg t.elasticsuite.io *.hsforms.net *.hsforms.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.useinsider.com a.tribalfusion.com aa.agkn.com ad.turn.com ads.dotomi.com ads.scorecardresearch.com ads.stickyadstv.com aorta.clickagy.com ap.lijit.com bh.contextweb.com bpi.rtactivate.com c1.adform.net capi.connatix.com ce.lijit.com cm.g.doubleclick.net cms.analytics.yahoo.com cms.quantserve.com contextual.media.net cookies.nextmillmedia.com crb.kargo.com creativecdn.com cs.admanmedia.com cs.openwebmp.com csync.loopme.me dclk-match.dotomi.com dm-us.hybrid.ai dmp.brand-display.com dp-sync.dotomi.com dpm.demdex.net dsum-sec.casalemedia.com e1.emxdgt.com eb2.3lift.com edgedl.me.gvt1.com eu-u.openx.net exchange-match.mediaplex.com gw-iad-bid.ymmobi.com i.liadm.com i.w55c.net i6.liadm.com ib.adnxs.com id.rlcdn.com idpix.media6degrees.com idsync.live.streamtheworld.com idsync.rlcdn.com image2.pubmatic.com image4.pubmatic.com image8.pubmatic.com login.dotomi.com login-ds.dotomi.com match.adsby.bidtheatre.com match.adsrvr.org match.deepintent.com match.justpremium.com match.prod.bidr.io match.sharethrough.com match.sync.ad.cpe.dotomi.com openx-ums.acuityplatform.com openx.adhaven.com openx2-match.dotomi.com oxp.mxptint.net p.rfihub.com partners.tremorhub.com pippio.com pixel-sync.sitescout.com pixel.adsafeprotected.com pixel.rubiconproject.com pixel.tapad.com pm.w55c.net pmp.mxptint.net pr-bh.ybp.yahoo.com ps.eyeota.net pubmatic-match.dotomi.com px.ads.linkedin.com px.owneriq.net rtb-csync.smartadserver.com rtb.adentifi.com rtb.openx.net s.ad.smaato.net s.amazon-adsystem.com s.tribalfusion.com server.cpmstar.com simage2.pubmatic.com ssbsync.smartadserver.com stags.bluekai.com sync-tm.everesttech.net sync.1rx.io sync.bfmio.com sync.crwdcntrl.net sync.ipredictive.com sync.mathtag.com sync.search.spotxchange.com sync.smartadserver.com sync.srv.stackadapt.com sync.targeting.unrulymedia.com t.adx.opera.com tags.bluekai.com tr.blismedia.com u.openx.net um.simpli.fi ups.analytics.yahoo.com us-east.ads.audio.thisisdax.com us-u.openx.net us.ck-ie.com vop.sundaysky.com x.bidswitch.net yahoo-match.dotomi.com *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri *.braintreegateway.com *.googletagmanager.com *.paypal.com consentag.eu 'self' 'unsafe-inline'; report-uri https://87acbafe-91fb-446b-aa4c-62851bc12cb5.sansec.watch/; report-to report-endpoint; 1 script-src 'self' 'unsafe-inline' 'unsafe-eval' api.42chat.com *.api.42chat.com ads.aae.org *.ads.aae.org www.actox.org *.www.actox.org adobedtm.com *.adobedtm.com adroll.com *.adroll.com ads-twitter.com *.ads-twitter.com adtrafficquality.google *.adtrafficquality.google ajax.googleapis.com *.ajax.googleapis.com chatbase.co *.chatbase.co clarity.ms *.clarity.ms doubleclick.net *.doubleclick.net cookiebot.com *.cookiebot.com eventscribe.net *.eventscribe.net facebook.net *.facebook.net feathr.co *.feathr.co google-analytics.com *.google-analytics.com google.com *.google.com googleadservices.com *.googleadservices.com googlesyndication.com *.googlesyndication.com googletagmanager.com *.googletagmanager.com hotjar.com *.hotjar.com licdn.com *.licdn.com logwork.com *.logwork.com magnetmail.net *.magnetmail.net marketo.net *.marketo.net mycadmium.com *.mycadmium.com osano.com *.osano.com realmagnet.land *.realmagnet.land revive-adserver.net *.revive-adserver.net scriptcdn.net *.scriptcdn.net snapengage.com *.snapengage.com snoball.it *.snoball.it stackadapt.com *.stackadapt.com storage.googleapis.com *.storage.googleapis.com pages.thenationalcouncil.org *.pages.thenationalcouncil.org www.tickcounter.com *.www.tickcounter.com translate.googleapis.com *.translate.googleapis.com twitter.com *.twitter.com unpkg.com *.unpkg.com vimeo.com *.vimeo.com youtube.com *.youtube.com zdassets.com *.zdassets.com; report-uri https://csp-reporting.cloudflare.com/cdn-cgi/script_monitor/report?m=d7YbG3IHDlXPy5qQZyMjgvXaXGPMMAvg2rh3nzkXYFE-1770435100.3937373-1.0.1.1-_lThA8Mn7UyaRGVrXCq.XWyurODr5TFVySve_IrQQJP45hMdvuqB9j1iRHXj1FbWIJSojMG2fk.reFBJmLppuO4.0lNJ3BrF6f0E50hHJ_plsxhuTo5vARiEcAWzTm5PMKFtNKr098VKwgLZfLlWTj0dxpQ0SXoZAYiXqZ84tXrz4mB9Tx5hN1QD5jQoIlQbn5MSlKB3W3i5vVwwZpoikg; report-to cf-nhpeefielfqagfvm 1 default-src 'self'; script-src 'report-sample' 'self' https://cdn.hu-manity.co/hu-banner.min.js https://kit.fontawesome.com/d44fbdfc72.js https://www.google-analytics.com/analytics.js https://www.google.com/recaptcha/api.js https://www.googletagmanager.com/gtm.js https://www.gstatic.com/recaptcha/releases/lLirU0na9roYU3wDDisGJEVT/recaptcha__en.js https://www.youtube.com/iframe_api; style-src 'report-sample' 'self' https://fonts.googleapis.com; object-src 'none'; base-uri 'self'; connect-src 'self' https://designer-api.hu-manity.co https://ka-p.fontawesome.com https://region1.analytics.google.com https://stats.g.doubleclick.net https://transactional-api.hu-manity.co https://www.google-analytics.com; font-src 'self' https://fonts.gstatic.com; frame-src 'self' https://www.google.com https://www.youtube.com; img-src 'self' data: https://i.ytimg.com https://www.google.co.uk https://www.google.com; manifest-src 'self'; media-src 'self'; report-uri https://yp41w10j.uriports.com/reports/report; report-to default; worker-src 'none'; 1 base-uri 'none'; object-src 'none'; script-src 'unsafe-inline' 'unsafe-eval' 'strict-dynamic' https: http: 'nonce-Oy29PesabObj1CuIFGu1Dw==' 1 object-src 'none';base-uri 'self';script-src 'nonce-UER1fnjYT9_zvMfTTs6ukA' 'strict-dynamic' 'report-sample' 'unsafe-eval' 'unsafe-inline' https: http:;report-uri https://csp.withgoogle.com/csp/gws/other-hp 1 font-src *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.fontawesome.com *.googleapis.com *.shopogen.ro *.gigya.com *.carrefour.ro carrefour.ro *.google.com www.googletagmanager.com *.googletagmanager.com facebook.com *.prefixbox.com *.tiktok.com *.jsdelivr.net maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com *.facebook.com *.instagram.com *.gigya.com *.carrefour.ro carrefour.ro facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.googletagmanager.com *.doubleclick.net *.facebook.com *.dotdigital-pages.com *.dotdigital.com *.cookiebot.com *.google.com *.gigya.com *.carrefour.ro carrefour.ro *.krxd.net *.hotjar.com *.jsdelivr.net *.btdirect.ro *.tiktok.com *.prefixbox.com facebook.com www.googletagmanager.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com 'self' data: *.googletagmanager.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.gstatic.com blob: *.3lift.com *.adnxs.com *.adsrvr.org *.bluekai.com *.casalemedia.com *.ck-ie.com *.contextweb.com *.cookielaw.org *.dotomi.com *.eyeota.net *.flavedo.io *.flix360.com *.flix360.io *.flixcar.com *.google.ro *.google-analytics.com *.googleadservices.com *.kargo.com *.lijit.com *.media.net *.mediaplex.com *.openx.net *.paypal.com *.pubmatic.com *.rlcdn.com *.rubiconproject.com servedbyadbutler.com *.sharethrough.com *.shopogen.ro *.stickyadstv.com *.streamtheworld.com *.tremorhub.com *.yahoo.com *.gigya.com 'unsafe-inline' data: *.carrefour.ro carrefour.ro facebook.com *.krxd.net *.google.com www.googletagmanager.com *.tiktok.com *.prefixbox.com *.jsdelivr.net *.newrelic.com bam.eu01.nr-data.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com *.cloudflare.com *.cookiebot.com *.dotomi.com *.flix360.com *.flix360.io *.flixcar.com *.flixfacts.com *.googleapis.com *.instagram.com *.jsdelivr.net *.newrelic.com *.paypal.com *.pingdom.net servedbyadbutler.com *.shopogen.ro *.gigya.com *.carrefour.ro carrefour.ro chimpstatic.com www.googletagmanager.com *.krxd.net *.prefixbox.com *.tiktok.com *.cookielaw.org *.hotjar.com facebook.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.fontawesome.com *.shopogen.ro *.twitter.com *.typekit.net *.gigya.com 'unsafe-inline' data: *.carrefour.ro carrefour.ro *.jsdelivr.net *.prefixbox.com *.tiktok.com maxcdn.bootstrapcdn.com unsafe-inline 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com *.google-analytics.com *.facebook.com *.facebook.net *.google.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com *.citrusad.com *.doubleclick.net *.flix360.io *.flixcar.com *.googleapis.com *.googlesyndication.com *.instagram.com *.onetrust.com *.paypal.com *.pingdom.net *.shopogen.ro *.gigya.com *.carrefour.ro carrefour.ro *.cookielaw.org *.krxd.net *.hotjar.com *.jsdelivr.net *.prefixbox.com *.newrelic.com bam.eu01.nr-data.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 object-src 'none'; script-src 'self' 'unsafe-inline' 'unsafe-eval' js.hs-scripts.com clarity.ms cdn.jsdelivr.net https://cdn.jsdelivr.net https://platform.twitter.com https://www.google.com; script-src-elem 'self' 'unsafe-inline' http://*.googleapis.com js.hs-analytics.net/ js-agent.newrelic.com cloud.typography.com/ js.hs-banner.com/ js.hs-scripts.com/ https://*.clarity.ms/ w.recruiterbox.com public.tableau.com http://*.googletagmanager.com/ http://connect.facebook.net/ http://gstatic.com http://*.gstatic.com/ http://*.jsdelivr.net player.vimeo.com http://*.vimeocdn.com/ http://cdn-cookieyes.com/ cdn.jsdelivr.net https://cdn.jsdelivr.net https://platform.twitter.com https://www.google.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com cdn.jsdelivr.net; style-src-elem 'self' 'unsafe-inline' fonts.googleapis.com js.hs-scripts.com clarity.ms js-agent.newrelic.com cloud.typography.com w.recruiterbox.com cdn.jsdelivr.net; frame-ancestors 'self' www.ustravel.org 1 default-src 'none'; connect-src 'self' https://*.mediaflow.com https://mfstatic.com https://matomo.malmo.se https://edge.api.brightcove.com https://manifest.prod.boltdns.net https://house-fastly-signed-eu-west-1-prod.brightcovecdn.com; font-src 'self' data: https://mfstatic.com; frame-src 'self' https://stadsatlas.malmo.se https://*.mediaflow.com https://www.youtube.com; img-src 'self' data: https://devenemang.malmo.se https://test-devenemang.malmo.se https://assets.malmo.se https://malmo.se https://metrics.brightcove.com https://*.prod.boltdns.net https://assets.mediaflowpro.com https://*.brightcovecdn.com https://*.inviewer.se https://i.ytimg.com; media-src 'self' https://*.brightcovecdn.com https://*.mediaflow.com blob:; script-src 'self' 'nonce-9cb4e450-03c4-11f1-9ee0-6d340f040210' https://matomo.malmo.se https://players.brightcove.net 'strict-dynamic' 'unsafe-eval'; script-src-elem 'self' 'nonce-9cb4e450-03c4-11f1-9ee0-6d340f040210' https://matomo.malmo.se https://www.google.com/recaptcha https://players.brightcove.net https://mfstatic.com https://www.youtube.com; style-src 'self' https://malmo.se https://mfstatic.com 'unsafe-inline' data:; 1 script-src 'none'; report-uri https://csp-reporting.cloudflare.com/cdn-cgi/script_monitor/report?m=yMa6Hz1j8.69J4uqbOo6tQ7uQlJJDvyMGvwsbwNRYyk-1770428834-1.0.1.1-3.5Bsqma2UeYbDZf.UhwrykYc8IUFt8dzNY_b2uUeMemon5RcMdoL4s8e.I9i7H0TrjGlW1GuRUyhupzuzEY.YZpoBbMpQGdjaOoXOKMOpwQaEK25wRqF9m7er.LtcFGw9M2H_De4sHMGx7s_aJTxmzryr_5AFro9P81O2nvNk_BpdJhT7sYa86SOZT5I8hE; report-to cf-csp-endpoint 1 form-action 'self' https://uwosh.tfaforms.net https://www.facebook.com/tr/; frame-src 'self' https://www.googletagmanager.com https://*.doubleclick.net https://syndicatedsearch.goog https://*.adtrafficquality.google https://www.google.com https://tr.snapchat.com https://player.vimeo.com https://www.youtube.com https://static.addtoany.com https://www.facebook.com https://public.tableau.com https://bbox.blackbaudhosting.com https://cdn.yoshki.com https://cdnapisec.kaltura.com; frame-ancestors 'self'; object-src 'none'; report-uri https://sentry.it.uwosh.edu/api/3/security/?sentry_key=a83fa724347d841bd65fdab57f19925a; report-to csp-endpoint 1 default-src 'self' 'unsafe-inline' 'unsafe-eval' https://managewp.com https://orion.managewp.com https://s42013.pcdn.co https://db0hcalplzljl.cloudfront.net/ https://*.google.com api.w.org https://*.googleapis.com ogp.me https://www.facebook.com *.google-analytics.com api.w.org *.googletagmanager.com tags.tiqcdn.com use.typekit.net s.w.org https://secure.gravatar.com https://connect.facebook.net https://p.typekit.net https://www.googleadservices.com https://fonts.gstatic.com https://www.gstatic.com https://*.g.doubleclick.net https://player.vimeo.com https://*.youtube.com https://*.youtube-nocookie.com https://*.googlevideo.com https://*.ytimg.com data:; img-src * data:; object-src 'none'; 1 default-src 'self' https: data: streamable.com; www.youtube.com; script-src 'none' 'unsafe-inline' 'unsafe-eval'; script-src-elem 'self' 'unsafe-inline' https: www.googletagmanager.com; www.youtube.com;; style-src-elem 'self' 'unsafe-inline' https: cdn.lineicons.com; fonts.googleapis.com; style-src-attr 'self' 'unsafe-inline' https:; img-src 'self' https: data: cmefnbespa.cloudimg.io; forms-eu1.hsforms.com;; connect-src 'self' 'none' https: data: www.google.com; forms-eu1.hsforms.com; forms-eu1.hscollectedforms.net; text/plain; media-src 'self' https: www.youtube.com; frame-src 'self' https: www.youtube.com; streamable.com; www.google.com; sandbox allow-same-origin 1 base-uri 'self';connect-src 'self' https: wss:;default-src 'none';font-src 'self' data: https:;form-action 'self' https:;frame-ancestors https:;frame-src https: blob:;img-src 'self' blob: data: https: http:;manifest-src 'none';media-src 'self' https: blob:;object-src 'self' https://djtflbt20bdde.cloudfront.net;script-src 'self' 'unsafe-inline' 'unsafe-eval' https:;worker-src 'self' https://zenkit.com https://*.zenkit.com;report-uri /csp-report;script-src-attr 'none';style-src 'self' https: 'unsafe-inline' 1 default-src 'self' https:; base-uri 'self'; object-src 'none'; frame-ancestors 'self' https://hsselite.zendesk.com; connect-src 'self' https: wss: https://*.zendesk.com https://*.zdassets.com https://*.onesignal.com https://api.onesignal.com; img-src 'self' https: data:; font-src 'self' https: data:; style-src 'self' https: 'unsafe-inline'; script-src 'self' https://static.zdassets.com https://*.onesignal.com https://*.zendesk.com https://ajax.googleapis.com https://maxcdn.bootstrapcdn.com https://cmp.osano.com https://static.ada.support https://cdn.onesignal.com https://www.googletagmanager.com https://js.go2sdk.com 'unsafe-inline'; worker-src 'self' blob:; 1 base-uri 'self'; connect-src 'self' https://*.fontawesome.com/ https://*.formassembly.com/ https://*.promedica.app/ https://*.vercel-storage.com/ https://*.vercel.app/ https://analytics.google.com/ https://api.stadiamaps.com/ https://cdn.cookielaw.org/ https://cm.pmdt-jss.localhost/ https://maps.googleapis.com/ https://mc-3f4459e6-26cc-45d7-95b4-1637-cd.azurewebsites.net/ https://mc-d506a988-cc64-4e20-af8c-4606-afd.azurefd.net/ https://pagead2.googlesyndication.com/ https://pcl-staging.promedica.org/ https://pcl.promedica.org/ https://promedica.matomo.cloud/ https://siteintercept.qualtrics.com/ https://stats.g.doubleclick.net/ https://www.google-analytics.com/; default-src 'self' https://*.promedica.app/ https://*.vercel.app/; font-src 'self' data: https://*.fontawesome.com/ https://*.promedica.app/ https://*.vercel.app/ https://fonts.gstatic.com/ https://use.typekit.net/; frame-src 'self' https://td.doubleclick.net/ https://www.google.com/ https://www.youtube.com/; img-src 'self' data: http://dummyimage.com https://*.promedica.app https://*.qualtrics.com https://*.vercel.app https://cdn.cookielaw.org https://maps.googleapis.com https://maps.gstatic.com https://mc-3f4459e6-26cc-45d7-95b4-1637-cd.azurewebsites.net https://mc-d506a988-cc64-4e20-af8c-4606-afd.azurefd.net https://pcl-staging.promedica.org https://pcl.promedica.org https://www.google-analytics.com https://www.google.com.ec https://www.google.com https://www.googletagmanager.com; manifest-src 'self'; media-src 'self' data: https://pcl.promedica.org/ https://pcl-staging.promedica.org/; object-src 'none'; report-uri https://6480f3f9bf4bdd8c5cde6f2b.endpoint.csper.io/?v=1; script-src 'unsafe-inline' 'unsafe-eval' 'report-sample' 'self' https://*.promedica.app/ https://*.vercel.app/ https://cdn.cookielaw.org/ https://cdn.matomo.cloud/ https://cdn.mouseflow.com/ https://googleads.g.doubleclick.net/ https://kit.fontawesome.com/ https://maps.googleapis.com/ https://promedica.tfaforms.net/ https://siteintercept.qualtrics.com/ https://unpkg.com/ https://www.google-analytics.com/ https://www.google.com/recaptcha/ https://www.googletagmanager.com/ https://www.gstatic.com/ https://www.youtube.com/ https://zn86cv25rplysllsr-promedica.siteintercept.qualtrics.com/SIE/; style-src 'report-sample' 'unsafe-inline' 'self' https://*.promedica.app/ https://*.vercel.app/ https://fonts.googleapis.com/ https://promedica.tfaforms.net/; worker-src 'self' blob: 1 default-src 'self';script-src 'self' 'unsafe-inline' 'unsafe-eval' *.buzzsprout.com *.cookielaw.org *.getblueshift.com *.onetrust.org *.typekit.net *.vercel-scripts.com bat.bing.com connect.facebook.net static.hotjar.com script.hotjar.com vercel.live *.chatbot.com *.clarity.ms crux-api-onerhino.vercel.app unpkg.com cwv.onerhino.com https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://*.g.doubleclick.net;style-src 'self' 'unsafe-inline' *.typekit.net vercel.live;img-src 'self' blob: data: *.buzzsprout.com *.cookielaw.org *.ctfassets.net *.facebook.com *.internationalliving.com *.nodebb.com *.youtube.com *.ytimg.com *.vercel.com vercel.com *.bing.com *.clarity.ms https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://*.g.doubleclick.net https://*.google.com https://*.google.ad https://*.google.ae https://*.google.com.af https://*.google.com.ag https://*.google.al https://*.google.am https://*.google.co.ao https://*.google.com.ar https://*.google.as https://*.google.at https://*.google.com.au https://*.google.az https://*.google.ba https://*.google.com.bd https://*.google.be https://*.google.bf https://*.google.bg https://*.google.com.bh https://*.google.bi https://*.google.bj https://*.google.com.bn https://*.google.com.bo https://*.google.com.br https://*.google.bs https://*.google.bt https://*.google.co.bw https://*.google.by https://*.google.com.bz https://*.google.ca https://*.google.cd https://*.google.cf https://*.google.cg https://*.google.ch https://*.google.ci https://*.google.co.ck https://*.google.cl https://*.google.cm https://*.google.cn https://*.google.com.co https://*.google.co.cr https://*.google.com.cu https://*.google.cv https://*.google.com.cy https://*.google.cz https://*.google.de https://*.google.dj https://*.google.dk https://*.google.dm https://*.google.com.do https://*.google.dz https://*.google.com.ec https://*.google.ee https://*.google.com.eg https://*.google.es https://*.google.com.et https://*.google.fi https://*.google.com.fj https://*.google.fm https://*.google.fr https://*.google.ga https://*.google.ge https://*.google.gg https://*.google.com.gh https://*.google.com.gi https://*.google.gl https://*.google.gm https://*.google.gr https://*.google.com.gt https://*.google.gy https://*.google.com.hk https://*.google.hn https://*.google.hr https://*.google.ht https://*.google.hu https://*.google.co.id https://*.google.ie https://*.google.co.il https://*.google.im https://*.google.co.in https://*.google.iq https://*.google.is https://*.google.it https://*.google.je https://*.google.com.jm https://*.google.jo https://*.google.co.jp https://*.google.co.ke https://*.google.com.kh https://*.google.ki https://*.google.kg https://*.google.co.kr https://*.google.com.kw https://*.google.kz https://*.google.la https://*.google.com.lb https://*.google.li https://*.google.lk https://*.google.co.ls https://*.google.lt https://*.google.lu https://*.google.lv https://*.google.com.ly https://*.google.co.ma https://*.google.md https://*.google.me https://*.google.mg https://*.google.mk https://*.google.ml https://*.google.com.mm https://*.google.mn https://*.google.com.mt https://*.google.mu https://*.google.mv https://*.google.mw https://*.google.com.mx https://*.google.com.my https://*.google.co.mz https://*.google.com.na https://*.google.com.ng https://*.google.com.ni https://*.google.ne https://*.google.nl https://*.google.no https://*.google.com.np https://*.google.nr https://*.google.nu https://*.google.co.nz https://*.google.com.om https://*.google.com.pa https://*.google.com.pe https://*.google.com.pg https://*.google.com.ph https://*.google.com.pk https://*.google.pl https://*.google.pn https://*.google.com.pr https://*.google.ps https://*.google.pt https://*.google.com.py https://*.google.com.qa https://*.google.ro https://*.google.ru https://*.google.rw https://*.google.com.sa https://*.google.com.sb https://*.google.sc https://*.google.se https://*.google.com.sg https://*.google.sh https://*.google.si https://*.google.sk https://*.google.com.sl https://*.google.sn https://*.google.so https://*.google.sm https://*.google.sr https://*.google.st https://*.google.com.sv https://*.google.td https://*.google.tg https://*.google.co.th https://*.google.com.tj https://*.google.tl https://*.google.tm https://*.google.tn https://*.google.to https://*.google.com.tr https://*.google.tt https://*.google.com.tw https://*.google.co.tz https://*.google.com.ua https://*.google.co.ug https://*.google.co.uk https://*.google.com.uy https://*.google.co.uz https://*.google.com.vc https://*.google.co.ve https://*.google.co.vi https://*.google.com.vn https://*.google.vu https://*.google.ws https://*.google.rs https://*.google.co.za https://*.google.co.zm https://*.google.co.zw https://*.google.cat;connect-src wss://*.pusher.com 'self' *.cookielaw.org api.getblueshift.com *.onetrust.com *.hotjar.io vercel.live *.chatbot.com bat.bing.com *.clarity.ms crux-api.vercel.app https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://*.g.doubleclick.net https://*.google.com https://*.google.ad https://*.google.ae https://*.google.com.af https://*.google.com.ag https://*.google.al https://*.google.am https://*.google.co.ao https://*.google.com.ar https://*.google.as https://*.google.at https://*.google.com.au https://*.google.az https://*.google.ba https://*.google.com.bd https://*.google.be https://*.google.bf https://*.google.bg https://*.google.com.bh https://*.google.bi https://*.google.bj https://*.google.com.bn https://*.google.com.bo https://*.google.com.br https://*.google.bs https://*.google.bt https://*.google.co.bw https://*.google.by https://*.google.com.bz https://*.google.ca https://*.google.cd https://*.google.cf https://*.google.cg https://*.google.ch https://*.google.ci https://*.google.co.ck https://*.google.cl https://*.google.cm https://*.google.cn https://*.google.com.co https://*.google.co.cr https://*.google.com.cu https://*.google.cv https://*.google.com.cy https://*.google.cz https://*.google.de https://*.google.dj https://*.google.dk https://*.google.dm https://*.google.com.do https://*.google.dz https://*.google.com.ec https://*.google.ee https://*.google.com.eg https://*.google.es https://*.google.com.et https://*.google.fi https://*.google.com.fj https://*.google.fm https://*.google.fr https://*.google.ga https://*.google.ge https://*.google.gg https://*.google.com.gh https://*.google.com.gi https://*.google.gl https://*.google.gm https://*.google.gr https://*.google.com.gt https://*.google.gy https://*.google.com.hk https://*.google.hn https://*.google.hr https://*.google.ht https://*.google.hu https://*.google.co.id https://*.google.ie https://*.google.co.il https://*.google.im https://*.google.co.in https://*.google.iq https://*.google.is https://*.google.it https://*.google.je https://*.google.com.jm https://*.google.jo https://*.google.co.jp https://*.google.co.ke https://*.google.com.kh https://*.google.ki https://*.google.kg https://*.google.co.kr https://*.google.com.kw https://*.google.kz https://*.google.la https://*.google.com.lb https://*.google.li https://*.google.lk https://*.google.co.ls https://*.google.lt https://*.google.lu https://*.google.lv https://*.google.com.ly https://*.google.co.ma https://*.google.md https://*.google.me https://*.google.mg https://*.google.mk https://*.google.ml https://*.google.com.mm https://*.google.mn https://*.google.com.mt https://*.google.mu https://*.google.mv https://*.google.mw https://*.google.com.mx https://*.google.com.my https://*.google.co.mz https://*.google.com.na https://*.google.com.ng https://*.google.com.ni https://*.google.ne https://*.google.nl https://*.google.no https://*.google.com.np https://*.google.nr https://*.google.nu https://*.google.co.nz https://*.google.com.om https://*.google.com.pa https://*.google.com.pe https://*.google.com.pg https://*.google.com.ph https://*.google.com.pk https://*.google.pl https://*.google.pn https://*.google.com.pr https://*.google.ps https://*.google.pt https://*.google.com.py https://*.google.com.qa https://*.google.ro https://*.google.ru https://*.google.rw https://*.google.com.sa https://*.google.com.sb https://*.google.sc https://*.google.se https://*.google.com.sg https://*.google.sh https://*.google.si https://*.google.sk https://*.google.com.sl https://*.google.sn https://*.google.so https://*.google.sm https://*.google.sr https://*.google.st https://*.google.com.sv https://*.google.td https://*.google.tg https://*.google.co.th https://*.google.com.tj https://*.google.tl https://*.google.tm https://*.google.tn https://*.google.to https://*.google.com.tr https://*.google.tt https://*.google.com.tw https://*.google.co.tz https://*.google.com.ua https://*.google.co.ug https://*.google.co.uk https://*.google.com.uy https://*.google.co.uz https://*.google.com.vc https://*.google.co.ve https://*.google.co.vi https://*.google.com.vn https://*.google.vu https://*.google.ws https://*.google.rs https://*.google.co.za https://*.google.co.zm https://*.google.co.zw https://*.google.cat;font-src 'self' *.typekit.net vercel.live;frame-src 'self' *.buzzsprout.com *.typeform.com *.youtube-nocookie.com *.youtube.com fast.wistia.net player.vimeo.com td.doubleclick.net vimeo.com vercel.live *.chatbot.com *.googletagmanager.com;object-src 'none';base-uri 'self';form-action 'self';frame-ancestors 'none' 1 object-src 'none'; frame-ancestors 'none'; base-uri 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://www.googletagmanager.com https://*.mercdn.net https://www.google.com https://*.adtrafficquality.google https://*.g.doubleclick.net https://analytics.tiktok.com https://b99.yahoo.co.jp https://bat.bing.com https://*.smartnews-ads.com https://connect.facebook.net https://ct.pinterest.com https://d.line-scdn.net https://dmp.im-apps.net https://dynamic.criteo.com https://h.accesstrade.net https://s.pinimg.com https://s.yimg.jp https://*.criteo.com https://static.ads-twitter.com https://statics.a8.net https://*.blob.core.windows.net https://trj.valuecommerce.com https://*.google-analytics.com; style-src 'self' 'unsafe-inline' https://*.mercdn.net https://fonts.googleapis.com; font-src https://fonts.gstatic.com; 1 script-src 'nonce-ca8TRUYyXU7DVvFaWPuerng8yXUD70gc' 'strict-dynamic' 'self' https: http:; report-uri /.netlify/functions/__csp-violations 1 default-src 'self'; script-src 'self' 'report-sample' 'unsafe-inline' 'unsafe-eval' https://webcachex-eu.datareporter.eu; style-src-attr 'unsafe-inline' 'report-sample'; img-src 'self' data: *.ytimg.com *.vimeocdn.com https://*.openstreetmap.org blob: https://youtube.com https://*.youtube.com https://liwest.at/ https://*.liwest.at/ https://*.hubspot.com https://www.facebook.com https://googleads.g.doubleclick.net https://www.googleadservices.com https://www.google.com https://px.ads.linkedin.com *.px.ads.linkedin.com https://*.hsforms.com https://alb.reddit.com bat.bing.com https://www.google.at https://www.google.de https://www.googletagmanager.com https://maps.wien.gv.at https://fonts.gstatic.com https://webcache-eu.datareporter.eu https://maps.googleapis.com https://*.econda-monitor.de; base-uri 'self'; frame-src 'self' *.youtube-nocookie.com *.youtube.com *.vimeo.com https://*.frcapi.com/ https://*.liwest.at/ https://liwest-penalty-shootout.supernice.games https://liwest-qots.web.app https://liwest-tron.web.app https://*.google.com https://liwest-spendenaktion.web.app https://www.googletagmanager.com https://liwest.speedtestcustom.com https://forms-eu1.hsforms.com; connect-src 'self' data: https://*.openstreetmap.org https://*.friendlycaptcha.eu https://*.datareporter.eu https://*.hsforms.com https://hubspot-forms-static-embed-eu1.s3.amazonaws.com https://*.econda-monitor.de https://px.ads.linkedin.com https://analytics.tiktok.com https://*.hubapi.com https://bat.bing.com https://bat.bing.net https://*.hubspot.com https://pixel-config.reddit.com https://www.googleadservices.com https://googleads.g.doubleclick.net https://pixels.spotify.com https://*.etracker.com https://*.etracker.de https://analytics-ipv6.tiktokw.us https://www.google.com https://l.ecn-ldr.de https://www.facebook.com https://connect.facebook.net https://maps.wien.gv.at https://api.opendkm.at https://static.hsappstatic.net https://www.googletagmanager.com https://api.ipgeolocation.io https://srv.doris.at https://maps.googleapis.com; script-src-elem 'self' 'report-sample' 'unsafe-inline' inline https://youtube.com https://*.youtube.com https://*.datareporter.eu https://*.webcachex-eu.datareporter.eu https://cdnjs.cloudflare.com https://*.googletagmanager.com https://*.hsforms.net https://*.vimeo.com https://tracknet.twyn.com https://l.ecn-ldr.de https://api.ipify.org https://connect.facebook.net https://bat.bing.com https://analytics.tiktok.com https://js-eu1.hsadspixel.net https://googleads.g.doubleclick.net https://*.etracker.com https://*.etracker.de https://pixel.byspotify.com https://js-eu1.hs-scripts.com https://js-eu1.hs-banner.com https://static.hsappstatic.net https://js-eu1.hs-analytics.net https://js-eu1.hs-banner.net https://js-eu1.hubspot.com https://snap.licdn.com https://www.redditstatic.com https://maps.googleapis.com https://*.econda-monitor.de; style-src 'self' 'report-sample' https://*.datareporter.eu; worker-src blob: 'report-sample'; font-src 'self' data: https://fonts.gstatic.com; style-src-elem 'self' 'report-sample' 'unsafe-inline' inline https://webcache.datareporter.eu https://webcache-eu.datareporter.eu https://fonts.googleapis.com https://fonts.gstatic.com https://www.googletagmanager.com; report-uri https://www.liwest.at/@http-reporting?csp=report&requestTime=1770431368692428&requestHash=fdbd937f5f879690f35ac8775109f41a4097fb8d 1 default-src 'none'; script-src 'self' 'unsafe-eval' 'strict-dynamic' https://js.hcaptcha.com https://accounts.google.com; script-src-elem 'self' 'unsafe-inline' https://*.pionexdev.com https://*.pionex.com https://connect.facebook.net https://fpnpmcdn.net https://www.googletagmanager.com https://accounts.google.com https://static.zdassets.com https://www.recaptcha.net https://www.gstatic.com https://appleid.cdn-apple.com https://static.cloudflareinsights.com https://getlaunchlist.com https://at.alicdn.com https://widget-mediator.zopim.com https://gcaptcha4.geetest.com https://static.geetest.com https://telegram.org; frame-src 'self' https://*.pionexdev.com https://*.pionex.com https://accounts.google.com https://www.recaptcha.net https://api.sumsub.com https://merchant.cop-staging.straitsx.com https://merchant.cop-staging.xfers.com https://merchant.cop.straitsx.com https://merchant.cop.xfers.com blob: about:; object-src 'none'; base-uri 'self'; worker-src 'self' blob:; connect-src 'self' https://*.pionexdev.com https://*.pionex.com https://www.google-analytics.com https://o4505147559706624.ingest.sentry.io wss://*.pionexdev.com wss://*.pionex.com wss://stream.pionex.com https://firebase.googleapis.com https://ekr.zdassets.com https://firebaseremoteconfig.googleapis.com https://www.recaptcha.net https://firebaseinstallations.googleapis.com https://www.facebook.com https://accounts.google.com https://www.googletagmanager.com wss://widget-mediator.zopim.com https://id.zopim.com https://pionex.zendesk.com https://bituniverse-dev-test.s3.us-west-2.amazonaws.com https://oauth.telegram.org blob:; img-src 'self' https://*.pionexdev.com https://*.pionex.com https://www.facebook.com https://www.googletagmanager.com https://connect.facebook.net https://*.picol.com https://lh7-rt.googleusercontent.com https://pionex.com https://static.geetest.com https://res.cdn.bituniverse.org data: blob:; media-src 'self' https://*.pionex.com https://static.zdassets.com blob: data:; style-src 'self' 'unsafe-inline' https://accounts.google.com https://static.geetest.com; style-src-elem 'self' 'unsafe-inline' https://accounts.google.com https://*.pionex.com https://accounts.google.com https://fonts.googleapis.com https://static.geetest.com blob:; font-src 'self' https://*.pionex.com https://fonts.gstatic.com data:; form-action 'self' https://*.pionexdev.com https://*.pionex.com; frame-ancestors 'self'; manifest-src 'self'; report-uri https://www.pionexdev.com/csp-report/report?m=gAAAAAAAAAAAXprTx4QUNxW7YUHkTRjqBJr6wtRmY3W63SDkOY5tGhMTGYSbFWOR2_8YGhuJLEkg3crbMIhN58mJhvKHP7kYDIYy4AECengTbpygF3UBYApr2s2sFj9ULVAWxVGt-9cLFw1hkGkH9dW8GTVexhq9eg==; report-to pionex-csp-endpoint 1 font-src fonts.googleapis.com fonts.gstatic.com *.googleapis.com *.gstatic.com data: *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action *.googlesyndication.com *.clarity.ms *.google.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ bid.g.doubleclick.net *.youtube-nocookie.com www.google.com consentcdn.cookiebot.com *.google.ro *.facebook.com *.weltpixel.com https://*.sameday.ro *.googletagmanager.com *.doubleclick.net 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: *.vimeocdn.com i.ytimg.com *.youtube.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com maps.googleapis.com maps.gstatic.com *.gstatic.com *.googleapis.com https://images.unsplash.com *.tbicp.com imgsct.cookiebot.com *.google.ro *.clarity.ms *.bing.com https://a.tile.openstreetmap.org https://b.tile.openstreetmap.org https://c.tile.openstreetmap.org https://www.selfawb.ro https://firebasestorage.googleapis.com flagpedia.net t.themarketer.com cdn1.themarketer.com *.facebook.com *.reddit.com *.google-analytics.com *.googletagmanager.com *.doubleclick.net *.google.com data: 'self' 'unsafe-inline'; script-src s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.googleapis.com *.gstatic.com https://cdn.jsdelivr.net/npm/@ryangjchandler/spruce@2.x.x/dist/spruce.umd.js www.google.com/recaptcha/ www.gstatic.com/recaptcha/ https://maps.googleapis.com *.tbicp.com consentcdn.cookiebot.com *.cookiebot.com *.google.ro *.clarity.ms *.aqurate.ai *.themarketer.com *.avada.io t.themarketer.com cdn1.themarketer.com https://*.sameday.ro *.googletagmanager.com *.googleadservices.com *.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com unpkg.com *.doubleclick.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com *.google.ro *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.gstatic.com t.themarketer.com cdn1.themarketer.com https://*.sameday.ro *.tagmanager.google.com *.googletagmanager.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.google.ro *.google.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com vimeo.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.googleapis.com https://maps.googleapis.com https://player.vimeo.com consentcdn.cookiebot.com *.googlesyndication.com *.clarity.ms *.google.com google.com *.facebook.com *.aqurate.ai *.themarketer.com https://ecommerce.fancourier.ro https://nominatim.openstreetmap.org https://api.fancourier.ro https://get.geojs.io *.avada.io www.gstatic.com t.themarketer.com cdn1.themarketer.com *.google-analytics.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.doubleclick.net *.run.app 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://251703a9-46ab-4e4f-ab25-1de6ee452399.sansec.watch/; report-to report-endpoint; 1 default-src 'self'; connect-src *; img-src * data:; script-src 'nonce-JzPLRruj01eiUnsAf9gtKwC3Zx9VZGE7' 'unsafe-eval' 'strict-dynamic' 'unsafe-inline' 'self' https: http: 'self' cdn.bizible.com; style-src 'self' 'unsafe-inline' https://404-tpa-276.mktoweb.com/ https://*.qualified.com; font-src 'self' kit.fontawesome.com https://ka-p.fontawesome.com/ https://fast.wistia.com/ data:; form-action 'self'; object-src 'none'; media-src 'self' blob: mediastream: https://*.qualified.com; frame-src https://www.googletagmanager.com https://td.doubleclick.net/ https://gtm.docketwise.com/ https://www.youtube.com/ https://insight.adsrvr.org/ https://app.netlify.com/ https://404-tpa-276.mktoweb.com/ https://*.qualified.com; child-src https://*.qualified.com; frame-ancestors demo.affinipay.com ka-p.fontawesome.com; upgrade-insecure-requests; block-all-mixed-content; report-uri /.netlify/functions/__csp-violations 1 frame-ancestors https://*.facebook.com https://*.youtube.com https://*.graphic.com.gh; 1 upgrade-insecure-requests; default-src 'self'; script-src 'report-sample' 'self' 'unsafe-inline' 'unsafe-eval' https://accessibilityserver.org https://amplify.outbrain.com https://bam.nr-data.net https://bat.bing.com https://c.lytics.io https://cdn.segment.com https://cdn.taboola.com https://cdn.userway.org https://connect.facebook.net https://googleads.g.doubleclick.net https://js-agent.newrelic.com https://platform.twitter.com https://qmod.quotemedia.com https://s.yimg.com https://script.hotjar.com https://securepubads.g.doubleclick.net https://sslwidget.criteo.com https://static.ads-twitter.com https://static.criteo.net https://static.hotjar.com https://tr.outbrain.com https://trc.taboola.com https://www.dwin1.com https://www.google-analytics.com https://www.googletagmanager.com https://www.googletagservices.com https://www.redditstatic.com; style-src 'report-sample' 'self' 'unsafe-inline' https://c.lytics.io https://cdnjs.cloudflare.com https://fonts.googleapis.com https://qmod.quotemedia.com https://static.c1.quotemedia.com; img-src 'self' data: https://alb.reddit.com https://analytics.twitter.com https://bat.bing.com https://c.lytics.io https://cdn.userway.org https://data.dianomi.com https://pagead2.googlesyndication.com https://pubads.g.doubleclick.net https://q.quora.com https://secure.gravatar.com https://sp.analytics.yahoo.com https://syndication.twitter.com https://t.co https://tr.outbrain.com https://www.facebook.com https://www.google.com https://www.googletagmanager.com https://www.quotemedia.com; connect-src 'self' https://api.segment.io https://api.userway.org https://app.quotemedia.com https://bam.nr-data.net https://ca.foolpitches.com https://cdn.segment.com https://cdn.userway.org https://cds.taboola.com https://csi.gstatic.com https://in.hotjar.com https://pips.taboola.com https://s.yimg.com https://securepubads.g.doubleclick.net https://stats.g.doubleclick.net https://to.getnitropack.com https://trc-events.taboola.com https://vc.hotjar.io https://www.google-analytics.com; font-src 'self' data: https://cdnjs.cloudflare.com https://fonts.gstatic.com https://static.c1.quotemedia.com; frame-src https://gum.criteo.com https://platform.twitter.com https://syndication.twitter.com https://www.facebook.com; report-uri https://csp.feroot.com/a5814c59-63d2-4c2f-8d39-70a4fbe37b03/a068f8b4-0865-4c32-bd31-375a39409b87/collect; 1 script-src 'unsafe-inline' 'unsafe-eval' cdn2.hubspot.net *.hubspot.com *.hubspotusercontent10.net js.hscollectedforms.net js.hsleadflows.net js.hs-scripts.com js.hsadspixel.net js.hs-analytics.net js.hs-banner.com js.hs-banner.net *.hsforms.net *.hsforms.com static.hsappstatic.net js.hubspotfeedback.com feedback.hubapi.com js.usemessages.com *.vidyard.com cdnjs.cloudflare.com cdnjs.cloudflare.com 10921146.fls.doubleclick.net plausible.io *.hotjar.com *.hotjar.io *.qualified.com bttrack.com *.googletagmanager.com *.force.com *.thycotic.com *.centrify.com *.bidr.io *.rlcdn.cm t.co *.twitter.com burly.io *.clickagy.com *.doubleclck.net *.zoominfo.com lltrck.com facebook.com *.facebook.net *.redditstatic.com *.linkedin.com *.licdn.com *.demandbase.com *.zoominfo.com 'strict-dynamic' 'nonce-zNwwgseC1MaCcmucNWPing==' 1 default-src 'self' www.google-analytics.com www.youtube.com cdn.cookielaw.org *.onetrust.com *.gstatic.com *.google.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.googletagmanager.com cdn.jsdelivr.net cdn.cookielaw.org img03.en25.com *.youtube.com *.google.com *.gstatic.com *.google-analytics.com embed.vev.page *.vev.design *.googleapis.com discover.hdrinc.com *.cloudflare.com unpkg.com; style-src 'self' 'unsafe-inline' cloud.typography.com cdn.jsdelivr.net *.googleapis.com www.hdrinc.com unpkg.com *.cloudflare.com; img-src 'self' data: *; media-src film.vev.design cdn.vev.design; frame-src 'self' *.google.com *.youtube.com *.vimeo.com discover.hdrinc.com *.doubleclick.net player.blubrry.com e.issuu.com caupneif01 *.youtube-nocookie.com *.googletagmanager.com *.cloudflare.com; child-src 'self' *.google.com *.youtube.com; font-src 'self' data: cloud.typography.com cdn.vev.design *.gstatic.com www.hdrinc.com cdn.scite.ai use.typekit.net fonts.vev.design; connect-src 'self' *.googleapis.com *.google-analytics.com *.cookielaw.org *.onetrust.com analytics.google.com *.doubleclick.net region1.analytics.google.com *.google.com *.gstatic.com; report-uri /report-csp-violation; upgrade-insecure-requests 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://*.gstatic.com *.fontawesome.com *.kameleoon.com *.kameleoon.eu *.kameleoon.io *.adp.com *.googleapis.com data: *.espssl.com maxcdn.bootstrapcdn.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.adyen.com api.bazaarvoice.com stg.api.bazaarvoice.com *.kameleoon.com *.kameleoon.eu *.kameleoon.io *.facebook.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.adyen.com *.wesupply.xyz https://wesupplylabs.com guarantee-cdn.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com *.kameleoon.com *.kameleoon.eu *.kameleoon.io *.burpee.com *.criteo.net *.criteo.com *.freshchat.com *.doubleclick.net *.paypalobjects.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * js.mollie.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io *.ftcdn.net *.behance.net *.paypal.com *.typekit.net *.gstatic.com *.adyen.com https://*.gstatic.com https://images.unsplash.com guarantee-cdn.com display.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com network-a.bazaarvoice.com network-stg-a.bazaarvoice.com photos-uat-us.bazaarvoice.com img.youtube.com *.kameleoon.com *.kameleoon.eu *.kameleoon.io *.clarity.ms *.doubleclick.net *.bing.com *.alocdn.com *.google-analytics.com *.google.com.br *.google.com *.google.com.ua *.google.de www.facebook.com *.rlcdn.com *.criteo.com *.espssl.com *.burpee.com *.listrakbi.com *.linksynergy.com *.securedvisit.com *.bazaarvoice.com connect.facebook.net graph.facebook.com business.facebook.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com https://www.mollie.com https://redchamps.com *.hsforms.net *.hsforms.com 'self' data: https://maps.gstatic.com *.googletagmanager.com ssl.gstatic.com www.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com js-agent.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.adyen.com *.googleapis.com https://maps.googleapis.com *.cloudflare.com guarantee-cdn.com apps.bazaarvoice.com apps.nexus.bazaarvoice.com apps-stg.nexus.bazaarvoice.com analytics-static.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com mpsnare.iesnare.com *.jsdelivr.net *.adp.com *.kameleoon.com *.kameleoon.eu *.kameleoon.io *.rapidspike.com *.facebook.com *.googleoptimize.com *.listrakbi.com *.rkdms.com *.amplitude.com *.trustpilot.com *.googletagmanager.com *.googleadservices.com data: *.bing.com *.criteo.net *.rmtag.com *.facebook.net *.doubleclick.net *.linksynergy.com *.clarity.ms *.datadome.co *.datadome.com *.criteo.com *.rakuten.com *.freshchat.com *.securedvisit.com *.burpee.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com js.mollie.com *.hsforms.net *.hsforms.com *.gstatic.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://fonts.googleapis.com/ *.fontawesome.com display.ugc.bazaarvoice.com *.kameleoon.com *.kameleoon.eu *.kameleoon.io *.listrakbi.com *.trustpilot.com *.googleapis.com data: *.freshchat.com *.espssl.com *.cloudflare.com *.adp.com assets.braintreegateway.com maxcdn.bootstrapcdn.com *.gstatic.com tagmanager.google.com fonts.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.adyen.com *.googleapis.com https://maps.googleapis.com https://player.vimeo.com api.bazaarvoice.com stg.api.bazaarvoice.com apps.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com *.kameleoon.com *.kameleoon.eu *.kameleoon.io *.facebook.com *.listrakbi.com *.paypalobjects.com *.clarity.ms *.rapidspike.com *.google-analytics.com *.doubleclick.net data: *.algolia.io *.revcontent.com *.datadome.co *.datadome.com *.adp.com *.amplitude.com *.bing.com *.bazaarvoice.com *.burpee.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.analytics.google.com *.googletagmanager.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 object-src 'none';base-uri 'self';script-src 'nonce-uQWFcUFR09IAooiJ2jXvyA' 'strict-dynamic' 'report-sample' 'unsafe-eval' 'unsafe-inline' https: http:;report-uri https://csp.withgoogle.com/csp/gws/other-hp 1 default-src 'self' https://*.cdninstagram.com https://*.sc-concierge.jp https://parco.jp https://*.parco.jp; script-src 'self' 'unsafe-inline' https://*.sc-concierge.jp https://*.googletagmanager.com https://*.google-analytics.com https://connect.facebook.net https://cdn.treasuredata.com https://googleads.g.doubleclick.net https://*.googleadservices.com https://autoline.link https://*.youtube.com https://*.vimeo.com https://cdnjs.cloudflare.com https://*.treasuredata.com https://d-track.send.microad.jp https://dsp.logly.co.jp https://js.fout.jp https://*.line-scdn.net https://hpadmin.transer.com https://dmp.im-apps.net https://*.yimg.jp https://3ppa.jp.cinarra.com https://*.tiktok.com https://cdn.smartnews-ads.com https://*.googleapis.com https://analytics.tiktok.com https://code.createjs.com https://code.jquery.com https://*.shutto-translation.com https://*.twitter.com https://polyfill.io https://sdk.n-analytics.io https://sitectl.athp.transer.com https://synalio.com https://track.list-finder.jp https://tracking.sitest.jp https://unpkg.com https://*.typekit.net https://*.promisejs.org https://amplify.outbrain.com https://*.ptengine.jp https://*.outbrain.com https://cdn.scaleflex.it https://*.cloudfront.net https://n-analytics.io https://*.ads-twitter.com https://*.google.com https://*.chatplus.jp https://cdn.jsdelivr.net; style-src 'self' 'unsafe-inline' https://*.sc-concierge.jp https://fonts.googleapis.com https://cdnjs.cloudflare.com https://*.typekit.net https://*.googleapis.com https://*.myfonts.net https://unpkg.com https://*.chatplus.jp https://cdn.jsdelivr.net; img-src 'self' data: https://*.sc-concierge.jp https://*.parco.jp https://parco.jp https://*.ytimg.com https://img.youtube.com https://pbs.twimg.com https://res.cloudinary.com https://maps.googleapis.com https://*.cdninstagram.com https://*.line.me https://*.facebook.com https://*.google.co.jp https://cnt.fout.jp https://*.google.com https://*.googletagmanager.com https://connect.facebook.net https://3ppa.jp.cinarra.com https://*.smartnews-ads.com https://*.vimeocdn.com https://placehold.jp https://*.fbcdn.net https://*.cinequinto.com https://*.club-quattro.com https://*.outbrain.com https://the-guest.com https://*.ipos-land.jp https://*.g.doubleclick.net https://*.gstatic.com https://t.co https://*.twitter.com https://*.chatplus.jp https://*.amazonaws.com; media-src 'self' https://*.sc-concierge.jp https://parco.jp https://*.chatplus.jp https://*.parco.jp; font-src 'self' data: https://*.sc-concierge.jp https://fonts.gstatic.com https://*.cloudflare.com https://cdn.jsdelivr.net https://*.chatplus.jp https://use.typekit.net; connect-src 'self' https://*.sc-concierge.jp https://parco.jp https://*.parco.jp https://*.google-analytics.com https://stats.g.doubleclick.net https://*.googleadservices.com https://*.twitter.com https://*.treasuredata.com https://analytics.google.com https://vimeo.com https://*.vimeo.com https://audiencedata.im-apps.net https://*.google.com https://*.facebook.com https://*.yahoo.co.jp https://*.slim02.jp https://analytics-ipv6.tiktokw.us https://analytics.tiktok.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://*.facebook.com https://*.google.com https://*.typekit.net https://*.promisejs.org https://unpkg.com https://*.outbrain.com https://synalio.com https://*.google.co.jp https://*.googleapis.com https://*.chatplus.jp https://api.treasuredata.com; frame-src https://*.sc-concierge.jp https://www.youtube.com https://www.googletagmanager.com https://js.fout.jp https://bid.g.doubleclick.net https://*.facebook.com https://*.google.com https://*.youtube-nocookie.com https://*.twitter.com https://*.chatplus.jp https://player.vimeo.com; object-src 'none'; base-uri 'self'; frame-ancestors 'none'; form-action 'self' https://*.facebook.com; worker-src 'self' blob:; 1 report-uri https://csp.withgoogle.com/csp/youtube_main/strict;base-uri 'self';object-src 'none';script-src 'report-sample' 'nonce-RLMMdztWIRq2Ek0XqAaifg' 'unsafe-inline' 'strict-dynamic' https: http: 'unsafe-eval' 1 default-src 'self'; script-src 'report-sample' 'self' 'unsafe-inline' 'unsafe-eval' ajax.aspnetcdn.com *.plexonline.com *.plexus-online.com *.plex.com web-sdk.aptrinsic.com; style-src 'report-sample' 'self' data: 'unsafe-inline' ajax.aspnetcdn.com *.plexonline.com *.plexus-online.com *.plex.com web-sdk.aptrinsic.com; img-src 'self' data: ajax.aspnetcdn.com *.plexonline.com *.plexus-online.com www.gstatic.com 127.0.0.1:18623 *.plex.com; font-src 'self' *.plex.com data: *.plexus-online.com fonts.gstatic.com maxcdn.bootstrapcdn.com *.plexonline.com at.alicdn.com use.typekit.net; connect-src 'self' web-sdk.aptrinsic.com esp.aptrinsic.com *.plex.com pcn-move.plexdev.io cdnma.cdnservice.space cdnma.global-cache.online cdnmb.global-cache.online 127.0.0.1:18623 js.authorize.net tablet.sigwebtablet.com:47290; media-src 'self' *.plex.com; object-src 'self'; child-src 'self'; frame-src 'self'; worker-src 'self'; frame-ancestors 'self' www.plexonline.com www.plexus-online.com; form-action 'self' *.plexus-online.com *.plexonline.com *.plex.com; base-uri 'self'; manifest-src 'self'; script-src-elem 'self' 'unsafe-inline' web-sdk.aptrinsic.com www.gstatic.com *.plexonline.com *.plex.com js.authorize.net jstest.authorize.net *.google-analytics.com www.pagespeed-mod.com *.plexus-online.com www.gstatic.com; style-src-elem 'unsafe-inline' *.plexonline.com web-sdk.aptrinsic.com www.gstatic.com maxcdn.bootstrapcdn.com *.plex.com *.plexus-online.com; report-uri https://csp.security.plex.com/csp/reporting 1 worker-src blob:; form-action *.cardinalcommerce.com *.paypal.com www.sandbox.paypal.com *.amazon.com *.facebook.com *.googlesyndication.com *.tiktok.com connect.facebook.net 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com plumrocket.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src *.googletagmanager.com *.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com *.paypal.com www.sandbox.paypal.com player.vimeo.com *.google.com *.braintreegateway.com google.com js.stripe.com *.amazon.com *.payments-amazon.com *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com connect.facebook.net www.commercepartnerhub.com assets.braintreegateway.com plumrocket.com *.authorize.net *.artifi.net www.googleadservices.com assets.pinterest.com ct.pinterest.com www.paypalobjects.com i.liadm.com 'self' 'unsafe-inline'; script-src *.googletagmanager.com *.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net *.google.com *.newrelic.com *.nr-data.net *.authorize.net *.commerce-payment-services.com *.paypal.com www.sandbox.paypal.com www.paypalobjects.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.gstatic.com assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com *.typekit.net google.com *.cdn-apple.com *.braintreegateway.com js.stripe.com *.payments-amazon.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googlesyndication.com *.jsdelivr.net *.tiktok.com *.klaviyo.com fast.a.klaviyo.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com *.shopify.com *.sandbox.braintreegateway.com *.popt.in *.cloudflare.com celebrosnlp.com *.celebros-analytics.com *.artifi.net maps.googleapis.com www.googletagservices.com cdn.gladly.qa cdn.gladly.com *.monetate.net *.visualwebsiteoptimizer.com *.cloudfront.net s.pinimg.com bat.bing.com tag.rmp.rakuten.com ut.rd.linksynergy.com *.pinterest.com cdn.noibu.com *.hotjar.com b-code.liadm.com secure.merchantadvantage.com static.currentcatalog.com currentc-ac.celebros.com ajax.googleapis.com *.celebros.com 'self' 'unsafe-inline' 'unsafe-eval'; report-uri https://www.currentcatalog.com/pr-csp/report/add/; report-to report-endpoint; 1 frame-src 'self' *.adyen.com *.ingrid.com *.googletagmanager.com *.google.com *.consentmanager.net *.bigcontent.io *.cloudflare.com *.klarna.com *.facebook.com *.ahlens.se *.klarnaservices.com; script-src 'self' abtasty.com *.abtasty.com bing.com *.bing.com bloomreach.com *.bloomreach.com cdn-apple.com *.cdn-apple.com cloudflare.com *.cloudflare.com consentmanager.net *.consentmanager.net doubleclick.net *.doubleclick.net facebook.net *.facebook.net getflowbox.com *.getflowbox.com google.com *.google.com googlesyndication.com *.googlesyndication.com googletagmanager.com *.googletagmanager.com hotjar.com *.hotjar.com ingrid.com *.ingrid.com klarnacdn.net *.klarnacdn.net maps.googleapis.com *.maps.googleapis.com 'unsafe-inline' 'unsafe-eval'; worker-src 'self' blob:; report-uri https://csp-reporting.cloudflare.com/cdn-cgi/script_monitor/report?m=25cLbFqUBskBbjbcxBBSs1XbhRWTDGlXw7OytOxi4fA-1770435165.6737547-1.0.1.1-gbONaTclbHZbMYrz8YL.1ajAQa6DvjISWbu..R7gyoBAQuj8wyE6HIay4uGBi2wRfwIW.eSe.OsxxlP6B1Yf2RESV5qoLeLc7QfS2obiimq9A1xbgBku9EjmB5NcgjOdNsbk0nV0ZbcilHXADPUwLvdv_4S5jjVidOi_mL5LAdgnY5KGfFkK9ifDuxOExQAf; report-to cf-ovvaawavzghsahgx 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com cash-f.squarecdn.com https://*.gstatic.com *.bglobale.com *.global-e.com assets.reviews.io applepay.cdn-apple.com *.amazonaws.com https://www.gstatic.com https://fonts.gstatic.com maxcdn.bootstrapcdn.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com * *.adyen.com www.apptrian.com pinterest.com www.pinterest.com ct.pinterest.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com https://plumrocket.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com * *.adyen.com www.apptrian.com pinterest.com www.pinterest.com ct.pinterest.com *.dotdigital-pages.com *.dotdigital.com webchat.dotdigital.com webchat.staging.dotdigital.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com account.fetchify.com *.bglobale.com *.global-e.com www.xtento.com https://*.google.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com https://plumrocket.com https://t.pepperjamnetwork.com https://*.dwin1.com https://*.awin1.com https://*.zenaps.com *.weltpixel.com *.googletagmanager.com *.doubleclick.net *.typeform.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io * https://*.gstatic.com *.adyen.com www.apptrian.com pinterest.com www.pinterest.com ct.pinterest.com *.trackedlink.net www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.bglobale.com *.global-e.com www.xtento.com cdn.xtento.com assets.reviews.io www.google.co.uk *.amazonaws.com https://*.google.com https://*.googleapis.com https://*.googleusercontent.com *.googleapis.com flagpedia.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com https://shareasale.com/sale.cfm https://track.linksynergy.com https://www.bizrate.com https://*.dwin1.com https://*.awin1.com https://*.zenaps.com https://track.webgains.com https://prf.hn https://track.flexlinks.com https://scripts.affiliatefuture.com https://t.powerreviews.com https://match.sharethrough.com https://cm.g.doubleclick.net https://x.bidswitch.net https://ib.adnxs.com https://rtb-csync.smartadserver.com https://sync-t1.taboola.com https://visitor.omnitagjs.com https://r.casalemedia.com https://gum.criteo.com https://jadserve.postrelease.com https://id5-sync.com https://ad.360yield.com https://matching.ivitrack.com https://contextual.media.net https://exchange.mediavine.com https://sync.outbrain.com https://simage2.pubmatic.com https://pixel.rubiconproject.com https://criteo-sync.teads.tv https://criteo-partners.tremorhub.com https://eb2.3lift.com https://ad.yieldlab.net https://sync-criteo.ads.yieldmo.com https://e1.emxdgt.com https://sync.1rx.io https://dis.criteo.com https://dpm.demdex.net https://ps.eyeota.net https://public-prod-dspcookiematching.dmxleo.com *.hsforms.net *.hsforms.com 'self' data: *.facebook.com *.reddit.com *.ads-twitter.com t.co *.twitter.com *.bing.com *.bing.net *.klaviyo.com *.pinterest.com *.pinimg.com *.clarity.ms *.googletagmanager.com *.doubleclick.net *.google.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com commerce-payments-sdk.adobe.io www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com *.cash.app *.visa.com *.mastercard.com applepay.cdn-apple.com www.apptrian.com pinterest.com www.pinterest.com s.pinimg.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal webchat.dotdigital.com webchat.staging.dotdigital.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com cc-cdn.com *.bglobale.com *.global-e.com www.xtento.com cdn.xtento.com app.termly.io widget.reviews.io js-agent.newrelic.com ajax.cloudflare.com static.cloudflareinsights.com ipinfo.io websdk.appsflyer.com ct.pinterest.com www.dwin1.com *.amazonaws.com api.uk.exponea.com tag.mention-me.com c0.adalyser.com joani11112.pcapredict.com joaniedev-1.store.advancedcommerce.services joanie-1.store-uk1.advancedcommerce.services static.dressipi.com load.collect.joanieclothing.com shopforward.eu script.hotjar.com cdn-sitegainer.com services.postcodeanywhere.co.uk static.mention-me.com https://cdn.polyfill.io https://browser.sentry-cdn.com https://cdn.lr-ingest.io https://unpkg.com *.gstatic.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com maps.googleapis.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com https://*.dwin1.com https://intljs.rmtag.com https://cdn.avmws.com https://images.bizrate.com https://*.awin1.com https://*.zenaps.com https://the.sciencebehindecommerce.com https://swrap.tradedoubler.com https://analytics.optimalpeople.fr https://www.linkconnector.com https://d3v27wwd40f0xu.cloudfront.net https://static.criteo.net https://sslwidget.criteo.com https://*.affiliatefuture.com https://static.powerreviews.com https://analytics.webgains.io *.hsforms.net *.hsforms.com *.googletagmanager.com *.googleadservices.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.bing.com *.clarity.ms *.klaviyo.com sc-static.net *.snapchat.com *.pinterest.com *.pinimg.com unpkg.com *.doubleclick.net *.typeform.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.cash.app https://fonts.googleapis.com/ webchat.dotdigital.com webchat.staging.dotdigital.com cc-cdn.com *.bglobale.com *.global-e.com assets.reviews.io data: use.typekit.net p.typekit.net *.amazonaws.com services.postcodeanywhere.co.uk https://fonts.googleapis.com https://hcaptcha.com https://*.hcaptcha.com *.gstatic.com *.googleapis.com maxcdn.bootstrapcdn.com assets.braintreegateway.com *.tagmanager.google.com *.googletagmanager.com *.typeform.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com pinterest.com www.pinterest.com ct.pinterest.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com * *.adyen.com www.apptrian.com pinterest.com www.pinterest.com ct.pinterest.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com api.craftyclicks.co.uk pcls1.craftyclicks.co.uk cc-cdn.com app.termly.io *.reviews.io region1.analytics.google.com stats.g.doubleclick.net pagead2.googlesyndication.com *.amazonaws.com grapheneai.joanieclothing.com wss://ws.hotjar.com content.hotjar.io api.zuko.io joaniedev-1.store.advancedcommerce.services joanie-1.store-uk1.advancedcommerce.services services.postcodeanywhere.co.uk metrics.hotjar.io https://*.ingest.sentry.io https://ipinfo.io https://*.google.com https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com maps.googleapis.com www.gstatic.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com https://shareasale.com/sale.cfm https://analytics.optimalpeople.fr https://measurement-api.criteo.com https://api.webgains.io https://the.sciencebehindecommerce.com https://*.wepowerconnections.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.pinterest.com *.pinimg.com sc-static.net *.snapchat.com *.doubleclick.net *.run.app *.typeform.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 frame-ancestors 'self' https://*.mastercontrol.com mastercontrol.service-now.com; object-src 'none'; form-action 'self' https://*.mastercontrol.com *.rise.com *.service-now.com mastercontrol.influitive.com gateway.zscloud.net mastercontrol.uservoice.com https://*.facebook.com https://connect.facebook.net; base-uri 'self' https://*.mastercontrol.com https://*.clarity.ms; report-uri https://reportcsp.azurewebsites.net/api/CSPViolation 1 font-src fonts.gstatic.com use.typekit.net https://cdn.checkout.com *.bglobale.com *.global-e.com *.klarnacdn.net *.fontawesome.com *.cloudflare.com *.twitter.com *.gstatic.com *.typekit.net *.twimg.com *.trustedshops.com *.googleapis.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com testsecureacceptance.cybersource.com secureacceptance.cybersource.com 0merchantacsstag.cardinalcommerce.com merchantacs.cardinalcommerce.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.twitter.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com https://js.checkout.com *.klarna.com *.online-metrix.net testflex.cybersource.com flex.cybersource.com testsecureacceptance.cybersource.com secureacceptance.cybersource.com sandbox.secure.checkout.visa.com secure.checkout.visa.com thm.visa.com sandbox.src.mastercard.com merchantacs.cardinalcommerce.com 0merchantacsstag.cardinalcommerce.com *.bglobale.com *.global-e.com https://www.googletagmanager.com/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.youtube.com/ *.weltpixel.com *.wesupply.xyz https://wesupplylabs.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.afd.co.uk *.brsrvr.com *.bloomreach.cloud sandbox.secure.checkout.visa.com secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com assets.secure.checkout.visa.com thm.visa.com *.bglobale.com *.global-e.com *.klarna.com *.klarnaevt.com *.klarnacdn.net http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: *.paypal.com *.cloudflare.com *.googleadservices.com *.google-analytics.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net amcglobal.sc.omtrdc.net commerce.adobe.net use.typekit.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com *.magento-ds.com www.google.com *.afd.co.uk cdn.brcdn.com https://*.checkout.com *.klarnacdn.net *.online-metrix.net testflex.cybersource.com flex.cybersource.com x.klarnacdn.net sandbox.secure.checkout.visa.com secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com assets.secure.checkout.visa.com thm.visa.com sandbox.src.mastercard.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.bglobale.com *.global-e.com *.klarna.com *.klarnaservices.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.cloudflare.com *.twitter.com *.google-analytics.com *.twimg.com *.gstatic.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.trackedlink.net cdn.jsdelivr.net https://www.googletagmanager.com tagmanager.google.com unpkg.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com https://cdn.checkout.com *.bglobale.com *.global-e.com *.klarnacdn.net *.fontawesome.com unsafe-inline assets.braintreegateway.com *.cloudflare.com *.googleapis.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io *.magento-datasolutions.com *.magento-ds.com *.sentry.io *.afd.co.uk *.dxpapi.com https://js.checkout.com *.klarnaevt.com thm.visa.com *.klarnacdn.net *.klarna.com *.klarnaservices.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ *.klarnauserservices.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.cloudflare.com *.twitter.com *.twimg.com *.googleadservices.com *.google-analytics.com *.sandbox.paypal.com *.paypalobjects.com *.trackedlink.net *.ampproject.org experiments-api.fabric-analytics.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' dropbox.okta.com *.oktacdn.com; connect-src 'self' dropbox.okta.com dropbox-admin.okta.com *.oktacdn.com *.mixpanel.com *.mapbox.com dropbox.kerberos.okta.com dropbox.mtls.okta.com *.authenticatorlocalprod.com:8769 http://localhost:8769 http://127.0.0.1:8769 *.authenticatorlocalprod.com:65111 http://localhost:65111 http://127.0.0.1:65111 *.authenticatorlocalprod.com:65121 http://localhost:65121 http://127.0.0.1:65121 *.authenticatorlocalprod.com:65131 http://localhost:65131 http://127.0.0.1:65131 *.authenticatorlocalprod.com:65141 http://localhost:65141 http://127.0.0.1:65141 *.authenticatorlocalprod.com:65151 http://localhost:65151 http://127.0.0.1:65151 https://oinmanager.okta.com data: *.ingest.sentry.io; script-src 'unsafe-inline' 'nonce-VaOiPwgm3TTIFHSzencqWg' 'unsafe-eval' 'self' 'report-sample' dropbox.okta.com *.oktacdn.com; style-src 'unsafe-inline' 'nonce-VaOiPwgm3TTIFHSzencqWg' 'self' 'report-sample' dropbox.okta.com *.oktacdn.com; frame-src 'self' dropbox.okta.com dropbox-admin.okta.com login.okta.com *.vidyard.com com-okta-authenticator: api-37ec43d7.duosecurity.com; img-src 'self' dropbox.okta.com *.oktacdn.com *.tiles.mapbox.com *.mapbox.com *.vidyard.com data: blob:; font-src 'self' dropbox.okta.com data: *.oktacdn.com fonts.gstatic.com; frame-ancestors 'self' https://app.dropboxer.net 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https: wss://ws.salecycle.com; object-src 'none'; style-src 'self' https: 'unsafe-hashes' 'unsafe-inline' https://*.aircaraibes.com https://googletagmanager.com https://tagmanager.google.com https://fonts.googleapis.com; img-src 'self' data: https:; media-src 'self'; frame-src 'self' https://*.aircaraibes.com https://aircaraibes.qualifioapp.com https://www.googletagmanager.com/ https://*.salecycle.com https://*.pinterest.com https://*.criteo.com https://*.cloudfront.net; frame-ancestors 'self' https://www.liligo.com https://www.liligo.fr https://checkin.si.amadeus.net https://*.aircaraibes.com; font-src 'self' data: https://fonts.googleapis.com https://fonts.gstatic.com https://*.finchatbot.com; connect-src 'self' https: wss://ws.salecycle.com; upgrade-insecure-requests 1 default-src 'self'; style-src 'self' 'unsafe-inline' googletagmanager.com tagmanager.google.com fonts.googleapis.com; script-src 'self' www.google.com *.googletagmanager.com *.gstatic.com; img-src 'self' googletagmanager.com *.gstatic.com * data:; frame-src 'self' www.youtube.com www.google.com blob:;frame-ancestors 'none'; form-action 'self'; font-src 'self' fonts.gstatic.com data:; connect-src 'self' *.googleapis.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com *.google.com 1 default-src 'self'; script-src 'self' 'unsafe-eval' 'strict-dynamic' 'nonce-zX0HvipU20agNvqDSm0Gsw==' https://*.adyen.com https://*.adyenpayments.com https://*.bambuser.com https://*.cevoid.com https://*.contentsquare.net https://*.doubleclick.net https://*.klarna.com https://*.klarnacdn.net https://*.kustom.co https://*.taboola.com https://*.usercentrics.eu https://analytics.tiktok.com https://api.unifaun.com https://assets.voyado.com https://bat.bing.com https://chat.kindlycdn.com https://connect.facebook.net https://ct.pinterest.com https://gallery.cevoid.com https://google-analytics.com https://pay.google.com https://s.pinimg.com https://t.contentsquare.net https://tr.snapchat.com https://www.googleadservices.com https://www.googletagmanager.com https://www.googletagservices.com https://ad.doubleclick.net https://modules.ecomid.com; style-src 'self' 'unsafe-inline' https: data:; connect-src 'self' https://*.az.contentsquare.net https://*.bambuser.com https://*.cevoid.com https://*.contentsquare.net https://*.facebook.com https://*.google-analytics.com https://*.google.com https://www.google.com https://*.google.se https://*.klarna.com https://*.kindly.ai https://*.kustom.co https://*.snapchat.com https://*.taboola.com https://*.tiktok.com https://*.usercentrics.eu https://*.kappahl.com https://*.newbie.com https://analytics-ipv6.tiktokw.us https://api.cevoid.com https://api.klarna.com https://api.raygun.io https://api.screen9.com https://api.unifaun.com https://assets.voyado.com https://bat.bing.com https://bat.bing.net https://bot.kindly.ai https://cdn.raygun.io https://chat.kindlycdn.com https://checkout-test.adyen.com https://checkout.adyen.com https://checkoutanalytics-test.adyen.com https://checkoutshopper-test.cdn.adyen.com https://checkoutshopper-test.cdn.adyen.com/ https://checkoutanalytics-live.adyen.com https://ct.pinterest.com https://dc.services.visualstudio.com https://gallery.cevoid.com https://google.com https://maps.googleapis.com https://pagead2.googlesyndication.com https://googleads.g.doubleclick.net https://pay.google.com https://qcdn.screen9.com https://qcnl.tv https://statsapi.screen9.com https://t.contentsquare.net https://t1.voyado.com https://wapi.lipscore.com https://www.google.com https://www.googleadservices.com https://www.googletagmanager.com https://www.pinterest.com https://www.sandbox.paypal.com https://ad.doubleclick.net https://stats.g.doubleclick.net https://modules.ecomid.com https://events.ecomid.com https://api.ecomid.com https://sockjs-eu.pusher.com; frame-src 'self' https://*.adyen.com https://*.adyenpayments.com https://*.bambuser.com https://*.doubleclick.net https://*.klarna.com https://*.klarnacdn.net https://*.kustom.co https://*.usercentrics.eu https://checkout.klarna.com https://ct.pinterest.com https://pay.google.com https://*.kappahl.com https://*.newbie.com https://tr.snapchat.com https://www.googletagmanager.com https://www.sandbox.paypal.com https://modules.ecomid.com https://www.facebook.com; img-src 'self' data: https: blob:; media-src 'self' blob: data: https:;font-src 'self' https: data:; worker-src 'self' blob:; object-src 'none'; base-uri 'self'; frame-ancestors 'none'; report-uri /csp-report; 1 default-src 'self'; script-src 'report-sample' 'self' 'unsafe-inline' https://bot.leadoo.com https://www.googletagmanager.com https://www.google.com https://app.interactiveads.ai https://www.gstatic.com https://www.redditstatic.com https://connect.facebook.net https://snap.licdn.com https://js-eu1.hs-scripts.com https://www.google-analytics.com https://js-eu1.hscollectedforms.net https://js-eu1.hs-analytics.net https://js-eu1.hsadspixel.net https://js-eu1.hs-banner.com https://snap.licdn.com https://sc.lfeeder.com https://www.google-analytics.com data:; style-src 'report-sample' 'self' 'unsafe-inline' https://bot.leadoo.com https://fonts.googleapis.com https://res.leadoo.com; object-src 'none'; base-uri 'self'; connect-src 'self' https://res.leadoo.com https://bot.leadoo.com https://www.google.com https://region1.google-analytics.com https://region1.analytics.google.com https://www.google-analytics.com https://stats.g.doubleclick.net https://ipapi.co https://px.ads.linkedin.com https://anl.leadoo.com https://www.redditstatic.com https://pixel-config.reddit.com https://api-eu1.hubapi.com https://forms-eu1.hscollectedforms.net https://www.facebook.com https://geoip.cookieyes.com https://www.google.pl; font-src 'self' https://res.leadoo.com https://fonts.gstatic.com data:; frame-src 'self' https://app.leadoo.com https://www.google.com https://www.googletagmanager.com https://player.vimeo.com https://www.youtube.com https://bot.leadoo.com https://app.interactiveads.ai; frame-ancestors 'self' https://www.google.com; img-src 'self' https://bot.leadoo.com https://leadoo.com https://res.leadoo.com https://www.redditstatic.com https://www.facebook.com https://px.ads.linkedin.com https://track-eu1.hubspot.com https://www.google-analytics.com https://alb.reddit.com https://tr.lfeeder.com https://www.google.ie https://www.google.pl https://test.leadoo.com https://www.googletagmanager.com https://secure.gravatar.com https://a.slack-edge.com https://forms-eu1.hsforms.com https://connect.facebook.net data:; manifest-src 'self'; media-src 'self' https://leadoo.com; worker-src 'none'; 1 default-src 'self' ; style-src 'self' 'unsafe-inline' optimize.google.com www.googletagmanager.com fonts.googleapis.com *.typekit.net *.yotpo.com *.myfonts.net *.cloudfront.net; font-src 'self' data: optimize.google.com fonts.gstatic.com *.abtasty.com *.dwin1.com *.typekit.net *.livechatinc.com snap.licdn.com *.tiktok.com static.ads-twitter.com ct.pinterest.com *.yotpo.com *.addthis.com *.moatads.com *.curalate.com *.cloudflare.com *.cloudfront.net; img-src 'self' data: *; base-uri 'self' ; form-action *; frame-ancestors 'self' ; script-src 'self' 'unsafe-inline' 'unsafe-eval' optimize.google.com www.googletagmanager.com www.googleanalytics.com www.google-analytics.com www.googleoptimize.com www.googleadservices.com maps.googleapis.com polyfill.io player.vimeo.com connect.facebook.net *.klevu.com api.exponea.com s.pinimg.com intljs.rmtag.com assistjs.skimresources.com googleads.g.doubleclick.net bat.bing.com t.contentsquare.net track.sweetanalytics.com *.yotpo.com snap.licdn.com static.ads-twitter.com *.tiktok.com *.abtasty.com *.dwin1.com *.livechatinc.com *.voyado.com *.ksearchnet.com *.hotjar.com *.veinteractive.com *.mouseflow.com *.sleeknote.com *.stripe.com *.zdassets.com *.trustpilot.com *.clarity.ms *.addthis.com *.addthisedge.com *.moatads.com *.clearpay.co.uk *.amplitude.com *.sagepay.com snapppt.com *.snapppt.com; connect-src 'self' mage.oliverbonas.com *.google-analytics.com *.klevu.com api.exponea.com ct.pinterest.com *.abtasty.com *.tiktok.com *.yotpo.com maps.googleapis.com vimeo.com *.addthis.com *.moatads.com *.dwin1.com *.54proxy.com *.ksearchnet.com *.hotjar.com *.hotjar.io *.zdassets.com *.clarity.ms *.amplitude.com *.sweetanalytics.com snapppt.com *.snapppt.com; frame-src 'self' player.vimeo.com *.fls.doubleclick.net ct.pinterest.com vimeo.com secure.livechatinc.com *.addthis.com *.curalate.com *.54proxy.com *.hotjar.com *.stripe.com *.trustpilot.com *.paypal.com; 1 script-src 'self' 'unsafe-inline' 'unsafe-eval' www.resellerratings.com www.paypal.com cdn.attn.tv s.yimg.com static.klaviyo.com cdn-tp4.mozu.com/27977-44902/ t.contentsquare.net ajax.googleapis.com www.googleadservices.com bat.bing.com www.google.com www.googletagmanager.com live-chat.chatbotize.com d2gh7vqn9p1ieu.cloudfront.net www.res-x.com resources.xg4ken.com polaris.truevaultcdn.com pay.google.com www.paypalobjects.com challenges.cloudflare.com googleads.g.doubleclick.net cdn.sift.com www.google-analytics.com www.mczbf.com acsbapp.com s3-us-west-2.amazonaws.com maps.googleapis.com www.clarity.ms static-tracking.klaviyo.com b-code.liadm.com sv.calendars.com edge1.certona.net services.xg4ken.com connect.facebook.net se.monetate.net cdn-tp4.mozu.com cdn.equalweb.com access.equalweb.com; report-uri https://csp-reporting.cloudflare.com/cdn-cgi/script_monitor/report?m=Yw9VbJM59PrXQEB7Vd.ZQs41qlkeFqIZ.e3bFexG5gE-1770429693-1.0.1.1-UMmtzvTCZjZgVjMstDKeIfg80_5G1pGvtZVzCgexsfWE.EaZJuzobmJDzIdviiySjqrG2lzI0NVK50Z_t9C5rvx7Ju5Beb74Zps6UKksywre1DtI1rlV6L_GulrjYmG0AUfQjpnyJThFtK9OiIox0cqsDVWbMm.TtwIVZX.SChfPxp7sLtUdiDQJ9PE6fY3WOCZbI8MsVJDvrHKfGVZxuw; report-to cf-mkhcejcknbrlkzdo 1 font-src fonts.googleapis.com fonts.gstatic.com *.googleapis.com *.gstatic.com data: oct8necdneu.azureedge.net *.trustedshops.com *.cloudflare.com https://fonts.gstatic.com https://widgets.trustedshops.com *.yotpo.com https://ws.colissimo.fr https://static.lyra.com/static/ data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.adyen.com sis-t.redsys.es:* sis.redsys.es sis-t.sermepa.es:* sis.sermepa.es * *.reskyt.com *.bing.com *.pinterest.com *.creativecdn.com *.tiktok.com *.t.co *.twitter.co *.doubleclick.net t.co *.twitter.com *.byspotify.com *.syndigo.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com *.yotpo.com https://secure.lyra.com/vads-payment/ https://api.lyra.com/api-payment/ https://static.lyra.com/static/ 'self' 'unsafe-inline'; frame-ancestors https://www.salesmanago.pl https://api.clerk.io https://cdn.clerk.io *.googleapis.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.adyen.com *.vimeo.com *.oct8ne.com *.googletagmanager.com * *.cookiebot.com *.reskyt.com *.bing.com *.pinterest.com *.creativecdn.com *.tiktok.com *.t.co *.twitter.co *.doubleclick.net t.co *.twitter.com *.byspotify.com *.syndigo.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com *.yotpo.com https://www.youtube.com https://form.typeform.com *.hipay-tpp.com *.hipay.com https://secure.lyra.com/vads-payment/ https://static.lyra.com/static/ 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.adyen.com maps.googleapis.com maps.gstatic.com *.gstatic.com *.googleapis.com https://images.unsplash.com *.google.com *.google.es *.google.com.br *.googletagmanager.com *.google-analytics.com *.g.doubleclick.net oct8necdneu.azureedge.net *.trustedshops.com *.bynder.com *.visualwebsiteoptimizer.com *.amazonaws.com *.atida.com *.dosfarma.com *.facebook.com *.zenaps.com *.awin1.com *.reskyt.com *.bing.com *.pinterest.com *.creativecdn.com *.tiktok.com *.t.co t.co *.twitter.co *.twitter.com *.cloudfront.net *.doubleclick.net *.byspotify.com *.cookiebot.com *.googlesyndication.com *.syndigo.com *.assets.efarma.com *.mifarma.co.uk *.adscale.de *.usercentrics.eu cm.g.doubleclick.net r.casalemedia.com id5-sync.com ad.360yield.com contextual.media.net exchange.mediavine.com jadserve.postrelease.com simage2.pubmatic.com *.pubmatic.com pixel.rubiconproject.com *.rubiconproject.com rtb-csync.smartadserver.com *.smartadserver.com criteo-sync.teads.tv *.teads.tv criteo-partners.tremorhub.com *.tremorhub.com eb2.3lift.com *.3lift.com ad.yieldlab.net *.yieldlab.net sync.1rx.io *.1rx.io *.criteo.com *.criteo.net *.consentcdn.cookiebot.eu *.atida.fr *.empathy.co openstreetmap.org www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com https://cdn.clerk.io *.ggpht https://widgets.trustedshops.com https://widgets-qa.trustedshops.com *.yotpo.com https://maps.googleapis.com https://maps.gstatic.com https://ws.colissimo.fr https://*.tile.openstreetmap.fr https://*.onyourmap.com https://google.fr https://secure.lyra.com/static/latest/images/type-carte/ https://static.lyra.com/static/ https://secure.lyra.com/vads-payment/ data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.adyen.com polyfill.io maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.googleapis.com *.gstatic.com https://maps.googleapis.com https://cdn.jsdelivr.net/npm/@ryangjchandler/spruce@2.x.x/dist/spruce.umd.js *.google.com *.google.es *.google.com.br *.googletagmanager.com *.google-analytics.com *.g.doubleclick.net *.cookiebot.com *.oct8ne.com *.trustedshops.com *.clerk.io *.cloudfront.net *.zdassets.com *.zendesk.com *.api.smooch.io *.visualwebsiteoptimizer.com *.connectif.cloud *.atida.com *.dosfarma.com *.newrelic.com *.nr-data.net *.dwin1.com *.pinimg.com *.ads-twitter.com *.tiktok.com *.kk-resources.com *.bing.com *.creativecdn.com *.facebook.net *.googlesyndication.com *.awin1.com *.zenaps.com *.facebook.com *.wepowerconnections.com *.sciencebehindecommerce.com *.reskyt.com *.pinterest.com *.t.co *.twitter.co *.doubleclick.net t.co *.twitter.com *.byspotify.com *.syndigo.com *.topsort.workers.dev *.cookiebot.eu *.clarity.ms *.roeyecdn.com *.cdn-apple.com *.lyra.com *.skeepers.io *.criteo.com static.ads-twitter.com connect.facebook.net tags.creativecdn.com *.consentcdn.cookiebot.eu *.dynamic.criteo.com *.static.cloudflareinsights.com static.cloudflareinsights.com *.empathy.co js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com cdn.scalapay.com b2c-cdn.scalapay.com https://api.clerk.io https://cdn.clerk.io https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.yotpo.com https://www.google.com https://www.gstatic.com https://ws.colissimo.fr https://api.mapbox.com https://*.typeform.com *.plugins.emarsys.net *.scarabresearch.com *.hipay-tpp.com *.hipay.com mpsnare.iesnare.com https://api.lyra.com/api-payment/ https://static.lyra.com/static/ 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.trustedshops.com *.cloudflare.com *.googletagmanager.com *.reskyt.com *.bing.com *.pinterest.com *.creativecdn.com *.tiktok.com *.t.co *.twitter.co *.doubleclick.net t.co *.twitter.com *.byspotify.com *.syndigo.com *.consentcdn.cookiebot.eu *.empathy.co unsafe-inline assets.braintreegateway.com https://api.clerk.io https://cdn.clerk.io https://fonts.googleapis.com https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.yotpo.com https://ws.colissimo.fr https://api.mapbox.com https://*.typeform.com *.hipay.com https://static.lyra.com/static/ 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com data: mpsnare.iesnare.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adyen.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.googleapis.com https://maps.googleapis.com https://player.vimeo.com *.google.com *.google.es *.google.com.br *.googletagmanager.com *.google-analytics.com *.g.doubleclick.net *.oct8ne.com *.google.com/pay *.api.smooch.io *.zdassets.com *.zendesk.com *.connectif.cloud *.atida.com *.dosfarma.com *.algolia.io *.cookiebot.com *.nr-data.net google.com *.googlesyndication.com *.awin1.com *.zenaps.com *.facebook.com *.wepowerconnections.com *.sciencebehindecommerce.com *.reskyt.com *.bing.com *.pinterest.com *.creativecdn.com *.tiktok.com *.t.co *.twitter.co *.doubleclick.net t.co *.twitter.com *.byspotify.com *.syndigo.com *.topsort.workers.dev *.spotify.com *.criteo.com *.criteo.net ct.pinterest.com *.clarity.ms ad.doubleclick.net googleads.g.doubleclick.net consent.cookiebot.eu *.cookiebot.eu *.consentcdn.cookiebot.eu *.dynamic.criteo.com *.amazonaws.com pay.google.com *.pay.google.com *.cdn.scalapay.com cdn.scalapay.com pixels.spotify.com *.empathy.co api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.trustedshops.com *.etrusted.com https://integrations.etrusted.site *.yotpo.com https://ws.colissimo.fr https://nominatim.openstreetmap.org https://*.onyourmap.com https://*.mapbox.com *.scarabresearch.com *.eservice.emarsys.net *.hipay-tpp.com *.hipay.com wss://mpsnare.iesnare.com https://secure.lyra.com/vads-payment/ https://api.lyra.com/api-payment/ 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src https://secure.lyra.com/vads-payment/ https://api.lyra.com/api-payment/ https://static.lyra.com/static/ 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 script-src 'strict-dynamic' 'unsafe-inline' https: 'nonce-3e84e100726bdf19e8f1bf056e7e69e4';object-src 'none';base-uri 'none';frame-src 'self' https://paywall.imoje.pl https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://wchat.freshchat.com https://*.webpush.freshchat.com https://www.youtube.com https://youtube.com https://youtu.be https://www.youtube-nocookie.com https://youtube-nocookie.com https://www.facebook.com https://open.spotify.com/embed/ https://podcasters.spotify.com/pod/show/ https://player.vimeo.com/video/ https://td.doubleclick.net https://platform.twitter.com/ https://www.googletagmanager.com/;report-uri https://o160244.ingest.sentry.io/api/1798165/security/?sentry_key=22e91a43970d40cdae6153ad3feb9951;report-to csp-endpoint 1 font-src fonts.gstatic.com use.typekit.net https://*.gstatic.com *.fontawesome.com *.oct8ne.com https://cdnjs.cloudflare.com *.gstatic.com https://sandbox.sequracdn.com/ *.reskyt.com/ https://cdn.doofinder.com/* data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.adyen.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://plumrocket.com https://www.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.googletagmanager.com *.adyen.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com *.oct8ne.com https://plumrocket.com sandbox.sequracdn.com live.sequracdn.com sandbox.sequrapi.com live.sequrapi.com *.trustpilot.com *.paypalobjects.com/ *.flyde.io/ *.redintelligence.net/ *.reskyt.com/ *.quantummetric.com/ *.sequrapi.com/ *.klarnacdn.net/ *.doubleclick.net/ *.google.com/ https://www.facebook.com *.amazonaws.com/* https://myadsplatform-prod.s3.eu-central-1.amazonaws.com/ https://static.criteo.net https://gum.criteo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net p.typekit.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com validator.swagger.io *.adyen.com https://*.gstatic.com cdn.doofinder.com magefan.com cm.magefan.com *.disqus.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.oct8ne.com sandbox.sequracdn.com live.sequracdn.com sandbox.sequrapi.com live.sequrapi.com *.padelnuestro.com https://www.google.ie *.googleapis.com *.gstatic.com https://www.google.es/ads/ https://www.googletagmanager.com/ https://www.emjcd.com/ https://cj.dotomi.com/ *.cloudfront.net *.bing.com/ *.adform.net/ *.facebook.com/ *.reskyt.com/ *.connectif.cloud/ *.doubleclick.net/ *.google.com/ *.placeholder.com https://grwapi.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com amcglobal.sc.omtrdc.net commerce.adobe.net use.typekit.net www.sandbox.paypal.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-ds.com www.googletagmanager.com *.adyen.com cdn.doofinder.com *.disqus.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.oct8ne.com https://cdnjs.cloudflare.com sandbox.sequracdn.com live.sequracdn.com sandbox.sequrapi.com live.sequrapi.com *.trustpilot.com https://sdk.privacy-center.org https://js-agent.newrelic.com https://bam.nr-data.net *.googleapis.com *.gstatic.com https://www.mczbf.com/ https://cdn.connectif.cloud/ *.cloudfront.net https://commerce.adobedtm.com/ *.bing.com/ *.adform.net/ *.jsdelivr.net/ *.flyde.io/ *.facebook.net/ *.tiktok.com/ *.klarnacdn.net/ *.reskyt.com/ *.quantummetric.com/ blob *.klarna.com/ *.sequrapi.com/ *.clarity.ms/ *.google.com/ https://grwapi.net https://unpkg.com https://eu1-config.doofinder.com/* *.doofinder.com/* https://eu1-config.doofinder.com/2.x/d0f0ef47-8a08-4c9c-9f1f-3c43a3aa757c.js *.usermaven.com/* *.creativecdn.com/* *.woopra.com/* https://static.woopra.com/ https://www.woopra.com/ https://tags.creativecdn.com/ https://ams.creativecdn.com/ https://f.creativecdn.com/ https://sync.outbrain.com/ 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://fonts.googleapis.com/ *.doofinder.com *.fontawesome.com https://fonts.googleapis.com https://cdnjs.cloudflare.com *.trustpilot.com *.googletagmanager.com/ *.reskyt.com/ *.quantummetric.com/ *.googleapis.com https://grwapi.net *.doofinder.com/* https://cdn.doofinder.com/* https://cdn.doofinder.com/livelayer/1/css/2/common.css 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io qa-api.magedevteam.com *.sentry.io *.adyen.com *.doofinder.com wss://*.doofinder.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.oct8ne.com sandbox.sequracdn.com live.sequracdn.com sandbox.sequrapi.com live.sequrapi.com https://pre.wayletlabs.com/* https://pro.waylet.es/* https://region1.google-analytics.com https://api.privacy-center.org *.doubleclick.net https://bam.nr-data.net *.googleapis.com *.gstatic.com *.google.com https://www.mczbf.com/ *.connectif.cloud/ *.flyde.io/ *.tiktok.com/ *.facebook.com/ *.reskyt.com/ *.quantummetric.com/ *.googlesyndication.com/ *.klarna.com/ *.klarnacdn.net/ *.clarity.ms https://grwapi.net https://track.adform.net https://google.com *.woopra.com/ 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 object-src 'none'; script-src 'self' 'unsafe-inline' 'unsafe-eval' adform.net *.adform.net betano.com *.betano.com betano.cz *.betano.cz betgenius.com *.betgenius.com cloudflare.com *.cloudflare.com cookielaw.org *.cookielaw.org creativecdn.com *.creativecdn.com facebook.net *.facebook.net fullstory.com *.fullstory.com gmlinteractive.com *.gmlinteractive.com googletagmanager.com *.googletagmanager.com kaizengaming.com *.kaizengaming.com kameleoon.eu *.kameleoon.eu optimove.net *.optimove.net sportradar.com *.sportradar.com cloudflareinsights.com *.cloudflareinsights.com app.delivery *.app.delivery google-analytics.com *.google-analytics.com lgrckt-in.com *.lgrckt-in.com tostarsbuilding.com *.tostarsbuilding.com; report-uri https://csp-reporting.cloudflare.com/cdn-cgi/script_monitor/report?m=So_Iowh1AF7P4PaJI7kCCcI7ZdoI6_s91iYEMu6QmU4-1770435040-1.0.1.1-sL15F6gWSpk9Sgw30NZw8jz4Z2.HV1YmnFYdDMK3xZB4K4sg_5hOBh5pu5oTdApZgRv.lgHK829f25diNtvNgRUfFo8.luEiwyGPHfLXbHe5eJ2C_7h6qso9HdlxyibrntSj_1e_pmTq_KYLJ690ccyl5FOagktjVVxa.UgblAaQ04r_EUO1ng75cHxwqVY97mRPLiZBjfZNN3QCrSUHKQ; report-to cf-ckqnkomzifsgpkza 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://connect.facebook.net https://maps.googleapis.com https://s3-eu-west-1.amazonaws.com https://script.hotjar.com https://static.hotjar.com https://static.inteliwise.com https://unpkg.com https://www.google-analytics.com https://www.google.com https://www.googletagmanager.com https://www.gstatic.com https://www.recaptcha.net https://*.recaptcha.net https://*.google.com https://*.doubleclick.net https://*.googleusercontent.com https://*.youtube.com https://*.facebook.net https://*.hotjar.com https://*.inteliwise.com https://bat.bing.com https://pixel.wp.pl https://www.clarity.ms https://scripts.clarity.ms https://*.clarity.ms https://analytics.tiktok.com https://static.ads-twitter.com https://www.googleadservices.com https://googleads.g.doubleclick.net https://microsoft.com https://perfo.salestube.pl https://sandbox.przelewy24.pl https://browser-update.org https://tenantpluginapiserver1.eloacc.warta.pl https://public-api-sessionserver1.eloacc.warta.pl; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://s3-eu-west-1.amazonaws.com https://*.hotjar.com https://*.inteliwise.com https://maxcdn.bootstrapcdn.com https://www.googletagmanager.com https://www.gstatic.com https://tenantpluginapiserver1.eloacc.warta.pl https://public-api-sessionserver1.eloacc.warta.pl; object-src 'none'; base-uri 'self'; frame-ancestors 'self'; connect-src 'self' https://inteliwise-eu.s3.amazonaws.com https://maps.googleapis.com https://s3-eu-west-1.amazonaws.com https://stats.g.doubleclick.net https://www.google-analytics.com https://www.googletagmanager.com https://www.google.com https://www.recaptcha.net https://*.hotjar.com https://*.inteliwise.com https://pixel.wp.pl https://rail-publisher.app.inteliwi.se https://ad.doubleclick.net https://*.clarity.ms wss://ws.hotjar.com https://content.hotjar.io https://metrics.hotjar.io https://www.facebook.com https://analytics.tiktok.com https://analytics-ipv6.tiktokw.us https://bat.bing.com https://unpkg.com https://vc.hotjar.io https://googleads.g.doubleclick.net https://www.googleadservices.com https://microsoft.com https://perfo.salestube.pl https://sandbox.przelewy24.pl https://tenantpluginapiserver1.eloacc.warta.pl https://public-api-sessionserver1.eloacc.warta.pl; font-src 'self' data: https://fonts.gstatic.com https://maxcdn.bootstrapcdn.com https://tenantpluginapiserver1.eloacc.warta.pl https://public-api-sessionserver1.eloacc.warta.pl; frame-src 'self' https://10798259.fls.doubleclick.net https://9049979.fls.doubleclick.net https://s3-eu-west-1.amazonaws.com https://vars.hotjar.com https://www.google.com https://www.recaptcha.net https://*.google.com https://*.hotjar.com https://*.inteliwise.com https://www.googletagmanager.com https://td.doubleclick.net https://*.youtube.com https://*.vimeo.com https://player.vimeo.com https://www.youtube.com https://tenantpluginapiserver1.eloacc.warta.pl; img-src 'self' data: https://maps.googleapis.com https://maps.gstatic.com https://www.google-analytics.com https://www.google.com https://www.google.pl https://*.hotjar.com https://*.inteliwise.com https://pixel.wp.pl https://ad.doubleclick.net https://bat.bing.com https://*.clarity.ms https://www.googletagmanager.com https://www.facebook.com https://connect.facebook.net https://c.bing.com https://t.co https://analytics.twitter.com https://fonts.gstatic.com https://*.ytimg.com https://*.vimeocdn.com https://tenantpluginapiserver1.eloacc.warta.pl https://public-api-sessionserver1.eloacc.warta.pl; manifest-src 'self'; media-src 'self' https://tenantpluginapiserver1.eloacc.warta.pl https://public-api-sessionserver1.eloacc.warta.pl; worker-src 'self' blob:; 1 default-src *.bellroy.com 'self' https: data:; base-uri 'self'; connect-src *.bellroy.com https: wss: www.google.com api.tangiblee.com; font-src *.bellroy.com 'self' data: https: themes.googleusercontent.com fonts.googleapis.com fonts.gstatic.com; frame-src *.bellroy.com 'self' https: data: ms-appx-web: www.facebook.com; img-src *.bellroy.com https: data: blob: android-webview-video-poster:; media-src *.bellroy.com https: data: blob:; script-src *.bellroy.com 'self' https: 'unsafe-inline' 'unsafe-eval' data: opera: google.com *.visa.com d1fc8wv8zag5ca.cloudfront.net; style-src *.bellroy.com https: 'unsafe-inline' data:; worker-src 'self' blob:; child-src 'self' blob:; block-all-mixed-content; report-uri /csp_reports 1 default-src 'self' image.spreadshirtmedia.net ; script-src 'self' 'unsafe-inline' 'unsafe-eval' data: https: *.go-mpulse.net apis.google.com assets.adobedtm.com *.cloudfront.net nxtck.com ssl.gstatic.com ws.sessioncam.com *.spreadshirt.net *.spreadshirt.com www.google-analytics.com www.google.com googleads.g.doubleclick.net connect.facebook.net www.googleadservices.com adtm.spreadshirts.net *.spreadshirt.net ; img-src 'self' data: https: image.spreadshirtmedia.net *.gstatic.com rtb-csync.smartadserver.com pixel.rubiconproject.com pixel.advertising.com dsum-sec.casalemedia.com cotads.adscale.de www.google-analytics.com eu-u.openx.net ih.adscale.de *.akstat.io www.facebook.com dsum-sec.casalemedia.com ad.yieldlab.net secure.adnxs.com mapping.nxtck.com stats.g.doubleclick.net www.google.com www.google.de cm.g.doubleclick.net ads.yahoo.com sync.ligadx.com eb2.3lift.com s.sspqns.com x.bidswitch.net image2.pubmatic.com sync.outbrain.com nxtck.com *.google-analytics.com *.analytics.google.com *.zdassets.com sanalytics.spreadshirt.net *.spreadshirt.net ; connect-src 'self' https: *.spreadshirt.net *.spreadshirt.com www.google-analytics.com www.google.com *.go-mpulse.net *.akstat.io/ dpm.demdex.net *.google-analytics.com *.analytics.google.com wss://*.zendesk.com *.spreadshirt.net ; font-src 'self' https: data: *.spreadshirt.net ; style-src 'self' data: 'unsafe-inline' https: *.spreadshirt.net ; object-src 'none' ; media-src image.spreadshirtmedia.net ; frame-src 'self' https: www.google.com accounts.google.com *.spreadshirt.net ; report-uri https://csp.spreadshirts.net/csp/reportOnly ; 1 default-src blob: https://*.mhcache.com;font-src 'self' https://*.myheritage.com https://*.mhcache.com https://fonts.gstatic.com;frame-src 'self' https://*.mhcache.com https://portal.allyable.com https://mh-site-files-5c53d6a9947c.s3.amazonaws.com https://myheritage-container.com https://www.myheritage-partners.com https://www.myheritage.com https://*.mk-sense.com https://player.vimeo.com https://*.facebook.com https://*.googleapis.com https://*.google.com https://tpc.googlesyndication.com https://*.doubleclick.net https://accounts.google.com/gsi/;script-src https://accounts.google.com/gsi/client https://www.datadoghq-browser-agent.com https://*.googleapis.com https://appleid.cdn-apple.com *.myheritage.es https://www.myheritage.es 'unsafe-eval' 'nonce-004a17e6b6bd6388feda9483d5d468de' 'strict-dynamic';style-src data: blob: 'unsafe-inline' 'self' https://*.myheritage.com https://*.mhcache.com https://fonts.googleapis.com https://accounts.google.com/gsi/style;connect-src data: 'self' https://*.myheritage.com https://portal.allyable.com https://*.mhcache.com https://adservice.google.com https://*.logs.datadoghq.com https://*.browser-intake-datadoghq.com https://browser-intake-datadoghq.com https://sentry.io https://*.bing.com https://*.facebook.com https://*.doubleclick.net https://*.mk-sense.com https://*.filae.com https://accounts.google.com/gsi/ https://www.google.com/pagead/landing https://*.googleapis.com https://maps.googleapis.com/maps/api/mapsjs/gen_204 https://translate.googleapis.com https://www.google.com/ccm/collect https://cdn.builder.io *.myheritage.es;media-src 'self' https://*.myheritage.com https://*.mhcache.com;frame-ancestors 'self' https://builder.io;img-src * data:;object-src 'none';base-uri 'self' https://*.mhcache.com;report-uri /FP/API/ContentSecurityPolicy/report-violation.php?report_mode=report&canonical_page_id=/company/home/ 1 object-src 'none';base-uri 'self';script-src 'nonce-sNNngw5ntB6XJ2bcYwu2nQ' 'strict-dynamic' 'report-sample' 'unsafe-eval' 'unsafe-inline' https: http:;report-uri https://csp.withgoogle.com/csp/gws/other-hp 1 object-src 'none'; script-src 'self' 'unsafe-inline' 'unsafe-eval' adform.net *.adform.net betano.com *.betano.com betano.ng *.betano.ng cloudflare.com *.cloudflare.com cookielaw.org *.cookielaw.org facebook.net *.facebook.net fullstory.com *.fullstory.com gmlinteractive.com *.gmlinteractive.com googletagmanager.com *.googletagmanager.com kaizengaming.com *.kaizengaming.com kameleoon.io *.kameleoon.io optimove.net *.optimove.net sportradar.com *.sportradar.com sportradarserving.com *.sportradarserving.com cloudflareinsights.com *.cloudflareinsights.com ads-twitter.com *.ads-twitter.com app.delivery *.app.delivery lgrckt-in.com *.lgrckt-in.com tostarsbuilding.com *.tostarsbuilding.com; report-uri https://csp-reporting.cloudflare.com/cdn-cgi/script_monitor/report?m=RyHtejqV6dsbiUJOBdB0yS5CAN_jKU8y7g9DYOikm6s-1770433105-1.0.1.1-Z.pMjWb9OlQZe.Toonr_jiFSF78NsGgKK10fUw3h_foaKtqRDQ7w6thdQ12X0YzkA_p1f4TdynHdThwppP0.101Y28peOI_knckKBVGBEl.tciwSsCd7xanzC9_fn5pBPtzLumwBw7OXt.X9jrhtXOnMNXhMF7_xXDu_pKhGtooDYhgkaMC2Fszd_TySE1jYhBzUKXHf4G4zS5lea.snlg; report-to cf-suvszgsgvrjoxywc 1 default-src 'self' https: 'unsafe-inline' data: 'unsafe-eval'; report-uri https://servix.idnes.cz/log/csp-report.aspx?w=emimino 1 frame-ancestors 'self' nearpod.com *.nearpod.com *.nearpod.us; report-uri https://nearpod.report-uri.com/r/t/csp/reportOnly 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com cdn.jsdelivr.net cdn.almapay.com https://fonts.gstatic.com https://ws.colissimo.fr *.sagepay.com *.opayo.eu.elavon.com https://cdnjs.cloudflare.com 'self' data: static.sensefuel.live data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.sips-services.com *.sagepay.com *.opayo.eu.elavon.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com https://www.youtube.com *.youtube-nocookie.com bid.g.doubleclick.net www.googletagmanager.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.getalma.eu *.almapay.com/ *.stripe.com/ *.checkout.com/ *.adyen.com/ *.truefitcorp.com *.weltpixel.com https://form.typeform.com *.sagepay.com *.opayo.eu.elavon.com *.google.com/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.ftcdn.net *.behance.net *.paypal.com *.typekit.net *.gstatic.com *.afd.co.uk t.powerreviews.com assets-manager.abtasty.com https://maps.googleapis.com https://maps.gstatic.com https://ws.colissimo.fr https://*.tile.openstreetmap.fr https://*.onyourmap.com https://google.fr https://www.magezon.com *.sagepay.com *.opayo.eu.elavon.com ebizmarts-website.s3.amazonaws.com *.openstreetmap.org www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.hsforms.net *.hsforms.com 'self' data: data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.afd.co.uk cdn.jsdelivr.net js-agent.newrelic.com party.spockee.io app.ekoo.co ui.powerreviews.com *.truefitcorp.com https://maps.googleapis.com https://www.google.com https://www.gstatic.com https://ws.colissimo.fr https://api.mapbox.com https://*.typeform.com widget.proximis.com *.sagepay.com *.opayo.eu.elavon.com https://cdnjs.cloudflare.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com songbird.cardinalcommerce.com *.hsforms.net *.hsforms.com *.gstatic.com https://www.googletagmanager.com tagmanager.google.com tag.search.sensefuel.live pdata.damart.fr try.abtasty.com 'self' 'unsafe-eval' 'nonce-NjVuYjR2NnlrZ21kb2RuNWt2aTloZjMzc2tpeWNneGc=' 'sha256-W5akSSK6LD5BjIlNICMcXaUObQSRAaj6bs7JHADURBA=' 'sha256-3qVqeAdyxxTdPkkRzqapjGkAUYLahxSrB7Mdup+GPQ0=' 'sha256-2rvfFrggTCtyF5WOiTri1gDS8Boibj4Njn0e+VCBmDI=' 'sha256-p8MCfMHqrovsjRYU9z0bU17dd0z81k/fVbGrtBBiM9g=' 'sha256-0pk2s4oXwBELlC6IBVb3nNaM2PjfjwI2N6OGIX5lx8Y=' 'sha256-nkEZknO0IxNxY/CkTMBhjNhwPvglpYumjx31B4fjkY8='; style-src *.adobe.com fonts.googleapis.com cdn.jsdelivr.net ui.powerreviews.com https://fonts.googleapis.com https://ws.colissimo.fr https://api.mapbox.com https://*.typeform.com *.sagepay.com *.opayo.eu.elavon.com https://cdnjs.cloudflare.com assets.braintreegateway.com *.googleapis.com *.gstatic.com tagmanager.google.com tag.search.sensefuel.live 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net vimeo.com www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.afd.co.uk *.getalma.eu *.almapay.com api.spockee.io backoffice-api.spockee.io ui.powerreviews.com display.powerreviews.com app.ekoo.co maps.googleapis.com https://ws.colissimo.fr https://maps.googleapis.com https://nominatim.openstreetmap.org https://*.onyourmap.com https://*.mapbox.com *.sagepay.com *.opayo.eu.elavon.com *.openstreetmap.org api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com c.search.sensefuel.live 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'none'; report-uri /next-external/log/csp/violations; report-to csp-violations; connect-src 'self' wss://www.nordnet.fi https://www.googletagmanager.com https://analytics.nordnet.fi https://cdn.prod.nntech.io https://files.nordnet.fi https://api.prod.nntech.io https://api.test.nntech.io https://experimentation.public.prod.nntech.io https://www.google.com https://storage.googleapis.com https://www.recaptcha.net https://nordnettest.boost.ai; font-src 'self' https://cdn.prod.nntech.io https://files.nordnet.fi; frame-src 'self' https://analytics.nordnet.fi https://10961666.fls.doubleclick.net https://www.youtube.com https://www.youtube-nocookie.com https://player.vimeo.com https://w.soundcloud.com https://embed.acast.com https://link.tink.com https://www.tv2.no https://checkout.trustly.com https://www.recaptcha.net https://www.google.com https://t.email.nordnet.fi https://dashboard.fundrella.com; img-src 'self' https://www.googletagmanager.com https://analytics.nordnet.fi https://cdn.prod.nntech.io https://files.nordnet.fi data: blob: https://cdn.tink.se https://images.ctfassets.net https://i.vimeocdn.com https://img.youtube.com https://www.recaptcha.net https://blogi.nordnet.fi https://boost-files-general-eu-west-1-test.s3-eu-west-1.amazonaws.com/files/NORDNETTEST/d929a8d5-9d88-426e-b412-3ccf7923fac3; manifest-src 'self'; media-src https://cdn.prod.nntech.io https://files.nordnet.fi https://videos.ctfassets.net; object-src 'self'; script-src 'self' 'nonce-4428eb9c-8072-4000-9e33-ff99e1730f1e' https://analytics.nordnet.fi https://cdn.prod.nntech.io https://files.nordnet.fi https://www.recaptcha.net https://nordnettest.boost.ai https://www.google.com; script-src-attr 'none'; style-src 'unsafe-inline' 'self' https://cdn.prod.nntech.io https://files.nordnet.fi; worker-src 'none'; base-uri 'none'; form-action 'self' https://pvu.nets.no https://pvu.avtalegiro.no https://online.alandsbanken.fi https://verkkopankki.danskebank.fi https://verkkomaksu.handelsbanken.fi https://epmt.nordea.fi https://identify.nordea.com https://verkkomaksu.poppankki.fi https://verkkomaksu.saastopankki.fi https://online.s-pankki.fi https://auth.aktia.fi https://kirjaudu.aktia.fi https://ebank.aktia.fi; frame-ancestors 'self' https://app.contentful.com; 1 font-src 'self' data:; script-src-attr 'self'; script-src-elem 'self' 'unsafe-inline' https://www.googletagmanager.com https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ cdnjs.cloudflare.com https://cdn.datatables.net https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com https://www.google.com stackpath.bootstrapcdn.com unpkg.com; style-src 'self' cdn.jsdelivr.net cdnjs.cloudflare.com https://cdn.datatables.net https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://live-instinet-drupal.pantheonsite.io https://unpkg.com stackpath.bootstrapcdn.com; style-src-attr 'self' 'unsafe-inline'; frame-ancestors 'self' 1 font-src fonts.gstatic.com use.typekit.net *.fontawesome.com maxcdn.bootstrapcdn.com *.gls.com *.szybkapaczka.pl *.gls-poland.com/ https://*.easypack24.net https://fonts.bunny.net fonts.googleapis.com https://*.typekit.net https://font.static.useinsider.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com https://*.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com https://www.googletagmanager.com/ secure.payu.com merch-prod.snd.payu.com https://parcelshop.dhl.pl https://pudofinder.dpd.com.pl https://widget.packeta.com https://backup.widget.packeta.com *.szybkapaczka.pl *.gls-poland.com/ https://*.dpd.com.pl/ https://*.dpd.cz/ https://consentcdn.cookiebot.com https://*.livechatinc.com https://secure-fra.livechatinc.com https://creativecdn.com https://martes.api.useinsider.com https://ams.creativecdn.com https://*.doubleclick.net https://*.criteo.com https://martes.api.useinsider.com/ https://*.criteo.net https://www.facebook.com https://*.avin1.com https://*.packeta.com https://api.dpd.cz/ 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ static.payu.com https://*.sysadvisors.pl *.szybkapaczka.pl *.openstreetmap.org *.gls-poland.com/ *.gls-poland.com.pl/ https://*.easypack24.net https://*.inpost.pl https://trustmate.io magefan.com cm.magefan.com https://firebasestorage.googleapis.com quickchart.io img.youtube.com https://fitanu.com https://*.paynow.pl https://*.cookiebot.com https://*.glami.pl https://*.bing.com https://google.pl https://*.useinsider.com https://*.google.pl https://log.api.useinsider.com https://*.adnxs.com https://cm.g.doubleclick.net https://*.creativecdn.com https://*.udmserve.net https://*.rubiconproject.com https://*.wp.pl https://*.teads.tv https://*.taboola.com https://*.adscale.de https://*.3lift.com https://*.outbrain.com https://*.smartadserver.com https://*.yieldmo.com https://*.openx.net https://*.360yield.com https://*.33across.com https://*.seedtag.com https://sync.go.sonobi.com https://*.nexx360.io https://*.clarity.ms https://*.casalemedia.com https://*.lijit.com https://*.omnitagjs.com https://*.media.net https://*.loopme.me https://onetag-sys.com https://*.mgid.com https://*.ad.smaato.net https://*.rmp.rakuten.com https://*.visx.net http://*.credit-agricole.pl https://*.facebook.com https://*.bidswitch.net https://*.zdusercontent.com https://*.criteo.com https://*.1rx.io https://*.emxdgt.com https://*.yieldlab.net https://*.tremorhub.com https://*.sharethrough.com https://*.pubmatic.com https://*.postrelease.com https://*.mediavine.com https://*.ivitrack.com https://id5-sync.com https://*.zendesk.com https://*.dmxleo.com https://*.facebook.net https://*.avin1.com https://*.unrulymedia.com https://sklepmartes.pl https://*.packeta.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net http://www.googletagmanager.com/ https://www.googletagmanager.com/ secure.payu.com secure.snd.payu.com https://*.sysadvisors.pl https://*.googlesyndication.com https://pagead2.googlesyndication.com https://*.mapbox.com https://widget.packeta.com https://backup.widget.packeta.com *.szybkapaczka.pl *.openstreetmap.org *.gls-poland.com/ *.snrbox.com https://unpkg.com https://cdn.jsdelivr.net https://*.easypack24.net https://trustmate.io https://cz.im9.cz https://sk.im9.cz *.avada.io *.shopify.com https://*.paynow.pl https://*.intum.com https://*.demoup.com https://cdn.intum.com https://*.cookiebot.com https://*.clarity.ms https://*.azureedge.net https://*.livechatinc.com https://*.wp.pl https://*.dmdi.pl https://*.savecart.pl https://*.goadservices.com https://*.bing.com https://*.dwin1.com https://glamipixel.com https://trafficscanner.pl https://*.cloudflareinsights.com https://martes.api.useinsider.com https://tags.creativecdn.com https://script.ar-mtch1.com https://eitri.api.useinsider.com https://*.allekurier.pl https://*.luigisbox.tech https://*.criteo.com https://*.facebook.net https://*.tiktok.com https://*.avin1.com https://*.martessport.eu https://*.packeta.com https://*.sklepmartes.pl https://cdn.thulium.com/ 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com maxcdn.bootstrapcdn.com https://*.sysadvisors.pl https://*.mapbox.com *.szybkapaczka.pl *.gls-poland.com/ *.snrcdn.net https://cdn.jsdelivr.net https://*.easypack24.net https://trustmate.io https://fonts.bunny.net fonts.gstatic.com https://assets.api.useinsider.com https://*.luigisbox.tech https://*.sklepmartes.pl 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ *.szybkapaczka.pl *.gls-poland.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.adobe.io performance.typekit.net *.sentry.io http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ secure.payu.com merch-prod.snd.payu.com https://*.sysadvisors.pl https://api.mapbox.com https://events.mapbox.com https://widget.packeta.com https://backup.widget.packeta.com *.szybkapaczka.pl *.openstreetmap.org *.gls-poland.com/ *.snrbox.com https://*.easypack24.net https://trustmate.io https://get.geojs.io *.avada.io https://*.demoup.com https://mycliplister.com https://*.google-analytics.com https://*.livechatinc.com https://googleads.g.doubleclick.net https://ams.creativecdn.com https://lt.ar-mtch1.com https://*.cookiebot.com https://*.useinsider.com https://*.clarity.ms https://*.bing.com https://*.inpost.pl https://*.luigisbox.tech https://*.tiktok.com https://*.sklepmartes.pl https://*.criteo.com https://*.keys.adm-services.goog https://*.facebook.com https://*.googlesyndication.com https://*.packeta.com https://pixel.wp.pl/ https://cdn.thulium.com/ 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' d1re4mvb3lawey.cloudfront.net *.bibliu.co *.bibliu.com; style-src 'self'; img-src 'self' d1re4mvb3lawey.cloudfront.net *.bibliu.co *.bibliu.com; font-src 'self' d1re4mvb3lawey.cloudfront.net *.bibliu.co *.bibliu.com; frame-src 'self' *.bibliu.co *.bibliu.com; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.cloudflare.com *.trustedshops.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com 'self' 'unsafe-inline'; frame-ancestors *.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com www.google.com youtu.be *.vimeo.com *.addthis.com https://www.googletagmanager.com/ vpos.infonet.com.py checkout.dinelco.com.py:4447 checkout.dinelco.com.py https://pay.standard.com.py https://vpos.infonet.com.py:8888 https://vpos.infonet.com.py https://dev-sgwf-01.bepsa.com.py https://www.pagopar.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.cloudflare.com https://cdn.klarna.com https://s.ytimg.com *.usercentrics.eu blob: *.magebig.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ magefan.com cm.magefan.com *.disqus.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com commerce-payments-sdk.adobe.io s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.cloudflare.com *.google-analytics.com *.gstatic.com *.googleadservices.com *.googleapis.com *.trustedshops.com *.usercentrics.eu *.addthis.com *.addthisedge.com *.moatads.com www.paypal.com www.paypalobjects.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ *.disqus.com vpos.infonet.com.py cdn.infonet.com.py checkout.dinelco.com.py:4447 checkout.dinelco.com.py https://vpos.infonet.com.py:8888 https://vpos.infonet.com.py https://dev-sgwf-01.bepsa.com.py https://pay.standard.com.py https://www.pagopar.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.cloudflare.com *.typekit.net *.trustedshops.com *.usercentrics.eu vpos.infonet.com.py 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.cloudflare.com *.googleapis.com https://ipinfo.io *.facebook.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ vpos.infonet.com.py checkout.dinelco.com.py:4447 checkout.dinelco.com.py https://pay.standard.com.py 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 worker-src blob:; font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com https://www.gstatic.com maxcdn.bootstrapcdn.com https://fonts.gstatic.com https://widgets.trustedshops.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.adyen.com pay.google.com payments-eu.amazon.com *.amazon.de *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com *.adyen.com pay.google.com https://*.google.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com c.paypal.com checkout.paypal.com assets.braintreegateway.com *.cardinalcommerce.com * https://*.contentsquare.net https://*.contentsquare.com https://analytics.tiktok.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.adyen.com pay.google.com *.payments-amazon.com *.media-amazon.com *.paypalobjects.com https://images.unsplash.com *.googleapis.com https://*.gstatic.com https://*.google.com https://*.googleapis.com https://*.googleusercontent.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://*.contentsquare.net https://*.contentsquare.com https://www.google.nl https://www.google.de https://bat.bing.com https://match.sharethrough.com https://cm.g.doubleclick.net https://criteo-partners.tremorhub.com https://x.bidswitch.net https://ib.adnxs.com https://rtb-csync.smartadserver.com https://sync-t1.taboola.com https://visitor.omnitagjs.com https://r.casalemedia.com https://gum.criteo.com https://id5-sync.com https://ad.360yield.com https://matching.ivitrack.com https://contextual.media.net https://ad.yieldlab.net https://ps.eyeota.net https://exchange.mediavine.com https://jadserve.postrelease.com https://sync.outbrain.com https://simage2.pubmatic.com https://pixel.rubiconproject.com https://criteo-sync.teads.tv https://eb2.3lift.com https://sync-criteo.ads.yieldmo.com https://e1.emxdgt.com https://dis.criteo.com https://sync.1rx.io https://analytics.tiktok.com https://*.reskyt.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net amcglobal.sc.omtrdc.net commerce.adobe.net use.typekit.net *.commerce-payment-services.com commerce-payments-sdk.adobe.io www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.magento-ds.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.magento-datasolutions.com *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com https://rum.hlx.page https://cdn.jsdelivr.net/npm/@ryangjchandler/spruce@2.x.x/dist/spruce.umd.js *.googleapis.com https://*.gstatic.com *.getflowbox.com https://*.google.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com connect.getflowbox.com t.contentsquare.net static.hotjar.com https://*.contentsquare.net https://app.contentsquare.com https://*.cookiefirst.com https://*.noibu.com https://cdn-4.convertexperiments.com https://s.pinimg.com https://static.criteo.net https://www.dwin1.com https://bat.bing.com https://ct.pinterest.com https://cdn.watchtower.graindata.com https://script.hotjar.com https://lantern.roeyecdn.com https://sslwidget.criteo.com https://cdn.segmentify.com https://*.prenatal.nl https://analytics.tiktok.com https://*.reskyt.com https://app.aiden.cx 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com maxcdn.bootstrapcdn.com https://fonts.googleapis.com https://hcaptcha.com https://*.hcaptcha.com assets.braintreegateway.com https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com https://*.cookiefirst.com https://cdn.segmentify.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.magento-datasolutions.com *.magento-ds.com *.adyen.com https://*.google.com payments-eu.amazon.com *.googleapis.com *.getflowbox.com https://ipinfo.io https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.trustedshops.com *.etrusted.com https://integrations.etrusted.site https://*.contentsquare.net https://*.contentsquare.com https://pagead2.googlesyndication.com https://googleads.g.doubleclick.net https://*.cookiefirst.com https://pipeline.prenatal.nl https://region1.google-analytics.com https://www.google.nl https://ct.pinterest.com https://measurement-api.criteo.com https://vc.hotjar.io https://gandalf-eu.segmentify.com https://*.convertexperiments.com https://*.noibu.com wss://*.noibu.com https://analytics.tiktok.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com blob: http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' 'unsafe-inline' https://*.fontawesome.com https://*.googleapis.com https://accounts.google.com https://analytics.google.com https://*.analytics.google.com https://*.sentry.io https://*.google-analytics.com https://*.gstatic.com https://google-analytics.com https://*.leadinfo.net https://*.leadinfo.com https://*.doubleclick.net https://*.hotjar.io https://*.hotjar.com https://*.googletagmanager.com https://*.google.com https://*.google.be https://*.google.de https://*.google.fr https://*.google.lu https://*.google.nl https://*.google.pl https://*.google.co.uk ; font-src 'self' 'unsafe-inline' https://*.fontawesome.com https://fonts.gstatic.com data: ; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://*.googletagmanager.com https://www.google.com/recaptcha/api.js https://www.gstatic.com/recaptcha/ https://maps.googleapis.com https://accounts.google.com/gsi/ https://*.google-analytics.com https://js.mollie.com https://cdn.leadinfo.net/ ; script-src-elem 'self' 'unsafe-inline' 'unsafe-eval' https://*.googletagmanager.com https://www.google.com/recaptcha/api.js https://www.gstatic.com/recaptcha/ https://maps.googleapis.com https://accounts.google.com/gsi/ https://*.google-analytics.com https://js.mollie.com https://cdn.leadinfo.net/ ; frame-src 'self' https://*.doubleclick.net/ https://accounts.google.com/ https://*.mollie.com https://*.googletagmanager.com https://*.google.com https://*.google.be https://*.google.de https://*.google.fr https://*.google.lu https://*.google.nl https://*.google.pl https://*.google.co.uk ; img-src 'self' https://*.googletagmanager.com https://*.googleapis.com https://*.gstatic.com https://*.doubleclick.net data: https://tile.openstreetmap.org https://*.google.com https://*.google.be https://*.google.de https://*.google.fr https://*.google.lu https://*.google.nl https://*.google.pl https://*.google.co.uk ; report-to csp-endpoint; report-uri https://www.companyweb.be/cspviolation 1 base-uri 'none'; object-src 'none'; script-src 'unsafe-inline' 'unsafe-eval' 'strict-dynamic' https: http: 'nonce-rnda25nRj6ONjFBAmo9oUQ==' 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.cloudflare.com *.twitter.com *.facebook.net *.twimg.com *.hotjar.com *.trustedshops.com *.googleapis.com *.magentocommerce.com *.paypal.com *.cardinalcommerce.com *.authorize.net *.fontawesome.com *.mncdn.com *.masterpassturkiye.com *.iyzipay.com *.bkm.com.tr *.akbank.com.tr *.yapikredi.com.tr *.garanti.com.tr *.ingage.tech *.pinterest.com *.pinimg.com *.connectad.io *.opera.com *.gumgum.com *.rakuten.com *.smaato.net *.adtarget.com *.mgid.com *.onetag-sys.com *.adscale.com *.loopme.me *.smilewanted.com *.wawlabs.com *.dmxleo.com *.cloudfront.net *.openx.net *.sharethis.com *.google.com.tr *.googlesyndication.com https://buysoci.al *.agkn.com *.a.run.app *.clarity.ms sc-static.net jadserve.postrelease.com sync.1rx.io sync.targeting.unrulymedia.com *.cloudflareinsights.com *.cookiespool.com *.tiktokw.us *.zopim.com *.zopim.io *.personaclick.com *.mnmedya.com *.ipaper.io *.useinsider.com https://*.useinsider.com wss://*.useinsider.com *.tiktok.com *.googleoptimize.com *.creativecdn.com https://*.amazonaws.com *.criteo.com *.rossmann.com.tr cdn.rossmann.com.tr *.vimeo.com www.rossmann.com.tr *.snapchat.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.paypal.com *.twitter.com *.facebook.com *.ingage.tech *.pinterest.com *.pinimg.com *.connectad.io *.opera.com *.gumgum.com *.rakuten.com *.smaato.net *.adtarget.com *.mgid.com *.onetag-sys.com *.adscale.com *.loopme.me *.smilewanted.com *.wawlabs.com *.dmxleo.com *.cloudfront.net *.openx.net *.sharethis.com *.google.com.tr *.googlesyndication.com https://buysoci.al *.agkn.com *.a.run.app *.clarity.ms sc-static.net jadserve.postrelease.com sync.1rx.io sync.targeting.unrulymedia.com *.cloudflareinsights.com *.cookiespool.com *.tiktokw.us *.mncdn.com *.personaclick.com *.mnmedya.com *.ipaper.io *.useinsider.com https://*.useinsider.com wss://*.useinsider.com *.tiktok.com *.googleoptimize.com *.creativecdn.com https://*.amazonaws.com *.criteo.com *.rossmann.com.tr cdn.rossmann.com.tr *.vimeo.com *.snapchat.com 'self' 'unsafe-inline'; frame-ancestors *.google.com *.gstatic.com *.ingage.tech *.pinterest.com *.pinimg.com *.connectad.io *.opera.com *.gumgum.com *.rakuten.com *.smaato.net *.adtarget.com *.mgid.com *.onetag-sys.com *.adscale.com *.loopme.me *.smilewanted.com *.wawlabs.com *.dmxleo.com *.cloudfront.net *.openx.net *.sharethis.com *.google.com.tr *.googlesyndication.com https://buysoci.al *.agkn.com *.a.run.app *.clarity.ms sc-static.net jadserve.postrelease.com sync.1rx.io sync.targeting.unrulymedia.com *.cloudflareinsights.com *.cookiespool.com *.tiktokw.us *.mncdn.com *.personaclick.com *.mnmedya.com *.ipaper.io *.useinsider.com https://*.useinsider.com wss://*.useinsider.com *.tiktok.com *.googleoptimize.com *.creativecdn.com https://*.amazonaws.com *.criteo.com *.rossmann.com.tr cdn.rossmann.com.tr *.vimeo.com *.snapchat.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com https://www.googletagmanager.com/ *.twitter.com *.gstatic.com *.hotjar.com *.google.com.tr *.veinteractive.com *.demdex.net *.solocpm.com *.facebook.com *.facebook.net *.addthis.com *.livechatinc.com *.yandex.ru *.adyen.com *.vimeo.com *.doubleclick.net *.bluekai.com *.useinsider.com *.masterpassturkiye.com *.iyzipay.com *.bkm.com.tr *.akbank.com.tr *.yapikredi.com.tr *.garanti.com.tr *.ingage.tech *.pinterest.com *.pinimg.com *.connectad.io *.opera.com *.gumgum.com *.rakuten.com *.smaato.net *.adtarget.com *.mgid.com *.onetag-sys.com *.adscale.com *.loopme.me *.smilewanted.com *.wawlabs.com *.dmxleo.com *.cloudfront.net *.openx.net *.sharethis.com *.googlesyndication.com https://buysoci.al *.agkn.com *.a.run.app *.clarity.ms sc-static.net jadserve.postrelease.com sync.1rx.io sync.targeting.unrulymedia.com *.cloudflareinsights.com *.cookiespool.com *.tiktokw.us https://www.youtube.com http://www.sandbox.paypal.com www.paypal.com *.mncdn.com *.personaclick.com *.mnmedya.com *.ipaper.io https://*.useinsider.com wss://*.useinsider.com *.tiktok.com *.googleoptimize.com *.creativecdn.com https://*.amazonaws.com *.criteo.com *.rossmann.com.tr cdn.rossmann.com.tr rossmann.api.useinsider.com td.doubleclick.net ams.creativecdn.com *.snapchat.com 'self' 'unsafe-inline'; img-src *.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com *.swagger.io https://images.unsplash.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ *.cloudflare.com *.klarna.com *.googleadservices.com *.google-analytics.com *.paypalobjects.com *.hotjar.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.magentocommerce.com *.cardinalcommerce.com *.authorize.net *.omtrdc.net *.newrelic.com *.doubleclick.net *.google.com *.google.com.tr *.facebook.com *.facebook.net *.demdex.net *.everesttech.net *.googleapis.com *.adis.ws *.livechatinc.com *.yandex.ru *.adyen.com *.setrowid.com *.setrow.com *.instagram.com *.useinsider.com *.googletagmanager.com *.mncdn.com *.iyzicopwi.com.tr *.masterpassturkiye.com *.iyzipay.com *.bkm.com.tr *.akbank.com.tr *.yapikredi.com.tr *.garanti.com.tr *.ingage.tech *.pinterest.com *.pinimg.com *.connectad.io *.opera.com *.gumgum.com *.rakuten.com *.smaato.net *.adtarget.com *.mgid.com *.onetag-sys.com *.adscale.com *.loopme.me *.smilewanted.com *.wawlabs.com *.dmxleo.com *.cloudfront.net *.openx.net *.sharethis.com *.googlesyndication.com https://buysoci.al *.agkn.com *.a.run.app *.clarity.ms sc-static.net jadserve.postrelease.com sync.1rx.io sync.targeting.unrulymedia.com *.cloudflareinsights.com *.cookiespool.com *.tiktokw.us *.bing.com *.zopim.com *.zopim.io *.google.co.in *.mastercard.com *.personaclick.com *.mnmedya.com *.ipaper.io https://*.useinsider.com wss://*.useinsider.com *.tiktok.com *.googleoptimize.com *.creativecdn.com https://*.amazonaws.com *.criteo.com *.rossmann.com.tr *.vimeo.com *.bidswitch.net *.adnxs.com *.casalemedia.com *.media.net *.360yield.com *.outbrain.com *.rubinproject.com *.sharethrough.com *.smartadserver.net *.taboola.com *.teads.tv *.3lift.com *.emxdgt.com *.adform.net *.omnitagjs.com *.sync.com *.ivitrack.com *.mediavine.com *.pubmatic.com *.tremorhub.com *.yieldlab.net *.yieldmo.com *.semasio.net *.krxd.net *.thebrighttag.com *.smartadserver.com *.yahoo.com https://id5-sync.com *.rubiconproject.com www.rossmann.com.tr cdn.rossmann.com.tr web-image.useinsider.com image.useinsider.com static.ads-twitter.com ads-twitter.com ads-api.twitter.com analytics.twitter.com t.co www.facebook.com *.snapchat.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com commerce-payments-sdk.adobe.io s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://maps.googleapis.com https://player.vimeo.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ *.cloudflare.com *.twitter.com *.google-analytics.com *.twimg.com *.gstatic.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.magentocommerce.com *.paypal.com *.hotjar.com *.cardinalcommerce.com *.authorize.net *.omtrdc.net *.instana.io *.google.com.tr *.googletagmanager.com *.veinteractive.com *.facebook.net *.supert.ag *.setrowid.com *.mainadv.com *.doubleclick.net *.googleapis.com *.addthis.com *.moatads.com *.addthisedge.com *.livechatinc.com *.yandex.ru *.adyen.com *.vimeo.com *.jsdelivr.net *.setrow.com *.instagram.com *.criteo.com *.criteo.net *.ciritizr.com *.bkrtx.com *.cloudfront.net *.useinsider.com *.critizr.com *.behance.net *.swagger.io *.avada.io *.mncdn.com *.iyzicopwi.com.tr *.masterpassturkiye.com *.iyzipay.com *.bkm.com.tr *.akbank.com.tr *.garanti.com.tr *.ingage.tech *.pinterest.com *.pinimg.com *.connectad.io *.opera.com *.gumgum.com *.rakuten.com *.smaato.net *.adtarget.com *.mgid.com *.onetag-sys.com *.adscale.com *.loopme.me *.smilewanted.com *.wawlabs.com *.dmxleo.com *.openx.net *.sharethis.com *.googlesyndication.com https://buysoci.al *.agkn.com *.a.run.app *.clarity.ms sc-static.net jadserve.postrelease.com sync.1rx.io sync.targeting.unrulymedia.com *.cloudflareinsights.com *.cookiespool.com *.tiktokw.us *.bing.com *.zopim.com *.zdassets.com *.personaclick.com *.mnmedya.com *.ipaper.io https://*.useinsider.com wss://*.useinsider.com *.tiktok.com *.googleoptimize.com *.creativecdn.com https://*.amazonaws.com *.rossmann.com.tr www.rossmann.com.tr rossmann.api.useinsider.com connect.facebook.net tags.creativecdn.com static.ads-twitter.com ads-twitter.com ads-api.twitter.com analytics.twitter.com embeds.ipaper.io static.hotjar.com cdn.rossmann.com.tr eitri.api.useinsider.com analytics.tiktok.com script.hotjar.com ams.creativecdn.com *.snapchat.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.facebook.net *.cloudflare.com *.googleapis.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.magentocommerce.com *.fontawesome.com *.paypal.com *.paypalobjects.com *.hotjar.com *.cardinalcommerce.com *.authorize.net *.omtrdc.net *.newrelic.com *.setrowid.com *.setrow.com *.critizr.com *.useinsider.com *.adobedtm.com *.google-analytics.com *.googletagmanager.com *.swagger.io *.mncdn.com *.masterpassturkiye.com *.iyzipay.com *.bkm.com.tr *.akbank.com.tr *.yapikredi.com.tr *.garanti.com.tr *.ingage.tech *.pinterest.com *.pinimg.com *.connectad.io *.opera.com *.gumgum.com *.rakuten.com *.smaato.net *.adtarget.com *.mgid.com *.onetag-sys.com *.adscale.com *.loopme.me *.smilewanted.com *.wawlabs.com *.dmxleo.com *.cloudfront.net *.openx.net *.sharethis.com *.google.com.tr *.googlesyndication.com https://buysoci.al *.agkn.com *.a.run.app *.clarity.ms sc-static.net jadserve.postrelease.com sync.1rx.io sync.targeting.unrulymedia.com *.cloudflareinsights.com *.cookiespool.com *.tiktokw.us *.bing.com *.personaclick.com *.mnmedya.com *.ipaper.io https://*.useinsider.com wss://*.useinsider.com *.tiktok.com *.googleoptimize.com *.creativecdn.com https://*.amazonaws.com *.criteo.com *.rossmann.com.tr *.vimeo.com www.rossmann.com.tr cdn.rossmann.com.tr maxcdn.bootstrapcdn.com assets.api.useinsider.com *.snapchat.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net *.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://maps.googleapis.com https://player.vimeo.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ *.cloudflare.com https://stats.g.doubleclick.net *.twitter.com *.facebook.com *.facebook.net *.paypalobjects.com *.hotjar.com *.hotjar.io *.twimg.com *.magentocommerce.com *.cardinalcommerce.com *.cardinalcommerce.net *.veinteractive.com *.demdex.net *.yandex.ru *.vimeo.com *.setrowid.com *.setrow.com *.useinsider.com *.adobedtm.com *.swagger.io https://get.geojs.io *.avada.io *.masterpassturkiye.com *.iyzipay.com *.bkm.com.tr *.akbank.com.tr *.yapikredi.com.tr *.garanti.com.tr https://mnemos-api.ahtapot.ai *.ingage.tech *.pinterest.com *.pinimg.com *.connectad.io *.opera.com *.gumgum.com *.rakuten.com *.smaato.net *.adtarget.com *.mgid.com *.onetag-sys.com *.adscale.com *.loopme.me *.smilewanted.com *.wawlabs.com *.dmxleo.com *.cloudfront.net *.openx.net *.sharethis.com *.google.com.tr *.googlesyndication.com https://buysoci.al *.agkn.com *.a.run.app *.clarity.ms sc-static.net jadserve.postrelease.com sync.1rx.io sync.targeting.unrulymedia.com *.cloudflareinsights.com *.cookiespool.com *.tiktokw.us *.zdassets.com *.zopim.com *.zopim.io wss://widget-mediator.zopim.com *.google-analytics.com *.mncdn.com *.personaclick.com *.mnmedya.com *.ipaper.io https://*.useinsider.com wss://*.useinsider.com *.tiktok.com *.googleoptimize.com *.creativecdn.com https://*.amazonaws.com *.criteo.com *.rossmann.com.tr www.rossmann.com.tr cdn.rossmann.com.tr rossmann.api.useinsider.com aryuder.api.useinsider.com hit.api.useinsider.com ams.creativecdn.com recommendationv2.api.useinsider.com *.snapchat.com static.ads-twitter.com ads-twitter.com ads-api.twitter.com analytics.twitter.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.ingage.tech *.pinterest.com *.pinimg.com *.connectad.io *.opera.com *.gumgum.com *.rakuten.com *.smaato.net *.adtarget.com *.mgid.com *.onetag-sys.com *.adscale.com *.loopme.me *.smilewanted.com *.wawlabs.com *.dmxleo.com *.cloudfront.net *.openx.net *.sharethis.com *.google.com.tr *.googlesyndication.com *.buysoci.al *.agkn.com *.a.run.app sc-static.net jadserve.postrelease.com sync.1rx.io sync.targeting.unrulymedia.com www.rossmann.com.tr cdn.rossmann.com.tr *.clarity.ms googleads.g.doubleclick.net analytics.tiktok.com *.snapchat.com *.twitter.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.fontawesome.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.staging-pbffinancecalculator.info *.pbffinancecalculator.info *.paybyfinance.co.uk *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com *.amazon.com *.staging-pbffinancecalculator.info *.pbffinancecalculator.info *.paybyfinance.co.uk 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ https://www.googletagmanager.com/ *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.staging-pbffinancecalculator.info *.pbffinancecalculator.info *.paybyfinance.co.uk c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.bing.com *.google-analytics.com *.googleadservices.com *.google.co.uk *.googletagmanager.com *.expressentry.melissadata.net *.paypalobjects.com *.ometria.services *.feefo.com *.adobedtm.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ *.ometria.com *.klarna.com *.klarnaevt.com *.klarnacdn.net https://firebasestorage.googleapis.com *.pbffinancecalculator.info cdn.shopify.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.bing.com *.google-analytics.com *.googletagmanager.com *.googleadservices.com *.googleapis.com expressentry.melissadata.net *.paypalobjects.com *.ometria.services *.noibu.com https://www.noibu.com https://cdn.noibu.com *.facebook.net https://cdn.jsdelivr.net http://www.googletagmanager.com/ https://www.googletagmanager.com/ *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com *.dixa.io x.klarnacdn.net *.klarnaservices.com *.avada.io *.shopify.com *.staging-pbffinancecalculator.info *.pbffinancecalculator.info *.paybyfinance.co.uk https://api.ometria.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.ometria.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.googleapis.com fonts.googleapis.com *.stripe.network *.stripecdn.com *.amazon.com *.klarnacdn.net *.fontawesome.com https://fonts.bunny.net unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.bing.com *.google-analytics.com *.googletagmanager.com *.googlesyndication.com *.googleapis.com maps.googleapis.com expressentry.melissadata.net *.paypalobjects.com *.ometria.services *.advancedcommerce.services *.algolia.net https://cdn.noibu.com wss://input.noibu.com https://input.noibu.com *.noibu.com *.facebook.net https://cdn.jsdelivr.net http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.dixa.io x.klarnacdn.net *.klarnaservices.com https://get.geojs.io *.avada.io *.staging-pbffinancecalculator.info *.pbffinancecalculator.info wss://*.staging-pbffinancecalculator.info wss://*.pbffinancecalculator.info *.paybyfinance.co.uk https://api.ometria.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.ometria.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com https://www.google-analytics.com https://cdnjs.cloudflare.com https://cdn.jsdelivr.net; script-src-elem 'self' https://www.googletagmanager.com https://www.google-analytics.com https://cdnjs.cloudflare.com https://cdn.jsdelivr.net; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://cdnjs.cloudflare.com; style-src-elem 'self' 'unsafe-inline' https://fonts.googleapis.com https://cdnjs.cloudflare.com; img-src 'self' data: https://www.google-analytics.com https://nhentai.website https://nhentai.jp.net https://*.nhentai.jp.net; font-src 'self' https://fonts.gstatic.com https://cdnjs.cloudflare.com data:; connect-src 'self' https://www.google-analytics.com https://www.googletagmanager.com https://static.cloudflareinsights.com https://nhentai.website; frame-src 'self' https://nhentai-website.disqus.com; frame-ancestors 'self'; base-uri 'self'; form-action 'self'; report-to csp-endpoint 1 script-src 'sha256-Xlj+3ReycLnAl2XScCaqHXpt0VFW/B1FzaUvWTR5ZGI=' 'self' self unsafe-eval; style-src self unsafe-eval; report-uri https://d302fc2a-dd34-416c-a079-e29edadd0fcf.sansec.watch/ 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https:; style-src 'self' 'unsafe-inline' https:; img-src 'self' data: https:; font-src 'self' data: https:; connect-src 'self' https:; frame-ancestors 'self'; base-uri 'self'; form-action 'self' https:; upgrade-insecure-requests; block-all-mixed-content 1 default-src data: 'self' blob: 'unsafe-inline' 'unsafe-eval' *.atyarisi.com wss://*.atyarisi.com *.google.com *.google.com.tr *.googletagmanager.com *.google-analytics.com *.support.google.com *.doubleclick.net *.googleadservices.com *.microsoft.com *.apple.com *.facebook.com *.facebook.net *.yahoo.com *.newrelic.com *.twitter.com *.instagram.com *.youtube.com tjktv.ercdn.net *.tjk.org *.broadage.com *.media.net *.liderform.com.tr *.googleapis.com *.googlevideo.com *.gstatic.com *.nsoft-cdn.com *.stg-digi.com *.rlcdn.com *.crwdcntrl.net *.dengage.com *.nr-data.net *.taboola.com *.tiktok.com *.dengagecdn.com *.sisalsanstech.com *.millipiyangoonline.com *.rsc.cdn77.org *.clarity.ms scripts.clarity.ms *.tiktokw.us *.tiktokv.com *.byteoversea.com; img-src * data:; report-uri /csp/cspreport/ 1 frame-src viz.tools.investis.com irs.tools.investis.com www.youtube.com www.youtube-nocookie.com; report-uri /report-csp-violation 1 default-src 'self' *.simyo.es *.typekit.net *.sumup.com *.opentech.com *.consorsbank.de *.bkm.com.tr *.micb.md *.capitecbank.co.za *.asseco-see.hr *.ing.com *.privatbank.ua *.n26.com *.six-group.com *.seglan.com *.monext.fr *.rsa3dsauth.com *.papara.com *.sibs.pt *.bpcbt.com *.capitalone.com *.bpcprocessing.com *.kapital24.uz *.alignet.io *.revolut.com *.wlp-acs.com *.mycardplace.com *.emlpayments.com *.abanca.com *.viseca.ch *.edb.com *.arca.am *.modirum.com *.redsys.es *.marqeta.com *.vinea.es *.cardinalcommerce.com; script-src-elem 'self' 'unsafe-inline' *.redsys.es *.cardinalcommerce.com *.googleapis.com *.pinterest.com bat.bing.com *.gstatic.com *.googletagmanager.com *.doubleclick.net *.amazon-adsystem.com *.pinimg.com *.taboola.com amplify.outbrain.com jgb8.simyo.es analytics.tiktok.com *.weborama.fr connect.facebook.net foodin.site sc-static.net *.hotjar.com *.mathtag.com *.appboycdn.com *.google-analytics.com *.useinsider.com *.criteo.com *.jsdelivr.net *.cardinalcommerce.com *.google.com www.google.com/recaptcha *.xizumubama.com *.thetto.com *.roterf.com *.snapchat.com *.appsflyer.com *.bazaarvoice.com *.bimien.com; script-src 'self' 'unsafe-inline' https: 'unsafe-eval' *.typekit.net *.redsys.es *.cardinalcommerce.com *.googletagmanager.com bat.bing.com *.googleapis.com *.gstatic.com *.google.com *.ggpht.com *.googleusercontent.com *.yandex.net yastatic.net blob:; img-src 'self' *.redsys.es *.simyo.es *.google.es *.doubleclick.net *.weborama.fr *.facebook.com *.cardinalcommerce.com bat.bing.com *.google-analytics.com analytics.tiktok.com *.typekit.net *.googletagmanager.com *.googleapis.com *.gstatic.com *.google.com *.googleusercontent.com *.vimeocdn.com data: *.360yield.com *.doubleclick.net *.stickyadstv.com *.yieldmo.com *.bing.com blob: bttrack.com *.shoppiday.es *.goin.cloud *.honey.io *.media.net *.camarabilbao.com *.adxcel-ec2.com *.mediavine.com *.weborama.fr *.criteo.com *.liadm.com *.adnxs.com *.rlcdn.com *.postrelease.com *.roeye.com *.ggpht.com *.sharethrough.com *.yandex.ru *.veritone-ce.com *.mediawallahscript.com *.rubiconproject.com *.casalemedia.com *.smartadserver.com *.pubmatic.com *.yahoo.com *.igstatic.com *.taboola.com *.1rx.io *.outbrain.com *.revcontent.com *.omnitagjs.com webkit-masked-url://hidden *.facebook.com *.google.ad *.google.al *.google.at *.google.be *.google.bg *.google.by *.google.ca *.google.ch *.google.cl *.google.cn *.google.co.cr *.google.co.id *.google.co.in *.google.co.jp *.google.co.kr *.google.co.ma *.google.co.th *.google.co.uk *.google.co.ve *.google.co.za *.google.com *.google.com.ar *.google.com.au *.google.com.br *.google.com.co *.google.com.do *.google.com.ec *.google.ba *.google.co.uz *.google.bf *.google.ci *.google.com.gi *.google.com.gt *.google.com.ni *.google.com.np *.google.com.eg *.google.com.hk *.google.com.mt *.google.com.mx *.google.com.my *.google.com.pe *.google.com.py *.google.com.qa *.google.com.sg *.google.com.tr *.google.com.tw *.google.com.ua *.google.com.uy *.google.com.vn *.google.com.gh *.google.cz *.google.de *.google.dk *.google.ee *.google.es *.google.co.ao *.google.co.il *.google.co.ug *.google.com.bo *.google.com.bz *.google.com.na *.google.com.sv *.google.md *.google.mw *.google.iq *.google.am *.google.fi *.google.cv *.google.dz *.google.ge *.google.hn *.google.kz *.google.lk *.google.lv *.google.rs *.google.sn *.google.fr *.google.gr *.google.hr *.google.hu *.google.ie *.google.is *.google.it *.google.lt *.google.lu *.google.ae *.google.mu *.google.nl *.google.no *.google.pl *.google.pt *.google.ro *.google.ru *.google.se *.google.si *.google.sk *.google.cm *.google.co.ke *.google.co.nz *.google.com.pa *.google.com.ph *.google.com.pk *.google.com.pr *.google.com.sa *.google.me *.google.mv *.google.tn *.bidswitch.net *.groovinads.com *.clarity.ms *.ytimg.com mikkiload.com *.prfrm-ads.com *.charleskeith.co.th *.barclays.co.uk *.snapchat.com *.adentifi.com *.amazonaws.com *.discordapp.com *.yandex.com *.productfruits.com *.discordapp.net *.profileengine.com *.phncdn.com *.leanlibrary.app *.ibb.co *.facebook.net *.css-tricks.com *.ipredictive.com *.line.me *.reskyt.com *.marca.com *.baidu.com *.huffingtonpost.es *.eficads.net; frame-src *.simyo.es *.redsys.es simyospain.speedtestcustom.com *.weborama.fr buybutwhere.com hipodi.com *.awin1.com *.googleapis.com cookieaquila.com *.mycardplace.com *.cardinalcommerce.com bat.bing.com *.pinterest.com *.amazon-adsystem.com *.doubleclick.net mapacob.aptica.es *.google.com *.socialmediaserver.es *.vimeo.com *.n26.com *.abanca.com *.borica.bg *.emlpayments.com *.nexigroup.com *.sebkort.com *.vinea.es *.cardcenter.ch 3dsecure-vrp.de acestream.tv *.modirum.com *.3dsecure.no *.apata.io *.edb.com *.bpcbt.com *.revolut.com *.targobank.de *.modirum.com acs2.arca.am *.bgpb.by *.marqeta.com *.wlp-acs.com *.opendns.com bnext.areq.mpts.modirum.com:9702 *.icard.com ebanking1.ccb.com.cn emet.live emet.news gateway.zscaler.net gateway.zscalertwo.net gateway.zscloud.net *.criteo.com *.rsa3dsauth.com *.moz.com sas.mc.redsys.es:9731 *.dkb.de *.arcot.com * *.criteo.net tdschded.monext.fr visa2.acs.cmbchina.com *.facebook.com *.googletagmanager.com *.pluscard.de *.pkobp.pl *.sia.eu *.alignet.io *.bpcprocessing.com *.sibs.pt *.swedbank.se *.useinsider.com *.boc.cn *.cloudfront.net *.kaspersky-labs.com *.micb.md *.merck.com *.zscalerthree.net *.secureacs.com *.bankserv.co.za *.gpesecure.com *.adsrvr.org *.ing.de *.viseca.ch *.icbc.com.cn *.netsgroup.com *.jysanbank.kz *.ukrsibbank.com *.monzo.com *.securesuite.net *.capitalone.com *.mtbank.by:8043 *.hitrust.com:9750 *.ajgirona.org *.creditagricole.ma *.mycardsecure.com *.google.com skytraf.xyz acs.hitrust-us.com:9750 securegw1.micb.md:6444 *.groovinads.com *.danskebank.com *.seglan.com *.useinsider.com div.show *.consorsbank.de *.co.uk *.indra-netplus.com *.firstdata.de *.snapchat.com *.sparkasse.at securesuite.net *.wibmo.com *.citibank.com *.zscaler.com *.bog.ge noop.style *.3dsacs.net *.bunq.com *.cihbank.ma *.ukrgasbank.com *.acdcproc.com *.privatbank.ua *.csi-processing.com *.placetopay.com *.s-id-check-sparkassen.de *.eewosecure.com *.cm-cic.com *.gc.ge *.sinnad.com.bh *.mercurypaymentservices.it ; font-src 'self' *.simyo.es *.redsys.es *.affilitizer.com *.escribelo.ai *.cdnfonts.com *.googleusercontent.com *.bootstrapcdn.com *.cardinalcommerce.com *.fontawesome.com fonts.gstatic.com *.typekit.net *.goin.cloud *.scite.ai *.cloudflare.com *.windows.net *.migaku.com *.slant.co *.alicdn.com *.faceworks.nl *.zohocdn.com yastatic.net ray.st chrome-extension moz-extension ms-browser-extension data:; connect-src 'self' *.adblockertool.com *.adfreevision.com *.amcreativemedia.com *.bttrack.com *.blackcrow.ai *.yimg.com *.browsekeeper.com *.creativecdn.com *.mczbf.com *.highdataanalytics.com *.uniswap.org *.kaspersky-labs.com infragrid.v.network *.dbankcloud.cn *.overbridgenet.com *.googlesyndication.com *.facebook.com *.simyo.es *.redsys.es ara.paa-reporting-advertising.amazon *.cardinalcommerce.com bat.bing.com *.taboola.com analytics.tiktok.com *.amazon-adsystem.com *.google-analytics.com *.doubleclick.net *.pinterest.com *.googleapis.com *.google.com *.google.com.ar *.google.com.co *.google.com.do *.google.com.mx *.google.com.pe *.google.com.tr *.google.com.uy *.google.de *.google.es *.google.fr *.google.ie *.google.it *.google.lt *.google.pt *.google.kz *.google.ro *.google.ae *.google.at *.google.ca *.google.ch *.google.cl *.google.co.ma *.google.co.uk *.google.co.ve *.google.be *.google.cm *.google.co.jp *.google.co.nz *.google.com.br *.google.cz *.google.fi *.google.com.pk *.google.com.pr *.google.com.sg *.google.com.gi *.google.ad *.google.by *.google.ba *.google.gr *.google.hu *.google.nl *.google.no *.google.rs *.google.sk *.google.se *.google.ru *.google.sn *.google.tn *.google.co.il *.google.com.pa *.google.com.qa *.google.dk *.google.me *.google.com.au *.google.com.gt *.google.com.hk *.google.co.cr *.gstatic.com *.googleadservices.com *.mplxtms.com *.yandex.ru *.cdn77.org *.adtonus.com *.fbanalytics.org *.mkmediaworks.com *.ultimateaderaser.com *.zendesk.com *.jquery.com *.zdassets.com meetlookup.com *.amazonaws.com rbtds.net *.clarity.ms zone1-services-cdn.com *.socialsolutionapp.com *.awesomeblocker.com *.global-data-lab.com *.range-offer.com *.report-uri.com *.pangle-ads.com *.adblocking247.com *.blocksly.org *.crystal-blocker.com *.datacloudstat.com *.software-downloading.com cubox.pro *.vimeocdn.com *.typekit.net *.vimeo.com *.reskyt.com *.braze.com *.criteo.com *.snapchat.com *.yandex.net *.yandex.com *.productfruits.com *.hotjar.io *.appsflyer.com *.onelink.me *.googletagmanager.com ya.ru *.socialmediaserver.es data: blob:; style-src-elem 'self' 'unsafe-inline' *.typekit.net *.googleapis.com *.scriptcdn.net *.tiktok.com *.webgains.io *.bing.com blob: bttrack.com *.amazon-adsystem.com *.taboola.com *.trackmytarget.com *.facebook.net *.weborama.fr *.pinterest.com *.eligrop.com *.hicloud.com *.kaspersky-labs.com *.doubleclick.net infimv.com *.blackcrow.ai *.simyo.es *.roeyecdn.com *.yandex.ru *.acestream.net *.pinimg.com *.yimg.com *.mplxtms.com *.criteo.net *.creativecdn.com *.dwin1.com *.google.com *.googleadservices.com *.googletagmanager.com *.mczbf.com *.opera-mini.net *.honey.io *.gstatic.com *.groovinads.com *.cloudflare.com *.useinsider.com *.line-scdn.net *.vulapo.com *.cloudfront.net *.mediarithmics.com hublosk.com *.adsrvr.org jullyambery.net *.adguard.org mikkiload.com *.prfrm-ads.com *.zdassets.com *.charleskeith.co.th *.eficads.net *.artfut.com *.clarity.ms *.reskyt.com *.bootstrapcdn.com *.fontawesome.com lonelyfix.com data:; style-src-attr 'unsafe-inline' *.typekit.net; style-src 'self' 'unsafe-inline' *.typekit.net *.googleapis.com *.google.com *.reskyt.com *.gstatic.com *.googleadservices.com; media-src data:; worker-src blob:; 1 frame-ancestors 'self' https://www.nwcg.gov 1 object-src 'none'; script-src 'self' https://api.mapbox.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com unpkg.com; script-src-attr 'self' 'unsafe-inline'; script-src-elem * 'unsafe-inline'; style-src 'self' cdnjs.cloudflare.com https://api.mapbox.com https://cdnjs.cloudflare.com https://unpkg.com unpkg.com; style-src-attr 'self' 'unsafe-inline'; style-src-elem * 'unsafe-inline'; frame-ancestors 'self' 1 default-src 'self'; script-src 'self'; img-src 'self' data:; style-src 'self' 'unsafe-inline'; report-uri https://greatergiving.report-uri.com/r/d/csp/reportOnly 1 default-src 'self' https://exlibris.ch https://*.exlibris.ch https://*.sentry.io; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://exlibris.ch https://*.exlibris.ch https://googletagmanager.com https://*.googletagmanager.com https://epoq-systems.de http://epoq-systems.de https://*.epoq-systems.de http://*.epoq-systems.de https://epoq.de http://epoq.de https://*.epoq.de http://*.epoq.de https://connect.facebook.net https://google.com https://*.google.com https://googleanalytics.com https://*.googleanalytics.com https://google-analytics.com https://*.google-analytics.com https://googlesyndication.com https://*.googlesyndication.com https://gstatic.com https://*.gstatic.com https://googleapis.com https://*.googleapis.com https://googleadservices.com https://*.googleadservices.com bat.bing.com https://*.hotjar.com https://*.hotjar.io https://datatrans.com https://*.datatrans.com https://googleads.g.doubleclick.net https://cookielaw.org https://*.cookielaw.org https://*.trustpilot.com https://pay.google.com https://sandbox.secure.checkout.visa.com https://*.sentry.io analytics.tiktok.com analytics-ipv6.tiktokw.us http://ads.tiktok.com; worker-src 'self' blob:; connect-src 'self' https://exlibris.ch https://*.exlibris.ch exlibris.azureedge.net exlibris.blob.core.windows.net https://epoq.de https://*.epoq.de http://epoq-systems.de https://epoq-systems.de *.facebook.com https://migros.ch https://www.google.at https://*.google.ba https://*.migros.ch https://*.google.de https://*.google.ch https://*.google.com https://www.google.fr https://*.google.it https://*.google.li https://*.google.tn https://*.google.co.uk https://*.google.com.sa https://www.googleadservices.com https://google-analytics.com https://*.google-analytics.com https://google-analytics.ch https://*.google-analytics.ch https://google.com https://*.google.com https://analytics.google.com https://*.analytics.google.com https://analytics.google.ch https://*.analytics.google.ch https://googleapis.com https://*.googleapis.com https://googlesyndication.com https://*.googlesyndication.com https://*.googletagmanager.com bat.bing.com bat.bing.net https://doubleclick.net https://*.doubleclick.net https://g.doubleclick.net https://*.g.doubleclick.net https://cookielaw.org https://*.cookielaw.org https://onetrust.com https://*.onetrust.com https://onetrust.io https://*.onetrust.io https://hotjar.com https://*.hotjar.com https://hotjar.io https://*.hotjar.io wss://*.hotjar.com wss://hotjar.com https://*.sentry.io analytics.tiktok.com analytics-ipv6.tiktokw.us http://ads.tiktok.com https://widget.trustpilot.com; style-src 'self' 'unsafe-inline' https://exlibris.ch https://*.exlibris.ch https://googleapis.com https://*.googleapis.com https://google.com https://*.google.com https://googletagmanager.com https://tagmanager.google.com fast.fonts.net https://epoq-systems.de https://*.epoq-systems.de https://epoq.de https://*.epoq.de http://epoq-systems.de http://*.epoq-systems.de http://epoq.de http://*.epoq.de; img-src 'self' dhttps data: *.facebook.com https://exlibris.ch https://*.exlibris.ch exlibris.azureedge.net https://epoq-systems.de https://*.epoq-systems.de https://epoq.de https://*.epoq.de http://epoq-systems.de http://*.epoq-systems.de http://epoq.de http://*.epoq.de https://gstatic.com https://*.gstatic.com https://googleapis.com https://*.googleapis.com https://google-analytics.com https://*.google-analytics.com https://doubleclick.net https://*.doubleclick.net https://g.doubleclick.net https://*.g.doubleclick.net https://googlesyndication.com https://*.googlesyndication.com https://*.google.at https://*.google.ch https://*.google.de https://*.google.dz https://*.google.es https://*.google.fr https://*.google.hr https://*.google.it https://*.google.li https://*.google.lu https://*.google.nl https://*.google.sc https://*.google.si https://*.google.co.uk https://*.google.co.in https://*.google.com https://*.google.com.pa https://*.google.com.ph https://*.google.com.gh https://*.google.com.tr https://*.google.com.br https://*.google.com.cy https://www.googleadservices.com https://googletagmanager.com https://*.googletagmanager.com https://hotjar.com https://*.hotjar.com https://hotjar.io https://*.hotjar.io bat.bing.com https://cookielaw.org https://*.cookielaw.org optanon.blob.core.windows.net exlibris.blob.core.windows.net https://migros.ch https://*.migros.ch analytics.tiktok.com analytics-ipv6.tiktokw.us http://ads.tiktok.com https://ytimg.com https://*.ytimg.com; media-src 'self' data https://exlibris.ch https://*.exlibris.ch exlibris.blob.core.windows.net https://*.phononet.de/ exlibris.azureedge.net; frame-src 'self' bytedance: sslocal: https://exlibris.ch https://*.exlibris.ch https://google.de https://*.google.de https://google.com https://*.google.com https://googletagmanager.com https://*.googletagmanager.com https://googlesyndication.com https://*.googlesyndication.com https://youtube.com https://*.youtube.com https://datatrans.com https://*.datatrans.com https://*.fls.doubleclick.net https://bic-media.com https://*.bic-media.com https://youtube-nocookie.com https://*.youtube-nocookie.com https://doubleclick.net https://*.doubleclick.net https://hotjar.com https://*.hotjar.com https://hotjar.io https://*.hotjar.io https://tradedoubler.com https://*.tradedoubler.com https://blickinsbuch.de https://*.blickinsbuch.de https://book2look.com https://*.book2look.com https://postfinance.ch https://*.postfinance.ch https://viseca.ch/ https://*.viseca.ch/ https://bonuscard.ch/ https://*.bonuscard.ch/ https://3ds.bonuscard.ch/ https://*.3ds.bonuscard.ch/ https://arcot.com/ https://*.arcot.com/ https://*.trustpilot.com https://pay.google.com https://sandbox.secure.checkout.visa.com https://3d.datatrans.com https://3d.sandbox.datatrans.com; font-src 'self' data: https://exlibris.ch https://*.exlibris.ch https://gstatic.com https://*.gstatic.com https://google.com https://*.google.com https://hotjar.com https://*.hotjar.com https://hotjar.io https://*.hotjar.io; manifest-src 'self' https://exlibris.ch https://*.exlibris.ch; frame-ancestors 'self' https://exlibris.ch https://*.exlibris.ch; report-uri /loc/csp-report 1 object-src 'none'; base-uri 'self'; script-src 'self' 'nonce-XALfvYtgIDogyk6oQ6u0kg' 'unsafe-inline' 'unsafe-eval' https://*.msauth.net https://*.msftauth.net https://*.msftauthimages.net https://*.msauthimages.net https://*.msidentity.com https://*.microsoftonline-p.com https://*.microsoftazuread-sso.com https://*.azureedge.net https://*.outlook.com https://*.office.com https://*.office365.com https://*.microsoft.com https://*.bing.com 'report-sample'; report-uri https://csp.microsoft.com/report/ESTS-UX-All 1 font-src *.klevu.com *.ksearchnet.com *.gstatic.com https://fonts.gstatic.com *.fontawesome.com fonts.gstatic.com https://pos.snapscan.io *.cloudflare.com *.googleapis.com *.zopim.com *.tawk.to *.jsdelivr.net media.flixfacts.com 'unsafe-inline' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com https://sandbox.payfast.co.za https://www.payfast.co.za/eng/process oppwa.com *.oppwa.com peachpayments.com *.peachpayments.com *.facebook.com webchat.jdg.co.za *.jdg.co.za 'self' 'unsafe-inline'; frame-ancestors *.hana.ondemand.com 'self'; style-src *.adobe.com *.klevu.com *.ksearchnet.com *.googleapis.com https://hcaptcha.com https://*.hcaptcha.com *.fontawesome.com oppwa.com *.oppwa.com *.peachpayments.com *.cloudflare.com *.jsdelivr.net www.gstatic.com media.flixcar.com 'unsafe-inline' data: https://js.klevu.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.zdassets.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; connect-src *.google-analytics.com dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://*.ingest.sentry.io *.klevu.com *.ksearchnet.com https://ipinfo.io *.google.com https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com https://get.geojs.io *.avada.io oppwa.com *.oppwa.com *.peachpayments.com *.testfreaks.com *.nosto.com *.hotjar.io *.hotjar.com *.doubleclick.net *.zendesk.com *.paypal.com *.tawk.to wss://*.tawk.to *.tawk.link *.addthis.com *.addthisedge.com *.what3words.com *.googleapis.com vsb111.tawk.to ekr.zdassets.com api.magento.com commerce.adobedc.net app.mobicredwidget.co.za wss://widget-mediator.zopim.com bam.nr-data.net *.googletagmanager.com security-hub.vaimo.network 'unsafe-eval' data: 'self' 'unsafe-inline'; frame-src data:text fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.google.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com oppwa.com *.oppwa.com peachpayments.com *.peachpayments.com *.nosto.com *.issuu.com *.hotjar.com *.hotjar.io *.googletagmanager.com *.criteo.net *.criteo.com *.addthis.com *.facebook.com webchat.jdg.co.za *.jdg.co.za 'self' 'unsafe-inline'; img-src *.criteo.com *.krxd.net *.chatlayer.ai assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'unsafe-inline' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.klevu.com *.ksearchnet.com *.google.com *.gstatic.com https://*.googleapis.com https://*.googleusercontent.com oppwa.com *.oppwa.com *.peachpayments.com *.eu-west-1.amazonaws.com https://pos.snapscan.io *.cloudflare.com *.google.lv *.google.co.za *.google.com.na *.google.na *.zopim.com *.nosto.com *.hotjar.com *.hotjar.io *.googletagmanager.com *.zopim.io *.sfdr.co sfdr.co *.tawk.to tawk.link *.tawk.link *.addthis.com *.jsdelivr.net *.facebook.com *.azurewebsites.net maps.googleapis.com app.mobicredwidget.co.za media.flixcar.com rt.flix360.com assets.secure.checkout.visa.com data: 'self' 'unsafe-inline'; script-src *.incredible.co.za *.chatlayer.ai assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://browser.sentry-cdn.com *.klevu.com *.ksearchnet.com *.google.com https://*.gstatic.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com *.avada.io *.oppwa.com oppwa.com *.peachpayments.com *.zopim.com *.videoly.co sfdr.co *.cnetcontent.com *.cloudfront.net *.google.lv *.google.co.za *.google.com.na *.google.na *.cloudflare.com *.cloudflareinsights.com *.nosto.com *.hotjar.com *.googletagmanager.com *.criteo.net *.criteo.com *.sfdr.co *.tawk.to *.tawk.link *.jsdelivr.net *.addthis.com *.addthisedge.com *.moatads.com *.mouseflow.com *.facebook.com *.what3words.com maps.googleapis.com commerce.adobedtm.com magento-recs-sdk.adobe.net static.zdassets.com app.mobicredwidget.co.za www.gstatic.com connect.facebook.net bam.nr-data.net js.testfreaks.com media.flixfacts.com media.flixcar.com security-hub.vaimo.network https://js.klevu.com 'self' 'unsafe-inline' 'unsafe-eval'; 1 font-src fonts.gstatic.com use.typekit.net *.googleapis.com *.gstatic.com 'self' data: 'unsafe-inline' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.adyen.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.google.com www.googletagmanager.com *.adyen.com widgets.sandbox.afterpay.com widgets.sandbox.clearpay.co.uk *.sharethis.com platform.cloud-iq.com.au *.facebook.com *.doubleclick.net *.bedbathntable.com.au *.criteo.com *.pinterest.com *.dotdigital-pages.com *.dotdigital.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com zip.co sandbox.zip.co zipmoney.com.au sandbox.zipmoney.com.au checkout.gb.zip.co checkout.quadpay.com checkout-sandbox.quadpay.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.ftcdn.net *.behance.net *.adyen.com https://static.afterpay.com https://site-assets.afterpay.com/ *.sharethis.com *.googleapis.com *.gstatic.com dev.visualwebsiteoptimizer.com *.google.com *.facebook.com *.cloud-iq.com.au *.afterpay.com *.linksynergy.com *.google.com.au *.bedbathntable.com.au bbnt-m2-image-library.s3-ap-southeast-2.amazonaws.com *.cdninstagram.com *.google.lk *.doubleclick.net *.bidswitch.net *.adnxs.com *.smartadserver.com *.taboola.com *.socdm.com *.criteo.com *.casalemedia.com *.dable.io *.adingo.jp *.stickyadstv.com *.360yield.com *.rlcdn.com *.media.net *.bing.com *.yieldmo.com *.aralego.com *.3lift.com *.clmbtech.com *.teads.tv *.smaato.net *.rubiconproject.com *.pubmatic.com *.outbrain.com *.aralego.net *.1rx.io *.bluekai.com *.contextweb.com *.unrulymedia.com *.trackedlink.net *.ddlnk.net www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com t.zip.co static.zipmoney.com.au data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.gstatic.com *.google.com www.googletagmanager.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.adyen.com https://portal.sandbox.clearpay.co.uk https://portal.clearpay.co.uk https://portal.sandbox.afterpay.com https://portal.afterpay.com https://static.afterpay.com https://js.sandbox.afterpay.com https://js.afterpay.com *.sharethis.com *.googleapis.com applepay.cdn-apple.com dev.visualwebsiteoptimizer.com *.afterpay.com *.newrelic.com cdnjs.cloudflare.com bam-cell.nr-data.net platform.cloud-iq.com.au *.crazyegg.com *.facebook.net *.facebook.com *.rakuten.com googleads.g.doubleclick.net cdn.lr-ingest.io *.foursixty.com *.bedbathntable.com.au *.tiktok.com *.pinimg.com *.criteo.com *.pinterest.com *.freshworks.net *.freshworks.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com static.zipmoney.com.au zip.co https://www.bedbathntable.com.au 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com static.afterpay.com/ js.sandbox.afterpay.com js.afterpay.com *.sharethis.com unpkg.com *.foursixty.com *.bedbathntable.com.au *.cloud-iq.com.au *.use.typekit.net *.p.typekit.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.adyen.com static.afterpay.com static.sandbox.afterpay.com js.sandbox.afterpay.com js.afterpay.com *.sharethis.com *.googleapis.com *.crazyegg.com googleads.g.doubleclick.net bam-cell.nr-data.net *.lr-ingest.io *.foursixty.com *.google-analytics.com *.doubleclick.net *.bedbathntable.com.au *.nr-data.net foursixty.com *.pinterest.com *.pangle-ads.com *.tiktok.com *.criteo.com *.google.com *.freshworks.net *.freshworks.com *.attraqt.io *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 frame-ancestors 'self'; report-uri https://www.kidspot.com.au/csp-reports 1 default-src 'self'; script-src 'self' https://ddwl4m2hdecbv.cloudfront.net https://b-code.liadm.com https://rp.liadm.com https://idx.liadm.com; connect-src 'self' https://pro.ip-api.com https://alocdn.com https://*.liadm.com https://9xgnrndqve.execute-api.us-west-2.amazonaws.com https://a.usbrowserspeed.com; img-src 'self' data:; style-src 'self' 'unsafe-inline'; 1 base-uri 'none'; object-src 'none'; script-src 'unsafe-inline' 'unsafe-eval' 'strict-dynamic' https: http: 'nonce-4i9qFNUiOZqCC0OGsmG7KA==' 1 worker-src blob:; font-src *.gstatic.com *.stape.io *.fontawesome.com https://fonts.gstatic.com https://www.google.com https://www.gstatic.com https://widgets.trustedshops.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ https://www.google.com/ *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.googletagmanager.com *.stape.io secure.pay1.de payments.amazon.de jsctool.com www.jsctool.com js.playground.klarna.com *.weltpixel.com https://secure.pay1.de/ 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://www.google.com/ https://www.google.de/ https://www.trustedshops.de/ magefan.com cm.magefan.com *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.gstatic.com *.doubleclick.net *.googletagmanager.com *.stape.io https://www.magezon.com cdn.pay1.de x.klarnacdn.net *.cloudfront.net m.media-amazon.com static-eu.payments-amazon.com d.ratepay.com https://widgets.trustedshops.com https://products.ki-demo.ovh https://tedox.ki-test.ovh blob: https://widgets-qa.trustedshops.com https://app.usercentrics.eu/ https://legal-images.trustedshops.com/ https://maps.googleapis.com/ https://maps.gstatic.com/ https://www.trustedshops.com/ https://integrations.etrusted.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ http://widgets.trustedshops.com/ https://widgets.trustedshops.com/ https://www.google-analytics.com/ https://www.google.com/ https://www.gstatic.com/ *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.gstatic.com *.googletagmanager.com *.doubleclick.net *.stape.io *.googleapis.com secure.pay1.de d.ratepay.com static-eu.payments-amazon.com x.klarnacdn.net cdn.klarna.com jsctool.com d.payla.io www.jsctool.com https://products.ki-demo.ovh https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com https://www.googletagmanager.com https://www.google-analytics.com https://web.cmp.usercentrics.eu https://privacy-proxy.usercentrics.eu https://app.usercentrics.eu/ https://secure.pay1.de/ https://www.googletagmanager.com/ 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.googleapis.com *.googletagmanager.com *.stape.io *.fontawesome.com *.google.com *.gstatic.com d.ratepay.com d.payla.io dr.payla.io https://products.ki-demo.ovh https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com https://integrations.etrusted.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://payments.amazon.de/ http://widgets.trustedshops.com/ https://widgets.trustedshops.com/ https://www.google-analytics.com/ https://stats.g.doubleclick.net/ *.google-analytics.com *.google.com *.doubleclick.net *.googlesyndication.com *.stape.io http://dpm.demdex.net https://www.google.com https://www.gstatic.com payments.amazon.de payments-eu.amazon.com d.ratepay.com jsctool.com eu.playground.klarnaevt.com www.jsctool.com https://products.ki-demo.ovh https://produkte.ki-trade.org *.trustedshops.com *.etrusted.com https://integrations.etrusted.site https://privacy-proxy.usercentrics.eu https://v1.api.service.cmp.usercentrics.eu https://consent-api.service.consent.usercentrics.eu https://aggregator.service.usercentrics.eu/ https://api.usercentrics.eu/ https://graphql.usercentrics.eu/ https://maps.googleapis.com/ https://region1.google-analytics.com/ 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.googleapis.com *.gstatic.com *.fontawesome.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * api.bazaarvoice.com stg.api.bazaarvoice.com *.authorize.net 'self' 'unsafe-inline'; frame-ancestors *.certcapture.com *.authorize.net 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.affirm.com *.affirm.ca *.certcapture.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com *.authorize.net *.wesupply.xyz https://wesupplylabs.com *.weltpixel.com https://*.online-metrix.net https://imgs.signifyd.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io *.ftcdn.net *.behance.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.googleapis.com *.gstatic.com *.affirm.com *.affirm.ca *.certcapture.com display.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com network-a.bazaarvoice.com network-stg-a.bazaarvoice.com photos-uat-us.bazaarvoice.com img.youtube.com services.postcodeanywhere.co.uk https://firebasestorage.googleapis.com https://imgs.signifyd.com https://*.online-metrix.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googleapis.com *.gstatic.com *.affirm.com *.affirm.ca *.certcapture.com apps.bazaarvoice.com apps.nexus.bazaarvoice.com apps-stg.nexus.bazaarvoice.com analytics-static.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com mpsnare.iesnare.com api.addressy.com *.avada.io *.authorize.net *.cloudflare.com https://cdn-scripts.signifyd.com https://imgs.signifyd.com https://h64.online-metrix.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com assets.braintreegateway.com *.certcapture.com display.ugc.bazaarvoice.com api.addressy.com *.fontawesome.com https://fonts.bunny.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.googleapis.com *.affirm.com *.affirm.ca *.certcapture.com api.bazaarvoice.com stg.api.bazaarvoice.com apps.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com api.addressy.com https://get.geojs.io *.avada.io *.authorize.net https://imgs.signifyd.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com *.certcapture.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src none blob: data: gap:; script-src 'self' 'nonce-xySiOSIO0otu-6F-Q1mHSn_GhnDSsQ6a1M-bKPPa2yxARx0GvCVaRQ' 'strict-dynamic' https://www.utrecht.nl https://www.utrecht.nl.internal https://accept.utrecht.typocloud.nl data: https://virtuele-gemeente-assistent.nl https://siteimproveanalytics.com https://cdn-eu.readspeaker.com formulieren.digitaal.utrecht.nl stats.utrecht.nl 'report-sample'; style-src-attr 'unsafe-inline' 'report-sample'; img-src 'self' data: *.ytimg.com *.vimeocdn.com https://translate.google.com https://stats.utrecht.nl https://www.toegankelijkheidsverklaring.nl https://nieuwsbrieven.utrecht.nl https://*.googleapis.com https://*.gstatic.com *.google.com *.googleusercontent.com https://web.archive.org *.6006206.global.siteimproveanalytics.io https://6006206.global.siteimproveanalytics.io/image.aspx https://www.utrecht.nl https://www.utrecht.nl.internal https://accept.utrecht.typocloud.nl https://*.siteimproveanalytics.io https://virtuele-gemeente-assistent.nl https://*.siteimproveanalytics.com; base-uri none; frame-src 'self' *.youtube-nocookie.com *.youtube.com *.vimeo.com https://kaarten.utrecht.onatlas.nl https://subsidie-checker.nl https://sdk.companywebcast.com https://infogram.com https://nieuwsbrieven.utrecht.nl *.google.com *.gu-geo.maps.arcgis.com https://infogram-download-eu.s3.eu-west-1.amazonaws.com https://app-eu.readspeaker.com https://sketchfab.com https://utrecht-kaarten-review-acc-skda4g.delta10-review.nl https://e.infogram.com https://vttts-eu.readspeaker.com https://www.utrecht.nl https://www.utrecht.nl.internal https://accept.utrecht.typocloud.nl https://www.youtube-nocookie.com; style-src-elem 'self' 'nonce-xySiOSIO0otu-6F-Q1mHSn_GhnDSsQ6a1M-bKPPa2yxARx0GvCVaRQ' https://formulieren.digitaal.utrecht.nl https://cdn-eu.readspeaker.com https://virtuele-gemeente-assistent.nl https://mijn.virtuele-gemeente-assistent.nl https://www.gstatic.com https://formulieren.digitaal.utrecht.nl/static/sdk/open-forms-sdk.css https://fonts.gstatic.com https://fonts.googleapis.com *.formulieren.digitaal.utrecht.nl *.mijn.virtuele-gemeente-assistent.nl *.virtuele-gemeente-assistent.nl https://virtuele-gemeente-assistent.nl/static/css/widget-v25.3.1-base.css https://virtuele-gemeente-assistent.nl/static/css/widget-v25.3.1-custom.css https://mijn.virtuele-gemeente-assistent.nl/utrecht/_styling https://cdn.honey.io/css/empty.css *.www.gstatic.com https://v.kcmg.nl/surveyembedding/assets/css/standard_controls_inline.css https://v.kcmg.nl/surveyembedding/assets/css/ng-survey.component.css https://v.kcmg.nl/surveyembedding/assets/css/bootstrapslider.css https://v.kcmg.nl/surveyembedding/assets/css/surveyjs-readded-csp-styles.css https://v.kcmg.nl https://v.kcmg.nl/surveyembedding/assets/css/surveyjs-defaultv2css@1.12.23/defaultV2.fontless.min.css *.v.kcmg.nl https://v.kcmg.nl/surveyembedding/assets/css/survey.component.css https://openstad-cdn.nl 'sha256-JQEHXnSrj4DJZ2DOwDDXtfkDs5+y7/1gFxshQP2KBoA=' https://*.utrecht.nl https://viewer.kcmg.nl 'report-sample'; connect-src 'self' https://public.pandosearch.com https://www.utrecht.nl wss://virtuele-gemeente-assistent.nl https://formulieren.digitaal.utrecht.nl *.google.com https://*.googleapis.com https://*.gstatic.com blob: data: https://translate.googleapis.com https://mijn.virtuele-gemeente-assistent.nl https://api.kcmg.nl https://viewerapi.kcmg.nl/StartSurvey https://viewerapi.kcmg.nl *.viewerapi.kcmg.nl https://api.utrecht.openstad.dev *.obi4wan.com *.readspeaker.com *.pandosearch.com https://stats.utrecht.nl https://chatapi.obi4wan.com/api https://cloudstatic.obi4wan.com/api https://virtuele-gemeente-assistent.nl wss://virtuele-gemeente-assistent.nl/socket.io/ wss://ws-eu.pusher.com/app https://cdn-eu.readspeaker.com; font-src 'self' https://formulieren.digitaal.utrecht.nl https://www.utrecht.nl https://fonts.gstatic.com https://v.kcmg.nl/surveyembedding/assets/webfonts/fa-brands-400.ttf https://v.kcmg.nl/surveyembedding/assets/webfonts/fa-regular-400.woff https://v.kcmg.nl/surveyembedding/assets/webfonts/fa-solid-900.woff https://v.kcmg.nl/surveyembedding/assets/webfonts/fa-regular-400.ttf https://v.kcmg.nl/surveyembedding/assets/webfonts/fa-regular-400.svg https://v.kcmg.nl/surveyembedding/assets/webfonts/fa-brands-400.eot https://v.kcmg.nl/surveyembedding/assets/webfonts/Radnika-Medium.otf https://v.kcmg.nl/surveyembedding/assets/webfonts/fa-solid-900.svg https://v.kcmg.nl/surveyembedding/assets/webfonts/fa-solid-900.woff2 https://v.kcmg.nl/surveyembedding/assets/webfonts/fa-regular-400.woff2 https://v.kcmg.nl/surveyembedding/assets/webfonts/fa-solid-900.eot https://v.kcmg.nl/surveyembedding/assets/webfonts/fa-solid-900.ttf https://v.kcmg.nl/surveyembedding/assets/webfonts/fa-brands-400.woff2 https://v.kcmg.nl *.v.kcmg.nl https://openstad-cdn.nl https://cdn.faceworks.nl data: https://cdn-eu.readspeaker.com; script-src-elem 'self' 'nonce-xySiOSIO0otu-6F-Q1mHSn_GhnDSsQ6a1M-bKPPa2yxARx0GvCVaRQ' https://stats.utrecht.nl https://formulieren.digitaal.utrecht.nl https://virtuele-gemeente-assistent.nl https://siteimproveanalytics.com https://e.infogram.com https://infogram.com 'strict-dynamic' https: 'unsafe-eval' blob: https://www.utrecht.nl https://formulieren.digitaal.utrecht.nl/static/sdk/open-forms-sdk.js *.virtuele-gemeente-assistent.nl https://www.utrecht.nl/templates/js/wijkvoorkeuren-wijzigen.js https://www.utrecht.nl/templates/js/eventtracking.js *.www.utrecht.nl https://www.utrecht.nl/fileadmin/open-forms.js https://virtuele-gemeente-assistent.nl/static/js/widget.js *.formulieren.digitaal.utrecht.nl https://www.utrecht.nl.internal https://accept.utrecht.typocloud.nl data: https://cdn-eu.readspeaker.com formulieren.digitaal.utrecht.nl stats.utrecht.nl https://viewer.kcmg.nl 'report-sample'; worker-src 'self' 'nonce-xySiOSIO0otu-6F-Q1mHSn_GhnDSsQ6a1M-bKPPa2yxARx0GvCVaRQ' blob:; style-src none blob: data: gap: 'self' *.obi4wan.com *.readspeaker.com https://www.utrecht.nl https://www.utrecht.nl.internal https://accept.utrecht.typocloud.nl https://redactie-acceptatie.utrecht.nl https://virtuele-gemeente-assistent.nl https://mijn.virtuele-gemeente-assistent.nl https://cdn-eu.readspeaker.com formulieren.digitaal.utrecht.nl 'report-sample'; form-action 'self' https://action.spike.email https://app-eu.readspeaker.com; media-src none blob: data: gap: https://app-eu.readspeaker.com https://cdn-eu.readspeaker.com https://vttts-eu.readspeaker.com; object-src none; report-uri https://www.utrecht.nl/@http-reporting?csp=report&requestTime=1770427253531589&requestHash=f6b188840c5c1d73b8d11f7900846987812db8a9 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://analytics-eu.clickdimensions.com https://www.googletagmanager.com https://maps.googleapis.com https://www.jscache.com https://www.youtube.com https://www.google.com https://www.riddle.com https://p.teads.tv https://webservices.data-8.co.uk https://www.eventbrite.co.uk https://connect.facebook.net https://acdn.adnxs.com https://c0.adalyser.com https://static.hotjar.com https://script.hotjar.com https://k.r66net.com https://www.tripadvisor.com https://www.tripadvisor.co.uk https://static.tacdn.com; style-src 'self' 'unsafe-inline' https://use.typekit.net https://p.typekit.net https://cdnjs.cloudflare.com https://webservices.data-8.co.uk https://static.tacdn.com https://fonts.googleapis.com; img-src 'self' data: https://ntswebstorage01.blob.core.windows.net https://www.tripadvisor.co.uk https://ciim-data.nts.org.uk https://nts-production.imgix.net https://nts-staging-test.imgix.net https://t.teads.tv https://ib.adnxs.com https://www.facebook.com https://maps.gstatic.com https://maps.googleapis.com; font-src 'self' https://www.nts.org.uk https://use.typekit.net https://static.tacdn.com https://fonts.gstatic.com; connect-src 'self' https://maps.googleapis.com https://googleads.g.doubleclick.net https://ciim-data.nts.org.uk https://analytics-eu.clickdimensions.com https://nts-production.imgix.net https://p.typekit.net https://use.typekit.net https://*.hotjar.com wss://*.hotjar.com; frame-src 'self' https://www.youtube.com https://www.youtube-nocookie.com https://www.googletagmanager.com https://www.riddle.com https://w.soundcloud.com https://*.doubleclick.net https://*.hotjar.com https://www.eventbrite.co.uk media-src 'self' https://ntswebstorage01.blob.core.windows.net; object-src 'none'; frame-ancestors 'self'; base-uri 'self'; form-action 'self'; 1 object-src 'none'; base-uri 'self'; script-src 'self' 'nonce-5Fx7WE8kblYUSMz0dUKawg' 'unsafe-inline' 'unsafe-eval' https://*.msauth.net https://*.msftauth.net https://*.msftauthimages.net https://*.msauthimages.net https://*.msidentity.com https://*.microsoftonline-p.com https://*.microsoftazuread-sso.com https://*.azureedge.net https://*.outlook.com https://*.office.com https://*.office365.com https://*.microsoft.com https://*.bing.com 'report-sample'; report-uri https://csp.microsoft.com/report/ESTS-UX-All 1 default-src 'self'; script-src 'unsafe-eval' 'strict-dynamic' 'nonce-AhJpnTjrtjqqlH+MH4Gblw=='; style-src 'self' 'unsafe-inline' dev-hellowork.com *.dev-hellowork.com; img-src 'self' data: f.maformation.fr hellowork.com *.hellowork.com dev-hellowork.com *.dev-hellowork.com googletagmanager.com *.googletagmanager.com google.com *.google.com *.google.fr googlesyndication.com *.googlesyndication.com linkedin.com *.linkedin.com *.ads.linkedin.com *.bing.com *.facebook.com *.facebook.net *.smartadserver.com *.bidswitch.net *.doubleclick.net *.casalemedia.com *.criteo.com id5-sync.com *.id5-sync.com *.360yield.com *.media.net *.mediavine.com *.postrelease.com *.outbrain.com *.pubmatic.com *.rubiconproject.com *.teads.tv *.tremorhub.com *.3lift.com *.yieldlab.net *.1rx.io *.demdex.net *.unrulymedia.com *.agkn.com *.taboola.com *.dmxleo.com; font-src 'self'; connect-src 'self' *.clarity.ms hellowork.com *.hellowork.com dev-hellowork.com *.dev-hellowork.com hellowork-group.com *.hellowork-group.com infra-hellowork.com *.infra-hellowork.com regionsjob.com *.regionsjob.com google.com *.google.com googletagmanager.com *.googletagmanager.com googlesyndication.com *.googlesyndication.com googleadservices.com *.googleadservices.com abtasty.com *.abtasty.com aticdn.net *.aticdn.net bing.com *.bing.com linkedin.com *.linkedin.com facebook.com *.facebook.com *.tiktok.com analytics-ipv6.tiktokw.us *.skeepers.io *.doubleclick.net trustindex.io *.trustindex.io; frame-src youtube-nocookie.com *.youtube-nocookie.com dailymotion.com *.dailymotion.com player.vimeo.com *.player.vimeo.com googletagmanager.com *.googletagmanager.com google.com *.google.com criteo.com *.criteo.com *.criteo.net *.doubleclick.net facebook.com *.facebook.com; object-src 'none'; base-uri 'self'; form-action 'self' https://www.facebook.com; frame-ancestors 'none'; report-to csp-endpoint; report-uri /csp-report 1 font-src *.googleapis.com *.gstatic.com data: *.fontawesome.com 'self' data: *.tawk.to fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.tawk.to *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.innoship.ro https://www.googletagmanager.com/ *.wesupply.xyz https://wesupplylabs.com s.pinimg.com ct.pinterest.com consentcdn.cookiebot.com *.weltpixel.com *.tawk.to https://b2d.springfarma.com/ https://consentcdn.cookiebot.eu/ *.creativecdn.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.gstatic.com *.googleapis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.tbicp.com *.tile.openstreetmap.org *.openstreetmap.org http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ t.themarketer.com cdn1.themarketer.com *.hsforms.net *.hsforms.com 'self' data: www.google.ro/ads www.facebook.com/tr analytics.tiktok.com *.google-analytics.com *.analytics.google.com s.pinimg.com ct.pinterest.com www.google.com.ua *.tawk.to cdn.jsdelivr.net *.facebook.com *.omnitagjs.com *.google.ro https://b2d.springfarma.com *.adnxs.com *.mktr2.com *.doubleclick.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.googleapis.com *.gstatic.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.tbicp.com https://scripts.luigisbox.com https://cdn.luigisbox.com https://live.luigisbox.com https://api.luigisbox.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ *.avada.io t.themarketer.com cdn1.themarketer.com *.hsforms.net *.hsforms.com www.google.ro attr-2p.com cdnjs.cloudflare.com retargeting.newsmanapp.com analytics.tiktok.com https://connect.facebook.net s.pinimg.com ct.pinterest.com consent.cookiebot.com *.tawk.to cdn.jsdelivr.net https://www.googletagmanager.com tagmanager.google.com *.facebook.net unpkg.com *.cloudflareinsights.com *.clarity.ms *.newrelic.com *.cookiebot.eu *.creativecdn.com https://b2d.springfarma.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com https://scripts.luigisbox.com https://cdn.luigisbox.com https://live.luigisbox.com https://api.luigisbox.com t.themarketer.com cdn1.themarketer.com *.googleapis.com *.gstatic.com *.tawk.to cdn.jsdelivr.net tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ *.mktr2.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.googleapis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://scripts.luigisbox.com https://cdn.luigisbox.com https://live.luigisbox.com https://api.luigisbox.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ https://get.geojs.io *.avada.io t.themarketer.com cdn1.themarketer.com c1api.themarketer.com c2api.themarketer.com c3api.themarketer.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com https://connect.facebook.net analytics.tiktok.com *.analytics.google.com s.pinimg.com ct.pinterest.com *.tawk.to wss://*.tawk.to *.facebook.net https://www.google.com https://ams.creativecdn.com https://bam.eu01.nr-data.net *.nr-data.net *.cookiebot.eu *.clarity.ms *.googlesyndication.com *.tiktokw.us https://b2d.springfarma.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.googleapis.com fonts.gstatic.com *.gstatic.com https://d22j4fzzszoii2.cloudfront.net *.typekit.net https://cdnjs.cloudflare.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.adyen.com pay.google.com payments-eu.amazon.com payments.amazon.de * 'self' 'unsafe-inline'; frame-ancestors *.certcapture.com *.palaisdesthes.com *.palaisdesthes.co.uk 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.adyen.com pay.google.com *.paypal.com *.sharethis.com *.certcapture.com * https://www.googletagmanager.com/ 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.adyen.com pay.google.com *.payments-amazon.com *.media-amazon.com *.paypalobjects.com *.sharethis.com *.certcapture.com a.tile.openstreetmap.org b.tile.openstreetmap.org c.tile.openstreetmap.org *.openstreetmap.org maps.googleapis.com maps.gstatic.com *.agkn.com *.360yield.com *.3lift.com *.abtasty.com *.adform.net *.adnxs.com *.avis-verifies.com *.bidswitch.net *.bing.com *.bing.net *.casalemedia.com *.clarity.ms *.criteo.com *.criteo.net *.doubleclick.net *.emxdgt.com *.exelator.com *.facebook.com *.google.fr *.google.ch *.googleapis.com *.gstatic.com *.rlcdn.com *.ivitrack.com *.klarna.com *.media.net *.mediavine.com *.mmtro.com https://mmtro.com *.omnitagjs.com *.outbrain.com *.palaisdesthes.com *.palaisdesthes.co.uk *.pubmatic.com *.rubiconproject.com *.sharethrough.com *.smaato.net *.smartadserver.com *.stickyadstv.com *.taboola.com *.teads.tv *.weborama.fr *.yahoo.com *.yieldlab.net *.yieldmo.com *.zebestof.com *.zdassets.com *.zendesk.com *.adscale.de *.id5-sync.com https://id5-sync.com *.liadm.com *.smartclip.net *.tremorhub.com *.krxd.net *.thebrighttag.com *.amazon-adsystem.com *.contentsquare.net *.privacy-center.org *.postrelease.com *.sc-trc.com *.surveyjs.io *.1rx.io *.join-stories.com *.parcellab.com *.opecloud.com *.zopim.io https://shareasale.com *.google.com *.unrulymedia.com *.hsforms.com *.hubspot.com *.hscollectedforms.net *.adsrvr.org www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com *.paypal.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ https://redchamps.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ *.google.com *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com https://rum.hlx.page *.sharethis.com *.googleapis.com *.certcapture.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com https://widgets.rr.skeepers.io/ https://api-product-reviews.cxr.skeepers.io/ https://cl-ppr.rr.skeepers.io/ https://cl-pbr.cxr.skeepers.io/ *.abtasty.com *.acdn.adnxs.com *.avtm.fr *.amazon-adsystem.com *.bing.com *.bing.net *.capadresse.com ws2.capadresse.com:7455 ws2.capadresse.com:7456 *.clarity.ms *.criteo.com *.criteo.net *.doubleclick.net *.effiliation.com *.facebook.net *.mmtro.com https://mmtro.com *.privacy-center.org *.static-sb.com *.tradedoubler.com *.zdassets.com *.zendesk.com *.mouseflow.com *.servedby.flashtalking.com https://servedby.flashtalking.com *.secure.adnxs.com/ https://secure.adnxs.com/ *.tag.zebestof.com https://tag.zebestof.com *.contentsquare.com *.contentsquare.net *.thank-you.io *.tiktok.com *.palaisdesthes.com *.palaisdesthes.co.uk *.optimalpeople.fr https://d16fk4ms6rqz1v.cloudfront.net *.dwin1.com *.skeepers.io *.surveyjs.io *.amcharts.com *.parcellab.com *.zopim.io *.adnxs.com *.hsforms.net *.hs-scripts.com *.hs-banner.com *.hscollectedforms.net *.hs-analytics.net *.billetweb.fr *.brevo.com https://sibautomation.com *.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com p.teads.tv google.com recaptcha.net http://www.googletagmanager.com/ https://www.googletagmanager.com/ palais-des-thes.my.join-stories.com *.get-potions.com https://cdnjs.cloudflare.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.sharethis.com *.certcapture.com fonts.googleapis.com unpkg.com fonts.gstatic.com *.parcellab.com assets.braintreegateway.com *.typekit.net https://fonts.googleapis.com https://cdnjs.cloudflare.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.zdassets.com *.zendesk.com *.join-stories.com *.zopim.io blob: http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.youtube.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adyen.com *.google.com google.com payments-eu.amazon.com *.paypal.com *.sharethis.com *.googleapis.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io *.certcapture.com maps.googleapis.com https://widgets.rr.skeepers.io/ https://api-product-reviews.cxr.skeepers.io/ https://cl-ppr.rr.skeepers.io/ https://cl-pbr.cxr.skeepers.io/ *.abtasty.com *.clarity.ms *.analytics.google.com *.googlesyndication.com *.palaisdesthes.com *.palaisdesthes.co.uk *.privacy-center.org *.social-sb.com *.zendesk.com *.zopim.io wss://widget-mediator.zopim.com *.mouseflow.com *.zdassets.com *.contentsquare.net *.thank-you.io *.tiktok.com *.zebestof.com *.doubleclick.net *.optimalpeople.fr *.criteo.com *.salecycle.com wss://ws.salecycle.com *.surveyjs.io http://127.0.0.1:63342 *.bing.com *.bing.net *.stories.studio *.parcellab.com *.algolia.io *.adnxs.com *.hsforms.com *.s3.amazonaws.com *.hscollectedforms.net *.hubspot.com *.skeepers.io *.brevo.com *.braintreegateway.com *.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.join-stories.com *.teads.tv http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ www.googleapis.com 'self' 'unsafe-inline'; child-src *.certcapture.com assets.braintreegateway.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 require-trusted-types-for 'script'; report-uri https://csp.withgoogle.com/csp/uxe-owners-acl/tv_google 1 report-uri https://csp.withgoogle.com/csp/youtube_main/strict;base-uri 'self';object-src 'none';script-src 'report-sample' 'nonce-cVSUIAOTELjPCudz8jHkjQ' 'unsafe-inline' 'strict-dynamic' https: http: 'unsafe-eval' 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://ajax.cloudflare.com https://*.migracion.gob.do https://cdn.userway.org https://eticket.migracion.gob.do https://personal.migracion.gob.do https://cdn.jsdelivr.net https://connect.facebook.net https://www.google-analytics.com https://challenges.cloudflare.com https://static.cloudflareinsights.com; worker-src https://migracion.gob.do blob:; style-src 'self' 'unsafe-inline' https://cdn.userway.org https://fonts.googleapis.com https://cdn.jsdelivr.net; font-src 'self' https://cdn.userway.org https://fonts.gstatic.com https://cdn.jsdelivr.net; media-src https://cdn.userway.org; img-src 'self' https://secure.gravatar.com https://s.w.org https://a.tile.openstreetmap.org https://b.tile.openstreetmap.org https://c.tile.openstreetmap.org data: https://cdn.userway.org https://*.migracion.gob.do https://cdn.jsdelivr.net https://www.google-analytics.com; connect-src 'self' https://cdn.userway.org https://api.userway.org https://*.migracion.gob.do https://www.google-analytics.com https://challenges.cloudflare.com; frame-src 'self' https://cdn.userway.org https://www.facebook.com https://www.youtube.com https://be.nortic.ogtic.gob.do https://eticket.migracion.gob.do https://challenges.cloudflare.com; object-src 'self'; base-uri 'self'; form-action 'self' https://*.migracion.gob.do; frame-ancestors 'self'; upgrade-insecure-requests; block-all-mixed-content; report-uri https://report-uri.migracion.gob.do/api/reports; report-to csp-endpoint; 1 script-src 'self' 'unsafe-eval' 'unsafe-inline' *.vercel.app *.uxuy.one *.uxuy.com *.uxuy.me www.googletagmanager.com; worker-src blob: 'self' *.vercel.app *.uxuy.one *.uxuy.com; object-src 'none'; 1 default-src 'self' https: *.channel.io *.channel.app *.cdninstagram.com; font-src 'self' https: data:; img-src 'self' https: data: blob: https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com *.channel.io *.cdninstagram.com *.with.is; object-src 'none'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://js.stripe.com https://connect.facebook.net https://platform.twitter.com https://cdn.jsdelivr.net https://*.googletagmanager.com https://www.google-analytics.com *.channel.io *.sentry-cdn.com https://static.ads-twitter.com https://js-agent.newrelic.com *.with.is; style-src 'self' https: 'unsafe-inline'; connect-src 'self' https://api.stripe.com https://analytics.twitter.com https://www.facebook.com https://support.with.is *.channel.io *.channel.app *.sentry.io wss://*.channel.io wss://*.desk-ws.channel.io wss://*.front-ws.channel.io https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://*.g.doubleclick.net https://*.google.co.jp https://*.google.com wss://ntjp.mieru-ca.com https://bam.nr-data.net *.with.is; frame-src 'self' https://js.stripe.com https://www.facebook.com https://www.youtube.com https://cdn.d2-apps.net https://10252404.fls.doubleclick.net https://www.google.com https://with-1923.firebaseapp.com; report-uri /csp-violation-report 1 default-src 'self' https://*.mziq.com; script-src-elem 'self' https://*.mziq.com 'sha256-kQ7PZqRD+DW+OLPgGpzeit+ne5Q32Q7r0bNZq//y0Rw=' 'sha256-2L+nOGxRAxUhUjVdJf/7Wl9Y9CJvuXyNSb7gUk9APMU=' https://www.googletagmanager.com https://*.tinymce.com https://*.tiny.cloud; style-src 'self' 'unsafe-inline' https://*.mziq.com https://fonts.googleapis.com https://fonts.gstatic.com https://*.tinymce.com https://*.tiny.cloud; style-src-elem 'self' 'unsafe-inline' https://*.mziq.com https://fonts.googleapis.com https://fonts.gstatic.com https://*.tinymce.com https://*.tiny.cloud; font-src 'self' data: https://*.mziq.com https://fonts.googleapis.com https://fonts.gstatic.com https://*.tinymce.com https://*.tiny.cloud; connect-src 'self' https://*.mziq.com wss://*.mziq.com https://www.google.com https://www.google.com.br https://analytics.google.com https://www.google-analytics.com https://*.tinymce.com https://*.tiny.cloud https://mz-prd-pub-filemanager-external.s3.us-east-1.amazonaws.com https://mz-prd-pub-mziq-cdn.s3.us-east-1.amazonaws.com https://browser-intake-datadoghq.com blob:; img-src 'self' data: polygon: https://*.mziq.com https://www.google.com https://www.google.com.br https://*.tinymce.com https://*.tiny.cloud blob:; object-src 'none'; base-uri 'self'; report-uri https://csp-report.mziq.com/csp-report; report-to csp-endpoint; 1 report-uri /csp-report-endpoint.php 1 font-src https://*.hotjar.com https://*.fontawesome.com maxcdn.bootstrapcdn.com *.yotpo.com *.googleapis.com *.gstatic.com data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net pilot-payflowlink.paypal.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com testsecureacceptance.cybersource.com secureacceptance.cybersource.com 0merchantacsstag.cardinalcommerce.com merchantacs.cardinalcommerce.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com 'self' 'unsafe-inline'; frame-src fast.amc.demdex.net *.adobe.com secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.googletagmanager.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.online-metrix.net testflex.cybersource.com flex.cybersource.com testsecureacceptance.cybersource.com secureacceptance.cybersource.com pay.google.com sandbox.secure.checkout.visa.com secure.checkout.visa.com thm.visa.com sandbox.src.mastercard.com merchantacs.cardinalcommerce.com 0merchantacsstag.cardinalcommerce.com business.facebook.com landofcoder.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.paypal.com *.sandbox.paypal.com *.paypalobjects.com api-static.mercadopago.com *.doubleclick.net http://*.twitter.com https://maps.googleapis.com https://maps.gstatic.com *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com www.gstatic.com sandbox.secure.checkout.visa.com secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com assets.secure.checkout.visa.com thm.visa.com https://facebook.com business.facebook.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com https://*.paypal.com *.sandbox.paypal.com https://*.paypalobjects.com https://assets.adobedtm.com https://amcglobal.sc.omtrdc.net https://dpm.demdex.net https://cm.everesttech.net https://*.adobe.com https://widgets.magentocommerce.com https://t.paypal.com https://fpdbs.paypal.com https://fpdbs.sandbox.paypal.com https://*.ftcdn.net https://*.behance.net https://*.vimeocdn.com https://i.ytimg.com https://d3sbl0c71oxeok.cloudfront.net https://dhkkzdfmpzvap.cloudfront.net https://d2bpzs5y44q6e0.cloudfront.net https://d37shgu97oizpd.cloudfront.net https://d1zlqll3enr74n.cloudfront.net https://d1jynp0fpwn93a.cloudfront.net https://d2cb3tokgpwh3v.cloudfront.net https://d1re8bfxx3pw6e.cloudfront.net https://d35u8xwkxs8vpe.cloudfront.net https://d13s9xffygp5o.cloudfront.net https://d388nbw0dwi1jm.cloudfront.net https://d11p2vtu3dppaw.cloudfront.net https://d3r89hiip86hka.cloudfront.net https://dc7snq0c8ipyk.cloudfront.net https://d5c7kvljggzso.cloudfront.net https://d2h8yg3ypfzua1.cloudfront.net https://d1b556x7apj5fb.cloudfront.net https://draz1ib3z71v2.cloudfront.net https://dr6hdp4s5yzfc.cloudfront.net https://d2bomicxw8p7ii.cloudfront.net https://d3aypcdgvjnnam.cloudfront.net https://d2a3iuf10348gy.cloudfront.net https://*.ssl-images-amazon.com https://*.ssl-images-amazon.co.uk https://*.ssl-images-amazon.co.jp https://*.ssl-images-amazon.it https://*.ssl-images-amazon.fr https://*.ssl-images-amazon.es https://*.ssl-images-amazon.de https://*.media-amazon.com https://*.media-amazon.co.uk https://*.media-amazon.co.jp https://*.media-amazon.it https://*.media-amazon.fr https://*.media-amazon.es https://*.media-amazon.de https://www.facebook.com https://connect.facebook.net https://graph.facebook.com https://business.facebook.com https://sandbox.secure.checkout.visa.com https://secure.checkout.visa.com https://sandbox-assets.secure.checkout.visa.com https://assets.secure.checkout.visa.com https://thm.visa.com https://cdn.aplazo.mx https://*.mercadopago.com https://*.mercadolivre.com https://*.mercadolibre.com https://*.mercadolibre.com.br https://*.mercadopago.com.br https://*.mlstatic.com https://*.mercadolivre.com.br https://*.mercadolibre.com.mx https://*.mercadolibre.com.ar https://*.mercadopago.com.mx https://b.stats.paypal.com https://dub.stats.paypal.com https://assets.braintreegateway.com https://c.paypal.com https://checkout.paypal.com https://*.sandbox.paypal.com https://*.yotpo.com https://*.steren.com.mx https://*.ocularsolution.com https://0.s3.envato.com https://*.hsforms.com https://*.hubspot.com/ https://bat.bing.com https://maps.googleapis.com https://maps.gstatic.com *.mercadolivre.com.br *.mercadolibre.com.mx *.mercadolibre.com.ar *.yotpo.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googletagmanager.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.online-metrix.net testflex.cybersource.com flex.cybersource.com pay.google.com x.klarnacdn.net sandbox.secure.checkout.visa.com secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com assets.secure.checkout.visa.com thm.visa.com sandbox.src.mastercard.com songbirdstag.cardinalcommerce.com business.facebook.com landofcoder.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.paypal.com *.sandbox.paypal.com *.paypalobjects.com *.bootstrapcdn.com https://*.hotjar.com https://*.fontawesome.com https://*.ocularsolution.com https://diffuser-cdn.app-us1.com https://*.liveperson.net https://*.omappapi.com http://js-na1.hs-scripts.com https://prism.app-us1.com http://*.twitter.com https://*.googleapis.com https://static.cloudflareinsights.com https://analytics.tiktok.com https://googleads.g.doubleclick.net https://calidad.steren.com.mx https://maps.googleapis.com https://maps.gstatic.com *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.paypal.com *.sandbox.paypal.com *.paypalobjects.com maxcdn.bootstrapcdn.com cdn.jsdelivr.net https://*.hotjar.com https://*.fontawesome.com https://use.fontawesome.com https://*.omappapi.com *.yotpo.com *.googleapis.com 'self' 'unsafe-inline'; object-src landofcoder.com 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com thm.visa.com business.facebook.com landofcoder.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.paypal.com *.sandbox.paypal.com *.paypalobjects.com https://*.hotjar.com https://*.hotjar.io wss://*.hotjar.com https://*.ocularsolution.com https://*.googleapis.com https://*.omappapi.com https://*.hubspot.com https://*.hscollectedforms.net https://bat.bing.com https://analytics.google.com https://analytics.tiktok.com *.yotpo.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src https:; connect-src https: wss:; font-src https: data:; frame-src https:; img-src https: data:; media-src https:; object-src https:; script-src 'unsafe-inline' 'unsafe-eval' https: data: blob:; style-src 'unsafe-inline' https:; report-uri https://www.check24.net/csp-violation-ezmd9dpdxv7nb0ecejb9/ 1 font-src *.bootstrapcdn.com *.trackcmp.net *.hotjar.com *.google-analytics.com *.nr-data.net *.typeform.com fonts.gstatic.com *.yotpo.com *.googleapis.com *.gstatic.com dhv2ziothpgrr.cloudfront.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.authorize.net https://plumrocket.com *.facebook.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors *.bolt.com *.authorize.net 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.bolt.com https://www.google.com/recaptcha/ www.googletagmanager.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.google.com *.authorize.net https://plumrocket.com *.hotjar.com *.addthis.com *.libsyn.com *.locally.com *.sheerid.com *.wayin.com *.newtonsoftware.com https://recruitingbypaycor.com/ *.curalate.com *.formstack.com *.trackcmp.net *.google-analytics.com *.nr-data.net data: *.typeform.com *.pagescdn.com *.yextpages.net *.googleapis.com *.weltpixel.com *.googletagmanager.com *.doubleclick.net *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com magefan.com cm.magefan.com store.paradoxlabs.com *.disqus.com *.google.com *.mageside.com mageside.com *.bc0a.com *.curalate.com *.s3.amazonaws.com *.amazonaws.com *.leupold.com *.googleapis.com *.gstatic.com *.trackcmp.net *.hotjar.com *.google-analytics.com *.nr-data.net *.typeform.com *.b0e8.com https://img.youtube.com maps.gstatic.com *.facebook.com *.reddit.com *.ads-twitter.com t.co *.twitter.com *.bing.com *.bing.net *.klaviyo.com *.pinterest.com *.pinimg.com *.clarity.ms *.googletagmanager.com *.doubleclick.net *.yotpo.com dhv2ziothpgrr.cloudfront.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.bolt.com *.commerce-quick-checkout.com http://localhost:8082 https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ polyfill.io www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://developer.adobe.com https://assets.armanet.us *.kaptcha.com *.disqus.com *.google.com *.gstatic.com *.authorize.net *.hotjar.com *.curalate.com *.app-us1.com *.avmws.com *.acsbapp.com acsbapp.com *.googleapis.com *.googletagmanager.com *.paypalobjects.com *.sheerid.com *.jsdelivr.net *.addthis.com *.addthisedge.com *.moatads.com *.cloudfront.net *.locally.com *.wayin.com *.activehosted.com *.newtonsoftware.com recruitingbypaycor.com *.leupold.com *.trackcmp.net *.google-analytics.com trackcmp.net *.vimeo.com *.apptrian.com *.facebook.com *.typeform.com *.sitescdn.net *.yextpages.net *.pagescdn.com *.b0e8.com *.bc0a.com *.googleadservices.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.bing.com *.clarity.ms *.klaviyo.com *.pinterest.com *.pinimg.com unpkg.com *.doubleclick.net *.yotpo.com dhv2ziothpgrr.cloudfront.net *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com d18eg7dreypte5.cloudfront.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.sheerid.com *.bootstrapcdn.com *.trackcmp.net *.hotjar.com *.google-analytics.com *.nr-data.net *.typeform.com *.sitescdn.net *.tagmanager.google.com *.googletagmanager.com fonts.googleapis.com *.yotpo.com *.googleapis.com dhv2ziothpgrr.cloudfront.net 'self' 'unsafe-inline'; object-src *.trackcmp.net *.hotjar.com *.google-analytics.com *.nr-data.net *.doubleclick.net *.typeform.com 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.bolt.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://srv.armanet.us https://assets.armanet.us *.kaptcha.com *.authorize.net *.bc0a.com *.hotjar.com wss://*.hotjar.com *.addthis.com *.googleapis.com *.acsbapp.com *.curalate.com *.hotjar.io *.trackcmp.net *.google-analytics.com *.g.doubleclick.net *.typeform.com *.pagescdn.com *.yext.com *.yext-pixel.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.pinterest.com *.pinimg.com *.doubleclick.net *.run.app *.yotpo.com dhv2ziothpgrr.cloudfront.net *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 base-uri https://*.adnami.io; worker-src blob: data:; form-action 'none' 1 script-src 'nonce-d5Z6pRl4YhpNvafZ1HdO3g==' 'self' cdn.orsted.com *.googletagmanager.com *.app.cookieinformation.com cdn.appdynamics.com *.googletagmanager.com *.gstatic.com *.googleoptimize.com www.googleadservices.com *.googleapis.com *.bing.com *.doubleclick.net *.t.co *.pardot.com *.youtube.com *.linkedin.com *.twitter.com *.globenewswire.com *.23video.com delivery.twentythree.com orsted.containers.piwik.pro orsted.piwik.pro *.crazyegg.com unpkg.com cs.lf-discover.com *.puzzel.com *.arcgis.com code.jquery.com *.lfeeder.com orsted-global-graduate-programme.simplecast.com omny.fm cdnjs.cloudflare.com *.bootstrapcdn.com *.defgo.com *.defgo.net *.vimeo.com presscloud.com *.ritzau.dk *.simplecast.com *.elnet.danskenergi.dk *.sli.do *.audioboom.com *.licdn.com *.adsrvr.org *.soundcloud.com *.google.com *.google.com.my *.google.nl *.google.dk *.facebook.net; style-src 'nonce-d5Z6pRl4YhpNvafZ1HdO3g==' 'self' cdn.orsted.com fonts.googleapis.com; style-src-attr 'unsafe-inline' cdn.orsted.com; img-src 'self' data: cdn.orsted.com *.azureedge.net *.youtube.com *.23video.com delivery.twentythree.com www.googletagmanager.com *.lfeeder.com *.linkedin.com *.doubleclick.net *.pardot.com; media-src 'self' blob: cdn.orsted.com *.youtube.com *.23video.com delivery.twentythree.com; font-src 'self' data: fonts.gstatic.com cdn.orsted.com; frame-src *.app.cookieinformation.com *.youtube.com *.23video.com delivery.twentythree.com *.google.com *.google.nl *.googletagmanager.com *.doubleclick.net *.pardot.com; connect-src *.app.cookieinformation.com *.euroland.com *.eum-appdynamics.com *.googletagmanager.com *.google.com *.doubleclick.net *.googleadservices.com *.crazyegg.com *.linkedin.com orsted.piwik.pro *.pardot.com; worker-src 'self'; 1 default-src 'self' https:; object-src 'none'; connect-src 'self' https: https://www.google-analytics.com https://www.googletagmanager.com; frame-src 'self' https: https://www.googletagmanager.com; img-src 'self' https: https://www.googletagmanager.com https://www.google-analytics.com https://ssl.gstatic.com https://www.gstatic.com data: blob:; style-src 'self' https: 'unsafe-inline' https://fonts.googleapis.com; font-src 'self' https: https://fonts.gstatic.com data:; script-src 'self' https: 'unsafe-eval' 'nonce-fkHiiMk1ufuu0Fwa9eS/+g=='; report-uri /csp_violations 1 font-src data: http://static-assets *.addgene.org https://fonts.gstatic.com 'self'; script-src https://tagmanager.google.com https://www.google.com https://*.googletagmanager.com https://js-agent.newrelic.com http://static-assets *.addgene.org https://www.googleadservices.com static.cloudflareinsights.com https://static.zdassets.com https://www.googletagmanager.com https://ajax.googleapis.com 'unsafe-inline' https://challenges.cloudflare.com https://googletagmanager.com https://assets.zendesk.com https://googleads.g.doubleclick.net 'self' https://widget.surveymonkey.com; img-src https://google.com https://*.google-analytics.com data: https://*.googletagmanager.com https://*.google.com https://ssl.gstatic.com https://www.google.com *.addgene.org http://static-assets https://i.ytimg.com https://*.g.doubleclick.net https://googleads.g.doubleclick.net https://*.analytics.google.com https://googletagmanager.com https://www.gstatic.com *.addgene.org.s3.amazonaws.com 'self'; style-src https://tagmanager.google.com http://static-assets *.addgene.org https://fonts.googleapis.com 'unsafe-inline' https://googletagmanager.com 'self'; connect-src https://*.google-analytics.com https://zendesk-eu.my.sentry.io https://*.googletagmanager.com https://*.google.com *.addgene.org https://ekr.zdassets.com cloudflareinsights.com https://*.g.doubleclick.net https://addgene.zendesk.com https://*.analytics.google.com *.nr-data.net 'self'; frame-src https://td.doubleclick.net *.addgene.org https://www.surveymonkey.com https://www.youtube.com https://www.googletagmanager.com https://challenges.cloudflare.com https://bid.g.doubleclick.net 'self'; default-src 'self' *.addgene.org; report-uri /csp-reporting/ 1 default-src 'self' *.wistia.com *.wistia.net embedwistia-a.akamaihd.net/ https://fonts.googleapis.com/; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://edge.fullstory.com https://rs.fullstory.com https://ajax.googleapis.com/ https://first.iovation.com/ https://mpsnare.iesnare.com/ https://128-koi-090.mktoresp.com/ *.gskydev.net *.gskydev.com https://auth.prod.greensky.com https://www.googleadservices.com https://googleads.g.doubleclick.net https://code.jquery.com https://cdn.jsdelivr.net https://pages.greenskycredit.com https://www.google.com/ https://www.gstatic.com https://cdnjs.cloudflare.com https://app-ab27.marketo.com https://munchkin.marketo.net https://abrtp1-cdn.marketo.com blob: http://static.site24x7rum.com https://www.googletagmanager.com https://www.google-analytics.com https://ssl.google-analytics.com *.wistia.com https://rtp-static.marketo.com https://abrtp1.marketo.com https://js.driftt.com; style-src 'self' 'unsafe-inline' https://cdnjs.cloudflare.com/ https://pages.greenskycredit.com/ https://cdn.jsdelivr.net/ https://www.greensky.com/ *.gskydev.com *.gskydev.net https://use.fontawesome.com/ https://pro.fontawesome.com/ https://rtp-static.marketo.com/ https://fonts.googleapis.com/ https://fonts.googleapis.com/css/ https://app-ab27.marketo.com/ https://munchkin.marketo.net; font-src 'self' https://cdnjs.cloudflare.com https://pro.fontawesome.com/ data: https://fonts.gstatic.com https://fast.wistia.com https://use.fontawesome.com; img-src 'self' https://www.googletagmanager.com https://rs.fullstory.com *.greensky.com/ *.gskydev.com/ *.gskydev.net/ https://embed-ssl.wistia.com data: https://www.google-analytics.com https://stats.g.doubleclick.net https://fast.wistia.com https://greensky.dotcmscloud.com https://*.greensky.dotcmscloud.com embedwistia-a.akamaihd.net/ https://embed-fastly.wistia.com http://embed.wistia.com/ https://www.google.com https://www.google.de https://app-ab27.marketo.com https://pages.greenskycredit.com; media-src 'self' blob: https://js.driftt.com; frame-src 'self' https://pages.greenskycredit.com/ https://app-ab27.marketo.com/ https://www.google.com/ https://js.driftt.com; connect-src 'self' https://analytics.google.com https://edge.fullstory.com https://rs.fullstory.com *.gskydev.com/ *.gskydev.net/ https://128-koi-090.mktoresp.com/ https://abrtp1.marketo.com https://*.google-analytics.com https://stats.g.doubleclick.net *.greensky.dotcmscloud.com https://greensky.dotcmscloud.com *.greensky.com *.litix.io embedwistia-a.akamaihd.net/ *.wistia.com https://128-koi-090.mktoresp.com; object-src 'self' https://app-ab27.marketo.com/ ; base-uri 'self';manifest-src 'self'; worker-src 'none'; report-to https://www.greensky.com 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'report-sample'; style-src 'self' 'unsafe-inline'; connect-src 'self' https:; img-src 'self' data: https:; font-src 'self' data:; frame-src 'self' https://www.googletagmanager.com https://www.google.com; report-uri https://proxy.csidetm.com/csp; report-to csp-endpoint; 1 frame-ancestors https://*.prace.cz https://my.teamio.com https://*.facebook.com https://*.jobs.cz https://*.topjobs.sk; report-uri /csp-reports/ 1 font-src *.bellamaison.com *.googletagmanager.com *.creativecdn.com *.jsdelivr.net *.personaclick.com *.segmentify.com *.cloudflareinsights.com *.googleapis.com *.gstatic.com *.newrelic.com *.nr-data.net *.fontawesome.com https://app.collectaction.com/ https://log.collectaction.com/ https://micro.collectaction.com/ *.alothemes.com *.magepow.com app.personaclick.com cdn.personaclick.com data: 'self' 'unsafe-inline'; form-action 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ *.bellamaison.com *.googletagmanager.com *.creativecdn.com *.jsdelivr.net *.personaclick.com *.segmentify.com *.cloudflareinsights.com *.googleapis.com *.gstatic.com *.newrelic.com *.nr-data.net https://app.collectaction.com/ https://log.collectaction.com/ https://micro.collectaction.com/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com app.personaclick.com cdn.personaclick.com 'self' 'unsafe-inline'; img-src data: widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.apptrian.com *.bellamaison.com *.googletagmanager.com *.creativecdn.com *.jsdelivr.net *.personaclick.com *.segmentify.com *.cloudflareinsights.com *.googleapis.com *.gstatic.com *.newrelic.com *.nr-data.net *.doubleclick.net *.facebook.com *.mncdn.org www.google.com.tr https://cdnydm.com/ https://cdn.dsmcdn.com/ https://app.collectaction.com/ https://log.collectaction.com/ https://micro.collectaction.com/ *.taggrs.io *.alothemes.com *.magepow.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com app.personaclick.com cdn.personaclick.com data: 'self' 'unsafe-inline'; script-src www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.apptrian.com *.bellamaison.com *.googletagmanager.com *.creativecdn.com *.jsdelivr.net *.personaclick.com *.segmentify.com *.cloudflareinsights.com *.googleapis.com *.gstatic.com *.newrelic.com *.nr-data.net *.doubleclick.net *.youtube-nocookie.com player.vimeo.com *.facebook.com connect.facebook.net *.yapaytech https://cdn.yapaytech.com/ https://scripts.clarity.ms/ https://www.clarity.ms/ https://s2.adform.net/ https://track.adform.net/ https://mc.yango.com/ https://cdn.sgmntfy.com/ https://app.collectaction.com/ https://log.collectaction.com/ https://micro.collectaction.com/ *.taggrs.io *.alothemes.com *.magepow.com www.facebook.com graph.facebook.com business.facebook.com app.personaclick.com cdn.personaclick.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src https://fonts.googleapis.com *.jsdelivr.net *.fontawesome.com *.alothemes.com *.magepow.com *.personaclick.com *.segmentify.com https://cdn.bellamaison.com/ https://cdn2.bellamaison.com/ https://app.collectaction.com/ https://log.collectaction.com/ https://micro.collectaction.com/ app.personaclick.com cdn.personaclick.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src www.apptrian.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com vimeo.com www.apptrian.com *.bellamaison.com *.googletagmanager.com *.creativecdn.com *.jsdelivr.net *.personaclick.com *.segmentify.com *.cloudflareinsights.com *.googleapis.com *.gstatic.com *.newrelic.com *.nr-data.net *.doubleclick.net https://www.google.com/ https://app.collectaction.com/ https://log.collectaction.com/ https://micro.collectaction.com/ https://f.clarity.ms/collect https://h.clarity.ms/collect https://z.clarity.ms/collect/ https://mc.yango.com/ *.alothemes.com *.magepow.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com app.personaclick.com cdn.personaclick.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.bellamaison.com *.googletagmanager.com *.creativecdn.com *.jsdelivr.net *.personaclick.com *.segmentify.com *.cloudflareinsights.com *.googleapis.com *.gstatic.com *.newrelic.com *.nr-data.net *.doubleclick.net *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ *.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com https://app.collectaction.com/ https://log.collectaction.com/ https://micro.collectaction.com/ app.personaclick.com cdn.personaclick.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src https: wss:; script-src https: 'unsafe-eval' 'unsafe-inline'; style-src https: 'unsafe-inline'; img-src https: data:; font-src https: data:; report-uri /csp-report; 1 default-src blob: https://*.mhcache.com;font-src 'self' https://*.myheritage.com https://*.mhcache.com https://fonts.gstatic.com;frame-src 'self' https://*.mhcache.com https://portal.allyable.com https://mh-site-files-5c53d6a9947c.s3.amazonaws.com https://myheritage-container.com https://www.myheritage-partners.com https://www.myheritage.com https://*.mk-sense.com https://player.vimeo.com https://*.facebook.com https://*.googleapis.com https://*.google.com https://tpc.googlesyndication.com https://*.doubleclick.net https://accounts.google.com/gsi/;script-src https://accounts.google.com/gsi/client https://www.datadoghq-browser-agent.com https://*.googleapis.com https://appleid.cdn-apple.com *.myheritage.de https://www.myheritage.de 'unsafe-eval' 'nonce-fad3f9a43bc8414ff2bde1f42d1b9a7f' 'strict-dynamic';style-src data: blob: 'unsafe-inline' 'self' https://*.myheritage.com https://*.mhcache.com https://fonts.googleapis.com https://accounts.google.com/gsi/style;connect-src data: 'self' https://*.myheritage.com https://portal.allyable.com https://*.mhcache.com https://adservice.google.com https://*.logs.datadoghq.com https://*.browser-intake-datadoghq.com https://browser-intake-datadoghq.com https://sentry.io https://*.bing.com https://*.facebook.com https://*.doubleclick.net https://*.mk-sense.com https://*.filae.com https://accounts.google.com/gsi/ https://www.google.com/pagead/landing https://*.googleapis.com https://maps.googleapis.com/maps/api/mapsjs/gen_204 https://translate.googleapis.com https://www.google.com/ccm/collect https://cdn.builder.io *.myheritage.de;media-src 'self' https://*.myheritage.com https://*.mhcache.com;frame-ancestors 'self' https://builder.io;img-src * data:;object-src 'none';base-uri 'self' https://*.mhcache.com;report-uri /FP/API/ContentSecurityPolicy/report-violation.php?report_mode=report&canonical_page_id=/company/home/ 1 default-src blob: https://*.mhcache.com;font-src 'self' https://*.myheritage.com https://*.mhcache.com https://fonts.gstatic.com;frame-src 'self' https://*.mhcache.com https://portal.allyable.com https://mh-site-files-5c53d6a9947c.s3.amazonaws.com https://myheritage-container.com https://www.myheritage-partners.com https://www.myheritage.com https://*.mk-sense.com https://player.vimeo.com https://*.facebook.com https://*.googleapis.com https://*.google.com https://tpc.googlesyndication.com https://*.doubleclick.net https://accounts.google.com/gsi/;script-src https://accounts.google.com/gsi/client https://www.datadoghq-browser-agent.com https://*.googleapis.com https://appleid.cdn-apple.com *.myheritage.fr https://www.myheritage.fr 'unsafe-eval' 'nonce-52d4ae098b1c04f2c785f831ecdf6e1c' 'strict-dynamic';style-src data: blob: 'unsafe-inline' 'self' https://*.myheritage.com https://*.mhcache.com https://fonts.googleapis.com https://accounts.google.com/gsi/style;connect-src data: 'self' https://*.myheritage.com https://portal.allyable.com https://*.mhcache.com https://adservice.google.com https://*.logs.datadoghq.com https://*.browser-intake-datadoghq.com https://browser-intake-datadoghq.com https://sentry.io https://*.bing.com https://*.facebook.com https://*.doubleclick.net https://*.mk-sense.com https://*.filae.com https://accounts.google.com/gsi/ https://www.google.com/pagead/landing https://*.googleapis.com https://maps.googleapis.com/maps/api/mapsjs/gen_204 https://translate.googleapis.com https://www.google.com/ccm/collect https://cdn.builder.io *.myheritage.fr;media-src 'self' https://*.myheritage.com https://*.mhcache.com;frame-ancestors 'self' https://builder.io;img-src * data:;object-src 'none';base-uri 'self' https://*.mhcache.com;report-uri /FP/API/ContentSecurityPolicy/report-violation.php?report_mode=report&canonical_page_id=/company/home/ 1 default-src 'self' https:; script-src 'self' https: 'unsafe-inline' 'unsafe-eval'; style-src 'self' https: 'unsafe-inline'; img-src 'self' https: data: blob:; media-src 'self' https: data: blob:; object-src 'none'; frame-ancestors 'self' https://experience.adobe.com https://infopoint.audi.it; connect-src 'self' https: wss://e0k754.acquire.io; base-uri 'self'; font-src 'self' https: data:; worker-src 'self' blob:; report-uri https://www.audi.es/api/csp-report; report-to csp-endpoint 1 default-src 'self' 'report-sample' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes' http://*.uqtr.uquebec.ca http://*.uqtr.ca data: https: blob:; base-uri 'self' http://*.uqtr.ca; form-action 'self' https: javascript: inline:; report-to csp-endpoint; report-uri https://webservice.uqtr.ca/prod/nginx/csp_api/report 1 connect-src 'self' https://analytics.tiktok.com https://api.hubspot.com https://app.clearbit.com https://cdn.cookielaw.org https://cdn.dreamdata.cloud https://content.hotjar.io https://cta-service-cms2.hubspot.com https://forms.hsforms.com https://px.ads.linkedin.com https://script.crazyegg.com https://www.google-analytics.com https://www.google.com https://edge.api.brightcove.com https://bat.bing.com/ https://manifest.prod.boltdns.net https://sdl.brightcovecdn.com https://logx.optimizely.com https://*.optimizely.com; default-src 'self'; font-src 'self' data: https://use.typekit.net https://*.optimizely.com; frame-ancestors 'none'; frame-src https://www.googletagmanager.com https://googleads.g.doubleclick.net https://cm.g.doubleclick.net https://www.facebook.com https://calendly.com https://forms.hsforms.com https://a5098497884553216.cdn.optimizely.com https://a5098497884553216.cdn-pci.optimizely.com; img-src 'self' data: https://bat.bing.com https://forms-na1.hsforms.com https://ib.adnxs.com https://perf-na1.hsforms.com https://px.ads.linkedin.com https://secure.adnxs.com https://track.accountinsight.cloud https://track.hubspot.com https://www.facebook.com https://www.google.com https://www.google.com.ua https://metrics.brightcove.com https://www.googletagmanager.com https://cf-images.us-east-1.prod.boltdns.net https://cdn.optimizely.com https://app.optimizely.com; media-src 'self' blob:; script-src 'self' 'nonce-gVRtxCUuobuTrHqY2LIzxQ==' https://a.dpmsrv.com https://analytics.tiktok.com https://bat.bing.com https://cdn.cookielaw.org https://cdn.dreamdata.cloud https://cm.g.doubleclick.net https://connect.facebook.net https://googleads.g.doubleclick.net https://ib.adnxs.com https://js.hs-analytics.net https://js.hs-banner.com https://js.hs-scripts.com https://js.hsforms.net https://js.hubspot.com https://js.usemessages.com https://s.dpmsrv.com https://script.crazyegg.com https://script.hotjar.com https://serve.nrich.ai https://snap.licdn.com https://st.getsitecontrol.com https://static.hotjar.com https://tag.clearbitscripts.com https://widgets.getsitecontrol.com https://www.googletagmanager.com https://x.clearbitjs.com https://assets.calendly.com https://static.hsappstatic.net https://48752163.fs1.hubspotusercontent-na1.net https://cdnjs.cloudflare.com https://players.brightcove.net wss://ws.hotjar.com/ https://*.optimizely.com https://optimizely.s3.amazonaws.com https://cdn-assets-prod.s3.amazonaws.com 'unsafe-eval'; style-src 'self' 'unsafe-inline' https://*.typekit.net https://assets.calendly.com https://*.optimizely.com https://app.optimizely.com; worker-src 'self' blob:; 1 default-src 'self' data:; frame-ancestors *.weirdfish.co.uk *.adyen.com *.amazon.com *.paypal.com *.google.com *.exponea.com *.monetate.net; connect-src * data:; font-src * data:; frame-src *; img-src * data:; media-src *; object-src *; script-src * 'unsafe-inline' 'unsafe-eval'; style-src * 'unsafe-inline' data:; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net cash-f.squarecdn.com https://client.crisp.chat https://plugin-magento-ui.glopalservice.com https://applepay.cdn-apple.com *.fontawesome.com https://fonts.bunny.net *.cloudflare.com fonts.gstatic.com/ maxcdn.bootstrapcdn.com https://cdnjs.cloudflare.com applepay.cdn-apple.com www.promessedefleurs.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com * 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com p.monetico-services.com www.promessedefleurs.com 'self' 'unsafe-inline'; frame-ancestors www.promessedefleurs.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ * ct.pinterest.com *.payplug.com *.dalenys.com https://applepay.cdn-apple.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com api-qa.payplug.com secure-qa.payplug.com www.promessedefleurs.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com *.google-analytics.com *.analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io * https://images.unsplash.com https://image.crisp.chat *.jardindupicvert.com *.jardindupicvert.com.localhost *.promessedefleurs.com *.promessedefleurs.com.localhost cl.avis-verifies.com ct.pinterest.com bat.bing.com www.google.com.vn https://cdn-redirector.glopal.com https://plugin-magento-ui.glopalservice.com https://secure-magenta.dalenys.com https://firebasestorage.googleapis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://redchamps.com *.openstreetmap.fr *.openstreetmap.org unpkg.com *.google.com *.google.fr *.google.ie www.promessedefleurs.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com *.cash.app *.visa.com *.mastercard.com applepay.cdn-apple.com https://maps.googleapis.com https://player.vimeo.com https://client.crisp.chat cl.avis-verifies.com bat.bing.com s.pinimg.com https://cdn-redirector.glopal.com https://plugin-magento-ui.glopalservice.com cdn-renderer.glopalstore.com https://secure-magenta.dalenys.com https://applepay.cdn-apple.com api-qa.payplug.com cdn-qa.payplug.com cdn.payplug.com *.avada.io *.shopify.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://cdnjs.cloudflare.com https://cdn.payplug.com https://cdn-qa.payplug.com https://unpkg.com/pwacompat *.google.com *.google.fr *.google.ie *.googletagmanager.com *.googleadservices.com www.promessedefleurs.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.cash.app https://client.crisp.chat https://cdn-redirector.glopal.com https://plugin-magento-ui.glopalservice.com https://secure-magenta.dalenys.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com https://fonts.googleapis.com https://cdnjs.cloudflare.com unpkg.com www.promessedefleurs.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.promessedefleurs.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.googleadservices.com *.google-analytics.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io * https://maps.googleapis.com https://player.vimeo.com https://client.crisp.chat wss://client.relay.crisp.chat https://plugins.crisp.chat *.jardindupicvert.com *.jardindupicvert.com.localhost *.promessedefleurs.com *.promessedefleurs.com.localhost ct.pinterest.com https://api-plugin-facade.glopalservice.com https://cognito-idp.eu-west-1.amazonaws.com api.glopaltranslator.com https://get.geojs.io *.avada.io www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.openstreetmap.org *.arcgis.com *.doubleclick.net www.promessedefleurs.com 'self' 'unsafe-inline'; child-src www.promessedefleurs.com http: https: blob: 'self' 'unsafe-inline'; default-src cl.avis-verifies.com www.promessedefleurs.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://www.googletagmanager.com https://*.visualwebsiteoptimizer.com https://dev.visualwebsiteoptimizer.com https://static.cloudflareinsights.com https://tags.tiqcdn.com https://connect.facebook.net https://analytics.tiktok.com https://static.ads-twitter.com https://*.hotjar.com https://tags.srv.stackadapt.com https://dsp-cdn.gammaplatform.com https://maps.googleapis.com https://www.google.com https://www.gstatic.com https://www.youtube.com https://*.doubleclick.net https://googleads.g.doubleclick.net https://*.fbcdn.net https://*.adform.net https://a1.adform.net https://*.outbrain.com https://wave.outbrain.com https://tt.mbww.com https://js-agent.newrelic.com https://infird.com https://*.google-analytics.com https://cdnjs.cloudflare.com https://visitor-service-convertium.toyota.com.my https://*.toyota.com.my; script-src-elem 'self' 'unsafe-inline' https://www.googletagmanager.com https://*.visualwebsiteoptimizer.com https://dev.visualwebsiteoptimizer.com https://static.cloudflareinsights.com https://tags.tiqcdn.com https://connect.facebook.net https://analytics.tiktok.com https://static.ads-twitter.com https://*.hotjar.com https://tags.srv.stackadapt.com https://dsp-cdn.gammaplatform.com https://maps.googleapis.com https://www.google.com https://www.gstatic.com https://www.youtube.com https://*.doubleclick.net https://googleads.g.doubleclick.net https://*.fbcdn.net https://*.adform.net https://a1.adform.net https://*.outbrain.com https://wave.outbrain.com https://tt.mbww.com https://js-agent.newrelic.com https://infird.com https://*.google-analytics.com https://cdnjs.cloudflare.com https://visitor-service-convertium.toyota.com.my https://*.toyota.com.my; style-src 'self' 'unsafe-inline' https://tags.srv.stackadapt.com https://fonts.googleapis.com https://www.gstatic.com https://www.youtube.com https://*.toyota.com.my https://cdnjs.cloudflare.com https://*.fbcdn.net; img-src 'self' data: https: http://*.toyota.com.my; font-src 'self' data: https://*.toyota.com.my https://cdnjs.cloudflare.com https://fonts.gstatic.com; connect-src 'self' https://*.outbrain.com https://*.google-analytics.com https://*.googleadservices.com https://*.tiktok.com https://*.visualwebsiteoptimizer.com https://tags.srv.stackadapt.com https://*.googleapis.com https://*.doubleclick.net https://*.toyota.com.my https://*.tiktokw.us https://*.tealiumiq.com https://*.hotjar.io https://bam.nr-data.net https://cdnjs.cloudflare.com https://www.googletagmanager.com https://*.google.co.jp https://*.google.com https://*.google.com.my https://*.google.com.hk https://*.google.ie https://*.google.com.pe https://*.google.com.kh https://*.google.com.sg https://*.google.co.uk https://*.google.de https://*.google.fr https://*.google.it https://*.google.es https://*.google.ca https://*.google.com.au https://*.google.co.in https://*.google.com.ph wss://ws.hotjar.com https://*.facebook.com https://www.facebook.com; frame-src 'self' https://www.googletagmanager.com https://www.youtube.com https://*.google.com https://www.facebook.com https://*.adform.net https://asia.creativecdn.com https://*.toyota.com.my https://cdnjs.cloudflare.com https://*.visualwebsiteoptimizer.com https://*.doubleclick.net; worker-src blob:; report-uri /bin/csp-report 1 object-src 'none'; script-src 'self' chosen.jquery.js https://polyfill-fastly.io https://unpkg.com; script-src-attr 'self'; style-src 'self' chosen.css https://use.typekit.net; style-src-attr 'self'; frame-ancestors 'self' 1 default-src 'self' *.apsiyon.com; style-src 'self' 'unsafe-inline' analytics.tiktok.com analytics.tiktok.com/api/v2/monitor cdn.apsiyon.com cdnjs.cloudflare.com translate.googleapis.com fonts.googleapis.com *.apsiyon.com wchat.freshchat.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.apsiyon.com www.google.com www.clarity.ms cdn.apsiyon.com analytics.tiktok.com analytics.tiktok.com/api/v2/monitor www.analytics.tiktok.com/api/v2/monitor connect.facebook.net www.googledservices.com www.googleadservices.com code.jquery.com cdn.jsdelivr.net maps.googleapis.com www.googletagmanager.com www.google-analytics.com googleads.g.doubleclick.net cdn.taboola.com trc.taboola.com www.gstatic.com wchat.freshchat.com snap.licdn.com; frame-src 'self' www.googletagmanager.com www.googleadservices.com connect.facebook.net web.facebook.com *.apsiyon.com m.facebook.com www.google.ro www.youtube.com youtube.com httpsapsiyoncom.webpush.freshchat.com www.google.com bid.g.doubleclick.net wchat.freshchat.com www.facebook.com analytics.tiktok.com analytics.tiktok.com/api/v2/monitor; img-src data: * ; connect-src 'self' 'unsafe-inline' localhost:51192 analytics.tiktok.com analytics.tiktok.com/api/v2/monitor www.google.bg www.google.li www.google.com.bd www.google.ro www.google.com.hk www.google.co.jp www.google.tm www.google.ps www.google.pl www.google.ba www.google.co.za www.google.cz www.google.md www.google.com.ua www.google.com.qa www.google.ba www.google.com.et www.google.jo www.google.hu www.google.ph stats.g.doubleclick.net www.google.at www.google.com.cy www.google.nl www.google.kz www.google.co.in www.google.com.sa www.google.es www.google.kg www.google.co.id www.google.dk www.google.com.kw www.google.co.kr www.google.cn www.google.co.th www.google.co.uz www.google.co.uk www.google.ae www.google.ch www.google.az www.google.lu www.google.it www.google.com.pk www.google.be www.google.fi www.google.no www.google.sn www.bing.com www.google.se www.google.iq www.google.ie www.google.fr www.googleanalytics.com www.google.de www.google.ru *.taboola.com www.google.co.il www.facebook.com www.google.com.tr *.clarity.ms *.apsiyon.com analytics.google.com www.google-analytics.com; font-src 'self' data: fonts.googleapis.com use.fontawesome.com themes.googleusercontent.com *.apsiyon.com themes.googleusercontent.com static3.avast.com cdnjs.cloudflare.com fonts.gstatic.com; 1 default-src 'self' https:; font-src 'self' https: data:; object-src 'none'; script-src 'self' https: 'unsafe-inline' 'unsafe-eval' https://www.googletagmanager.com; worker-src 'self' blob:; style-src 'self' https: 'unsafe-inline'; img-src 'self' https: data: www.googletagmanager.com; connect-src 'self' https: ws: wss:; report-uri https://csp-report.browser-intake-datadoghq.com/api/v2/logs?dd-api-key=pubf68dfe1092b9b71f30b0f8123a55b7f0&dd-evp-origin=content-security-policy&ddsource=csp-report&ddtags=project%3Ask%2Cenv%3Aproduction&service=sk 1 default-src 'self'; frame-src https://www.youtube.com https://www.youtube-nocookie.com; img-src 'self' data: https://i.ytimg.com; script-src 'self' https://www.youtube.com https://www.youtube-nocookie.com; connect-src 'self' https://www.youtube.com; media-src 'self' https://www.youtube.com 1 font-src *.vita4you.gr *.googletagmanager.com *.adobe.com www.googleadservices.com www.google-analytics.com *.googleapis.com vimeo.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.contactpigeon.com assets.vita4you.gr *.newrelic.com *.nr-data.net fonts.googleapis.com fonts.gstatic.com *.hotjar.com *.zopim.com *.fontawesome.com 'self' data: *.skroutz.gr *.cloudflare.com *.twitter.com *.twimg.com *.usercentrics.eu *.bing.com *.zdassets.com *.google.com *.google.gr *.clarity.ms/ applepay.cdn-apple.com *.klevu.com *.ksearchnet.com https://fonts.bunny.net maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com *.contactpigeon.com assets.vita4you.gr *.google.gr *.skroutz.gr *.zopim.com *.moosend.com *.cloudflare.com td.doubleclick.net int-ecommerce.nexi.it coll-ecommerce.nexi.it ecommerce.nexi.it 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com player.vimeo.com https://www.google.com/recaptcha/ www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com widget-v3.boxnow.gr widget-v5.boxnow.cy *.skroutz.gr *.contactpigeon.com *.hotjar.com *.facebook.com td.doubleclick.net *.clarity.ms/ *.bing.com *.googletagmanager.com *.google.com int-ecommerce.nexi.it coll-ecommerce.nexi.it ecommerce.nexi.it stg-ta.nexigroup.com xpay.nexigroup.com pay.google.com applepay.cdn-apple.com *.addthis.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com https://trustmark.gr *.tiktok.com *.contactpigeon.com assets.vita4you.gr *.vita4you.gr *.googleapis.com *.gstatic.com *.trustedshops.com *.zopim.com cdn.jsdelivr.net *.skroutz.gr *.moosend.com *.cloudflare.com *.googleadservices.com *.google-analytics.com *.paypal.com *.twitter.com *.twimg.com *.ytimg.com *.bing.com *.zopim.io td.doubleclick.net *.facebook.com *.mastercard.com *.google.com *.google.gr *.googletagmanager.com *.clarity.ms/ https://bat.bing.net rum.corewebvitals.io int-ecommerce.nexi.it coll-ecommerce.nexi.it ecommerce.nexi.it stg-ta.nexigroup.com xpay.nexigroup.com cdn.klarna.com www.gstatic.com pay.google.com applepay.cdn-apple.com *.klevu.com *.ksearchnet.com https://firebasestorage.googleapis.com flagpedia.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com *.octocom.ai *.octocomstorage.blob.core.windows.net 'self' data: *.tiktok.com *.googletagmanager.com *.googleapis.com *.vita4you.gr *.facebook.net *.facebook.com *.doubleclick.net *.google-analytics.com *.gstatic.com *.contactpigeon.com assets.vita4you.gr *.newrelic.com *.nr-data.net *.paypal.com *.google.com *.hotjar.com *.fontawesome.com *.feedbackcompany.com *.trustpilot.com cdn.jsdelivr.net *.googleoptimize.com *.skroutz.gr skroutza.skroutz.gr *.cloudflare.com *.google.gr https://trustmark.gr/badge/dist/index.js https://static.adman.gr/adman.js https://greca.adman.gr cdn.omnicliq.com/ss.js *.clarity.ms/ *.bing.com *.debugbear.com https://apis.google.com *.corewebvitals.io int-ecommerce.nexi.it coll-ecommerce.nexi.it ecommerce.nexi.it stg-ta.nexigroup.com xpay.nexigroup.com www.google.com www.gstatic.com pay.google.com applepay.cdn-apple.com *.klevu.com *.ksearchnet.com *.addthis.com *.moatads.com *.addthisedge.com *.pinterest.com *.avada.io *.shopify.com maps.googleapis.com https://js.klevu.com https://assets.vita4you.gr 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.octocom.ai *.octocomstorage.blob.core.windows.net *.googletagmanager.com www.googleadservices.com www.google-analytics.com *.googleapis.com vimeo.com *.vita4you.gr *.facebook.net *.facebook.com *.doubleclick.net *.google-analytics.com *.gstatic.com *.contactpigeon.com assets.vita4you.gr *.newrelic.com *.nr-data.net *.fontawesome.com *.trustpilot.com cdn.jsdelivr.net *.skroutz.gr *.cloudflare.com *.twitter.com *.twimg.com *.typekit.net *.bing.com *.hotjar.com *.clarity.ms/ *.klevu.com *.ksearchnet.com https://fonts.bunny.net maxcdn.bootstrapcdn.com https://statsjs.klevu.com https://js.klevu.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' data: *.contactpigeon.com assets.vita4you.gr *.google.gr *.zopim.com *.skroutz.gr *.moosend.com *.cloudflare.com *.youtube.com 'self' 'unsafe-inline'; manifest-src assets.vita4you.gr 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.octocom.ai *.octocomstorage.blob.core.windows.net *.googleadservices.com *.google-analytics.com *.googleapis.com *.gstatic.com *.mastercard.com *.google.com *.google.gr *.googletagmanager.com *.tiktok.com *.contactpigeon.com assets.vita4you.gr *.paypal.com stats.g.doubleclick.net https://googleads.g.doubleclick.net/ *.zdassets.com *.hotjar.com *.hotjar.io wss://*.hotjar.com *.zopim.com wss://*.zopim.com *.feedbackcompany.com *.skroutz.gr *.cloudflare.com api.zevioo.com https://pagead2.googlesyndication.com ss.vita4you.gr *.bing.com *.clarity.ms/ *.debugbear.com td.doubleclick.net https://bat.bing.net int-ecommerce.nexi.it coll-ecommerce.nexi.it ecommerce.nexi.it stg-ta.nexigroup.com xpay.nexigroup.com pay.google.com applepay.cdn-apple.com *.klevu.com *.ksearchnet.com *.addthis.com https://get.geojs.io *.avada.io www.gstatic.com maps.googleapis.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; script-src 'self' 'unsafe-inline' https:; style-src 'self' 'unsafe-inline' https:; img-src 'self' data: https:; 1 object-src 'none';base-uri 'self';script-src 'nonce-tXS-PoOvw0bCMR9Q50jZwg' 'strict-dynamic' 'report-sample' 'unsafe-eval' 'unsafe-inline' https: http:;report-uri https://csp.withgoogle.com/csp/gws/other-hp 1 script-src 'nonce-ga+dCiIojPZeI+1ne4qxjQ==' 'strict-dynamic' 'unsafe-eval' 'unsafe-inline' https: 'report-sample'; base-uri 'none'; report-uri https://events.mercadolibre.com/csp/reports?identifier=w1qeU4XKVwGbQGBuEKyE3KhFBIpr5IZSIaRiTowMc8UG7kU18vRsmBTEKL2krAj23LIS&policy_id=26548&user_id=&request_id=b25962f3-1d3f-47b0-b495-ed1b17d34179; report-to csp-endpoint-wqeuxkvwgbqgbuekyekhfbiprizsiaritowmcugkuvrsmbteklkrajlis; object-src https://http2.mlstatic.com/ https://mlstaticquic-a.akamaihd.net/; frame-ancestors 'self' https://*.mercadolibre.cl:* https://*.mercadolibre.com:* https://*.mercadolibre.com.ve:* https://*.mercadolibre.com.ar:* https://*.mercadolivre.com.br:* https://*.mercadolibre.com.co:* https://*.mercadolibre.com.ec:* https://*.mercadolibre.com.mx:* https://*.mercadolibre.com.pe:* https://*.mercadolibre.com.uy:* https://*.mercadopago.cl:* https://*.mercadopago.com.ar:* https://*.mercadopago.com.br:* https://*.mercadopago.com.co:* https://*.mercadopago.com.mx:* https://*.mercadopago.com.pe:* https://*.mercadopago.com.uy:* https://*.mercadopago.com.ve:* https://*.mercadopago.com:* https://*.adminml.com:* https://*.mercadolibre.co.cr:* https://*.mercadolibre.com.pa:* https://*.mercadolibre.com.do:* https://*.mercadolibre.com.bo:* https://*.mercadolibre.com.py:* https://*.mercadolibre.com.gt:* https://*.mercadolibre.com.hn:* https://*.mercadolibre.com.ni:* https://*.mercadolibre.com.sv:* https://*.mercadopago.com.ec:* https://*.portalinmobiliario.com:* https://*.mercadolivre.com:* 1 script-src 'strict-dynamic' 'nonce-gWg1oOHRF+TeEDRJpI/jrA==' 1 font-src https://fonts.gstatic.com fonts.gstatic.com *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.klarnaservices.com *.klarnacdn.net *.klarna.com *.addsauce.com *.fontawesome.com *.bootstrapcdn.com *.funky-buddha.com *.cloudfront.net fonts.googleapis.com skroutza.skroutz.gr data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net pilot-payflowlink.paypal.com *.facebook.com www.apptrian.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com *.vivapayments.com skroutza.skroutz.gr *.modirum.com *.eurocommerce.gr 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.google.com *.google.com *.doubleclick.net *.facebook.com *.klarna.com *.klarnacdn.net www.apptrian.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com bytedance: sslocal: connect.facebook.net graph.facebook.com business.facebook.com *.contactpigeon.com *.bestprice.gr *.googletagmanager.com *.cookiebot.com *.grxchange.gr *.criteo.com *.skroutz.gr skroutza.skroutz.gr https://player.vimeo.com https://www.youtube-nocookie.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com validator.swagger.io maps.googleapis.com maps.gstatic.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.gstatic.com *.plenigo.com *.klarnacdn.net *.klarnaservices.com *.klarna.com *.addsauce.com www.apptrian.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com analytics.tiktok.com connect.facebook.net graph.facebook.com business.facebook.com *.findbar.io *.contactpigeon.com *.designer-images.net *.bestprice.gr *.visualwebsiteoptimizer.com *.cloudflarestream.com *.rubiconproject.com *.smartadserver.com *.funky-buddha.com *.sharethrough.com *.casalemedia.com *.postrelease.com *.unrulymedia.com *.servenobid.com *.cookiebot.com *.bidswitch.net *.mediavine.com *.omnitagjs.com *.tremorhub.com *.linkedin.com *.outbrain.com *.360yield.com *.pubmatic.com *.yieldlab.net *.ivitrack.com *.taboola.com *.yieldmo.com *.demdex.net *.criteo.com *.google.gr *.3lift.com *.media.net *.adnxs.com *.teads.tv *.bing.com *.glami.gr *.emxdgt.com id5-sync.com trustmark.gr *.1rx.io *.e-satisfaction.com glamipixel.com fonts.googleapis.com skroutza.skroutz.gr blob: https://updates.themepunch.tools http://updates.themepunch.tools https://updates.themepunch-ext-a.tools http://updates.themepunch-ext-a.tools https://updates.themepunch-ext-b.tools http://updates.themepunch-ext-b.tools https://dev.sliderrevolution.com https://revolution.themepunch.com http://revolution5.themepunch.com http://pbs.twimg.com https://pbs.twimg.com http://scontent.cdninstagram.com https://img.youtube.com http://live.staticflickr.com https://live.staticflickr.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.google.com/recaptcha/ www.gstatic.com/recaptcha/ maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.playground.klarnaservices.com *.klarnacdn.net *.klarnaservices.com *.klarna.com *.funky-buddha.com *.addsauce.com www.apptrian.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com analytics.tiktok.com *.vivapayments.com connect.facebook.net graph.facebook.com business.facebook.com *.findbar.io *.contactpigeon.com *.avada.io *.stat-track.com polyfill.io *.moosend.com *.bestprice.gr *.visualwebsiteoptimizer.com *.googleoptimize.com *.googleapis.com *.cookiebot.com *.socital.com *.eyefitu.com *.simpler.so *.skroutz.gr *.hotjar.com *.clarity.ms *.criteo.com *.tiktok.com *.linkwi.se *.licdn.com glamipixel.com *.adman.gr *.bing.com trustmark.gr self data: snapppt.com *.e-satisfaction.com cdn.simpler.so sdk.local.simpler.so skroutza.skroutz.gr https://player.vimeo.com https://www.youtube.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.klarnacdn.net *.klarna.com *.addsauce.com *.findbar.io *.fontawesome.com *.moosend.com *.bootstrapcdn.com *.bestprice.gr *.contactpigeon.com *.funky-buddha.com *.cloudfront.net *.myfonts.net *.e-satisfaction.com skroutza.skroutz.gr https://fonts.googleapis.com http://fonts.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.funky-buddha.com www.apptrian.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com *.findbar.io blob: 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com *.google-analytics.com *.facebook.com *.facebook.net *.google.com *.playground.klarnaservices.com *.playground.klarnaevt.com *.klarnaservices.com *.addsauce.com *.klarnacdn.net *.klarna.com *.klarnaevt.com www.apptrian.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com analytics.tiktok.com connect.facebook.net graph.facebook.com business.facebook.com *.findbar.io *.contactpigeon.com https://get.geojs.io *.avada.io *.stat-track.com *.m-pages.com *.m-operations.com *.googlesyndication.com *.monitor.azure.com *.visualstudio.com *.funky-buddha.com *.googleapis.com *.cookiebot.com *.linkedin.com *.bestprice.gr *.socital.com *.eyefitu.com *.simpler.so *.criteo.com *.clarity.ms *.hotjar.io *.bing.com wss: *.e-satisfaction.com button.simpler.so button.staging.simpler.so analytics.simpler.so analytics.staging.simpler.so button.local.simpler.so fonts.googleapis.com skroutza.skroutz.gr https://fonts.googleapis.com https://fonts.gstatic.com https://api.weatherbit.io 'self' 'unsafe-inline'; child-src *.contactpigeon.com http: https: blob: 'self' 'unsafe-inline'; default-src *.funky-buddha.com *.clarity.ms *.criteo.net *.google.com *.tiktok.com *.bing.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri *.contactpigeon.com 'self' 'unsafe-inline'; 1 connect-src 'self' https://correspondent.report-uri.com https://static.cdn-decorrespondent.nl https://useruploads.cdn-decorrespondent.nl https://decorrespondent.matomo.cloud https://o206126.ingest.sentry.io https://space-corre.video-dns.com; media-src 'self' https://static.cdn-decorrespondent.nl https://traffic.omny.fm https://*.mc.tritondigital.com https://useruploads.cdn-decorrespondent.nl blob: https://space-corre.video-dns.com; form-action 'self' https://www.mollie.com https://pay.ideal.nl https://www.paypal.com; report-uri https://correspondent.report-uri.com/r/d/csp/reportOnly; report-to csp-report-only-endpoint 1 default-src 'self' 'unsafe-inline' 'unsafe-eval' oqvestir.com.br *.oqvestir.com.br wake-components.fbitsstatic.net oqvestir.fbitsstatic.net *.wake.tech fbits.net nr-data.net newrelic.com google.com googletagmanager.com google-analytics.com facebook.net facebook.com jquery.com bootstrapcdn.com *.fbits.net *.nr-data.net *.newrelic.com *.google.com *.googletagmanager.com *.google-analytics.com *.facebook.net *.facebook.com *.jquery.com *.bootstrapcdn.com wss://signalr.fbits.net k-analytix.com *.k-analytix.com i.konduto.com *.yapay.com.br *.traycheckout.com.br h.online-metrix.net *.clearsale.com.br dzpxyxks1bfmb.cloudfront.net *.gstatic.com *.koin.com.br *.soclminer.com.br *.btg360.com.br *.socialminer.com signalrcore.fbits.net wss://signalrcore.fbits.net *.cloudfront.net *.mlstatic.com *.mercadopago.com *.mercadolibre.com *.mercadopago.com.br *.paypal.com *.paypalobjects.com *.fbits.store *.adyen.com *.pagar.me *.mundipagg.com *.getnet.com.br *.g.doubleclick.net *.doubleclick.net oqvestir.fbitsstatic.net *.criteo.com *.clarity.ms capig.shop2gether.com.br q.clarity.ms static.criteo.net clarity.ms sslwidget.criteo.com dynamic.criteo.com googleads.g.doubleclick.net gum.criteo.com bat.bing.com google.com.br googleadservices.com tags.creativecdn.com apigate.shop2gether.com.br o.clarity.ms *.creativecdn.com *.braintree-api.com *.braintreegateway.com *.pagseguro.com.br *.pagbank.com *.vindi.com.br *.cieloecommerce.cielo.com.br *.braspag.com.br *.pagador.com.br *.online-metrix.net bt-wake-connector.com.br *.pagaleve.com.br *.pagaleve.io wake-api.pagaleve.com.br securegtm.despegar.com api.ipify.org browser-intake-datadoghq.com *.datadoghq-browser-agent.com *.datadoghq.com n8n.icommgroup.com.br wake.koin.com.br *.icommgroup.com.br *.pinterest.com paypal-wake.s3.us-east-1.amazonaws.com *.cardinalcommerce.com *.api.useinsider.com *.useinsider.com *.secureacs.com *.crmbonus.com api.globalgetnet.com *.globalgetnet.com *.sandbox.3dsecure.io *.3dsecure.io *.sizebay.technology *.dwin1.com *.awin1.com *.zenaps.com *.sciencebehindecommerce.com *.wepowerconnections.com recommendationv2.api.useinsider.com wake-commerce-scripts.omni.chat trackings.nemu.com.br openfpcdn.io ipinfo.io api.ipify.org api.bigdatacloud.net firebase.googleapis.com *.googleapis.com d1vrnvkozosezy.cloudfront.net *.visa.com *.wake.tech *.appmax.com.br *.tunagateway.com *.internalsizebay.com *.pagoexpress.com.br *.infraicommgroup.com src.mastercard.com ; img-src https: data:; style-src https: 'unsafe-inline'; font-src https: data:; frame-ancestors *.oqvestir.com.br oqvestir.com.br; report-uri https://pub-csp.fbits.net/checkout_sem_carrinho; report-to https://pub-csp.fbits.net/checkout_sem_carrinho; worker-src 'self' blob:; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.klarnacdn.net 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com pinterest.com www.pinterest.com ct.pinterest.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.vaude.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com pinterest.com www.pinterest.com ct.pinterest.com *.criteo.com *.klarna.com js.mollie.com td.doubleclick.net app.usercentrics.eu web.cmp.usercentrics.eu v1.api.service.cmp.usercentrics.eu *.outtra.com *.googletagmanager.com *.fls.doubleclick.net *.amazon-adsystem.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com pinterest.com www.pinterest.com ct.pinterest.com *.klarna.com *.klarnaevt.com *.klarnacdn.net *.disqus.com https://img.youtube.com https://www.mollie.com *.hsforms.net *.hsforms.com 'self' data: www.vaude.com vaude.localhost https://vaude.localhost/ www.google.de app.usercentrics.eu web.cmp.usercentrics.eu v1.api.service.cmp.usercentrics.eu uct.service.usercentrics.eu *.equalweb.com *.weglot.com ad.doubleclick.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://rum.hlx.page www.google.com/recaptcha/ www.gstatic.com/recaptcha/ www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com pinterest.com www.pinterest.com s.pinimg.com https://dynamic.criteo.com https://sslwidget.criteo.com *.klarna.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.disqus.com js.mollie.com *.hsforms.net *.hsforms.com *.gstatic.com *.abtasty.com ion.vaude.com id.vaude.com analytics.vaude.com js-agent.newrelic.com vaude.matomo.cloud app.usercentrics.eu web.cmp.usercentrics.eu v1.api.service.cmp.usercentrics.eu api.usercentrics.eu graphql.usercentrics.eu privacy-proxy.usercentrics.eu *.equalweb.com cdn.matomo.cloud cdn.scarabresearch.com static.scarabresearch.com webchannel-content.eservice.emarsys.net https://vaude.homepagerecruiter.de https://cdn.tailwindcss.com https://production.neocomapp.com *.weglot.com *.outtra.com *.amazon-adsystem.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.klarnacdn.net *.googleapis.com *.gstatic.com *.equalweb.com *.weglot.com *.outtra.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com pinterest.com www.pinterest.com ct.pinterest.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com pinterest.com www.pinterest.com ct.pinterest.com https://measurement-api.criteo.com *.klarnaevt.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.klarna.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com *.abtasty.com analytics.vaude.com bam.nr-data.net pagead2.googlesyndication.com vaude.matomo.cloud app.usercentrics.eu web.cmp.usercentrics.eu v1.api.service.cmp.usercentrics.eu api.usercentrics.eu graphql.usercentrics.eu privacy-proxy.usercentrics.eu aggregator.service.usercentrics.eu consent-api.service.consent.usercentrics.eu *.equalweb.com cdn.matomo.cloud cdn.scarabresearch.com static.scarabresearch.com webchannel-content.eservice.emarsys.net https://prompts.api.production.neocomapp.com *.weglot.com https://cdn-api-weglot.com *.outtra.com *.amazon-adsystem.com *.paa-reporting-advertising.amazon 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; script-src 'self' 'nonce-kmudT3cBX8lYDsMENzpwKg==' 'strict-dynamic' 'unsafe-eval' 'unsafe-hashes' 'unsafe-inline' 'sha256-f9ms/4u9WrRYV3p93xXv88VDowcvTVxabxYcmCxoxBE=' https://connect.facebook.net https://accounts.google.com https://www.googletagmanager.com https://cdn.jifo.co https://s.infogram.com https://www.youtube.com https://www.google.com https://www.google.com.au https://www.googleadservices.com https://www.google.co.in https://www.gstatic.com https://securepubads.g.doubleclick.net https://bat.bing.com https://www.clarity.ms https://play.google.com https://can.canstar.com.au https://graph.canstar.com.au https://jnn-pa.googleapis.com https://logx.optimizely.com https://identitytoolkit.googleapis.com https://sso.canstar.com.au https://ad.doubleclick.net https://adservice.google.com https://analytics.google.com https://sdk-02.moengage.com https://metrics.hotjar.io https://siteintercept.qualtrics.com https://collector-px58c3a4zy.perimeterx.net https://platform.twitter.com https://syndication.twitter.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://gfonts.jifo.co https://cdn.jifo.co https://themes.jifo.co https://accounts.google.com https://graph.canstar.com.au https://platform.twitter.com; style-src-attr 'self' 'unsafe-inline'; script-src-attr 'self' 'unsafe-inline' https://cns-angular-content-uat-2.freetls.fastly.net https://cns-angular-content-prod-1.freetls.fastly.net https://cns-angular-content-prod-2.freetls.fastly.net; img-src 'self' data: blob: https://graph.canstar.com.au https://snapshots.uat.canstar.com.au https://snapshots.canstar.com.au https://www.youtube.com https://i.ytimg.com https://yt3.ggpht.com https://images.jifo.co https://www.google.com https://www.google.com.au https://www.google.co.in https://www.gstatic.com https://www.googletagmanager.com https://securepubads.g.doubleclick.net https://bat.bing.com https://www.clarity.ms https://play.google.com https://can.canstar.com.au https://graph.canstar.com.au https://jnn-pa.googleapis.com https://logx.optimizely.com https://identitytoolkit.googleapis.com https://sso.canstar.com.au https://ad.doubleclick.net https://adservice.google.com https://analytics.google.com https://sdk-02.moengage.com https://fonts.gstatic.com https://themes.jifo.co https://gfonts.jifo.co https://cdn.jifo.co https://www.facebook.com https://connect.facebook.net https://analytics.tiktok.com https://www.canstarblue.com.au https://www.canstar.com.au https://secure.gravatar.com https://ep1.adtrafficquality.google https://adtrafficquality.google; font-src 'self' https://fonts.gstatic.com https://themes.jifo.co https://gfonts.jifo.co https://cdn.jifo.co https://script.hotjar.com; frame-src 'self' https://www.youtube.com https://accounts.google.com https://e.infogram.com https://www.googletagmanager.com http://www.googletagmanager.com https://10445216.fls.doubleclick.net https://10420344.fls.doubleclick.net https://can.canstar.com.au https://can.canstarblue.com.au https://securepubads.g.doubleclick.net https://platform.twitter.com https://syndication.twitter.com https://a25480140109.cdn.optimizely.com; connect-src 'self' https://graph.canstar.com.au https://can.canstar.com.au https://can.canstarblue.com.au https://jnn-pa.googleapis.com https://www.google-analytics.com https://bat.bing.com https://www.clarity.ms https://sdk-02.moengage.com https://connect.facebook.net https://www.facebook.com https://accounts.google.com https://www.googletagmanager.com https://cdn.jifo.co https://s.infogram.com https://www.youtube.com https://www.google.com https://www.google.com.au https://www.googleadservices.com https://www.google.co.in https://www.gstatic.com https://securepubads.g.doubleclick.net https://stats.g.doubleclick.net https://play.google.com https://logx.optimizely.com https://identitytoolkit.googleapis.com https://sso.canstar.com.au https://ad.doubleclick.net https://adservice.google.com https://analytics.google.com https://clerk.canstar.com.au https://vital-wasp-63.clerk.accounts.dev https://faithful-gannet-95.clerk.accounts.dev https://clerk-telemetry.com https://analytics.tiktok.com https://analytics-ipv6.tiktokw.us https://metrics.hotjar.io https://surveystats.hotjar.io https://siteintercept.qualtrics.com https://collector-px58c3a4zy.perimeterx.net https://ep1.adtrafficquality.google https://adtrafficquality.google https://cns-angular-content-uat-2.freetls.fastly.net https://cns-angular-content-prod-1.freetls.fastly.net https://cns-angular-content-prod-2.freetls.fastly.net; worker-src 'self' blob:; base-uri 'self'; form-action 'self'; report-uri https://graph.canstar.com.au/csp-report; 1 default-src 'self'; report-uri https://csp-reporting.cloudflare.com/cdn-cgi/script_monitor/report?m=cFQ6jxu7n3ICJgJ_8KEGIFTixQgGlanGrhKYXlG_fY4-1770432141-1.0.1.1-5188JekaPfNmXMTYCYSMVYB0brOq5LKTLAIClAX8zTCs8g.v5bS1Ggy1b5F0pz3xD0fOeytP6tT_LowR.A3Kg3DFBR9IPYr7KolSiSteoiwTCzdiQEBHtlllCOUTwVwiiE_RdleKW1W6FdiX2PQC4SMUOdb2Nb_WSZi5bb9lfYnMoAt3GH34pJVEUtu10rWno5_1exx8bzt4r0b08bw.xA; report-to cf-qfcmaddmabsiilau 1 default-src 'self' https:; script-src 'self' https: 'unsafe-inline' 'unsafe-eval'; style-src 'self' https: 'unsafe-inline'; img-src 'self' https: data: blob:; media-src 'self' https: data: blob:; object-src 'none'; frame-ancestors 'self' https://experience.adobe.com https://infopoint.audi.it; connect-src 'self' https: wss://e0k754.acquire.io; base-uri 'self'; font-src 'self' https: data:; worker-src 'self' blob:; report-uri https://www.audi.it/api/csp-report; report-to csp-endpoint 1 object-src 'none'; script-src 'self' 'unsafe-inline' 'unsafe-eval' adform.net *.adform.net betano.co *.betano.co betgenius.com *.betgenius.com cookielaw.org *.cookielaw.org creativecdn.com *.creativecdn.com facebook.net *.facebook.net gmlinteractive.com *.gmlinteractive.com googletagmanager.com *.googletagmanager.com kameleoon.io *.kameleoon.io optimove.net *.optimove.net sportradar.com *.sportradar.com cloudflareinsights.com *.cloudflareinsights.com app.delivery *.app.delivery cloudflare.com *.cloudflare.com lgrckt-in.com *.lgrckt-in.com tostarsbuilding.com *.tostarsbuilding.com; report-uri https://csp-reporting.cloudflare.com/cdn-cgi/script_monitor/report?m=gxtlI1C8AwbuWRU0Aw2zLTmD_GO7ZnuSs5lUYCo7WyY-1770432701-1.0.1.1-xAqYZZ.1ZeM8ILFtGf_yuV_fmeqOzcrUqpOHbvnSLmhSAreWiIfhqwmdRUXcJLhS2HLrd1iDcwYrWhr1VJnJFm1G8dqFe5NSB5KIF0hg_9At2_mzaO3armNYVqsloRgYCPftkeIWlbDCzyAHzzlHy9r897ewrl1uPfOE6k12EtzUi9ld18z1JN8fyHzR9tZlg1b7MHAiVOl7VMQ0C5dhUg; report-to cf-zsenymfuchudxiwg 1 default-src 'self';base-uri 'self';frame-ancestors 'self';frame-src https://* 'self' epichttp: https://epic.gateway.patientco.com https://epic.production.paymentfusion.com https://premier.trustcommerce.com;script-src 'nonce-560b2b16b33c4f6f97137d91b677f2fc' https://mychart.et0965.epichosted.com 'self';img-src https://* 'self' blob: data:;connect-src 'self' epichttp:;style-src https://mychart.et0965.epichosted.com 'self' 'unsafe-inline';worker-src 'self' blob:;child-src 'self' blob:;form-action https://central.mychart.org/MyChart/ 'self';media-src https://* 'self' blob:; 1 font-src cdn.jsdelivr.net fonts.gstatic.com cdn.almapay.com fonts.googleapis.com https://applepay.cdn-apple.com *.cloudflare.com *.twitter.com *.gstatic.com *.typekit.net *.twimg.com *.trustedshops.com *.googleapis.com *.fontawesome.com https://fonts.bunny.net https://cdnjs.cloudflare.com applepay.cdn-apple.com https://*.123elec.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com https://connect-v2.fintecture.com https://connect-v2-sbx.fintecture.com *.twitter.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com https://*.123elec.com https://inrecruitingfr.intervieweb.it *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.getalma.eu www.google.com *.payplug.com *.dalenys.com https://applepay.cdn-apple.com *.twitter.com *.google.com api-qa.payplug.com secure-qa.payplug.com https://*.123elec.com https://inrecruitingfr.intervieweb.it *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com https://images.unsplash.com a.tile.openstreetmap.org b.tile.openstreetmap.org c.tile.openstreetmap.org *.openstreetmap.org maps.googleapis.com maps.gstatic.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com https://assets.fintecture.com https://secure-magenta.dalenys.com *.cloudflare.com *.googleadservices.com *.google-analytics.com *.paypal.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.googleapis.com *.gstatic.com magefan.com cm.magefan.com https://firebasestorage.googleapis.com https://*.123elec.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobedtm.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ cdn.jsdelivr.net https://maps.googleapis.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ maps.googleapis.com maps.gstatic.com fonts.googleapis.com chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com https://secure-magenta.dalenys.com https://applepay.cdn-apple.com api-qa.payplug.com cdn-qa.payplug.com cdn.payplug.com *.cloudflare.com *.twitter.com *.google-analytics.com *.twimg.com *.gstatic.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.googleapis.com apis.google.com *.google.com *.doofinder.com *.avada.io *.shopify.com https://cdnjs.cloudflare.com applepay.cdn-apple.com https://cdn.payplug.com https://cdn-qa.payplug.com https://inrecruitingfr.intervieweb.it api.payplug.com https://msr.123elec.com https://*.123elec.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com cdn.jsdelivr.net fonts.googleapis.com downloads.mailchimp.com https://secure-magenta.dalenys.com *.cloudflare.com *.googleapis.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.doofinder.com https://fonts.bunny.net https://fonts.googleapis.com https://cdnjs.cloudflare.com https://*.123elec.com *.stripe.network *.stripecdn.com *.amazon.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.getalma.eu https://maps.googleapis.com https://player.vimeo.com maps.googleapis.com form-assets.mailchimp.com *.intuit.com *.amazonaws.com *.cloudflare.com *.twitter.com *.paypal.com *.twimg.com *.doofinder.com wss://eu1-b-layer.doofinder.com https://get.geojs.io *.avada.io https://*.123elec.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' 'unsafe-inline' 'unsafe-eval' shop2gether.com.br *.shop2gether.com.br wake-components.fbitsstatic.net shop2gether.fbitsstatic.net *.wake.tech fbits.net nr-data.net newrelic.com google.com googletagmanager.com google-analytics.com facebook.net facebook.com jquery.com bootstrapcdn.com *.fbits.net *.nr-data.net *.newrelic.com *.google.com *.googletagmanager.com *.google-analytics.com *.facebook.net *.facebook.com *.jquery.com *.bootstrapcdn.com wss://signalr.fbits.net k-analytix.com *.k-analytix.com i.konduto.com *.yapay.com.br *.traycheckout.com.br h.online-metrix.net *.clearsale.com.br dzpxyxks1bfmb.cloudfront.net *.gstatic.com *.koin.com.br *.soclminer.com.br *.btg360.com.br *.socialminer.com signalrcore.fbits.net wss://signalrcore.fbits.net *.cloudfront.net *.mlstatic.com *.mercadopago.com *.mercadolibre.com *.mercadopago.com.br *.paypal.com *.paypalobjects.com gstatic.com *.fbits.store *.adyen.com *.criteo.com *.criteo.net *.g.doubleclick.net *.google.com.br *.googleadservices.com static.zdassets.com clarity.ms assets.zendesk.com *.creativecdn.com *.zdassets.com shop2gether.zendesk.com widget-mediator.zopim.com *.clarity.ms td.doubleclick.net icomm-public.s3.amazonaws.com *.pagar.me *.mundipagg.com *.getnet.com.br vm.icommgroup.com.br:3005 *.icommgroup.com.br:3005 *.icommgroup.com.br s3.sa-east-1.amazonaws.com *.sa-east-1.amazonaws.com *.braintree-api.com *.braintreegateway.com *.pagseguro.com.br *.adyen.com *.pagbank.com *.infraicommgroup.com:3005 *.infraicommgroup.com *.vindi.com.br *.cieloecommerce.cielo.com.br *.braspag.com.br *.pagador.com.br *.online-metrix.net bt-wake-connector.com.br *.pagaleve.com.br *.pagaleve.io wake-api.pagaleve.com.br securegtm.despegar.com api.ipify.org browser-intake-datadoghq.com *.datadoghq-browser-agent.com *.datadoghq.com wake.koin.com.br n8n.icommgroup.com.br *.azurewebsites.net *.hotjar.com *.fbits.net koin-custom-conector-gateway.fbits.net *.koin.com.br static.hotjar.com static.fbits.net payments.koin.com.br *.pinterest.com paypal-wake.s3.us-east-1.amazonaws.com *.useinsider.com *.api.useinsider.com nocodb.infraicommgroup.com:8080 nocodb.infraicommgroup.com *.cardinalcommerce.com *.secureacs.com *.crmbonus.com api.globalgetnet.com *.globalgetnet.com *.sandbox.3dsecure.io *.varify.io *.3dsecure.io *.sizebay.technology *.wepowerconnections.com *.sciencebehindecommerce.com *.zenaps.com *.awin1.com *.dwin1.com recommendationv2.api.useinsider.com wake-commerce-scripts.omni.chat viacep.com.br nominatim.openstreetmap.org trackings.nemu.com.br openfpcdn.io api.ipify.org api.bigdatacloud.net firebase.googleapis.com cdn.jsdelivr.net appleid.cdn-apple.com *.visa.com *.wake.tech *.appmax.com.br *.tunagateway.com *.internalsizebay.com src.mastercard.com api.fpjs.io *.pagoexpress.com.br ; img-src https: data:; style-src https: 'unsafe-inline'; font-src https: data:; frame-ancestors *.shop2gether.com.br shop2gether.com.br; report-uri https://pub-csp.fbits.net/89b96c87-f007-4cac-b565-ea42183a33fc; report-to https://pub-csp.fbits.net/89b96c87-f007-4cac-b565-ea42183a33fc; worker-src 'self' blob:; 1 object-src 'none';base-uri 'self';script-src 'nonce-2ws7kOsk3ELSV2wTjbbNLQ' 'strict-dynamic' 'report-sample' 'unsafe-eval' 'unsafe-inline' https: http:;report-uri https://csp.withgoogle.com/csp/gws/other-hp 1 font-src *.oney.io *.staging.oney.io *.fontawesome.com https://fonts.bunny.net fonts.googleapis.com fonts.gstatic.com https://stackpath.bootstrapcdn.com https://fonts.gstatic.com/ https://akio-25-49.akio.cloud/ https://service.joomeo.com *.gstatic.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.fd-recette.net https://akio-25-49.akio.cloud/ https://service.joomeo.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net https://www.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.google.com *.hipay-tpp.com *.hipay.com *.paypal.com *.google.com/ *.googleapis.com *.photoweb.com *.photoweb.es *.contentsquare.net *.kwanko.com https://hq-dev.magento.digitalphoto.dev https://cdn.segment.com https://events.eu1.segmentapis.com https://akio-25-49.akio.cloud/ https://www.googletagmanager.com https://widget.trustpilot.com https://privacy.fnac.phoenix.digitalphoto.group https://www.dwin1.com *.awin1.com *.zenaps.com https://the.sciencebehindecommerce.com https://*.wepowerconnections.com https://lantern.roeyecdn.com https://lantern.roeye.com https://service.joomeo.com https://gum.criteo.com/ https://www.mainadv.com/ https://tag.perfmaker.net/ https://tagassistant.google.com https://sst.photoweb.fr https://gum.criteo.com https://www.mainadv.com https://tag.perfmaker.net *.wepowerconnections.com *.facebook.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.hipay.com *.google.com *.oney.io *.staging.oney.io magefan.com cm.magefan.com *.facebook.com https://firebasestorage.googleapis.com * https://www.magezon.com *.openstreetmap.org maps.googleapis.com maps.gstatic.com photoweb.com *.photoweb.com *.magento.digitalphoto.dev blob: *.contentsquare.net https://akio-25-49.akio.cloud/ https://www.dwin1.com *.awin1.com *.zenaps.com https://the.sciencebehindecommerce.com https://*.wepowerconnections.com https://lantern.roeyecdn.com https://lantern.roeye.com https://service.joomeo.com *.hsforms.net *.hsforms.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.hipay-tpp.com *.hipay.com mpsnare.iesnare.com *.paypal.com *.google.com *.oney.io *.staging.oney.io *.googletagmanager.com *.facebook.net *.avada.io *.shopify.com * maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.eu01.nr-data.net *.trustpilot.com *.contentsquare.net *.privacy-center.org *.kwanko.com https://hq-dev.magento.digitalphoto.dev https://cdn.segment.com https://events.eu1.segmentapis.com https://akio-25-49.akio.cloud/ https://www.dwin1.com *.awin1.com *.zenaps.com https://the.sciencebehindecommerce.com https://*.wepowerconnections.com https://lantern.roeyecdn.com https://lantern.roeye.com https://service.joomeo.com https://cdn.jsdelivr.net *.hsforms.net *.hsforms.com *.gstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.hipay.com *.googleapis.com *.fontawesome.com https://fonts.bunny.net fonts.googleapis.com https://stackpath.bootstrapcdn.com https://fonts.googleapis.com/ https://fonts.google.com https://akio-25-49.akio.cloud/ https://service.joomeo.com https://cdn.jsdelivr.net *.gstatic.com https://www.googletagmanager.com https://tag.perfmaker.net/ 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com data: mpsnare.iesnare.com *.googleapis.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.hipay-tpp.com *.hipay.com wss://mpsnare.iesnare.com *.googleapis.com *.oney.io *.staging.oney.io *.google-analytics.com https://get.geojs.io *.avada.io maps.googleapis.com *.google.com https://stats.g.doubleclick.net *.eu01.nr-data.net *.contentsquare.net *.kwanko.com https://hq-dev.magento.digitalphoto.dev https://cdn.segment.com https://events.eu1.segmentapis.com https://akio-25-49.akio.cloud/ https://api.privacy-center.org/v1/events https://prompts.maze.co/api/widgets https://sdk.fra-02.braze.eu/api/v3/data/ https://pagead2.googlesyndication.com/ https://jls.photoweb.fr/ https://www.dwin1.com *.awin1.com *.zenaps.com https://the.sciencebehindecommerce.com https://*.wepowerconnections.com https://lantern.roeyecdn.com https://lantern.roeye.com https://service.joomeo.com t.elasticsuite.io *.hsforms.net *.hsforms.com https://sst.photoweb.fr *.googletagmanager.com region1.google-analytics.com region1.analytics.google.com stats.g.doubleclick.net https://halc.iadvize.com https://api.privacy-center.org https://prompts.maze.co https://sdk.fra-02.braze.eu https://akio-25-49.akio.cloud https://jls.photoweb.fr *.kameleoon.io *.merchant-center-analytics.goog *.iadvize.com *.tiktok.com *.perfmaker.net *.clarity.ms *.bing.com *.google.pt *.google.fr *.google.es *.google.de *.google.it *.google.be *.google.nl *.google.co.uk *.tiktokw.us 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self';script-src 'self' 'unsafe-inline' 'nonce-DkA5cx6+Tkbt+m+M1kbH0j0D' 'unsafe-eval' https://pixel.byspotify.com *.travcorpservices.com https://www.google.com https://www.google-analytics.com https://www.googleoptimize.com https://www.googletagmanager.com https://ajax.googleapis.com https://www.gstatic.com https://googleads.g.doubleclick.net https://api.feefo.com https://register.feefo.com https://bat.bing.com https://cdn.evgnet.com https://connect.facebook.net https://i.clarity.ms https://static-ssl.responsetap.com *.hotjar.com https://tag.simpli.fi https://unpkg.com https://www.bugherd.com https://decagon.ai https://www.datadoghq-browser-agent.com https://assetscdn.stackla.com/media/js https://vjs.zencdn.net https://cdn.amplitude.com/libs https://sdk.joinsherpa.io https://apps.mypurecloud.com https://consentcdn.cookiebot.com https://cdnjs.cloudflare.com https://ttc-contiki.entry.promo https://cdn.optimizely.com https://www.riddle.com;style-src 'self' 'unsafe-inline' https://assetscdn.stackla.com/media/components/stackla-uikit/dist https://fonts.googleapis.com https://p.typekit.net https://use.typekit.net https://vjs.zencdn.net https://apps.mypurecloud.com;img-src 'self' https://bat.bing.com https://c.clarity.ms https://i.ytimg.com https://www.facebook.com https://www.google-analytics.com https://www.google.com https://www.uplift-platform.com data:;frame-src 'self' https://10006172.fls.doubleclick.net https://uplift-cdn-stg.uplift.com https://vars.hotjar.com https://widget.stackla.com https://www.google.com https://apps.joinsherpa.io https://www.googletagmanager.com https://a25408250069.cdn.optimizely.com;font-src 'self' https://assetscdn.stackla.com https://fonts.gstatic.com https://use.typekit.net https://vjs.zencdn.net https://apps.mypurecloud.com;connect-src 'self' *.travcorpservices.com *.travcorp.com *.corp.ttc:7443 https://api.feefo.com https://bat.bing.com https://in.hotjar.com https://ws11.hotjar.com/api https://l.clarity.ms https://metrics.responsetap.com/infinity https://noembed.com https://pm-mrkt.prodgw.uplift-platform.com https://rum.browser-intake-datadoghq.com https://session-replay.browser-intake-datadoghq.com https://ttctravel.germany-2.evergage.com https://www.facebook.com https://www.google-analytics.com https://logx.optimizely.com https://region1.analytics.google.com https://ttc.contiki.com 1 default-src 'self'; connect-src 'self' *.engagement.coremedia.cloud *.byside.com wss://*.engagement.coremedia.cloud wss://*.byside.com; script-src 'self' *.engagement.coremedia.cloud 'unsafe-inline'; style-src 'self' *.engagement.coremedia.cloud 'unsafe-inline'; img-src 'self' *.engagement.coremedia.cloud data:; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.certcapture.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com www.google.com *.certcapture.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.trustpilot.com https://symphony.ocltraining-int.com https://symphony.ocltraining-qa.com https://symphony.ocltraining.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.certcapture.com magefan.com cm.magefan.com *.disqus.com https://img.youtube.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com www.googletagmanager.com https://rum.hlx.page www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.certcapture.com *.disqus.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.trustpilot.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.certcapture.com assets.braintreegateway.com *.trustpilot.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.certcapture.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src *.certcapture.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self';base-uri 'self';frame-ancestors 'self';frame-src https://* 'self' epichttp: https://premier.trustcommerce.com;script-src 'nonce-74f7f1ff62a4492caaadc05d202f1ce0' https://www.novantmychart.org 'self';img-src https://* 'self' blob: data:;connect-src 'self' epichttp:;style-src https://www.novantmychart.org 'self' 'unsafe-inline';worker-src 'self' blob:;child-src 'self' blob:;form-action https://central.mychart.org/MyChart/ 'self';media-src https://* 'self' blob:; 1 font-src *.lafoirfouille.fr use.typekit.net fonts.gstatic.com static.sensefuel.live data: 'self' 'unsafe-inline'; form-action *.lafoirfouille.fr sogecommerce.societegenerale.eu 'self' 'unsafe-inline'; frame-src *.lafoirfouille.fr www.google.com sogecommerce.societegenerale.eu 'self' 'unsafe-inline'; img-src *.lafoirfouille.fr www.googletagmanager.com cdn-cookieyes.com tag.beyable.com data: 'self' 'unsafe-inline'; script-src *.lafoirfouille.fr front.activation.beyable.com tag.search.sensefuel.live tag.search.sensefuel.com tag.beyable.com www.gstatic.com www.google.com www.googletagmanager.com cdn-cookieyes.com static.target2sell.com *.socloz.com beyableprodrt.blob.core.windows.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.lafoirfouille.fr fonts.googleapis.com use.typekit.net p.typekit.net tag.search.sensefuel.com *.search.sensefuel.live tag.beyable.com 'self' 'unsafe-inline'; manifest-src *.lafoirfouille.fr 'self' 'unsafe-inline'; connect-src *.lafoirfouille.fr *.snoophome.com cdn-cookieyes.com *.cookieyes.com *.target2sell.com *.search.sensefuel.live *.ingest.de.sentry.io *.google-analytics.com beyableprodrt.blob.core.windows.net www.googletagmanager.com www.google.com 'self' 'unsafe-inline'; media-src *.lafoirfouille.fr *.search.sensefuel.live 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; frame-ancestors https://*.lafoirfouille.fr/ https://api.cqeq65dd63-ffdigital1-d1-public.model-t.cc.commerce.ondemand.com https://api.cqeq65dd63-ffdigital1-s1-public.model-t.cc.commerce.ondemand.com https://api.cqeq65dd63-ffdigital1-p1-public.model-t.cc.commerce.ondemand.com https://v.calameo.com 'self'; object-src data: 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; base-uri 'self' 'unsafe-inline'; 1 script-src 'self' 'unsafe-inline' cdn.jsdelivr.net cdnjs.cloudflare.com ajax.googleapis.com js.pusher.com use.fontawesome.com sdk.amazonaws.com app-rsrc.getbee.io loader.getbee.io localhost:3000 localhost:8080 127.0.0.1:3000 127.0.0.1:8080; style-src 'self' 'unsafe-inline' cdn.jsdelivr.net cdnjs.cloudflare.com fonts.googleapis.com; img-src 'self' secure.gravatar.com cartstack.s3.amazonaws.com; font-src 'self' data: fonts.googleapis.com fonts.gstatic.com; connect-src 'self' api.cartstack.com ws-us3.pusher.com wss://ws-us3.pusher.com bee-auth.getbee.io bee-utils.getbee.io bee-stats.getbee.io bee-sentry.beefree.io bee-bumper.getbee.io localhost:3000 localhost:8080 ws://localhost:3000 ws://localhost:8080; frame-src 'self' app.getbee.io; default-src 'none'; object-src 'none'; media-src 'self'; worker-src 'self'; manifest-src 'self'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'; report-uri /csp-report.php 1 style-src-elem preprod-cdn.otter.ro cdn.otter.ro dev.otter247.local stage2.otter.ro stage2.tezyo.ro stage2.gryxx.ro stage2.aldoshoes.ro data: https://static.klaviyo.com https://cdn.jsdelivr.net https://*.adobe.com https://fonts.googleapis.com https://*.doubleclick.net https://*.facebook.com https://fonts.gstatic.com https://*.googletagmanager.com https://*.googlesyndication.com https://*.fontawesome.com https://maxcdn.bootstrapcdn.com https://fonts.bunny.net https://fonts.static.com https://*.nosto.com https://*.nos.to https://assets.braintreegateaway.com https://*.cloudfront.net https://*.reviews.io https://*.reviews.co.uk https://preprod-cdn.otter.ro https://cdn.otter.ro 'unsafe-inline' https://www.googletagmanager.com https://www.googlesyndication.com https://use.fontawesome.com https://assets.braintreegateway.com https://d2c7ipcroan06u2.cloudfront.net; font-src fonts.gstatic.com use.typekit.net *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com *.fontawesome.com maxcdn.bootstrapcdn.com *.cloudfront.net *.reviews.io *.reviews.co.uk *.googleapis.com https://fonts.bunny.net fonts.googleapis.com preprod-cdn.otter.ro cdn.otter.ro static.klaviyo.com cdn.jsdelivr.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com *.googlesyndication.com *.tiktok.com *.reviews.io *.reviews.co.uk *.nosto.com *.nos.to 'self' 'unsafe-inline'; frame-ancestors https://www.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ https://www.google.com/ *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com *.innoship.ro *.reviews.io *.reviews.co.uk *.nosto.com *.nos.to preprod-cdn.otter.ro cdn.otter.ro static.klaviyo.com cdn.jsdelivr.net https://www.googletagmanager.com https://consentcdn.cookiebot.eu https://event.2performant.com https://ams.creativecdn.com https://www.gstatic.com/ 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.gstatic.com *.googlesyndication.com *.roeye.com *.tiktok.com *.tile.openstreetmap.org *.openstreetmap.org * https://www.magezon.com *.cloudfront.net *.reviews.io *.reviews.co.uk https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://firebasestorage.googleapis.com quickchart.io img.youtube.com *.nosto.com *.nos.to www.google.com.ua preprod-cdn.otter.ro cdn.otter.ro static.klaviyo.com cdn.jsdelivr.net https://ss.otter.ro data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net https://www.google.com/ *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com cdn.jsdelivr.net *.tiktok.com * *.reviews.io *.reviews.co.uk https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.fontawesome.com *.googleapis.com https://www.gstatic.com/ *.avada.io *.shopify.com *.nosto.com *.nos.to maps.googleapis.com preprod-cdn.otter.ro cdn.otter.ro static.klaviyo.com https://cdn.otter.ro https://ss.otter.ro 'self' 'unsafe-inline' 'unsafe-eval'; style-src https://*.adobe.com fonts.googleapis.com *.googleapis.com https://*.doubleclick.net https://*.facebook.com *.gstatic.com https://*.googletagmanager.com https://*.googlesyndication.com *.tiktok.com https://*.fontawesome.com maxcdn.bootstrapcdn.com https://*.cloudfront.net *.reviews.io *.reviews.co.uk https://static.klaviyo.com https://fonts.bunny.net fonts.gstatic.com https://*.nosto.com *.nos.to preprod-cdn.otter.ro cdn.otter.ro dev.otter247.local stage2.otter.ro stage2.tezyo.ro stage2.gryxx.ro stage2.aldoshoes.ro data: https://cdn.jsdelivr.net https://fonts.googleapis.com https://fonts.gstatic.com https://maxcdn.bootstrapcdn.com https://fonts.static.com https://*.nos.to https://assets.braintreegateaway.com https://*.reviews.io https://*.reviews.co.uk https://preprod-cdn.otter.ro https://cdn.otter.ro 'unsafe-inline' https://www.googletagmanager.com https://www.googlesyndication.com https://use.fontawesome.com https://assets.braintreegateway.com https://d2c7ipcroan06u2.cloudfront.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com preprod-cdn.otter.ro cdn.otter.ro static.klaviyo.com cdn.jsdelivr.net 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.google-analytics.com *.facebook.com *.facebook.net https://www.google.com/ *.doubleclick.net *.googlesyndication.com *.tiktok.com *.cloudfront.net *.reviews.io *.reviews.co.uk https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://get.geojs.io *.avada.io *.nosto.com *.nos.to maps.googleapis.com preprod-cdn.otter.ro cdn.otter.ro stage2.otter.ro stage2.tezyo.ro stage2.gryxx.ro stage2.aldoshoes.ro static.klaviyo.com cdn.jsdelivr.net https://tezyo.zendesk.com https://ekr.zdassets.com https://*.zendesk.com https://*.zdassets.com https://event.2performant.com https://tidytracking.com https://ss.otter.ro 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src blob: https://*.mhcache.com;font-src 'self' https://*.myheritage.com https://*.mhcache.com https://fonts.gstatic.com;frame-src 'self' https://*.mhcache.com https://portal.allyable.com https://mh-site-files-5c53d6a9947c.s3.amazonaws.com https://myheritage-container.com https://www.myheritage-partners.com https://www.myheritage.com https://*.mk-sense.com https://player.vimeo.com https://*.facebook.com https://*.googleapis.com https://*.google.com https://tpc.googlesyndication.com https://*.doubleclick.net https://accounts.google.com/gsi/;script-src https://accounts.google.com/gsi/client https://www.datadoghq-browser-agent.com https://*.googleapis.com https://appleid.cdn-apple.com *.myheritage.nl https://www.myheritage.nl 'unsafe-eval' 'nonce-29719d7611561345e98dab7c0c742741' 'strict-dynamic';style-src data: blob: 'unsafe-inline' 'self' https://*.myheritage.com https://*.mhcache.com https://fonts.googleapis.com https://accounts.google.com/gsi/style;connect-src data: 'self' https://*.myheritage.com https://portal.allyable.com https://*.mhcache.com https://adservice.google.com https://*.logs.datadoghq.com https://*.browser-intake-datadoghq.com https://browser-intake-datadoghq.com https://sentry.io https://*.bing.com https://*.facebook.com https://*.doubleclick.net https://*.mk-sense.com https://*.filae.com https://accounts.google.com/gsi/ https://www.google.com/pagead/landing https://*.googleapis.com https://maps.googleapis.com/maps/api/mapsjs/gen_204 https://translate.googleapis.com https://www.google.com/ccm/collect https://cdn.builder.io *.myheritage.nl;media-src 'self' https://*.myheritage.com https://*.mhcache.com;frame-ancestors 'self' https://builder.io;img-src * data:;object-src 'none';base-uri 'self' https://*.mhcache.com;report-uri /FP/API/ContentSecurityPolicy/report-violation.php?report_mode=report&canonical_page_id=/company/home/ 1 font-src fonts.gstatic.com use.typekit.net cash-f.squarecdn.com converse.com.br https://magento.com *.converse.com.br *.fontawesome.com https://fonts.gstatic.com https://www.google.com https://www.gstatic.com *.gstatic.com 'self' data: data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com * www.facebook.com 'self' connect.facebook.net graph.facebook.com business.facebook.com https://plumrocket.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com * www.google.com https://gum.criteo.com/ api.sunset.systems targeting.voxus.tv https://springmedia.go2cloud.org/ https://googleads.g.doubleclick.net/ https://www.google.com.br/ https://tpc.googlesyndication.com/ https://static.criteo.net/ td.doubleclick.net https://fledge.us.criteo.com/ https://www.googletagmanager.com/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com https://plumrocket.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net * converse.com.br www.facebook.com https://mcstaging.converse.com.br www.google.com.br conectiva.io https://s.ad.smaato.net https://simage2.pubmatic.com https://ade.clmbtech.com/ https://sync-criteo.ads.yieldmo.com https://e1.emxdgt.com https://x.bidswitch.net/ https://cm.g.doubleclick.net https://ib.adnxs.com/ secure.adnxs.com https://pixel.rubiconproject.com/ https://match.sharethrough.com https://rtb-csync.smartadserver.com https://sync-t1.taboola.com/ https://criteo-sync.teads.tv https://eb2.3lift.com/ https://ups.analytics.yahoo.com/ https://tg.socdm.com/ https://visitor.omnitagjs.com https://gum.criteo.com https://r.casalemedia.com https://ads.stickyadstv.com https://ad.360yield.com https://matching.ivitrack.com https://i.liadm.com/ https://exchange.mediavine.com https://c.bing.com/ https://trends.revcontent.com https://criteo-partners.tremorhub.com/ https://secure.adnxs.com https://contextual.media.net https://dis.criteo.com https://tags.bluekai.com https://cm.adgrx.com https://sync.outbrain.com bat.bing.com https://device.clearsale.com.br https://c.clarity.ms https://rsp.servername.net http://rsp.servername.net https://googleads.g.doubleclick.net/ http://www.googleadservices.com/ https://idsync.rlcdn.com/ https://*.rakuten.com https://*.linksynergy.com https://*.nxtck.com https://*.xg4ken.com https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://*.g.doubleclick.net https://*.google.com https://*.google.com.br *.converse.com.br http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ connect.facebook.net graph.facebook.com business.facebook.com 'self' data: data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com https://adobe.com/ www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net https://amcglobal.sc.omtrdc.net/ commerce.adobe.net use.typekit.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-ds.com https://adyen.com pay.google.com *.payments-amazon.com http://www.paypal.com *.ratepay.com *.cash.app *.visa.com *.mastercard.com https://rum.hlx.page www.google.com/recaptcha/ www.gstatic.com/recaptcha/ converse.com.br js-agent.newrelic.com js.go2sdk.com tag.rmp.rakuten.com ads01.groovinads.com img.metaffiliation.com https://assets.adobedtm.com/ https://secure.authorize.net/ https://test.authorize.net/ https://js.braintreegateway.com/ https://unpkg.com/ https://commerce.adobe.net/ https://use.typekit.net/ https://t.paypal.com https://s.ytimg.com https://magento-ds.com www.facebook.com connect.facebook.net https://graph.facebook.com/ https://business.facebook.com/ https://google.com.br/ https://gstatic.com/ http://www.googletagmanager.com/ https://www.googletagmanager.com/ http://www.paypalobjects.com https://www.googleoptimize.com https://static.zdassets.com/ https://device.clearsale.com.br https://dynamic.criteo.com www.rtb123.com conectiva.io analytics.tiktok.com cdn.targeting.voxus.com.br https://app.cartstack.com.br bat.bing.com https://static.hotjar.com https://service.maxymiser.net https://widget-mediator.zopim.com https://sslwidget.criteo.com https://bat.bing.com www.clarity.ms targeting.voxus.com.br https://script.hotjar.com/ https://tpc.googlesyndication.com https://*.rakuten.com https://*.linksynergy.com https://*.nxtck.com https://*.xg4ken.com https://*.googletagmanager.com *.converse.com.br *.collect.igodigital.com graph.facebook.com business.facebook.com *.googleapis.com *.google.com *.gstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src https://adobe.com fonts.googleapis.com *.cash.app converse.com.br https://fonts.googleapis.com https://magento.com *.fontawesome.com https://gstatic.com use.typekit.net p.typekit.net *.converse.com.br *.googleapis.com *.google.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com https://static.zdassets.com/ *.converse.com.br http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io commerce.adobe.net qa-api.magedevteam.com *.sentry.io * fcmregistrations.googleapis.com firebaseinstallations.googleapis.com k.clarity.ms bam.nr-data.net converse.com.br https://dpm.demdex.net https://amcglobal.sc.omtrdc.net *.google-analytics.com https://commerce.adobedtm.com https://commerce.adobedc.net https://*.snplow.net https://api.magento.com https://*.adobe.io https://performance.typekit.net https://www.sandbox.paypal.com https://www.paypalobjects.com https://www.paypal.com https://pilot-payflowlink.paypal.com https://commerce.adobe.io https://commerce.adobe.net https://qa-api.magedevteam.com https://*.sentry.io https://*.adyen.com http://magento.com https://magento.com http://stats.g.doubleclick.net https://stats.g.doubleclick.net http://www.google-analytics.com https://www.google-analytics.com www.facebook.com https://connect.facebook.net https://graph.facebook.com https://business.facebook.com https://t.elasticsuite.io https://analytics.google.com/ https://ekr.zdassets.com/ https://conscooper.zendesk.com wss://widget-mediator.zopim.com https://analytics.tiktok.com targeting.voxus.com.br api.performa.ai https://www.google.com.br https://bat.bing.com/ https://api.ipify.org logs-01.loggly.com https://api.voxus.tv https://conectiva.io https://coopershoes.zendesk.com/ https://*.clarity.ms/ https://vc.hotjar.io/ https://pagead2.googlesyndication.com/ https://measurement-api.criteo.com/ https://*.analytics.google.com https://*.googletagmanager.com https://*.g.doubleclick.net https://*.google.com https://*.google.com.br *.converse.com.br http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ connect.facebook.net graph.facebook.com business.facebook.com http://dpm.demdex.net https://www.google.com https://www.gstatic.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src converse.com.br bat.bing.com k.clarity.ms www.google.com commerce.adobedc.net analytics.tiktok.com *.converse.com.br *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 object-src 'none'; script-src * 'unsafe-inline' 'unsafe-eval'; script-src-attr 'self'; base-uri 'self'; frame-ancestors 'self' https: 1 frame-ancestors 'none'; default-src 'self'; script-src 'self' 'nonce-OWI4OWRjMDctNDEyNy00NDQwLWI4OGYtMjhkNjJmZWU1OGU3' https://status.livepix.gg https://www.google.com https://www.gstatic.com https://www.googletagmanager.com https://js.intercomcdn.com https://widget.intercom.io https://www.youtube.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; font-src 'self' https://fonts.gstatic.com https://fonts.intercomcdn.com; img-src 'self' https://static.livepix.gg https://cdn.livepix.gg https://www.googletagmanager.com https://downloads.intercomcdn.com https://static.intercomassets.com https://js.intercomcdn.com https://messenger-apps.intercom.io https://i.ytimg.com; frame-src 'self' https://checkout.livepix.gg https://rlgrjlrv2czy.statuspage.io https://www.googletagmanager.com https://intercom-sheets.com https://www.google.com https://www.youtube.com; connect-src 'self' https://webservice.livepix.gg https://unleash.livepix.gg https://fingerprint.livepix.gg https://fp.livepix.gg https://livia.livepix.gg https://www.google.com https://www.google-analytics.com https://api-iam.intercom.io wss://nexus-websocket-a.intercom.io https://o4508013286391808.ingest.us.sentry.io; manifest-src 'self' https://static.livepix.gg; media-src 'self' blob: https://static.livepix.gg https://js.intercomcdn.com 1 script-src 'self' 'unsafe-eval' https://connect.facebook.net https://am.yahoo.co.jp https://b99.yahoo.co.jp https://www.google-analytics.com assets.adobedtm.com https://www.googletagmanager.com http://hm.mieru-ca.com https://hpjp.mieru-ca.com https://www.everestjs.net https://s.yimg.jp http://aigjapan.sc.omtrdc.net https://www.youtube.com 'sha256-dMIRRtml3Oi21Iaq03PtC+8mIuBozHki1nfF3K1YXgw=' 'sha256-Yw3/67WDFoT7czVF2RALaOaLaRtweKwjgMzcHEb7oIs=' 'sha256-+/WzJIUpU+5NsHuQGBp2n0iZvi5LUQ0h8K/qrDy2YJQ=' 'sha256-T4GdVguKtoAY/4wetSihwnlAEpUpN0SBr64TOJa8NU0=' 'sha256-KIDFo1cCsPZjm0CKg+wI3amz1hzD9mNUJ2+4AGHa3uU=' 'sha256-LBsTTQlX5+H68ly1EZvOY6Z9bHzQqntXIpb70r7UJis=' 'sha256-U/nEWHrEPshKXL66+Ph2p6sLJqyHx9w9Sjv8K1Ya0zU=' 'sha256-BcF795XkHI9YEs7DNkb2Auwhmzf0SqcdlO/cXV17POc=' 'sha256-cQonxShNT1IfSfxwOOa2GnQjv3H9iqQdPYmUrW6Tl9w=' 'sha256-Dsxt1/qoUZUtAc/xB2KsqxHj3ORjhh9iGH+ezhmuyks=' 'sha256-UeZ0R36qQ5kcoJ4QcT9JHYwgL70p9095Vm9jdRGAKSc=' 'nonce-qutxwmnqzkdqtq';script-src-elem 'self' https://connect.facebook.net https://am.yahoo.co.jp https://b99.yahoo.co.jp https://www.google-analytics.com assets.adobedtm.com https://www.googletagmanager.com http://hm.mieru-ca.com https://hpjp.mieru-ca.com https://www.everestjs.net https://s.yimg.jp http://aigjapan.sc.omtrdc.net https://www.youtube.com 'sha256-dMIRRtml3Oi21Iaq03PtC+8mIuBozHki1nfF3K1YXgw=' 'sha256-Yw3/67WDFoT7czVF2RALaOaLaRtweKwjgMzcHEb7oIs=' 'sha256-+/WzJIUpU+5NsHuQGBp2n0iZvi5LUQ0h8K/qrDy2YJQ=' 'sha256-T4GdVguKtoAY/4wetSihwnlAEpUpN0SBr64TOJa8NU0=' 'sha256-KIDFo1cCsPZjm0CKg+wI3amz1hzD9mNUJ2+4AGHa3uU=' 'sha256-LBsTTQlX5+H68ly1EZvOY6Z9bHzQqntXIpb70r7UJis=' 'sha256-U/nEWHrEPshKXL66+Ph2p6sLJqyHx9w9Sjv8K1Ya0zU=' 'sha256-BcF795XkHI9YEs7DNkb2Auwhmzf0SqcdlO/cXV17POc=' 'sha256-cQonxShNT1IfSfxwOOa2GnQjv3H9iqQdPYmUrW6Tl9w=' 'sha256-Dsxt1/qoUZUtAc/xB2KsqxHj3ORjhh9iGH+ezhmuyks=' 'sha256-UeZ0R36qQ5kcoJ4QcT9JHYwgL70p9095Vm9jdRGAKSc=' 'nonce-qutxwmnqzkdqtq'; 1 default-src 'self' https://*.ototoy.jp; script-src 'self' 'unsafe-inline' 'unsafe-eval' blob: https://*.ototoy.jp https://bccks.jp https://cdnjs.cloudflare.com/ajax/libs/jquery.bootstrapvalidator/ https://connect.facebook.net https://platform.instagram.com https://www.instagram.com https://code.jquery.com https://scdn.line-apps.com https://d.line-scdn.net https://embed.nicovideo.jp https://platform.twitter.com https://syndication.twitter.com https://player.vimeo.com https://platform.vine.co https://static-fe.payments-amazon.com https://*.googleapis.com https://*.gstatic.com https://*.google.com https://*.ggpht.com https://*.googleusercontent.com https://*.google-analytics.com https://*.googletagmanager.com; style-src 'self' 'unsafe-inline' https://*.ototoy.jp https://cdnjs.cloudflare.com/ajax/libs/font-awesome/ https://cdnjs.cloudflare.com/ajax/libs/jquery.bootstrapvalidator/ https://fonts.googleapis.com; img-src 'self' data: blob: *; font-src 'self' data: https://cdnjs.cloudflare.com/ajax/libs/font-awesome/ https://fonts.gstatic.com; connect-src 'self' data: blob: https://*.ototoy.jp https://payments-fe.amazon.com https://api3.veritrans.co.jp https://*.googleapis.com https://*.gstatic.com https://*.google-analytics.com https://*.analytics.google.com https://analytics.google.com https://*.googletagmanager.com https://*.g.doubleclick.net https://*.google.com https://*.google.ad https://*.google.ae https://*.google.com.af https://*.google.com.ag https://*.google.al https://*.google.am https://*.google.co.ao https://*.google.com.ar https://*.google.as https://*.google.at https://*.google.com.au https://*.google.az https://*.google.ba https://*.google.com.bd https://*.google.be https://*.google.bf https://*.google.bg https://*.google.com.bh https://*.google.bi https://*.google.bj https://*.google.com.bn https://*.google.com.bo https://*.google.com.br https://*.google.bs https://*.google.bt https://*.google.co.bw https://*.google.by https://*.google.com.bz https://*.google.ca https://*.google.cd https://*.google.cf https://*.google.cg https://*.google.ch https://*.google.ci https://*.google.co.ck https://*.google.cl https://*.google.cm https://*.google.cn https://*.google.com.co https://*.google.co.cr https://*.google.com.cu https://*.google.cv https://*.google.com.cy https://*.google.cz https://*.google.de https://*.google.dj https://*.google.dk https://*.google.dm https://*.google.com.do https://*.google.dz https://*.google.com.ec https://*.google.ee https://*.google.com.eg https://*.google.es https://*.google.com.et https://*.google.fi https://*.google.com.fj https://*.google.fm https://*.google.fr https://*.google.ga https://*.google.ge https://*.google.gg https://*.google.com.gh https://*.google.com.gi https://*.google.gl https://*.google.gm https://*.google.gr https://*.google.com.gt https://*.google.gy https://*.google.com.hk https://*.google.hn https://*.google.hr https://*.google.ht https://*.google.hu https://*.google.co.id https://*.google.ie https://*.google.co.il https://*.google.im https://*.google.co.in https://*.google.iq https://*.google.is https://*.google.it https://*.google.je https://*.google.com.jm https://*.google.jo https://*.google.co.jp https://*.google.co.ke https://*.google.com.kh https://*.google.ki https://*.google.kg https://*.google.co.kr https://*.google.com.kw https://*.google.kz https://*.google.la https://*.google.com.lb https://*.google.li https://*.google.lk https://*.google.co.ls https://*.google.lt https://*.google.lu https://*.google.lv https://*.google.com.ly https://*.google.co.ma https://*.google.md https://*.google.me https://*.google.mg https://*.google.mk https://*.google.ml https://*.google.com.mm https://*.google.mn https://*.google.com.mt https://*.google.mu https://*.google.mv https://*.google.mw https://*.google.com.mx https://*.google.com.my https://*.google.co.mz https://*.google.com.na https://*.google.com.ng https://*.google.com.ni https://*.google.ne https://*.google.nl https://*.google.no https://*.google.com.np https://*.google.nr https://*.google.nu https://*.google.co.nz https://*.google.com.om https://*.google.com.pa https://*.google.com.pe https://*.google.com.pg https://*.google.com.ph https://*.google.com.pk https://*.google.pl https://*.google.pn https://*.google.com.pr https://*.google.ps https://*.google.pt https://*.google.com.py https://*.google.com.qa https://*.google.ro https://*.google.ru https://*.google.rw https://*.google.com.sa https://*.google.com.sb https://*.google.sc https://*.google.se https://*.google.com.sg https://*.google.sh https://*.google.si https://*.google.sk https://*.google.com.sl https://*.google.sn https://*.google.so https://*.google.sm https://*.google.sr https://*.google.st https://*.google.com.sv https://*.google.td https://*.google.tg https://*.google.co.th https://*.google.com.tj https://*.google.tl https://*.google.tm https://*.google.tn https://*.google.to https://*.google.com.tr https://*.google.tt https://*.google.com.tw https://*.google.co.tz https://*.google.com.ua https://*.google.co.ug https://*.google.co.uk https://*.google.com.uy https://*.google.co.uz https://*.google.com.vc https://*.google.co.ve https://*.google.co.vi https://*.google.com.vn https://*.google.vu https://*.google.ws https://*.google.rs https://*.google.co.za https://*.google.co.zm https://*.google.co.zw https://*.google.cat; frame-src 'self' https://bandcamp.com https://m.facebook.com https://mobile.facebook.com https://web.facebook.com https://www.facebook.com https://www.instagram.com https://social-plugins.line.me https://embed.nicovideo.jp https://w.soundcloud.com https://open.spotify.com https://platform.twitter.com https://syndication.twitter.com https://player.vimeo.com https://www.youtube.com https://secure2.arcot.com https://secure4.arcot.com https://dig-acs2.cafis-paynet.jp https://dig3ds.cafis-paynet.jp https://geoissuer.cardinalcommerce.com https://acs-jcn.dnp-cdms.jp https://api.veritrans.co.jp https://*.google.com https://td.doubleclick.net; report-uri /csp-report.php?v=3 1 font-src *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com https://static.dhlecommerce.nl https://fonts.gstatic.com *.fontawesome.com * data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com *.googlesyndication.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com https://www.paypal.com https://hostedfields-externalapi.alpha.buckaroo.aws https://hostedfields-externalapi.prod-pci.buckaroo.io * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.gstatic.com *.googlesyndication.com *.roeye.com https://portal.payconiq.com https://static.buckaroo.nl https://www.paypalobjects.com https://maps.googleapis.com https://maps.gstatic.com * data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com *.jsdelivr.net https://static.buckaroo.nl https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl https://buckaroo.nl https://www.paypal.com https://hostedfields-externalapi.alpha.buckaroo.aws https://hostedfields-externalapi.prod-pci.buckaroo.io https://static.dhlecommerce.nl https://maps.googleapis.com * 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl https://static.dhlecommerce.nl https://maps.googleapis.com https://fonts.googleapis.com *.fontawesome.com * 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com * 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.google-analytics.com *.facebook.com *.facebook.net *.google.com *.doubleclick.net *.googlesyndication.com wss://websocketservice-externalapi.prod.buckaroo.io https://static.buckaroo.nl wss://websockets.buckaroo.io/ https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl https://hostedfields-externalapi.alpha.buckaroo.aws https://hostedfields-externalapi.prod-pci.buckaroo.io https://applepay.buckaroo.io https://www.paypal.com https://api-gw.dhlparcel.nl https://static.dhlecommerce.nl https://maps.googleapis.com * 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.oct8ne.com *.salesforce-sites.com *.lightning.force.com fonts.gstatic.com *.azureedge.net *.doofinder.com *.typekit.net *.googleapis.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' 'unsafe-inline'; frame-ancestors *.storyblok.com 'self'; style-src *.doofinder.com *.salesforce-sites.com *.lightning.force.com *.photoslurp.com *.nosto.com *.klaviyo.com *.typekit.net *.storyblok.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.salesforce-sites.com *.lightning.force.com *.storyblok.com *.zdassets.com *.doofinder.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; img-src https://www.googletagmanager.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com https://images.unsplash.com cdn.doofinder.com *.oct8ne.com *.salesforce-sites.com *.lightning.force.com https://sandbox.sequracdn.com https://live.sequracdn.com *.facebook.com *.google.com *.google.es widgets.trustedshops.com *.twitter.com t.co *.azureedge.net *.pinterest.com *.doofinder.com *.bing.com www.googletagmanager.com *.storyblok.com data: 'self' 'unsafe-inline'; frame-src https://www.googletagmanager.com https://www.google.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.oct8ne.com *.salesforce-sites.com *.lightning.force.com https://sandbox.sequracdn.com https://live.sequracdn.com *.hotjar.com *.pinterest.com *.doofinder.com *.empathybroker.com *.empathy.co *.criteo.com www.googletagmanager.com 'self' 'unsafe-inline'; script-src https://analytics.tiktok.com/ https://ui.swogo.net/ https://www.googletagmanager.com www.googleadservices.com www.google-analytics.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://maps.googleapis.com cdn.doofinder.com *.oct8ne.com *.salesforce-sites.com *.lightning.force.com https://sandbox.sequracdn.com https://live.sequracdn.com www.googletagmanager.com *.googleoptimize.com widgets.trustedshops.com static-eu.oct8ne.com static.zdassets.com *.facebook.net *.tradedoubler.com *.doubleclick.net *.hotjar.com *.ads-twitter.com smct.co *.bsmartdata.com *.retargeted.co *.bing.com *.clarity.ms *.smartsuppcdn.com *.smartsuppchat.com *.smartsupp.com *.connectif.cloud *.klaviyo.com *.photoslurp.com *.pinimg.com *.nosto.com *.doofinder.com *.empathybroker.com *.unpkg.com *.storyblok.com 'self' 'unsafe-inline' 'unsafe-eval'; connect-src https://analytics.tiktok.com/ https://tracking.swogo.net/ https://api.swogo.net/ https://api.trustedshops.com/ https://www.googletagmanager.com https://www.google.com www.google-analytics.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://maps.googleapis.com https://player.vimeo.com *.doofinder.com wss://*.doofinder.com *.oct8ne.com *.salesforce-sites.com *.lightning.force.com https://sandbox.sequracdn.com https://live.sequracdn.com *.zendesk.com *.zopim.com *.doubleclick.net *.hotjar.com *.hotjar.io *.clarity.ms *.smartsuppcdn.com *.googleapis.com *.gstatic.com *.google-analytics.com *.google.es *.connectif.cloud *.klaviyo.com *.photoslurp.com *.zdassets.com *.pinterest.com *.nosto.com *.empathybroker.com *.empathy.co www.googletagmanager.com 'self' 'unsafe-inline'; 1 default-src 'none'; report-uri /api/sec-csp/110000764/report 1 default-src 'self' https://*.brandhub.codered.net https://*.powertrain.codered.net; media-src 'self' blob:; script-src 'self' https://mb.etrackingserver.de https://*.scene7.com https://app.usercentrics.eu https://chatbot.codered.net/static/ 'unsafe-inline' 'unsafe-eval' blob:; style-src 'self' 'unsafe-inline' https://*.scene7.com https://chatbot.codered.net/static/; img-src 'self' https://js.api.here.com https://*.scene7.com https://*.usercentrics.eu https://dev.day.com blob: data:; connect-src 'self' https://*.usercentrics.eu https://mb.etrackingserver.de https://*.scene7.com https://*.mercedes-benz-trucks.net https://*.hereapi.com https://*.api.here.com https://chatbot.codered.net blob:; font-src 'self' https://js.api.here.com data:; 1 default-src *; script-src data: http: https: 'unsafe-inline' 'unsafe-eval'; style-src 'self' data: 'unsafe-inline' https: *.bootstrapcdn.com; img-src * 'self' data: blob:; font-src *; connect-src https:; media-src *; object-src 'none'; frame-src *; report-uri https://www.hsag.com/_csp; 1 script-src 'self' 'nonce-+FU0PzLka7UAAxJJORtyJb4d+XgCPIN49kUf++b/8es=' 'strict-dynamic' 'wasm-unsafe-eval' www.youtube.com az416426.vo.msecnd.net cdn.cookielaw.org www.google-analytics.com maps.googleapis.com www.googletagmanager.com dl.episerver.net www.youtube.com www.google.com www.gstatic.com snap.licdn.com https://*.googletagmanager.com https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://*.g.doubleclick.net https://*.google.com https://*.google.com https://*.google.ad https://*.google.ae https://*.google.com.af https://*.google.com.ag https://*.google.com.ai https://*.google.al https://*.google.am https://*.google.co.ao https://*.google.com.ar https://*.google.as https://*.google.at https://*.google.com.au https://*.google.az https://*.google.ba https://*.google.com.bd https://*.google.be https://*.google.bf https://*.google.bg https://*.google.com.bh https://*.google.bi https://*.google.bj https://*.google.com.bn https://*.google.com.bo https://*.google.com.br https://*.google.bs https://*.google.bt https://*.google.co.bw https://*.google.by https://*.google.com.bz https://*.google.ca https://*.google.cd https://*.google.cf https://*.google.cg https://*.google.ch https://*.google.ci https://*.google.co.ck https://*.google.cl https://*.google.cm https://*.google.cn https://*.google.com.co https://*.google.co.cr https://*.google.com.cu https://*.google.cv https://*.google.com.cy https://*.google.cz https://*.google.de https://*.google.dj https://*.google.dk https://*.google.dm https://*.google.com.do https://*.google.dz https://*.google.com.ec https://*.google.ee https://*.google.com.eg https://*.google.es https://*.google.com.et https://*.google.fi https://*.google.com.fj https://*.google.fm https://*.google.fr https://*.google.ga https://*.google.ge https://*.google.gg https://*.google.com.gh https://*.google.com.gi https://*.google.gl https://*.google.gm https://*.google.gr https://*.google.com.gt https://*.google.gy https://*.google.com.hk https://*.google.hn https://*.google.hr https://*.google.ht https://*.google.hu https://*.google.co.id https://*.google.ie https://*.google.co.il https://*.google.im https://*.google.co.in https://*.google.iq https://*.google.is https://*.google.it https://*.google.je https://*.google.com.jm https://*.google.jo https://*.google.co.jp https://*.google.co.ke https://*.google.com.kh https://*.google.ki https://*.google.kg https://*.google.co.kr https://*.google.com.kw https://*.google.kz https://*.google.la https://*.google.com.lb https://*.google.li https://*.google.lk https://*.google.co.ls https://*.google.lt https://*.google.lu https://*.google.lv https://*.google.com.ly https://*.google.co.ma https://*.google.md https://*.google.me https://*.google.mg https://*.google.mk https://*.google.ml https://*.google.com.mm https://*.google.mn https://*.google.ms https://*.google.com.mt https://*.google.mu https://*.google.mv https://*.google.mw https://*.google.com.mx https://*.google.com.my https://*.google.co.mz https://*.google.com.na https://*.google.com.ng https://*.google.com.ni https://*.google.ne https://*.google.nl https://*.google.no https://*.google.com.np https://*.google.nr https://*.google.nu https://*.google.co.nz https://*.google.com.om https://*.google.com.pa https://*.google.com.pe https://*.google.com.pg https://*.google.com.ph https://*.google.com.pk https://*.google.pl https://*.google.pn https://*.google.com.pr https://*.google.ps https://*.google.pt https://*.google.com.py https://*.google.com.qa https://*.google.ro https://*.google.ru https://*.google.rw https://*.google.com.sa https://*.google.com.sb https://*.google.sc https://*.google.se https://*.google.com.sg https://*.google.sh https://*.google.si https://*.google.sk https://*.google.com.sl https://*.google.sn https://*.google.so https://*.google.sm https://*.google.sr https://*.google.st https://*.google.com.sv https://*.google.td https://*.google.tg https://*.google.co.th https://*.google.com.tj https://*.google.tl https://*.google.tm https://*.google.tn https://*.google.to https://*.google.com.tr https://*.google.tt https://*.google.com.tw https://*.google.co.tz https://*.google.com.ua https://*.google.co.ug https://*.google.co.uk https://*.google.com.uy https://*.google.co.uz https://*.google.com.vc https://*.google.co.ve https://*.google.vg https://*.google.co.vi https://*.google.com.vn https://*.google.vu https://*.google.ws https://*.google.rs https://*.google.co.za https://*.google.co.zm https://*.google.co.zw https://*.google.cat https://connect.facebook.net/ https://munchkin.marketo.net/ static.hotjar.com script.hotjar.com https://cdn.jsdelivr.net/;object-src 'none';base-uri 'self';report-uri https://o4507537122852864.ingest.de.sentry.io/api/4507764299726928/security/?sentry_key=2e67b3fa9c193f38db8ea33933d09ffa&sentry_environment=production&sentry_release=sprint24; 1 default-src 'self' https://*.appreciatehub.com *.google-analytics.com *.cloudflare.com https://*.googleapis.com https://*.pendo.io https://*.alamoapp.octanner.io https://*.api.octanner.net https://*.salesforce.com *.cloudinary.com https://s3.amazonaws.com/oc-images-api/* *.doubleclick.net *.octanner.net *.gstatic.com *.jwpcdn.com *.recaptcha.net https://www.gstatic.com/recaptcha/releases/* wss://*.fathomvoice.com *.fathomvoice.com *.fonticons.com *.fortawesome.com 'unsafe-inline' 'unsafe-eval' data:; frame-src 'self' www.google.com www.recaptcha.net https://res.cloudinary.com; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com https://fonts.bunny.net *.merkur-static.si cdn.jsdelivr.net cdn.cnj.si omara.cdn-cnj.si ka-p.fontawesome.com media.flixfacts.com 'self' data: *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.paypal.com https://lapp.leanpay.hr https://app.leanpay.hr https://stage-app.leanpay.si https://app.leanpay.si https://stage-app.leanpay.ro https://vendor.leanpay.ro *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.braintreegateway.com *.paypal.com google.com *.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io *.paypal.com *.typekit.net *.gstatic.com https://firebasestorage.googleapis.com cdn.jsdelivr.net *.nosto.com *.merkur-static.si *.fontawesome.com img.cdn-cnj.si www.merkur-static.si thumbs.nosto.com media.flixcar.com media.flixfacts.com logo.flix360.io rt.flix360.com maps.gstatic.com *.visualwebsiteoptimizer.com *.google.si *.facebook.com *.iprom.net *.hubspot.com inpref.com 536003278.recs.igodigital.com maps.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com 'self' data: www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://api.cartfox.io https://app.cartfox.io *.avada.io *.shopify.com *.merkur-static.si cdn.jsdelivr.net unpkg.com *.pushpushgo.com *.fontawesome.com *.nosto.com *.smind.si kit.fontawesome.com inte.searchnode.io connect.nosto.com cpx.smind.si media.flixfacts.com media.flixcar.com maps.googleapis.com *.cloudfront.net *.iprom.net *.hs-scripts.com *.hs-banner.com *.hs-analytics.net *.facebook.net *.videoly.co 536003278.recs.igodigital.com 536003278.collect.igodigital.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.gstatic.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com https://fonts.bunny.net *.merkur-static.si cdn.jsdelivr.net media.flixcar.com assets.braintreegateway.com *.googleapis.com *.gstatic.com *.stripe.network *.stripecdn.com *.amazon.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://api.cartfox.io https://app.cartfox.io https://get.geojs.io *.avada.io *.merkur-static.si unpkg.com *.pushpushgo.com *.nosto.com *.fontawesome.com region1.google-analytics.com kit.fontawesome.com ka-p.fontawesome.com connect.nosto.com media.flixcar.com maps.googleapis.com *.visualwebsiteoptimizer.com inpref.com *.doubleclick.net *.iprom.net 536003278.recs.igodigital.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.google-analytics.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src media.flixcar.com rt.flix360.com 536003278.recs.igodigital.com *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://d045c69f-01fa-46bf-a2b1-87c1c2bb7952.sansec.watch/; report-to report-endpoint; 1 base-uri *.google.com *.gstatic.com 'self' 'unsafe-inline'; default-src *.google.com *.gstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; media-src *.google.com *.gstatic.com *.storyblok.com *.zdassets.com *.doofinder.com 'self' 'unsafe-inline'; manifest-src *.google.com *.gstatic.com 'self' 'unsafe-inline'; child-src *.google.com *.gstatic.com http: https: blob: 'self' 'unsafe-inline'; object-src *.google.com *.gstatic.com 'self' 'unsafe-inline'; style-src *.google.com *.gstatic.com *.doofinder.com *.photoslurp.com *.nosto.com *.klaviyo.com *.typekit.net *.storyblok.com 'self' 'unsafe-inline'; img-src *.google.com *.gstatic.com https://alehop.smartie.io widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.adyen.com cdn.doofinder.com https://images.unsplash.com *.oct8ne.com *.facebook.com *.google.es widgets.trustedshops.com *.twitter.com t.co *.azureedge.net *.pinterest.com *.doofinder.com *.bing.com www.googletagmanager.com *.storyblok.com data: 'self' 'unsafe-inline'; form-action *.google.com *.gstatic.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.adyen.com 'self' 'unsafe-inline'; font-src *.google.com *.oct8ne.com fonts.gstatic.com *.azureedge.net *.doofinder.com *.typekit.net *.googleapis.com data: 'self' 'unsafe-inline'; frame-ancestors *.google.com *.gstatic.com *.storyblok.com 'self'; frame-src td.doubleclick.net www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.adyen.com *.oct8ne.com *.hotjar.com *.pinterest.com *.doofinder.com *.empathybroker.com *.empathy.co *.criteo.com www.googletagmanager.com 'self' 'unsafe-inline'; connect-src *.google.com *.googlesyndication.com analytics.tiktok.com *.analytics.google.com *.gstatic.com www.google-analytics.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adyen.com *.doofinder.com wss://*.doofinder.com https://maps.googleapis.com https://player.vimeo.com *.oct8ne.com *.zendesk.com *.zopim.com *.doubleclick.net *.hotjar.com *.hotjar.io *.clarity.ms *.smartsuppcdn.com *.googleapis.com *.google-analytics.com *.google.es *.connectif.cloud *.klaviyo.com *.photoslurp.com *.zdassets.com *.pinterest.com *.nosto.com *.empathybroker.com *.empathy.co www.googletagmanager.com 'self' 'unsafe-inline'; script-src https://analytics.tiktok.com *.google.com *.gstatic.com www.googleadservices.com www.google-analytics.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.adyen.com cdn.doofinder.com https://maps.googleapis.com *.oct8ne.com www.googletagmanager.com *.googleoptimize.com widgets.trustedshops.com static-eu.oct8ne.com static.zdassets.com *.facebook.net *.tradedoubler.com *.doubleclick.net *.hotjar.com *.ads-twitter.com smct.co *.bsmartdata.com *.retargeted.co *.bing.com *.clarity.ms *.smartsuppcdn.com *.smartsuppchat.com *.smartsupp.com *.connectif.cloud *.klaviyo.com *.photoslurp.com *.pinimg.com *.nosto.com *.doofinder.com *.empathybroker.com *.unpkg.com *.storyblok.com 'self' 'unsafe-inline' 'unsafe-eval'; 1 default-src 'self';base-uri 'self';frame-ancestors 'self';frame-src https://* 'self' epichttp: https://mychart.personapay.com;script-src 'nonce-3d5d095a25804c50a0f1708ea2eb8c0e' https://mywvuchart.com 'self';img-src https://* 'self' blob: data:;connect-src 'self' epichttp:;style-src https://mywvuchart.com 'self' 'unsafe-inline';worker-src 'self' blob:;child-src 'self' blob:;form-action https://central.mychart.org/MyChart/ 'self';media-src https://* 'self' blob:; 1 script-src 'nonce-AoVsHj3NK01xaEkz_O9XBg' 'report-sample' 'strict-dynamic' 'unsafe-eval' 'unsafe-inline' http: https:; object-src 'none'; report-uri https://csp.withgoogle.com/csp/uxe-owners-acl; base-uri 'none' 1 default-src 'self'; script-src 'self'; connect-src 'self'; img-src 'self'; style-src 'self';base-uri 'self';form-action 'self' 1 connect-src 'self' data: https://www.motonet.fi https://graphql.datocms.com https://*.doubleclick.net https://www.instagram.com https://*.broman.group https://*.litix.io https://vimeo.com https://*.klarna.com https://*.klarnaevt.com/v1/ https://*.adyen.com/checkoutanalytics/ https://*.adyen.com/checkoutshopper/ https://api.postmarkapp.com https://www.youtube.com https://api.videoly.co https://js.testfreaks.com https://api.testfreaks.com https://reviews.testfreaks.com https://policy.app.cookieinformation.com https://consent.app.cookieinformation.com/api/consent https://api.custobar.com/js/v1/custobar.js https://*.google-analytics.com https://googleads.g.doubleclick.net/pagead/viewthroughconversion/ https://*.googlesyndication.com https://*.adform.net https://*.creativecdn.com https://connect.facebook.net https://browser-intake-datadoghq.eu https://*.broman.group https://js.playground.kustom.co https://eu.klarnaevt.com https://*.cdn.adyen.com/checkoutshopper/ https://i.ytimg.com https://www.datocms-assets.com https://stagingaksapimanagementbroman.azure-api.net https://testapimanagementbroman.azure-api.net https://*.googleapis.com https://*.gstatic.com *.google.com https://*.ggpht.com https://*.mux.com https://*.vimeocdn.com https://dapi.videoly.co https://*.facebook.com https://*.seadform.net https://*.adform.net https://*.criteo.net https://*.criteo.com https://www.googletagmanager.com/ https://ib.adnxs.com/setuid https://ib.adnxs.com/getuid https://cm.g.doubleclick.net https://dev.visualwebsiteoptimizer.com https://qr.motonet.fi https://*.googletagmanager.com https://eu.fw-cdn.com https://*.freshchat.com/ https://src.freshmarketer.eu/mas; img-src 'self' data: https://www.datocms-assets.com https://i.ytimg.com https://image.mux.com https://*.broman.group https://js.playground.kustom.co https://eu.klarnaevt.com https://*.cdn.adyen.com/checkoutshopper/ https://i.ytimg.com https://www.datocms-assets.com https://stagingaksapimanagementbroman.azure-api.net https://testapimanagementbroman.azure-api.net https://*.googleapis.com https://*.gstatic.com *.google.com https://*.ggpht.com https://*.mux.com https://*.vimeocdn.com https://dapi.videoly.co https://*.facebook.com https://*.seadform.net https://*.adform.net https://*.criteo.net https://*.criteo.com https://www.googletagmanager.com/ https://ib.adnxs.com/setuid https://ib.adnxs.com/getuid https://cm.g.doubleclick.net https://dev.visualwebsiteoptimizer.com https://qr.motonet.fi; frame-src 'self' https://www.youtube.com https://www.youtube-nocookie.com https://js.playground.kustom.co https://osm.klarnaservices.com/ https://*.adyen.com/ https://*.vimeo.com https://app.ecoonline.com https://www.maston.fi https://websds.volvo.com https://policy.app.cookieinformation.com/ https://*.criteo.com https://*.adform.net https://*.creativecdn.com https://www.facebook.com https://*.googletagmanager.com https://eu.fw-cdn.com https://*.freshchat.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://cdn.broman.group https://maps.googleapis.com https://js.playground.kustom.co https://js.klarna.com https://js.klarna.com/web-sdk/ https://api.videoly.co/1/quchbox/0/299/quch.js https://www.paypal.com/sdk/js https://dapi.videoly.co https://www.youtube.com https://*.vimeo.com https://policy.app.cookieinformation.com https://api.custobar.com/js/v1/custobar.js https://*.criteo.net https://*.criteo.com https://*.adform.net https://connect.facebook.net https://tags.creativecdn.com https://dev.visualwebsiteoptimizer.com https://*.googletagmanager.com https://eu.fw-cdn.com https://*.freshchat.com; object-src data:; worker-src 'self' blob:; 1 script-src 'unsafe-inline' 'unsafe-eval' cdn2.hubspot.net *.hubspot.com *.hubspotusercontent10.net js.hscollectedforms.net js.hsleadflows.net js.hs-scripts.com js.hsadspixel.net js.hs-analytics.net js.hs-banner.com js.hs-banner.net *.hsforms.net *.hsforms.com static.hsappstatic.net js.hubspotfeedback.com feedback.hubapi.com js.usemessages.com *.vidyard.com cdnjs.cloudflare.com cdnjs.cloudflare.com 10921146.fls.doubleclick.net plausible.io *.hotjar.com *.hotjar.io *.qualified.com bttrack.com *.googletagmanager.com *.force.com *.thycotic.com *.centrify.com *.bidr.io *.rlcdn.cm t.co *.twitter.com burly.io *.clickagy.com *.doubleclck.net *.zoominfo.com lltrck.com facebook.com *.facebook.net *.redditstatic.com *.linkedin.com *.licdn.com *.demandbase.com *.zoominfo.com 'strict-dynamic' 'nonce-cfpDKKs/KGK4VJYvt5DnXA==' 1 default-src 'self'; script-src 'self' 'report-sample' 'unsafe-inline' https://qvdt3feo.com/events.js https://cdnjs.cloudflare.com/ajax/libs/fotorama/4.6.4/ https://unpkg.com/isotope-layout@3/dist/ https://maps.googleapis.com https://ajax.googleapis.com https://*.formstack.com https://pi.pardot.com https://static.ads-twitter.com https://js.adsrvr.org https://connect.facebook.net https://*.googletagmanager.com https://cdn.cookielaw.org https://go.firstsolar.com https://player.vimeo.com https://siteimproveanalytics.com https://snap.licdn.com https://tags.srv.stackadapt.com https://use.typekit.net https://*.google-analytics.com; style-src 'self' 'report-sample' 'unsafe-inline' https://cdnjs.cloudflare.com https://static.formstack.com https://fonts.googleapis.com https://www.firstsolar.com https://tags.srv.stackadapt.com/sa.css https://cdnjs.cloudflare.com/ajax/libs/fotorama/4.6.4/ https://static.formstack.com https://fonts.googleapis.com https://tags.srv.stackadapt.com; object-src 'none'; base-uri 'self'; connect-src 'self' https://*.facebook.com https://*.formstack.com/ https://acrobat.adobe.com https://geolocation.onetrust.com https://privacyportal.onetrust.com https://stats.g.doubleclick.net https://cdn.cookielaw.org https://analytics.google.com https://insight.adsrvr.org https://px.ads.linkedin.com https://tags.srv.stackadapt.com https://*.google-analytics.com https://region1.analytics.google.com https://www.googletagmanager.com https://www.google.com https://translate.googleapis.com https://cta-service-cms2.hubspot.com https://overbridgenet.com https://www.facebook.com https://firstsolar.formstack.com; font-src 'self' https://*.formstack.com https://*.gstatic.com https://use.typekit.net https://www.googletagmanager.com https://www.youtube.com https://vimeo.com https://www.facebook.com https://match.adsrvr.org https://r2cdn.perplexity.ai https://svcs.tql.com; frame-src 'self' https://www.youtube.com https://*.facebook.com https://match.adsrvr.org https://go.firstsolar.com https://insight.adsrvr.org https://player.vimeo.com; img-src 'self' https://www.linkedin.com https://*.facebook.net https://*.googletagmanager.com https://*.google.com https://t.co https://analytics.twitter.com https://cdn.cookielaw.org https://px4.ads.linkedin.com https://i.vimeocdn.com https://*.typekit.net https://px.ads.linkedin.com https://*.facebook.com https://www.google.co.uk https://www.google.co.in https://www.google.co.ug https://www.google.co.id https://www.google.ge https://www.google.es https://www.google.fi https://www.google.co.il https://www.google.com.om https://www.google.com.my https://www.google.de https://www.google.co.kr https://www.google.co.uz https://www.google.com.vn https://dc.ads.linkedin.com https://www.google.com.ua https://www.google.com.au https://www.google.com.pk https://www.google.com.sg https://www.google.co.za https://www.google.co.jp https://www.google.nl https://www.google.ae https://www.google.com.hk https://www.google.lk https://www.google.com.sv https://www.google.com.mx https://www.google.com.pe https://www.google.dk https://www.google.pl https://www.google.co.nz https://www.google.rs https://www.google.be https://stats.g.doubleclick.net https://www.google.co.ma https://www.google.bf https://www.google.dz https://www.google.com.co https://www.google.cz https://www.google.com.gh https://www.google.com.ar https://www.google.so https://www.google.ci https://www.google.it https://www.google.ro https://www.google.ie https://www.google.com.pr https://www.google.co.ke https://www.google.se https://t.co https://analytics.twitter.com https://connect.facebook.net https://www.googletagmanager.com https://www.google.com.et https://www.google.ee https://www.google.com.np https://www.google.no https://www.google.com.cy https://www.google.com.ec https://fonts.gstatic.com https://px.ads.linkedin.com https://track.hubspot.com https://perf-na1.hsforms.com https://www.linkedin.com blob: data:; manifest-src 'self'; media-src 'self'; worker-src 'none'; report-uri https://o4510664129118208.ingest.us.sentry.io/api/4510664137441280/security/?sentry_key=1800fa7749fb2178678388266695ce8a; 1 default-src 'self' disqo.okta.com *.oktacdn.com; connect-src 'self' disqo.okta.com disqo-admin.okta.com *.oktacdn.com *.mixpanel.com *.mapbox.com disqo.kerberos.okta.com disqo.mtls.okta.com *.authenticatorlocalprod.com:8769 http://localhost:8769 http://127.0.0.1:8769 *.authenticatorlocalprod.com:65111 http://localhost:65111 http://127.0.0.1:65111 *.authenticatorlocalprod.com:65121 http://localhost:65121 http://127.0.0.1:65121 *.authenticatorlocalprod.com:65131 http://localhost:65131 http://127.0.0.1:65131 *.authenticatorlocalprod.com:65141 http://localhost:65141 http://127.0.0.1:65141 *.authenticatorlocalprod.com:65151 http://localhost:65151 http://127.0.0.1:65151 https://oinmanager.okta.com data: *.ingest.sentry.io; script-src 'unsafe-inline' 'nonce-zaqSqFNwEmWKMkqutUBxgA' 'unsafe-eval' 'self' 'report-sample' disqo.okta.com *.oktacdn.com; style-src 'unsafe-inline' 'nonce-zaqSqFNwEmWKMkqutUBxgA' 'self' 'report-sample' disqo.okta.com *.oktacdn.com; frame-src 'self' disqo.okta.com disqo-admin.okta.com login.okta.com *.vidyard.com com-okta-authenticator:; img-src 'self' disqo.okta.com *.oktacdn.com *.tiles.mapbox.com *.mapbox.com *.vidyard.com data: blob:; font-src 'self' disqo.okta.com data: *.oktacdn.com fonts.gstatic.com; frame-ancestors 'self' https://www.disqotech.com 1 style-src-elem maps.gstatic.com maps.googleapis.com fonts.googleapis.com *.gstatic.com 'unsafe-inline' 'self' mcstaging.chopo.com.mx www.chopo.com.mx; font-src fonts.gstatic.com use.typekit.net *.fontawesome.com fonts.googleapis.com https://fonts.gstatic.com *.gstatic.com data: https://fonts.bunny.net https://www.google.com https://www.gstatic.com 'self' data: data: 'self' 'unsafe-inline'; form-action *.mercadopago.com.mx https://mercadopago.com.mx https://grupoproa.qualtrics.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.mitec.com.mx 'self' 'unsafe-inline'; frame-ancestors *.mercadopago.com.mx https://mercadopago.com.mx https://grupoproa.qualtrics.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.mitec.com.mx www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com player.vimeo.com *.mercadopago.com.mx https://mercadopago.com.mx https://grupoproa.qualtrics.com 'self' *.doubleclick.net *.sharethis.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.mitec.com.mx www.google.com *.examedi.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net *.mercadopago.com.mx https://mercadopago.com.mx https://grupoproa.qualtrics.com maps.gstatic.com maps.googleapis.com *.gstatic.com *.facebook.com *.sharethis.com *.googleapis.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com https://firebasestorage.googleapis.com *.mitec.com.mx *.bird.eu *.hsforms.net *.hsforms.com 'self' data: data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net amcglobal.sc.omtrdc.net *.adobe.io use.typekit.net magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.magento-datasolutions.com *.magento-ds.com *.mercadopago.com.mx https://mercadopago.com.mx https://grupoproa.qualtrics.com *.googleapis.com maps.google.com *.gstatic.com *.sharethis.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.avada.io *.mitec.com.mx www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.google.com *.jscrambler.com *.examedi.com *.hsforms.net *.hsforms.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com *.fontawesome.com *.mercadopago.com.mx https://mercadopago.com.mx https://grupoproa.qualtrics.com maps.gstatic.com maps.googleapis.com *.gstatic.com 'unsafe-inline' 'self' mcstaging.chopo.com.mx www.chopo.com.mx *.sharethis.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com https://fonts.bunny.net *.googleapis.com *.addtoany.com *.mitec.com.mx *.google.com https://www.chopo.com.mx 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net commerce.adobe.io *.magento-datasolutions.com *.magento-ds.com *.sentry.io *.mercadopago.com.mx https://mercadopago.com.mx https://grupoproa.qualtrics.com *.googleapis.com maps.google.com *.gstatic.com *.sharethis.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com https://get.geojs.io *.avada.io http://dpm.demdex.net *.mitec.com.mx https://www.google.com https://www.gstatic.com *.jscrambler.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.klarnacdn.net *.fontawesome.com https://cdnjs.cloudflare.com *.gstatic.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors https://api.clerk.io https://cdn.clerk.io 'self'; frame-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.klarna.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.trustpilot.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com https://cdn.clerk.io *.klarna.com *.klarnaevt.com *.klarnacdn.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com 'self' data: data: 'self' 'unsafe-inline'; script-src geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ polyfill.io https://api.clerk.io https://cdn.clerk.io *.klarna.com *.klarnacdn.net *.klarnaservices.com https://cdnjs.cloudflare.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.google.com *.gstatic.com *.trustpilot.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src https://api.clerk.io https://cdn.clerk.io *.klarnacdn.net *.fontawesome.com https://fonts.googleapis.com https://cdnjs.cloudflare.com unsafe-inline assets.braintreegateway.com *.googleapis.com *.gstatic.com *.trustpilot.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com api.magento.com commerce.adobe.io www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io *.klarnaevt.com *.klarnacdn.net *.klarna.com *.klarnaservices.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com t.elasticsuite.io *.google-analytics.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' https:; font-src 'self' https: data:; img-src 'self' https: data:; object-src 'none'; script-src 'self' https:; style-src 'self' https:; report-uri https://csp-collector-qt0v.onrender.com/csp-report 1 script-src 'self' 'unsafe-inline' 'unsafe-eval' *.googletagservices.com *.googleadservices.com *.cdnwebcloud.com https://apis.google.com https://www.googleoptimize.com https://connect.facebook.net https://www.gstatic.com *.google-analytics.com https://ajax.googleapis.com https://gstatic.com https://www.googletagmanager.com *.womtp.com https://api.ipify.org https://maps.googleapis.com *.google.com *.vo.msecnd.net https://static.criteo.net https://bucket.cdnwebcloud.com *.doubleclick.net https://static.hotjar.com https://ws.walmeric.com https://sslwidget.criteo.com https://script.hotjar.com https://pagead2.googlesyndication.com https://neural29.cdnwebcloud.com https://sb.scorecardresearch.com https://ads.profilemkt.com https://snap.licdn.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com gstatic.com *.womtp.com *.walmeric.com *.google.com; img-src 'self' data: *.azureedge.net *.gstatic.com *.googleapis.com *.gstatic.com *.doubleclick.net *.google-analytics.com *.womtp.com *.walmeric.com https://magazine.solvia.es *.blob.core.windows.net https://plataforma-des.infosolvia.es https://imagenes.solvia.es *.google.com https://www.google.es https://sb.scorecardresearch.com https://ceres-tk3f2sxfca-ey.a.run.app *.doubleclick.net https://www.facebook.com https://t.womtp.com https://pagead2.googlesyndication.com *.cdnwebcloud.com https://px.ads.linkedin.com *.googletagmanager.com; font-src 'self' *.googleapis.com *.gstatic.com; connect-src 'self' *.solvia.es https://dc.services.visualstudio.com *.hotjar.com *.linkedin.com *.cdnwebcloud.com *.google.com *.googleapis.com *.googlesyndication.com *.indigitall.com *.doubleclick.net *.google-analytics.com; object-src 'self' https://www.google.com; frame-ancestors 'none'; form-action 'self' https://www.facebook.com 1 default-src 'self'; base-uri 'self'; object-src 'none'; script-src 'self' 'unsafe-inline' https://scripts.cleverwebserver.com https://*.cleverads.com https://www.google-analytics.com https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; img-src 'self' data: https://*.cleverwebserver.com https://*.cloudfront.net https://*.doubleclick.net; connect-src 'self' https://*.cleverwebserver.com https://*.cleverads.com https://www.google-analytics.com; frame-src 'self' https://*.cleverads.com https://*.doubleclick.net; frame-ancestors 'self' https://cartola.globo.com https://portal6.com.br https://climatempo.com.br https://ojogodobicho.com https://ge.globo.com https://cnnbrasil.com.br https://tudogostoso.com.br https://veja.abril.com.br https://nsctotal.com.br https://letras.mus.br https://ndmais.com.br https://olx.com.br https://oantagonista.com.br; upgrade-insecure-requests; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.fontawesome.com maxcdn.bootstrapcdn.com *.development.scalapay.com *.staging.scalapay.com *.integration.scalapay.com *.scalapay.com *.googleapis.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com x.klarnacdn.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com *.doubleclick.net *.facebook.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.bird.eu flagpedia.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.development.scalapay.com *.staging.scalapay.com *.integration.scalapay.com *.scalapay.com *.googleapis.com *.adobedtm.com dev.visualwebsiteoptimizer.com *.exacttarget.com google.it/pagead/1p-conversion self data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com *.vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.avada.io maps.googleapis.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.development.scalapay.com *.staging.scalapay.com *.integration.scalapay.com *.scalapay.com *.googleapis.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com *.cardinalcommerce.com *.authorize.net *.ccdc02.com *.googleadservices.com *.paypalobjects.com *.braintreegateway.com *.paypal.com *.ytimg.com www.gstatic.com/recaptcha www.google.com/recaptcha *.js-agent.newrelic.com unpkg.com/@googlemaps/markerclusterer/dist/index.min.js self *.criteo.com *.yandex.com *.yandex.ru *.teads.tv *.mainadv.com *.bing.com *.clarity.ms *.pinterest.com *.tiktok.com *.amazon-adsystem.com *.quantserve.com 'sha256-g/qbQ8sW5eJ9JO8sQzRJ1OvARbUyKpJXFeof9SLw1eI=' 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.fontawesome.com maxcdn.bootstrapcdn.com assets.braintreegateway.com *.development.scalapay.com *.staging.scalapay.com *.integration.scalapay.com *.scalapay.com *.stripe.network *.stripecdn.com *.amazon.com service.force.com x.klarnacdn.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.google-analytics.com *.facebook.com *.facebook.net https://get.geojs.io *.avada.io www.gstatic.com maps.googleapis.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.development.scalapay.com *.staging.scalapay.com *.integration.scalapay.com *.scalapay.com *.googleapis.com *.gstatic.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.adobe.com assets.adobedtm.com *.googletagmanager.com *.authorize.net *.ccdc02.com *.googleadservices.com *.paypalobjects.com *.braintreegateway.com *.paypal.com *.ytimg.com *.vimeocdn.com www.gstatic.com/recaptcha www.google.com/recaptcha *.google.bg *.doubleclick.net unpkg.com/@googlemaps/markerclusterer/dist/index.min.js unpkg.com/@googlemaps/markerclusterer/dist/* self consentcdn.cookiebot.com *.googlesyndication.com dev.visualwebsiteoptimizer.com js.klarna.com na.klarnaevt.com trustpilot.com googleads.g.doubleclick.net bam.nr-data.net *.criteo.com *.yandex.com *.yandex.ru *.teads.tv *.mainadv.com *.bing.com *.clarity.ms *.pinterest.com *.tiktok.com *.amazon-adsystem.com *.quantserve.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src bam.nr-data.net 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self';base-uri 'self';frame-ancestors 'self' https://*.epic.com https://*.geisinger.edu https://*.geisinger.org https://*.mycarecompass.edu https://*.mycarecompass.org https://*.mygeisinger.org https://geisinger.org https://www.geisinger.org;frame-src https://* 'self' epichttp: https://*.geisinger.edu https://pay.instamed.com https://paymentsafe.experianhealth.com;script-src https://mychart.mycarecompass.org 'self' 'unsafe-eval' 'unsafe-inline' https://*.geisinger.edu https://*.geisinger.org https://*.google.com https://*.googleapis.com https://*.gyantts.com https://*.jquery.com https://*.mycarecompass.org https://*.virtualearth.net https://ajax.microsoft.com https://mycarecompass.org https://twemoji.maxcdn.com https://unpkg.com https://www.gstatic.com;img-src https://* 'self' blob: data:;connect-src 'self' epichttp: https://*.amazonaws.com https://*.gyantts.com wss://web.production.gyantts.com wss://web2.dev.gyantts.com wss://web2.production.gyantts.com;style-src https://mychart.mycarecompass.org 'self' 'unsafe-inline' https://*.geisinger.edu https://*.geisinger.org https://*.gyantts.com https://*.mycarecompass.org https://mycarecompass.org https://s3.amazonaws.com;worker-src 'self' blob:;child-src 'self' blob:;font-src 'self' https://*.gyantts.com https://s3.amazonaws.com;form-action https://central.mychart.org/MyChart/ 'self';media-src https://* 'self' blob:; 1 font-src maxcdn.bootstrapcdn.com *.oct8ne.com fonts.gstatic.com *.azureedge.net *.doofinder.com *.typekit.net *.googleapis.com data: 'self' 'unsafe-inline'; frame-ancestors *.multisafepay.com https://pay.google.com *.storyblok.com 'self'; frame-src www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.facebook.com platform.twitter.com *.multisafepay.com https://pay.google.com *.oct8ne.com https://sandbox.sequracdn.com https://live.sequracdn.com *.hotjar.com *.pinterest.com *.doofinder.com *.empathybroker.com *.empathy.co *.criteo.com www.googletagmanager.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.salesmanago.pl *.salesmanago.es *.salesmanago.com https://images.unsplash.com www.facebook.com pinterest.com assets.pinterest.com syndication.twitter.com *.multisafepay.com *.oct8ne.com https://sandbox.sequracdn.com https://live.sequracdn.com *.facebook.com *.google.com *.google.es widgets.trustedshops.com *.twitter.com t.co *.azureedge.net *.pinterest.com *.doofinder.com *.bing.com www.googletagmanager.com *.storyblok.com data: 'self' 'unsafe-inline'; script-src www.googleadservices.com www.google-analytics.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.salesmanago.pl *.salesmanago.es *.salesmanago.com https://maps.googleapis.com connect.facebook.net twitter.com platform.twitter.com *.multisafepay.com https://pay.google.com *.oct8ne.com https://sandbox.sequracdn.com https://live.sequracdn.com www.googletagmanager.com *.googleoptimize.com widgets.trustedshops.com static-eu.oct8ne.com static.zdassets.com *.facebook.net *.tradedoubler.com *.doubleclick.net *.hotjar.com *.ads-twitter.com smct.co *.bsmartdata.com *.retargeted.co *.bing.com *.clarity.ms *.smartsuppcdn.com *.smartsuppchat.com *.smartsupp.com *.connectif.cloud *.klaviyo.com *.photoslurp.com *.pinimg.com *.nosto.com *.doofinder.com *.empathybroker.com *.unpkg.com *.storyblok.com *.usizy.es 'self' 'unsafe-inline' 'unsafe-eval'; style-src maxcdn.bootstrapcdn.com *.multisafepay.com *.photoslurp.com *.nosto.com *.doofinder.com *.klaviyo.com *.typekit.net *.storyblok.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.storyblok.com *.zdassets.com *.doofinder.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.google-analytics.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.salesmanago.pl *.salesmanago.es *.salesmanago.com https://maps.googleapis.com https://player.vimeo.com *.multisafepay.com *.oct8ne.com https://sandbox.sequracdn.com https://live.sequracdn.com *.zendesk.com *.zopim.com *.doubleclick.net *.hotjar.com *.hotjar.io *.clarity.ms *.smartsuppcdn.com *.googleapis.com *.gstatic.com *.google-analytics.com *.google.es *.connectif.cloud *.klaviyo.com *.photoslurp.com *.zdassets.com *.pinterest.com *.nosto.com *.doofinder.com *.empathybroker.com *.empathy.co www.googletagmanager.com usizy.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.salesmanago.pl *.salesmanago.es *.salesmanago.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; form-action https://sis.redsys.es/ pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' 'unsafe-inline'; 1 object-src 'none'; style-src 'self' 'unsafe-inline' fonts.googleapis.com cdn.jsdelivr.net cdnjs.cloudflare.com unpkg.com cdn3.theuaelottery.ae cdn3.uat-uaenl.ae www.gstatic.com;report-uri https://muddy-meadow-fb56.swang-203.workers.dev/csp-report 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://www.uship.com https://api.uship.com https://api-web.uship.com https://login.uship.com https://about.uship.com https://api-reviews.uship.com https://collect.uship.com https://content.uship.com https://go.uship.com https://help.uship.com https://ship.uship.com https://static.uship.com https://tm.uship.com https://track.uship.com https://login.okta.com https://www.ushipcdn.cloud https://t.ushipcdn.com https://www.googletagmanager.com https://www.google-analytics.com https://analytics.google.com https://region1.analytics.google.com https://ajax.googleapis.com https://fonts.googleapis.com https://maps.googleapis.com https://www.google.com https://www.googleadservices.com https://www.youtube.com https://cdn.cookielaw.org https://geolocation.onetrust.com https://privacyportal.onetrust.com https://cdn.optimizely.com https://logx.optimizely.com https://rum.optimizely.com https://eum.instana.io https://eum-red-saas.instana.io https://app-sj21.marketo.com https://munchkin.marketo.net https://js.stripe.com https://bat.bing.com https://www.bing.com https://bat.bing.net https://edge.fullstory.com https://rs.fullstory.com https://d.adroll.com https://ipv4.d.adroll.com https://s.adroll.com https://aorta.clickagy.com https://hemsync.clickagy.com https://tags.clickagy.com https://file-paa.zoom.us https://log-gateway.zoom.us https://us01apizva.zoom.us https://us01campaign.zoom.us https://us01ccistatic.zoom.us https://p.yotpo.com https://staticw2.yotpo.com https://unpkg.com https://ajax.cloudflare.com https://cdnjs.cloudflare.com https://vjs.zencdn.net https://static.cloudflareinsights.com https://connect.facebook.net https://www.facebook.com https://snap.licdn.com https://px.ads.linkedin.com https://pixel.byspotify.com https://ct.pinterest.com https://d.impactradius-event.com https://d.impct.site https://googleads.g.doubleclick.net https://stats.g.doubleclick.net https://lex.33across.com https://insight.adsrvr.org https://js.adsrvr.org https://match.adsrvr.org https://tags.tiqcdn.com https://collect.tealiumiq.com https://cdn.mxpnl.com https://api-js.mixpanel.com https://js.zi-scripts.com https://ws.zoominfo.com https://widget.trustpilot.com https://player.vimeo.com https://app-sj21.marketo.com; script-src-attr 'unsafe-inline'; style-src 'self' 'unsafe-inline' https://www.uship.com https://api.uship.com https://api-web.uship.com https://login.uship.com https://about.uship.com https://api-reviews.uship.com https://collect.uship.com https://content.uship.com https://go.uship.com https://help.uship.com https://ship.uship.com https://static.uship.com https://tm.uship.com https://track.uship.com https://login.okta.com https://www.ushipcdn.cloud https://t.ushipcdn.com https://ajax.googleapis.com https://fonts.googleapis.com https://maps.googleapis.com https://p.yotpo.com https://staticw2.yotpo.com https://unpkg.com https://ajax.cloudflare.com https://cdnjs.cloudflare.com https://vjs.zencdn.net https://static.cloudflareinsights.com https://fonts.gstatic.com https://use.fontawesome.com; img-src 'self' data: https://www.uship.com https://api.uship.com https://api-web.uship.com https://login.uship.com https://about.uship.com https://api-reviews.uship.com https://collect.uship.com https://content.uship.com https://go.uship.com https://help.uship.com https://ship.uship.com https://static.uship.com https://tm.uship.com https://track.uship.com https://login.okta.com https://www.ushipcdn.cloud https://t.ushipcdn.com https://s.ushipcdn.com https://resources.awsuship.com https://d2i7mi0re7cgbq.cloudfront.net https://proof-of-delivery-prod.s3.us-east-1.amazonaws.com https://uship-legacy-resources-prod.s3.us-east-1.amazonaws.com https://www.googletagmanager.com https://www.google-analytics.com https://analytics.google.com https://region1.analytics.google.com https://ajax.googleapis.com https://fonts.googleapis.com https://maps.googleapis.com https://fonts.gstatic.com https://maps.gstatic.com https://www.gstatic.com https://www.google.com https://www.googleadservices.com https://www.youtube.com https://cdn.cookielaw.org https://geolocation.onetrust.com https://privacyportal.onetrust.com https://cdn.optimizely.com https://logx.optimizely.com https://rum.optimizely.com https://eum.instana.io https://eum-red-saas.instana.io https://bat.bing.com https://www.bing.com https://bat.bing.net https://edge.fullstory.com https://rs.fullstory.com https://d.adroll.com https://ipv4.d.adroll.com https://s.adroll.com https://aorta.clickagy.com https://hemsync.clickagy.com https://tags.clickagy.com https://p.yotpo.com https://staticw2.yotpo.com https://connect.facebook.net https://www.facebook.com https://snap.licdn.com https://px.ads.linkedin.com https://pixel.byspotify.com https://ct.pinterest.com https://d.impactradius-event.com https://d.impct.site https://googleads.g.doubleclick.net https://stats.g.doubleclick.net https://lex.33across.com https://insight.adsrvr.org https://js.adsrvr.org https://match.adsrvr.org https://*.online-metrix.net https://cdn.sanity.io https://notify.bugsnag.com https://app.jazz.co https://t.vibe.co; font-src 'self' data: https://www.uship.com https://api.uship.com https://api-web.uship.com https://login.uship.com https://about.uship.com https://api-reviews.uship.com https://collect.uship.com https://content.uship.com https://go.uship.com https://help.uship.com https://ship.uship.com https://static.uship.com https://tm.uship.com https://track.uship.com https://login.okta.com https://www.ushipcdn.cloud https://t.ushipcdn.com https://p.yotpo.com https://staticw2.yotpo.com https://fonts.gstatic.com https://use.fontawesome.com https://unpkg.com https://ajax.cloudflare.com https://cdnjs.cloudflare.com https://vjs.zencdn.net https://static.cloudflareinsights.com https://api.radar.io https://static.radar.com; connect-src 'self' https://www.uship.com https://api.uship.com https://api-web.uship.com https://login.uship.com https://about.uship.com https://api-reviews.uship.com https://collect.uship.com https://content.uship.com https://go.uship.com https://help.uship.com https://ship.uship.com https://static.uship.com https://tm.uship.com https://track.uship.com https://login.okta.com https://www.ushipcdn.cloud https://t.ushipcdn.com https://proof-of-delivery-prod.s3.us-east-1.amazonaws.com https://uship-legacy-resources-prod.s3.us-east-1.amazonaws.com https://www.googletagmanager.com https://www.google-analytics.com https://analytics.google.com https://region1.analytics.google.com https://ajax.googleapis.com https://fonts.googleapis.com https://maps.googleapis.com https://www.google.com https://www.googleadservices.com https://www.youtube.com https://cdn.cookielaw.org https://geolocation.onetrust.com https://privacyportal.onetrust.com https://cdn.optimizely.com https://logx.optimizely.com https://rum.optimizely.com https://eum.instana.io https://eum-red-saas.instana.io https://app-sj21.marketo.com https://munchkin.marketo.net https://bat.bing.com https://www.bing.com https://bat.bing.net https://edge.fullstory.com https://rs.fullstory.com https://d.adroll.com https://ipv4.d.adroll.com https://s.adroll.com https://aorta.clickagy.com https://hemsync.clickagy.com https://tags.clickagy.com https://file-paa.zoom.us https://log-gateway.zoom.us https://us01apizva.zoom.us https://us01campaign.zoom.us https://us01ccistatic.zoom.us https://p.yotpo.com https://staticw2.yotpo.com https://connect.facebook.net https://www.facebook.com https://snap.licdn.com https://px.ads.linkedin.com https://pixel.byspotify.com https://ct.pinterest.com https://d.impactradius-event.com https://d.impct.site https://googleads.g.doubleclick.net https://stats.g.doubleclick.net https://lex.33across.com https://insight.adsrvr.org https://js.adsrvr.org https://match.adsrvr.org https://tags.tiqcdn.com https://collect.tealiumiq.com https://cdn.mxpnl.com https://api-js.mixpanel.com https://js.zi-scripts.com https://ws.zoominfo.com https://api.radar.io https://static.radar.com; media-src 'self' data: https://www.uship.com https://api.uship.com https://api-web.uship.com https://login.uship.com https://about.uship.com https://api-reviews.uship.com https://collect.uship.com https://content.uship.com https://go.uship.com https://help.uship.com https://ship.uship.com https://static.uship.com https://tm.uship.com https://track.uship.com https://login.okta.com https://www.ushipcdn.cloud; frame-src 'self' https://www.uship.com https://api.uship.com https://api-web.uship.com https://login.uship.com https://about.uship.com https://api-reviews.uship.com https://collect.uship.com https://content.uship.com https://go.uship.com https://help.uship.com https://ship.uship.com https://static.uship.com https://tm.uship.com https://track.uship.com https://login.okta.com https://www.ushipcdn.cloud https://www.googletagmanager.com https://www.google.com https://www.youtube.com https://cdn.cookielaw.org https://geolocation.onetrust.com https://privacyportal.onetrust.com https://cdn.optimizely.com https://logx.optimizely.com https://rum.optimizely.com https://js.stripe.com https://connect.stripe.com https://bat.bing.com https://www.bing.com https://bat.bing.net https://aorta.clickagy.com https://hemsync.clickagy.com https://tags.clickagy.com https://file-paa.zoom.us https://log-gateway.zoom.us https://us01apizva.zoom.us https://us01campaign.zoom.us https://us01ccistatic.zoom.us https://connect.facebook.net https://www.facebook.com https://snap.licdn.com https://px.ads.linkedin.com https://pixel.byspotify.com https://ct.pinterest.com https://d.impactradius-event.com https://d.impct.site https://googleads.g.doubleclick.net https://stats.g.doubleclick.net https://lex.33across.com https://insight.adsrvr.org https://js.adsrvr.org https://match.adsrvr.org https://*.online-metrix.net https://widget.trustpilot.com https://player.vimeo.com https://app-sj21.marketo.com; worker-src 'self' blob:; child-src 'self'; manifest-src 'self' https://www.ushipcdn.cloud; object-src 'none'; frame-ancestors 'self'; block-all-mixed-content; report-uri https://uship.report-uri.com/r/t/csp/reportOnly; report-to csp 1 object-src 'none'; script-src 'unsafe-inline' 'unsafe-eval' 'strict-dynamic' https: http: 'nonce-'; base-uri 'none'; frame-ancestors 'self' 1 object-src 'none'; script-src 'self' 'report-sample'; style-src 'self' 'report-sample'; webrtc 'block'; worker-src 'self'; base-uri 'self'; form-action 'self'; frame-ancestors 'self' 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' blob: https://www.googletagmanager.com https://www.google-analytics.com https://sdk.privacy-center.org; object-src 'none'; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; img-src 'self' data: blob: https://*.gstatic.com https://www.google-analytics.com; frame-src 'self' https://www.youtube.com https://player.vimeo.com; frame-ancestors 'self'; font-src 'self' https://fonts.gstatic.com data:; connect-src 'self' https://www.google-analytics.com https://www.googletagmanager.com; report-uri /report-csp-violation; upgrade-insecure-requests 1 font-src fonts.gstatic.com use.typekit.net https://fonts.gstatic.com fonts.googleapis.com *.gstatic.com *.development.scalapay.com *.staging.scalapay.com *.scalapay.com *.googleapis.com https://api.systempay.fr/static/ *.fontawesome.com https://cdnjs.cloudflare.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com https://paiement.systempay.fr/vads-payment/ https://api.systempay.fr/api-payment/ https://api.systempay.fr/static/ 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.demdex.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com https://*.pinterest.com/ https://wisepops.net/ https://*.wisepops.com/ https://*.trustpilot.com/ https://*.systempay.fr/ https://*.amaymag2.dnd.fr/ https://*.atelier-amaya.com/ *.weltpixel.com *.trustpilot.com *.dotdigital-pages.com *.dotdigital.com https://paiement.systempay.fr/vads-payment/ https://api.systempay.fr/static/ www.xtento.com *.sendcloud.sc *.jsdelivr.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net https://images.unsplash.com maps.googleapis.com maps.gstatic.com https://*.cdninstagram.com/ https://*.instagram.com/ https://*.google.com/ https://*.google.fr/ https://*.zdassets.com/ https://*.pinterest.com/ https://*.facebook.com/ *.development.scalapay.com *.staging.scalapay.com *.scalapay.com *.googleapis.com *.gstatic.com https://assets.shipup.co https://paiement.systempay.fr/static/latest/images/type-carte/ https://api.systempay.fr/static/ https://paiement.systempay.fr/vads-payment/ www.xtento.com cdn.xtento.com *.amazonaws.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com assets.adobedtm.com *.adobe.io www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com *.magento-ds.com https://cdn.jsdelivr.net/npm/@ryangjchandler/spruce@2.x.x/dist/spruce.umd.js maps.googleapis.com maps.gstatic.com fonts.googleapis.com https://maps.googleapis.com/maps/api/mapsjs *.trustpilot.com *.development.scalapay.com *.staging.scalapay.com *.scalapay.com *.googleapis.com *.gstatic.com https://cdn.shipup.co *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com https://api.systempay.fr/api-payment/ https://api.systempay.fr/static/ https://www.googletagmanager.com tagmanager.google.com www.xtento.com cdn.xtento.com https://cdnjs.cloudflare.com *.sendcloud.sc *.jsdelivr.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.magento-datasolutions.com *.magento-ds.com https://fonts.googleapis.com *.gstatic.com *.trustpilot.com *.development.scalapay.com *.staging.scalapay.com *.scalapay.com *.googleapis.com https://cdn.shipup.co https://api.systempay.fr/static/ *.fontawesome.com tagmanager.google.com https://cdnjs.cloudflare.com *.sendcloud.sc *.jsdelivr.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com https://*.zdassets.com/ 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io *.snplow.net commerce.adobedc.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.magento-datasolutions.com *.magento-ds.com https://maps.googleapis.com/maps/api/mapsjs https://api.shipup.co *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com https://paiement.systempay.fr/vads-payment/ https://api.systempay.fr/api-payment/ https://www.google-analytics.com *.sendcloud.sc *.cdn.jsdelivr.net *.mapbox.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com https://paiement.systempay.fr/vads-payment/ https://api.systempay.fr/api-payment/ https://api.systempay.fr/static/ 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src maxcdn.bootstrapcdn.com *.gstatic.com https://www.nominette.com https://demo.nominette.nl data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.adyen.com pay.google.com payments-eu.amazon.com *.amazon.de 'self' 'unsafe-inline'; frame-ancestors *.gstatic.com https://www.nominette.com https://demo.nominette.nl 'self'; frame-src bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.adyen.com pay.google.com *.paypal.com www.google.com *.hotjar.com *.hotjar.io *.weltpixel.com https://www.nominette.com https://demo.nominette.nl 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.adyen.com pay.google.com *.payments-amazon.com *.media-amazon.com *.paypalobjects.com maps.gstatic.com maps.googleapis.com *.google.com *.google.be *.googleapis.com *.gstatic.com *.google-analytics.com *.magentocommerce.com *.trustprofile.io bat.bing.com *.facebook.com https://www.nominette.com https://demo.nominette.nl maps.google.com data: 'self' 'unsafe-inline'; script-src googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com maps.googleapis.com *.google.com www.gstatic.com *.googleapis.com *.newrelic.com *.nr-data.net *.hotjar.com *.hotjar.io *.voyado.com https://www.nominette.com bat.bing.com *.clarity.ms *.realytics.io *.realytics.net connect.facebook.net https://demo.nominette.nl 'self' 'unsafe-inline' 'unsafe-eval'; style-src maxcdn.bootstrapcdn.com *.googleapis.com https://www.nominette.com https://demo.nominette.nl 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adyen.com *.google.com google.com payments-eu.amazon.com *.paypal.com *.google.be *.google-analytics.com *.googleapis.com *.nr-data.net *.g.doubleclick.net *.hotjar.com *.hotjar.io *.voyado.com *.exatom.io bat.bing.com *.clarity.ms *.realytics.io *.stape.cc 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.gstatic.com *.fontawesome.com * *.googleapis.com https://www.google.com https://www.gstatic.com maxcdn.bootstrapcdn.com *.development.scalapay.com *.staging.scalapay.com *.integration.scalapay.com *.scalapay.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de 'self' 'unsafe-inline'; frame-ancestors https://api.clerk.io https://cdn.clerk.io self www.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.sharethis.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de https://www.paypal.com https://www.googletagmanager.com https://www.google.com https://www.vimeo.com https://f.vimeocdn.com https://adyen.com https://checkoutshopper-test.adyen.com https://checkoutshopper-live.adyen.com https://pal-test.adyen.com https://pal-live.adyen.com https://amazon.com https://www.yotpo.com https://int-ecommerce.nexi.it *.kasanova.com * https://www.googletagmanager.com/ www.google.com www.gstatic.com apis.google.com accounts.google.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.sharethis.com https://cdn.clerk.io d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de static-eu.payments-amazon.com *.google.com *.gstatic.com https://www.vimeo.com https://f.vimeocdn.com *.googleapis.com *.ggpht https://ecommerce.nexi.it *.cloudfront.net *.kasanova.com * https://static.zdassets.com/ http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ *.development.scalapay.com *.staging.scalapay.com *.integration.scalapay.com *.scalapay.com 'self' data: data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com https://www.vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://rum.hlx.page *.sharethis.com https://api.clerk.io https://cdn.clerk.io *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.google.com *.googleapis.com https://f.vimeocdn.com *.gstatic.com https://googleads.g.doubleclick.net *.clerk.io https://int-ecommerce.nexi.it *.kasanova.com https://assets.livestory.io https://js-agent.newrelic.com *.consentcdn.cookiebot.com/ * http://www.googletagmanager.com/ https://www.googletagmanager.com/ accounts.google.com cdn.jsdelivr.net *.development.scalapay.com *.staging.scalapay.com *.integration.scalapay.com *.scalapay.com https://accounts.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.sharethis.com https://api.clerk.io https://cdn.clerk.io *.googleapis.com * *.fontawesome.com *.google.com *.gstatic.com accounts.google.com cdn.jsdelivr.net maxcdn.bootstrapcdn.com *.development.scalapay.com *.staging.scalapay.com *.integration.scalapay.com *.scalapay.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com https://static.zdassets.com/ http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.sharethis.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de https://assets.livestory.io https://api.livestory.io https://www.google-analytics.com https://int-ecommerce.nexi.it *.kasanova.com *.googleapis.com * http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ http://dpm.demdex.net https://www.google.com https://www.gstatic.com accounts.google.com *.development.scalapay.com *.staging.scalapay.com *.integration.scalapay.com *.scalapay.com *.gstatic.com t.elasticsuite.io *.google-analytics.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://fonts.gstatic.com https://ws.colissimo.fr *.development.scalapay.com *.staging.scalapay.com *.scalapay.com *.googleapis.com *.beautysuccess.fr fonts.googleapis.com googleapis.com https://cdnjs.cloudflare.com data: 'self' 'unsafe-inline'; form-action *.paypal.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src bid.g.doubleclick.net player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com *.weltpixel.com *.hipay-tpp.com *.hipay.com *.googleapis.com https://www.youtube.com https://form.typeform.com libs.hipay.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com *.hipay.com *.googleapis.com https://maps.googleapis.com https://maps.gstatic.com https://ws.colissimo.fr https://*.tile.openstreetmap.fr https://*.onyourmap.com *.development.scalapay.com *.staging.scalapay.com *.scalapay.com *.beautysuccess.fr maps.googleapis.com googleapis.com maps.gstatic.com *.openstreetmap.org api.maptiler.com magefan.com cm.magefan.com data: 'self' 'unsafe-inline'; script-src googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.hipay-tpp.com *.hipay.com mpsnare.iesnare.com *.paypal.com *.googleapis.com https://www.googletagmanager.com tagmanager.google.com https://maps.googleapis.com https://www.google.com https://www.gstatic.com https://ws.colissimo.fr https://api.mapbox.com https://*.typeform.com *.development.scalapay.com *.staging.scalapay.com *.scalapay.com *.gstatic.com *.beautysuccess.fr *.googletagmanager.com maps.googleapis.com googleapis.com api.socloz.com https://cdnjs.cloudflare.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com *.hipay.com *.googleapis.com tagmanager.google.com https://fonts.googleapis.com https://ws.colissimo.fr https://api.mapbox.com https://*.typeform.com *.development.scalapay.com *.staging.scalapay.com *.scalapay.com *.gstatic.com *.beautysuccess.fr googleapis.com libs.hipay.com https://cdnjs.cloudflare.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src data: mpsnare.iesnare.com *.googleapis.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.hipay-tpp.com *.hipay.com wss://mpsnare.iesnare.com *.googleapis.com https://www.google-analytics.com https://ws.colissimo.fr https://maps.googleapis.com https://nominatim.openstreetmap.org https://*.onyourmap.com https://*.mapbox.com *.beautysuccess.fr api.maptiler.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 base-uri 'self'; frame-ancestors 'self' edicomgroup.com analytics.edicomgroup.com; default-src 'self'; connect-src 'self' https://file.zoom.us https://file-paa.zoom.us https://us01apizva.zoom.us https://log-gateway.zoom.us https://us01ccistatic.zoom.us https://us01cci.zoom.us https://us01cciapi.zoom.us https://us01campaign.zoom.us wss://zpns.zoom.us/ws https://consent.cookiebot.com https://consentcdn.cookiebot.com https://wall.nixi1.com wss://wall.nixi1.com https://px.ads.linkedin.com https://apir.nixi1.com https://adservice.google.com https://cdn.linkedin.oribi.io https://pagead2.googlesyndication.com https://googleads.g.doubleclick.net https://region1.google-analytics.com https://www.google.com; font-src 'self' data: https://assets.l1l.co https://aocs.l1l.co https://fonts.gstatic.com https://stackpath.bootstrapcdn.com; frame-src 'self' https://us01ccistatic.zoom.us https://www.youtube.com https://www.youtube-nocookie.com https://player.vimeo.com https://www.google.com https://td.doubleclick.net https://consentcdn.cookiebot.com https://www.googletagmanager.com https://consent.cookiebot.com; img-src 'self' data: https://file.zoom.us https://file-paa.zoom.us https://img.youtube.com https://vumbnail.com https://www.linkedin.com https://i.vimeocdn.com https://imgsct.cookiebot.com https://assets.l1l.co https://i.ytimg.com https://px.ads.linkedin.com https://www.google.com https://www.google.es https://www.googletagmanager.com https://pagead2.googlesyndication.com; media-src 'self' https://us01ccistatic.zoom.us; manifest-src 'self'; object-src 'none'; script-src 'nonce-BXiGm+/QQAkGc1wMP8bI8Q==' 'strict-dynamic' 'sha256-2V/Eo6qonFC5Hh0d0ntvjXOJjVzTMoQdZ3r9VWpRL0U=' 'sha256-d/LWxV8YLDJOzXanMuab5l9GTAX9zAOnImzPldTHrH8=' 'sha256-HXiAJh84MdjjObB3ThhLBG7DIulxQWAfVPabPu+lPEs=' 'sha256-FYTmr4YLc/kKo72QELzOWKzdifs57bsT2dWxEfzm12c=' 'sha256-h8gG1uNWi02S00uhnnPan+IfTOULBEi0D46e6eAw/dk=' 'sha256-9/aMdaF6mnJPXmaogJHnJZW13dtTQLSbrobRQK8tMCc='; style-src 'report-sample' 'self' 'unsafe-inline' https://aocs.l1l.co https://fonts.googleapis.com https://stackpath.bootstrapcdn.com; worker-src blob:; report-uri https://64a6558e3723daccf20601d6.endpoint.csper.io/; 1 connect-src 'self' *.google.com *.google.cz *.leady.com *.google-analytics.com *.facebook.net connect.facebook.net https://cdn.jsdelivr.net https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://*.g.doubleclick.net; script-src 'self' 'nonce-M2E4OGVhZTM2M2I3YmUzZA==' *.google.com *.google.cz *.leady.com *.google-analytics.com *.facebook.net connect.facebook.net https://cdn.jsdelivr.net https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://*.g.doubleclick.net 'sha256-Ry5VVOTX8NJGEP4t9KtV/jWVgiv7ZcNmtZxCQScUTlk=' 'sha256-8iiJTU1Hf/vwORdni3nM30l8Ko0NMb8bqvTfGeIbIA4='; font-src 'self' https://fonts.gstatic.com https://cdnjs.cloudflare.com; img-src 'self' 'self' https://*.google-analytics.com https://*.googletagmanager.com https://www.facebook.com/ https://*.google.cz/ https://*.googleusercontent.com https://ct.leady.com; style-src 'self' 'unsafe-inline' https://cdn.jsdelivr.net https://cdnjs.cloudflare.com; report-uri https://www.expats.cz/csp-report 1 font-src fonts.gstatic.com *.kueskipay.com *.gstatic.com *.zotabox.com https://*.tawk.to *.fontawesome.com https://fonts.gstatic.com maxcdn.bootstrapcdn.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com *.kueskipay.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com https://www.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.kueskipay.com https://hotjar.com https://fast.amc.demdex.net https://secure.authorize.net https://static.addtoany.com https://www.googletagmanager.com https://td.doubleclick.net https://*.creativecdn.com https://*.mercadopago.com https://*.mercadopago.com.mx *.mercadolibre.com *.google.com/ *.sandbox.paypal.com *.paypalobjects.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com https://www.magezon.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.feedoptimise.com cdn.feedoptimise.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.kueskipay.com *.google.com *.google.com.mx *.facebook.com *.zotabox.com *.mercadolibre.com *.mercadolivre.com *.swagger.io *.akamai.net *.dico.com.mx https://bat.bing.com https://*.tawk.to https://www.googletagmanager.com https://*.mercadopago.com.mx *.mlstatic.com *.mercadopago.com *.mercadolivre.com.br *.mercadolibre.com.mx *.mercadolibre.com.ar *.sandbox.paypal.com *.paypalobjects.com *.hsforms.net *.hsforms.com 'self' data: data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://cdn.ampproject.org raw.githubusercontent.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com https://chimpstatic.com downloads.mailchimp.com *.list-manage.com *.facebook.com https://connect.facebook.net graph.facebook.com https://business.facebook.com www.feedoptimise.com cdn.feedoptimise.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.kueskipay.com *.googletagmanager.com *.mxpnl.com *.addtoany.com https://*.hotjar.com https://*.zotabox.com *.facebook.net *.tawk.to *.mailchimp.com *.pinterest.com *.tumblr.com *.tumblr.cb1 *.doubleclick.net https://dpm.demdex.net https://amcglobal.sc.omtrdc.net https://geostag.cardinalcommerce.com https://geo.cardinalcommerce.com https://1eafstag.cardinalcommerce.com https://1eaf.cardinalcommerce.com https://centinelapistag.cardinalcommerce.com https://centinelapi.cardinalcommerce.com https://pilot-payflowlink.paypal.com https://api.braintreegateway.com https://api.sandbox.braintreegateway.com https://client-analytics.braintreegateway.com https://client-analytics.sandbox.braintreegateway.com https://*.braintree-api.com https://*.paypal.com https://graph.facebook.com https://*.kueskipay.com https://*.doubleclick.net https://*.tawk.to https://*.hotjar.io https://*.mercadolibre.com https://*.google-analytics.com https://*.hsforms.com https://*.dico.com.mx *.google.com https://*.mercadopago.com https://*.sandbox.paypal.com *.paypalobjects.com https://t.elasticsuite.io https://*.hsforms.net https://*.creativecdn.com https://bat.bing.com https://analytics.tiktok.com https://www.googleoptimize.com *.mlstatic.com *.mercadopago.com *.sandbox.paypal.com *.hsforms.net *.hsforms.com *.gstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com unsafe-inline downloads.mailchimp.com https://static.klaviyo.com *.kueskipay.com *.googletagmanager.com *.mxpnl.com *.googleapis.com *.tawk.to *.fontawesome.com *.addtoany.com maxcdn.bootstrapcdn.com *.paypal.com *.sandbox.paypal.com *.paypalobjects.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net https://amcglobal.sc.omtrdc.net www.google-analytics.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://cdn.ampproject.org api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com www.facebook.com https://connect.facebook.net graph.facebook.com https://business.facebook.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.kueskipay.com *.doubleclick.net https://dpm.demdex.net https://geostag.cardinalcommerce.com https://geo.cardinalcommerce.com https://1eafstag.cardinalcommerce.com https://1eaf.cardinalcommerce.com https://centinelapistag.cardinalcommerce.com https://centinelapi.cardinalcommerce.com https://pilot-payflowlink.paypal.com https://api.braintreegateway.com https://api.sandbox.braintreegateway.com https://client-analytics.braintreegateway.com https://client-analytics.sandbox.braintreegateway.com https://*.braintree-api.com https://*.paypal.com https://graph.facebook.com https://*.kueskipay.com https://*.doubleclick.net https://*.tawk.to https://*.hotjar.com https://*.hotjar.io https://*.zotabox.com https://*.mercadolibre.com *.google-analytics.com https://*.hsforms.com https://*.dico.com.mx https://*.google.com https://*.mercadopago.com https://*.sandbox.paypal.com *.paypalobjects.com t.elasticsuite.io https://*.hsforms.net wss://*.tawk.to https://*.creativecdn.com https://analytics.tiktok.com https://google.com *.mercadopago.com *.mercadolibre.com http://dpm.demdex.net *.sandbox.paypal.com *.hsforms.net *.hsforms.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline' 'unsafe-eval' 'strict-dynamic'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; script-src 'self' 'unsafe-inline' https: http: https://vercel.live https://vercel.com https://*.posthog.com *.clerk.accounts.dev https://cdn.mux.com https://mux.com https://*.mux.com https://stream.mux.com https://*.gleap.io/ https://translate.google.com/ https://translate.googleapis.com/ https://www.gstatic.com/ https://*.google.com/; style-src 'self' 'unsafe-inline' https://vercel.live/ https://*.mux.com; img-src 'self' blob: data: https: *.thenational.academy/ thenational.academy/; font-src 'self' gstatic-fonts.thenational.academy/ fonts.gstatic.com/ data: https://vercel.live/ https://assets.vercel.com; object-src 'self' *.google.com; base-uri 'self'; form-action 'self'; frame-ancestors 'self' *.google.com/; connect-src *.thenational.academy thenational.academy https://vercel.live/ https://vercel.com *.pusher.com *.pusherapp.com *.hubspot.com *.hsforms.com *.cloudinary.com/ https://eu.i.posthog.com *.posthog.com https://api.avo.app/ *.clerk.accounts.dev clerk-telemetry.com https://mux.com https://*.mux.com https://stream.mux.com https://inferred.litix.io *.gleap.io wss://*.gleap.io *.google.com *.bugsnag.smartbear.com *.bugsnag.com; media-src 'self' blob: *.thenational.academy/ https://res.cloudinary.com/ https://oaknationalacademy-res.cloudinary.com/ https://*.cloudinary.com/ https://*.mux.com/ https://stream.mux.com/ https://*.gleap.io/ https://ssl.gstatic.com; frame-src 'self' *.thenational.academy/ https://vercel.live/ https://vercel.com https://challenges.cloudflare.com https://www.avo.app/ https://stream.mux.com https://*.mux.com https://*.gleap.io/ *.google.com/; worker-src 'self' blob: *.thenational.academy/; child-src blob:; report-uri https://ph-eu-api.thenational.academy/report/?token=phc_LCrtgEAumOz4qgXuJNqMK2xisQ4mGaApixHEPXeRRoN&sample_rate=0.05&v=1; report-to posthog 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com maxcdn.bootstrapcdn.com self data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.wesupply.xyz https://wesupplylabs.com *.weltpixel.com self 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.panafoto.com *.facebook.com *.hubspot.com *.facebook.net *.hsforms.com *.google.com self data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com polyfill.io js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.cloudflare.com https://www.googletagmanager.com tagmanager.google.com js.hs-scripts.com content.syndigo.com cdn.cs.1worldsync.com media.flixfacts.com media.flixcar.com connect.facebook.net js.hscollectedforms.net ws.cs.1worldsync.com js.hubspot.com js.hsadspixel.net js.hs-analytics.net js.hs-banner.com static.klaviyo.com rum-static.pingdom.net *.klaviyo.com self unsafe-inline *.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com maxcdn.bootstrapcdn.com assets.braintreegateway.com tagmanager.google.com self unsafe-inline 'self' 'unsafe-inline'; object-src none 'self' 'unsafe-inline'; media-src *.adobe.com self 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com https://www.google-analytics.com cta-service-cms2.hubspot.com api.hubapi.com forms.hscollectedforms.net content.syndigo.com media.flixcar.com fast.a.klaviyo.com rum-collector-2.pingdom.net static-forms.klaviyo.com *.doubleclick.net self 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self';script-src 'self' 'unsafe-inline' 'nonce-7mKY7cX1qz8xWTW42zMOMrkz' 'unsafe-eval' https://pixel.byspotify.com *.travcorpservices.com https://www.google.com https://www.google-analytics.com https://www.googleoptimize.com https://www.googletagmanager.com https://ajax.googleapis.com https://www.gstatic.com https://googleads.g.doubleclick.net https://api.feefo.com https://register.feefo.com https://bat.bing.com https://cdn.evgnet.com https://connect.facebook.net https://i.clarity.ms https://static-ssl.responsetap.com *.hotjar.com https://tag.simpli.fi https://unpkg.com https://www.bugherd.com https://decagon.ai https://www.datadoghq-browser-agent.com https://assetscdn.stackla.com/media/js https://vjs.zencdn.net https://cdn.amplitude.com/libs https://sdk.joinsherpa.io https://apps.mypurecloud.com https://consentcdn.cookiebot.com https://cdnjs.cloudflare.com https://ttc-contiki.entry.promo https://cdn.optimizely.com https://www.riddle.com;style-src 'self' 'unsafe-inline' https://assetscdn.stackla.com/media/components/stackla-uikit/dist https://fonts.googleapis.com https://p.typekit.net https://use.typekit.net https://vjs.zencdn.net https://apps.mypurecloud.com;img-src 'self' https://bat.bing.com https://c.clarity.ms https://i.ytimg.com https://www.facebook.com https://www.google-analytics.com https://www.google.com https://www.uplift-platform.com data:;frame-src 'self' https://10006172.fls.doubleclick.net https://uplift-cdn-stg.uplift.com https://vars.hotjar.com https://widget.stackla.com https://www.google.com https://apps.joinsherpa.io https://www.googletagmanager.com https://a25408250069.cdn.optimizely.com;font-src 'self' https://assetscdn.stackla.com https://fonts.gstatic.com https://use.typekit.net https://vjs.zencdn.net https://apps.mypurecloud.com;connect-src 'self' *.travcorpservices.com *.travcorp.com *.corp.ttc:7443 https://api.feefo.com https://bat.bing.com https://in.hotjar.com https://ws11.hotjar.com/api https://l.clarity.ms https://metrics.responsetap.com/infinity https://noembed.com https://pm-mrkt.prodgw.uplift-platform.com https://rum.browser-intake-datadoghq.com https://session-replay.browser-intake-datadoghq.com https://ttctravel.germany-2.evergage.com https://www.facebook.com https://www.google-analytics.com https://logx.optimizely.com https://region1.analytics.google.com https://ttc.contiki.com 1 media-src 'self' blob: data: https://bayer04.stream41.radiohost.de https://bayer04.do-not-publish.com http://bayer04-live.cast.addradio.de https://*.cdninstagram.com; default-src 'self' https://*.sentry.io; script-src 'self' 'unsafe-inline' 'unsafe-eval' blob: https://*.b04itpg.de https://*.bayer04.de https://*.usercentrics.eu https://*.facebook.net https://*.wt-safetag.com https://*.flockler.com https://*.sportradar.com; script-src-elem 'self' 'unsafe-inline' https://*.bayer04.de https://www.bayer04.de https://cdn-werkself-prod.bayer04.de https://*.usercentrics.eu https://www.gstatic.com https://*.facebook.net https://*.wt-safetag.com https://*.cdn.flockler.com https://*.flockler.com https://avplayer-cdn.sportradar.com https://*.sportradar.com; worker-src 'self' blob:; style-src 'self' 'unsafe-inline' https://*.b04itpg.de https://*.bayer04.de https://b04-ep-media-prod.azureedge.net https://*.flockler.com https://*.sportradar.com; font-src 'self' https://*.b04itpg.de https://*.bayer04.de data:; img-src 'self' data: https://*.b04itpg.de https://*.bayer04.de https://www.bayer04.de https://cdn-werkself-prod.bayer04.de https://*.usercentrics.eu https://*.facebook.com https://*.ytimg.com https://*.youtube.com https://*.facebook.net https://b04-ep-media-prod.azureedge.net https://*.flockler.com https://flockler.com https://*.flocklr.com https://*.cdninstagram.com https://*.twimg.com https://*.fbcdn.net https://*.raxcdn.com; connect-src 'self' data: https://*.sentry.io wss://*.b04itpg.de https://*.b04itpg.de https://*.bayer04.de https://*.usercentrics.eu https://*.wt-safetag.com https://*.facebook.com https://*.facebook.net https://b04-ep-media-prod.azureedge.net https://*.flockler.com https://spottvod.akamaized.net https://*.youborafds01.com https://ls.readertracking.com https://eu-api.friendlycaptcha.eu; frame-src 'self' https://my.matterport.com https://*.flockler.com https://www.google.com https://www.youtube-nocookie.com; frame-ancestors 'none'; manifest-src https://*.bayer04.de; report-uri https://o4508738008186880.ingest.de.sentry.io/api/4510279136837712/security/?sentry_key=453d974898eaf8cbcad7111d916a5b22; report-to csp-endpoint 1 default-src blob: https://*.mhcache.com;font-src 'self' https://*.myheritage.com https://*.mhcache.com https://fonts.gstatic.com;frame-src 'self' https://*.mhcache.com https://portal.allyable.com https://mh-site-files-5c53d6a9947c.s3.amazonaws.com https://myheritage-container.com https://www.myheritage-partners.com https://www.myheritage.com https://*.mk-sense.com https://player.vimeo.com https://*.facebook.com https://*.googleapis.com https://*.google.com https://tpc.googlesyndication.com https://*.doubleclick.net https://accounts.google.com/gsi/;script-src https://accounts.google.com/gsi/client https://www.datadoghq-browser-agent.com https://*.googleapis.com https://appleid.cdn-apple.com *.myheritage.pl https://www.myheritage.pl 'unsafe-eval' 'nonce-b760926171699f3a2365fa89abcdc81f' 'strict-dynamic';style-src data: blob: 'unsafe-inline' 'self' https://*.myheritage.com https://*.mhcache.com https://fonts.googleapis.com https://accounts.google.com/gsi/style;connect-src data: 'self' https://*.myheritage.com https://portal.allyable.com https://*.mhcache.com https://adservice.google.com https://*.logs.datadoghq.com https://*.browser-intake-datadoghq.com https://browser-intake-datadoghq.com https://sentry.io https://*.bing.com https://*.facebook.com https://*.doubleclick.net https://*.mk-sense.com https://*.filae.com https://accounts.google.com/gsi/ https://www.google.com/pagead/landing https://*.googleapis.com https://maps.googleapis.com/maps/api/mapsjs/gen_204 https://translate.googleapis.com https://www.google.com/ccm/collect https://cdn.builder.io *.myheritage.pl;media-src 'self' https://*.myheritage.com https://*.mhcache.com;frame-ancestors 'self' https://builder.io;img-src * data:;object-src 'none';base-uri 'self' https://*.mhcache.com;report-uri /FP/API/ContentSecurityPolicy/report-violation.php?report_mode=report&canonical_page_id=/company/home/ 1 default-src 'self';base-uri 'self';frame-ancestors 'self';frame-src https://* 'self' epichttp: https://pay.instamed.com;script-src 'nonce-1aebc1c0e4d4448886406e47bcfe9319' https://www.mylghealth.org 'self';img-src https://* 'self' blob: data:;connect-src 'self' epichttp:;style-src https://www.mylghealth.org 'self' 'unsafe-inline';worker-src 'self' blob:;child-src 'self' blob:;form-action https://central.mychart.org/MyChart/ 'self';media-src https://* 'self' blob:; 1 default-src 'self' sf-tbid.okta.com tbid.digital.salesforce.com *.oktacdn.com; connect-src 'self' sf-tbid.okta.com sf-tbid-admin.okta.com tbid.digital.salesforce.com *.oktacdn.com *.mixpanel.com *.mapbox.com sf-tbid.kerberos.okta.com sf-tbid.mtls.okta.com *.authenticatorlocalprod.com:8769 http://localhost:8769 http://127.0.0.1:8769 *.authenticatorlocalprod.com:65111 http://localhost:65111 http://127.0.0.1:65111 *.authenticatorlocalprod.com:65121 http://localhost:65121 http://127.0.0.1:65121 *.authenticatorlocalprod.com:65131 http://localhost:65131 http://127.0.0.1:65131 *.authenticatorlocalprod.com:65141 http://localhost:65141 http://127.0.0.1:65141 *.authenticatorlocalprod.com:65151 http://localhost:65151 http://127.0.0.1:65151 https://oinmanager.okta.com data: https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/; script-src 'unsafe-inline' 'unsafe-eval' 'self' 'report-sample' sf-tbid.okta.com tbid.digital.salesforce.com *.oktacdn.com https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/; style-src 'unsafe-inline' 'self' 'report-sample' sf-tbid.okta.com tbid.digital.salesforce.com *.oktacdn.com; frame-src 'self' sf-tbid.okta.com sf-tbid-admin.okta.com tbid.digital.salesforce.com login.okta.com *.vidyard.com com-okta-authenticator: https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/; img-src 'self' sf-tbid.okta.com tbid.digital.salesforce.com *.oktacdn.com *.tiles.mapbox.com *.mapbox.com *.vidyard.com data: blob:; font-src 'self' sf-tbid.okta.com tbid.digital.salesforce.com data: *.oktacdn.com fonts.gstatic.com; frame-ancestors 'self' https://iis.digital.salesforce.com 1 frame-ancestors 'self'; report-uri https://www.delicious.com.au/csp-reports 1 default-src 'self'; script-src 'self' *.artfut.com *.bootstrapcdn.com *.clarity.ms *.cloudfront.net *.criteo.com *.facebook.com *.fullstory.com *.gstatic.com *.google-analytics.com *.google.com *.googleapis.com *.jsdelivr.net *.livechatinc.com *.moengage.com *.onetrust.com *.razorpay.com *.tatadigital.com *.trackier.com *.unbxdapi.com c.amazon-adsystem.com connect.facebook.net googleads.g.doubleclick.net sc-static.net tr.snapchat.com www.googleadservices.com www.googletagmanager.com; style-src 'self' 'unsafe-inline' *.bootstrapcdn.com *.googleapis.com *.jsdelivr.net *.onetrust.com www.gstatic.com; img-src 'self' data: https:; connect-src 'self' aax-eu.amazon-adsystem.com ad.doubleclick.net analytics.google.com api.fastrackeyewear.com apac-recommendations.unbxd.io ara.paa-reporting-advertising.amazon connect.facebook.net d3995ea24pmi7m.cloudfront.net google.com *.amazon.in *.clarity.ms *.criteo.com *.facebook.com *.fullstory.com *.google.com *.googleapis.com *.livechatinc.com *.moengage.com *.onetrust.com *.paytm.in *.phonepe.com *.razorpay.com *.tatadigital.com *.titaneyeplus.com *.unbxdapi.com s.amazon-adsystem.com search.unbxd.io secure.paytmpayments.com stats.g.doubleclick.net tr.snapchat.com tr6.snapchat.com www.google-analytics.com www.google.co.in www.google.com www.googleadservices.com; font-src 'self' *.amazon-adsystem.com *.gstatic.com *.google.co.in *.onetrust.com *.unbxd.io ad.doubleclick.net ara.paa-reporting-advertising.amazon google.com stats.g.doubleclick.net www.google-analytics.com www.googleadservices.com; frame-src 'self' *; report-uri https://admin.titaneyeplus.com/csp.php; 1 font-src fonts.gstatic.com use.typekit.net data: *.fontawesome.com https://fonts.gstatic.com https://www.google.com https://www.gstatic.com *.gstatic.com 'self' data: https://media.flixcar.com/ https://media.flixfacts.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://www.facebook.com/tr/ https://content.jwplatform.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com cdn.dnky.co amc.demdex.net www.google.com youtube.com *.hotjar.com https://www.facebook.com/tr/ https://static.addtoany.com/ https://static.zdassets.com/ https://script.hotjar.com *.googlesyndication.com *.googletagmanager.com *.doubleclick.net *.google 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net *.vimeocdn.com i.ytimg.com *.youtube.com *.ftcdn.net *.behance.net data: www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com maps.gstatic.com maps.googleapis.com accounts.google.com https://googleads.g.doubleclick.net https://www.google.com.ar https://www.google.com.do https://www.googletagmanager.com https://www.m.casacuesta.com https://connect.facebook.net logo.flixfacts.co.uk https://widgets.magentocommerce.com/ https://media.flixcar.com/ *.flix360.com notifications-icommkt.website *.googlesyndication.com *.zdassets.com/ekr/snippet.js *.googletagmanager.com *.simpleanalyticscdn.com *.flixcar.com *.ocularsolution.com *.amazonaws.com *.syndigo.cloud *.baidu.com *.cloudfront.net *.syndigo.com *.google data: 'self' 'unsafe-inline'; script-src https://assets.adobedtm.com/ *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net commerce.adobe.net unpkg.com commerce.adobedtm.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com cdn.dnky.co r1-t.trackedlink.net www.gstatic.com js-agent.newrelic.com bam.nr-data.net maps.googleapis.com player.vimeo.com *.googleapis.com *.google.com *.gstatic.com *.avada.io *.hotjar.com *.hotjar.io https://static.hotjar.com/c/hotjar- https://static.hotjar.com https://script.hotjar.com https://www.google-analytics.com https://www.google-analytics.com/u/analytics_debug.js https://stats.g.doubleclick.net http://www.google.com/recaptcha/api.js https://static.zdassets.com/ https://d12zyq17vm1xwx.cloudfront.net/v2/wpn.min.js https://static.cloudflareinsights.com/ https://externalassets.icommarketing.com/icomMkt_tracking_jquery.min.js intent://arvr.google.com https://static.addtoany.com/menu/page.js https://static.addtoany.com/ https://static.zdassets.com/ekr/snippet.js *.flixfacts.com/ *.flixcar.com/ https://media.flixfacts.com/js/loader.js https://media.flixcar.com/delivery/static/tracking/tracking.js https://samsungxr.s3.amazonaws.com/js/ar_casacuesta.js https://cdn.jsdelivr.net/gh/Wruczek/Bootstrap-Cookie-Alert@gh-pages/cookiealert.js https://www.google.com/recaptcha/api.js https://www.gstatic.com/recaptcha/releases/1AZgzF1o3OlP73CVr69UmL65/recaptcha__es.js *.googlesyndication.com *.googletagmanager.com *.singular.net *.icommkt.online *.syndigo.com *.flixfacts.com *.ocularsolution.com *.syndigo.cloud *.zdassets.com *.zopim.com *.flix360.io *.adobedtm.com *.google/sodar/sodar2.js *.gbqofs.com *.gbqofs.io *.doubleclick.net *.gbss.io 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com cdn.dnky.co *.fontawesome.com *.googleapis.com *.google.com *.gstatic.com https://media.flixfacts.com/ https://media.flixcar.com/ 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.youtube.com https://static.zdassets.com/ https://media.flixcar.com/ https://media.flixfacts.com/ https://media.flixsyndication.net/ https://assets-jpcust.jwpsrv.com/ https://ssl.p.jwpcdn.com/ *.cloudfront.net/ https://d3nkfb7815bs43.cloudfront.net/ https://d2m3ikv8mpgiy8.cloudfront.net/ https://media.pointandplace.com/ https://player.pointandplace.com/ https://t.pointandplace.com/ *.pointandplace.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.adobe.io performance.typekit.net vimeo.com api.magento.com commerce.adobedtm.com commerce.adobedc.net commerce.adobe.io www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com api.comapi.com bam.nr-data.net http://dpm.demdex.net https://www.google.com https://www.gstatic.com https://get.geojs.io *.avada.io t.elasticsuite.io *.google-analytics.com *.hotjar.com *.hotjar.io https://www.google-analytics.com https://stats.g.doubleclick.net https://www.facebook.com/tr/ http://ccnecommerce.com/ https://notifications-icommkt.com/ https://track-icommkt.com/ https://casacuesta.zendesk.com/ https://ekr.zdassets.com/ wss://widget-mediator.zopim.com/ *.youtube.com https://prod.flixgvid.flix360.io https://t.flix360.com https://syndication.flix360.com *.flix360.com *.amazonaws.com *.flixcar.com *.googlesyndication.com *.syndigo.com *.ocularsolution.com *.simpleanalitycscdn.com *.casacuesta.com *.simpleanalyticscdn.com *.singular.net *.baidu.com *.google *.gbqofs.io *.gstatic.com *.google.com.do/ads/ga-audiences wss://ws.hotjar.com/api/v2/client/ws *.doubleclick.net *.syndigo.cloud *.googleapis.com *.gbss.io *.gbqofs.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://www.googletagmanager.com *.googleapis.com *.klarnacdn.net *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.development.scalapay.com *.staging.scalapay.com *.integration.scalapay.com *.scalapay.com *.klaviyo.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com https://api.clerk.io https://cdn.clerk.io 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.awin1.com *.zenaps.com *.fls.doubleclick.net *.klarna.com js.mollie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * sibautomation.com *.criteo.com *.gelproximity.com *.trustpilot.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://images.unsplash.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.awin1.com *.zenaps.com *.wepowerconnections.com https://cdn.clerk.io *.feedaty.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klarna.com *.klarnaevt.com *.klarnacdn.net magefan.com cm.magefan.com https://firebasestorage.googleapis.com flagpedia.net https://www.mollie.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.development.scalapay.com *.staging.scalapay.com *.integration.scalapay.com *.scalapay.com *.googleapis.com *.elfsight.com *.elfsightcdn.com *.trustpilot.com *.trustpilot.net *.doofinder.com *.google.com *.google.it *.bidswitch.net *.doubleclick.net *.adnxs.com *.media.net *.rubiconproject.com *.sharethrough.com *.smartadserver.com *.taboola.com *.teads.tv eb2.3lift.com *.yahoo.com *.adform.net *.criteo.com *.popupsmart.com *.onesignal.com upstream.heidipay.com sbx-upstream.heidipay.io *.casalemedia.com id5-sync.com *.360yield.com *.mediavine.com *.postrelease.com *.outbrain.com *.pubmatic.com *.tremorhub.com *.yieldlab.net *.1rx.io *.agkn.com *.unrulymedia.com www.gstatic.com pay.google.com google.com/pay ecomms2s.sella.it sandbox.gestpay.net img.riskified.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com https://maps.googleapis.com tagmanager.google.com https://www.googletagmanager.com https://cdn.jsdelivr.net/npm/@ryangjchandler/spruce@2.x.x/dist/spruce.umd.js www.google.com/recaptcha/ www.gstatic.com/recaptcha/ www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.awin1.com *.dwin1.com *.zenaps.com *.wepowerconnections.com https://the.sciencebehindecommerce.com lantern.roeyecdn.com https://api.clerk.io https://cdn.clerk.io *.feedaty.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klarna.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.avada.io *.gstatic.com maps.googleapis.com js.mollie.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.development.scalapay.com *.staging.scalapay.com *.integration.scalapay.com *.scalapay.com *.googleapis.com *.elfsight.com *.doofinder.com sibautomation.com *.iubenda.com *.popupsmart.com *.criteo.com *.onesignal.com onesignal.com *.gelproximity.com *.clerk.io *.hotjar.com www.google.com www.gstatic.com beacon.riskified.com tracking.trovaprezzi.it tps.trovaprezzi.it www.trovaprezzi.it *.trustpilot.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://www.googletagmanager.com tagmanager.google.com *.googleapis.com https://api.clerk.io https://cdn.clerk.io *.feedaty.com https://static.klaviyo.com *.klarnacdn.net *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.gstatic.com assets.braintreegateway.com *.development.scalapay.com *.staging.scalapay.com *.integration.scalapay.com *.scalapay.com *.doofinder.com onesignal.com *.popupsmart.com *.trustpilot.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com https://maps.googleapis.com https://player.vimeo.com https://www.google-analytics.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.wepowerconnections.com https://the.sciencebehindecommerce.com *.feedaty.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klarnaevt.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.klarna.com https://get.geojs.io *.avada.io www.gstatic.com maps.googleapis.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.development.scalapay.com *.staging.scalapay.com *.integration.scalapay.com *.scalapay.com *.googleapis.com *.gstatic.com *.onesignal.com onesignal.com *.popupsmart.com *.elfsight.com *.doofinder.com wss://*.doofinder.com *.brevo.com *.iubenda.com *.doubleclick.net *.criteo.com *.google-analytics.com www.google.com pay.google.com google.com/pay ecomms2s.sella.it sandbox.gestpay.net c.riskified.com 'self' 'unsafe-inline'; child-src *.awin1.com *.zenaps.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' 'unsafe-inline' 'unsafe-eval' plenitudedistribuidora.com.br *.plenitudedistribuidora.com.br wake-components.fbitsstatic.net plenitudedistribuidora.fbitsstatic.net *.wake.tech fbits.net nr-data.net newrelic.com google.com googletagmanager.com google-analytics.com facebook.net facebook.com jquery.com bootstrapcdn.com *.fbits.net *.nr-data.net *.newrelic.com *.google.com *.googletagmanager.com *.google-analytics.com *.facebook.net *.facebook.com *.jquery.com *.bootstrapcdn.com wss://signalr.fbits.net *.googleadservices.com *.tawk.to k-analytix.com *.k-analytix.com i.konduto.com *.yapay.com.br *.traycheckout.com.br h.online-metrix.net *.ebit.com.br *.cartstack.com wss://vsb31.tawk.to *.cartstack.com.br *.smarthint.co app.cartstack.com.br *.datafrete.app *.getblue.io *.targeting.voxus.com.br cdn.targeting.voxus.com.br googleads.g.doubleclick.net *.g.doubleclick.net *.voxus.tv *.voxus.com.br *.loggly.com targeting.voxus.com.br *.clearsale.com.br accounts.google.com *.facebook.net connect.facebook.net *.facebook.com facebook.com *.conectiva.io *.sunset.systems *.performa.ai *.cupom.social *.conectiva.app conectiva.app api.performa.ai valid.performa.ai cartstack.com.br api.cartstack.com.br sunset.systems api.sunset.systems cupom.social app.cupom.social cdn.performa.ai *.google.com.br *.google.com *.googletagmanager.com translate.googleapis.com google.com *.trustvox.com.br rate.trustvox.com.br *.google-analytics.com apis.google.com app.cartstack.com dzpxyxks1bfmb.cloudfront.net *.gstatic.com conectiva.io trustvox.com.br *.goadopt.io googletagmanager.com google-analytics.com gstatic.com *.koin.com.br *.soclminer.com.br *.btg360.com.br *.socialminer.com *.tiktok.com signalrcore.fbits.net wss://signalrcore.fbits.net *.cloudfront.net *.mlstatic.com *.mercadopago.com *.mercadolibre.com *.mercadopago.com.br *.paypal.com *.paypalobjects.com td.doubleclick.net *.doubleclick.net integration-hub.mailclick.me *.fbits.store *.adyen.com google.co.jp google.com.bo google.co.uk google.com.uy google.pt google.com.py google.es google.it google.fr google.al google.nl google.be *.pagar.me *.mundipagg.com *.rdstation.com.br *.getnet.com.br *.clarity.ms *.stape.co sa.stape.co clarity.ms *.braintree-api.com *.braintreegateway.com *.pagseguro.com.br *.pagbank.com *.google.pt *.vindi.com.br *.cieloecommerce.cielo.com.br *.braspag.com.br *.pagador.com.br *.online-metrix.net bt-wake-connector.com.br *.pagaleve.com.br *.pagaleve.io wake-api.pagaleve.com.br securegtm.despegar.com api.ipify.org browser-intake-datadoghq.com *.datadoghq-browser-agent.com *.datadoghq.com wake.koin.com.br *.monitfy.com cdn.monitfy.com *.fpcs-monitor.com.br web.fpcs-monitor.com.br paypal-wake.s3.us-east-1.amazonaws.com newimgebit-a.akamaihd.net youtube.com yampi-vitrine-digital-prod.s3.us-east-1.amazonaws.com *.cardinalcommerce.com *.secureacs.com api.globalgetnet.com *.globalgetnet.com *.sandbox.3dsecure.io *.mailbiz.one *.jsdelivr.net *.3dsecure.io *.visa.com s.pinimg.com *.pinimg.com mpc-prod-18-s6uit34pua-uc.a.run.app ct.pinterest.com *.pinterest.com *.youtube.com demo-1.conversionsapigateway.com *.conversionsapigateway.com analytics-ipv6.tiktokw.us *.tiktokw.us *.wake.tech *.appmax.com.br *.tunagateway.com static.zdassets.com mpc2-prod-25-is5qnl632q-wl.a.run.app mbiz.mailclick.me collector.mailbiz.one cdn.jsdelivr.net *.pagoexpress.com.br viacep.com.br *.viacep.com.br ; img-src https: data:; style-src https: 'unsafe-inline'; font-src https: data:; frame-ancestors *.plenitudedistribuidora.com.br plenitudedistribuidora.com.br; report-uri https://pub-csp.fbits.net/checkout_sem_carrinho; report-to https://pub-csp.fbits.net/checkout_sem_carrinho; worker-src 'self' blob:; 1 default-src 'none'; connect-src googleads.g.doubleclick.net our.umbraco.com stats.g.doubleclick.net www.google-analytics.com www.google.com cdn.linkedin.oribi.io region1.analytics.google.com iwfsecurity.report-uri.com consentcdn.cookiebot.com translate.googleapis.com 'self'; font-src fonts.gstatic.com use.typekit.net 'self'; manifest-src 'self'; object-src 'self'; frame-src vimeo.com donorbox.org www.buzzsprout.com player.vimeo.com www.googletagmanager.com www.youtube.com consentcdn.cookiebot.com www.google.com indd.adobe.com 'self'; frame-ancestors 'self'; img-src data: t.co analytics.twitter.com fonts.gstatic.com www.google.co.uk our.umbraco.com www.gravatar.com www.googletagmanager.com www.linkedin.com www.facebook.com px4.ads.linkedin.com www.google-analytics.com px.ads.linkedin.com gtranslate.net p.typekit.net www.gstatic.com dashboard.umbraco.com i.vimeocdn.com www.google.com translate.googleapis.com translate.google.com bat.bing.com *.cookiebot.com 'self'; media-src data: 'self' vimeo.com player.vimeo.com *.akamaized.net; script-src 'self' 'unsafe-eval' bat.bing.com static.ads-twitter.com vimeo.com www.vimeo.com ajax.aspnetcdn.com www.google.com connect.facebook.net www.googleadservices.com www.gstatic.com www.google-analytics.com snap.licdn.com translate-pa.googleapis.com consent.cookiebot.com use.typekit.net translate.google.com translate.googleapis.com consentcdn.cookiebot.com use.typekit.net dev.iwf.org.uk www.googletagmanager.com *.iwf.org.uk *.cookiebot.com *.typekit.net cdn.veritonic.com inline: 'unsafe-inline' 'unsafe-eval' 'self'; style-src translate.googleapis.com www.gstatic.com inline: 'self' 'unsafe-inline'; report-uri https://iwfsecurity.report-uri.com/r/d/csp/enforce; 1 font-src *.gstatic.com fonts.gstatic.com use.typekit.net *.typekit.net *.googleapis.com data: https://www.googletagmanager.com *.fontawesome.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action www.facebook.com ecommerce.raiffeisenbank.rs *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self' *.jasmin.rs *.cookiebot.com *.hotjar.com *.googletagmanager.com www.gstatic.com 'self'; frame-src www.facebook.com bid.g.doubleclick.net storifyme.com storifyme.xyz *.storifyme.com *.storifyme.xyz *.jasmin.rs *.yandex.com *.yandex.md *.doubleclick.net *.cookiebot.com *.googletagmanager.com *.yango.com fast.amc.demdex.net *.adobe.com *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.paypal.com www.sandbox.paypal.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * www.google.com 'self' 'unsafe-inline'; img-src *.googleapis.com *.gstatic.com stats.g.doubleclick.net www.google.com www.google.rs www.facebook.com www.googletagmanager.com storifyme.com storifyme.xyz *.storifyme.com *.storifyme.xyz assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com googleads.g.doubleclick.net bid.g.doubleclick.net analytics.google.com *.ftcdn.net *.behance.net *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io maps.googleapis.com maps.gstatic.com *.yandex.ru https://yandex.ru *.yandex.com *.yandex.md *.cookiebot.com *.yads.tech *.sharethis.com *.ymmobi.com *.doubleclick.net *.opera.com *.jasmin.rs jasmin.b-cdn.net kickoffcrm.com *.google.ru *.yango.com *.facebook.net *.linkedin.com data: www.googleadservices.com www.google-analytics.com p.typekit.net *.paypal.com *.typekit.net www.paypal.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com magefan.com cm.magefan.com *.disqus.com https://img.youtube.com https://firebasestorage.googleapis.com data: 'self' 'unsafe-inline'; script-src *.googleapis.com *.gstatic.com *.googletagmanager.com www.google-analytics.com connect.facebook.net googleads.g.doubleclick.net stats.g.doubleclick.net storifyme.com storifyme.xyz *.storifyme.com *.storifyme.xyz *.hotjar.com *.yandex.ru *.yandex.com *.cookiebot.com *.jasmin.rs mc.yango.com jasmin.sales-snap.com *.licdn.com *.tiktok.com assets.adobedtm.com *.adobe.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com commerce-payments-sdk.adobe.io s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com songbird.cardinalcommerce.com tagmanager.google.com https://www.googletagmanager.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.disqus.com *.avada.io *.shopify.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.googleapis.com *.jasmin.rs jasmin.sales-snap.com *.adobe.com fonts.googleapis.com assets.braintreegateway.com https://www.googletagmanager.com tagmanager.google.com *.fontawesome.com https://fonts.bunny.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.b-cdn.net storifyme.com storifyme.xyz *.storifyme.com *.storifyme.xyz *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src *.googleapis.com *.google.com google.com www.google-analytics.com connect.facebook.net stats.g.doubleclick.net *.facebook.com dpm.demdex.net amcglobal.sc.omtrdc.net www.googleadservices.com analytics.google.com www.googletagmanager.com *.cardinalcommerce.com vimeo.com ekr.zdassets.com get.geojs.io *.avada.io *.hotjar.com *.hotjar.io wss://ws.hotjar.com storifyme.com storifyme.xyz *.storifyme.com *.storifyme.xyz *.yandex.ru *.yandex.com yandex.com *.yandex.md *.doubleclick.net *.jasmin.rs *.googlesyndication.com *.yango.com jasmin.sales-snap.com *.linkedin.com *.cookiebot.com *.tiktok.com *.newrelic.com *.nr-data.net *.adobe.io performance.typekit.net *.sentry.io *.paypal.com *.braintreegateway.com *.braintree-api.com www.paypal.com www.sandbox.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com https://www.google-analytics.com https://*.google-analytics.com https://*.analytics.google.com https://get.geojs.io 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' *.rgi.net *.rgfi.net; script-src 'self' *.rgi.net *.rgfi.net 'unsafe-inline'; img-src 'self' *.rgi.net *.rgfi.net; frame-src 'self' *.rgi.net www.youtube.com www.youtube-nocookie.com; frame-ancestors 'self' *.data-line.de *.rgi.net; object-src 'none'; report-uri https://gindat.report-uri.com/r/d/csp/reportOnly 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com data: fonts.googleapis.com *.fontawesome.com maxcdn.bootstrapcdn.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.despegar.com *.koin.com.br *.googletagmanager.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com cdn.dnky.co amc.demdex.net www.google.com www.facebook.com youtube.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.despegar.com *.koin.com.br *.googletagmanager.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net maps.gstatic.com maps.googleapis.com accounts.google.com www.facebook.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.despegar.com *.koin.com.br *.googletagmanager.com fonts.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com 'self' data: data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net amcglobal.sc.omtrdc.net *.adobe.io use.typekit.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-ds.com *.typekit.net google.com *.google.com *.cdn-apple.com cdn.dnky.co r1-t.trackedlink.net www.gstatic.com js-agent.newrelic.com bam.nr-data.net maps.googleapis.com connect.facebook.net player.vimeo.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com https://live.decidir.com/ *.despegar.com *.koin.com.br *.googletagmanager.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://www.google.com *.gstatic.com https://maps.googleapis.com live.decidir.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com cdn.dnky.co *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.fontawesome.com maxcdn.bootstrapcdn.com assets.braintreegateway.com *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.snplow.net commerce.adobedc.net commerce.adobe.io *.sentry.io *.paypal.com google.com *.google.com maps.googleapis.com api.comapi.com bam.nr-data.net *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.despegar.com *.googletagmanager.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.google-analytics.com *.decidir.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 frame-ancestors 'self'; report-uri https://www.bodyandsoul.com.au/csp-reports 1 font-src fonts.gstatic.com use.typekit.net self data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.adyen.com pay.google.com payments-eu.amazon.com *.amazon.de https://store.plumrocket.com pal-test.adyen.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.adyen.com pay.google.com *.paypal.com self *.doubleclick.net *.criteo.com *.easydmp.net *.snapchat.com https://store.plumrocket.com https://accounts.google.com checkoutshopper-test.adyen.com pal-test.adyen.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io *.adyen.com pay.google.com *.payments-amazon.com *.media-amazon.com *.paypalobjects.com self *.bing.com *.paypal.com *.google.fr *.electrodepot.fr *.electrodepot.be *.electrodepot.es *.cookielaw.org *.snapchat.com checkoutshopper-test.adyen.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com self sc-static.net *.abtasty.com *.jsdelivr.net *.gstatic.com *.facebook.net *.tiktok.com *.googleapis.com *.easydmp.net *.vzbl.eu *.aticdn.net *.m1by1.com *.woosmap.com *.doubleclick.net *.cookielaw.org *.snapchat.com *.valiuz.com *.mediarithmics.com *.prediggo.services https://accounts.google.com checkoutshopper-test.adyen.com 'self' 'unsafe-eval' 'nonce-Z3ZwZWRzN24yNzM2OWZzbTZ0dTVpMWphYWF3cmpjbTY=' 'sha256-W5akSSK6LD5BjIlNICMcXaUObQSRAaj6bs7JHADURBA=' 'sha256-3qVqeAdyxxTdPkkRzqapjGkAUYLahxSrB7Mdup+GPQ0=' 'sha256-2rvfFrggTCtyF5WOiTri1gDS8Boibj4Njn0e+VCBmDI=' 'sha256-p8MCfMHqrovsjRYU9z0bU17dd0z81k/fVbGrtBBiM9g=' 'sha256-0pk2s4oXwBELlC6IBVb3nNaM2PjfjwI2N6OGIX5lx8Y=' 'sha256-nkEZknO0IxNxY/CkTMBhjNhwPvglpYumjx31B4fjkY8='; style-src *.adobe.com fonts.googleapis.com self *.gstatic.com *.electrodepot.fr *.electrodepot.be *.electrodepot.es *.snapchat.com https://accounts.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.adyen.com *.google.com google.com payments-eu.amazon.com *.paypal.com self *.snapchat.com *.cookielaw.org *.abtasty.com *.googleapis.com *.vzbl.eu *.criteo.com *.easydmp.net *.xiti.com *.valiuz.com *.doubleclick.net *.mediarithmics.com https://accounts.google.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.electrodepot.fr *.electrodepot.be *.electrodepot.es *.bing.com *.criteo.net *.snapchat.com *.netvigie.com *.xiti.com *.valiuz.com *.googletagmanager.com *.google.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 object-src 'none';base-uri 'self';script-src 'nonce-LaFYuEGm_eVLUsMz0Ehoaw' 'strict-dynamic' 'report-sample' 'unsafe-eval' 'unsafe-inline' https: http:;report-uri https://csp.withgoogle.com/csp/gws/other-hp 1 script-src 'self' https://static.apisearch.cloud 1 object-src 'none';base-uri 'self';script-src 'nonce-vEL2JaDh63AlzSGIRjGBkA' 'strict-dynamic' 'report-sample' 'unsafe-eval' 'unsafe-inline' https: http:;report-uri https://csp.withgoogle.com/csp/gws/other-hp 1 font-src https://fonts.gstatic.com/ https://fonts.googleapis.com/ https://www.google.com/ https://www.gstatic.com/ https://maps.googleapis.com/ https://www.google-analytics.com/ https://static.cloudflareinsights.com/ data: https://maps.gstatic.com https://credomatic.compassmerchantsolutions.com/ *.core.windows.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com self *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * secure.nmi.com secure.networkmerchants.com collectcheckout.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ https://*.doubleclick.net/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * secure.nmi.com secure.networkmerchants.com collectcheckout.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://kalicr.com https://www.google.co.cr/ https://www.facebook.com/ https://almaceneselrey.com/ https://www.google.com/ https://www.gstatic.com/ https://maps.googleapis.com/ https://www.google-analytics.com/ https://static.cloudflareinsights.com/ https://maps.gstatic.com https://fonts.googleapis.com/ https://credomatic.compassmerchantsolutions.com/ www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.core.windows.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://googletagmanager.com/ https://www.googletagmanager.com/ data: https://connect.facebook.net/ https://applepay.cdn-apple.com https://www.google.com/ https://www.gstatic.com/ https://maps.googleapis.com/ https://www.google-analytics.com/ https://static.cloudflareinsights.com/ https://maps.gstatic.com https://fonts.googleapis.com/ https://credomatic.compassmerchantsolutions.com/ s7.addthis.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.core.windows.net secure.nmi.com secure.networkmerchants.com collectcheckout.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://credomatic.compassmerchantsolutions.com/ https://fonts.gstatic.com/ https://fonts.googleapis.com/ https://googletagmanager.com/ https://www.googletagmanager.com/ data: https://secure.networkmerchants.com/ https://www.google.com/ https://www.gstatic.com/ https://maps.googleapis.com/ https://www.google-analytics.com/ https://static.cloudflareinsights.com/ https://maps.gstatic.com unsafe-inline assets.braintreegateway.com *.core.windows.net secure.nmi.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.core.windows.net 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://credomatic.compassmerchantsolutions.com/ https://googletagmanager.com/ https://www.googletagmanager.com/ https://*.doubleclick.net/ data: https://www.facebook.com/ https://places.googleapis.com/ https://www.google.co.cr https://www.google.com/ https://www.gstatic.com/ https://maps.googleapis.com/ https://www.google-analytics.com/ https://static.cloudflareinsights.com/ https://maps.gstatic.com https://fonts.googleapis.com/ ekr.zdassets.com/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.core.windows.net secure.nmi.com secure.networkmerchants.com collectcheckout.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * oppwa.com *.oppwa.com peachpayments.com *.peachpayments.com webchat.jdg.co.za *.jdg.co.za 'self' 'unsafe-inline'; frame-ancestors *.hana.ondemand.com 'self'; object-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; media-src *.gstatic.com *.google.com capitracking.istore.co.za analytics.twitter.com t.co sp.analytics.yahoo.com cdn1.stamped.io stamped.io *.zdassets.com 'self' 'unsafe-inline'; font-src *.gstatic.com fonts.gstatic.com use.typekit.net *.typekit.net *.klevu.com *.ksearchnet.com https://fonts.gstatic.com *.fontawesome.com https://fonts.bunny.net cdn1.stamped.io stamped.io *.cloudflare.com *.googleapis.com *.zopim.com *.tawk.to *.jsdelivr.net media.flixfacts.com 'unsafe-inline' data: data: 'self' 'unsafe-inline'; style-src *.googleapis.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com *.klevu.com *.ksearchnet.com https://hcaptcha.com https://*.hcaptcha.com *.fontawesome.com https://fonts.bunny.net assets.braintreegateway.com oppwa.com *.oppwa.com *.peachpayments.com cdn1.stamped.io stamped.io *.cloudflare.com *.jsdelivr.net www.gstatic.com media.flixcar.com 'unsafe-inline' data: https://statsjs.klevu.com https://js.klevu.com 'self' 'unsafe-inline'; connect-src *.googleapis.com *.google.com *.gstatic.com s.yimg.com in.visitors.live dsp-trk.eskimi.com dsp-ap.eskimi.com sslwidget.criteo.com wss://in.visitors.live analytics.tiktok.com/* portal.immerss.live *.linkedin.com *.creativecdn.com wss://ws.hotjar.com *.istore.co.za *.tiktok.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io *.sentry.io *.magento-datasolutions.com *.magento-ds.com *.paypal.com google.com *.braintreegateway.com *.braintree-api.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://*.ingest.sentry.io *.klevu.com *.ksearchnet.com sandbox-api.layup.co.za layup.co.za https://ipinfo.io https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com oppwa.com *.oppwa.com *.peachpayments.com cdn1.stamped.io stamped.io *.testfreaks.com *.nosto.com *.hotjar.io *.hotjar.com *.doubleclick.net *.zendesk.com *.tawk.to wss://*.tawk.to *.tawk.link *.addthis.com *.addthisedge.com *.what3words.com vsb111.tawk.to ekr.zdassets.com app.mobicredwidget.co.za wss://widget-mediator.zopim.com bam.nr-data.net *.googletagmanager.com security-hub.vaimo.network 'unsafe-eval' data: 'self' 'unsafe-inline'; frame-src *.google.com ams.creativecdn.com portal.immerss.live *.doubleclick.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * oppwa.com *.oppwa.com peachpayments.com *.peachpayments.com *.nosto.com *.issuu.com *.hotjar.com *.hotjar.io *.googletagmanager.com *.criteo.net *.criteo.com *.addthis.com webchat.jdg.co.za *.jdg.co.za 'self' 'unsafe-inline'; img-src *.googleapis.com *.gstatic.com *.google.com *.googleusercontent.com capitracking.istore.co.za analytics.twitter.com t.co sp.analytics.yahoo.com pixel.rubiconproject.com cm.g.doubleclick.net r.casalemedia.com eb2.3lift.com simage2.pubmatic.com contextual.media.net sync-t1.taboola.com exchange.mediavine.com s.ad.smaato.net match.sharethrough.com jadserve.postrelease.com c.bing.com sync.outbrain.com rtb-csync.smartadserver.com secure.adnxs.com ib.adnxs.com ads.yahoo.com ups.analytics.yahoo.com dis.criteo.com *.doubleclick.net *.linkedin.com *.tribalfusion.com sync.go.sonobi.com istore.co.za cm.adform.net ams.creativecdn.com bh.contextweb.com widgets.magentocommerce.com 'unsafe-inline' data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.klevu.com *.ksearchnet.com https://*.googleapis.com https://*.googleusercontent.com https://firebasestorage.googleapis.com store.paradoxlabs.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: oppwa.com *.oppwa.com *.peachpayments.com *.eu-west-1.amazonaws.com cdn1.stamped.io stamped.io *.cloudflare.com *.google.lv *.google.co.za *.google.com.na *.google.na *.zopim.com *.nosto.com *.hotjar.com *.hotjar.io *.googletagmanager.com *.zopim.io *.sfdr.co sfdr.co *.tawk.to tawk.link *.tawk.link *.addthis.com *.jsdelivr.net *.azurewebsites.net maps.googleapis.com app.mobicredwidget.co.za amcglobal.sc.omtrdc.net media.flixcar.com rt.flix360.com assets.secure.checkout.visa.com data: 'self' 'unsafe-inline'; script-src *.google.com *.googleapis.com *.gstatic.com capitracking.istore.co.za s.yimg.com platform2.cloud-iq.com static.ads-twitter.com rookdsp.com dsp-media.eskimi.com portal.immerss.live snap.licdn.com tags.creativecdn.com *.tiktok.com *.tribalfusion.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net assets.adobedtm.com amcglobal.sc.omtrdc.net commerce.adobe.net use.typekit.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com www.vimeo.com *.vimeocdn.com *.youtube.com *.magento-ds.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com *.typekit.net google.com *.cdn-apple.com *.braintreegateway.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://browser.sentry-cdn.com js.klevu.com *.ksearchnet.com https://*.gstatic.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com *.avada.io js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.oppwa.com oppwa.com *.peachpayments.com cdn1.stamped.io stamped.io *.zopim.com *.videoly.co sfdr.co *.cnetcontent.com *.cloudfront.net *.klevu.com *.google.lv *.google.co.za *.google.com.na *.google.na *.cloudflare.com *.cloudflareinsights.com *.nosto.com *.hotjar.com *.googletagmanager.com *.criteo.net *.criteo.com *.sfdr.co *.tawk.to *.tawk.link *.jsdelivr.net *.addthis.com *.addthisedge.com *.moatads.com *.mouseflow.com *.facebook.com *.what3words.com maps.googleapis.com static.zdassets.com app.mobicredwidget.co.za www.gstatic.com bam.nr-data.net js.testfreaks.com media.flixfacts.com media.flixcar.com security-hub.vaimo.network https://js.klevu.com 'self' 'unsafe-inline' 'unsafe-eval'; 1 require-trusted-types-for 'script'; report-uri https://csp.withgoogle.com/csp/uxe-owners-acl/wallet_google 1 script-src 'strict-dynamic' 'nonce-uHn8FlP6AjWOEiT7n++ngg==' 1 frame-ancestors 'self';img-src 'self' data: https://pixel.wp.com http://esc.vn https://secure.trust-provider.com https://www.facebook.com https://www.google.com.vn https://www.google.com.my https://c.clarity.ms https://www.googletagmanager.com https://en.wordpress.com https://www.google.com.sg https://www.gstatic.com https://www.google.com.kh https://fonts.gstatic.com https://vietit.vn https://www.google.be https://vnnic.vn https://www.google.de https://www.google.com.tw https://www.google.nl https://stats.g.doubleclick.net https://i-sohoa.vnecdn.net https://smarttrain.edu.vn https://www.google.bs https://www.google.co.jp https://encrypted-tbn0.gstatic.com https://cafefcdn.com https://www.google.com.au https://image.thanhnien.vn https://c.bing.com https://www.google.com.et https://www.google.co.za https://png.pngtree.com https://www.paypalobjects.com https://t.paypal.com https://www.google.com.hk https://www.google.com.pk https://i.ytimg.com https://translate.google.com https://ws.com.vn https://www.google.co.zw https://cdn.24h.com.vn https://woocommerce.com https://updates.themepunch-ext-b.tools https://www.google.co.uk https://storage.googleapis.com https://s3.envato.com https://really-simple-ssl.com https://anhsangvacuocsong.vn https://vneconomy.mediacdn.vn https://www.google.at https://www.google.la https://www.google.co.kr https://www.google.com.tr https://www.google.ch https://www.google.com.ph https://www.google.no https://www.google.com.ng https://www.google.com.br https://www.google.co.in https://googleads.g.doubleclick.net https://www.google.ie https://baovemoitruong.org.vn https://tenmien.vn https://adservice.google.com https://www.google.cz https://new.esc.vn blob: https://www.google.fr https://www.google.ru https://static-images.vnncdn.net https://www.google.se https://www.google.hu https://translate.googleapis.com https://vtv1.mediacdn.vn https://pos.baidu.com file https://www.google.ca https://www.google.co.uz https://www.google.ae https://www.google.al https://d5nxst8fruw4z.cloudfront.net https://www.google.iq https://www.google.co.id https://ictvietnam.mediacdn.vn https://www.activesearchresults.com https://www.google-analytics.com https://www.google.co.ma https://www.google.pl https://cafebiz.cafebizcdn.vn https://www.google.fi https://www.google.dk https://www.google.com.mm https://connect.facebook.net https://secure.gravatar.com https://ts.w.org https://s.w.org https://ps.w.org ; default-src 'self'; script-src 'self' 'unsafe-inline' https://stats.wp.com https://yoast.com https://secure.trust-provider.com https://s0.wp.com https://www.googletagmanager.com https://connect.facebook.net https://www.clarity.ms https://cdnjs.cloudflare.com https://maps.googleapis.com https://www.portotheme.com https://translate.google.com https://widgets.wp.com https://www.paypal.com https://translate.googleapis.com blob: https://www.youtube.com https://translate-pa.googleapis.com https://infirc.com https://d31qbv1cthcecs.cloudfront.net http://code.jquery.com https://gc.kis.v2.scr.kaspersky-labs.com https://abfc-extension.com https://cdn.mxpnl.com https://player.vimeo.com https://googleads.g.doubleclick.net http://ajax.googleapis.com https://ff.kis.v2.scr.kaspersky-labs.com https://me.kis.v2.scr.kaspersky-labs.com https://cdn.onesignal.com 'unsafe-eval'; script-src-elem 'self' 'unsafe-inline' https://stats.wp.com https://yoast.com https://secure.trust-provider.com https://s0.wp.com https://www.googletagmanager.com https://connect.facebook.net https://www.clarity.ms https://cdnjs.cloudflare.com https://maps.googleapis.com https://www.portotheme.com https://translate.google.com https://widgets.wp.com https://www.paypal.com https://translate.googleapis.com blob: https://www.youtube.com https://translate-pa.googleapis.com https://infirc.com https://d31qbv1cthcecs.cloudfront.net http://code.jquery.com https://gc.kis.v2.scr.kaspersky-labs.com https://abfc-extension.com https://cdn.mxpnl.com https://player.vimeo.com https://googleads.g.doubleclick.net http://ajax.googleapis.com https://ff.kis.v2.scr.kaspersky-labs.com https://me.kis.v2.scr.kaspersky-labs.com https://cdn.onesignal.com ; style-src 'self' 'unsafe-inline' https://use.fontawesome.com https://fonts.googleapis.com https://s0.wp.com https://gc.kis.v2.scr.kaspersky-labs.com http://fonts.googleapis.com https://www.gstatic.com https://widgets.wp.com https://me.kis.v2.scr.kaspersky-labs.com https://ff.kis.v2.scr.kaspersky-labs.com http://netdna.bootstrapcdn.com ; style-src-elem 'self' 'unsafe-inline' https://use.fontawesome.com https://fonts.googleapis.com https://s0.wp.com https://gc.kis.v2.scr.kaspersky-labs.com http://fonts.googleapis.com https://www.gstatic.com https://widgets.wp.com https://me.kis.v2.scr.kaspersky-labs.com https://ff.kis.v2.scr.kaspersky-labs.com http://netdna.bootstrapcdn.com ; font-src 'self' https://fonts.gstatic.com https://use.fontawesome.com https://s0.wp.com https://s1.wp.com chrome-extension http://fonts.gstatic.com null data:; frame-src 'self' https://widgets.wp.com https://wordpress.com https://www.facebook.com https://m.facebook.com https://www.youtube.com https://td.doubleclick.net https://maps.google.com https://web.facebook.com https://www.google.com null https://www.paypal.com https://mozbar.moz.com https://app.stylar.com https://www.youtube-nocookie.com data: https://www.googletagmanager.com wvjbscheme://__wvjb_queue_message__ https://auth.ztsa-iag-int.trendmicro.com https://gateway.zscalerthree.net blob:; connect-src 'self' https://f.clarity.ms https://analytics.google.com https://o.clarity.ms https://adservice.google.com https://q.clarity.ms https://stats.g.doubleclick.net https://t.clarity.ms https://translate.googleapis.com https://w.clarity.ms https://maps.googleapis.com https://r.clarity.ms https://z.clarity.ms https://x.clarity.ms https://www.google.com.vn https://l.clarity.ms https://e.clarity.ms https://www.googleadservices.com https://u.clarity.ms https://p.clarity.ms https://h.clarity.ms https://s.clarity.ms https://v.clarity.ms https://www.facebook.com https://b.clarity.ms https://i.clarity.ms https://www.google.com.hk https://d.clarity.ms https://a.clarity.ms https://region1.analytics.google.com https://m.clarity.ms https://www.clarity.ms https://www.google-analytics.com https://www.google.com.sg https://j.clarity.ms https://www.google.com.kh https://yoast.com wss://gc.kis.v2.scr.kaspersky-labs.com https://y.clarity.ms https://infragrid.v.network https://www.google.de https://www.google.com.au https://www.paypal.com https://widgets.wp.com https://overbridgenet.com https://k.clarity.ms properties https://n.clarity.ms https://www.google.co.jp https://gc.kis.v2.scr.kaspersky-labs.com https://api-js.mixpanel.com https://me.kis.v2.scr.kaspersky-labs.com https://woocommerce.com https://www.google.co.uk http://localhost https://www.google.com.ph https://www.google.co.kr https://www.google.com.tw data: https://www.google.fr https://www.google.ru wss://me.kis.v2.scr.kaspersky-labs.com https://translate-pa.googleapis.com https://api.blocksly.org http://ad.doubleclick.net https://www.google.co.id https://www.google.ca https://ff.kis.v2.scr.kaspersky-labs.com https://www.google.co.ma https://www.google.se https://www.google.co.in wss://ff.kis.v2.scr.kaspersky-labs.com ws://localhost; media-src 'self' https://sw-themes.com data: https://updates.themepunch-ext-b.tools; worker-src 'self' blob:; report-uri https://esc.vn/wp-json/rsssl/v1/csp?rsssl_apitoken=293818460; 1 script-src 'nonce-6VZ5+0WzBaAo0eU8Ag3bRQ==' 'strict-dynamic' 'unsafe-eval' 'unsafe-inline' https: 'report-sample'; base-uri 'none'; report-uri https://events.mercadolibre.com/csp/reports?identifier=w1qeU4XKVwGbQGBuEKyE3KhFBIpr5IZSIaRiTowMc8UG7kU18vRsmBTEKL2krAj23LIS&policy_id=26548&user_id=&request_id=173ecb3f-8f49-4c40-9787-92099f4b2e2b; report-to csp-endpoint-wqeuxkvwgbqgbuekyekhfbiprizsiaritowmcugkuvrsmbteklkrajlis; object-src https://http2.mlstatic.com/ https://mlstaticquic-a.akamaihd.net/; frame-ancestors 'self' https://*.mercadolibre.cl:* https://*.mercadolibre.com:* https://*.mercadolibre.com.ve:* https://*.mercadolibre.com.ar:* https://*.mercadolivre.com.br:* https://*.mercadolibre.com.co:* https://*.mercadolibre.com.ec:* https://*.mercadolibre.com.mx:* https://*.mercadolibre.com.pe:* https://*.mercadolibre.com.uy:* https://*.mercadopago.cl:* https://*.mercadopago.com.ar:* https://*.mercadopago.com.br:* https://*.mercadopago.com.co:* https://*.mercadopago.com.mx:* https://*.mercadopago.com.pe:* https://*.mercadopago.com.uy:* https://*.mercadopago.com.ve:* https://*.mercadopago.com:* https://*.adminml.com:* https://*.mercadolibre.co.cr:* https://*.mercadolibre.com.pa:* https://*.mercadolibre.com.do:* https://*.mercadolibre.com.bo:* https://*.mercadolibre.com.py:* https://*.mercadolibre.com.gt:* https://*.mercadolibre.com.hn:* https://*.mercadolibre.com.ni:* https://*.mercadolibre.com.sv:* https://*.mercadopago.com.ec:* https://*.portalinmobiliario.com:* https://*.mercadolivre.com:* 1 frame-ancestors 'self'; report-uri https://send.hsbrowserreports.com/csp/report?resource=website-grader-ui/static-1.7710/html/public-en.html&cfRay=9c9f3f372d7ccec1-IAD 1 default-src 'self'; script-src 'report-sample' 'self' 'nonce-TDaOWbS/WsWEep0Km7etFpc/25XogF6fvTesqkzsMUA=' 'strict-dynamic' https://ajax.googleapis.com/ajax/libs/jquery/3.7.0/jquery.min.js https://ak.sail-horizon.com/spm/spm.v1.min.js https://analytics.tiktok.com/i18n/pixel/events.js https://bat.bing.com/bat.js https://cdn-ukwest.onetrust.com/scripttemplates/202503.1.0/otBannerSdk.js https://cdn-ukwest.onetrust.com/scripttemplates/otSDKStub.js https://connect.facebook.net/en_US/fbevents.js https://d.la11-core1.sfdc-cehfhs.salesforceliveagent.com/chat/rest/EmbeddedService/EmbeddedServiceConfig.jsonp https://d.la3-c1-cdg.salesforceliveagent.com/chat/rest/EmbeddedService/EmbeddedServiceConfig.jsonp https://d16fk4ms6rqz1v.cloudfront.net/capture/mrandmrssmith.js https://dv4m25lzcyglc.cloudfront.net/3.0.0/gh7rnghq.js https://googleads.g.doubleclick.net/pagead/viewthroughconversion/726324624/ https://js.stripe.com/v2/ https://js.stripe.com/v3/ https://checkout.stripe.com/checkout.js https://js.stripe.com/basil/stripe.js https://mrandmrssmith.my.salesforce.com/embeddedservice/5.0/esw.min.js https://api.feefo.com/api/javascript/mr-mrs-smith https://register.feefo.com//feefo-widget-v2/js/feefo-widget.js https://api.feefo.com/feefo-widgets-data/loader/widgets/mr-mrs-smith https://register.feefo.com/feefo-widgets-app/feefo_widgets_loader.js https://register.feefo.com/feefo-widget-v2/js/loader/pop-up-reviews.bundle.js https://se.monetate.net/js/2/a-58d4210d/p/mrandmrssmith.com/entry.js https://service.force.com/embeddedservice/5.0/client/liveagent.esw.min.js https://static.cloudflareinsights.com/beacon.min.js/vcd15cbe7772f49c399c6a5babf22c1241717689176015 https://static.mention-me.com/dist/static/js/async/bootloader-init.v2.b874a4b9.js https://t.contentsquare.net/uxa/cea2376851edf.js https://tag.mention-me.com/api/v2/refereefind/mm2133a6f1 https://tag.rmp.rakuten.com/111651.ct.js https://widget.trustpilot.com/bootstrap/v5/tp.widget.bootstrap.min.js https://www.googletagmanager.com/gtag/destination https://d2wy8f7a9ursnm.cloudfront.net/bugsnag-2.min.js https://d2wy8f7a9ursnm.cloudfront.net/v4/bugsnag.min.js https://ajax.googleapis.com/ajax/libs/jquery/1.7.2/jquery.min.js https://ajax.googleapis.com/ajax/libs/jqueryui/1.8.18/jquery-ui.min.js https://ajax.googleapis.com/ajax/libs/jqueryui/1.13.2/jquery-ui.min.js https://maps.googleapis.com/maps/api/js https://assets.pinterest.com/js/pinit.js https://cdnjs.cloudflare.com/ajax/libs/svgxuse/1.2.6/svgxuse.min.js https://cdn.firebase.com/js/client/1.1.2/firebase.js https://code.jquery.com/jquery-migrate-1.2.1.js https://js.braintreegateway.com/web/3.0.1/js/client.min.js https://js.braintreegateway.com/web/3.0.1/js/apple-pay.min.js https://api.skyscanner.net/api.ashx https://translate.google.com/translate_a/element.js https://static-eu.payments-amazon.com/OffAmazonPayments/uk/lpa/js/Widgets.js https://www.googleadservices.com/pagead/conversion.js https://0.r.msn.com/scripts/microsoft_adcenterconversion.js http://e.monetate.net/js/3/a-58d4210d/d/mms-monetate.mmsmith.info/t1640009934/2cbacf4e5b15a1ac/custom.js http://f.monetate.net/trk/4/s/a-58d4210d/d/mms-monetate.mmsmith.info/ https://mrandmrssmith--chatsand.sandbox.my.salesforce.com/embeddedservice/5.0/esw.min.js https://tag-demo.mention-me.com/api/v2/referreroffer/mm2133a6f1 https://static-demo.mention-me.com/dist/static/js/async/bootloader-init.v2.b874a4b9.js https://se.monetate.net/js/3/a-58d4210d/d/mms-monetate.mmsmith.info/t1640009934/2cbacf4e5b15a1ac/custom.js https://service.force.com/embeddedservice/5.0/utils/common.min.js https://service.force.com/embeddedservice/5.0/client/invite.esw.min.js https://d.la3-c1-cdg.salesforceliveagent.com/chat/rest/Visitor/Settings.jsonp https://service.force.com/embeddedservice/5.0/utils/inert.min.js https://d.la11-core1.sfdc-cehfhs.salesforceliveagent.com/chat/rest/Visitor/Settings.jsonp https://d.la11-core1.sfdc-cehfhs.salesforceliveagent.com/chat/rest/Visitor/Availability.jsonp https://register.feefo.com/badge-ui/feefo_adaptive_badges.js https://tag-demo.mention-me.com/api/v2/refereefind/mm2133a6f1 https://api.mapbox.com/mapbox-gl-js/plugins/mapbox-gl-rtl-text/v0.2.0/mapbox-gl-rtl-text.js http://register.feefo.com//feefo-widget-v2/js/feefo-widget.js https://register.feefo.com//feefo-widget-v2/js/feefo-widget.js http://se.monetate.net/js/2/a-58d4210d/d/mms-monetate.mmsmith.info/entry.js https://se.monetate.net/js/2/a-58d4210d/d/mms-monetate.mmsmith.info/entry.js http://c.webtrends-optimize.com/acs/accounts/f0fa8f35-66f6-474c-87f7-6947403a3fd3/js/wt.js https://c.webtrends-optimize.com/acs/accounts/f0fa8f35-66f6-474c-87f7-6947403a3fd3/js/wt.js; style-src * 'unsafe-inline' 'report-sample' 'self'; object-src 'none'; base-uri 'self'; connect-src 'self' https://*.onetrust.com https://*.feefo.com https://*.analytics.google.com https://*.google-analytics.com https://*.mapbox.com https://*.contentsquare.net https://maps.googleapis.com https://api.sail-personalize.com https://google.com https://i.salecycle.com https://notify.bugsnag.com https://sessions.bugsnag.com https://www.google.co.uk https://www.google.com https://tag-demo.mention-me.com http://ots.webtrends-optimize.com https://ots.webtrends-optimize.com https://analytics.tiktok.com https://*.mrandmrssmith.com wss://ws.salecycle.com; font-src 'self' data: https://www.mrandmrssmith.com https://use.typekit.net https://fonts.gstatic.com https://fonts.feefo.com https://mrandmrssmith.com; frame-src 'self' https://js.stripe.com https://s.salecycle.com https://service.force.com https://widget.trustpilot.com https://www.googletagmanager.com https://demo.mention-me.com https://accounts.google.com https://form.typeform.com https://tags.rd.linksynergy.com; img-src 'self' data: https://www.mrandmrssmith.com https://*.mrandmrssmith.com https://api.feefo.com https://api.mapbox.com https://cdn-ukwest.onetrust.com https://public.feefo.com https://s3-eu-west-1.amazonaws.com https://www.google.co.uk https://www.googletagmanager.com https://mrandmrssmith-res.cloudinary.com https://f.monetate.net https://bat.bing.com https://c.contentsquare.net https://www.facebook.com https://www.google.com https://consent.linksynergy.com; manifest-src 'self'; media-src 'self'; worker-src 'self' blob: 1 script-src 'self' https://abtasty.com https://*.abtasty.com https://analytics.tiktok.com https://*.analytics.tiktok.com https://s.salecycle.com https://d16fk4ms6rqz1v.cloudfront.net/ https://i.salecycle.com/ wss://ws.salecycle.com https://assets.sc-trc.com/ https://mymachine.salecycle.com:8080 https://media.beaverbrooks.co.uk https://media.loupe.co.uk https://*.amplience.net https://amplience.net https://*.amplience.com https://amplience.com https://*.staging.bigcontent.io https://*.bigcontent.io https://*.beaverbrooks.co.uk/ https://beaverbrooks.co.uk/ https://*.loupe.co.uk/ https://loupe.co.uk/ https://*.cookiebot.com/ https://cookiebot.com https://vercel.live https://*.vercel-scripts.com https://vercel-scripts.com https://*.pusher.com wss://*.pusher.com https://*.vercel.com https://vercel.com https://*.vercel.aws.beaverbrooks.co.uk https://*.aws.beaverbrooks.co.uk https://*.vercel.aws.loupe.co.uk https://*.aws.loupe.co.uk https://*.trustpilot.com https://trustpilot.com https://*.appointedd.com https://appointedd.com https://*.googletagmanager.com https://googletagmanager.com https://tagmanager.google.com https://www.googleadservices.com https://*.pixlee.com https://pixlee.com https://*.pixlee.co https://pixlee.co https://*.pxlecdn.com https://pxlecdn.com https://*.google-analytics.com https://google-analytics.com https://*.gstatic.com https://gstatic.com https://cdnjs.cloudflare.com https://cdn.jsdelivr.net https://*.doubleclick.net https://doubleclick.net https://*.googlesyndication.com https://googlesyndication.com https://*.dwin1.com https://dwin1.com https://*.awin1.com https://awin1.com https://*.roeyecdn.com https://roeyecdn.com https://*.roeye.com https://roeye.com https://*.zenaps.com https://zenaps.com https://*.wepowerconnections.com https://wepowerconnections.com https://*.tiktok.com https://tiktok.com https://*.pingdom.net https://pingdom.net https://*.facebook.net https://facebook.net https://*.facebook.com https://facebook.com https://*.contentsquare.net https://contentsquare.net https://*.cybersource.com https://cybersource.com https://*.digicert.com https://digicert.com https://*.vee24.com https://vee24.com https://*.paypal.com https://paypal.com https://*.paypalobjects.com https://paypalobjects.com https://*.klarnacdn.net https://klarnacdn.net https://*.klarna.com https://klarna.com https://*.klarnaapi.com https://klarnaapi.com https://*.bing.com https://bat.bing.com https://*.bat.bing.com https://flex.atdmt.com https://*.flex.atdmt.com https://clarity.ms https://*.clarity.ms https://*.rolex.com https://rolex.com https://*.recaptcha.net https://recaptcha.net https://*.adobedtm.com https://adobedtm.com https://*.demdex.net https://demdex.net https://*.everesttech.net https://everesttech.net https://*.naver.com https://naver.com https://*.naver.net https://naver.net https://*.pstatic.net https://pstatic.net https://www.youtube.com https://player.vimeo.com https://*.googleapis.com https://googleapis.com https://*.google.com https://google.com https://*.google.pl https://google.pl https://*.google.co.uk https://google.co.uk https://*.google.md https://google.md https://google.ie https://*.jquery.com https://jquery.com https://*.givex.com https://givex.com https://*.sentry.io https://sentry.io https://*.ingest.sentry.io https://ingest.sentry.io https://*.sentry-cdn.com https://sentry-cdn.com https://*.exponea.com https://exponea.com https://*.pinterest.com https://pinterest.com https://*.pinimg.com https://pinimg.com 'unsafe-eval' 'unsafe-inline'; style-src 'self' https://*.googleapis.com https://googleapis.com https://vercel.live https://*.vercel-scripts.com https://vercel-scripts.com https://*.pusher.com wss://*.pusher.com https://*.vercel.com https://vercel.com https://*.vercel.aws.beaverbrooks.co.uk https://*.aws.beaverbrooks.co.uk https://*.vercel.aws.loupe.co.uk https://*.aws.loupe.co.uk https://*.vee24.com https://vee24.com https://*.googletagmanager.com https://googletagmanager.com https://tagmanager.google.com https://www.googleadservices.com 'unsafe-inline'; img-src 'self' https://ggpht.com https://*.ggpht.com https://abtasty.com https://*.abtasty.com https://googleads.g.doubleclick.net https://google.ie https://*.google.ie https://google.ae https://*.google.ae https://google.se https://*.google.se https://google.es https://*.google.es https://google.nl https://*.google.nl https://google.de https://*.google.de https://google.it https://*.google.it https://google.com.hk https://*.google.com.hk https://media.beaverbrooks.co.uk https://media.loupe.co.uk https://*.amplience.net https://amplience.net https://*.amplience.com https://amplience.com https://*.staging.bigcontent.io https://*.bigcontent.io https://*.beaverbrooks.co.uk/ https://beaverbrooks.co.uk/ https://*.loupe.co.uk/ https://loupe.co.uk/ https://*.cookiebot.com/ https://cookiebot.com https://*.facebook.net https://facebook.net https://*.facebook.com https://facebook.com https://*.googleapis.com https://googleapis.com https://*.google.com https://google.com https://*.google.pl https://google.pl https://*.google.co.uk https://google.co.uk https://*.google.md https://google.md https://google.ie https://*.gstatic.com https://gstatic.com https://*.googleusercontent.com https://googleusercontent.com https://*.googletagmanager.com https://googletagmanager.com https://tagmanager.google.com https://www.googleadservices.com https://*.dwin1.com https://dwin1.com https://*.awin1.com https://awin1.com https://*.roeyecdn.com https://roeyecdn.com https://*.roeye.com https://roeye.com https://*.zenaps.com https://zenaps.com https://*.wepowerconnections.com https://wepowerconnections.com https://vercel.live https://*.vercel-scripts.com https://vercel-scripts.com https://*.pusher.com wss://*.pusher.com https://*.vercel.com https://vercel.com https://*.vercel.aws.beaverbrooks.co.uk https://*.aws.beaverbrooks.co.uk https://*.vercel.aws.loupe.co.uk https://*.aws.loupe.co.uk https://*.digicert.com https://digicert.com https://*.paypal.com https://paypal.com https://*.paypalobjects.com https://paypalobjects.com https://*.klarnacdn.net https://klarnacdn.net https://*.klarna.com https://klarna.com https://*.klarnaapi.com https://klarnaapi.com https://*.contentsquare.net https://contentsquare.net https://*.rolex.com https://rolex.com https://*.bing.com https://bat.bing.com https://*.bat.bing.com https://flex.atdmt.com https://*.flex.atdmt.com https://clarity.ms https://*.clarity.ms https://*.pixlee.com https://pixlee.com https://*.pixlee.co https://pixlee.co https://*.pxlecdn.com https://pxlecdn.com https://*.ytimg.com https://ytimg.com https://*.doubleclick.net https://doubleclick.net https://*.googlesyndication.com https://googlesyndication.com https://*.adobedtm.com https://adobedtm.com https://*.demdex.net https://demdex.net https://*.everesttech.net https://everesttech.net https://*.tiktok.com https://tiktok.com https://*.vee24.com https://vee24.com data:; frame-src 'self' https://pinterest.com https://*.pinterest.com https://s.salecycle.com https://d16fk4ms6rqz1v.cloudfront.net/ https://i.salecycle.com/ wss://ws.salecycle.com https://assets.sc-trc.com/ https://mymachine.salecycle.com:8080 https://*.jotform.com/ https://jotform.com/ https://vercel.live https://*.vercel-scripts.com https://vercel-scripts.com https://*.pusher.com wss://*.pusher.com https://*.vercel.com https://vercel.com https://*.vercel.aws.beaverbrooks.co.uk https://*.aws.beaverbrooks.co.uk https://*.vercel.aws.loupe.co.uk https://*.aws.loupe.co.uk https://*.googletagmanager.com https://googletagmanager.com https://tagmanager.google.com https://www.googleadservices.com https://*.trustpilot.com https://trustpilot.com https://*.cookiebot.com/ https://cookiebot.com https://*.pixlee.com https://pixlee.com https://*.pixlee.co https://pixlee.co https://*.pxlecdn.com https://pxlecdn.com https://www.youtube.com https://player.vimeo.com https://*.beaverbrooks.co.uk/ https://beaverbrooks.co.uk/ https://*.loupe.co.uk/ https://loupe.co.uk/ https://*.amplience.net https://amplience.net https://*.amplience.com https://amplience.com https://*.staging.bigcontent.io https://*.bigcontent.io https://*.appointedd.com https://appointedd.com https://*.vee24.com https://vee24.com https://*.cybersource.com https://cybersource.com https://*.facebook.net https://facebook.net https://*.facebook.com https://facebook.com https://*.paypal.com https://paypal.com https://*.paypalobjects.com https://paypalobjects.com https://*.klarnacdn.net https://klarnacdn.net https://*.klarna.com https://klarna.com https://*.klarnaapi.com https://klarnaapi.com https://*.rolex.com https://rolex.com https://*.recaptcha.net https://recaptcha.net https://*.cardinalcommerce.com https://cardinalcommerce.com https://*.google.com https://google.com https://*.google.pl https://google.pl https://*.google.co.uk https://google.co.uk https://*.google.md https://google.md https://google.ie https://*.adobedtm.com https://adobedtm.com https://*.demdex.net https://demdex.net https://*.everesttech.net https://everesttech.net https://*.givex.com https://givex.com https://*.pinterest.com https://pinterest.com https://*.pinimg.com https://pinimg.com https://*.v12finance.com https://v12finance.com https://v12retailfinance.com/; frame-ancestors 'self' https://*.jotform.com/ https://jotform.com/ https://vercel.live https://*.vercel-scripts.com https://vercel-scripts.com https://*.pusher.com wss://*.pusher.com https://*.vercel.com https://vercel.com https://*.vercel.aws.beaverbrooks.co.uk https://*.aws.beaverbrooks.co.uk https://*.vercel.aws.loupe.co.uk https://*.aws.loupe.co.uk https://*.googletagmanager.com https://googletagmanager.com https://tagmanager.google.com https://www.googleadservices.com https://*.trustpilot.com https://trustpilot.com https://*.cookiebot.com/ https://cookiebot.com https://*.pixlee.com https://pixlee.com https://*.pixlee.co https://pixlee.co https://*.pxlecdn.com https://pxlecdn.com https://www.youtube.com https://player.vimeo.com https://*.beaverbrooks.co.uk/ https://beaverbrooks.co.uk/ https://*.loupe.co.uk/ https://loupe.co.uk/ https://*.amplience.net https://amplience.net https://*.amplience.com https://amplience.com https://*.staging.bigcontent.io https://*.bigcontent.io https://*.appointedd.com https://appointedd.com https://*.vee24.com https://vee24.com https://*.cybersource.com https://cybersource.com https://*.facebook.net https://facebook.net https://*.facebook.com https://facebook.com https://*.paypal.com https://paypal.com https://*.paypalobjects.com https://paypalobjects.com https://*.klarnacdn.net https://klarnacdn.net https://*.klarna.com https://klarna.com https://*.klarnaapi.com https://klarnaapi.com https://*.rolex.com https://rolex.com https://*.recaptcha.net https://recaptcha.net https://*.cardinalcommerce.com https://cardinalcommerce.com https://*.google.com https://google.com https://*.google.pl https://google.pl https://*.google.co.uk https://google.co.uk https://*.google.md https://google.md https://google.ie https://*.adobedtm.com https://adobedtm.com https://*.demdex.net https://demdex.net https://*.everesttech.net https://everesttech.net https://*.givex.com https://givex.com https://*.pinterest.com https://pinterest.com https://*.pinimg.com https://pinimg.com https://*.v12finance.com https://v12finance.com https://v12retailfinance.com/; form-action https://*.paypal.com https://paypal.com https://*.facebook.net https://facebook.net https://*.facebook.com https://facebook.com https://*.cardinalcommerce.com https://cardinalcommerce.com 'self'; worker-src 'self' https://media.beaverbrooks.co.uk https://media.loupe.co.uk https://*.amplience.net https://amplience.net https://*.amplience.com https://amplience.com https://*.staging.bigcontent.io https://*.bigcontent.io https://*.beaverbrooks.co.uk/ https://beaverbrooks.co.uk/ https://*.loupe.co.uk/ https://loupe.co.uk/ https://*.cookiebot.com/ https://cookiebot.com https://vercel.live https://*.vercel-scripts.com https://vercel-scripts.com https://*.pusher.com wss://*.pusher.com https://*.vercel.com https://vercel.com https://*.vercel.aws.beaverbrooks.co.uk https://*.aws.beaverbrooks.co.uk https://*.vercel.aws.loupe.co.uk https://*.aws.loupe.co.uk https://*.trustpilot.com https://trustpilot.com https://*.appointedd.com https://appointedd.com https://*.googletagmanager.com https://googletagmanager.com https://tagmanager.google.com https://www.googleadservices.com https://*.pixlee.com https://pixlee.com https://*.pixlee.co https://pixlee.co https://*.pxlecdn.com https://pxlecdn.com https://*.google-analytics.com https://google-analytics.com https://*.gstatic.com https://gstatic.com https://cdnjs.cloudflare.com https://cdn.jsdelivr.net https://*.doubleclick.net https://doubleclick.net https://*.googlesyndication.com https://googlesyndication.com https://*.dwin1.com https://dwin1.com https://*.awin1.com https://awin1.com https://*.roeyecdn.com https://roeyecdn.com https://*.roeye.com https://roeye.com https://*.zenaps.com https://zenaps.com https://*.wepowerconnections.com https://wepowerconnections.com https://*.tiktok.com https://tiktok.com https://*.pingdom.net https://pingdom.net https://*.facebook.net https://facebook.net https://*.facebook.com https://facebook.com https://*.contentsquare.net https://contentsquare.net https://*.cybersource.com https://cybersource.com https://*.digicert.com https://digicert.com https://*.vee24.com https://vee24.com https://*.paypal.com https://paypal.com https://*.paypalobjects.com https://paypalobjects.com https://*.klarnacdn.net https://klarnacdn.net https://*.klarna.com https://klarna.com https://*.klarnaapi.com https://klarnaapi.com https://*.bing.com https://bat.bing.com https://*.bat.bing.com https://flex.atdmt.com https://*.flex.atdmt.com https://clarity.ms https://*.clarity.ms https://*.rolex.com https://rolex.com https://*.recaptcha.net https://recaptcha.net https://*.adobedtm.com https://adobedtm.com https://*.demdex.net https://demdex.net https://*.everesttech.net https://everesttech.net https://*.naver.com https://naver.com https://*.naver.net https://naver.net https://*.pstatic.net https://pstatic.net https://www.youtube.com https://player.vimeo.com https://*.googleapis.com https://googleapis.com https://*.google.com https://google.com https://*.google.pl https://google.pl https://*.google.co.uk https://google.co.uk https://*.google.md https://google.md https://google.ie https://*.jquery.com https://jquery.com https://*.givex.com https://givex.com https://*.sentry.io https://sentry.io https://*.ingest.sentry.io https://ingest.sentry.io https://*.sentry-cdn.com https://sentry-cdn.com https://*.exponea.com https://exponea.com https://*.pinterest.com https://pinterest.com https://*.pinimg.com https://pinimg.com blob: 'unsafe-eval' 'unsafe-inline'; object-src 'none'; base-uri 'self'; report-uri /api/csp-report; report-to csp-endpoint; 1 default-src blob: https://*.mhcache.com;font-src 'self' https://*.myheritage.com https://*.mhcache.com https://fonts.gstatic.com;frame-src 'self' https://*.mhcache.com https://portal.allyable.com https://mh-site-files-5c53d6a9947c.s3.amazonaws.com https://myheritage-container.com https://www.myheritage-partners.com https://www.myheritage.com https://*.mk-sense.com https://player.vimeo.com https://*.facebook.com https://*.googleapis.com https://*.google.com https://tpc.googlesyndication.com https://*.doubleclick.net https://accounts.google.com/gsi/;script-src https://accounts.google.com/gsi/client https://www.datadoghq-browser-agent.com https://*.googleapis.com https://appleid.cdn-apple.com *.myheritage.se https://www.myheritage.se 'unsafe-eval' 'nonce-cbe6ab4a45d0c13b387fbdee34d78705' 'strict-dynamic';style-src data: blob: 'unsafe-inline' 'self' https://*.myheritage.com https://*.mhcache.com https://fonts.googleapis.com https://accounts.google.com/gsi/style;connect-src data: 'self' https://*.myheritage.com https://portal.allyable.com https://*.mhcache.com https://adservice.google.com https://*.logs.datadoghq.com https://*.browser-intake-datadoghq.com https://browser-intake-datadoghq.com https://sentry.io https://*.bing.com https://*.facebook.com https://*.doubleclick.net https://*.mk-sense.com https://*.filae.com https://accounts.google.com/gsi/ https://www.google.com/pagead/landing https://*.googleapis.com https://maps.googleapis.com/maps/api/mapsjs/gen_204 https://translate.googleapis.com https://www.google.com/ccm/collect https://cdn.builder.io *.myheritage.se;media-src 'self' https://*.myheritage.com https://*.mhcache.com;frame-ancestors 'self' https://builder.io;img-src * data:;object-src 'none';base-uri 'self' https://*.mhcache.com;report-uri /FP/API/ContentSecurityPolicy/report-violation.php?report_mode=report&canonical_page_id=/company/home/ 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.mercadolibre.com *.mercadolivre.com *.mlstatic.com *.mercadopago.com *.mercadopago.com.ar *.mercadopago.cl *.mercadopago.com.co *.mercadopago.com.br *.mercadopago.com.mx *.mercadopago.com.uy *.mercadopago.com.ve *.mercadopago.com.pe 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net https://www.clarity.ms maps.gstatic.com maps.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.mercadolibre.com *.mercadolivre.com *.mlstatic.com *.mercadopago.com *.mercadopago.com.ar *.mercadopago.cl *.mercadopago.com.co *.mercadopago.com.br *.mercadopago.com.mx *.mercadopago.com.uy *.mercadopago.com.ve *.mercadopago.com.pe data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://www.clarity.ms https://scripts.clarity.ms www.google.com www.gstatic.com maps.googleapis.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.mercadolibre.com *.mercadolivre.com *.mlstatic.com *.mercadopago.com *.mercadopago.com.ar *.mercadopago.cl *.mercadopago.com.co *.mercadopago.com.br *.mercadopago.com.mx *.mercadopago.com.uy *.mercadopago.com.ve *.mercadopago.com.pe 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://www.clarity.ms https://scripts.clarity.ms https://l.clarity.ms maps.googleapis.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.mercadolibre.com *.mercadolivre.com *.mlstatic.com *.mercadopago.com *.mercadopago.com.ar *.mercadopago.cl *.mercadopago.com.co *.mercadopago.com.br *.mercadopago.com.mx *.mercadopago.com.uy *.mercadopago.com.ve *.mercadopago.com.pe 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.fontawesome.com www.searchanise.com *.searchserverapi.com *.yotpo.com *.googleapis.com *.gstatic.com data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net pilot-payflowlink.paypal.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com www.searchanise.com *.searchserverapi.com *.twitter.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.googletagmanager.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com www.searchanise.com *.searchserverapi.com *.twitter.com *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com p.typekit.net www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com validator.swagger.io d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de https://cdn.mundipagg.com https://api.pagar.me *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.twitter.com *.twimg.com www.google.com www.google.ru www.searchanise.com *.searchserverapi.com s3.amazonaws.com *.yotpo.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net www.paypalobjects.com js.braintreegateway.com www.paypal.com unpkg.com commerce.adobedtm.com commerce.adobe.net www.sandbox.paypal.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googletagmanager.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de https://ws-sandbox.bellunopag.com.br https://api.belluno.digital https://i.k-analytix.com https://i.konduto.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com cdn.dnky.co webchat.dotdigital.com *.avada.io *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com searchanise-ef84.kxcdn.com s3.amazonaws.com ajax.aspnetcdn.com www.searchanise.com *.searchserverapi.com *.searchanise.com api.amplitude.com *.twitter.com *.twimg.com *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com cdn.dnky.co webchat.dotdigital.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com unsafe-inline www.searchanise.com *.searchserverapi.com searchanise-ef84.kxcdn.com s3.amazonaws.com *.twitter.com ton.twimg.com *.yotpo.com *.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com *.adobe.io performance.typekit.net commerce.adobedtm.com commerce.adobedc.net api.magento.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com commerce.adobe.io commerce.adobe.net qa-api.magedevteam.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de https://api.mundipagg.com https://api.pagar.me https://viacep.com.br https://www.viacep.com.br *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com https://get.geojs.io *.avada.io *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com api.amplitude.com stats.g.doubleclick.net *.yotpo.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' https: blob:; script-src 'self' 'unsafe-inline' 'unsafe-eval' https:; style-src 'self' 'unsafe-inline' https:; img-src 'self' https: blob:; font-src 'self' https: ; connect-src 'self' https: wss:; object-src 'none'; 1 frame-src 'self' td.doubleclick.net youtube.com *.youtube.com oneconnect.opendigitaleducation.com google.com www.google.com *.doubleclick.net www.googletagmanager.com; report-to /infra/monitoring/csp 1 default-src 'self'; script-src 'report-sample' 'self' 'unsafe-inline' 'unsafe-eval' https://events.framer.com/script https://framer.com https://framerusercontent.com https://www.googletagmanager.com/gtm.js https://www.googletagmanager.com/gtag/js; style-src 'report-sample' 'self' 'unsafe-inline'; object-src 'none'; base-uri 'self'; connect-src 'self' https://events.framer.com https://lottie.host https://region1.google-analytics.com https://website-data-beta.vercel.app https://www.google-analytics.com; font-src 'self' https://cdnjs.cloudflare.com https://framerusercontent.com; frame-src 'self' https://embeds.beehiiv.com https://framer.com; img-src 'self' data: https://framerusercontent.com https://www.googletagmanager.com https://yastatic.net; manifest-src 'self'; media-src 'self' https://framerusercontent.com; worker-src 'none'; frame-ancestors 'self'; report-uri https://68af03dee39705929f59b2eb.endpoint.csper.io?builder=true&v=9; 1 object-src 'none';base-uri 'self';script-src 'nonce-WcUzHmvLTsYFeC5BiCbG4Q' 'strict-dynamic' 'report-sample' 'unsafe-eval' 'unsafe-inline' https: http:;report-uri https://csp.withgoogle.com/csp/gws/other-hp 1 default-src 'self'; img-src 'self' *.taiko-p.jp data: https://www.googletagmanager.com/ https://www.google.co.jp/ https://cdn-au.onetrust.com/; style-src 'self' 'unsafe-inline'; script-src 'self' 'nonce-6986b12b36725' */gtm.js https://www.googletagmanager.com/ https://cdn-au.onetrust.com/; connect-src */ajax/ https://stats.g.doubleclick.net/ https://cdn-au.onetrust.com/ https://www.google-analytics.com https://geolocation.onetrust.com/ https://privacyportal-au.onetrust.com/ https://analytics.google.com/ https://www.google.co.jp/; report-uri csp_report.php; 1 font-src https://cdn.checkout.com *.cdn-apple.com instantcredit.net test.instantcredit.net druni.my.site.com *.salesforce.com *.force.com *.salesforce-sites.com *.lightning.force.com fonts.gstatic.com *.azureedge.net *.doofinder.com *.typekit.net *.googleapis.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com www.paycomet.com api.paycomet.com 'self' 'unsafe-inline'; frame-ancestors *.storyblok.com 'self'; style-src https://cdn.checkout.com *.doofinder.com instantcredit.net test.instantcredit.net druni.my.site.com *.salesforce.com *.force.com *.salesforce-sites.com *.lightning.force.com *.photoslurp.com *.nosto.com *.klaviyo.com *.typekit.net *.storyblok.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src druni.my.site.com *.salesforce.com *.force.com *.salesforce-sites.com *.lightning.force.com *.storyblok.com *.zdassets.com *.doofinder.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; img-src https://www.googletagmanager.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com cdn.doofinder.com https://images.unsplash.com instantcredit.net test.instantcredit.net www.googletagmanager.com www.druni.pt druni.my.site.com *.salesforce.com *.force.com *.salesforce-sites.com *.lightning.force.com https://sandbox.sequracdn.com https://live.sequracdn.com *.facebook.com *.google.com *.google.es widgets.trustedshops.com *.twitter.com t.co *.azureedge.net *.pinterest.com *.doofinder.com *.bing.com *.storyblok.com data: 'self' 'unsafe-inline'; frame-src https://www.googletagmanager.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ https://js.checkout.com *.klarna.com www.paycomet.com api.paycomet.com instantcredit.net test.instantcredit.net www.googletagmanager.com druni.my.site.com *.salesforce.com *.force.com *.salesforce-sites.com *.lightning.force.com https://sandbox.sequracdn.com https://live.sequracdn.com *.hotjar.com *.oct8ne.com *.pinterest.com *.doofinder.com *.empathybroker.com *.empathy.co *.criteo.com 'self' 'unsafe-inline'; script-src https://analytics.tiktok.com/ https://ui.swogo.net/ https://www.googletagmanager.com www.googleadservices.com www.google-analytics.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://*.checkout.com *.klarnacdn.net *.cdn-apple.com cdn.doofinder.com https://maps.googleapis.com www.paycomet.com api.paycomet.com instantcredit.net test.instantcredit.net code.jquery.com www.googletagmanager.com druni.my.site.com druni.my.salesforce-scrt.com *.salesforce.com *.force.com *.salesforce-sites.com *.lightning.force.com https://sandbox.sequracdn.com https://live.sequracdn.com *.googleoptimize.com widgets.trustedshops.com static-eu.oct8ne.com static.zdassets.com *.facebook.net *.tradedoubler.com *.doubleclick.net *.hotjar.com *.ads-twitter.com smct.co *.bsmartdata.com *.retargeted.co *.bing.com *.clarity.ms *.smartsuppcdn.com *.smartsuppchat.com *.smartsupp.com *.connectif.cloud *.klaviyo.com *.photoslurp.com *.pinimg.com *.nosto.com *.doofinder.com *.empathybroker.com *.unpkg.com *.storyblok.com 'self' 'unsafe-inline' 'unsafe-eval'; connect-src https://analytics.tiktok.com/ https://tracking.swogo.net/ https://api.swogo.net/ https://api.trustedshops.com/ https://www.googletagmanager.com www.google-analytics.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://js.checkout.com *.klarnaevt.com *.klarnacdn.net *.klarna.com *.doofinder.com wss://*.doofinder.com https://maps.googleapis.com https://player.vimeo.com instantcredit.net *.instantcredit.net www.googletagmanager.com druni.my.salesforce-scrt.com druni.my.site.com *.salesforce.com *.force.com *.salesforce-sites.com *.lightning.force.com https://sandbox.sequracdn.com https://live.sequracdn.com *.oct8ne.com *.zendesk.com *.zopim.com *.doubleclick.net *.hotjar.com *.hotjar.io *.clarity.ms *.smartsuppcdn.com *.googleapis.com *.gstatic.com *.google-analytics.com *.google.es *.connectif.cloud *.klaviyo.com *.photoslurp.com *.zdassets.com *.pinterest.com *.nosto.com *.empathybroker.com *.empathy.co 'self' 'unsafe-inline'; 1 script-src 'self' *.fallcoweb.it fallcoweb.it *.portalenotarile.it portalenotarile.it 'unsafe-eval' 'nonce-vVxH1M8PIVwhLmxMjPyBQ5bP/Z5kGnMvrfxwWey7M1I=' 'strict-dynamic' 'report-sample'; script-src-attr 'unsafe-inline' 'report-sample'; img-src http: https: data: blob: ; object-src 'self' firma.fallcoweb.it firma-test.fallcoweb.it; base-uri 'self'; frame-ancestors 'self' *.fallcoweb.it fallcoweb.it *.portalenotarile.it portalenotarile.it; report-uri https://o4506184205402112.ingest.us.sentry.io/api/4509672896921600/security/?sentry_key=06528fda593958158ec55deaa5621ec1; 1 default-src 'self' data: 'unsafe-inline' 'unsafe-eval' https://cdn-assets-prod.s3.amazonaws.com https://*.ozmoapp.com https://*.modeaondemand.com https://*.contentsquare.net https://edge.api.flagsmith.com https://*.kaptcha.com https://*.ctfassets.net https://*.freedommobile.ca https://*.appdynamics.com https://*.contentful.com https://*.eum-appdynamics.com https://*.googleapis.com https://tags.tiqcdn.com https://*.lpsnmedia.net https://*.tealiumiq.com https://*.qualtrics.com https://*.gstatic.com https://*.cardinalcommerce.com https://*.googletagmanager.com https://*.googleadservices.com https://*.google.com https://*.google.ca https://*.facebook.net https://*.facebook.com https://*.twitter.com https://*.t.co https://*.demdex.net https://*.doubleclick.net https://*.everesttech.net https://*.adswizz.com https://*.exelator.com https://*.tapad.com https://*.spatialbuzz.com https://*.spatialbuzz.net https://*.niceincontact.com https://d31hajf7vfnsd2.cloudfront.net; frame-src 'self' https://quebecor.satmetrix.com https://www.googletagmanager.com https://cxone.niceincontact.com https://web-modules-de-ca1.niceincontact.com https://asset.gomoxie.solutions https://dnyepvvjamjdg.cloudfront.net https://www.youtube.com https://*.demdex.net https://*.doubleclick.net https://*.facebook.com https://*.google.com https://*.freedommobile.ca https://*.lpsnmedia.net https://*.kaptcha.com https://*.spatialbuzz.com https://*.spatialbuzz.net; worker-src 'self' blob:; frame-ancestors 'self' https://*.freedommobile.ca; 1 default-src https://*.s4c.cymru https://s4c.cymru; img-src 'self' data: https://*.s4c.cymru https://s4c.cymru https://cdn-cookieyes.com https://i.ytimg.com https://*.google.com/cse https://clients1.google.com https://*.gstatic.com; font-src 'self' data: https://*.s4c.cymru https://s4c.cymru https://fonts.gstatic.com https://cloud.typography.com; form-action 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://cdn-cookieyes.com https://*.googletagmanager.com https://*.google.com/cse https://*.hotjar.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://cloud.typography.com https://*.s4c.cymru https://s4c.cymru https://*.google.com/cse; connect-src https://*.s4c.cymru https://s4c.cymru https://cdn-cookieyes.com https://log.cookieyes.com https://*.google-analytics.com; object-src 'none'; frame-ancestors 'none'; frame-src 'self' https:; report-uri https://csp.s4c.cymru/report; report-to csp-endpoint; 1 default-src 'self' *.irsn.fr *.asnr.fr; script-src 'self' *.irsn.fr *.asnr.fr cdn.ckeditor.com embed.api.video static.doubleclick.net unpkg.com vod.api.video www.google.com www.gstatic.com www.youtube.com www.youtube-nocookie.com; object-src 'none'; style-src 'self' 'unsafe-inline' *.irsn.fr *.asnr.fr fonts.googleapis.com unpkg.com www.youtube.com www.youtube-nocookie.com; img-src 'self' data: *.irsn.fr *.asnr.fr i.ytimg.com yt3.ggpht.com; media-src 'self' *.irsn.fr *.asnr.fr; frame-src 'self' *.irsn.fr *.asnr.fr embed.api.video www.youtube.com www.youtube-nocookie.com; frame-ancestors 'self' *.irsn.fr *.asnr.fr; child-src 'self' *.irsn.fr *.asnr.fr embed.api.video www.youtube.com www.youtube-nocookie.com; font-src 'self' data: *.irsn.fr *.asnr.fr embed.api.video fonts.gstatic.com themes.googleusercontent.com; connect-src 'self' *.irsn.fr *.asnr.fr collector.api.video googleads.g.doubleclick.net jnn-pa.googleapis.com vod.api.video www.youtube.com www.youtube-nocookie.com; report-uri /sa-report-csp-violation; upgrade-insecure-requests 1 default-src 'self';media-src 'self' blob: data: https:// *.onnetwork.tv *.tvp.pl;worker-src 'self' blob: data: *.sadeczanin.info;script-src 'self' 'unsafe-inline' 'unsafe-eval' *.googleapis.com; script-src-elem 'self' 'unsafe-inline' 'unsafe-eval' *.googletagmanager.com https://weatherwidget.io *.weatherwidget.io *.google.com *.g.doubleclick.net *.instagram.com *.googlesyndication.com *.twitter.com *.openxcdn.net *.4dex.io *.criteo.net tags.crwdcntrl.net *.creativecdn.com cdn.id5-sync.com cdn.prod.uidapi.com *.onnetwork.tv *.googleapis.com *.jsdelivr.net *.facebook.net *.2mdn.net *.google-analytics.com *.optad360.io *.script.ac *.ampproject.org; img-src 'self' https: data: blob: http://api.sadeczanin.info; style-src 'self' 'unsafe-inline' www.fonts.googleapis.com *.googleapis.com *.onnetwork.tv *.google.com; font-src 'self' data: *.fonts.googleapis.com *.onnetwork.tv *.gstatic.com; frame-src 'self' https://weatherwidget.io *.weatherwidget.io https://instagram.com *.instagram.com https://twitframe.com *.twitframe.com *.twitter.com *.facebook.com *.googlesyndication.com *.google.com *.g.doubleclick.net *.googleadservices.com *.youtube.com *.youtu.be https://youtube.com https://youtu.be https://zrzutka.pl *.zrzutka.pl *.criteo.com *.onnetwork.tv *.googleapis.com *.aztv.pl *.casalemedia.com *.openx.net *.quantumdex.io *.adxbid.info *.openx.net *.quantumdex.io https://adxbid.info *.adxbid.info https://onetag-sys.com *.onetag-sys.com *.openx.net *.smartadserver.com *.wp.pl *.rubiconproject.com *.pubmatic.com *.a-mo.net *.indexww.com *.adnxs.com *.3lift.com https://hdsystem.pl https://www.hdsystem.pl *.richaudience.com; connect-src 'self' *.google-analytics.com *.sadeczanin.info pagead2.googlesyndication.com *.google.com *.g.doubleclick.net *.gstatic.com bcp.crwdcntrl.net id5-sync.com *.criteo.com *.criteo.net *.onnetwork.tv *.jsdelivr.net *.openx.net *.adnxs.com *.quantumdex.io *.wp.pl *.rubiconproject.com https://dnacdn.net *.dnacdn.net *.onetag-sys.com https://onetag-sys.com *.a-mo.net *.casalemedia.com *.pubmatic.com *.smartadserver.com *.adform.net *.creativecdn.com *.vidoomy.com *.4dex.io *.adxpremium.services *.adsrvr.org *.richaudience.com; 1 default-src 'self' 'unsafe-inline'; script-src https: 'self' 'unsafe-inline' 'unsafe-eval'; style-src https: 'self' 'unsafe-inline'; 1 object-src 'none'; script-src 'self' 'unsafe-inline' 'unsafe-eval' adform.net *.adform.net betano.com *.betano.com betano.dk *.betano.dk betgenius.com *.betgenius.com cookielaw.org *.cookielaw.org creativecdn.com *.creativecdn.com facebook.net *.facebook.net fullstory.com *.fullstory.com gmlinteractive.com *.gmlinteractive.com googletagmanager.com *.googletagmanager.com optimove.net *.optimove.net sportradar.com *.sportradar.com cloudflareinsights.com *.cloudflareinsights.com app.delivery *.app.delivery lgrckt-in.com *.lgrckt-in.com tostarsbuilding.com *.tostarsbuilding.com; report-uri https://csp-reporting.cloudflare.com/cdn-cgi/script_monitor/report?m=KeKLn457g1gLXAaSdcD9USztP_OSGcV76LdIcMDxcRc-1770430335-1.0.1.1-JrJnd4mCa6NY6FBpu7dpFxXBKQ7L45PKHlHxA84omgEo1RRzZ13oXRkzXiU.WCGATmt0CZpFRQSaS2ZeR1_OlRScj7VVgG1YpyxJ3uW6a.Ur93Wl7HHcDfqH25Orbzyobjy1_NXVS90ViK7hF9Wm3x4DoOlsJw8S3rMZcjLocnprpfCcHWNK1WWUhynr0SH7xBwDbk4gL6ODKzbGx6lpMw; report-to cf-bjoybhqrkkscvsrd 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com static.klaviyo.com *.klevu.com *.ksearchnet.com *.fontawesome.com https://fonts.bunny.net *.cloudflare.com *.twitter.com *.twimg.com *.trustedshops.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com webpay3g.transbank.cl webpay3gint.transbank.cl *.facebook.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.twitter.com 'self' 'unsafe-inline'; frame-ancestors *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com *.weltpixel.com *.googletagmanager.com *.doubleclick.net www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.twitter.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net data: *.googleapis.com *.facebook.com *.reddit.com *.google-analytics.com *.googletagmanager.com *.doubleclick.net *.google.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com https://firebasestorage.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.cloudflare.com *.klarna.com *.googleadservices.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.cloudfront.net *.google.com.mx *.clarity.ms *.bing.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.googleapis.com *.gstatic.com *.googletagmanager.com *.googleadservices.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com unpkg.com *.doubleclick.net www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com *.avada.io js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.cloudflare.com *.twitter.com *.google-analytics.com *.twimg.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com dbschile.api.useinsider.com *.queue-it.net *.clarity.ms *.getblue.io *.gorgias.chat *.mouseflow.com www.googleoptimize.com https://js.klevu.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.tagmanager.google.com *.googletagmanager.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com https://static.klaviyo.com *.klevu.com *.ksearchnet.com *.fontawesome.com https://fonts.bunny.net assets.braintreegateway.com *.cloudflare.com *.googleapis.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu https://statsjs.klevu.com https://js.klevu.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.googleapis.com *.yango.com *.clarity.ms *.gorgias.chat *.google-analytics.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.doubleclick.net *.run.app www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.cloudflare.com *.twitter.com *.twimg.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri http://csp-reporting-service.com/my-project/endpoint; report-to report-endpoint; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com fonts.googleapis.com *.fontawesome.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com *.mercadolibre.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.mlstatic.com *.mercadopago.com *.mercadolibre.com *.mercadolivre.com.br *.mercadolibre.com.mx *.mercadolibre.com.ar *.mercadolivre.com maps.googleapis.com maps.gstatic.com 'self' data: gpsfarma.com www.afip.gob.ar www.google.com.ar https://firebasestorage.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.mlstatic.com *.mercadopago.com maps.googleapis.com *.avada.io js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com fonts.gstatic.com *.fontawesome.com https://fonts.bunny.net assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.mercadopago.com *.mercadolibre.com maps.googleapis.com stats.g.doubleclick.net https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com data: likeme.com.co *.likeme.com.co maxcdn.bootstrapcdn.com s3.amazonaws.com *.fontawesome.com *.gstatic.com 'self' data: https://maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.mercadopago.com *.mlstatic.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://www.facebook.com 'self' 'unsafe-inline'; frame-ancestors *.mercadopago.com *.mlstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com https://www.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ cdn.dnky.co amc.demdex.net www.google.com www.facebook.com youtube.com gum.criteo.com likeme.com.co *.likeme.com.co *.criteo.com fledge.criteo.com app.zinrelo.com www.youtube.com *.addi.com td.doubleclick.net *.mercadolibre.com *.blob.core.windows.net/* *.mercadopago.com *.mlstatic.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com https://ibang-webviews.ibang.ai https://app.zinrelo.com https://vars.hotjar.com https://static.criteo.net http://static.criteo.net https://td.doubleclick.net https://fledge.us.criteo.com https://fledge.eu.criteo.com 'self' 'unsafe-inline'; img-src https://assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io maps.gstatic.com maps.googleapis.com accounts.google.com www.facebook.com *.likeme.com.co *.cloudfront.net www.google.cl www.google.com.uy www.google.com.ar www.google.com.co dis.criteo.com criteo-sync.teads.tv criteo-partners.tremorhub.com d1qbqkkh49kht1.cloudfront.net zinrelo-notification-images.s3.amazonaws.com *.addi.com *.clarity.ms *.mlstatic.com *.mercadopago.com *.mercadolibre.com *.mercadolivre.com.br *.mercadolibre.com.mx *.mercadolibre.com.ar *.mercadolivre.com connect.facebook.net graph.facebook.com business.facebook.com 'self' data: https://ibangblob.blob.core.windows.net www.mercadolivre.com http://imgmp.mlstatic.com https://cdn.stickyadstv.com https://www.google.com.ar https://www.mercadopago.com.co http://img.mlstatic.com https://pixel.rubiconproject.com https://likeme.com.co https://*.g.doubleclick.net https://*.smartadserver.com https://*.cloudfront.net https://sync.outbrain.com https://contextual.media.net https://ad.360yield.com https://r.casalemedia.com https://cm.adform.net https://x.bidswitch.net https://match.sharethrough.com https://ads.stickyadstv.com https://exchange.mediavine.com https://sync-t1.taboola.com https://sync-criteo.ads.yieldmo.com https://c.bing.com https://e1.emxdgt.com https://s.ad.smaato.net https://i.liadm.com https://ads.yahoo.com https://ups.analytics.yahoo.com https://secure.adnxs.com https://ib.adnxs.com https://sp.analytics.yahoo.com https://dis.criteo.com https://i6.liadm.com https://simage2.pubmatic.com https://eb2.3lift.com https://jadserve.postrelease.com https://www.google.com.co https://criteo-sync.teads.tv https://tg.socdm.com https://visitor.omnitagjs.com https://gum.criteo.com https://matching.ivitrack.com https://trends.revcontent.com https://ade.clmbtech.com https://idsync.rlcdn.com https://tags.bluekai.com https://s3.amazonaws.com https://criteo-partners.tremorhub.com https://hb.yahoo.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ cdn.dnky.co r1-t.trackedlink.net www.gstatic.com js-agent.newrelic.com bam.nr-data.net maps.googleapis.com connect.facebook.net player.vimeo.com dynamic.c static.criteo.net dynamic.criteo.com sslwidget.criteo.com fast.amc.demdex.net widget.eu.criteo.com likeme.com.co *.likeme.com.co *.cloudfront.net *.zinrelo.com cdnjs.cloudflare.com www.googleoptimize.com www.clarity.ms analytics.tiktok.com *.embluemail.com s3.amazonaws.com cdn.addi.com www.youtube.com static.doubleclick.net www.google.com ajax.googleapis.com connect.nosto.com *.taboola.com *.hotjar.com *.mlstatic.com *.mercadopago.com *.google.com https://maps.googleapis.com *.blob.core.windows.net/* www.facebook.com graph.facebook.com business.facebook.com *.gstatic.com https://www.google.com https://cdn.zinrelo.com http://cdn.zinrelo.com https://www.wheelofpopups.com https://*.cloudfront.net https://app.zinrelo.com https://www.googleoptimize.com https://cdn.embluemail.com https://widgets-static.embluemail.com https://script.hotjar.com https://static.hotjar.com https://cdnjs.cloudflare.com https://*.g.doubleclick.net https://*.mailmunch.com https://widgets-api.embluemail.com https://analytics.tiktok.com https://www.clarity.ms 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com cdn.dnky.co likeme.com.co *.likeme.com.co use.fontawesome.com *.cloudfront.net maxcdn.bootstrapcdn.com www.youtube.com *.fontawesome.com *.mercadopago.com *.mlstatic.com *.googleapis.com *.gstatic.com https://trazosvisuales.com https://trazosvisuales.info https://maxcdn.bootstrapcdn.com https://cdnjs.cloudflare.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.comapi.com bam.nr-data.net likeme.com.co *.likeme.com.co maxcdn.bootstrapcdn.com gum.criteo.com s.clarity.ms app.zinrelo.com www.youtube.com channels-public-api.addi.com www.google.cl www.google.com.uy www.google.com.ar www.google.com.co *.google.com *.clarity.ms mug.criteo.com connect.nosto.com googleads.g.doubleclick.net jnn-pa.googleapis.com *.mercadopago.com *.mercadolibre.com *.sistecredito.com/* *.blob.core.windows.net/* *.mlstatic.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.google-analytics.com https://www.google-analytics.com https://*.g.doubleclick.net https://trazosvisuales.info https://maxcdn.bootstrapcdn.com https://trazosvisuales.com https://measurement-api.criteo.com/ https://analytics.tiktok.com/ https://v.clarity.ms https://pagead2.googlesyndication.com/ https://cdnjs.cloudflare.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src bam.nr-data.net s.clarity.ms *.google.com www.google-analytics.com analytics.tiktok.com likeme.com.co *.likeme.com.co *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' blob: data: *.massport.com *.prod.acquia-sites.com ; script-src 'self' 'unsafe-inline' *.google.com *.googleapis.com *.newrelic.com bam.nr-data.net *.youtube.com *.youtube-nocookie.com *.googletagmanager.com *.google-analytics.com *.gstatic.com *.pointr.cloud *.bing.com *.pinimg.com *.facebook.net *.teads.tv *.aocadp.com; object-src 'self' *.nr-data.net; style-src 'self' 'unsafe-inline' fonts.googleapis.com www.gstatic.com *.massport.com *.prod.acquia-sites.com; img-src 'self' 'unsafe-inline' *.gstatic.com *.massport.com data: *.prod.acquia-sites.com bos.resources.aocdms.com *.googleapis.com *.google.com *.bing.com *.teads.tv *.pinterest.com *.facebook.com *.facebook.net; media-src 'self' 'unsafe-inline' 'unsafe-eval' *.massport.com *.prod.acquia-sites.com *.youtube-nocookie.com; frame-src 'self' *.google.com *.atlassian.net *.prod.acquia-sites.com *.nr-data.net *.youtube.com *.youtube-nocookie.com *.items.aero *.pinterest.com; child-src 'self' *.massport.com *.prod.acquia-sites.com ; font-src 'self' themes.googleusercontent.com fonts.gstatic.com data: *.massport.com *.prod.acquia-sites.com; connect-src 'self' *.google-analytics.com *.googletagmanager.com analytics.google.com *.googleapis.com bam.nr-data.net mbta-proxy.bos.aocadp.com gtfs.bos.aocadp.com *.prod.acquia-sites.com *.nr-data.net *.pointr.cloud *.bing.com *.teads.tv *.pinterest.com; report-uri https://browser-intake-ddog-gov.com/api/v2/logs?dd-api-key=pubae3d9e4f547e5d8888b052206ca0205e&dd-evp-origin=content-security-policy&ddsource=csp-report; upgrade-insecure-requests 1 script-src 'unsafe-inline' 'self' https://payments.salesforce.com/ https://stats.g.doubleclick.net https://checkoutshopper-test.adyen.com/ https://pal-test.adyen.com https://cdn.cookielaw.org https://acquia--c.vf.force.com/resource/1697461438000/AcquiaDAMFavicon https://checkoutshopper-live.adyen.com/ https://d.la1-c2-ia4.salesforceliveagent.com/chat/rest/Visitor/Availability.jsonp https://d.la3-core1.sfdc-yfeipo.salesforceliveagent.com/chat/rest/Visitor/Settings.jsonp https://cdn.content.aws-prod1-useast1.aws.sfdc.cl/ https://d.la13-core1.sfdc-yfeipo.salesforceliveagent.com/chat/rest/Visitor/Availability.jsonp https://d.la1-core1.sfdc-yfeipo.salesforceliveagent.com/chat/rest/Visitor/Settings.jsonp https://d.la3-core1.sfdc-yfeipo.salesforceliveagent.com/chat/rest/Visitor/Availability.jsonp https://pay.google.com https://d.la1-c2-ia4.salesforceliveagent.com/chat/rest/EmbeddedService/EmbeddedServiceConfig.jsonp https://d.la3-core1.sfdc-yfeipo.salesforceliveagent.com/chat/rest/EmbeddedService/EmbeddedServiceConfig.jsonp https://tagmanager.google.com https://www.gstatic.com/recaptcha/ https://uip.canary.lwc.dev https://d.la13-core1.sfdc-yfeipo.salesforceliveagent.com/chat/rest/Visitor/Settings.jsonp https://cdn.content.aws-dev2-uswest2.aws.sfdc.cl/ blob: https://www.googletagmanager.com/gtag/js https://www.google.com/recaptcha/ https://js.stripe.com/ https://d.la13-core1.sfdc-yfeipo.salesforceliveagent.com/chat/rest/EmbeddedService/EmbeddedServiceConfig.jsonp https://www.googletagmanager.com import: https://acquia.my.site.com/ESWMessagingServiceDepl1737557964121/assets/js/bootstrap.min.js https://www.google-analytics.com *.salesforce.com https://www.paypal.com/sdk/js 'report-sample' https://service.force.com/embeddedservice/ 'unsafe-eval' https://d.la1-c2-ia4.salesforceliveagent.com/chat/rest/Visitor/Settings.jsonp; report-to sfdc-csp-ep; report-uri https://acquia.lightning.force.com/_/ContentDomainCSPNoAuth?tenantId=00D6g000003vCaM&networkId=0DM6g000000eGOT&type=communities 1 base-uri 'self'; default-src 'self' https: wss: ws:; script-src 'self' 'unsafe-eval' https://cdn.jsdelivr.net/npm/cross-storage@1.0.0/dist/hub.min.js https://og-frontend.stg-east.frontend.public.atl-paas.net/assets/ https://*.services.atlassian.com https://code.jquery.com/jquery-3.6.0.min.js https://remote-app-switcher.stg-east.frontend.public.atl-paas.net https://translate.googleapis.com/_/translate_http/_/js/ https://ajax.googleapis.com/ajax/libs/jqueryui/1.13.2/jquery-ui.min.js https://ajax.googleapis.com/ajax/libs/jquery/3.6.0/jquery.min.js https://js.intercomcdn.com https://widget.intercom.io/widget/ https://www.gstatic.com/recaptcha/releases/ https://www.google.com/recaptcha/ https://js.stripe.com https://meet.jit.si https://bam.nr-data.net 'sha256-u8Qc9T1x0D5Z/CHTQ498yO/+i2ySExBMOwf4RL2t4WI=' 'sha256-FV4wGfcn2NrqSJwtGQUWZ2Ie5XrIVKqtnc6g2gmRRco=' 'sha256-6wRdeNJzEHNIsDAMAdKbdVLWIqu8b6+Bs+xVNZqplQw=' 'sha256-N6H1UNp6u4dhUx+FZUQMMcXz17KIEWQw+ZVCPp4d3Zo=' 'sha256-qyYeb40S0YW7zrzwvSX5SEThkjXxwfWSwDp+FlCY0ic=' 'sha256-XHhqFY/vlAF49XCJL4Eg+ttSAnGAobln30utBWOcPhU=' 'sha256-L8u6aiCFdh23FnTLOjO9T7p6zkSJPTaOzZoZUz9OnVQ=' 'sha256-ZMCyrJrkz95Pmv4GzcpT7uihWvUib4x2CFIKGfMsuYU=' 'sha256-ffGUIypjdVM8v7ybOzYmI52fKI8S9IVsUI1OqyrUw8Q=' 'sha256-4qVpzn2Bx0qK9KtIsF/n3VVomtjXD/qPqKpKFNRrMWY=' 'sha256-eETIIu3VZ7EA7inGoTk/IDe2GZACdmowaBuJOhm6Bik=' 'nonce-435497d391b14138ba1df895501c1c1c'; style-src 'self' 'unsafe-inline' https://*.opsgeni.us https://og-frontend.stg-east.frontend.public.atl-paas.net/assets/ https://fonts.googleapis.com/css2 data:; img-src 'self' data: https:; font-src 'self' https://og-frontend.stg-east.frontend.public.atl-paas.net/assets/ https://fonts.intercomcdn.com https://fonts.gstatic.com data:; frame-ancestors 'self' https://*.app.opsgeni.us https://*.opsgeni.us https://*.atlassian.net chrome-extension://dmjofbngkpnmmiccjhikngiodkbofnpc chrome-extension://deejhllflojhohbeechaicbcofamcbkp; form-action 'self'; report-uri https://web-security-reports.services.atlassian.com/csp-report/og-frontend; report-to csp-default-endpoint; connect-src 'self' https: wss: ws:; object-src 'none'; frame-src 'self' https://*.opsgeni.us https://intercom-sheets.com https://*.atlassian.com https://*.opsgenie.com https://js.stripe.com https://reporting.opsgenie.com https://www.google.com 1 script-src 'self' 'unsafe-eval' assets.sitescdn.net connect.cooper.edu https://cdnjs.cloudflare.com https://www.skynettechnologies.com; script-src-attr 'self' 'unsafe-inline'; script-src-elem 'self' 'unsafe-inline' answers-embed.cooper.edu.pagescdn.com buttons-config.sharethis.com cdn.unibuddy.co chimpstatic.com mx.technolutions.net traffic-drivers.unibuddy.co www.google-analytics.com www.googletagmanager.com www.youvisit.com www.youtube.com cooper.us10.list-manage.com s3.amazonaws.com t.sharethis.com js-agent.newrelic.com www.skynettechnologies.com assets.sitescdn.net connect.cooper.edu https://cdnjs.cloudflare.com https://www.skynettechnologies.com; style-src 'self' fonts.googleapis.com https://assets.sitescdn.net https://cdnjs.cloudflare.com; style-src-attr 'self' 'unsafe-inline'; style-src-elem 'self' 'unsafe-inline' cdn-images.mailchimp.com fonts.googleapis.com https://assets.sitescdn.net https://cdnjs.cloudflare.com; frame-ancestors 'self' cooper.edu; report-uri https://cooper.report-uri.com/r/d/csp/wizard 1 default-src 'self' 846-hel-222.mktoresp.com 173-dti-322.mktoresp.com 059-alg-683.mktoresp.com js.zi-scripts.com static.addtoany.com stats.g.doubleclick.net tracking-api.g2.com play.google.com www.google.com; connect-src 'self' 846-hel-222.mktoweb.com analytics.google.com c.6sc.co ipv6.6sc.co cdn.cookielaw.org distillery.wistia.com fast.wistia.com pipedream.wistia.com geolocation.onetrust.com epsilon.6sense.com secure.adnxs.com ws.zoominfo.com px.ads.linkedin.com www.google.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net jnn-pa.googleapis.com api.simplecast.com cdn.simplecast.com givebutter.com umsafoundation.org www.youtube.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com pagead2.googlesyndication.com google.com stats.g.doubleclick.net js.zi-scripts.com privacyportal-eu.onetrust.com 846-hel-222.mktoresp.com app.qualified.com tracking-api.g2.com tr.capterra.com 173-dti-322.mktoresp.com embed-cloudfront.wistia.com *.clarity.ms 173-dti-322.mktoutil.com www.google.com.co; font-src 'self' www.perforce.com www.blazemeter.com www.gliffy.com www.jrebel.com www.openlogic.com www.zend.com www.puppet.com www.perfecto.io fonts.gstatic.com cdn.simplecast.com data: fast.wistia.com use.typekit.net www.gartner.com; frame-src 'self' 846-hel-222.mktoweb.com 173-dti-322.mktoresp.com 059-alg-683.mktoresp.com resources.perforce.com static.addtoany.com www.googletagmanager.com www.perforce.com www.blazemeter.com www.gliffy.com www.jrebel.com www.openlogic.com www.zend.com www.puppet.com www.perfecto.io fast.wistia.net player.simplecast.com www.youtube.com umsafoundation.org live-totalview.pantheonsite.io live-imsl.pantheonsite.io www.google.com app.qualified.com fast.wistia.com player.vimeo.com player.captivate.fm 605957.extforms.netsuite.com www.gartner.com; img-src 'self' data: b.6sc.co c.bing.com bat.bing.com *.clarity.ms cdn.cookielaw.org cdn2.hubspot.net embed-ssl.wistia.com f.hubspotusercontent00.net pic.trendemon.com px.ads.linkedin.com trackingapi.trendemon.com analytics.twitter.com cdn.bizible.com cdn.bizibly.com googleads.g.doubleclick.net t.co track.hubspot.com www.facebook.com www.gliffy.com www.google.com www.linkedin.com www.perforce.com www.blazemeter.com www.jrebel.com www.openlogic.com www.zend.com www.puppet.com www.perfecto.io umsafoundation.org live-mondrian.pantheonsite.io i.ytimg.com image.simplecastcdn.com yt3.ggpht.com fast.wistia.net googletagmanager.com ssl.gstatic.com www.gstatic.com *.google-analytics.com *.googletagmanager.com www.googletagmanager.com pagead2.googlesyndication.com www.googleadservices.com google.com www.google.com.tw www.google.mn fast.wistia.com www.google.co.uk www.google.com.br www.google.no fonts.gstatic.com www.google.co.in www.google.com.ec www.google.pl; manifest-src 'self' 846-hel-222.mktoresp.com 173-dti-322.mktoresp.com 059-alg-683.mktoresp.com js.zi-scripts.com static.addtoany.com stats.g.doubleclick.net tracking-api.g2.com play.google.com www.google.com www.perforce.com www.blazemeter.com www.gliffy.com www.jrebel.com www.openlogic.com www.zend.com www.puppet.com www.perfecto.io; media-src 'self' blob: app.qualified.com fast.wistia.com embed-ssl.wistia.com data: embed-fastly.wistia.com embed-cloudfront.wistia.com; object-src 'self'; script-src 'self' 'report-sample' 'unsafe-eval' 846-hel-222.mktoweb.com assets.trendemon.com browser.sentry-cdn.com cdn.cookielaw.org cdn.jsdelivr.net cdnjs.cloudflare.com fast.wistia.com fast.wistia.net googleads.g.doubleclick.net j.6sc.co js.zi-scripts.com munchkin.marketo.net resources.perforce.com *.clarity.ms snap.licdn.com static.addtoany.com static.cloudflareinsights.com trackingapi.trendemon.com tracking.g2crowd.com ct.capterra.com cdn.bizible.com cdn.getmoreproof.com js.hs-analytics.net js.hs-banner.com js.hs-scripts.com connect.facebook.net static.ads-twitter.com p-js.s3.amazonaws.com player.simplecast.com widgets.givebutter.com www.google.com www.googletagmanager.com www.perforce.com www.blazemeter.com www.gliffy.com www.jrebel.com www.openlogic.com www.zend.com www.puppet.com www.perfecto.io umsafoundation.org www.youtube.com googletagmanager.com tagmanager.google.com *.googletagmanager.com www.googleadservices.com pagead2.googlesyndication.com https://cdn.ckeditor.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://code.highcharts.com https://fast.wistia.com https://resources.perforce.com https://resources.roguewave.com https://static.addtoany.com https://unpkg.com info.perforce.com 'nonce-Gv4wehmpnJw416i-_c5_VA'; script-src-elem 'self' feedback.perforce.com js.qualified.com cdn.cookielaw.org googleads.g.doubleclick.net ct.capterra.com gist.github.com j.6sc.co munchkin.marketo.net trackingapi.trendemon.com scripts.clarity.ms js.zi-scripts.com cdnjs.cloudflare.com https://cdn.ckeditor.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://code.highcharts.com https://fast.wistia.com https://resources.perforce.com https://resources.roguewave.com https://static.addtoany.com https://unpkg.com info.perforce.com resources.perforce.com 'nonce-Gv4wehmpnJw416i-_c5_VA'; style-src 'self' 'report-sample' 'unsafe-inline' 846-hel-222.mktoweb.com cdnjs.cloudflare.com resources.perforce.com www.perforce.com www.blazemeter.com www.gliffy.com www.jrebel.com www.openlogic.com www.zend.com www.puppet.com www.perfecto.io fonts.googleapis.com www.youtube.com googletagmanager.com tagmanager.google.com app-ab48.marketo.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://code.highcharts.com https://unpkg.com; style-src-elem 'self' feedback.perforce.com resources.perforce.com www.googletagmanager.com cdnjs.cloudflare.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://code.highcharts.com https://unpkg.com; webrtc 'block'; worker-src 'self' blob:; base-uri 'self'; form-action 'self' https://feedback.perforce.com; frame-ancestors 'self' www.perforce.com 1 default-src 'none'; report-uri /next-external/log/csp/violations; report-to csp-violations; connect-src 'self' wss://www.nordnet.se https://www.googletagmanager.com https://analytics.nordnet.se https://cdn.prod.nntech.io https://files.nordnet.se https://api.prod.nntech.io https://api.test.nntech.io https://experimentation.public.prod.nntech.io https://www.google.com https://storage.googleapis.com https://www.recaptcha.net https://nordnettest.boost.ai; font-src 'self' https://cdn.prod.nntech.io https://files.nordnet.se; frame-src 'self' https://analytics.nordnet.se https://10961666.fls.doubleclick.net https://www.youtube.com https://www.youtube-nocookie.com https://player.vimeo.com https://w.soundcloud.com https://embed.acast.com https://link.tink.com https://www.tv2.no https://checkout.trustly.com https://www.recaptcha.net https://www.google.com https://t.email.nordnet.se https://dashboard.fundrella.com; img-src 'self' https://www.googletagmanager.com https://analytics.nordnet.se https://cdn.prod.nntech.io https://files.nordnet.se data: blob: https://cdn.tink.se https://images.ctfassets.net https://i.vimeocdn.com https://img.youtube.com https://www.recaptcha.net https://blogg.nordnet.se https://boost-files-general-eu-west-1-test.s3-eu-west-1.amazonaws.com/files/NORDNETTEST/d929a8d5-9d88-426e-b412-3ccf7923fac3; manifest-src 'self'; media-src https://cdn.prod.nntech.io https://files.nordnet.se https://videos.ctfassets.net; object-src 'self'; script-src 'self' 'nonce-ca90c475-ce26-438d-8bac-47481f57298b' https://analytics.nordnet.se https://cdn.prod.nntech.io https://files.nordnet.se https://www.recaptcha.net https://nordnettest.boost.ai https://www.google.com; script-src-attr 'none'; style-src 'unsafe-inline' 'self' https://cdn.prod.nntech.io https://files.nordnet.se; worker-src 'none'; base-uri 'none'; form-action 'self' https://pvu.nets.no https://pvu.avtalegiro.no https://online.alandsbanken.fi https://verkkopankki.danskebank.fi https://verkkomaksu.handelsbanken.fi https://epmt.nordea.fi https://identify.nordea.com https://verkkomaksu.poppankki.fi https://verkkomaksu.saastopankki.fi https://online.s-pankki.fi https://auth.aktia.fi https://kirjaudu.aktia.fi https://ebank.aktia.fi; frame-ancestors 'self' https://app.contentful.com https://app.sigmastocks.com; 1 font-src fonts.gstatic.com use.typekit.net *.gstatic.com 'self' data: use.fontawesome.com *.antartica.cl data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com webpay3g.transbank.cl webpay3gint.transbank.cl *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * tracking.bciplus.cl www.google.com wchat.freshchat.com *.antartica.cl www.mercadopago.cl www.mercadolibre.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net *.trackedlink.net *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com 'self' data: www.facebook.com www.google.cl *.antartica.cl www.gstatic.com www.mercadolibre.com www.mercadopago.cl *.google.com.ar antartica.cl data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com amcglobal.sc.omtrdc.net commerce.adobe.net use.typekit.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-ds.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com *.fw-cdn.com/ *.freshchat.com/ *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.google.com *.gstatic.com *.mercadopago.cl *.googletagmanager.com *.facebook.net *.hotjar.com unpkg.com tracking.krip.cl r2-t.trackedlink.net www.clarity.ms static.trackedweb.net js-agent.newrelic.com wchat.freshchat.com static.zdassets.com *.antartica.cl sdk.mercadopago.com http2.mlstatic.com https://fw-cdn.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com https://*.freshchat.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com unsafe-inline assets.braintreegateway.com *.googleapis.com *.gstatic.com use.fontawesome.com *.antartica.cl www.mercadopago.cl www.gstatic.com *.googletagmanager.com *.cookielaw.org 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io commerce.adobe.net qa-api.magedevteam.com *.sentry.io *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com t.elasticsuite.io *.google-analytics.com api.bciplus.cl ekr.zdassets.com libreriaantartica.zendesk.com wchat.freshchat.com bam.nr-data.net *.antartica.cl api.mercadopago.com www.mercadolibre.com events.mercadopago.com *.hotjar.com *.hotjar.io *.clarity.ms *.doubleclick.net *.cookielaw.org 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com www.google.com bam.nr-data.net r2.trackedweb.net commerce.adobedc.net *.antartica.cl 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 base-uri 'self'; connect-src 'self' wss://localhost:9500 https://matomo-web.chuv.ch https://prompts.maze.co https://*.infomaniak.cloud https://*.axept.io https://*.facil-iti.app; default-src 'self'; font-src 'self' data: https://localhost:9500 https://fonts.gstatic.com; frame-ancestors 'self' https://*.chuv.ch; frame-src 'self' https://www.medigo.ch https://pro.medigo.ch https://player.vimeo.com https://www.youtube-nocookie.com https://challenges.cloudflare.com https://*.facil-iti.app; img-src 'self' data: https://*.infomaniak.cloud https://fonts.gstatic.com https://i.ytimg.com https://i.vimeocdn.com https://favicons.axept.io https://axeptio.imgix.net; manifest-src 'self'; media-src 'self'; object-src 'none'; script-src 'self' inline 'unsafe-eval' https://challenges.cloudflare.com https://cdn.facil-iti.app https://matomo-web.chuv.ch https://snippet.maze.co https://challenges.cloudflare.com https://*.axept.io; script-src-attr 'self' 'unsafe-inline' inline; script-src-elem 'self' 'unsafe-inline' 'unsafe-eval' https://localhost:9500 https://cdn.facil-iti.app https://matomo-web.chuv.ch https://snippet.maze.co https://challenges.cloudflare.com https://*.axept.io https://www.youtube.com https://connect.facebook.net; style-src 'self' 'unsafe-inline'; style-src-attr 'self' 'unsafe-inline' inline; style-src-elem 'self' 'unsafe-inline' blob: https://fonts.googleapis.com; worker-src 'none'; report-uri /CspReportLogger.php 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.hotjar.com *.mavenoid.com *.klevu.com *.ksearchnet.com *.narvar.com *.narvar.qa *.onetrust.com www.worx.com worx.com *.signifyd.com *.onlineada.workers.dev maxaccess-api.onlineada.workers.dev *.maxaccess.io *.fontawesome.com https://fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de api.bazaarvoice.com stg.api.bazaarvoice.com www.facebook.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com *.sharethis.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.affirm.com *.affirm.ca display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com s.amazon-adsystem.com *.hotjar.com www.facebook.com *.pinterest.com www.paypalobjects.com *.amc.demdex.net *.demdex.net *.cardinalcommerce.com *.authorize.net *.vimeo.com www.google.com *.ugc.bazaarvoice.com *.bazaarvoice.com *.api.bazaarvoice.com *.amazon-adsystem.com *.weltpixel.com mcstaging.worx.com tst.kaptcha.com *.adsrvr.org www.worx.com worx.com *.dap.akadns.net *.signifyd.com *.monetate.net ssl.kaptcha.com *.online-metrix.net *.captcha-delivery.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com * https://*.online-metrix.net https://imgs.signifyd.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.sharethis.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.payments-amazon.com *.affirm.com *.affirm.ca display.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com network-a.bazaarvoice.com network-stg-a.bazaarvoice.com photos-uat-us.bazaarvoice.com img.youtube.com *.bing.com *.adsrvr.org x.bidswitch.net pixel.advanseads *.fg8dgt.com www.facebook.com *.tremorhub.com *.reson8.com *.mathtag.com *.bluekai.com sync.search.spotxchange.com thrtle.com sync.go.sonobi.com *.demdex.net www.livehelpnow.net *.rubiconproject.net *.g.doubleclick.net tapestry.tapad.com segments.company-target.com simage2.pubmatic.com dsum.casalemedia.com ads.altitude-arena.com i.liadm.com *.listrakbi.com *.adobedtm.com *.sc.omtrdc.net *.everesttech.net *.magentocommerce.com *.sandbox.paypal.com *.ytimg.com *.swagger.io *.cloudfront.net *.bazaarvoice.com *.ugc.bazaarvoice.co *.rlcdn.com *.bfmio.com *.klevu.com *.ksearchnet.com *.narvar.com *.narvar.qa www.sandbox.paypal.com *.stats.paypal.com *.braintreegateway.com www.google.co.in *.cookielaw.org *.dap.akadns.net *.espssl.com *.s3.us-east-2.amazonaws.com *.pinterest.com *.hotjar.com www.emjcd.com *.dotomi.com *.worx.com worx.com *.five9.com *.nextdoor.com s3.amazonaws.com *.googleapis.com *.facebook.net *.eu.worx.com pippio.com *.adsymptotic.com *.openx.net *.agkn.com *.audrte.com *.krxd.net *.videohub.tv *.adxns.com *.media6degrees.com *.ads.linkedin.com *.scorecardresearch.com *.netseer.com *.us1.dyntrk.com *.insightexpressai.com *.mediawallahscript.com *.t.domdex.com *.services.xg4ken.com trkn.us *.mmsho.com *.narrative.io *.postrelease.com *.ispot.tv *.crsspxl.com *.bnmla.com *.acxiomapac.com *.y-medialink.com *.shopping.rakuten.com *.rtbiq.com *.ib-ibi.com *.signifyd.com *.monetate.net *.srv.stackadapt.com *.spotify.com *.rd.linksynergy.com um.simpli.fi cs.media.net *.addthis.com sync.ipredictive.com lrp.mxptint.net pixel.tapad.com epiv.cardlytics.com secure.adnxs.com www.entitytag.co.uk px.owneriq.net bttrack.com ssum.casalemedia.com usersync-b3.videoamp.com *.maxaccess.io *.online-metrix.net s3-us-west-2.amazonaws.com maps.googleapis.com maps.gstatic.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.pixriot.com *.storeimaging.com https://imgs.signifyd.com https://*.online-metrix.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://rum.hlx.page *.sharethis.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.affirm.com *.affirm.ca apps.bazaarvoice.com apps.nexus.bazaarvoice.com apps-stg.nexus.bazaarvoice.com analytics-static.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com mpsnare.iesnare.com js-agent.newrelic.com bam.nr-data.net blueacornici.atlassian.net *.monetate.net www.livehelpnow.net js.klevu.com *.listrakbi.com *.facebook.net *.steelhousemedia.com *.adacado.com *.hotjar.com *.amazon-adsystem.com *.rlcdn.com *.adsrvr.org *.bidswitch.net *.adobedtm.com *.cardinalcommerce.com *.ccdc02.com *.authorize.net *.paypal.com *.ytimg.com *.bazaarvoice.com *.nexus.bazaarvoice.co *.ugc.bazaarvoice.com *.api.bazaarvoice.com *.iesnare.com *.atlassian.net polyfill.io *.fg8dgt.com *.ksearchnet.com *.sandbox.braintreegateway.com *.bing.com *.tiktok.com www.mczbf.com *.cookielaw.org *.maxaccess.io *.five9.com *.r.bidswitch.net *.dstillery.com *.media6degrees.com *.onlineada.workers.dev *.fullstory.com s.pinimg.com *.mavenoid.com *.cloudfront.net mcstaging.worx.com www.worx.com worx.com *.orderwave.com *.googleapis.com get.geojs.io *.g.doubleclick.net *.nextdoor.com code.jquery.com dap-dist.akamaized.net serviceconnection.pro *.blob.core.windows.net kalicube.pro *.jsdelivr.net *.dap.akadns.net sjwoe.com www.sjwoe.com *.narvar.com *.ads.linkedin.com www.googleoptimize.com *.signifyd.com *.datadome.co *.captcha-delivery.com *.schemaapp.com ct.pinterest.com cdnjs.cloudflare.com *.online-metrix.net kenwheeler.github.io maps.googleapis.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com https://cdn-scripts.signifyd.com https://imgs.signifyd.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.sharethis.com display.ugc.bazaarvoice.com *.googleapis.com *.listrakbi.com *.mavenoid.com *.five9.com *.espssl.com *.typekit.net serviceconnection.pro *.onetrust.com www.worx.com worx.com *.signifyd.com https://static.klaviyo.com *.klevu.com *.ksearchnet.com *.fontawesome.com assets.braintreegateway.com https://js.klevu.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.worx.com *.narvar.com *.narvar.qa 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.sharethis.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.affirm.com *.affirm.ca api.bazaarvoice.com stg.api.bazaarvoice.com apps.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com *.onetrust.com bam.nr-data.net *.listrakbi.com *.listrak.com *.hotjar.io *.g.doubleclick.net *.demdex.net *.sc.omtrdc.net *.cardinalcommerce.com *.amazonservices.com *.amazonservices.co.uk *.amazonservices.co.jp *.amazonservices.jp *.amazonservices.it *.amazonservices.fr *.amazonservices.es *.amazonservices.de *.bazaarvoice.com *.api.bazaarvoice.com *.klevu.com *.ksearchnet.com *.sandbox.braintreegateway.com *.tiktok.com *.cookielaw.org *.onlineada.workers.dev *.cloudfront.net *.execute-api.us-east-2.amazonaws.com *.five9.com *.fullstory.com www.mczbf.com *.pinterest.com *.ingest.sentry.io *.mavenoid.com *.googleapis.com surveystats.hotjar.io serviceconnection.pro kalicube.pro *.blob.core.windows.net www.facebook.com *.jsdelivr.net *.dap.akadns.net sjwoe.com www.sjwoe.com www.worx.com worx.com *.ads.linkedin.com www.googleoptimize.com www.livehelpnow.net *.signifyd.com *.monetate.net *.datadome.co *.cloudfunctions.net *.bing.com *.schemaapp.com *.google.co.in *.maxaccess.io s.amazon-adsystem.com ara.paa-reporting-advertising.amazon maps.googleapis.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.pixriot.com *.storeimaging.com https://imgs.signifyd.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src www.searchanise.com *.searchserverapi.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com www.searchanise.com *.searchserverapi.com *.twitter.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.bolt.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.bolt.com https://www.google.com/recaptcha/ www.googletagmanager.com www.searchanise.com *.searchserverapi.com *.twitter.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.twitter.com *.twimg.com www.google.ru www.searchanise.com *.searchserverapi.com s3.amazonaws.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.bolt.com *.commerce-quick-checkout.com http://localhost:8082 https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.pagar.me searchanise-ef84.kxcdn.com s3.amazonaws.com ajax.aspnetcdn.com www.searchanise.com *.searchserverapi.com *.searchanise.com api.amplitude.com *.twitter.com *.twimg.com *.avada.io js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com www.searchanise.com *.searchserverapi.com searchanise-ef84.kxcdn.com s3.amazonaws.com *.twitter.com ton.twimg.com *.fontawesome.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.bolt.com *.pagar.me https://viacep.com.br https://www.viacep.com.br api.amplitude.com stats.g.doubleclick.net https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com https://api-gw-v4.dev.gokwik.io https://sandbox.pdp.gokwik.co https://pdp.gokwik.co *.adobe.com *.adobedtm.com *.cardinalcommerce.com *.ccdc02.com *.jsdelivr.net unpkg.com *.kapturecrm.com *.wizzy.ai *.gozayaan.com *.googletagmanager.com *.supabase.co *.hotjar.com swopstore.com script.google.com *.facebook.net *.matomo.cloud *.soch.com *.bing.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com *.adobedtm.com *.cardinalcommerce.com *.ccdc02.com *.jsdelivr.net unpkg.com *.kapturecrm.com *.wizzy.ai *.gozayaan.com *.googletagmanager.com *.supabase.co *.hotjar.com swopstore.com script.google.com *.facebook.net *.matomo.cloud *.soch.com *.bing.com api.razorpay.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com * 'self' 'unsafe-inline'; img-src *.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.googleapis.com https://api-gw-v4.dev.gokwik.io https://sandbox.pdp.gokwik.co https://pdp.gokwik.co *.adtrafficquality.google *.clarity.ms *.cardinalcommerce.com *.ccdc02.com *.jsdelivr.net unpkg.com *.kapturecrm.com *.wizzy.ai *.gozayaan.com *.googletagmanager.com *.supabase.co *.hotjar.com swopstore.com script.google.com *.facebook.net *.matomo.cloud *.soch.com *.bing.com cdn.razorpay.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net assets.adobedtm.com amcglobal.sc.omtrdc.net *.adobe.io use.typekit.net *.commerce-payment-services.com *.magento-ds.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.magento-datasolutions.com *.googleapis.com *.gstatic.com http://sp-kf-collector.dev.gokwik.io https://api-gw-v4.dev.gokwik.io https://sandbox.pdp.gokwik.co https://pdp.gokwik.co *.lightwidget.com *.artfut.com *.adtrafficquality.google *.googlesyndication.com s3-ap-southeast-1.amazonaws.com *.cloudflare.com *.clarity.ms *.vimeo.com *.mxpnl.com *.bing.com *.cardinalcommerce.com *.ccdc02.com *.jsdelivr.net unpkg.com *.kapturecrm.com *.wizzy.ai *.gozayaan.com *.googletagmanager.com *.supabase.co *.hotjar.com swopstore.com script.google.com *.facebook.net *.matomo.cloud *.soch.com cdn.jsdelivr.net checkout.razorpay.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com *.adobedtm.com *.cardinalcommerce.com *.ccdc02.com *.jsdelivr.net unpkg.com *.kapturecrm.com *.wizzy.ai *.gozayaan.com *.googletagmanager.com *.supabase.co *.hotjar.com swopstore.com script.google.com *.facebook.net *.matomo.cloud *.soch.com *.bing.com assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.snplow.net commerce.adobedc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net *.sentry.io www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io *.paypal.com google.com *.google.com *.magento-datasolutions.com *.magento-ds.com *.googleapis.com http://sp-kf-collector.dev.gokwik.io https://api-gw-v4.dev.gokwik.io https://sandbox.pdp.gokwik.co https://pdp.gokwik.co *.onedirect.in *.adtrafficquality.google *.clarity.ms *.mixpanel.com *.adobe.com *.adobedtm.com *.cardinalcommerce.com *.ccdc02.com *.jsdelivr.net unpkg.com *.kapturecrm.com *.wizzy.ai *.gozayaan.com *.googletagmanager.com *.supabase.co *.hotjar.com swopstore.com script.google.com *.facebook.net *.matomo.cloud *.soch.com *.bing.com lumberjack.razorpay.com lumberjack-metrics.razorpay.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com wss://sockets.wizzy.ai *.wizsearch.in wss://sockets.wizsearch.in 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self';base-uri 'self';frame-ancestors 'self';frame-src https://* 'self' epichttp:;script-src 'nonce-02ba9e2450bf4aa496a02b088bd58d7e' https://portal.mydh.org 'self';img-src https://* 'self' blob: data:;style-src https://portal.mydh.org 'self' 'unsafe-inline';worker-src 'self' blob:;child-src 'self' blob:;form-action https://central.mychart.org/MyChart/ 'self';media-src https://* 'self' blob:; 1 object-src 'none'; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.clarity.ms https://cdn.cookielaw.org https://www.googletagmanager.com https://www.google-analytics.com https://players.brightcove.net/ https://www.recaptcha.net https://www.gstatic.com https://js-agent.newrelic.com https://pi.pardot.com https://www.youtube.com https://in2.taskanalytics.com https://bam.nr-data.net https://snap.licdn.com https://googleads.g.doubleclick.net https://info.weareplanet.com https://www.googleadservices.com https://static.hotjar.com https://script.hotjar.com https://tag.demandbase.com https://j.6sc.co https://tracking.g2crowd.com https://connect.facebook.net https://tpc.googlesyndication.com https://cdn.weglot.com/weglot.min.js https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com https://www.google.com; style-src 'self' 'report-sample' https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com; webrtc 'block'; worker-src 'self'; base-uri 'self'; form-action 'self'; frame-ancestors 'self' 1 report-uri https://www.dropbox.com/csp_log?policy_name=dash&report_only=true; default-src 'none'; img-src 'self' data: https://*; font-src 'self' data:; object-src 'none'; frame-src https://www.dropbox.com https://snippet.meticulous.ai https://*.dropboxusercontent.com; connect-src 'self' blob: https://*.dropbox.com https://*.logs.datadoghq.com https://*.logs.datadoghq.eu https://*.sentry.io https://api.dropboxapi.com https://content.dropboxapi.com https://cdn.dropboxexperiment.com https://api.sprig.com https://cognito-identity.us-west-2.amazonaws.com https://user-events-v3.s3-accelerate.amazonaws.com https://*.dropboxusercontent.com https://cfl.dropboxstatic.com https://edge.fullstory.com https://rs.fullstory.com https://browser.sentry-cdn.com https://s2.googleusercontent.com https://paper.dropboxstatic.com https://app.dropboxer.net; media-src 'self' https://*.dropbox.com https://*.dropboxusercontent.com blob:; script-src 'self' 'report-sample' 'sha256-Ug+Tt6thCsOMMEscVE3D3ynGMA/+AqEnDh5MqhLRPMY=' https://www.dropbox.com https://browser.sentry-cdn.com https://snippet.meticulous.ai https://cfl.dropboxstatic.com; style-src 'self' 'unsafe-inline'; worker-src 'self' blob:; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com data: fonts.googleapis.com *.fontawesome.com maxcdn.bootstrapcdn.com 'self' data: https://www.surviocdn.com/ *.survicate.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.paypal.com *.googletagmanager.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors *.magerocket.com *.despegar.com *.koin.com.br *.googletagmanager.com *.gocuotas.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com cdn.dnky.co amc.demdex.net www.google.com www.facebook.com youtube.com *.globalgetnet.com *.magerocket.com *.despegar.com *.koin.com.br *.googletagmanager.com *.gocuotas.com *.mercadolibre.com mldp.mercadopago.com www.mercadolibre.com https://www.survio.com/ *.doubleclick.net *.pinterest.com *.getblue.io *.groovinads.com *.online-metrix.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net maps.gstatic.com maps.googleapis.com accounts.google.com www.facebook.com *.globalgetnet.com *.magerocket.com *.despegar.com *.koin.com.br *.googletagmanager.com fonts.googleapis.com *.gocuotas.com imgmp.mlstatic.com *.mlstatic.com *.mercadopago.com *.mercadolibre.com *.mercadolivre.com.br *.mercadolibre.com.mx *.mercadolibre.com.ar 'self' data: www.mercadolibre.com www.mercadolibre.com.mx www.mercadolibre.com.ar www.mercadolibre.com.br a248.e.akamai.net mercadolivre.com.br www.mercadolivre.com.br www.mercadolivre.com.mx www.mercadolivre.com.ar www.mercadopago.com secure.mlstatic.com *.google.com.ar *.doubleclick.net *.mercadolivre.com www.mailing.somosrex.com *.clarity.ms *.groovinads.com *.bing.com *.online-metrix.net img.survicate.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net amcglobal.sc.omtrdc.net *.adobe.io use.typekit.net *.commerce-payment-services.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.magento-ds.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.magento-datasolutions.com https://rum.hlx.page cdn.dnky.co r1-t.trackedlink.net www.gstatic.com js-agent.newrelic.com bam.nr-data.net maps.googleapis.com connect.facebook.net player.vimeo.com *.braindw.com https://live.decidir.com *.globalgetnet.com *.magerocket.com *.despegar.com *.koin.com.br *.googletagmanager.com *.gocuotas.com *.mlstatic.com https://www.google.com *.gstatic.com http2.mlstatic.com secure.mlstatic.com https://maps.googleapis.com https://merchants.playdigital.com.ar/ https://merchants.preprod.playdigital.com.ar/ https://ecommerce-modal.modo.com.ar/ https://ecommerce-modal.preprod.modo.com.ar/ *.convertexperiments.com *.wcx.cloud *.pinimg.com *.survicate.com *.clarity.ms *.mathtag.com *.tiktok.com *.getblue.io *.groovinads.com *.wcentrix.com *.cloudfront.net *.pinterest.com *.icommarketing.com *.decidir.com *.mercadopago.com *.online-metrix.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com cdn.dnky.co *.fontawesome.com maxcdn.bootstrapcdn.com *.googleapis.com *.gstatic.com https://ecommerce-modal.modo.com.ar/ https://ecommerce-modal.preprod.modo.com.ar/ *.survicate.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net commerce.adobe.io *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.magento-datasolutions.com *.magento-ds.com maps.googleapis.com api.comapi.com bam.nr-data.net *.braindw.com https://developers.decidir.com/ *.globalgetnet.com *.iesnare.com wss://mpsnare.iesnare.com *.magerocket.com *.despegar.com *.googletagmanager.com *.gocuotas.com *.mercadopago.com *.google-analytics.com api.mercadopago.com events.mercadopago.com www.mercadolibre.com https://merchants.playdigital.com.ar/ https://merchants.preprod.playdigital.com.ar/ https://ecommerce-modal.modo.com.ar/ https://ecommerce-modal.preprod.modo.com.ar/ *.doubleclick.net notifications-icommkt.com track-icommkt.com *.clarity.ms *.pinterest.com *.tiktok.com *.convertexperiments.com *.decidir.com *.online-metrix.net 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.globalgetnet.com *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' 'strict-dynamic' 'report-sample' data: script-src 'self' 'unsafe-inline' 'unsafe-eval' 'strict-dynamic' 'report-sample' data: https://static.cloudflareinsights.com https://js.hs-analytics.net/analytics https://js.hs-analytics.net https://js.hscollectedforms.net https://www.gstatic.com https://boards.eu.greenhouse.io https://cdnjs.cloudflare.com https://cdn-cookieyes.com https://cdn.jsdelivr.net/npm/slick-carousel@1.8.1/slick/slick.min.js https://cdn.jsdelivr.net/npm/swiper@8.4.7/swiper-bundle.min.js https://cdnjs.cloudflare.com/ajax/libs/aos/2.3.4/aos.js https://cdnjs.cloudflare.com/ajax/libs/waypoints/3.0.0/jquery.waypoints.min.js https://googleads.g.doubleclick.net/pagead/viewthroughconversion/16451025998/ https://js-na1.hs-scripts.com/6849561.js https://js.hs-banner.com/v2/6849561/banner.js https://js.hs-scripts.com/6849561.js https://js.hsadspixel.net/fb.js https://js.hscollectedforms.net/collectedforms.js https://js.hsforms.net/forms/embed/v2.js https://js.qualified.com/qualified.js https://sc.lfeeder.com/lftracker_v1_p1e024BeMLX7GB6d.js https://snap.licdn.com/li.lms-analytics/insight.min.js https://static.addtoany.com https://static.cloudflareinsights.com/beacon.min.js/vcd15cbe7772f49c399c6a5babf22c1241717689176015 https://tag.clearbitscripts.com/v1/pk_d197df6018af43b45412e833b5426444/tags.js https://unpkg.com/swiper@8/swiper-bundle.min.js https://ws.zoominfo.com/pixel/6146fbdc366fa2001cc5dec5 https://www.googletagmanager.com/gtag/js https://www.google.com/recaptcha/enterprise.js https://x.clearbitjs.com/v2/pk_d197df6018af43b45412e833b5426444/destinations.min.js https://px.ads.linkedin.com https://app.markup.io https://app.qualified.com https://weatherwidget.io/w/ https://unpkg.com/@lottiefiles/lottie-player@latest/dist/lottie-player.js https://www.googletagmanager.com https://eleos.health/cdn-cgi/scripts/5c5dd728/cloudflare-static/email-decode.min.js https://tag.demand-genius.com/demand-genius.iife.js 'nonce-eleosscripts'; script-src-elem 'self' 'unsafe-inline' 'unsafe-eval' 'strict-dynamic' 'report-sample' data: https://js.hscollectedforms.net https://js.hs-analytics.net https://static.cloudflareinsights.com https://js.hs-analytics.net/analytics https://app.markup.io https://app.qualified.com https://boards.eu.greenhouse.io https://cdn-cookieyes.com https://cdn.jsdelivr.net/npm/slick-carousel@1.8.1/slick/slick.min.js https://cdn.jsdelivr.net/npm/swiper@8.4.7/swiper-bundle.min.js https://cdnjs.cloudflare.com https://cdnjs.cloudflare.com/ajax/libs/aos/2.3.4/aos.js https://cdnjs.cloudflare.com/ajax/libs/waypoints/3.0.0/jquery.waypoints.min.js https://eleos.health/cdn-cgi/scripts/5c5dd728/cloudflare-static/email-decode.min.js https://googleads.g.doubleclick.net/pagead/viewthroughconversion/16451025998/ https://js-na1.hs-scripts.com/6849561.js https://js.hsadspixel.net https://js.hsadspixel.net/fb.js https://js.hs-analytics.net https://js.hs-banner.com https://js.hs-banner.com/v2/6849561/banner.js https://js.hs-scripts.com/6849561.js https://js.hscollectedforms.net https://js.hscollectedforms.net/collectedforms.js https://js.hsforms.net/forms/embed/v2.js https://js.qualified.com https://js.qualified.com/qualified.js https://px.ads.linkedin.com https://sc.lfeeder.com/lftracker_v1_p1e024BeMLX7GB6d.js https://snap.licdn.com/li.lms-analytics/insight.min.js https://static.addtoany.com https://static.cloudflareinsights.com/beacon.min.js/vcd15cbe7772f49c399c6a5babf22c1241717689176015 https://tag.clearbitscripts.com/v1/pk_d197df6018af43b45412e833b5426444/tags.js https://unpkg.com https://unpkg.com/@lottiefiles/lottie-player@latest/dist/lottie-player.js https://unpkg.com/swiper@8/swiper-bundle.min.js https://weatherwidget.io/w/ https://ws.zoominfo.com/pixel/6146fbdc366fa2001cc5dec5 https://www.google.com/recaptcha/enterprise.js https://www.googletagmanager.com https://www.googletagmanager.com/gtag/js https://x.clearbitjs.com/v2/pk_d197df6018af43b45412e833b5426444/destinations.min.js 'nonce-eleosscripts'; style-src 'self' 'unsafe-inline' 'report-sample' data: https://fonts.googleapis.com https://unpkg.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com/@lottiefiles/lottie-player@latest/dist/lottie-player.js; style-src-elem 'self' 'report-sample' data: https://fonts.googleapis.com https://unpkg.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com/@lottiefiles/lottie-player@latest/dist/lottie-player.js 'nonce-eleosstyles'; style-src-attr 'unsafe-inline'; img-src 'self' data: https://*.hubspot.com https://*.hsforms.com https://*.hscollectedforms.net https://s.w.org https://www.linkedin.com https://cdn-cookieyes.com https://forms-na1.hsforms.com https://forms.hsforms.com https://px.ads.linkedin.com https://s3.amazonaws.com https://s3-spotlightr-output.b-cdn.net https://secure.gravatar.com https://tr.lfeeder.com https://track.hubspot.com https://www.google.com https://www.googletagmanager.com https://www.google-analytics.com https://googleads.g.doubleclick.net https://www.google.com.gt https://images.unsplash.com https://px4.ads.linkedin.com/ https://unpkg.com/@lottiefiles/lottie-player@latest/dist/lottie-player.js; connect-src 'self' data: https://*.hubspot.com https://*.hsforms.com https://*.hscollectedforms.net https://api.hubapi.com https://app.clearbit.com https://app.markup.io https://app.qualified.com https://cdn-cookieyes.com https://directory.cookieyes.com https://eleos.health https://forms.hscollectedforms.net https://forms.hsforms.com https://log.cookieyes.com https://o209747.ingest.us.sentry.io https://px.ads.linkedin.com https://ws.zoominfo.com https://www.google.com https://api.spotlightr.com wss://ws.qualified.com wss://ws5.qualified.com https://www.google-analytics.com/ https://unpkg.com/@lottiefiles/lottie-player@latest/dist/lottie-player.js https://analytics.propensity.com https://analytics.propensity-abm.com https://cdn.jsdelivr.net https://unpkg.com https://static.hsappstatic.net https://x.clearbitjs.com; font-src 'self' data: https://fonts.gstatic.com; media-src 'self' data: https://videos.cdn.spotlightr.com https://s3-spotlightr-output.b-cdn.net https://unpkg.com/@lottiefiles/lottie-player@latest/dist/lottie-player.js; report-uri https://682f45bb819d722f2bc72340.endpoint.csper.io?builder=true&v=2; object-src 'none'; frame-src 'self' https://forms.hsforms.com https://www.youtube.com https://app.qualified.com https://job-boards.eu.greenhouse.io https://job-boards.cdn.greenhouse.io https://static.addtoany.com https://td.doubleclick.net https://videos.cdn.spotlightr.com https://www.google.com https://www.googletagmanager.com https://eleos.health https://weatherwidget.io/w/; worker-src blob:; manifest-src 'self'; base-uri 'self'; upgrade-insecure-requests 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://*.adyen.com https://acsbapp.com https://bat.bing.com https://widget.us.criteo.com https://*.googletagmanager.com https://*.google-analytics.com https://*.googleadservices.com https://pagead2.googlesyndication.com https://*.flos.com https://*.salesforce.com https://service.force.com https://*.cquotient.com https://*.hotjar.com https://*.vimeo.com https://*.contentful.com https://*.clarity.ms https://a.omappapi.com https://api.omappapi.com https://*.optimonk.com https://*.contentsquare.net https://*.outbrain.com https://dev.visualwebsiteoptimizer.com https://consent.cookiebot.com https://*.cookiebot.com https://d.la1-c2-fra.salesforceliveagent.com https://d.la11-core1.sfdc-3d0u2f.salesforceliveagent.com https://maps.googleapis.com https://dev.flos.com https://pay.google.com https://www.paypal.com https://d.ratepay.com https://*.collect.igodigital.com https://dynamic.criteo.com https://sslwidget.criteo.com https://s.pinimg.com https://ct.pinterest.com https://connect.facebook.net https://snap.licdn.com https://acdn.adnxs.com https://analytics.webgains.io https://googleads.g.doubleclick.net; connect-src 'self' https://*.flos.com https://cdn.acsbapp.com https://bat.bing.com https://cdn-renderer.optimonk.com https://*.paypal.com https://*.salesforce.com https://service.force.com https://api.omappapi.com https://*.google.com/pagead/ https://*.adyen.com https://*.contentful.com https://*.google-analytics.com https://*.analytics.google.com https://*.clarity.ms https://front.optimonk.com https://cdn-account.optimonk.com https://cdn-limit.optimonk.com https://jfapiprod.optimonk.com https://pagead2.googlesyndication.com https://dev.visualwebsiteoptimizer.com https://maps.googleapis.com https://mapsresources-pa.googleapis.com https://google.com/pay https://www.google.com/pay https://pay.google.com/about/redirect/ https://pay.google.com/gp/p/ https://pay.google.com/gp/p/payment_method_manifest.json https://www.sandbox.paypal.com/xoplatform/logger/api/logger https://checkoutanalytics-test.adyen.com https://www.google.com/ccm/collect https://*.googleadservices.com https://www.googleadservices.com https://amplify.outbrain.com https://tr.outbrain.com https://ib.adnxs.com https://px.ads.linkedin.com https://ct.pinterest.com https://measurement-api.criteo.com https://consentcdn.cookiebot.com; img-src 'self' data: blob: https://*.flos.com https://*.dam.flos.net https://bat.bing.com https://x.bidswitch.net https://cm.g.doubleclick.net https://simage4.pubmatic.com https://r.casalemedia.com https://gum.criteo.com https://id5-sync.com https://ad.360yield.com https://contextual.media.net https://exchange.mediavine.com https://jadserve.postrelease.com https://sync.outbrain.com https://simage2.pubmatic.com https://pixel.rubiconproject.com https://rtb-csync.smartadserver.com https://sync-t1.taboola.com https://criteo-sync.teads.tv https://criteo-partners.tremorhub.com https://eb2.3lift.com https://ad.yieldlab.net https://sync.1rx.io https://dis.criteo.com https://dpm.demdex.net https://aa.agkn.com https://editor-upload-cdn.optimonk.com https://cdn-content.optimonk.com https://dam.flos.net https://*.adyen.com https://*.google-analytics.com https://*.googlesyndication.com https://*.googleadservices.com https://*.clarity.ms https://c.bing.com https://dev.visualwebsiteoptimizer.com https://www.googletagmanager.com https://maps.gstatic.com https://mapsresources-pa.googleapis.com https://www.paypalobjects.com https://www.gstatic.com https://tau.collect.igodigital.com https://px.ads.linkedin.com https://www.facebook.com https://connect.facebook.net https://ib.adnxs.com https://googleads.g.doubleclick.net https://www.google.com https://www.google.it https://pagead2.googlesyndication.com https://www.googleadservices.com https://imgsct.cookiebot.com; frame-src 'self' https://*.adyen.com https://*.facebook.com https://*.paypal.com https://*.googletagmanager.com https://*.salesforce.com https://*.vimeo.com https://*.cookiebot.com https://*.criteo.com https://*.pinterest.com https://pay.google.com https://service.force.com https://dev.visualwebsiteoptimizer.com https://www.sandbox.paypal.com; style-src 'self' 'unsafe-inline' https://cdn-content.optimonk.com https://*.googleapis.co https://*.adyen.com https://*.salesforce.com https://a.omappapi.com https://service.force.com https://cdn-asset.optimonk.com https://*.googleapis.com https://*.adyen.com https://*.salesforce.com https://a.omappapi.com https://service.force.com https://cdn-asset.optimonk.com; font-src 'self' https://*.googleapis.com https://fonts.gstatic.com https://cdn-content.optimonk.com https://cdn-custom.optimonk.com https://*.flos.com data:; worker-src 'self' blob: https://maps.googleapis.com; report-uri https://csp-reporting.cloudflare.com/cdn-cgi/script_monitor/report?m=QKvP3P1.qjt2H24aZIg74vo468vi5qTJ3wH0h4qc744-1770434571-1.0.1.1-Yj0E1AU1b2Qur6lPKsRCEsd.OIGMUE5NNgf0wQ9ttlK.pNGjAzYIQEm6pgQdFltMShhYmstzU7gkU2rZ85A3fUn277AvNz9x58t0odXcBW4ZVT_aDbZyuGZGWWb9tZ7tBb3VnEg6zf4xKPkyySqeRYAvgJu7eLqqupIbDegN8uC6f7GlqtPdABakkvbIBWL4; report-to cf-cjbyxgumpfpycipb 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.bing.com *.cookiebot.com *.google-analytics.com *.googleapis.com *.googletagmanager.com *.google.com *.gstatic.com *.doubleclick.net *.curator.io *.elfsight.com *.hotjar.com *.facebook.net *.cloudfront.net *.micpn.com *.searchstax.com *.wisepops.com wisepops.com *.wisepops.net wisepops.net *.sentry-cdn.com *.thehotelsnetwork.com; style-src 'self' 'unsafe-inline' *.googleapis.com *.gstatic.com *.fonts.net *.myfonts.net *.doubleclick.net *.curator.io; img-src 'self' data: blob: *.google.co.uk *.facebook.com *.doubleclick.net *.google-analytics.com *.micpn.com *.googleapis.com *.gstatic.com *.cloudfront.net *.curator.io *.tripadvisor.com; connect-src 'self' *.bing.com *.cookiebot.com *.google-analytics.com *.googleapis.com *.googletagmanager.com *.google.com *.gstatic.com *.doubleclick.net *.micpn.com *.facebook.com *.mapbox.com *.curator.io *.wisepops.net *.wisepops.com wisepops.net wisepops.com *.thehotelsnetwork.com; font-src 'self' data: *.fonts.net *.myfonts.net *.gstatic.com; worker-src 'self' blob:; child-src 'self' blob: *.google.com *.googleapis.com *.googletagmanager.com *.doubleclick.net; frame-src 'self' *.google.com *.doubleclick.net *.facebook.com; media-src 'self'; object-src 'none'; base-uri 'self'; report-uri https://3chillies.report-uri.com/r/d/csp/reportOnly; 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.hotjar.com https://js.playground.klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.script.crazyegg.com *.empathy.co *.cdn.aplazame.com api.aplazame.com *.maps.googleapis.com *.cdn.jsdelivr.net https://www.google-analytics.com https://cdnjs.cloudflare.com *.clarity.ms *.facebook.net *.facebook.com *.pinterest.com *.googletagmanager.com *.google.com *.google.es *.analytics.google.com *.connectif.cloud *.doubleclick.net *.googleadservices.com *.joseluisjoyerias.com *.pinimg.com *.googlesyndication.com *.google-analytics.com; script-src-elem 'unsafe-inline' *.klarna.com *.klarnacdn.net *.klarnaevt.com cdn.aplazame.com *.empathy.co cdn.jsdelivr.net script.crazyegg.com *.clarity.ms *.facebook.net *.facebook.com *.pinterest.com *.googletagmanager.com *.google.com *.google.es *.analytics.google.com *.connectif.cloud *.doubleclick.net *.googleadservices.com *.joseluisjoyerias.com *.pinimg.com *.googlesyndication.com *.google-analytics.com; style-src 'self' 'unsafe-inline' *.klarnacdn.net https://cdnjs.cloudflare.com https://fonts.googleapis.com; img-src 'self' data: https://www.joseluisjoyerias.com https://www.google-analytics.com *.clarity.ms c.bing.com *.facebook.net *.facebook.com *.pinterest.com *.googletagmanager.com *.google.com *.google.es *.analytics.google.com *.connectif.cloud *.doubleclick.net *.googleadservices.com *.joseluisjoyerias.com *.pinimg.com *.googlesyndication.com *.google-analytics.com *.klarnacdn.net; font-src 'self' *.klarna.com *.klarnacdn.net *.klarnaevt.com https://fonts.gstatic.com cdn.aplazame.com *.clarity.ms *.facebook.net *.facebook.com *.pinterest.com *.googletagmanager.com *.google.com *.google.es *.analytics.google.com *.connectif.cloud *.doubleclick.net *.googleadservices.com *.joseluisjoyerias.com *.pinimg.com *.googlesyndication.com *.google-analytics.com; connect-src 'self' *.hotjar.com *.hotjar.io *.empathy.co *.klarna.com *.klarnacdn.net *.klarnaevt.com https://js.playground.klarna.com https://www.google-analytics.com google.com script.crazyegg.com maps.googleapis.com api.aplazame.com *.clarity.ms *.facebook.net *.facebook.com *.pinterest.com *.googletagmanager.com *.google.com *.google.es *.analytics.google.com *.connectif.cloud *.doubleclick.net *.googleadservices.com *.joseluisjoyerias.com *.pinimg.com *.googlesyndication.com *.google-analytics.com capig.stape.pro; frame-src 'self' *.clarity.ms *.facebook.net *.facebook.com *.pinterest.com *.googletagmanager.com *.google.com *.google.es *.analytics.google.com *.connectif.cloud *.doubleclick.net *.googleadservices.com *.joseluisjoyerias.com *.pinimg.com *.googlesyndication.com *.google-analytics.com *.klarna.com; child-src 'self'; form-action 'self'; base-uri 'self'; report-uri /csp-report-endpoint 1 font-src cdnjs.cloudflare.com fonts.gstatic.com *.fontawesome.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com magento.buildify.shop *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.sharethis.com platform.twitter.com magento.buildify.shop c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * https://www.paypal.com https://*.paypal.com https://*.paypalobjects.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.sharethis.com s3.amazonaws.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com https://tr.lfeeder.com https://*.lfeeder.com https://www.google.by https://*.google.by https://media.aheadworks.com https://*.aheadworks.com https://firebasestorage.googleapis.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://cdn.polyfill.io *.sharethis.com platform.twitter.com platform.instagram.com apis.google.com magento.buildify.shop https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://www.paypal.com https://*.paypal.com https://*.paypalobjects.com https://browser.sentry-cdn.com *.avada.io *.shopify.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.sharethis.com cdnjs.cloudflare.com fonts.googleapis.com magento.buildify.shop https://static.klaviyo.com *.fontawesome.com unsafe-inline assets.braintreegateway.com https://fonts.bunny.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io *.sharethis.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com https://www.paypal.com https://*.paypal.com https://*.paypalobjects.com https://*.ingest.sentry.io https://get.geojs.io *.avada.io 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com data: https://api.systempay.fr/static/ *.fontawesome.com https://cdnjs.cloudflare.com *.googleusercontent.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com https://paiement.systempay.fr/vads-payment/ https://api.systempay.fr/api-payment/ https://api.systempay.fr/static/ *.hsforms.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com https://paiement.systempay.fr/vads-payment/ https://api.systempay.fr/static/ https://www.googletagmanager.com/ *.hs-sites.com *.hsforms.com *.doubleclick.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.googleapis.com https://paiement.systempay.fr/static/latest/images/type-carte/ https://api.systempay.fr/static/ https://paiement.systempay.fr/vads-payment/ http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ https://maps.googleapis.com https://maps.gstatic.com https://www.google.fr https://api.mapbox.com *.tile.openstreetmap.org *.axept.io *.google.com *.googletagmanager.com *.googleusercontent.com *.hsforms.com *.hubspot.com *.imgix.net *.openstreetmap.org *.hsforms.net 'self' data: data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ https://api.systempay.fr/api-payment/ https://api.systempay.fr/static/ http://www.googletagmanager.com/ https://www.googletagmanager.com/ https://cdnjs.cloudflare.com https://maps.googleapis.com *.axept.io *.facebook.net *.googletagmanager.com *.hotjar.com *.hs-analytics.net *.hs-banner.com *.hs-scripts.com *.hscollectedforms.net *.hsforms.net *.hubspot.com *.bing.com *.hsforms.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://api.systempay.fr/static/ *.fontawesome.com https://fonts.googleapis.com https://cdnjs.cloudflare.com *.googletagmanager.com *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.googleapis.com https://paiement.systempay.fr/vads-payment/ https://api.systempay.fr/api-payment/ http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ https://maps.googleapis.com https://nominatim.openstreetmap.org *.axept.io *.axeptio.tech *.google-analytics.com *.hotjar.com *.hotjar.io wss://ws.hotjar.com *.hsforms.com *.hscollectedforms.net *.hubspot.com t.elasticsuite.io *.hsforms.net 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src https://paiement.systempay.fr/vads-payment/ https://api.systempay.fr/api-payment/ https://api.systempay.fr/static/ *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://76c33e6e-b3ed-47af-8820-21ea80415831.sansec.watch/; report-to report-endpoint; 1 script-src 'none'; script-src-elem 'none'; script-src-attr 'none'; report-uri https://csp-report.apptrana.com/csp/report/11447 1 default-src 'none'; connect-src 'self' https://*.icfcdn.com https://www.google.com https://cdn.plyr.io https://*.gstatic.com; script-src 'nonce-3e5f860137231608a8e6571853b4e629d485c22a2abad7f45f126ce3121513a0' 'strict-dynamic' 'report-sample' 'self' https://*.icfcdn.com https://www.google.com https://www.gstatic.com https://*.googleapis.com; style-src 'self' 'nonce-3e5f860137231608a8e6571853b4e629d485c22a2abad7f45f126ce3121513a0' 'report-sample' https://fonts.googleapis.com; style-src-elem 'unsafe-inline' 'report-sample' https://fonts.googleapis.com; style-src-attr 'unsafe-inline' 'report-sample'; font-src https://fonts.gstatic.com https://fonts.googleapis.com; img-src 'self' blob: https://*.gstatic.com https://*.nsimg.net https://*.icfcdn.com; media-src 'self' data: https://cdn.plyr.io https://*.nsimg.net https://live.metamediafonts.com; frame-src https:; frame-ancestors 'self'; base-uri 'self'; report-to report-only; report-uri /reporting/cspReport?reportOnly 1 report-uri https://csp.withgoogle.com/csp/youtube_main/strict;base-uri 'self';object-src 'none';script-src 'report-sample' 'nonce-QcVWODqkLJSip6qxYG9dhw' 'unsafe-inline' 'strict-dynamic' https: http: 'unsafe-eval' 1 default-src 'self' https:; script-src 'self' https: 'unsafe-inline' 'unsafe-eval'; style-src 'self' https: 'unsafe-inline'; img-src 'self' https: data: blob:; media-src 'self' https: data: blob:; object-src 'none'; frame-ancestors 'self' https://experience.adobe.com https://infopoint.audi.it; connect-src 'self' https: wss://e0k754.acquire.io; base-uri 'self'; font-src 'self' https: data:; worker-src 'self' blob:; report-uri https://www.audi.co.uk/api/csp-report; report-to csp-endpoint 1 default-src 'self' https: data: blob:; script-src 'self' 'unsafe-inline' 'unsafe-eval' https: data: blob: https://*.hubspot.com https://*.hubapi.com https://*.hsforms.com https://*.hs-scripts.com https://*.hscollectedforms.net https://*.hs-banner.com https://*.hubspotusercontent.com https://*.hubspotusercontent-eu1.net https://js.hs-analytics.net https://js.hsforms.net https://api.hsforms.com https://api.hubapi.com https://*.hsleadflows.net https://*.hsadspixel.net https://*.hs-web-analytics.net https://static.hsappstatic.net https://cdn2.hubspot.net https://cdn.hubspot.com https://*.cloudfront.net https://cdn.jsdelivr.net https://www.googletagmanager.com https://www.google-analytics.com https://www.google.com https://www.gstatic.com https://stats.g.doubleclick.net https://www.googleadservices.com https://cdn.cookielaw.org https://www.youtube.com; style-src 'self' 'unsafe-inline' https: data:; img-src 'self' https: data: blob:; font-src 'self' https: data:; frame-src 'self' https: data:; connect-src 'self' https: wss: https://www.tayyarijeetki.in; media-src 'self' https: data: blob:; worker-src 'self' https: blob:; object-src 'none'; base-uri 'self'; form-action 'self' https:; frame-ancestors 'self' https://*.hubspot.com; 1 font-src *.googleapis.com *.gstatic.com data: 'self' data: *.doubleclick.net *.facebook.com *.alicdn.com *.cloudflare.com *.faceworks.nl *.font.im ncspublicasset.s3.eu-west-3.amazonaws.com *.typekit.net data: 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; form-action *.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.multisafepay.com https://pay.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.sharethis.com www.google.com *.google.com *.doubleclick.net *.facebook.com *.multisafepay.com https://pay.google.com www.paypal.com www.sandbox.paypal.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * www.xtento.com *.googletagmanager.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.sharethis.com *.gstatic.com *.googleapis.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.multisafepay.com www.paypal.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com www.xtento.com cdn.xtento.com *.alicdn.com *.bing.com *.bing.net *.cookiebot.com europe-west1-maxlead-dwh-test.cloudfunctions.net *.googleadservices.com *.google-analytics.com www.google.ad www.google.ae www.google.al www.google.am www.google.at www.google.az www.google.ba www.google.be www.google.bf www.google.bi www.google.bj www.google.bs www.google.bt www.google.by www.google.ca www.google.cd www.google.cg www.google.ch www.google.ci www.google.cl www.google.cm www.google.co.ao www.google.co.bw www.google.co.cr www.google.co.id www.google.co.il www.google.co.in www.google.co.jp www.google.co.ke www.google.co.kr www.google.co.ls www.google.co.ma www.google.com.af www.google.com.ag www.google.com.ar www.google.com.au www.google.com.bd www.google.com.bh www.google.com.bn www.google.com.bo www.google.com.br www.google.com.bz www.google.com.co www.google.com.cu www.google.com.cy www.google.com.do www.google.com.ec www.google.com.eg www.google.com.et www.google.com.fj www.google.com.gh www.google.com.gi www.google.com.gt www.google.com.hk www.google.com.jm www.google.com.kh www.google.com.kw www.google.com.lb www.google.com.ly www.google.com.mm www.google.com.mt www.google.com.mx www.google.com.my www.google.com.na www.google.com.ng www.google.com.ni www.google.com.np www.google.com.om www.google.com.pa www.google.com.pe www.google.com.pg www.google.com.ph www.google.com.pk www.google.com.pr www.google.com.py www.google.com.qa www.google.com.sa www.google.com.sb www.google.com.sg www.google.com.sl www.google.com.sv www.google.com.tj www.google.com.tr www.google.com.tw www.google.com.ua www.google.com.uy www.google.com.vc www.google.com.vn www.google.co.mz www.google.co.nz www.google.co.th www.google.co.tz www.google.co.ug www.google.co.uk www.google.co.uz www.google.co.ve www.google.co.za www.google.co.zm www.google.co.zw www.google.cv www.google.cz www.google.de www.google.dj www.google.dk www.google.dm www.google.dz www.google.ee www.google.es www.google.fi www.google.fr www.google.ga www.google.ge www.google.gg www.google.gm www.google.gr www.google.gy www.google.hn www.google.hr www.google.hu www.google.ie www.google.im www.google.iq www.google.is www.google.it www.google.je www.google.jo www.google.kg www.google.ki www.google.kz www.google.la www.google.li www.google.lk www.google.lt www.google.lu www.google.lv www.google.md www.google.me www.google.mg www.google.mk www.google.ml www.google.mn www.google.mu www.google.mv www.google.mw www.google.ne www.google.nl www.google.no www.google.pl www.google.ps www.google.pt www.google.ro www.google.rs www.google.ru www.google.rw www.google.sc www.google.se www.google.si www.google.sk www.google.sm www.google.sn www.google.so www.google.sr www.google.td www.google.tg www.google.tl www.google.tn www.google.tt google.com *.googlesyndication.com *.licdn.com *.linkedin.com *.magento.cloud *.mailplus.nl s3.amazonaws.com data: 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.sharethis.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.multisafepay.com https://pay.google.com m17.mailplus.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com songbird.cardinalcommerce.com www.xtento.com cdn.xtento.com 9292.nl *.bing.com *.clarity.ms *.cloudflare.com *.cookiebot.com *.cookiebot.eu *.googleadservices.com *.googlesyndication.com *.hotjar.com *.ipify.org *.licdn.com *.mailplus.nl *.marker.io *.oribi.io *.pinimg.com *.pinterest.com *.thinglink.me *.vimeo.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; style-src *.adobe.com *.sharethis.com fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.multisafepay.com unsafe-inline assets.braintreegateway.com *.mailplus.nl *.typekit.net *.vimeocdn.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.gstatic.com *.vimeocdn.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com *.sharethis.com *.googleapis.com *.google-analytics.com *.facebook.com *.facebook.net *.google.com *.multisafepay.com www.paypal.com www.sandbox.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com google.com t.elasticsuite.io 9292.nl *.alicdn.com *.bing.com *.bing.net *.clarity.ms *.cookiebot.com *.doubleclick.net *.googleadservices.com www.google.ad www.google.ae www.google.al www.google.am www.google.at www.google.az www.google.ba www.google.be www.google.bf www.google.bg www.google.bj www.google.by www.google.ca www.google.cd www.google.cg www.google.ch www.google.ci www.google.cl www.google.cm www.google.co.ao www.google.co.bw www.google.co.cr www.google.co.id www.google.co.il www.google.co.in www.google.co.jp www.google.co.ke www.google.co.kr www.google.co.ma www.google.com.af www.google.com.ag www.google.com.ar www.google.com.au www.google.com.bd www.google.com.bh www.google.com.bn www.google.com.bo www.google.com.br www.google.com.co www.google.com.cu www.google.com.cy www.google.com.do www.google.com.ec www.google.com.eg www.google.com.et www.google.com.fj www.google.com.gh www.google.com.gi www.google.com.gt www.google.com.hk www.google.com.jm www.google.com.kh www.google.com.kw www.google.com.lb www.google.com.ly www.google.com.mm www.google.com.mt www.google.com.mx www.google.com.my www.google.com.na www.google.com.ng www.google.com.ni www.google.com.np www.google.com.om www.google.com.pa www.google.com.pe www.google.com.pg www.google.com.ph www.google.com.pk www.google.com.py www.google.com.qa www.google.com.sa www.google.com.sg www.google.com.sl www.google.com.sv www.google.com.tr www.google.com.tw www.google.com.ua www.google.com.uy www.google.com.vc www.google.com.vn www.google.co.mz www.google.co.nz www.google.co.th www.google.co.tz www.google.co.ug www.google.co.uk www.google.co.uz www.google.co.ve www.google.co.za www.google.co.zm www.google.co.zw www.google.cv www.google.cz www.google.de www.google.dk www.google.dz www.google.ee www.google.es www.google.fi www.google.fr www.google.ga www.google.ge www.google.gg www.google.gr www.google.gy www.google.hn www.google.hr www.google.hu www.google.ie www.google.im www.google.iq www.google.is www.google.it www.google.jo www.google.kg www.google.ki www.google.kz www.google.la www.google.li www.google.lk www.google.lt www.google.lu www.google.lv www.google.md www.google.me www.google.mg www.google.mk www.google.mn www.google.mu www.google.mw www.google.nl www.google.no www.google.pl www.google.ps www.google.pt www.google.ro www.google.rs www.google.ru www.google.rw www.google.se www.google.si www.google.sk www.google.sn www.google.so www.google.sr www.google.tg www.google.tn www.google.tt *.googlesyndication.com *.gstatic.com *.hotjar.com *.hotjar.io *.jquery.com *.linkedin.com *.marker.io *.pinterest.com s3.ap-east-1.amazonaws.com s3.eu-west-1.amazonaws.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://95b39a76-7377-449c-a715-7f75d8431eb4.sansec.watch/; report-to report-endpoint; 1 default-src 'self' https:; font-src 'self' https: data:; img-src 'self' https: data: www.googletagmanager.com www.google-analytics.com *.contentsquare.net; object-src 'none'; script-src 'self' https: 'unsafe-inline' 'unsafe-eval' blob: www.googletagmanager.com www.google-analytics.com www.googleadservices.com d1stxfv94hrhia.cloudfront.net commondatastorage.googleapis.com d2wy8f7a9ursnm.cloudfront.net cdn.ckeditor.com t.contentsquare.net contentsquare.com secure.livechatinc.com; style-src 'self' https: 'unsafe-inline'; child-src blob: https://accounts.google.com https://www.google.com https://storage.googleapis.com https://www.googletagmanager.com/ https://www.paypalobjects.com https://*.paypal.com https://www.sandbox.paypal.com https://*.doubleclick.net https://www.facebook.com https://connect.facebook.com https://facebook.com https://service.force.com https://finditparts.my.site.com https://finditparts.my.salesforce.com https://secure.livechatinc.com https://app.dover.com/ https://app.dover.io/; worker-src blob:; frame-ancestors 'self' https://buttercms.com https://app.fullbay.com; connect-src 'self' https: http://localhost:3035 ws://localhost:3035 ws://localhost:3001/cable wss://www-build.finditparts.com/cable wss://www.finditparts.com/cable apis.google.com maps.googleapis.com cdn.jsdelivr.net code.jquery.com www.google-analytics.com *.attn.tv *.contentsquare.net *.webeyez.com firehose.eu-west-1.amazonaws.com cognito-identity.eu-west-1.amazonaws.com secure.livechatinc.com 1 object-src 'none'; connect-src 'self' *.evilangel.com cognito-identity.us-east-1.amazonaws.com backend.getbeamer.com *.comm100.io *.algolia.net insights.algolia.io *.algolianet.com *.gammaapis.com *.gammacdn.com analytics.google.com *.google-analytics.com adservice.google.com *.analytics.google.com *.doubleclick.net *.pubnub.com *.lovense.com *.handyfeeling.com www.gammaentertainment.com *.tiypa.com *.recombee.us dasasoveekepl.cloudfront.net capture.trackjs.com ws: jlduihq7lrcdxgw4vrndhdfcsq.appsync-api.us-east-1.amazonaws.com tcs4u525zrg5hnnoe5kzndxuaq.appsync-api.us-east-1.amazonaws.com xtnzefcqrb.execute-api.us-east-1.amazonaws.com 2aed6ghjsb4436qtebuqk3gfzq0xeauy.lambda-url.us-east-1.on.aws lzzos7clo5.execute-api.us-east-1.amazonaws.com *.izooto.com www.idealgasm.com 3tt0xhv5u7.execute-api.us-east-1.amazonaws.com; form-action 'self' *.evilangel.com join.gammasecure.com; script-src 'self' *.evilangel.com app.getbeamer.com static.getbeamer.com blob: vue.comm100.com standby.comm100vue.com *.gammacdn.com www.google-analytics.com www.googletagmanager.com www.gstatic.com www.google.com code.jquery.com d3a3ewgd1iewwz.cloudfront.net cdn.izooto.com 'unsafe-eval' 'unsafe-inline'; frame-src 'self' *.evilangel.com push.getbeamer.com app.getbeamer.com www.google.com *.doubleclick.net cdn.izooto.com *.banhq.com; report-uri https://csp-report.browser-intake-datadoghq.com/api/v2/logs?dd-api-key=pub787d5a6164b329b26f2e4f7956bbed10&dd-evp-origin=content-security-policy&ddsource=csp-prod&ddtags=CSP-Prod; 1 default-src 'self'; script-src 'self' https://code.jquery.com https://www.googletagmanager.com https://pxl-csumbedu.terminalfour.net https://static.hotjar.com https://script.hotjar.com https://cbe.capturehighered.net https://s.adroll.com https://d.adroll.com https://www.google.com https://cse.google.com https://www.gstatic.com https://siteimproveanalytics.com 'unsafe-inline'; style-src 'self' https://fonts.googleapis.com https://pxl-csumbedu.terminalfour.net https://www.google.com https://www.csuci.edu 'unsafe-inline'; font-src 'self' https://fonts.gstatic.com https://pxl-csumbedu.terminalfour.net data:; img-src 'self' https://www.csuci.edu https://pxl-csumbedu.terminalfour.net https://40230.global.siteimproveanalytics.io data:; media-src 'self' https://player.vimeo.com https://vimeocdn.com; connect-src 'self' https://region1.google-analytics.com https://content.hotjar.io wss://ws.hotjar.com; frame-src 'self' https://www.google.com; frame-ancestors 'self'; object-src 'none'; base-uri 'none'; 1 default-src 'none'; base-uri 'self'; child-src 'self' blob:; connect-src 'self' bam.nr-data.net links.services.disqus.com cdn.cookielaw.org api.segment.io *.mapbox.com *.mux.com analytics.google.com www.google-analytics.com geolocation.onetrust.com wss: bat.bing.com *.clarity.ms wahoofitness-us.attn.tv wahoofitness.attn.tv events.attentivemobile.com stats.g.doubleclick.net region1.analytics.google.com www.google.com privacyportal.onetrust.com api.rudderstack.com vc.hotjar.io region1.google-analytics.com www.google.cz www.google.au cdn.segment.com fonts.googleapis.com cdn.wahooligan.com www.google.no *.wahooligan.com; font-src 'self' cdn.wahooligan.com fonts.gstatic.com moz-extension data:; form-action 'self' www.wahooligan.com *.wahoofitness.com wahoofitness.zendesk.com api.wahooligan.com www.facebook.com bat.bing.com n.clarity.ms analytics.google.com wahoofitness.centercode.com api.wahooligan.com/oauth/authorize api.staging.wahooligan.com/oauth/authorize *.wahooligan.com; frame-ancestors 'self' *.zendesk.com *.wahooligan.com *.wahoofitness.com; frame-src 'self' disqus.com metabase.wahooligan.com www.youtube-nocookie.com js.stripe.com www.googletagmanager.com td.doubleclick.net www.facebook.com; img-src * data: blob:; media-src blob:; script-src 'self' 'unsafe-inline' 'unsafe-eval' cdn.wahooligan.com www.google-analytics.com api.tiles.mapbox.com code.jquery.com cdn.segment.com cdnjs.cloudflare.com js.stripe.com js-agent.newrelic.com bam.nr-data.net bam.nr-data.com *.zendesk.com static.zdassets.com cdn.cookielaw.org c.disquscdn.com optanon.blob.core.windows.net www.gstatic.com www.googletagmanager.com cdn.rudderlabs.com data: *.wahooligan.com; script-src-elem 'self' 'unsafe-inline' cdn.wahooligan.com code.jquery.online code.jquery.com cdn.cookielaw.org cdn.segment.com bam.nr-data.com bam.nr-data.net www.googletagmanager.com js-agent.newrelic.com optanon.blob.core.windows.net assets.zendesk.com static.zdassets.com www.google-analytics.com api.tiles.mapbox.com cdnjs.cloudflare.com geolocation.onetrust.com www.gstatic.com js.stripe.com cdn.rudderlabs.com cdn.attn.tv *.zendesk.com www.clarity.ms script.hotjar.com static.hotjar.com resources.xg4ken.com googleads.g.doubleclick.net bat.bing.com connect.facebook.net n.clarity.ms analytics.google.com *.wahooligan.com; style-src 'self' 'unsafe-inline' fonts.gstatic.com cdn.cookielaw.org fonts.googleapis.com api.tiles.mapbox.com cdn.wahooligan.com c.disquscdn.com www.gstatic.com; style-src-elem 'self' 'unsafe-inline' cdn.wahooligan.com cdn.cookielaw.org assets.zendesk.com api.tiles.mapbox.com fonts.googleapis.com www.gstatic.com connect.facebook.net cdnjs.cloudflare.com; report-uri https://www.wahooligan.com/csp_reports 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.cloudflare.com *.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.twitter.com *.authorize.net *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.authorize.net 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com *.facebook.com *.twitter.com *.authorize.net c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.cloudflare.com *.cloudfront.net *.baen.com *.twitter.com *.twimg.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.cloudflare.com *.twitter.com *.twimg.com *.fontawesome.com *.facebook.net *.authorize.net *.simpli.fi js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.cloudflare.com *.fontawesome.com *.bootstrapcdn.com *.gstatic.com *.twitter.com *.twimg.com assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.cloudflare.com *.authorize.net *.doubleclick.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src d.digsgogo.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.klevu.com *.ksearchnet.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com *.googlesyndication.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://d1pna5l3xsntoj.cloudfront.net https://helloretailcdn.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.googlesyndication.com *.roeye.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com *.klevu.com *.ksearchnet.com *.maksuturva.fi data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com https://core.helloretail.com https://d1pna5l3xsntoj.cloudfront.net https://helloretailcdn.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com *.jsdelivr.net chimpstatic.com downloads.mailchimp.com *.list-manage.com *.klevu.com *.ksearchnet.com *.maksuturva.fi https://script.custobar.com https://script.custobar.com/nf3ax/custobar-k7wdkh46linx.js 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://d1pna5l3xsntoj.cloudfront.net https://helloretailcdn.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com downloads.mailchimp.com *.klevu.com *.ksearchnet.com maxcdn.bootstrapcdn.com https://js.klevu.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com https://core.helloretail.com https://helloretailcdn.com *.google-analytics.com *.facebook.com *.facebook.net *.doubleclick.net *.googlesyndication.com *.klevu.com *.ksearchnet.com *.maksuturva.fi https://api.custobar.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src * https: data: blob: 'unsafe-inline' 'unsafe-hashes'; 1 object-src 'none';base-uri 'self';script-src 'nonce-0m7JHWGgQ20pfWGfeYAdPQ' 'strict-dynamic' 'report-sample' 'unsafe-eval' 'unsafe-inline' https: http:;report-uri https://csp.withgoogle.com/csp/gws/other-hp 1 default-src 'self' blob: data: 'unsafe-inline' 'unsafe-eval' ws: *.nexiuslearning.com *.google-analytics.com *.etitan.hu *.googletagmanager.com *.googleapis.com *.gstatic.com *.google.com *.bootstrapcdn.com *.extremenet.hu stats.g.doubleclick.net www.youtube-nocookie.com; report-uri https://etitancsp.azurewebsites.net/api/eTitanCSP; 1 default-src 'self' csp-id-produzione-v20; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://maxcdn.bootstrapcdn.com https://www.iubenda.com https://creditoemiliano.germany-2.evergage.com; img-src * data: blob:; script-src-elem 'self' 'unsafe-inline' blob: https://sslwidget.criteo.com https://ajax.googleapis.com https://www.googletagmanager.com https://maps.googleapis.com https://assets.adobedtm.com https://*.iubenda.com https://connect.facebook.net https://*.criteo.com https://cdn.evgnet.com https://secure.quantserve.com https://www.dwin1.com https://*.quantcount.com https://*.teads.tv https://tags.creativecdn.com https://apis.google.com https://platform.twitter.com https://maxcdn.bootstrapcdn.com https://*.adform.net https://*.iubenda.com https://connect.facebook.net https://creditoemiliano.germany-2.evergage.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://maps.googleapis.com https://credem.demdex.net https://cdn.iubenda.com https://apps.mypurecloud.de https://assets.adobedtm.com https://www.googletagmanager.com https://cdn.evgnet.com https://cs.iubenda.com https://www.dwin1.com https://tags.creativecdn.com https://dynamic.criteo.com https://p.teads.tv https://connect.facebook.net https://secure.quantserve.com https://rules.quantcount.com https://apis.google.com https://platform.twitter.com https://sslwidget.criteo.com https://*.adform.net https://maxcdn.bootstrapcdn.com; frame-src 'self' https://cdn.iubenda.com https://apps.mypurecloud.de https://*.fls.doubleclick.net https://gum.criteo.com https://credem.demdex.net https://accounts.google.com https://platform.twitter.com https://*.youtube.com https://static.criteo.net https://*.adform.net https://documentcloud.adobe.com; connect-src 'self' https://idb.iubenda.com wss://aichatbot.youandemili.com https://aichatbot.youandemili.com https://credem.tt.omtrdc.net https://maps.googleapis.com https://api-cdn.mypurecloud.de https://creditoemiliano.germany-2.evergage.com https://analytics.google.com https://*.analytics.google.com https://*.google-analytics.com https://ad.doubleclick.net https://*.doubleclick.net https://pagead2.googlesyndication.com https://*.teads.tv https://ams.creativecdn.com https://pixel.quantserve.com https://dpm.demdex.net https://www.google.com https://www.google.it https://www.google.de https://www.google.fr https://www.google.es https://www.google.co.uk https://www.google.ca https://www.google.pl https://www.google.be https://www.google.ch https://www.google.at https://www.google.nl https://www.google.pt https://www.google.se https://www.google.com.br https://www.google.com.mx https://www.google.co.jp https://www.google.com.au https://www.google.co.in https://www.google.co.kr https://www.google.com.sg https://www.google.gr https://www.google.ro https://www.google.dk https://www.google.no https://www.googleadservices.com https://cpl.iubenda.com https://www.googletagmanager.com https://sslwidget.criteo.com https://www.facebook.com https://pixel.quantcount.com https://viewlicense.adobe.io https://translate.googleapis.com; font-src 'self' data: ms-browser-extension: chrome-extension: https://fonts.gstatic.com https://maxcdn.bootstrapcdn.com; 1 default-src 'self' https:; script-src 'self' 'unsafe-eval' https://www.googletagmanager.com https://*.google-analytics.com https://*.googleadservices.com https://*.company-target.com https://a.omappapi.com https://stage-cms-portal.quest.com https://www.quest.com https://*.qualified.com https://*.ddev.site https://cdn.cookielaw.org https://app.qualified.com https://*.qualified.com https://cdn.cookielaw.org https://s.company-target.com 'nonce-A8mIrdXDneY5DS11UbJBQh_kckjX7wL8'; object-src 'none'; style-src 'self' 'unsafe-inline' *.google.com *.userway.org *.googleapis.com *.analysis.windows.net *.twitter.com *.nr-data.net *.youtube.com *.youtube-nocookie.com *.vimeo.com *.pagespeed-mod.com *.googletagmanager.com *.gstatic.com *.sharethis.com *.gleap.io *.cloudflare.com *.jsdelivr.net *.gitbook.com *.omappapi.com/; img-src 'self' 'unsafe-inline' https: data: quest.com *.quest.com blob:; media-src 'self' 'unsafe-inline' quest.com *.quest.com; frame-src 'self' 'unsafe-inline' *.webp *.twitter.com *.youtube.com *.youtube-nocookie.com *.facebook.com facebook.com *.nr-data.net *.youtube.com *.vimeo.com *.googletagmanager.com *.gleap.io *.company-target.com players.brightcove.net *.gitbook.io https://app.qualified.com; frame-ancestors 'self' *.google.com *.google-analytics.com *.analysis.windows.net *.googleapis.com *.twitter.com *.nr-data.net *.youtube.com *.youtube-nocookie.com *.vimeo.com *.pagespeed-mod.com *.googletagmanager.com *.gstatic.com *.sharethis.com *.gleap.io *.company-target.com; child-src *; font-src 'self' *.googleapis.com *.typekit.net *.userway.org *.analysis.windows.net *.gstatic.com *.twitter.com *.nr-data.net *.youtube.com *.youtube-nocookie.com *.vimeo.com *.pagespeed-mod.com *.googletagmanager.com data *.sharethis.com *.google.com *.gleap.io *.jsdelivr.net *.cloudflare.com; connect-src 'self' *.google-analytics.com *.vardot.com https: *.gleap.io 1 report-uri https://csp.withgoogle.com/csp/youtube_main/strict;base-uri 'self';object-src 'none';script-src 'report-sample' 'nonce-yutJjl5tIVq4dA7YIXhy1g' 'unsafe-inline' 'strict-dynamic' https: http: 'unsafe-eval' 1 default-src 'self';base-uri 'self';frame-ancestors 'self';frame-src https://* 'self' epichttp:;script-src 'nonce-356c546100694b2a911e3330a36ba4e0' https://www.maisa.fi 'self' https://apomato.maisa.fi/matomo/matomo.js;img-src https://* 'self' blob: data:;connect-src 'self' epichttp: https://apomato.maisa.fi/matomo/matomo.js https://apomato.maisa.fi/matomo/matomo.php;style-src https://www.maisa.fi 'self' 'unsafe-inline';worker-src 'self' blob:;child-src 'self' blob:;form-action 'self' https://testi.apro.tunnistus.fi https://tunnistautuminen.suomi.fi https://www.terveyskyla.fi;media-src https://* 'self' blob:; 1 default-src 'self' data: *.wroclaw.pl *.cookiebot.com *.google.com *.googleapis.com *.googletagmanager.com *.google-analytics.com *.youtube.com *.youtube-nocookie.com *.ytimg.com *.facebook.com *.fbcdn.net *.googleusercontent.com fonts.gstatic.com https://unpkg.com *.curator.io https://curator-assets.b-cdn.net *.amazonaws.com https://api.mapbox.com https://callme360.com *.doubleclick.net https://cdn.jsdelivr.net *.googlesyndication.com *.openstreetmap.org *.cloudflare.com https://cdn.gravitec.net *.crazyegg.com *.gemius.pl *.criteo.com *.criteo.net *.optad360.net *.google.pl *.cloudflareinsights.com *.clarity.ms *.newrelic.com *.gravitec.media *.crwdcntrl.net *.openxcdn.net *.nr-data.net *.optad360-video.com optad360-video.com *.adtrafficquality.google *.googleadservices.com *.2mdn.net *.facebook.net *.slideshare.net; script-src 'self' 'unsafe-inline' 'unsafe-eval' blob: *.wroclaw.pl *.googleapis.com *.cookiebot.com *.google.com *.googletagmanager.com *.google-analytics.com *.youtube.com *.ytimg.com *.facebook.net https://unpkg.com *.juicer.io *.curator.io https://api.mapbox.com *.jsdelivr.net *.cloudflare.com *.highcharts.com *.statsforads.com *.optad360.io *.doubleclick.net https://callme360.com *.gstatic.com https://cdn.gravitec.net *.crazyegg.com *.gemius.pl *.criteo.com *.criteo.net *.cloudflareinsights.com *.clarity.ms *.newrelic.com *.gravitec.media *.crwdcntrl.net *.openxcdn.net *.nr-data.net *.adtrafficquality.google *.googleadservices.com *.googlesyndication.com *.2mdn.net; style-src 'self' 'unsafe-inline' *.wroclaw.pl *.googleapis.com *.google.com https://unpkg.com *.curator.io https://api.mapbox.com https://callme360.com *.cloudflare.com *.jsdelivr.net https://cdn.jsdelivr.net; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com *.klarnacdn.net *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com https://geowidget.easypack24.net *.easypack24.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com *.googlesyndication.com *.tiktok.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com secure.payu.com merch-prod.snd.payu.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.klarna.com https://geowidget-app.inpost.pl/ https://lilou-configurator.netlify.app exchange.mediavine.com ams.creativecdn.com tags.creativecdn.com *.criteo.com *.criteo.net facebook.com 'unsafe-inline' data: 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://images.unsplash.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.googlesyndication.com *.roeye.com *.tiktok.com static.payu.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.klarna.com *.klarnaevt.com *.klarnacdn.net https://firebasestorage.googleapis.com https://geowidget.easypack24.net *.easypack24.net *.inpost.pl *.openstreetmap.org *.hsforms.net *.hsforms.com *.cdninstagram.com *.google.pl google.com google.pl *.criteo.com *.criteo.net https: data: data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://maps.googleapis.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com *.jsdelivr.net *.tiktok.com secure.payu.com secure.snd.payu.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.klarna.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com https://d3bo67muzbfgtl.cloudfront.net https://sentry.lilou.pl *.avada.io *.shopify.com https://geowidget.easypack24.net *.easypack24.net *.inpost.pl *.openstreetmap.org *.hsforms.net *.hsforms.com *.sentry-cdn.com exchange.mediavine.com unpkg.com *.mapbox.com furgonetka.pl *.hotjar.com *.criteo.com *.criteo.net *.cloudflareinsights.com *.wp.pl *.clickonometrics.pl bat.bing.com tags.creativecdn.com ams.creativecdn.com lib.onet.pl sgqcvfjvr.onet.pl events.onet.pl events.ocdn.eu clarity.ms *.clarity.ms 'unsafe-inline' 'unsafe-eval' www.googletagmanager.com cdngazeta.pl 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com *.tiktok.com assets.braintreegateway.com *.klarnacdn.net https://d3bo67muzbfgtl.cloudfront.net *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com https://geowidget.easypack24.net https://geowidget.inpost.pl *.easypack24.net *.openstreetmap.org lilouparis.test lilou.test *.lilouparis.com *.lilou.pl 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com https://geowidget.easypack24.net 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io https://maps.googleapis.com https://player.vimeo.com *.google-analytics.com *.facebook.com *.facebook.net *.doubleclick.net *.googlesyndication.com *.tiktok.com secure.payu.com merch-prod.snd.payu.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.klarnaevt.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.klarna.com https://api.edrone.me https://sentry.lilou.pl https://get.geojs.io *.avada.io *.easypack24.net *.inpost.pl *.openstreetmap.org t.elasticsuite.io *.hsforms.net *.hsforms.com *.sentry-cdn.com *.wp.pl exchange.mediavine.com bat.bing.com bat.bing.net ams.creativecdn.com tags.creativecdn.com measurement-api.criteo.com api-s.edrone.me events.ocdn.eu *.googleadservices.com *.google.pl *.googletagmanager.com health.ems.onet.pl content.hotjar.io hotjar.com wss://ws.hotjar.com *.onet.pl analytics-ipv6.tiktokw.us *.gazeta.pl clk.leadexpert.pl 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com bat.bing.com google.com exchange.mediavine.com www.googletagmanager.com tags.creativecdn.com ams.creativecdn.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 frame-ancestors 'self'; report-uri https://www.themercury.com.au/csp-reports 1 default-src 'self' *.wargaming.net *.wgprod.net https://*.wgcdn.co https://*.gcdn.co https://www.youtube.com ; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.wargaming.net *.wgprod.net *.tvsquared.com *.cookielaw.org *.onetrust.com *.outbrain.com *.snapchat.com *.redditstatic.com s.yimg.jp https://sc-static.net https://ob.cheqzone.com https://analytics.google.com https://www.google.com https://www.google.com.cy https://*.adform.net https://partner.worldoftanks.com https://*.wgcdn.co https://*.gcdn.co https://www.googleoptimize.com https://www.googletagmanager.com https://*.google-analytics.com https://*.analytics.google.com https://www.googleadservices.com https://u360.d-bi.fr https://bat.bing.com https://connect.facebook.net https://googleads.g.doubleclick.net https://*.adroll.com https://*.addthis.com https://*.addthisedge.com https://tag.marinsm.com https://pixel-geo.prfct.co https://static.criteo.net https://stackadapt.com https://*.creative-serving.com https://*.criteo.com https://*.cloudfront.net https://js.gleam.io https://a1.adform.net https://ajax.googleapis.com https://www.youtube.com https://animate.adobe.com https://*.stackadapt.com https://pagead2.googlesyndication.com https://secure.quantserve.com https://rules.quantcount.com https://*.clarity.ms s.yimg.jp cdn.taboola.com ; style-src 'self' 'unsafe-inline' *.wargaming.net *.wgprod.net https://fonts.googleapis.com https://*.wgcdn.co https://*.gcdn.co ; img-src 'self' data: android-webview-video-poster: * ; connect-src 'self' *.wargaming.net *.wgprod.net *.cookielaw.org *.onetrust.com *.outbrain.com *.snapchat.com s.yimg.jp https://*.worldoftanks.com https://*.worldoftanks.eu https://*.worldoftanks.asia https://*.wgcdn.co https://sc-static.net https://ob.cheqzone.com https://analytics.google.com https://www.google.com wss://worldoftanks.eu wss://worldoftanks.asia wss://worldoftanks.com https://*.facebook.com https://www.googleoptimize.com https://*.addthis.com https://*.google-analytics.com https://*.analytics.google.com https://ymetrica1.com https://*.cloudfront.net https://google.com https://google.com.ua https://google.pl https://*.doubleclick.net https://*.googleapis.com https://pagead2.googlesyndication.com https://*.clarity.ms s.yimg.jp https://collect.worldoftanks.asia https://content-wg.gcdn.co https://api.worldoftanks.asia https://bat.bing.com ; font-src 'self' *.wargaming.net *.wgprod.net https://fonts.gstatic.com https://*.wgcdn.co https://*.gcdn.co ; media-src 'self' *.wargaming.net *.wgprod.net https://*.wgcdn.co https://*.gcdn.co ; frame-src 'self' *.wargaming.net *.wgprod.net https://tr.snapchat.com https://creativecdn.com https://*.adform.net https://*.facebook.com https://ad3.adfarm1.adition.com https://connect.facebook.net https://www.youtube.com https://bid.g.doubleclick.net https://*.criteo.com https://*.addthis.com https://gleam.io https://*.gcdn.co https://*.wgcdn.co https://aax-eu.amazon-adsystem.com ; object-src 'self' *.wargaming.net *.wgprod.net https://*.gcdn.co https://www.youtube.com ; report-uri https://cspreport.wargaming.net/cspreport 1 frame-src 'none' 1 default-src 'self'; base-uri 'self'; object-src 'none'; frame-ancestors 'self'; upgrade-insecure-requests; block-all-mixed-content; img-src 'self' data: https:; font-src 'self' data: https:; script-src 'self' 'unsafe-inline' https://hcaptcha.com https://*.hcaptcha.com https://consent.cookiebot.com https://consentcdn.cookiebot.com https://consentcdn.cookiebot.eu https://www.googletagmanager.com https://www.google-analytics.com; frame-src 'self' https://hcaptcha.com https://*.hcaptcha.com https://consent.cookiebot.com https://consentcdn.cookiebot.com https://consentcdn.cookiebot.eu; style-src 'self' 'unsafe-inline' https://hcaptcha.com https://*.hcaptcha.com https://consent.cookiebot.com https://consentcdn.cookiebot.com https://consentcdn.cookiebot.eu; connect-src 'self' https://hcaptcha.com https://*.hcaptcha.com https://consent.cookiebot.com https://consentcdn.cookiebot.com https://consentcdn.cookiebot.eu https://www.google-analytics.com 1 manifest-src 'self' *.gosh.nhs.uk; script-src-elem 'self' 'unsafe-inline' 'unsafe-eval' 'strict-dynamic' https: http: 'report-sample' *.gosh.nhs.uk www.gosh.nhs.uk feeds.trac.jobs *.googletagmanager.com www.cqc.org.uk e.issuu.com 'nonce-eUYxNBJSJiz+utvPo6umxg=='; font-src 'self' https://fonts.gstatic.com script.hotjar.com https://fonts.googleapis.com data:; script-src 'self' 'unsafe-inline' 'unsafe-eval' 'strict-dynamic' https: http: 'report-sample' https://www.googletagmanager.com https://www.google.co.uk https://www.google.com https://feeds.trac.jobs feeds.trac.jobs 'nonce-eUYxNBJSJiz+utvPo6umxg=='; img-src 'self' data: *.gosh.nhs.uk *.google-analytics.com *.googletagmanager.com i.ytimg.com *.cqc.org.uk *.gstatic.com *.google.com stats.g.doubleclick.net feeds.trac.jobs https://static.trac.jobs static.trac.jobs healthjobsuk.com services.postcodeanywhere.co.uk dx4nr741tfc02.cloudfront.net www.healthjobsuk.com 'sha384-YephmBv2489Q13yLaARSHqhDtSlHeIs5DEiq8I1fyh4aQcG+nRoz5Y6eWndd5cVz' *.onetrust.com cdn-ukwest.onetrust.com script.hotjar.com survey-images.hotjar.com www.google.com www.google.ad www.google.ae www.google.com.af www.google.com.ag www.google.com.ai www.google.al www.google.am www.google.co.ao www.google.com.ar www.google.as www.google.at www.google.com.au www.google.az www.google.ba www.google.com.bd www.google.be www.google.bf www.google.bg www.google.com.bh www.google.bi www.google.bj www.google.com.bn www.google.com.bo www.google.com.br www.google.bs www.google.bt www.google.co.bw www.google.by www.google.com.bz www.google.ca www.google.cd www.google.cf www.google.cg www.google.ch www.google.ci www.google.co.ck www.google.cl www.google.cm www.google.cn www.google.com.co www.google.co.cr www.google.com.cu www.google.cv www.google.com.cy www.google.cz www.google.de www.google.dj www.google.dk www.google.dm www.google.com.do www.google.dz www.google.com.ec www.google.ee www.google.com.eg www.google.es www.google.com.et www.google.fi www.google.com.fj www.google.fm www.google.fr www.google.ga www.google.ge www.google.gg www.google.com.gh www.google.com.gi www.google.gl www.google.gm www.google.gr www.google.com.gt www.google.gy www.google.com.hk www.google.hn www.google.hr www.google.ht www.google.hu www.google.co.id www.google.ie www.google.co.il www.google.im www.google.co.in www.google.iq www.google.is www.google.it www.google.je www.google.com.jm www.google.jo www.google.co.jp www.google.co.ke www.google.com.kh www.google.ki www.google.kg www.google.co.kr www.google.com.kw www.google.kz www.google.la www.google.com.lb www.google.li www.google.lk www.google.co.ls www.google.lt www.google.lu www.google.lv www.google.com.ly www.google.co.ma www.google.md www.google.me www.google.mg www.google.mk www.google.ml www.google.com.mm www.google.mn www.google.ms www.google.com.mt www.google.mu www.google.mv www.google.mw www.google.com.mx www.google.com.my www.google.co.mz www.google.com.na www.google.com.ng www.google.com.ni www.google.ne www.google.nl www.google.no www.google.com.np www.google.nr www.google.nu www.google.co.nz www.google.com.om www.google.com.pa www.google.com.pe www.google.com.pg www.google.com.ph www.google.com.pk www.google.pl www.google.pn www.google.com.pr www.google.ps www.google.pt www.google.com.py www.google.com.qa www.google.ro www.google.ru www.google.rw www.google.com.sa www.google.com.sb www.google.sc www.google.se www.google.com.sg www.google.sh www.google.si www.google.sk www.google.com.sl www.google.sn www.google.so www.google.sm www.google.sr www.google.st www.google.com.sv www.google.td www.google.tg www.google.co.th www.google.com.tj www.google.tl www.google.tm www.google.tn www.google.to www.google.com.tr www.google.tt www.google.com.tw www.google.co.tz www.google.com.ua www.google.co.ug www.google.co.uk www.google.com.uy www.google.co.uz www.google.com.vc www.google.co.ve www.google.vg www.google.co.vi www.google.com.vn www.google.vu www.google.ws www.google.rs www.google.co.za www.google.co.zm www.google.co.zw www.google.cat; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://*.doubleclick.net www.google.co.uk https://analytics.google.com https://vc.hotjar.io https://in.hotjar.com https://content.hotjar.io https://csmetrics.hotjar.com metrics.hotjar.io wss://ws.hotjar.com surveystats.hotjar.io https://feeds.trac.jobs sentry.issuu.com stats.g.doubleclick.net translate.googleapis.com *.onetrust.com cdn-ukwest.onetrust.com adservice.google.com https://ask.hotjar.io www.googleadservices.com www.google.com www.google.ad www.google.ae www.google.com.af www.google.com.ag www.google.com.ai www.google.al www.google.am www.google.co.ao www.google.com.ar www.google.as www.google.at www.google.com.au www.google.az www.google.ba www.google.com.bd www.google.be www.google.bf www.google.bg www.google.com.bh www.google.bi www.google.bj www.google.com.bn www.google.com.bo www.google.com.br www.google.bs www.google.bt www.google.co.bw www.google.by www.google.com.bz www.google.ca www.google.cd www.google.cf www.google.cg www.google.ch www.google.ci www.google.co.ck www.google.cl www.google.cm www.google.cn www.google.com.co www.google.co.cr www.google.com.cu www.google.cv www.google.com.cy www.google.cz www.google.de www.google.dj www.google.dk www.google.dm www.google.com.do www.google.dz www.google.com.ec www.google.ee www.google.com.eg www.google.es www.google.com.et www.google.fi www.google.com.fj www.google.fm www.google.fr www.google.ga www.google.ge www.google.gg www.google.com.gh www.google.com.gi www.google.gl www.google.gm www.google.gr www.google.com.gt www.google.gy www.google.com.hk www.google.hn www.google.hr www.google.ht www.google.hu www.google.co.id www.google.ie www.google.co.il www.google.im www.google.co.in www.google.iq www.google.is www.google.it www.google.je www.google.com.jm www.google.jo www.google.co.jp www.google.co.ke www.google.com.kh www.google.ki www.google.kg www.google.co.kr www.google.com.kw www.google.kz www.google.la www.google.com.lb www.google.li www.google.lk www.google.co.ls www.google.lt www.google.lu www.google.lv www.google.com.ly www.google.co.ma www.google.md www.google.me www.google.mg www.google.mk www.google.ml www.google.com.mm www.google.mn www.google.ms www.google.com.mt www.google.mu www.google.mv www.google.mw www.google.com.mx www.google.com.my www.google.co.mz www.google.com.na www.google.com.ng www.google.com.ni www.google.ne www.google.nl www.google.no www.google.com.np www.google.nr www.google.nu www.google.co.nz www.google.com.om www.google.com.pa www.google.com.pe www.google.com.pg www.google.com.ph www.google.com.pk www.google.pl www.google.pn www.google.com.pr www.google.ps www.google.pt www.google.com.py www.google.com.qa www.google.ro www.google.ru www.google.rw www.google.com.sa www.google.com.sb www.google.sc www.google.se www.google.com.sg www.google.sh www.google.si www.google.sk www.google.com.sl www.google.sn www.google.so www.google.sm www.google.sr www.google.st www.google.com.sv www.google.td www.google.tg www.google.co.th www.google.com.tj www.google.tl www.google.tm www.google.tn www.google.to www.google.com.tr www.google.tt www.google.com.tw www.google.co.tz www.google.com.ua www.google.co.ug www.google.co.uk www.google.com.uy www.google.co.uz www.google.com.vc www.google.co.ve www.google.vg www.google.co.vi www.google.com.vn www.google.vu www.google.ws www.google.rs www.google.co.za www.google.co.zm www.google.co.zw www.google.cat; frame-src 'self' https://www.google.com https://www.youtube.com https://vars.hotjar.com www.googletagmanager.com e.issuu.com *.recaptcha.net td.doubleclick.net; base-uri 'self'; style-src 'self' 'report-sample' 'unsafe-inline' services.postcodeanywhere.co.uk fonts.googleapis.com feeds.trac.jobs www.cqc.org.uk www.gstatic.com; object-src 'none'; default-src 'self' *.gosh.nhs.uk; media-src 'self' gosh.shorthandstories.com cdn.plyr.io data: media.gosh.nhs.uk ssl.gstatic.com *.s3.amazonaws.com; report-uri https://o516378.ingest.sentry.io/api/5622733/security/?sentry_key=c5f8a650e74b48a889ccadeaa5014261&sentry_environment=production 1 default-src 'self'; script-src 'nonce-45760b40-3dc8-411f-b27c-c73be9883b91' 'self' 'strict-dynamic'; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://fonts.gstatic.com https://*.aptrinsic.com https://*.bevylabs.com https://*.osano.com https://*.brainfi.sh; font-src 'self' data: https://*.bevylabs.com https://fonts.googleapis.com https://fonts.gstatic.com https://res.cloudinary.com https://*.brainfi.sh; img-src 'self' data: blob: https://unpkg.com https://*.aptrinsic.com https://*.bevylabs.com https://*.cloudinary.com https://*.facebook.com https://*.google-analytics.com https://*.gstatic.com https://*.googleapis.com https://storage.googleapis.com https://*.googleusercontent.com https://*.googletagmanager.com https://px.ads.linkedin.com https://www.googletagmanager.com https://www.startupgrind.com https://image.mux.com https://img.youtube.com https://i.ytimg.com https://*.vidyard.com https://i.vimeocdn.com https://cdn.bizible.com https://*.lrkt-in.com https://*.litix.io https://cdn.prod.website-files.com https://*.brainfi.sh https://*.adroll.com https://ml314.com https://x.bidswitch.net https://pixel.tapad.com https://pixel.rubiconproject.com https://ps.eyeota.net https://idsync.rlcdn.com https://dsum-sec.casalemedia.com https://us-u.openx.net https://sync.outbrain.com https://sync.taboola.com https://eb2.3lift.com https://image2.pubmatic.com https://ib.adnxs.com https://secure.adnxs.com https://match.adsrvr.org https://t.co https://*.twitter.com https://*.ads-twitter.com https://*.reddit.com https://*.redditstatic.com https://alb.reddit.com https://*.hubspot.com https://*.hubapi.com https://track.hubspot.com https://www.google.com.mx https://www.google.com.ph https://www.google.co.uk https://www.google.fr https://www.google.nl https://www.google.es https://www.google.it https://www.google.pt https://www.google.co.cr https://www.google.co.ke https://www.google.com.ar https://www.google.com.co https://www.google.com.eg https://www.google.com.pe https://www.google.sk https://www.google.kg; frame-src 'self' https://*.cloud.looker.com https://*.google.com https://*.osano.com https://*.youtube.com https://*.exceedlms.com https://embed-cdn.spotifycdn.com https://exceedlms.com https://js.stripe.com/ https://player.vimeo.com https://static.elfsight.com/platform/platform.js https://td.doubleclick.net/ https://www.google.com/recaptcha/ https://recaptcha.google.com/recaptcha/ https://www.slideshare.net/ https://bevywidgets.com https://play.vidyard.com https://*.googletagmanager.com https://*.brainfi.sh; connect-src 'self' blob: data: wss: https://*.algolia.io https://*.algolia.net https://*.algolianet.com https://*.aptrinsic.com https://*.bevylabs.com https://*.cloudinary.com https://*.google-analytics.com https://*.google.com https://*.gstatic.com https://*.lr-ingest.io https://*.logrocket.io https://*.lrkt-in.com https://*.mux.com https://*.litix.io https://*.osano.com https://*.posthog.com https://*.rollbar.com https://*.stripe.com https://*.zdassets.com https://*.zendesk.com https://*.daily.co https://*.googleapis.com https://*.pluot.blue https://chat.stream-io-api.com https://px.ads.linkedin.com https://stats.g.doubleclick.net https://www.googletagmanager.com https://*.mktoresp.com https://*.fides-cdn.ethyca.com https://*.ethyca.com https://*.brainfi.sh wss://*.brainfi.sh https://*.reddit.com https://*.redditstatic.com https://*.hubspot.com https://*.hubapi.com https://*.hs-scripts.com https://*.hsadspixel.net https://*.hs-banner.com https://*.hs-analytics.net https://*.hotjar.com https://*.hotjar.io https://*.googlesyndication.com https://www.google.com.mx https://www.google.com.ph https://www.google.co.uk https://www.google.fr https://www.google.nl https://www.google.es https://www.google.it https://www.google.pt https://www.google.co.cr https://www.google.co.ke https://www.google.com.ar https://www.google.com.co https://www.google.com.eg https://www.google.com.pe https://www.google.sk https://www.google.kg; media-src 'self' blob: https://*.mux.com; worker-src 'self' blob:; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self' https://*.bevy.com; upgrade-insecure-requests; report-uri /api/csp-report/ 1 default-src 'none'; script-src 'unsafe-eval'; script-src-elem 'self' 'unsafe-inline' ajax.googleapis.com cdn.parsely.com cookie-cdn.cookiepro.com www.queryly.com browser.sentry-cdn.com connect.facebook.net js.sentry-cdn.com uschamber.tfaforms.net www.google.com www.googletagmanager.com api.queryly.com cms.www.uschamber.com co-admin.uschamber.com googleads.g.doubleclick.net in.ml314.com ml314.com secure.wufoo.com snap.licdn.com static.ads-twitter.com tags.srv.stackadapt.com www.gstatic.com www.youtube.com; script-src-attr 'unsafe-inline'; style-src-elem 'self' 'unsafe-inline' fonts.googleapis.com uschamber.tfaforms.net code.jquery.com tags.srv.stackadapt.com; style-src-attr 'unsafe-inline'; img-src 'self' data: uschamberfoundation.imgix.net cookie-cdn.cookiepro.com p1.parsely.com www.facebook.com www.googletagmanager.com www.queryly.com dpm.demdex.net ib.adnxs.com idsync.rlcdn.com match.adsrvr.org ps.eyeota.net px.ads.linkedin.com s3.us-east-1.amazonaws.com t.co us-u.openx.net uschamber-co.imgix.net uschamber.imgix.net www.google.com www.uschamber.com chamber-foundation.files.svdcdn.com data.queryly.com; font-src 'self' data: fonts.gstatic.com; connect-src 'self' cookie-cdn.cookiepro.com www.google-analytics.com analytics.formassembly.com p1.parsely.com uschamberfoundation.imgix.net o4507211308007424.ingest.us.sentry.io analytics.google.com content.hotjar.io px.ads.linkedin.com region1.analytics.google.com stats.g.doubleclick.net tags.srv.stackadapt.com www.facebook.com www.google.com www.googleadservices.com region1.google-analytics.com www.googletagmanager.com; object-src 'none'; frame-src www.google.com www.googletagmanager.com www.youtube.com 'self'; worker-src blob:; frame-ancestors 'none'; form-action 'self'; base-uri 'self'; manifest-src 'self'; report-uri https://uschamber.report-uri.com/r/t/csp/wizard; 1 default-src 'self' https: data: 'unsafe-inline' 'unsafe-eval'; img-src https: data:; report-uri https://www.milestonesys.com/csp/report 1 default-src * 'unsafe-inline' 'unsafe-eval'; img-src * data:; report-uri /report-csp-violation; upgrade-insecure-requests 1 object-src 'none'; script-src 'nonce-velNNOzU2Kk6S6C2aR3K9w==' 'unsafe-inline' 'unsafe-eval' 'strict-dynamic' https: http:; base-uri 'none'; report-uri https://o463592.ingest.sentry.io/api/5471479/security/?sentry_key=ab531d6dca0d488898493ccc9706f202&sentry_environment=prod 1 default-src 'self' *.air.org; child-src 'self' *.air.org; connect-src 'self' *.sharethis.com *.air.org https://analytics.google.com https://fd.cleantalk.org https://www.google.com https://www.googleadservices.com https://stats.g.doubleclick.net https://data.stbuttons.click https://moderate.cleantalk.org https://region1.analytics.google.com https://www.googletagmanager.com https://www.google-analytics.com https://use.typekit.net https://views.unsplash.com https://gateway.shorthand.com https://www.google.co.in https://use.fontawesome.com; font-src 'self' *.typekit.net *.fontawesome.com *.gstatic.com *.air.org; frame-src 'self' *.air.org https://www.googletagmanager.com https://www.youtube.com https://job-boards.greenhouse.io https://player.vimeo.com https://public.tableau.com https://www.google.com https://support.google.com https://w.soundcloud.com https://experience.arcgis.com https://iframely.shorthand.com *.softr.app; img-src 'self' *.sharethis.com *.knightlab.com *.air.org https://googleads.g.doubleclick.net https://www.google.com https://www.googletagmanager.com https://air-workspace.shorthandstories.com https://www.googleadservices.com https://public.tableau.com data:; manifest-src 'self'; media-src 'self' *.air.org https://air-workspace.shorthandstories.com; script-src 'self' *.sharethis.com *.air.org https://www.googletagmanager.com https://fd.cleantalk.org https://googleads.g.doubleclick.net https://www.youtube.com https://boards.greenhouse.io cdn.jsdelivr.net cdnjs.cloudflare.com chosen.js https://cdn.ckeditor.com https://cdn.jsdelivr.net https://code.jquery.com https://maxcdn.bootstrapcdn.com https://moderate.cleantalk.org https://unpkg.com https://use.fontawesome.com mdbootstrap.com stackpath.bootstrapcdn.com; script-src-attr 'self'; script-src-elem 'self' 'unsafe-inline' *.googletagmanager.com *.googleapis.com *.sharethis.com *.typekit.net *.knightlab.com *.air.org https://googleads.g.doubleclick.net https://fd.cleantalk.org https://www.youtube.com https://boards.greenhouse.io https://app.icontact.com https://air-workspace.shorthandstories.com https://public.tableau.com https://player.vimeo.com https://www.google.com https://www.gstatic.com https://analytics.shorthand.com https://platform-api.sharethis.com https://iframely.shorthand.com https://www.googletagmanager.com https://stackpath.bootstrapcdn.com https://connect.facebook.net https://moderate.cleantalk.org cdn.jsdelivr.net cdnjs.cloudflare.com chosen.js https://cdn.ckeditor.com https://cdn.jsdelivr.net https://code.jquery.com https://maxcdn.bootstrapcdn.com https://unpkg.com https://use.fontawesome.com mdbootstrap.com stackpath.bootstrapcdn.com; style-src 'self' *.air.org cdn.jsdelivr.net cdnjs.cloudflare.com chosen.css fonts.googleapis.com https://cdn.jsdelivr.net mdbootstrap.com stackpath.bootstrapcdn.com use.fontawesome.com use.typekit.net; style-src-attr 'self' 'unsafe-inline'; style-src-elem 'self' 'unsafe-inline' *.typekit.net *.knightlab.com *.air.org https://app.icontact.com cdn.jsdelivr.net cdnjs.cloudflare.com chosen.css fonts.googleapis.com https://cdn.jsdelivr.net mdbootstrap.com stackpath.bootstrapcdn.com use.fontawesome.com use.typekit.net; webrtc 'block'; base-uri 'self' *.air.org; form-action 'self' *.air.org https://app.icontact.com; frame-ancestors 'self' https://www.air.org https://air.org; report-uri https://air.org/log-report-uri/reportOnly; block-all-mixed-content; trusted-types 'none' 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://static.cloudflareinsights.com https://static.contactlab.it https://ingestion.webanalytics.italia.it https://www.youtube.com; object-src 'none'; style-src 'self' 'unsafe-inline' https://static.cineca.it; img-src 'self' data: https:; media-src 'self'; frame-src 'self'; frame-ancestors 'self'; child-src 'self'; font-src 'self' data: https://static.cineca.it; connect-src 'self' https://static.cloudflareinsights.com https://ingestion.webanalytics.italia.it https://www.youtube.com; report-uri /report-csp-violation 1 report-uri https://csp.withgoogle.com/csp/youtube_main/strict;base-uri 'self';object-src 'none';script-src 'report-sample' 'nonce-vvSrzd8flV17PNKQAuB4tw' 'unsafe-inline' 'strict-dynamic' https: http: 'unsafe-eval' 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://fonts.gstatic.com maxcdn.bootstrapcdn.com fonts.googleapis.com https://applepay.cdn-apple.com *.fontawesome.com applepay.cdn-apple.com 'self' data: 'unsafe-inline' https://admin.dev3.gh-stores.com https://dev3.gh-stores.com https://admin.gh-stores.com https://gh-stores.com https://www.gh-stores.com *.development.scalapay.com *.staging.scalapay.com *.integration.scalapay.com *.scalapay.com *.googleapis.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com https://www.paypal.com *.stripe.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com https://www.googletagmanager.com/ mirakl.m2e.cloud *.stripe.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.payplug.com *.dalenys.com https://applepay.cdn-apple.com *.cookiebot.com *.facebook.com *.google.it *.doubleclick.net https://www.paypal.com https://www.sandbox.paypal.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://images.unsplash.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ quickchart.io img.youtube.com flagpedia.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com https://secure-magenta.dalenys.com *.googleapis.com 'self' *.fontawesome.com *.google.pl *.google.it *.google.com *.google.nl *.gh-stores.com gh-stores.com *.facebook.com *.facebook.net *.atdmt.com *.adobedtm.com *.cookiebot.com https://dev3.gh-stores.com https://gh-stores.com https://www.gh-stores.com *.development.scalapay.com *.staging.scalapay.com *.integration.scalapay.com *.scalapay.com data: 'self' 'unsafe-inline'; script-src www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com *.vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com https://maps.googleapis.com https://player.vimeo.com https://cdn.jsdelivr.net/npm/@ryangjchandler/spruce@2.x.x/dist/spruce.umd.js widget.freshworks.com m2epro.freshdesk.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ pay.google.com *.gstatic.com maps.googleapis.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://secure-magenta.dalenys.com https://applepay.cdn-apple.com api-qa.payplug.com cdn-qa.payplug.com api.payplug.com cdn.payplug.com *.googleapis.com 'sha256-g/qbQ8sW5eJ9JO8sQzRJ1OvARbUyKpJXFeof9SLw1eI=' 'self' 'unsafe-inline' *.cookiebot.com *.stripe.com *.facebook.net *.googleads.g.doubleclick.net *.cloudflare.com *.ajax.cloudflare.com *.payplug.com https://dev3.gh-stores.com https://admin.dev3.gh-stores.com/backadmin https://www.gh-stores.com https://gh-stores.com https://www.admin.gh-stores.com/backadmin https://admin.gh-stores.com/backadmin *.googletagmanager.com *.googleadservices.com *.google-analytics.com *.freshdesk.com *.freshworks.com *.braintreegateway.com *.cardinalcommerce.com *.ccdc02.com *.sandbox.paypal.com *.paypalobjects.com *.ytimg.com *.scalapay.com *.jsdelivr.net *.dalenys.com *.omtrdc.net *.development.scalapay.com *.staging.scalapay.com *.integration.scalapay.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com widget.freshworks.com m2epro.freshdesk.com https://fonts.googleapis.com maxcdn.bootstrapcdn.com fonts.gstatic.com *.gstatic.com unsafe-inline assets.braintreegateway.com https://secure-magenta.dalenys.com *.googleapis.com *.googletagmanager.com https://dev3.gh-stores.com https://gh-stores.com https://www.gh-stores.com https://fonts.gstatic.com 'self' 'unsafe-inline' *.development.scalapay.com *.staging.scalapay.com *.integration.scalapay.com *.scalapay.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com https://maps.googleapis.com https://player.vimeo.com widget.freshworks.com m2epro.freshdesk.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ *.stripe.com www.gstatic.com maps.googleapis.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.googleapis.com *.google.pl *.google.it *.google.nl *.google-analytics.com *.googleadservices.com *.googletagmanager.com *.googlesyndication.com *.cookiebot.com *.facebook.com *.scalapay.com *.stape.cloud https://dev3.gh-stores.com https://gh-stores.com https://www.gh-stores.com *.development.scalapay.com *.staging.scalapay.com *.integration.scalapay.com *.gstatic.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src https: wss: blob:; connect-src https: wss: blob:; script-src https: 'unsafe-inline' 'unsafe-eval'; worker-src 'self' blob:; style-src https: 'unsafe-inline' blob:; img-src https: data: blob:; font-src https: data: blob:; object-src https: data:; media-src https: data: blob:; frame-ancestors 'none'; report-uri /security/csp_violations 1 default-src 'none'; connect-src 'self' embedr.flickr.com chat-us.libanswers.com resources.bepress.com playback.bepressaws.com cascade2.libchat.com visitor2.constantcontact.com distillery.wistia.com api-iam.intercom.io wss://nexus-websocket-a.intercom.io yoast.com listgrowth.ctctcdn.com www.facebook.com stats.g.doubleclick.net *.google-analytics.com analytics.google.com *.analytics.google.com *.googleapis.com; font-src 'self' data: cdn.jsdelivr.net fonts.gstatic.com static.juicer.io fonts.bunny.net; frame-src 'self' imsa.libanswers.com accounts.google.com admin.helperhelper.com community.imsa.edu v2.libanswers.com docs.google.com calendar.google.com www.youtube.com www.google.com www.facebook.com bbox.blackbaudhosting.com assets.bepress.com *.concept3d.com; img-src 'self' connect.facebook.net *.gstatic.com live.staticflickr.com www.googletagmanager.com previews.dropbox.com www.google-analytics.com *.imsa.edu s.w.org ps.w.org theeventscalendar.com fast.wistia.com data: embedwistia-a.akamaihd.net cdnjs.cloudflare.com www.paypalobjects.com *.googleapis.com onpointplugins.com secure.gravatar.com cdn.datatables.net *.facebook.com bbox.blackbaudhosting.com cdn.weglot.com localist-images.azureedge.net *.cloudfront.net imsa.edu *.googleusercontent.com *.google.com *.ctctcdn.com *.ytimg.com *.imsa.edu blackfacts.com; script-src data: 'self' 'unsafe-inline' 'unsafe-eval' assets.bepress.com blackfacts.com imsa.libanswers.com community.imsa.edu pi.pardot.com cdn.jsdelivr.net widget.intercom.io js.intercomcdn.com fast.wistia.com ajax.googleapis.com www.google.com www.gstatic.com cdnjs.cloudflare.com static.ctctcdn.com connect.facebook.net www.facebook.com assets.juicer.io bbox.blackbaudhosting.com bbox.blackbaudhosting.com cdn.datatables.net connect.facebook.net www.google-analytics.com www.googletagmanager.com; style-src 'self' 'unsafe-inline' www.gstatic.com cdn.jsdelivr.net cdnjs.cloudflare.com *.googleapis.com static.ctctcdn.com assets.juicer.io bbox.blackbaudhosting.com cdn.datatables.net; script-src-elem 'self' 'unsafe-inline' imsa.libanswers.com *.googleapis.com assets.bepress.com connect.facebook.net www.gstatic.com *.google.com cdnjs.cloudflare.com static.ctctcdn.com www.google-analytics.com cdn.datatables.net www.googletagmanager.com embedr.flickr.com widgets.flickr.com imsa.enterprise.localist.com *.imsa.edu blackfacts.com; style-src-elem 'self' 'unsafe-inline' static.ctctcdn.com *.googleapis.com cdn.datatables.net www.gstatic.com *.imsa.edu fonts.bunny.net imsa.enterprise.localist.com; media-src 'self' blob: ; worker-src 'self' blob: ; report-uri https://app.imsa.edu/connect/csp/report 1 script-src 'self' 'nonce-ecl7Ea5ZRmT4UhN7w3reSK/NE6Cv7NaHOYXCb8K5rPU=' 'strict-dynamic' 'wasm-unsafe-eval' www.youtube.com az416426.vo.msecnd.net cdn.cookielaw.org www.google-analytics.com maps.googleapis.com www.googletagmanager.com dl.episerver.net www.youtube.com www.google.com www.gstatic.com snap.licdn.com https://*.googletagmanager.com https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://*.g.doubleclick.net https://*.google.com https://*.google.com https://*.google.ad https://*.google.ae https://*.google.com.af https://*.google.com.ag https://*.google.com.ai https://*.google.al https://*.google.am https://*.google.co.ao https://*.google.com.ar https://*.google.as https://*.google.at https://*.google.com.au https://*.google.az https://*.google.ba https://*.google.com.bd https://*.google.be https://*.google.bf https://*.google.bg https://*.google.com.bh https://*.google.bi https://*.google.bj https://*.google.com.bn https://*.google.com.bo https://*.google.com.br https://*.google.bs https://*.google.bt https://*.google.co.bw https://*.google.by https://*.google.com.bz https://*.google.ca https://*.google.cd https://*.google.cf https://*.google.cg https://*.google.ch https://*.google.ci https://*.google.co.ck https://*.google.cl https://*.google.cm https://*.google.cn https://*.google.com.co https://*.google.co.cr https://*.google.com.cu https://*.google.cv https://*.google.com.cy https://*.google.cz https://*.google.de https://*.google.dj https://*.google.dk https://*.google.dm https://*.google.com.do https://*.google.dz https://*.google.com.ec https://*.google.ee https://*.google.com.eg https://*.google.es https://*.google.com.et https://*.google.fi https://*.google.com.fj https://*.google.fm https://*.google.fr https://*.google.ga https://*.google.ge https://*.google.gg https://*.google.com.gh https://*.google.com.gi https://*.google.gl https://*.google.gm https://*.google.gr https://*.google.com.gt https://*.google.gy https://*.google.com.hk https://*.google.hn https://*.google.hr https://*.google.ht https://*.google.hu https://*.google.co.id https://*.google.ie https://*.google.co.il https://*.google.im https://*.google.co.in https://*.google.iq https://*.google.is https://*.google.it https://*.google.je https://*.google.com.jm https://*.google.jo https://*.google.co.jp https://*.google.co.ke https://*.google.com.kh https://*.google.ki https://*.google.kg https://*.google.co.kr https://*.google.com.kw https://*.google.kz https://*.google.la https://*.google.com.lb https://*.google.li https://*.google.lk https://*.google.co.ls https://*.google.lt https://*.google.lu https://*.google.lv https://*.google.com.ly https://*.google.co.ma https://*.google.md https://*.google.me https://*.google.mg https://*.google.mk https://*.google.ml https://*.google.com.mm https://*.google.mn https://*.google.ms https://*.google.com.mt https://*.google.mu https://*.google.mv https://*.google.mw https://*.google.com.mx https://*.google.com.my https://*.google.co.mz https://*.google.com.na https://*.google.com.ng https://*.google.com.ni https://*.google.ne https://*.google.nl https://*.google.no https://*.google.com.np https://*.google.nr https://*.google.nu https://*.google.co.nz https://*.google.com.om https://*.google.com.pa https://*.google.com.pe https://*.google.com.pg https://*.google.com.ph https://*.google.com.pk https://*.google.pl https://*.google.pn https://*.google.com.pr https://*.google.ps https://*.google.pt https://*.google.com.py https://*.google.com.qa https://*.google.ro https://*.google.ru https://*.google.rw https://*.google.com.sa https://*.google.com.sb https://*.google.sc https://*.google.se https://*.google.com.sg https://*.google.sh https://*.google.si https://*.google.sk https://*.google.com.sl https://*.google.sn https://*.google.so https://*.google.sm https://*.google.sr https://*.google.st https://*.google.com.sv https://*.google.td https://*.google.tg https://*.google.co.th https://*.google.com.tj https://*.google.tl https://*.google.tm https://*.google.tn https://*.google.to https://*.google.com.tr https://*.google.tt https://*.google.com.tw https://*.google.co.tz https://*.google.com.ua https://*.google.co.ug https://*.google.co.uk https://*.google.com.uy https://*.google.co.uz https://*.google.com.vc https://*.google.co.ve https://*.google.vg https://*.google.co.vi https://*.google.com.vn https://*.google.vu https://*.google.ws https://*.google.rs https://*.google.co.za https://*.google.co.zm https://*.google.co.zw https://*.google.cat https://connect.facebook.net/ https://munchkin.marketo.net/ static.hotjar.com script.hotjar.com https://cdn.jsdelivr.net/;object-src 'none';base-uri 'self';report-uri https://o4507537122852864.ingest.de.sentry.io/api/4507764299726928/security/?sentry_key=2e67b3fa9c193f38db8ea33933d09ffa&sentry_environment=production&sentry_release=sprint24; 1 default-src 'self' https:; font-src 'self' https: data:; img-src 'self' https: data: https://*.stripe.com; object-src 'none'; script-src 'self' https: https://connect-js.stripe.com https://js.stripe.com https://*.js.stripe.com https://maps.googleapis.com 'nonce-CBJUXTPsGHF17DdkvinDBw=='; style-src 'self' https: 'nonce-CBJUXTPsGHF17DdkvinDBw=='; frame-src 'self' https://connect-js.stripe.com https://js.stripe.com https://*.js.stripe.com https://hooks.stripe.com; connect-src 'self' https://api.stripe.com https://maps.googleapis.com; report-uri /systems/csp_report 1 font-src fonts.gstatic.com use.typekit.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.ccavenue.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * https://plumrocket.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.demdex.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.ccavenue.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * https://plumrocket.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net *.ccavenue.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net assets.adobedtm.com *.adobe.io www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com *.magento-ds.com *.ccavenue.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.magento-datasolutions.com *.magento-ds.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.magento-datasolutions.com *.magento-ds.com *.ccavenue.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://*.publitas.com *.fontawesome.com *.kohlerbycochez.com https://script.hotjar.com *.algolia.com *.googleapis.com *.bootstrapcdn.com https://*.bazaarvoice.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com testsecureacceptance.cybersource.com secureacceptance.cybersource.com 0merchantacsstag.cardinalcommerce.com merchantacs.cardinalcommerce.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.online-metrix.net testflex.cybersource.com flex.cybersource.com testsecureacceptance.cybersource.com secureacceptance.cybersource.com pay.google.com merchantacs.cardinalcommerce.com 0merchantacsstag.cardinalcommerce.com https://*.publitas.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com c.paypal.com checkout.paypal.com assets.braintreegateway.com *.cardinalcommerce.com * *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net www.gstatic.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.kohlerbycochez.com network-a.bazaarvoice.com maps.gstatic.com *.algolia.com media.flixcar.com rt.flix360.com *.google.com *.google-analytics.com *.googleadservices.com https://www.google.com https://www.google.com.co maps.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.facebook.com *.reddit.com https://*.bazaarvoice.com https://*.google.com.pa data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.online-metrix.net testflex.cybersource.com flex.cybersource.com pay.google.com x.klarnacdn.net centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com https://*.publitas.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://apps.bazaarvoice.com *.kohlerbycochez.com apps.bazaarvoice.com static.hotjar.com script.hotjar.com h.online-metrix.net js-agent.newrelic.com www.google.com www.gstatic.com maps.googleapis.com *.algolia.com media.flixfacts.com media.flixcar.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://www.googletagmanager.com tagmanager.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com unpkg.com https://cdn.jsdelivr.net https://scripts.publitas.com https://view.publitas.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://*.publitas.com *.fontawesome.com *.kohlerbycochez.com *.algolia.com *.google.com *.googleapis.com *.gstatic.com *.bootstrapcdn.com assets.braintreegateway.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com videos.pexels.com *.algolia.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.kohlerbycochez.com bam.nr-data.net maps.googleapis.com https://surveystats.hotjar.io media.flixcar.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.google-analytics.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.doubleclick.net *.run.app https://*.bazaarvoice.com https://*.hotjar.io 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src bam.nr-data.net *.kohlerbycochez.com ws.hotjar.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self';base-uri 'self';img-src 'self' assets.bounceexchange.com bat.bing.com cdn.media.amplience.net data: edge.curalate.com events.bouncex.net gateway.foresee.com idr.cdnwidget.com network-a.bazaarvoice.com pix.cdnwidget.com seescandies.a.bigcontent.io www.facebook.com www.googletagmanager.com sees-candies-pwa-production.mobify-storefront.com;script-src 'self' 'unsafe-eval' 'unsafe-inline' action.dstillery.com api.bounceexchange.com apps.bazaarvoice.com assets.bounceexchange.com bat.bing.com blob: cas.zma.gs connect.facebook.net credit.klarnacdn.net ct.pinterest.com edge.curalate.com edge.fullstory.com gateway.foresee.com https://cdnjs.cloudflare.com/ajax/libs/crypto-js/ js.klarna.com js.zi-scripts.com ndn.statistinamics.com rs.fullstory.com s.pinimg.com sgtm.sees.com tag.wknd.ai tr2.smarterhq.io www.googletagmanager.com sees-candies-pwa-production.mobify-storefront.com https://runtime.commercecloud.com;style-src 'self' 'unsafe-inline' assets.bounceexchange.com cdn.c1.amplience.net;font-src 'self' data:;media-src 'self' data:;connect-src 'self' ad.doubleclick.net api.bazaarvoice.com bat.bing.com cas.zma.gs ct.pinterest.com edge.curalate.com edge.fullstory.com events.bouncex.net js.zi-scripts.com jsa-sees.domdog.io rs.fullstory.com seescandiesprod.cdn.content.amplience.net sgtm.sees.com ws.zoominfo.com www.google.com https://runtime.commercecloud.com;frame-src 'self' 10375605.fls.doubleclick.net assets.bounceexchange.com ct.pinterest.com sgtm.sees.com www.facebook.com;frame-ancestors 'self' https://runtime.commercecloud.com;worker-src 'self';form-action 'self' www.facebook.com;object-src 'none';manifest-src 'none';report-uri https://csp-sees.domdog.io/report-uri/sees.com/3/1-1 1 frame-ancestors 'self'; report-uri https://www.ntnews.com.au/csp-reports 1 frame-ancestors 'self' *.books.com.tw *.book.com.tw; report-uri https://cspr.books.com.tw/CspReport/fetchCspr 1 base-uri 'self'; block-all-mixed-content; default-src 'self'; form-action 'self'; frame-ancestors 'self'; plugin-types 'none'; script-src 'self' 'report-sample' 'unsafe-inline'; style-src 'self' 'report-sample' 'unsafe-inline'; object-src 'none'; worker-src 'none'; report-uri https://prod.ap.batic.cudasvc.com/xenios/api/v1/error/report??paid=151&spid=437&v=v1.0&payload=rJeyhteK1R4ehvX19W96lNbaCGhFOwYEfK03vVIAbGSAqTMkAdvym88TbB6ZcVIk3BKtzXIrOm_KBfeoBaCjF-SKRcVe6f9ReRIsd3j8IF2SDLukjVEW9IitjrCY-_SJCX_FALqnIG_rHmvbljEe-4J9MZXxsV5N_tephzJe60VMLdAIUh-CCxPVYZVvWv8DOcmXusqkbwG4BX3RjkjDrg==; 1 default-src 'self'; script-src 'report-sample' 'self' 'sha256-BiNyGbGZEG1ZcMWhdKvmZ1DwYSpvZ8xcAxRrIag59sQ=' 'sha256-p96cet82gMKBOah5xqTlTC1NImfgmfwp9xhnLYsv45Q=' 'sha256-K7F5t+0jCUOcvI0w5XCLORVrRe6Cl7fcvsyOhpNlvRA=' 'sha256-osJOIDsvZzKR6jjDkmJzOK/lCl+6P59lwiMwf2WwwX0=' 'sha256-ech7dK56PGMmo3zLhyCe9XpUu/4+pGU11bUeBEpq56o=' 'sha256-5aTBNtoMSFGD0AJ9+0YPRibd5APCDzFjjKtA16wQik8=' 'sha256-hV1mihBfiWqmXQxPNANChEuUWIOIlte4D1DUOfqSY2Y=' 'sha256-DHkQzQeawSI3bMDJPOulIinzX/ih38goNk2cvBZsgPM=' 'sha256-LjOYZt74qQlHixQckZ1K+NyxwGO8jPc/zUDhd43i7qY=' 'sha256-C6r1Uv+2BkE8Qjrq+iYLyfsjck3nrA/PhDEE1u7CHtk=' 'sha256-hV1mihBfiWqmXQxPNANChEuUWIOIlte4D1DUOfqSY2Y=' 'sha256-BxUWVs1+UwaUImPFWmLpOCjBDGTFuFcwcXgQwKyVSYU=' https://www.googletagmanager.com/gtm.js https://www.googletagmanager.com/gtag/js https://www.google-analytics.com/analytics.js https://www.googleadservices.com/pagead/conversion_async.js https://www.google.com/recaptcha/api.js https://www.gstatic.com/recaptcha/releases/ https://googleads.g.doubleclick.net/pagead/viewthroughconversion/976618339/ https://a.clickcertain.com/px/smart/a/ https://a.remarketstats.com/px/smart/; style-src 'report-sample' 'self' 'unsafe-inline'; object-src 'none'; base-uri 'self'; connect-src 'self' https://stats.g.doubleclick.net https://www.google-analytics.com; font-src 'self'; frame-src 'self' https://www.google.com https://a.clickcertain.com/; img-src 'self' https://www.google-analytics.com https://www.google.com https://www.google.pl; manifest-src 'self'; media-src 'self'; worker-src 'none'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://fonts.gstatic.com *.fontawesome.com https://www.google.com https://www.gstatic.com *.cloudflare.com *.trustedshops.com *.bootstrapcdn.com https://display.ugc.bazaarvoice.com 'self' data: *.vortexoptics.com https://vortexoptics.com/static https://*.userway.org/ *.yotpo.com *.googleapis.com dhv2ziothpgrr.cloudfront.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com https://www.facebook.com/tr/ https://mcstaging.vortexoptics.com/ https://mcstaging.vortexgolf.com/ https://vortexoptics.com/ https://vortexgolf.com/ https://*.userway.org/ *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net https://www.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com www.google.com https://w.soundcloud.com https://www.google.com https://vars.hotjar.com https://amc.demdex.net/ https://www.facebook.com/ https://*.doubleclick.net/ https://*.userway.org/ *.weltpixel.com www.xtento.com *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net http://amcglobal.sc.omtrdc.net/ widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net data: *.googleapis.com *.meetanshi.com https://mcstaging.vortexoptics.com/ *.cloudflare.com https://cdn.klarna.com *.ytimg.com *.usercentrics.eu https://www.google.com/ https://facebook.com/ https://cm.everesttech.net/ https://dpm.demdex.net/ https://www.facebook.com/ https://connect.facebook.net/ *.bazaarvoice.com/ https://contentorigin.bazaarvoice.com/ https://vortexoptics.widen.net/ *.gettopple.com/ https://bam.nr-data.net/ *.kaltura.com/ https://*.userway.org/ https://yotpo-media-temporary.s3.amazonaws.com/ www.xtento.com cdn.xtento.com *.yotpo.com dhv2ziothpgrr.cloudfront.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com https://player.vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://rum.hlx.page *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ https://developer.adobe.com https://magento.com https://cdn.avmws.com/ http://cdn.avmws.com/ https://cdn.jsdelivr.net/npm/select2@4.1.0-rc.0/dist/js/select2.min.js *.cloudflare.com *.trustedshops.com *.usercentrics.eu https://chimpstatic.com *.zdassets.com https://www.google.com https://www.gstatic.com https://geoip.nekudo.com https://static.hotjar.com https://script.hotjar.com https://www.googletagmanager.com https://connect.facebook.net/ https://widget-mediator.zopim.com https://googleads.g.doubleclick.net/ *.gettopple.com/ https://mpsnare.iesnare.com/ *.vortexoptics.com https://vortexoptics.com/static/ https://klear.com/ https://cdnapisec.kaltura.com/ https://*.userway.org/ wss://pod-13-sunco-ws.zendesk.com *.maxmind.com www.xtento.com cdn.xtento.com *.yotpo.com dhv2ziothpgrr.cloudfront.net *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com d18eg7dreypte5.cloudfront.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com *.googleapis.com *.google.com *.gstatic.com *.cloudflare.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.bazaarvoice.com *.bootstrapcdn.com *.vortexoptics.com https://vortexoptics.com/static https://*.userway.org/ https://cdn.jsdelivr.net/npm/select2@4.1.0-rc.0/dist/css/select2.min.css *.yotpo.com dhv2ziothpgrr.cloudfront.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.zdassets.com https://mpsnare.iesnare.com/ https://*.userway.org/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io *.googleapis.com https://developer.adobe.com https://cdn.avmws.com/ http://cdn.avmws.com/ http://dpm.demdex.net https://www.google.com https://www.gstatic.com *.meetanshi.com *.gstatic.com *.cloudflare.com https://rum.hlx.page *.zdassets.com *.zendesk.com wss://widget-mediator.zopim.com https://widget-mediator.zopim.com https://in.hotjar.com http://amcglobal.sc.omtrdc.net/ https://stats.g.doubleclick.net/ https://www.google-analytics.com/ https://dpm.demdex.net/ https://www.facebook.com/ https://*.hotjar.com https://maps.googleapis.com *.bazaarvoice.com wss://*.hotjar.com https://*.hotjar.io wss://mpsnare.iesnare.com/star wss://pod-13-sunco-ws.zendesk.com https://*.googlesyndication.com *.vortexoptics.com https://vortexoptics.com/static https://insights.algolia.io https://klear.com/ https://*.userway.org/ *.mmapiws.com *.yotpo.com dhv2ziothpgrr.cloudfront.net *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 style-src-elem 'unsafe-inline' sportofino.com *.sportofino.com *.snrcdn.net geowidget.easypack24.net fonts.googleapis.com cdn.luigisbox.tech; script-src-elem *.snrcdn.net *.etrusted.com https://widgets.trustedshops.com *.livechatinc.com geowidget.inpost.pl widget.packeta.com static.paynow.pl maps.googleapis.com www.googletagmanager.com js.braintreegateway.com ssl.ceneo.pl www.glami.cz www.ladenzeile.de x.klarnacdn.net c.paypal.com pay.google.com static.cloudflareinsights.com 'self' 'unsafe-inline' sportofino.com *.sportofino.com scripts.luigisbox.tech cdn.luigisbox.tech consent.cookiebot.com s.pinimg.com ct.pinterest.com consentcdn.cookiebot.com bat.bing.com a.mgid.com connect.facebook.net cdn.tmtarget.com glamipixel.com tags.creativecdn.com library.startquestion.com pixel.wp.pl googleads.g.doubleclick.net dss.hybrid.ai web.snrbox.com st.hybrid.ai emd.hybrid.ai im9.cz googleadservices.com expandeco.daktela.com www.googleadservices.com analytics.tiktok.com; font-src *.klarnacdn.net *.fontawesome.com https://cdnjs.cloudflare.com fonts.gstatic.com geowidget.easypack24.net https://widgets.trustedshops.com cdn.thulium.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * sandbox.przelewy24.pl secure.przelewy24.pl 'self' 'self' 'unsafe-inline'; frame-ancestors pay.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.klarna.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * apm.przelewy24.pl secure.payu.com merch-prod.snd.payu.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.bird.eu *.klarna.com *.klarnaevt.com *.klarnacdn.net magefan.com cm.magefan.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com static.przelewy24.pl www.gstatic.com gstatic.com static.payu.com sportofino.com *.sportofino.com *.gstatic.com *.googleapis.com *.ggpht.com *.paynow.pl www.glami.cz static.paynow.pl https://widgets.trustedshops.com https://widgets-qa.trustedshops.com bat.bing.com pixel.wp.pl www.glami.pl www.facebook.com a.mgid.com dot.wp.pl stileo.it www.glami.ro sync.teads.tv www.google.pl sync.taboola.com ih.adscale.de eb2.3lift.com sync.outbrain.com ssp-csync.smartadserver.com ads.stickyadstv.com ads.yieldmo.com us-u.openx.net ad.doubleclick.net imgsct.cookiebot.com dss.hybrid.ai bat.bing.net ams.creativecdn.com cm.mgid.com www.fashiola.de www.fashiola.fr rt.udmserve.net www.heureka.cz ib.adnxs.com dsum-sec.casalemedia.com c1.adform.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.klarna.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://cdnjs.cloudflare.com sandbox.przelewy24.pl secure.przelewy24.pl apm.przelewy24.pl secure.payu.com secure.snd.payu.com 'self' 'unsafe-inline' sportofino.com *.sportofino.com library.startquestion.com bat.bing.com px.leadexpert.pl scripts.luigisbox.tech tags.creativecdn.com cdn.luigisbox.tech js-agent.newrelic.com bam.eu01.nr-data.net widgets.trustedshops.com www.snrcdn.net gstatic.com tck.snrbox.com proxy.snrbox.com connect.facebook.net creativecdn.com cdn.livechatinc.com *.inpost.pl https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com reco.sportofino.com dss.hybrid.ai a.mgid.com consentcdn.cookiebot.com widget.packeta.com googleadservices.com expandeco.daktela.com glamipixel.com pixel.wp.pl consent.cookiebot.com cdn.tmtarget.com cdn.thulium.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.klarnacdn.net *.fontawesome.com unsafe-inline assets.braintreegateway.com https://fonts.googleapis.com https://cdnjs.cloudflare.com fonts.googleapis.com https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com reco.sportofino.com geowidget.easypack24.net cdn.luigisbox.tech 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com player.vimeo.com akamaized.net download-video.akamaized.net cdnstrapi.sportofino.com cdn.thulium.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.klarnaevt.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.klarna.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com sandbox.przelewy24.pl secure.przelewy24.pl wss://sandbox-ws.przelewy24.pl wss://secure-ws.przelewy24.pl apple-pay-gateway.apple.com apm.przelewy24.pl www.google.com pay.google.com secure.payu.com merch-prod.snd.payu.com *.snrbox.com maps.googleapis.com widget.packeta.com reco.sportofino.com *.trustedshops.com *.etrusted.com https://integrations.etrusted.site api.luigisbox.tech pagead2.googlesyndication.com live.luigisbox.tech region1.google-analytics.com ct.pinterest.com consentcdn.cookiebot.com app.startquestion.com googleads.g.doubleclick.net pixel.wp.pl ams.creativecdn.com bat.bing.com bat.bing.net www.facebook.com www.google.pl stats.g.doubleclick.net expandeco.daktela.com cdn.thulium.com fcmregistrations.googleapis.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://sportofino.com/csp_reports; report-to report-endpoint; 1 default-src 'self' https:; object-src 'none'; connect-src 'self' https: https://www.google-analytics.com https://www.googletagmanager.com; frame-src 'self' https: https://www.googletagmanager.com; img-src 'self' https: https://www.googletagmanager.com https://www.google-analytics.com https://ssl.gstatic.com https://www.gstatic.com data: blob:; style-src 'self' https: 'unsafe-inline' https://fonts.googleapis.com; font-src 'self' https: https://fonts.gstatic.com data:; script-src 'self' https: 'unsafe-eval' 'nonce-Lprnn8AvYJEs11VosfLQhQ=='; report-uri /csp_violations 1 default-src blob: https://*.mhcache.com;font-src 'self' https://*.myheritage.com https://*.mhcache.com https://fonts.gstatic.com;frame-src 'self' https://*.mhcache.com https://portal.allyable.com https://mh-site-files-5c53d6a9947c.s3.amazonaws.com https://myheritage-container.com https://www.myheritage-partners.com https://www.myheritage.com https://*.mk-sense.com https://player.vimeo.com https://*.facebook.com https://*.googleapis.com https://*.google.com https://tpc.googlesyndication.com https://*.doubleclick.net https://accounts.google.com/gsi/;script-src https://accounts.google.com/gsi/client https://www.datadoghq-browser-agent.com https://*.googleapis.com https://appleid.cdn-apple.com *.myheritage.fi https://www.myheritage.fi 'unsafe-eval' 'nonce-45fc9bf8eda51103b1bb324d7b0b2159' 'strict-dynamic';style-src data: blob: 'unsafe-inline' 'self' https://*.myheritage.com https://*.mhcache.com https://fonts.googleapis.com https://accounts.google.com/gsi/style;connect-src data: 'self' https://*.myheritage.com https://portal.allyable.com https://*.mhcache.com https://adservice.google.com https://*.logs.datadoghq.com https://*.browser-intake-datadoghq.com https://browser-intake-datadoghq.com https://sentry.io https://*.bing.com https://*.facebook.com https://*.doubleclick.net https://*.mk-sense.com https://*.filae.com https://accounts.google.com/gsi/ https://www.google.com/pagead/landing https://*.googleapis.com https://maps.googleapis.com/maps/api/mapsjs/gen_204 https://translate.googleapis.com https://www.google.com/ccm/collect https://cdn.builder.io *.myheritage.fi;media-src 'self' https://*.myheritage.com https://*.mhcache.com;frame-ancestors 'self' https://builder.io;img-src * data:;object-src 'none';base-uri 'self' https://*.mhcache.com;report-uri /FP/API/ContentSecurityPolicy/report-violation.php?report_mode=report&canonical_page_id=/company/home/ 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com https://fonts.bunny.net *.alothemes.com *.magepow.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com https://plumrocket.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com 'self' 'unsafe-inline'; frame-ancestors *.certcapture.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.certcapture.com https://plumrocket.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.weltpixel.com *.googletagmanager.com *.doubleclick.net *.typeform.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://images.unsplash.com *.certcapture.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com maps.googleapis.com maps.gstatic.com https://firebasestorage.googleapis.com *.alothemes.com *.magepow.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.facebook.com *.reddit.com *.ads-twitter.com t.co *.twitter.com *.bing.com *.bing.net *.klaviyo.com *.pinterest.com *.pinimg.com *.clarity.ms *.google-analytics.com *.googletagmanager.com *.doubleclick.net *.google.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://maps.googleapis.com *.certcapture.com chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com maps.googleapis.com *.avada.io *.alothemes.com *.magepow.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googletagmanager.com *.googleadservices.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.bing.com *.clarity.ms *.klaviyo.com *.pinterest.com *.pinimg.com unpkg.com *.doubleclick.net *.typeform.com https://cdn.attn.tv https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.certcapture.com downloads.mailchimp.com *.fontawesome.com https://fonts.bunny.net *.alothemes.com *.magepow.com assets.braintreegateway.com maxcdn.bootstrapcdn.com *.tagmanager.google.com *.googletagmanager.com *.typeform.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://maps.googleapis.com https://player.vimeo.com *.certcapture.com form-assets.mailchimp.com *.intuit.com *.amazonaws.com maps.googleapis.com https://get.geojs.io *.avada.io *.alothemes.com *.magepow.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.google-analytics.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.pinterest.com *.pinimg.com *.doubleclick.net *.run.app *.typeform.com 'self' 'unsafe-inline'; child-src *.certcapture.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; child-src 'none'; connect-src 'self' https://*.bozar.be https://*.contentsquare.net https://*.facebook.com https://*.google-analytics.com https://*.onetrust.com https://*.recombee.com https://*.secutix.com https://*.visualwebsiteoptimizer.com https://*.vwo.com https://o419740.ingest.sentry.io/api/5336472/envelope/; font-src 'self' https://fonts.gstatic.com; frame-src 'self' https://*.googletagmanager.com https://*.google.com https://*.matterport.com https://*.soundcloud.com https://*.spotify.com https://*.vimeo.com https://*.youtube.com; img-src 'self' https://*.cookielaw.org https://*.facebook.com https://*.googletagmanager.com https://*.vimeocdn.com; object-src 'none'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://*.bozar.be https://*.hotjar.com https://*.cookielaw.org https://*.contentsquare.net https://*.googletagmanager.com cdn.jsdelivr.net https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://script.crazyegg.com https://unpkg.com; script-src-elem 'self' 'unsafe-inline' https://*.bozar.be https://*.cookielaw.org https://*.facebook.net https://*.googletagmanager.com https://*.hotjar.com https://matomojs.trackify.info https://*.visualwebsiteoptimizer.com https://*.vwo.com https://*.youtube.com cdn.jsdelivr.net https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://script.crazyegg.com https://unpkg.com; style-src 'self' 'report-sample' 'unsafe-inline' https://unpkg.com; style-src-attr 'self' 'unsafe-inline'; style-src-elem 'self' 'unsafe-inline' https://unpkg.com; webrtc 'block'; worker-src 'self'; base-uri 'none'; form-action 'self'; frame-ancestors 'self' https://*.bozar.be https://*.secutix.com; report-uri https://o419740.ingest.sentry.io/api/5336472/security/?sentry_key=352ab04e14224ad0804d381177289653&sentry_environment=master-7rqtwti&sentry_release=4607a27df0b6f7a5b2920053d31d2ea2622c59fd; block-all-mixed-content 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com fonts.googleapis.com *.googleapis.com data: https://fonts.gstatic.com *.stape.io *.fontawesome.com https://fonts.bunny.net *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com d114hh0cykhyb0.cloudfront.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com google.com *.braintreegateway.com *.paypal.com *.google.com www.google.com *.dotdigital-pages.com *.dotdigital.com webchat.dotdigital.com webchat.staging.dotdigital.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.stape.io www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com *.googleapis.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com superbrightleds.atlassian.net *.criteo.com *.criteo.net *.nr-data.net *.trustpilot.com *.pinimg.com *.pinterest.com *.licdn.com *.linkedin.com *.vwo.com *.facebook.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://images.unsplash.com maps.googleapis.com maps.gstatic.com *.googleapis.com *.trackedlink.net ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com magefan.com cm.magefan.com *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.doubleclick.net *.stape.io https://firebasestorage.googleapis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://redchamps.com livehelpnow.net *.livehelpnow.net *.placeholder.com *.cloudfront.net *.trustkeeper.net *.trustwave.com *.digicert.com dis.criteo.com tags.bluekai.com secure.adnxs.com sync.ad-stir.com *.yahoo.com *.360yield.com *.3lift.com *.addthis.com *.adnxs.com *.adscale.de *.advertising.com *.agkn.com *.amazon-adsystem.com *.bbb.org *.bidswitch.net *.bing.com *.casalemedia.com *.clmbtech.com *.contextweb.com *.criteo.com *.demdex.net *.dmxleo.com matching.ivitrack.com *.krxd.net *.liadm.com mcprod.superbrightleds.com *.media.net exchange.mediavine.com partner.mediawallahscript.com *.omnitagjs.com *.outbrain.com *.postrelease.com *.pubmatic.com *.revcontent.com *.rlcdn.com *.rubiconproject.com *.sharethrough.com *.smaato.net *.socdm.com *.smartadserver.com *.stickyadstv.com *.taboola.com *.tapad.com *.teads.tv ad.tpmn.co.kr *.tremorhub.com *.turn.com *.yieldlab.net *.yieldmo.com *.zonos.com *.pinimg.com *.pinterest.com *.linkedin.com *.visualwebsiteoptimizer.com id5-sync.com a.twiago.com sync.1rx.io *.facebook.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net amcglobal.sc.omtrdc.net commerce.adobe.net use.typekit.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.magento-ds.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.magento-datasolutions.com https://maps.googleapis.com https://player.vimeo.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.googleapis.com *.gstatic.com https://cdn.jsdelivr.net/npm/@ryangjchandler/spruce@2.x.x/dist/spruce.umd.js www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal webchat.dotdigital.com webchat.staging.dotdigital.com chimpstatic.com downloads.mailchimp.com *.list-manage.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.googletagmanager.com *.doubleclick.net *.stape.io *.avada.io www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com superbrightleds.atlassian.net *.digicert.com *.criteo.net *.criteo.com *.zonos.com *.trustpilot.com *.iglobalstores.com *.mixpanel.com *.mxpnl.com *.pinimg.com *.pinterest.com *.googleoptimize.com pageimprove.io *.licdn.com *.linkedin.com *.visualwebsiteoptimizer.com *.vwo.com *.facebook.net *.livehelpnow.net *.bing.com *.maxmind.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com webchat.dotdigital.com webchat.staging.dotdigital.com downloads.mailchimp.com https://fonts.googleapis.com *.googleapis.com *.googletagmanager.com *.stape.io *.fontawesome.com https://fonts.bunny.net *.stripe.network *.stripecdn.com *.amazon.com d114hh0cykhyb0.cloudfront.net http://localhost:* *.trustpilot.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io *.sentry.io *.paypal.com google.com *.google.com *.magento-datasolutions.com *.magento-ds.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io https://maps.googleapis.com https://player.vimeo.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.googleapis.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com *.doubleclick.net *.googlesyndication.com *.stape.io https://get.geojs.io *.avada.io www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.criteo.com *.zonos.com *.mixpanel.com *.pinimg.com *.pinterest.com pageimprove.io *.visualwebsiteoptimizer.com *.facebook.com *.mmapiws.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src * data:; script-src * 'unsafe-inline' 'unsafe-eval'; style-src * 'unsafe-inline' data:; frame-ancestors 'none'; worker-src blob:; connect-src * 'unsafe-inline'; img-src * blob: data: 'unsafe-inline'; object-src 'self' blob:; report-uri /cspapi/report/CspReport; 1 script-src 'self' https://cloud.typography.com/7315076/7256812/css/fonts.css siteimproveanalytics.com ; object-src 'none'; img-src *.siteimproveanalytics.io 1 script-src 'self' 'unsafe-inline' 'unsafe-eval' https://octane.co https://*.octane.co https://ride-static.octane.co https://ride-api.octane.co https://octane.co https://*.octane.co https://octanelending.com https://*.octanelending.com *.googletagmanager.com *.google-analytics.com *.gstatic.com *.google.com *.vwo.com *.visualwebsiteoptimizer.com *.intercom.io *.intercomcdn.com *.onetrust.com https://cdn.cookielaw.org; style-src 'self' 'unsafe-inline' 'unsafe-eval' https://octane.co https://*.octane.co https://ride-static.octane.co https://ride-api.octane.co https://octane.co https://*.octane.co https://octanelending.com https://*.octanelending.com fonts.googleapis.com www.gstatic.com app.vwo.com www.googletagmanager.com translate.googleapis.com; frame-ancestors 'self' https://polarisxchange.com https://slingshot.polarisxchange.com https://indianmotorcycle.polarisxchange.com https://www.rvs.com https://rvs.com https://buy.cycletrader.com https://www.atvrider.com https://www.cyclevolta.com https://www.cycleworld.com https://www.dirtrider.com https://www.motorcyclecruiser.com https://www.motorcyclistonline.com https://www.utvdriver.com https://octane.co https://*.octane.co https://ride-static.octane.co https://ride-api.octane.co https://octanelending.com https://*.octanelending.com https://*.dev-octanelisting.com https://*.octanelisting.com; worker-src 'self' blob:; upgrade-insecure-requests 1 object-src 'none';base-uri 'self';script-src 'nonce-rLJIJI3krFpiTCdudpBoZg' 'strict-dynamic' 'report-sample' 'unsafe-eval' 'unsafe-inline' https: http:;report-uri https://csp.withgoogle.com/csp/gws/other-hp 1 default-src 'self' https:; font-src 'self' https: data: https://use.typekit.net https://p.typekit.net; img-src 'self' https: data: http://www.googleadservices.com; object-src 'none'; base-uri 'self'; style-src 'self' https: 'unsafe-inline' https://use.typekit.net https://cdn.consentmanager.net; script-src 'self' https: unsafe-inline unsafe-eval strict-dynamic https://use.typekit.net http://connect.facebook.net http://b-code.liadm.com https://js.intercomcdn.com https://static.intercomcdn.com https://widget.intercom.io https://app.intercom.io 'nonce-mlovD2M7f68QOIRisYvd2g=='; connect-src 'self' https: wss://nexus-websocket-a.intercom.io 1 default-src 'self' https://static.slo-tech.com https://zy.si https://push.slo-tech.com; script-src 'self' 'unsafe-inline' https://static.slo-tech.com https://oglasi.slo-tech.com https://zy.si; style-src 'self' data: 'unsafe-inline' static.slo-tech.com; img-src 'self' data: https://* http://* https://static.slo-tech.com https://oglasi.slo-tech.com https://zy.si; connect-src 'self' https://oglasi.slo-tech.com https://push.slo-tech.com wss://push.slo-tech.com ws://push.slo-tech.com https://zy.si; frame-src 'self' https://oglasi.slo-tech.com https://www.youtube-nocookie.com; worker-src 'none'; frame-ancestors 'none'; form-action 'self'; upgrade-insecure-requests; sandbox; report-uri https://sentry.ilol.si/api/2/security/?sentry_key=1caf1e883a1146c09085276ddd50841d 1 object-src 'none'; script-src 'nonce-p7--hgs18zLK90GnyEHhkwPZ' 'strict-dynamic' http: https:; base-uri 'none'; 1 object-src 'none';base-uri 'self';script-src 'nonce-96ip7f8gRu9PLcN7ryYNAg' 'strict-dynamic' 'report-sample' 'unsafe-eval' 'unsafe-inline' https: http:;report-uri https://csp.withgoogle.com/csp/gws/maps-tactile 1 font-src *.googleapis.com *.gstatic.com fonts.cdnfonts.com *.zohostatic.ca css.zohocdn.com cdn.userway.org *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com m2.grasscity.com staticw2.yotpo.com 'self' data: *.yotpo.com dhv2ziothpgrr.cloudfront.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.authorize.net *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.authorize.net self 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com www.paypal.com www.sandbox.paypal.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * www.google.com https://www.googletagmanager.com/ *.authorize.net pub-7be69f7c77b4c166d1c3.tracking.refersion.com https://config-cdn.ksearchnet.com *.refersion.com checkout.sezzle.com sandbox.checkout.sezzle.com tracking.sezzle.com *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.paypal.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com https://images.unsplash.com *.googleapis.com *.gstatic.com *.curopayments.net cdn.userway.org *.clarity.ms c.bing.com www.google.co.in shopper.shop.pe css.zohocdn.com www.grasscity.com i.liadm.com i6.liadm.com ads.trafficjunky.net store.paradoxlabs.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ magefan.com cm.magefan.com https://img.youtube.com https://firebasestorage.googleapis.com flagpedia.net m2.grasscity.com p.yotpo.com media.sezzle.com *.hsforms.net *.hsforms.com 'self' data: *.yotpo.com dhv2ziothpgrr.cloudfront.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.paypal.com www.sandbox.paypal.com www.paypalobjects.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ www.googletagmanager.com/gtm.js shop.pe app.shop.pe tags.srv.stackadapt.com jscloud.net analytics.ahrefs.com *.cloudfront.net *.clarity.ms cdn.userway.org shopper.shop.pe cdn.convertcart.com dc4.convertcart.com addshoppers.s3.amazonaws.com cdn.aggle.net salesiq.zohopublic.ca *.zohostatic.ca *.zohocdn.com aggle.net r1-t.trackedlink.net static.trackedweb.net p.gcprivacy.com dashboard.searchatlas.com self https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ http://www.googletagmanager.com/ https://www.googletagmanager.com/ s7.addthis.com https://cdn.jsdelivr.net *.avada.io *.shopify.com maps.googleapis.com *.authorize.net https://config-cdn.ksearchnet.com js.klevu.com m2.grasscity.com script.tapfiliate.com static.cloudflareinsights.com assets.mantisadnetwork.com unpkg.com cdn.refersion.com staticw2.yotpo.com static.klaviyo.com static-tracking.klaviyo.com *.refersion.com checkout-sdk.sezzle.com sandbox.checkout-sdk.sezzle.com widget.sezzle.com *.hsforms.net *.hsforms.com *.google.com *.yotpo.com dhv2ziothpgrr.cloudfront.net *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com d18eg7dreypte5.cloudfront.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com unsafe-inline assets.braintreegateway.com fonts.googleapis.com cdn.convertcart.com css.zohocdn.com *.zohostatic.ca cdn.userway.org tags.srv.stackadapt.com https://static.klaviyo.com https://cdn.jsdelivr.net *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.gstatic.com m2.grasscity.com staticw2.yotpo.com fonts.cdnfonts.com *.googleapis.com *.yotpo.com dhv2ziothpgrr.cloudfront.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.paypal.com www.sandbox.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.googleapis.com www.google.co.in r1.trackedweb.net wss://onlinesupportmatrix.support wss://onlinechatmatrix.online manage.safeopt.com cdn.convertcart.com api2.amplitude.com api.route.com api-stage.route.com wss://vts.zohopublic.ca *.zohopublic.ca salesiq.zohocloud.ca herb.aggle.net/ shop.pe app.shop.pe shopper.shop.pe api.userway.org *.userway.org *.clarity.ms cdn.userway.org analytics.ahrefs.com jscloud.net tags.srv.stackadapt.com dc4.convertcart.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ ekr.zdassets.com/ https://get.geojs.io *.avada.io www.gstatic.com maps.googleapis.com *.authorize.net connect-sandbox.bolt.com statsjs.klevu.com js.klevu.com staticw2.yotpo.com m2.grasscity.com tracking.refersion.com *.refersion.com gateway.sezzle.com sandbox.gateway.sezzle.com media.sezzle.com widget.sezzle.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com *.yotpo.com dhv2ziothpgrr.cloudfront.net *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src thm.visa.com m2.grasscity.com *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net cash-f.squarecdn.com https://*.gstatic.com data: *.sodatech.com *.sodatech.net *.gstatic.com *.typekit.net cdn.livechatinc.com mediacdn.espssl.com viewer.byondxr.com use.fontawesome.com 'self' data: https://fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com * *.adyen.com api.bazaarvoice.com stg.api.bazaarvoice.com pal-test.adyen.com www.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com *.pinterest.com https://ghirardelli.slgnt.us 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ * *.adyen.com *.sharethis.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com *.ehappify.com www.xtento.com *.vimeo.com *.jsctool.com *.pinterest.com *.mmcagentur.at *.doubleclick.net *.facebook.com *.facebook.net *.google.com *.demdex.net *.authorize.net *.paypal.com *.googletagmanager.com *.xtento.com *.app-wallee.com *.waltpixel.com *.equitystory.com offer.slgnt.us vars.hotjar.com *.pepperjamnetwork.com services.listrak.com *.serverdata.net *.livechatinc.com *.lindtusa.com *.russellstover.com *.ghirardelli.com https://*.ordergroove.com *.weltpixel.com app-wallee.com www.jsctool.com static.ogmystyle.com static2.ogmystyle.com www.mystyleplatform.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.trustpilot.com geowidget.inpost.pl sandbox-easy-geowidget-sdk.easypack24.net widget.packeta.com https://ghirardelli.slgnt.us https://www.paypalobjects.com https://lindtusa.rlvs.co.uk https://optmize.google.com https://www.google.com/ https://ct.pinterest.com/ 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io * https://*.gstatic.com *.adyen.com *.sharethis.com display.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com network-a.bazaarvoice.com network-stg-a.bazaarvoice.com photos-uat-us.bazaarvoice.com img.youtube.com *.cloudfront.net *.amazonaws.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ www.xtento.com cdn.xtento.com blob: lindt.test *.lindt.test maps.googleapis.com *.pinterest.com *.postcodeanywhere.co.uk *.klarna.com *.invibes.com *.b26net.com https://www.google-analytics.com *.googletagmanager.com *.teads.tv *.videostep.com *.facebook.com *.google.com *.google.ad *.google.ae *.google.com.af *.google.com.ag *.google.com.ai *.google.al *.google.am *.google.co.ao *.google.com.ar *.google.as *.google.at *.google.com.au *.google.az *.google.ba *.google.com.bd *.google.be *.google.bf *.google.bg *.google.com.bh *.google.bi *.google.bj *.google.com.bn *.google.com.bo *.google.com.br *.google.bs *.google.bt *.google.co.bw *.google.by *.google.com.bz *.google.ca *.google.cd *.google.cf *.google.cg *.google.ch *.google.ci *.google.co.ck *.google.cl *.google.cm *.google.cn *.google.com.co *.google.co.cr *.google.com.cu *.google.cv *.google.com.cy *.google.cz *.google.de *.google.dj *.google.dk *.google.dm *.google.com.do *.google.dz *.google.com.ec *.google.ee *.google.com.eg *.google.es *.google.com.et *.google.fi *.google.com.fj *.google.fm *.google.fr *.google.ga *.google.ge *.google.gg *.google.com.gh *.google.com.gi *.google.gl *.google.gm *.google.gr *.google.com.gt *.google.gy *.google.com.hk *.google.hn *.google.hr *.google.ht *.google.hu *.google.co.id *.google.ie *.google.co.il *.google.im *.google.co.in *.google.iq *.google.is *.google.it *.google.je *.google.com.jm *.google.jo *.google.co.jp *.google.co.ke *.google.com.kh *.google.ki *.google.kg *.google.co.kr *.google.com.kw *.google.kz *.google.la *.google.com.lb *.google.li *.google.lk *.google.co.ls *.google.lt *.google.lu *.google.lv *.google.com.ly *.google.co.ma *.google.md *.google.me *.google.mg *.google.mk *.google.ml *.google.com.mm *.google.mn *.google.ms *.google.com.mt *.google.mu *.google.mv *.google.mw *.google.com.mx *.google.com.my *.google.co.mz *.google.com.na *.google.com.ng *.google.com.ni *.google.ne *.google.nl *.google.no *.google.com.np *.google.nr *.google.nu *.google.co.nz *.google.com.om *.google.com.pa *.google.com.pe *.google.com.pg *.google.com.ph *.google.com.pk *.google.pl *.google.pn *.google.com.pr *.google.ps *.google.pt *.google.com.py *.google.com.qa *.google.ro *.google.ru *.google.rw *.google.com.sa *.google.com.sb *.google.sc *.google.se *.google.com.sg *.google.sh *.google.si *.google.sk *.google.com.sl *.google.sn *.google.so *.google.sm *.google.sr *.google.st *.google.com.sv *.google.td *.google.tg *.google.co.th *.google.com.tj *.google.tl *.google.tm *.google.tn *.google.to *.google.com.tr *.google.tt *.google.com.tw *.google.co.tz *.google.com.ua *.google.co.ug *.google.co.uk *.google.com.uy *.google.co.uz *.google.com.vc *.google.co.ve *.google.vg *.google.co.vi *.google.com.vn *.google.vu *.google.ws *.google.rs *.google.co.za *.google.co.zm *.google.co.zw *.google.cat *.taboola.com *.doubleclick.net *.outbrain.com *.adobedtm.com *.omtrdc.net *.demdex.net *.everesttech.net *.magentocommerce.com *.sodatech.com *.sodatech.net api.official-deals.co.uk api.official-coupons.com *.adsymptotic.com cdn.livechat-files.com cp.official-coupons.com cookie-cdn.cookiepro.com cp.official-deals.co.uk site-azp.slgnt.us ct.pinterest.com *.ads.linkedin.com cdn.polyfill.io offer.slgnt.us *.blob.core.windows.net s.pinimg.com snap.licdn.com mediacdn.espssl.com *.clarity.ms *.bing.com *.serverdata.net lindtna.test *.lindtna.test *.livechatinc.com mageside.com app-wallee.com *.gstatic.com d.ratepay.com viewer.byondxr.com s3.us-west-2.amazonaws.com showroom-media.byondxr.com media-optimization-service.byondxr.com *.byondxr.com *.listrakbi.com www.mystyleplatform.com static.mystyleplatform.com static2.mystyleplatform.com static2.ogmystyle.com mystyleplatform.s3.us-west-2.amazonaws.com https://www.unifaunonline.se https://*.tile.openstreetmap.org/ www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com https://redchamps.com 'self' data: geowidget.inpost.pl sandbox-easy-geowidget-sdk.easypack24.net widget.packeta.com https://www.upsellit.com https://mediacdn.espssl.com/2824/Shared/Modal/chocolate.png https://www.linkedin.com https://*.linkedin.com/ https://px.ads.linkedin.com *.googleadservices.com *.russellstover.com https://www.google-anaytics.com https://www.googletagmanager.com https://optimize.google.com https://bam.nr-data.net *.bazaarvoice.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net amcglobal.sc.omtrdc.net *.adobe.io use.typekit.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com *.magento-ds.com *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com *.cash.app *.visa.com *.mastercard.com *.sharethis.com *.googleapis.com *.attn.tv events.attentivemobile.com apps.bazaarvoice.com apps.nexus.bazaarvoice.com apps-stg.nexus.bazaarvoice.com analytics-static.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com mpsnare.iesnare.com widget.freshworks.com m2epro.freshdesk.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ www.xtento.com cdn.xtento.com *.pcapredict.com lindt.slgnt.eu maps.googleapis.com *.pinterest.com *.postcodeanywhere.co.uk *.cloudflare.com *.teads.tv *.r66net.com *.facebook.net *.googleadservices.com *.doubleclick.net *.cookiepro.com *.cloudfront.net *.videostep.com *.mfgroup.ch *.taboola.com *.outbrain.com *.adobedtm.com *.authorize.net *.unpkg.com *.fontawesome.com *.sodatech.net *.sodatech.com www.clarity.ms bat.bing.com *.b2c.com bt.fraud0.com container.pepperjam.com www.googleoptimize.com *.hotjar.com *.pepperjamnetwork.com *.revlifter.io site-azp.slgnt.us ct.pinterest.com *.ads.linkedin.com cdn.polyfill.io offer.slgnt.us *.blob.core.windows.net s.pinimg.com snap.licdn.com acsbapp.com cdn.noibu.com www.youtube.com *.upsellit.com *.livechatinc.com *.serverdata.net *.tiktok.com *.ordergroove.com app-wallee.com https://www.googletagmanager.com tagmanager.google.com d.ratepay.com www.jsctool.com byondxr-viewer.byondxr.com web-apps.byondxr.com *.listrakbi.com *.listrak.com mystyleplatform.com www.mystyleplatform.com static.ogmystyle.com static2.ogmystyle.com d203yb14zlmxwn.cloudfront.net cdnjs.cloudflare.com cdn.jsdelivr.net use.fontawesome.com *.mczbf.com https://api.unifaun.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com songbird.cardinalcommerce.com *.google.com *.gstatic.com *.trustpilot.com geowidget.inpost.pl sandbox-easy-geowidget-sdk.easypack24.net widget.packeta.com https://www.youtube.com https://www.googleanalytics.com https://www.google-analytics.com https://www.googleoptimize.com 'unsafe-inline' https://optimize.google.com 'unsafe-inline' https://www.lindt-spruengli.com/* https://www.lindt-spruengli.com/media/target/VAPI.min.js https://www.lindt-spruengli.com/media/target/at.js https://click2cart.com https://ghirardelli.mycontactcenter.net/ https://pop1-apps.mycontactcenter.net/ https://form.jotform.com https://ghirardelli-pages.vercel.app https://form.jotform.com/jsform/250416509718156 https://form.jotform.com/250695600740152 https://api-js.datadome.co 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com *.cash.app https://fonts.googleapis.com/ *.sharethis.com display.ugc.bazaarvoice.com *.amazonaws.com widget.freshworks.com m2epro.freshdesk.com https://static.klaviyo.com *.fonts.net *.postcodeanywhere.co.uk *.cloudfront.net *.cloudflare.com *.sodatech.com *.sodatech.net *.googleapis.com *.getfirebug.com cloud.typography.com *.serverdata.net *.myfonts.net *.russellstover.com tagmanager.google.com d.ratepay.com *.listrakbi.com *.listrak.com use.fontawesome.com www.mystyleplatform.com static.ogmystyle.com static2.ogmystyle.com unsafe-inline assets.braintreegateway.com *.gstatic.com *.trustpilot.com geowidget.inpost.pl widget.packeta.com https://cloud.typography.com 'unsafe-inline' https://optimize.google.com https://fonts.googleapis.com 'unsafe-inline' 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.cloudfront.net *.serverdata.net *.livechatinc.com *.listrakbi.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io *.magento-datasolutions.com *.magento-ds.com *.sentry.io * *.adyen.com *.sharethis.com *.googleapis.com *.attn.tv events.attentivemobile.com api.bazaarvoice.com stg.api.bazaarvoice.com apps.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com widget.freshworks.com m2epro.freshdesk.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.paypal.com *.postcodeanywhere.co.uk *.ratepay.com *.luckyorange.net *.cookiepro.com *.mfgroup.ch *.doubleclick.net *.visitors.live wss://in.visitors.live wss://visitors.live wss://in.visitors.live/ wss://visitors.live/ visitors.live *.taboola.com *.demdex.net *.omtrdc.net *.magento.com *.adobe.net *.adobedtm.com *.adobedc.net *.typekit.net *.magedevteam.com *.sodatech.com *.sodatech.net *.teads.tv www.sjwoe.com input.noibu.com wss://input.noibu.com/pv_part in.hotjar.com www.facebook.com *.b2c.com bt.fraud0.com *.revlifter.com *.pepperjamnetwork.com *.revlifter.io site-azp.slgnt.us ct.pinterest.com *.ads.linkedin.com cdn.polyfill.io offer.slgnt.us s.pinimg.com snap.licdn.com *.acsbapp.com cdn.noibu.com https://maps.googleapis.com *.clarity.ms *.facebook.com *.serverdata.net *.livechatinc.com api.addressy.com *.listrakbi.com *.mczbf.com *.tiktok.com *.ordergroove.com https://www.google-analytics.com d.ratepay.com www.jsctool.com *.byondxr.com api.byondxr.com s3.us-west-2.amazonaws.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.google.com google.com t.elasticsuite.io *.google-analytics.com https://cdn.linkedin.oribi.io https://vc.hotjar.io *.ghirardelli.com *.hotjar.io *.bing.com ws.hotjar.com wss://ws.hotjar.com sc-api.click2cart.com https://geolocation.onetrust.com https://bat.bing.com ghirardelli-pages.vercel.app https://ghirardelli-pages.vercel.app/api/synup https://ghirardelli-pages.vercel.app 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.byondxr.com *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' https://dl.gov.cn https://*.dl.gov.cn;script-src 'unsafe-inline'; style-src 'unsafe-inline'; frame-src 'self' https://widget.tianqiapi.com; child-src 'self' https://widget.tianqiapi.com;report-uri /csp-log; 1 connect-src 'self' https://status.netservicesgroup.com https://www.google-analytics.com; default-src 'self' http://www.techadvisory.org https://maps.googleapis.com https://csi.gstatic.com https://maps.gstatic.com https://helpdesk.netservicesgroup.com:80; img-src 'self' http://www.internettrafficreport.com https://csi.gstatic.com https://maps.googleapis.com https://maps.gstatic.com http://www.techadvisory.org https://www.netservicesgroup.com http://graphs.ntppool.net http://www.pool.ntp.org https://www.google-analytics.com https://secure.trust-provider.com http://www.trustlogo.com/; frame-src https://www.google.com https://status.netservicesgroup.com; child-src https://status.netservicesgroup.com https://www.google.com https://helpdesk.netservicesgroup.com http://openspeedtest.com https://urldefense.proofpoint.com https://quickclick.com; style-src 'self' https://www.netservicesgroup.com https://status.netservicesgroup.com 'sha256-zL+zKXgt2515GaHwEfkV8QPRfZZcGr/ibUw4EJ3V13s=' 'sha256-ES2uzHuEQM4whrqb1S+eihZ+mxiQTgCzn2AsyOHbX88=' 'sha256-ES2uzHuEQM4whrqb1S+eihZ+mxiQTgCzn2AsyOHbX88=' 'sha256-ES2uzHuEQM4whrqb1S+eihZ+mxiQTgCzn2AsyOHbX88=' 'sha256-Pkt8j98M46glrPDzrqR9I9gac/h2nvberIdQkhIGySk=' https://fonts.googleapis.com https://maxcdn.bootstrapcdn.com https://secure.trust-provider.com 'sha256-ES2uzHuEQM4whrqb1S+eihZ+mxiQTgCzn2AsyOHbX88=' 'sha256-rvExcqXg6slhViMilpJKfslIcSuTwNcaJTyiU0PTfEc=' https://secure.comodo.com; script-src 'self' https://www.google.com https://www.gstatic.com https://secure.trust-provider.com http://www.trustlogo.com https://cdnjs.cloudflare.com https://maps.googleapis.com https://www.netservicesgroup.com https://ajax.googleapis.com https://oss.maxcdn.com https://ssl.google-analytics.com https://www.google-analytics.com https://www.googletagmanager.com https://status.netservicesgroup.com https://secure.comodo.com 'sha256-3ocR7726kV2Y3awnQx4u408K1Dxd7l3X9nvrC91J15k=' 'sha256-YG4fTNWYCHAm4AVC2mnK8Tj09alaJWJTk+LJy+5kHho=' 'sha256-ES2uzHuEQM4whrqb1S+eihZ+mxiQTgCzn2AsyOHbX88=' 'sha256-rvExcqXg6slhViMilpJKfslIcSuTwNcaJTyiU0PTfEc=' 'sha256-/LNrhX3k9yooaUcjJ9wGqDoSJEFQEozZc8jtdbq+lMg=' 'sha256-ahfvWH65y6WEYvXXrsReZDD9l5f9wMFjeLjl+8hkRIg=' 'sha256-rvExcqXg6slhViMilpJKfslIcSuTwNcaJTyiU0PTfEc='; font-src 'self' https://www.netservicesgroup.com https://fonts.gstatic.com https://maxcdn.bootstrapcdn.com; report-uri https://www.netservicesgroup.com/csp.php 1 default-src 'self' *.irsn.fr *.asnr.fr; script-src 'self' *.irsn.fr *.asnr.fr cdn.ckeditor.com embed.api.video public.message-business.com static.doubleclick.net unpkg.com vod.api.video www.google.com www.gstatic.com www.youtube.com www.youtube-nocookie.com e.infogram.com; object-src 'none'; style-src 'self' 'unsafe-inline' *.irsn.fr *.asnr.fr fonts.googleapis.com unpkg.com www.youtube.com www.youtube-nocookie.com; img-src 'self' data: *.irsn.fr *.asnr.fr i.ytimg.com yt3.ggpht.com *.tile.openstreetmap.org; media-src 'self' *.irsn.fr *.asnr.fr; frame-src 'self' *.irsn.fr *.asnr.fr embed.api.video www.youtube.com www.youtube-nocookie.com e.infogram.com; frame-ancestors 'self' *.irsn.fr *.asnr.fr; child-src 'self' *.irsn.fr *.asnr.fr embed.api.video www.youtube.com www.youtube-nocookie.com; font-src 'self' data: *.irsn.fr *.asnr.fr embed.api.video fonts.gstatic.com themes.googleusercontent.com; connect-src 'self' *.irsn.fr *.asnr.fr collector.api.video googleads.g.doubleclick.net jnn-pa.googleapis.com vod.api.video www.youtube.com www.youtube-nocookie.com; report-uri /sa-report-csp-violation; upgrade-insecure-requests 1 object-src 'none';base-uri 'self';script-src 'nonce-ktuU2AgI5bctS46xDHp3Lw' 'strict-dynamic' 'report-sample' 'unsafe-eval' 'unsafe-inline' https: http:;report-uri https://csp.withgoogle.com/csp/gws/other-hp 1 default-src 'self' 'unsafe-inline' www.googletagmanager.com www.google-analytics.com ipv4check.ec-elements.com ipv6check.ec-elements.com data: 'unsafe-eval'; report-uri /csp-violation-report-endpoint/ 1 worker-src *.noibu.com; font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com *.googleapis.com *.bootstrapcdn.com *.paypalobjects.com *.gladly.com *.cookielaw.org www.google.com www.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com https://plumrocket.com *.tilebar-vis.com *.byondxr.com *.facebook.com *.facebook.net *.yotpo.com *.listrakbi.com *.cookielaw.org *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com https://plumrocket.com *.tilebar-vis.com *.byondxr.com sketchfab.com *.weltpixel.com *.facebook.com *.paypalobjects.com *.yotpo.com *.cardknox.com *.vimeo.com vimeo.com *.googletagmanager.com *.xtento.com *.doubleclick.net *.gladly.com *.optimizely.com *.creativecdn.com *.pinterest.com *.listrakbi.com *.cookielaw.org *.noibu.com photos.pixlee.co cdn.cardknox.com/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * speedsize.com *.speedsize.com www.xtento.com 'self' 'unsafe-inline'; img-src *.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io *.paypal.com *.typekit.net *.gstatic.com www.apptrian.com *.googleadservices.com *.facebook.com *.yotpo.com *.cdninstagram.com *.google-analytics.com *.google.com *.google.com.vn *.google.co.il *.google.com.sg *.google.co.uk *.google.de *.magentocommerce.com *.paypalobjects.com *.ytimg.com *.web-view.net *.googleapis.com *.nagich.co.il vimeo.com *.vimeo.com *.tilebar.com *.zdassets.com *.pxlecdn.com *.cloudfront.net *.roomvo.com *.tilebar-vis.com *.byondxr.com *.searchspring.net *.gladly.com *.edgecastcdn.net *.doubleclick.net *.bing.com *.pinterest.com *.optimizely.com *.adnxs.com *.pubmatic.com *.adingo.jp *.adingo.com *.creativecdn.com *.yahoo.com *.yahoo.net *.33across.com *.mobon.net *.seedtag.com *.clarity.ms *.brcdn.com *.brsrvr.com *.listrakbi.com *.cookielaw.org wac.edgecastcdn.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com https://redchamps.com speedsize.com *.speedsize.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com *.vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ www.apptrian.com *.byondxr.com *.tilebar-vis.com *.fontawesome.com *.googleapis.com *.gstatic.com *.dxpapi.com *.google-analytics.com apis.google.com *.googleadservices.com *.googletagmanager.com *.facebook.net *.doubleclick.net *.analytics.com *.rawgit.com *.nagich.co.il *.luckyorange.com *.xtento.com *.paypal.com *.paypalobjects.com *.forsixty.com *.criteo.com *.searchspring.io *.searchspring.net *.roomvo.io *.roomvo.com *.cloudflareinsights.com *.optimizely.com *.turnto.com *.pixlee.com *.pxlecdn.com *.cloudflare.com *.gladly.com *.smooch.io *.bing.com *.creativecdn.com *.pinimg.com *.particularaudience.com *.googletagservices.com *.googlesyndication.com cnstrc.com getrockerbox.com/ *.adnxs.com *.adingo.jp *.adingo.com *.cnstrc.com *.tilebar.com *.pinterest.com *.callrail.com *.clarity.ms *.algoliaradar.com *.brcdn.com *.listrakbi.com *.cloudfront.net *.cookielaw.org *.noibu.com cdn.cardknox.com/ifields/2.15.2405.1601/ifields.min.js js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com speedsize.com *.speedsize.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com *.googleapis.com *.bootstrapcdn.com *.cloudflare.com *.turnto.com *.gladly.com *.brcdn.com *.listrakbi.com *.cookielaw.org *.google.com *.gstatic.com *.typekit.net assets.braintreegateway.com speedsize.com *.speedsize.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com speedsize.com *.speedsize.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com www.apptrian.com *.dxpapi.com *.doubleclick.net *.analytics.com *.facebook.com *.google-analytics.com *.nagich.co.il player.vimeo.com *.luckyorange.com *.googleapis.com *.visitors.live *.zdassets.com *.searchspring.io *.searchspring.net *.roomvo.io *.roomvo.com cloudflareinsights.com *.cloudflareinsights.com *.optimizely.com *.turnto.com *.tilebar-vis.com *.byondxr.com unpkg.com *.unpkg.com *.gladly.com *.smooch.io *.creativecdn.com *.pinimg.com *.particularaudience.com *.googletagservices.com *.googlesyndication.com *.pinterest.com *.cnstrc.com *.cardknox.com *.clarity.ms *.pixlee.com *.algolia.io *.listrakbi.com *.betanetqa.me *.cloudflare.com *.cookielaw.org https://*.noibu.com wss://*.noibu.com www.google.com www.gstatic.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com speedsize.com *.speedsize.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src speedsize.com *.speedsize.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri /bnews/csp/report; report-to report-endpoint; 1 default-src 'none'; report-uri https://csp-reporting.cloudflare.com/cdn-cgi/script_monitor/report?m=dFGuI1l5Oondzc3oHlk13Ayt6Gl0kot7PWfCGolg8LI-1770426367.0503318-1.0.1.1-.dr1G3LT9G1cn07.EqjP9a3zLPni4IkAlS4smMwsyN.oPg0hJpR02vk.KSDpuQLeC.GjIpJU6Z5waL0RtPsW3SpHGI9Jyq.H0OuOJeqki.Crs.paNMeze_wRgNHFjaAFAG9EVRLkqVMDCapvWC8mSij8AHNhNvL68hvIaTECIRkZG0Wkv9K5dBxyDi1P5VCx_hQjMxikQ2YpR7tAW9Ygqw; report-to cf-wweotgymgqwbesdx 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.salesforceliveagent.com *.cloudflare.com *.force.com *.adsrvr.org *.bing.com *.clickcease.com *.connect.facebook.net *.cookielaw.org *.doubleclick.net *.facebook.com *.wistia.com *.hsforms.com *.forms-na1.hsforms.com *.gtm.prosci.com *.googletagmanager.com *.gstatic.com *.hs-scripts.com *.hs-sites.com *.hsforms.net *.hubspot.com *.hubspotusercontent-na1.net *.hsadspixel.net *.js.usemessages.com *.jsdelivr.net *.kit.fontawesome.com *.luckyorange.com *.prosci.com *.linkedin.com *.licdn.com *.hsappstatic.net *.hubapi.com *.cloudflare *.fontawesome.com *.hsleadflows.net *.hs-analytics.net js.usemessages.com js.hs-banner.com *.google.com *.google.pl *.bing.net js.hubspotfeedback.com *.facebook.net *.googleapis.com *.sentry-cdn.com *.hubspot.net; style-src 'self' 'unsafe-inline' *.cloudflare.com *.adsrvr.org *.bing.com *.clickcease.com *.connect.facebook.net *.cookielaw.org *.doubleclick.net *.facebook.com *.wistia.com *.hsforms.com *.forms-na1.hsforms.com *.gtm.prosci.com *.googletagmanager.com *.gstatic.com *.hs-scripts.com *.hs-sites.com *.hsforms.net *.hubspot.com *.hubspotusercontent-na1.net *.hsadspixel.net *.js.usemessages.com *.jsdelivr.net *.kit.fontawesome.com *.luckyorange.com *.prosci.com *.linkedin.com *.licdn.com *.hsappstatic.net *.hubapi.com *.cloudflare *.fontawesome.com *.hsleadflows.net *.hs-analytics.net js.usemessages.com js.hs-banner.com *.google.pl *.bing.net *.google.com *.facebook.net *.googleapis.com *.sentry-cdn.com *.hubspot.net; img-src 'self' data: blob: *.cloudflare.com *.adsrvr.org *.bing.com *.clickcease.com *.connect.facebook.net *.cookielaw.org *.doubleclick.net *.facebook.com *.wistia.com *.hsforms.com *.forms-na1.hsforms.com *.gtm.prosci.com *.googletagmanager.com *.gstatic.com *.hs-scripts.com *.hs-sites.com *.hsforms.net *.hubspot.com *.hubspotusercontent-na1.net *.hsadspixel.net *.js.usemessages.com *.jsdelivr.net *.kit.fontawesome.com *.luckyorange.com *.prosci.com *.linkedin.com *.licdn.com *.hsappstatic.net *.hubapi.com *.cloudflare *.fontawesome.com *.hsleadflows.net *.hs-analytics.net js.usemessages.com js.hs-banner.com *.google.pl *.bing.net *.google.com *.facebook.net *.googleapis.com *.sentry-cdn.com *.hubspot.net; frame-src *.force.com *.adsrvr.org *.facebook.com *.wistia.com *.hsforms.com *.forms-na1.hsforms.com *.hs-sites.com *.hsforms.net *.hubspot.com *.googletagmanager.com *.doubleclick.net gtm.prosci.com; connect-src 'self' *.cloudflare.com *.adsrvr.org *.bing.com *.clickcease.com *.connect.facebook.net *.cookielaw.org *.doubleclick.net *.facebook.com *.wistia.com *.hsforms.com *.forms-na1.hsforms.com *.gtm.prosci.com *.googletagmanager.com *.gstatic.com *.hs-scripts.com *.hs-sites.com *.hsforms.net *.hubspot.com *.hubspotusercontent-na1.net *.hsadspixel.net *.js.usemessages.com *.jsdelivr.net *.kit.fontawesome.com *.luckyorange.com *.prosci.com *.linkedin.com *.licdn.com *.hsappstatic.net *.hubapi.com *.cloudflare *.fontawesome.com *.hsleadflows.net *.hs-analytics.net js.usemessages.com js.hs-banner.com *.google.pl *.bing.net *.google.com *.facebook.net *.googleapis.com *.sentry-cdn.com *.hubspot.net; font-src 'self' data: *.cloudflare.com *.adsrvr.org *.bing.com *.clickcease.com *.connect.facebook.net *.cookielaw.org *.doubleclick.net *.facebook.com *.wistia.com *.hsforms.com *.forms-na1.hsforms.com *.gtm.prosci.com *.googletagmanager.com *.gstatic.com *.hs-scripts.com *.hs-sites.com *.hsforms.net *.hubspot.com *.hubspotusercontent-na1.net *.hsadspixel.net *.js.usemessages.com *.jsdelivr.net *.kit.fontawesome.com *.luckyorange.com *.prosci.com *.linkedin.com *.licdn.com *.hsappstatic.net *.hubapi.com *.cloudflare *.fontawesome.com *.hsleadflows.net *.hs-analytics.net js.usemessages.com js.hs-banner.com *.google.pl *.bing.net *.google.com *.facebook.net *.googleapis.com *.sentry-cdn.com *.hubspot.net; 1 font-src fonts.gstatic.com https://fonts.gstatic.com *.fontawesome.com maxcdn.bootstrapcdn.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.authorize.net *.ccavenue.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.authorize.net *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ bid.g.doubleclick.net *.youtube-nocookie.com services.sheerid.com *.authorize.net *.ccavenue.com www.googletagmanager.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com https://images.unsplash.com *.visualwebsiteoptimizer.com *.hsforms.com *.gstatic.com shareasale.com *.google.com.ua bat.bing.com *.facebook.com *.fs1.hubspotusercontent-na1.net track.hubspot.com t.co analytics.twitter.com/ bat.bing.net *.google.de services.sheerid.com *.cloudfront.net edge.marker.io store.paradoxlabs.com *.ccavenue.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.google.com *.googleadservices.com *.google-analytics.com *.googletagmanager.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com https://maps.googleapis.com maps.googleapis.com *.visualwebsiteoptimizer.com *.hsforms.net *.dwin1.com *.amplitude.com js.hs-scripts.com bat.bing.com static.ads-twitter.com *.hotjar.com cdn.jsdelivr.net cdn.jst.ai tags.srv.stackadapt.com js.hubspot.com js.hsadspixel.net js.hscollectedforms.net js.hs-banner.com js.hubspotfeedback.com js.hsleadflows.net js.hs-analytics.net my.jst.ai *.clarity.ms aly.jst.ai smct.co edge.marker.io services.sheerid.com *.forethought.ai static-tracking.klaviyo.com api.marker.io *.authorize.net *.ccavenue.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.kaptcha.com *.avada.io connect.facebook.net *.googletagmanager.com *.googleadservices.com *.google-analytics.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com songbird.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com tags.srv.stackadapt.com services.sheerid.com *.klaviyo.com https://static.klaviyo.com https://fonts.googleapis.com *.fontawesome.com maxcdn.bootstrapcdn.com *.stripe.network *.stripecdn.com *.amazon.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com v.ftcdn.net 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.newrelic.com *.nr-data.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com vimeo.com https://maps.googleapis.com https://player.vimeo.com forms.hsforms.com *.googleapis.com *.amplitude.com *.visualwebsiteoptimizer.com bat.bing.net bat.bing.com cta-service-cms2.hubspot.com api.hubapi.com *.hotjar.com *.hotjar.io forms.hscollectedforms.net *.clarity.ms tags.srv.stackadapt.com forms.hubspot.com smct.co aly.jst.ai wss://ws.hotjar.com/api/v2/client/ws api.marker.io ipapi.co static-tracking.klaviyo.com *.authorize.net *.ccavenue.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.kaptcha.com https://get.geojs.io *.avada.io *.google-analytics.com *.analytics.google.com *.googletagmanager.com stats.g.doubleclick.net *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 connect-src 'self' https://*.analytics.google.com https://*.aptrinsic.com https://*.g.doubleclick.net https://*.google-analytics.com https://*.google.com https://*.googletagmanager.com https://*.sentry.io https://api.ipgeolocation.io https://api.triptease.io https://bat.bing.com https://bat.bing.net https://consent.cookiebot.com https://consentcdn.cookiebot.com https://content.hotjar.io https://data.flip.to https://dc.services.visualstudio.com https://fonts.googleapis.com https://google.com https://googleads.g.doubleclick.net https://maps.googleapis.com https://mc.yandex.com https://mc.yandex.ru https://messages.guest-experience.triptease.io https://metrics.corinthia.com https://metrics.hotjar.io https://onboard.triptease.io https://p.relay-t.io https://region1.analytics.google.com https://sa.flip.to https://scripts.affilired.com https://sleeknotestaticcontent.sleeknote.com https://static-meta.triptease.io https://stats.g.doubleclick.net https://sync.srv.stackadapt.com https://tags.srv.stackadapt.com https://vc.hotjar.io https://wl-suppliers.app.cvent.com https://www.dripuploads.com https://www.facebook.com https://www.google.ae https://www.google.co.uk https://www.google.com https://www.menumodo.com https://www.thehotelsnetwork.com wss://ws.hotjar.com; default-src 'self' https://*.adform.net https://*.adnxs.com https://*.sentry.io https://cdn.jsdelivr.net/npm/bootstrap@4.6.2/; font-src 'self' data: https://*.cloudfront.net/graphik/ https://*.cloudfront.net/lato/ https://fonts.googleapis.com https://fonts.gstatic.com https://fonts.gstatic.com/s/barlow/ https://fonts.gstatic.com/s/lato/ https://fonts.gstatic.com/s/roboto/ https://static.tacdn.com https://use.typekit.net https://www.menumodo.com; frame-src 'self' https://*.adsrvr.org https://*.fls.doubleclick.net https://*.speedrfp.com https://consent.cookiebot.com https://consentcdn.cookiebot.com https://customs.affilired.com https://mc.yandex.com https://mc.yandex.ru https://onboard.triptease.io https://targeted-messages.triptease.io https://td.doubleclick.net https://www.facebook.com https://www.google.com https://www.googletagmanager.com https://www.opentable.co.uk https://www.thehotelsnetwork.com https://www.youtube-nocookie.com; img-src 'self' blob: data: *.ggpht.com *.googleapis.com *.linkedin.com https://*.adform.net https://*.adnxs.com https://*.adsrvr.org https://*.analytics.google.com https://*.g.doubleclick.net https://*.google-analytics.com https://*.google.com https://*.googletagmanager.com https://*.sojern.com https://*.speedrfp.com https://*.youtube.com https://ad.doubleclick.net https://bat.bing.com https://cdnjs.cloudflare.com/ajax/libs/intl-tel-input/17.0.19/ https://cm.g.doubleclick.net/pixel https://cms.analytics.yahoo.com https://d1cmxvrarpztze.cloudfront.net https://dpm.demdex.net https://googletagmanager.com https://i.ytimg.com https://imgsct.cookiebot.com https://mc.yandex.com https://mc.yandex.ru https://metrics.corinthia.com https://pubads.g.doubleclick.net https://region1.analytics.google.com https://ssl.gstatic.com https://stackadapt.com https://static.tacdn.com https://stats.g.doubleclick.net https://storage.ghadiscovery.com https://sync.srv.stackadapt.com https://tags.srv.stackadapt.com https://tags.w55c.net https://www.facebook.com https://www.google.ae https://www.google.co.uk https://www.google.com https://www.gstatic.com https://www.menumodo.com https://www.pages04.net https://www.tripadvisor.co.uk maps.gstatic.com; manifest-src 'self'; media-src 'self'; script-src-elem 'self' 'unsafe-inline' *.licdn.com https://*.adsrvr.org https://*.aptrinsic.com https://*.google-analytics.com https://*.google.com https://*.googletagmanager.com https://*.sojern.com https://*.speedrfp.com https://*.youtube.com https://ajax.googleapis.com https://api.getdrip.com https://bat.bing.com https://browser.sentry-cdn.com https://cdn.denomatic.com https://cdn.flip.to https://cdn.jsdelivr.net https://cdn.jsdelivr.net/npm/bootstrap@4.6.2/ https://cdn.jsdelivr.net/npm/bootstrap@5.0.0-beta2/ https://cdn.jsdelivr.net/npm/bootstrap@5.0.2/ https://cdn.jsdelivr.net/npm/bootstrap@5.2.3/ https://cdn.jsdelivr.net/npm/feather-icons/ https://cdn.jsdelivr.net/npm/ip-geolocation-api-jquery-sdk@1.0.6/ https://cdn.jsdelivr.net/npm/jquery@3.5.1/ https://cdn.jsdelivr.net/npm/jquery@3.6.4/ https://cdn.jsdelivr.net/npm/popper.js@1.16.1/ https://cdn.otstatic.com https://cdnjs.cloudflare.com/ajax/libs/intl-tel-input/17.0.19/ https://cdnjs.cloudflare.com/ajax/libs/popper.js/1.12.9/ https://code.jquery.com/jquery-3.2.1.slim.min.js https://components.flip.to https://connect.facebook.net https://consent.cookiebot.com https://consentcdn.cookiebot.com https://contentz.mkt941.com https://customs.affilired.com https://d16fk4ms6rqz1v.cloudfront.net https://googleads.g.doubleclick.net https://integration.flip.to https://js.monitor.azure.com https://js.sentry-cdn.com https://maps.googleapis.com https://maps.googleapis.com/maps/api/* https://maxcdn.bootstrapcdn.com/bootstrap/4.0.0/ https://mc.yandex.com https://mc.yandex.ru https://navigator.ink-global.com https://onboard.triptease.io https://p.relay-t.io https://script.crazyegg.com https://script.hotjar.com https://sleeknotecustomerscripts.sleeknote.com https://sleeknotestaticcontent.s3.eu-west-1.amazonaws.com https://sleeknotestaticcontent.sleeknote.com https://static-meta.triptease.io https://static.hotjar.com https://static.tacdn.com https://static.x-channel.triptease.io https://tag.getdrip.com https://tag.yieldoptimizer.com https://tagmanager.google.com https://tags.srv.stackadapt.com/events.js https://targeted-messages.triptease.io https://www.googletagmanager.com https://www.gstatic.com/recaptcha/ https://www.jscache.com https://www.menumodo.com https://www.opentable.co.uk https://www.thehotelsnetwork.com https://www.tripadvisor.com; script-src 'self' 'unsafe-eval' 'unsafe-inline' https://*.adsrvr.org https://*.aptrinsic.com https://*.google-analytics.com https://*.googletagmanager.com https://*.gstatic.com https://*.sojern.com https://*.speedrfp.com https://*.youtube.com https://ajax.googleapis.com https://api.getdrip.com https://bat.bing.com https://browser.sentry-cdn.com https://cdn.denomatic.com https://cdn.flip.to https://cdn.jsdelivr.net/npm/bootstrap@4.6.2/ https://cdn.jsdelivr.net/npm/bootstrap@5.0.0-beta2/ https://cdn.jsdelivr.net/npm/bootstrap@5.0.2/ https://cdn.jsdelivr.net/npm/bootstrap@5.2.3/ https://cdn.jsdelivr.net/npm/feather-icons@4.29.0/ https://cdn.jsdelivr.net/npm/feather-icons/ https://cdn.jsdelivr.net/npm/ip-geolocation-api-jquery-sdk@1.0.6/ https://cdn.jsdelivr.net/npm/jquery@3.5.1/ https://cdn.jsdelivr.net/npm/jquery@3.6.4/ https://cdn.jsdelivr.net/npm/popper.js@1.16.1/ https://cdn.otstatic.com https://cdnjs.cloudflare.com/ajax/libs/intl-tel-input/17.0.19/ https://cdnjs.cloudflare.com/ajax/libs/popper.js/1.12.9/ https://code.jquery.com/jquery-3.2.1.slim.min.js https://components.flip.to https://connect.facebook.net https://consent.cookiebot.com https://consentcdn.cookiebot.com https://contentz.mkt941.com https://customs.affilired.com https://d16fk4ms6rqz1v.cloudfront.net https://googleads.g.doubleclick.net https://googletagmanager.com https://integration.flip.to https://js.monitor.azure.com https://js.sentry-cdn.com https://maps.googleapis.com https://maxcdn.bootstrapcdn.com/bootstrap/4.0.0/ https://mc.yandex.com https://mc.yandex.ru https://navigator.ink-global.com https://onboard.triptease.io https://p.relay-t.io https://script.crazyegg.com https://script.hotjar.com https://sleeknotecustomerscripts.sleeknote.com https://sleeknotestaticcontent.s3.eu-west-1.amazonaws.com https://sleeknotestaticcontent.sleeknote.com https://static-meta.triptease.io https://static.hotjar.com https://static.tacdn.com https://tag.getdrip.com https://tag.yieldoptimizer.com https://tagmanager.google.com https://tags.srv.stackadapt.com https://targeted-messages.triptease.io https://wl-suppliers.app.cvent.com https://www.google.com https://www.gstatic.com/recaptcha/ https://www.jscache.com https://www.opentable.co.uk https://www.thehotelsnetwork.com https://www.tripadvisor.co.uk https://www.tripadvisor.com; style-src-elem 'self' 'unsafe-inline' https://cdn.jsdelivr.net/npm/bootstrap@5.2.3/dist/css/bootstrap.min.css https://p.typekit.net https://tags.srv.stackadapt.com/sa.css https://use.typekit.net https://www.menumodo.com; style-src 'self' 'unsafe-inline' data: https://*.aptrinsic.com https://*.googletagmanager.com https://cdn.jsdelivr.net/npm/bootstrap@4.6.2/ https://cdn.jsdelivr.net/npm/bootstrap@5.0.0-beta2/ https://cdn.jsdelivr.net/npm/bootstrap@5.0.2/ https://cdn.jsdelivr.net/npm/bootstrap@5.2.3/ https://cdnjs.cloudflare.com/ajax/libs/intl-tel-input/17.0.19/ https://fonts.googleapis.com https://googletagmanager.com https://maxcdn.bootstrapcdn.com/bootstrap/4.0.0/ https://p.typekit.net https://static.tacdn.com https://tagmanager.google.com https://use.typekit.net https://www.menumodo.com; script-src-attr https://www.menumodo.com; 1 default-src 'self' 'unsafe-inline'; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.authorize.net *.google.com cdnjs.cloudflare.com cdn.rawgit.com maps.googleapis.com rw1.marchex.io connect.facebook.net googleads.g.doubleclick.net *.googletagmanager.com *.google-analytics.com *.googleadservices.com *.gstatic.com cdn.jsdelivr.net *.youtube.com *.vimeo.com s.ytimg.com *.googlesyndication.com *.hotjar.com unpkg.com *.googleapis.com investors.danaher.com cdn.cookielaw.org *.onetrust.com *.marketingcloudfx.com *.leadmanagerfx.com *.usefathom.com *.decibelinsight.net *.decibel.com *.medallia.com; object-src *.oembed.com *.vimeo.com *.youtube.com; style-src 'self' 'unsafe-inline' cdnjs.cloudflare.com fonts.googleapis.com tagmanager.google.com *.gstatic.com *.typekit.net *.jsdelivr.net maxcdn.bootstrapcdn.com investors.danaher.com *.onetrust.com; img-src 'self' 'unsafe-inline' data: maps.googleapis.com px.marchex.io *.facebook.com *.google.com *.gstatic.com cdn.rawgit.com raw.githubusercontent.com *.g.doubleclick.net *.google-analytics.com *.googletagmanager.com zensource-salisbury.s3.amazonaws.com chat.mcsoftware.com *.timevaluecalculators.com *.ytimg.com cdn.cookielaw.org *.vimeocdn.com *.usefathom.com; media-src *.vimeo.com *.youtube.com *.spotify.com *.vimeocdn.com 'self'; frame-src 'self' 'unsafe-inline' *.doubleclick.net *.google.com players.brightcove.net *.youtube.com *.googletagmanager.com vars.hotjar.com *.spotify.com *.vimeo.com player.vimeo.com; font-src data: 'self' 'unsafe-inline' fonts.googleapis.com fonts.gstatic.com use.typekit.net maxcdn.bootstrapcdn.com cdnjs.cloudflare.com *.onetrust.com; connect-src 'self' 'unsafe-inline' *.authorize.net *.facebook.com *.onetrust.com stats.addtoany.com *.google-analytics.com cdn.cookielaw.org *.hotjar.com:* *.hotjar.com:* vc.hotjar.io:* wss://*.hotjar.com stats.g.doubleclick.net *.clarity.ms privacyportal-de.onetrust.com *.marketingcloudfx.com *.leadmanagerfx.com *.decibelinsight.net *.decibel.com *.medallia.com; report-uri /report-csp-violation 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://fonts.gstatic.com https://ws.colissimo.fr *.fontawesome.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com https://plumrocket.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.dotdigital-pages.com *.dotdigital.com webchat.dotdigital.com webchat.staging.dotdigital.com https://www.youtube.com https://form.typeform.com *.criteo.com *.hotjar.com *.facebook.com *.simply-jobs.fr https://plumrocket.com payment.direct.worldline-solutions.com payment.preprod.direct.worldline-solutions.com payment.anzworldline-solutions.com.au payment.preprod.anzworldline-solutions.com.au payment.payone.com payment.preprod.payone.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.bird.eu *.trackedlink.net *.ddlnk.net https://maps.googleapis.com https://maps.gstatic.com https://ws.colissimo.fr https://*.tile.openstreetmap.fr https://*.onyourmap.com https://google.fr magefan.com cm.magefan.com *.disqus.com *.thebrighttag.com *.avis-verifies.com *.adform.net id5-sync.com *.liadm.com *.google.com *.google.fr *.kameleoon.eu *.nr-data.net *.metaffiliation.com *.facebook.com *.d-bi.fr *.adnxs.com *.omnitagjs.com *.casalemedia.com *.dmxleo.com *.360yield.com *.criteo.com *.media.net *.mediavine.com *.outbrain.com *.pubmatic.com *.rubiconproject.com *.sharethrough.com *.smaato.net *.smartadserver.com *.taboola.com *.teads.tv *.3lift.com *.advertising.com *.yahoo.com *.yieldlab.net *.yieldmo.com *.rlcdn.com *.smartclip.net *.tremorhub.com *.twiago.com *.krxd.net *.bing.com *.bidswitch.net *.doubleclick.net *.googletagmanager.com *.googleapis.com *.monnaiedeparis.fr blob: www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net amcglobal.sc.omtrdc.net commerce.adobe.net use.typekit.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-ds.com *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://rum.hlx.page *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal webchat.dotdigital.com webchat.staging.dotdigital.com https://maps.googleapis.com https://www.google.com https://www.gstatic.com https://ws.colissimo.fr https://api.mapbox.com https://*.typeform.com *.disqus.com *.kameleoon.eu *.google.fr *.facebook.net *.d-bi.fr *.hotjar.com *.serving-sys.com *.criteo.com *.criteo.net *.monnaiedeparis.fr *.metaffiliation.com *.eulerian.net *.doubleclick.net *.bing.com *.soundclound.com *.soundcloud.com *.piwik.pro *.gstatic.com *.clarity.ms ipinfo.io *.addtoany.com *.googletagmanager.com *.m1by1.com payment.direct.worldline-solutions.com payment.preprod.direct.worldline-solutions.com payment.anzworldline-solutions.com.au payment.preprod.anzworldline-solutions.com.au payment.payone.com payment.preprod.payone.com https://widgets.rr.skeepers.io/ https://api-product-reviews.cxr.skeepers.io/ https://cl-ppr.rr.skeepers.io/ https://cl-pbr.cxr.skeepers.io/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://www.monnaiedeparis.fr 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com webchat.dotdigital.com webchat.staging.dotdigital.com https://fonts.googleapis.com https://ws.colissimo.fr https://api.mapbox.com https://*.typeform.com *.fontawesome.com *.googleapis.com *.addtoany.com 'self' data: *.typekit.net maxcdn.bootstrapcdn.com assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io commerce.adobe.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com qa-api.magedevteam.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com https://ws.colissimo.fr https://maps.googleapis.com https://nominatim.openstreetmap.org https://*.onyourmap.com https://*.mapbox.com http://dpm.demdex.net *.google-analytics.com *.g.doubleclick.net *.kameleoon.eu *.google.fr *.hotjar.com *.serving-sys.com *.criteo.com *.criteo.net *.monnaiedeparis.fr *.metaffiliation.com *.eulerian.net *.piwik.pro * payment.direct.worldline-solutions.com payment.preprod.direct.worldline-solutions.com payment.anzworldline-solutions.com.au payment.preprod.anzworldline-solutions.com.au payment.payone.com payment.preprod.payone.com https://widgets.rr.skeepers.io/ https://api-product-reviews.cxr.skeepers.io/ https://cl-ppr.rr.skeepers.io/ https://cl-pbr.cxr.skeepers.io/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://fonts.googleapis.com; report-to report-endpoint; 1 object-src 'none'; script-src 'self' cdn.jsdelivr.net cdnjs.cloudflare.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com https://use.fontawesome.com mdbootstrap.com; script-src-attr 'self'; style-src 'self' cdn.jsdelivr.net cdnjs.cloudflare.com fonts.googleapis.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://fonts.googleapis.com https://unpkg.com mdbootstrap.com use.fontawesome.com; style-src-attr 'self'; frame-ancestors 'self' 1 object-src 'none'; block-all-mixed-content; default-src 'self'; img-src 'self' data: https://biblionix.com/ https://demonstration.biblionix.com https://secure.gravatar.com/; style-src 'self' 'unsafe-inline' https://demonstration.biblionix.com https://www.gstatic.com/ https://fonts.googleapis.com/; script-src 'self' 'unsafe-eval' 'unsafe-inline' https://demonstration.biblionix.com https://www.gstatic.com/ https://cdn.walkme.com/; font-src 'self' https://fonts.gstatic.com/ data:; report-uri https://www.biblionix.com/report/?block=0 1 frame-ancestors 'none'; report-uri https://13fc2e96c75baedc98bc60c37c2c93be.report-uri.com/r/d/csp/wizard; script-src 'strict-dynamic' 'nonce-bIm1z6gSSi4XH3Cjsu2nGw==' 1 object-src 'none';base-uri 'self';script-src 'nonce-WTQ9PINQh07FtkT3kicABg' 'strict-dynamic' 'report-sample' 'unsafe-eval' 'unsafe-inline' https: http:;report-uri https://csp.withgoogle.com/csp/gws/other-hp 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' c.amazon-adsystem.com *.prod.mplat-ppcprotect.com res4.applovin.com c.albss.com s.axon.ai cdn.attn.tv the.sciencebehindecommerce.com lantern.roeyecdn.com www.dwin1.com *.bing.com bat.bing.net t.contentsquare.net *.scarabresearch.com connect.facebook.net www.facebook.com uktc.fospha.com www.googletagmanager.com maps.googleapis.com pagead2.googlesyndication.com googleads.g.doubleclick.net www.google-analytics.com *.google.com www.gstatic.com *.google-analytics.com heapanalytics.com cdn.heapanalytics.com cdn.huel.io global.localizecdn.com services.postcodeanywhere.co.uk pub.loudcrowd.com survey-cdn.lumoa.me *.mention-me.com *.clarity.ms *.onetrust.com *.optimizely.com paperplaneslive.com www.paypal.com cdn.pdst.fm d34r8q7sht0t9k.cloudfront.net www.redditstatic.com *.shopify.com cdn.shopify.com sc-static.net tr.snapchat.com pixel.byspotify.com js.stripe.com cdn.studentbeans.com connect.studentbeans.com d2hrivdxn8ekm8.cloudfront.net acdn.adnxs.com action.dstillery.com *.tiktok.com analytics-ipv6.tiktokw.us sf16-website-login.neutral.ttwstatic.com widget.trustpilot.com va.vercel-scripts.com vercel.live b99.yahoo.co.jp s.yimg.jp *.zdassets.com *.zendesk.com *.zopim.com; style-src 'self' 'unsafe-inline' fonts.googleapis.com www.gstatic.com fonts.gstatic.com cdn.huel.io services.postcodeanywhere.co.uk *.onetrust.com cdn.studentbeans.com sf16-website-login.neutral.ttwstatic.com vercel.live *.zdassets.com *.zendesk.com *.zopim.com; img-src blob: data: 'self' trkn.us match.adsrvr.org ce.lijit.com huel-us.attn.tv events.attentivemobile.com www.awin1.com www.wepowerconnections.com lantern.roeye.com *.bing.com bat.bing.net *.ctfassets.net www.facebook.com connect.facebook.com connect.facebook.net lookaside.fbsbx.com uktc.fospha.com www.googletagmanager.com *.gstatic.com maps.google.com googleads.g.doubleclick.net region1.analytics.google.com stats.g.doubleclick.net *.google-analytics.com pagead2.googlesyndication.com google.com translate.google.com www.googleadservices.com www.google.com www.google.ad www.google.ae www.google.com.af www.google.com.ag www.google.al www.google.am www.google.co.ao www.google.com.ar www.google.as www.google.at www.google.com.au www.google.az www.google.ba www.google.com.bd www.google.be www.google.bf www.google.bg www.google.com.bh www.google.bi www.google.bj www.google.com.bn www.google.com.bo www.google.com.br www.google.bs www.google.bt www.google.co.bw www.google.by www.google.com.bz www.google.ca www.google.cd www.google.cf www.google.cg www.google.ch www.google.ci www.google.co.ck www.google.cl www.google.cm www.google.cn www.google.com.co www.google.co.cr www.google.com.cu www.google.cv www.google.com.cy www.google.cz www.google.de www.google.dj www.google.dk www.google.dm www.google.com.do www.google.dz www.google.com.ec www.google.ee www.google.com.eg www.google.es www.google.com.et www.google.fi www.google.com.fj www.google.fm www.google.fr www.google.ga www.google.ge www.google.gg www.google.com.gh www.google.com.gi www.google.gl www.google.gm www.google.gr www.google.com.gt www.google.gy www.google.com.hk www.google.hn www.google.hr www.google.ht www.google.hu www.google.co.id www.google.ie www.google.co.il www.google.im www.google.co.in www.google.iq www.google.is www.google.it www.google.je www.google.com.jm www.google.jo www.google.co.jp www.google.co.ke www.google.com.kh www.google.ki www.google.kg www.google.co.kr www.google.com.kw www.google.kz www.google.la www.google.com.lb www.google.li www.google.lk www.google.co.ls www.google.lt www.google.lu www.google.lv www.google.com.ly www.google.co.ma www.google.md www.google.me www.google.mg www.google.mk www.google.ml www.google.com.mm www.google.mn www.google.com.mt www.google.mu www.google.mv www.google.mw www.google.com.mx www.google.com.my www.google.co.mz www.google.com.na www.google.com.ng www.google.com.ni www.google.ne www.google.nl www.google.no www.google.com.np www.google.nr www.google.nu www.google.co.nz www.google.com.om www.google.com.pa www.google.com.pe www.google.com.pg www.google.com.ph www.google.com.pk www.google.pl www.google.pn www.google.com.pr www.google.ps www.google.pt www.google.com.py www.google.com.qa www.google.ro www.google.ru www.google.rw www.google.com.sa www.google.com.sb www.google.sc www.google.se www.google.com.sg www.google.sh www.google.si www.google.sk www.google.com.sl www.google.sn www.google.so www.google.sm www.google.sr www.google.st www.google.com.sv www.google.td www.google.tg www.google.co.th www.google.com.tj www.google.tl www.google.tm www.google.tn www.google.to www.google.com.tr www.google.tt www.google.com.tw www.google.co.tz www.google.com.ua www.google.co.ug www.google.co.uk www.google.com.uy www.google.co.uz www.google.com.vc www.google.co.ve www.google.co.vi www.google.com.vn www.google.vu www.google.ws www.google.rs www.google.co.za www.google.co.zm www.google.co.zw www.google.cat heapanalytics.com cdn.heapanalytics.com cdn.huel.io cdn.shopify.com huel.io us-s2s.huel.com uk-s2s.huel.com huel-assets.s3.eu-west-2.amazonaws.com s3.eu-west-2.amazonaws.com huel.imgix.net huel-crm.imgix.net global.localizecdn.com media.loudcrowd.com mention-me.com *.clarity.ms *.onetrust.com paperplaneslive.com t.paypal.com *.podscribe.com alb.reddit.com tr.snapchat.com segment.prod.bidr.io *.media6degree.com ib.adnxs.com analytics.tiktok.com analytics-ipv6.tiktokw.us vercel.com b99.yahoo.co.jp www.zenaps.com v2assets.zopim.io static.zdassets.com; font-src 'self' data: *.onetrust.com vercel.live; worker-src 'self' blob:; object-src 'none'; base-uri 'self'; form-action 'self' www.facebook.com; media-src data: blob: 'self' lookaside.fbsbx.com cdn.huel.io media.loudcrowd.com cdn.shopify.com *.ctfassets.net; frame-src 'self' huelus.aftership.com aax-eu.amazon-adsystem.com www.awin1.com www.facebook.com www.googletagmanager.com www.google.com www.gstatic.com *.huel.com huel.com mention-me.com huel.mention-me.com huel-privacy.my.onetrust.com *.optimizely.com tr.snapchat.com js.stripe.com *.studentbeans.com www.tiktok.com vercel.live *.youtube.com cdn.smooch.io *.zdassets.com *.zendesk.com *.zopim.com; connect-src 'self' aax-eu.amazon-adsystem.com ara.paa-reporting-advertising.amazon ara.paa-reporting-advertising.amazon.com c.amazon-adsystem.com *.prod.mplat-ppcprotect.com *.applovin.com ttip-ipv4-prod.telemetry.vaultdcr.com ttip-ipv6-prod.telemetry.vaultdcr.com tte-prod.telemetry.vaultdcr.com *.attn.tv events.attentivemobile.com the.sciencebehindecommerce.com www.wepowerconnections.com *.bing.com bat.bing.net cognito-idp.eu-west-2.amazonaws.com *.ctfassets.net webchannel-content.eservice.emarsys.net *.scarabresearch.com www.facebook.com lookaside.fbsbx.com fbcapig.huel.com *.googlesyndication.com *.google-analytics.com *.googleapis.com *.cloudfunctions.net google.com analytics.google.com region1.analytics.google.com stats.g.doubleclick.net googleads.g.doubleclick.net www.googletagmanager.com www.googleadservices.com pagead2.googlesyndication.com www.google.com www.google.ad www.google.ae www.google.com.af www.google.com.ag www.google.al www.google.am www.google.co.ao www.google.com.ar www.google.as www.google.at www.google.com.au www.google.az www.google.ba www.google.com.bd www.google.be www.google.bf www.google.bg www.google.com.bh www.google.bi www.google.bj www.google.com.bn www.google.com.bo www.google.com.br www.google.bs www.google.bt www.google.co.bw www.google.by www.google.com.bz www.google.ca www.google.cd www.google.cf www.google.cg www.google.ch www.google.ci www.google.co.ck www.google.cl www.google.cm www.google.cn www.google.com.co www.google.co.cr www.google.com.cu www.google.cv www.google.com.cy www.google.cz www.google.de www.google.dj www.google.dk www.google.dm www.google.com.do www.google.dz www.google.com.ec www.google.ee www.google.com.eg www.google.es www.google.com.et www.google.fi www.google.com.fj www.google.fm www.google.fr www.google.ga www.google.ge www.google.gg www.google.com.gh www.google.com.gi www.google.gl www.google.gm www.google.gr www.google.com.gt www.google.gy www.google.com.hk www.google.hn www.google.hr www.google.ht www.google.hu www.google.co.id www.google.ie www.google.co.il www.google.im www.google.co.in www.google.iq www.google.is www.google.it www.google.je www.google.com.jm www.google.jo www.google.co.jp www.google.co.ke www.google.com.kh www.google.ki www.google.kg www.google.co.kr www.google.com.kw www.google.kz www.google.la www.google.com.lb www.google.li www.google.lk www.google.co.ls www.google.lt www.google.lu www.google.lv www.google.com.ly www.google.co.ma www.google.md www.google.me www.google.mg www.google.mk www.google.ml www.google.com.mm www.google.mn www.google.com.mt www.google.mu www.google.mv www.google.mw www.google.com.mx www.google.com.my www.google.co.mz www.google.com.na www.google.com.ng www.google.com.ni www.google.ne www.google.nl www.google.no www.google.com.np www.google.nr www.google.nu www.google.co.nz www.google.com.om www.google.com.pa www.google.com.pe www.google.com.pg www.google.com.ph www.google.com.pk www.google.pl www.google.pn www.google.com.pr www.google.ps www.google.pt www.google.com.py www.google.com.qa www.google.ro www.google.ru www.google.rw www.google.com.sa www.google.com.sb www.google.sc www.google.se www.google.com.sg www.google.sh www.google.si www.google.sk www.google.com.sl www.google.sn www.google.so www.google.sm www.google.sr www.google.st www.google.com.sv www.google.td www.google.tg www.google.co.th www.google.com.tj www.google.tl www.google.tm www.google.tn www.google.to www.google.com.tr www.google.tt www.google.com.tw www.google.co.tz www.google.com.ua www.google.co.ug www.google.co.uk www.google.com.uy www.google.co.uz www.google.com.vc www.google.co.ve www.google.co.vi www.google.com.vn www.google.vu www.google.ws www.google.rs www.google.co.za www.google.co.zm www.google.co.zw www.google.cat heapanalytics.com cdn.heapanalytics.com huel.io *.huel.io *.huel-staging.io huel.com *.huel.com hibble.myshopify.com huelczech.myshopify.com huelpoland.myshopify.com hueleurope.myshopify.com hueldenmark.myshopify.com huelgermany.myshopify.com huelamerica.myshopify.com hueljapan.myshopify.com huelsweden.myshopify.com huel.imgix.net huel-crm.imgix.net global.localizecdn.com api.addressy.com *.loudcrowd.com websurvey.lumoa.me *.mention-me.com *.clarity.ms *.onetrust.com *.optimizely.com paperplaneslive.com *.podscribe.com *.pusher.com *.reddit.com www.redditstatic.com *.shopify.com monorail-edge.shopifysvc.com *.snapchat.com pixels.spotify.com *.studentbeans.com ib.adnxs.com *.tiktok.com analytics-ipv6.tiktokw.us vercel.live *.zdassets.com *.zendesk.com *.zopim.com zendesk-eu.my.sentry.io wss://*.zendesk.com wss://*.zopim.com; frame-ancestors 'self' app.contentful.com; upgrade-insecure-requests; report-to sentry; report-uri https://o4506552359124992.ingest.us.sentry.io/api/4509920468533248/security/?sentry_key=01841fdb68b60d9143ac67a06a18c18f; 1 default-src 'self'; script-src 'self' 'unsafe-eval' 'unsafe-inline' data: https://www.shoppingsheet.com https://connect.facebook.net https://bbox.blackbaudhosting.com https://www.youvisit.com https://*.google.com https://*.uwplatt.edu https://googleads.g.doubleclick.net https://8ab0a26cb0027939bcf5-49c99c3c0c9c98b3365b710757036e1b.ssl.cf5.rackcdn.com https://ai.ocelotbot.com https://cdn.jsdelivr.net https://ep1.adtrafficquality.google https://ep2.adtrafficquality.google https://fw.cdn.technolutions.net https://googleads.g.doubleclick.net https://libraryh3lp.com https://mx.technolutions.net https://partner.googleadservices.com https://s.yimg.com https://script.hotjar.com https://siteimproveanalytics.com https://slate-technolutions-net.cdn.technolutions.net https://slate-uwplatt-edu.cdn.technolutions.net https://slate.uwplatt.edu https://static.hotjar.com https://*.olark.com https://unpkg.com https://www.googletagmanager.com https://www.googletagmanager.com/ https://www.youtube.com https://youtube.com; script-src-elem 'self' 'unsafe-eval' 'unsafe-inline' data: https://www.shoppingsheet.com https://connect.facebook.net https://bbox.blackbaudhosting.com https://www.youvisit.com https://*.google.com https://*.uwplatt.edu https://googleads.g.doubleclick.net https://8ab0a26cb0027939bcf5-49c99c3c0c9c98b3365b710757036e1b.ssl.cf5.rackcdn.com https://ai.ocelotbot.com https://cdn.jsdelivr.net https://ep1.adtrafficquality.google https://ep2.adtrafficquality.google https://fw.cdn.technolutions.net https://googleads.g.doubleclick.net https://libraryh3lp.com https://mx.technolutions.net https://partner.googleadservices.com https://s.yimg.com https://script.hotjar.com https://siteimproveanalytics.com https://slate-technolutions-net.cdn.technolutions.net https://slate-uwplatt-edu.cdn.technolutions.net https://slate.uwplatt.edu https://static.hotjar.com https://*.olark.com https://unpkg.com https://www.googletagmanager.com https://www.googletagmanager.com/ https://www.youtube.com https://youtube.com; style-src 'self' 'unsafe-inline' https://www.shoppingsheet.com https://www.google.com https://ai.ocelotbot.com https://cdn.jsdelivr.net https://fonts.googleapis.com https://static.olark.com https://static.hotjar.com https://script.hotjar.com; style-src-elem 'self' 'unsafe-inline' https://www.shoppingsheet.com https://slate-technolutions-net.cdn.technolutions.net https://static.olark.com https://ai.ocelotbot.com https://cdn.jsdelivr.net https://fonts.googleapis.com https://*.google.com https://*.uwplatt.edu https://ep2.adtrafficquality.google https://slate-uwplatt-edu.cdn.technolutions.net https://fw.cdn.technolutions.net; object-src 'none'; base-uri 'self'; connect-src 'self' https://syndicatedsearch.goog https://www.google-analytics.com https://cdn-graphql.youvisit.com https://region1.analytics.google.com https://knrpc.olark.com https://www.googleadservices.com https://googleads.g.doubleclick.net https://stats.g.doubleclick.net https://ai.ocelotbot.com https://libraryh3lp.com https://6349506.global.r2.siteimproveanalytics.io https://analytics.google.com https://content.hotjar.io https://mx.technolutions.net https://s.yimg.com https://*.uwplatt.edu https://www.google.com https://www.googletagmanager.com https://slate-uwplatt-edu.cdn.technolutions.net https://ep1.adtrafficquality.google https://*.hotjar.com https://*.hotjar.io https://ws.hotjar.com wss://*.hotjar.com; font-src 'self' data: https://fonts.gstatic.com https://static.olark.com https://script.hotjar.com; frame-src 'self' https://signup.e2ma.net https://ww2.matchinggifts.com https://www.youvisit.com https://www.shoppingsheet.com https://app.e2ma.net https://cdn.yoshki.com https://cdn.youvisit.com https://www.youtube-nocookie.com https://static.olark.com https://libraryh3lp.com https://e.issuu.com https://www.googletagmanager.com https://ep2.adtrafficquality.google https://syndicatedsearch.goog https://www.youtube.com https://*.uwplatt.edu; img-src 'self' data: https://se-images.campuslabs.com https://www.googleadservices.com https://trck.youvisit.com https://googleads.g.doubleclick.net/ https://se-images.campuslabs.com https://id.ocelotbot.com https://image.isu.pub https://6349506.global.r2.siteimproveanalytics.io https://*.uwplatt.edu https://sp.analytics.yahoo.com https://trkn.us https://*.google.com https://log.olark.com https://www.googletagmanager.com https://syndicatedsearch.goog https://ep1.adtrafficquality.google https://static.hotjar.com https://script.hotjar.com https://survey-images.hotjar.com; manifest-src 'self'; media-src 'self' https://static.olark.com; worker-src 'none'; frame-ancestors 'self' https://*.uwplatt.edu https://uwplatt.sharepoint.com; report-uri https://sentry.uwplatt.edu/api/5/security/?sentry_key=92e79271e0a535df88c88de202623cf3&sentry_environment=csp_reporting; report-to csp-endpoint; 1 font-src *.googleapis.com *.gstatic.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com cloud.taggbox.com stackpath.bootstrapcdn.com cdn.userway.org cloud.tagshop.ai cdn.tagshop.ai 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.authorize.net 'self' 'unsafe-inline'; frame-ancestors *.authorize.net 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com accounts.accessibe.com mossberg.app.box.com *.taggbox.com platform.twitter.com td.doubleclick.net cdn.userway.org *.authorize.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io camo.githubusercontent.com *.googleapis.com *.gstatic.com https://firebasestorage.googleapis.com *.google.com *.googleadservices.com *.google-analytics.com *.googletagmanager.com web1.acsbapp.com maps.gstatic.com *.ggpht.com resources.mossberg.com cdn.taggbox.com cdn.userway.org api.delivrabl.net aorta.clickagy.com cloud.tagshop.ai idsync.rlcdn.com c.clarity.ms c.bing.com aa.agkn.com d.agkn.com us-u.openx.net cm.g.doubleclick.net *.liadm.com track.hubspot.com forms.hsforms.com *.hsforms.net *.hsforms.com 'self' data: data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com *.youtube.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.googleapis.com *.gstatic.com *.avada.io *.shopify.com connect.facebook.net *.googletagmanager.com *.googleadservices.com *.google-analytics.com acsbapp.com *.acsbapp.com cdn.userway.org cdn.userconsent.org maps.googleapis.com api.pinterest.com *.taggbox.com web.taggshop.io kit.fontawesome.com widget.tagshop.ai cloud.tagshop.ai platform.twitter.com tags.clickagy.com www.clarity.ms static.cloudflareinsights.com js.hs-scripts.com js.hscollectedforms.net js.hs-banner.com js.hs-analytics.net *.authorize.net *.hsforms.net *.hsforms.com *.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com web.taggshop.io cloud.taggbox.com cdn.userway.org widget.tagshop.ai cloud.tagshop.ai cdn.tagshop.ai *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com cdn.tagshop.ai 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.googleapis.com https://get.geojs.io *.avada.io *.google-analytics.com *.analytics.google.com *.googletagmanager.com stats.g.doubleclick.net cdn.acsbapp.com api.userway.org cdn.userway.org *.userway.org maps.googleapis.com graph.facebook.com api.taggbox.com resources.mossberg.com *.doubleclick.net api.ipdata.co web.taggshop.io widget.tagshop.ai aorta.clickagy.com hemsync.clickagy.com i.clarity.ms forms.hubspot.com *.authorize.net t.elasticsuite.io *.hsforms.net *.hsforms.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://www.mossberg.com; report-to report-endpoint; 1 object-src 'none'; base-uri 'self'; script-src 'self' 'nonce-kr56eR4iFzn0qg_JMPxhdg' 'unsafe-inline' 'unsafe-eval' https://*.msauth.net https://*.msftauth.net https://*.msftauthimages.net https://*.msauthimages.net https://*.msidentity.com https://*.microsoftonline-p.com https://*.microsoftazuread-sso.com https://*.azureedge.net https://*.outlook.com https://*.office.com https://*.office365.com https://*.microsoft.com https://*.bing.com 'report-sample'; report-uri https://csp.microsoft.com/report/ESTS-UX-All 1 frame-ancestors 'none'; base-uri 'self'; default-src 'self' https://*.yahoo.com https://*.yimg.com; script-src 'self' 'nonce-MzU0ZjhkMDMtYmViNS00YTQ3LWE5NDEtNzEyMTkzMWJhNzVi' 'strict-dynamic' 'unsafe-eval' https://*.yahoo.net https://*.yahoo.com https://*.yimg.com *.oath.com https://*.hereapi.com https://*.youtube.com https://*.yahooapis.com blob: *.googletagmanager.com; style-src 'self' 'unsafe-inline' https://assets.video.yahoo.net https://*.yimg.com; frame-src 'self' https://*.yahoo.net https://*.youtube.com https://s.yimg.com https://*.yahoo.com; img-src 'self' data: blob: https://*.yimg.com https://s.ytimg.com yahoo.com https://*.yahoo.com *.here.com https://sb.scorecardresearch.com https://*.yahoo.net https://*.bing.net https://media.zenfs.com; media-src * blob:; object-src 'self' https://*.yimg.com; connect-src * blob:; font-src * data:; child-src blob:; report-uri https://csp.yahoo.com/beacon/csp?src=scout 1 frame-ancestors 'self' *.andrew.com; 1 script-src 'self' 'report-sample' 'unsafe-inline' 'unsafe-eval' https://*.zohocdn.com https://static.zohocdn.com.cn https://*.zohostatic.com https://*.zohowebstatic.com https://*.zoho.com https://salesiq.zoho.com https://cdn.pagesense.io; report-uri https://logsapi.zoho.com/csplog?service=creator; 1 default-src 'self'; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://code.jquery.com/ui/ https://src.mastercard.com/srci/integration/components/ https://cdn.jsdelivr.net/npm/intl-tel-input@25.3.1/build/css/intlTelInput.css; script-src 'self' 'unsafe-eval' 'nonce-b9c158c44c3ee2e8d2c858a815e58930' https://js.stripe.com/ https://g.stripe.com/ https://hosted.paysafe.com/request/ https://ajax.cloudflare.com https://cdnjs.cloudflare.com/ajax/libs/moment.js/ https://static.cloudflareinsights.com https://cdn.webrtc-experiment.com/DetectRTC.min.js https://code.jquery.com/ui/ https://maps.googleapis.com/maps/api/ https://challenges.cloudflare.com/turnstile/v0/api.js https://www.google.com/recaptcha/api.js https://www.datadoghq-browser-agent.com/datadog-logs-us.js https://www.datadoghq-browser-agent.com/datadog-rum-us.js https://www.datadoghq-browser-agent.com/datadog-rum-v4.js http://stats.pusher.com/timeline/v2/jsonp/ https://cdn.onesignal.com/ https://onesignal.com/api/v1/sync/ https://hpoint-cr-binaries-prod.s3.amazonaws.com/cloud/sdk/wrappers/js/ https://cdn.jsdelivr.net/npm/intl-tel-input@25.3.1/build/js/intlTelInputWithUtils.min.js https://app.brainfi.sh/api/searchWidgets.callback.codeblocks https://cdn.jsdelivr.net/npm/@brainfish-ai/web-tracker@latest/dist/tracker.js https://cdn.jsdelivr.net/npm/@brainfish-ai/nudge-widget@latest/dist/index.js https://src.mastercard.com/ https://secure.checkout.visa.com/checkout-widget/resources/js/ https://qwww.aexp-static.com/akamai/remotecommerce/scripts/ https://webapp.src.discover.com/websdk/ https://content.discovercard.com/ https://js.verygoodvault.com/vgs-collect/ https://js3.verygoodvault.com/vgs-collect/ https://www.datadoghq-browser-agent.com/datadog-logs-v4.js; font-src 'self' data: https://fonts.gstatic.com; img-src 'self' data: https://img.gotab.io/ https://static.gotab.io/ https://s3.amazonaws.com/gotabpublic/ https://s3.amazonaws.com/gotabpublic/ https://maps.gstatic.com/ https://maps.googleapis.com/maps/ https://i.vimeocdn.com/video/ https://src.mastercard.com/srci/integration/ https://content.discovercard.com/ https://cdn.jsdelivr.net/npm/intl-tel-input@25.3.1/build/img/ https://*.untappd.com/ https://checkoutshopper-live.adyen.com/checkoutshopper/images/ https://checkoutshopper-live-us.adyen.com/ https://*.googleapis.com https://cdn.prod.website-files.com/ https://gotabpublic.s3.amazonaws.com/; media-src 'self' data: https://s3.amazonaws.com/gotabpublic/ https://gotabpublic.s3.amazonaws.com/; frame-src 'self' https://js.stripe.com/ https://metabase.gotab.io/ https://report.gotab.io/ https://www.google.com/ https://js.verygoodvault.com/vgs-collect/ https://content.discovercard.com/ https://src.mastercard.com/ https://srcdcf.americanexpress.com/ https://secure.checkout.visa.com/checkout-widget/ https://checkoutshopper-live.adyen.com/ https://checkoutshopper-live-us.adyen.com/ https://challenges.cloudflare.com/ https://chat.gotab.io/ https://app.opsi.io/ https://agent.brainfi.sh/; connect-src 'self' https://*.gotab.io/ wss://stats.gotab.io/ https://s3.amazonaws.com/gotabpublic/ https://s3.amazonaws.com/gotabpublic/ https://hosted.paysafe.com/request/api/ https://api.paysafe.com/request/api/ https://api.paysafe.com/request/api/v1/ https://checkoutshopper-live.adyen.com/checkoutshopper/ https://checkoutshopper-live-us.adyen.com/ https://*.logs.datadoghq.com/ https://*.browser-intake-datadoghq.com/ *.verygoodvault.com *.verygoodproxy.com https://maps.googleapis.com/maps/api/ https://cloud.handpoint.io/ https://cloud.handpoint.com/ ws://ws-mt1.pusher.com/app/ https://vimeo.com/api/ https://vgs-collect-keeper.apps.verygood.systems/vgs https://*.mastercard.com/ https://*.aexp-static.com/ https://*.americanexpress.com/ https://*.visa.com/ https://*.staticv.me/ https://*.discover.com/ https://*.discovercard.com/ https://content.discovercard.com/ https://src.apis.discover.com/sdk/ https://www.google.com/maps/conversion/collect https://*.googleapis.com https://www.google.com/recaptcha/ wss://analytic.brainfi.sh/analytics/ws/ https://app.brainfi.sh/api/searchWidgets.getConfigByKey; worker-src 'self' blob:; report-uri https://browser-intake-datadoghq.com/api/v2/logs?dd-api-key=pub4721f170b2076f8c4dce4d125ff9509d&dd-evp-origin=content-security-policy&ddsource=csp-report&ddtags=version%3Amaster.26ee15786e61ea35c7878c3876972009e7b8b406.1%2Cservice%3Agotabnode%2Cenv%3Aproduction; report-to csp-report 1 default-src 'self'; connect-src *; img-src * data:; script-src 'self' cdn.bizible.com; style-src 'self' 'unsafe-inline' https://404-tpa-276.mktoweb.com/ https://*.qualified.com; font-src 'self' kit.fontawesome.com ka-p.fontawesome.com https://fast.wistia.com/ https://fast.wistia.net/ data:; form-action 'self'; object-src 'none'; media-src 'self' blob: mediastream: https://*.qualified.com; frame-src https://www.googletagmanager.com https://td.doubleclick.net/ https://gtm.8am.com/ https://insight.adsrvr.org/ https://app.netlify.com/ https://404-tpa-276.mktoweb.com/ https://*.qualified.com; child-src https://*.qualified.com; frame-ancestors demo.affinipay.com ka-p.fontawesome.com; upgrade-insecure-requests; block-all-mixed-content 1 default-src 'self'; base-uri 'none'; object-src 'none'; form-action https:; img-src 'self' https: data: blob:; font-src 'self' https: data:; style-src 'self' 'unsafe-inline' https:; script-src 'self' https: 'unsafe-inline' 'unsafe-eval'; connect-src 'self' https: data: blob:; media-src 'self' https: data:; worker-src 'self' blob:; frame-src https:; manifest-src 'self' https:; 1 default-src 'none'; script-src 'nonce-9L+rK7s0EfMuzv0Hau3n0ghkMRvZS4qn' 'self' 'unsafe-inline' 'unsafe-eval' 'report-sample' https://www.googletagmanager.com https://assets.adobedtm.com https://cdn.cookielaw.org https://swa.regiobank.nl https://www.google-analytics.com https://player.vimeo.com https://d6tizftlrpuof.cloudfront.net https://snsbank.demdex.net https://api.usabilla.com https://tagmanager.google.com https://w.usabilla.com https://connect.facebook.net https://cdn.tt.omtrdc.net static.regiobank.nl; connect-src 'self' https://cdn.cookielaw.org https://www.google-analytics.com https://snsbank.tt.omtrdc.net https://stats.g.doubleclick.net https://swa.regiobank.nl https://api.usabilla.com https://dpm.demdex.net https://upload.snsbank.nl https://snsbank.sc.omtrdc.net https://*.advieskeuze.nl static.regiobank.nl; font-src 'self' data: https: https://fonts.gstatic.com; frame-src 'self' https://snsbank.demdex.net https://player.vimeo.com https://d6tizftlrpuof.cloudfront.net; img-src 'self' 'report-sample' data: https: https://googleads.g.doubleclick.net https://d6tizftlrpuof.cloudfront.net https://px.ads.linkedin.com/collect/ https://www.facebook.com https://snsbank.demdex.net https://www.google-analytics.com https://swa.regiobank.nl https://w.usabilla.com https://i.vimeocdn.com https://www.google.nl https://www.google.com https://www.linkedin.com https://bat.bing.com https://cdn.cookielaw.org https://www.google.be https://ssl.gstatic.com https://www.gstatic.com https://fonts.gstatic.com https://www.google.co.uk https://www.googletagmanager.com https://www.google.de https://www.google.pl https://secure.adnxs.com https://www.google.fr https://www.google.es https://translate.google.com https://www.google.gr https://www.google.fi https://www.google.lu https://www.google.ik https://www.google.ru https://charting.vwdservices.com; manifest-src 'self'; media-src 'self' data:; style-src 'self' 'unsafe-inline' data: https: https://fonts.gstatic.com https://d6tizftlrpuof.cloudfront.net https://fonts.googleapis.com https://tagmanager.google.com https://www.googletagmanager.com; object-src 'none'; worker-src blob:; frame-ancestors 'self'; base-uri 'self' https://d6tizftlrpuof.cloudfront.net; form-action 'self' https://www.solease.nl; report-uri /web/reportreceiver; 1 object-src 'none';base-uri 'self';script-src 'nonce-SvJerMXABse8a3cZbGKEKg' 'strict-dynamic' 'report-sample' 'unsafe-eval' 'unsafe-inline' https: http:;report-uri https://csp.withgoogle.com/csp/gws/other-hp 1 object-src 'none'; style-src 'unsafe-inline' *; default-src 'none'; worker-src 'none'; connect-src 'self' *.algolia.net *.algolianet.com *.algolia.io; base-uri 'none'; media-src *; script-src 'self' 'unsafe-inline' 'report-sample' 'nonce-EZatyqC1j5eCfu0AkIHvAg=='; img-src blob: data: *; font-src 'self' data:; frame-ancestors 'none' 1 font-src cash-f.squarecdn.com *.gstatic.com data: *.googleapis.com cdnjs.cloudflare.com js-agent.newrelic.com api.map.baidu.com *.baidu.com *.bdimg.com *.mtcaptcha.com *.bglobale.com *.global-e.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com * *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com https://secure-test.worldpay.com/shopper/3ds/ddc.html 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com * www.google.com *.bglobale.com *.global-e.com maisongoyard--staging.sandbox.my.salesforce-sites.com maisongoyard.my.salesforce-sites.com *.mtcaptcha.com *.smartpixels.fr c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com https://pay.google.com https://secure-test.worldpay.com https://*.online-metrix.net https://imgs.signifyd.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io * *.gstatic.com *.googleapis.com maps.googleapis.com maps.gstatic.com *.baidu.com *.bdimg.com sdk.privacy-center.org *.mtcaptcha.com goyard-marquage-webconf.smartpixels.fr ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com *.bglobale.com *.global-e.com *.goyard.com *.smartpixels.fr goyard-marquage-test-we-appservice-webconf.azurewebsites.net sprint-7onpvba-jccxky3s5ebcw.us-a1.magentosite.cloud www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.cloudflare.com https://imgs.signifyd.com https://*.online-metrix.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com *.cash.app *.visa.com *.mastercard.com *.googleapis.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.gstatic.com cdnjs.cloudflare.com bam.nr-data.net mcstaging.goyard.com mcprod.goyard.com goyard.com js-agent.newrelic.com api.map.baidu.com *.baidu.com *.bdimg.com sdk.privacy-center.org *.mtcaptcha.com chimpstatic.com downloads.mailchimp.com *.list-manage.com *.bglobale.com *.global-e.com *.goyard.com payments.worldpay.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com https://www.google.com/recaptcha/api.js *.cloudflare.com https://pay.google.com/gp/p/js/pay.js https://applepay.cdn-apple.com/jsapi/v1/apple-pay-sdk.js *.payments.worldpay.com/resources/cse/js/worldpay-cse-1.0.2.min.js https://d35p4vvdul393k.cloudfront.net/sdk_library/us/stg/ops/pc_gsmpi_web_sdk.js https://d16i99j5zwwv51.cloudfront.net/sdk_library/us/prd/ops/pc_gsmpi_web_sdk.js https://payments.worldpay.com/resources/hpp/integrations/embedded/js/hpp-embedded-integration-library.js https://cdn-scripts.signifyd.com https://cdn-scripts.signifyd.com/api/script-tag.js https://imgs.signifyd.com https://h64.online-metrix.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.cash.app fonts.googleapis.com cdnjs.cloudflare.com *.googleapis.com *.baidu.com *.bdimg.com *.mtcaptcha.com downloads.mailchimp.com *.bglobale.com *.global-e.com unsafe-inline assets.braintreegateway.com *.cloudflare.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.goyard.com *.goyard.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com * *.googleapis.com api.map.baidu.com *.baidu.com *.bdimg.com api.privacy-center.org *.mtcaptcha.com *.goyard.com *.bglobale.com *.global-e.com *.nr-data.net *.smartpixels.fr api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com https://imgs.signifyd.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src maisongoyard--staging.sandbox.my.salesforce-sites.com maisongoyard.my.salesforce-sites.com *.mtcaptcha.com *.goyard.com *.bglobale.com *.global-e.com *.nr-data.net *.smartpixels.fr payments.worldpay.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' jhnet.okta.com sso.jhnet.com *.oktacdn.com; connect-src 'self' jhnet.okta.com jhnet-admin.okta.com sso.jhnet.com *.oktacdn.com *.mixpanel.com *.mapbox.com jhnet.kerberos.okta.com jhnet.mtls.okta.com *.authenticatorlocalprod.com:8769 http://localhost:8769 http://127.0.0.1:8769 *.authenticatorlocalprod.com:65111 http://localhost:65111 http://127.0.0.1:65111 *.authenticatorlocalprod.com:65121 http://localhost:65121 http://127.0.0.1:65121 *.authenticatorlocalprod.com:65131 http://localhost:65131 http://127.0.0.1:65131 *.authenticatorlocalprod.com:65141 http://localhost:65141 http://127.0.0.1:65141 *.authenticatorlocalprod.com:65151 http://localhost:65151 http://127.0.0.1:65151 https://oinmanager.okta.com data: *.ingest.sentry.io; script-src 'unsafe-inline' 'unsafe-eval' 'self' 'report-sample' jhnet.okta.com sso.jhnet.com *.oktacdn.com; style-src 'unsafe-inline' 'self' 'report-sample' jhnet.okta.com sso.jhnet.com *.oktacdn.com; frame-src 'self' jhnet.okta.com jhnet-admin.okta.com sso.jhnet.com login.okta.com *.vidyard.com com-okta-authenticator:; img-src 'self' jhnet.okta.com sso.jhnet.com *.oktacdn.com *.tiles.mapbox.com *.mapbox.com *.vidyard.com data: blob:; font-src 'self' jhnet.okta.com sso.jhnet.com data: *.oktacdn.com fonts.gstatic.com; frame-ancestors 'self' 1 object-src 'none';base-uri 'self';script-src 'nonce-vDsyZiB562eNFpEqp/YN' 'unsafe-inline' 'unsafe-eval' 'strict-dynamic' https: http: 'report-sample';report-uri https://csp.withgoogle.com/csp/scfe 1 script-src 'self' 'unsafe-eval' 'unsafe-inline' 'strict-dynamic' 'nonce-93fae56f-63b0-4366-b4b8-7999b3c250bd' *.aaui-879784980514.s3.us-east-2.amazonaws.com *.aauicdnva7.azureedge.net *.adform.net *.app.launchdarkly.com *.awaascicdprodva7.blob.core.windows.net *.d30ln29764hddd.cloudfront.net *.doubleclick.net *.euroland.com *.eurolandir.com *.googletagmanager.com *.jquery.com *.leaddesk.com *.linkedin.com *.omniture.com *.omtrdc.net *.services.adobe.com *.youtube.com http://maps.google.com/maps-api-v3/api/ http://maps.google.com/maps/api/ http://maps.googleapis.com/maps/api/ https://*.aptrinsic.com https://*.flockler.com https://adminconsole.adobe.com https://adobe.com https://adobe.io https://adobe.net https://adobeid-na1.services.adobe.com https://ajax.googleapis.com https://analytics-eu.clickdimensions.com https://api.emea01.idio.episerver.net https://app.powerbi.com https://assets.adobedtm.com https://assets.adobedtm.com https://assets2.adobe.com https://az416426.vo.msecnd.net/scripts/a/ai.0.js https://cdn.cookielaw.org https://cdn.jsdelivr.net/npm/ https://cdnjs.cloudflare.com/ajax/libs/popper.js/ https://cloudui-emea01.profilestore.episerver.net https://connect.facebook.net https://cookie-cdn.cookiepro.com https://d1igp3oop3iho5.cloudfront.net/v2/YTCU__QFgA3N4sqa5K5xQA-eu1/zaius-min.js https://d1igp3oop3iho5.cloudfront.net/v2/buA6R3hGThUwo2b3jMhdjQ-eu1/zaius-min.js https://dl.episerver.net https://fl-cdn.scdn1.secure.raxcdn.com https://geolocation.onetrust.com https://googleads.g.doubleclick.net https://js.monitor.azure.com/scripts/ https://kuula.co https://ld-webchat.s3.eu-north-1.amazonaws.com https://login.microsoftonline.com https://maps.googleapis.com https://maxcdn.bootstrapcdn.com/bootstrap/ https://research.innolink.fi https://s.emea01.idio.episerver.net/ https://snap.licdn.com https://sstats.adobe.com https://static.ads-twitter.com https://tpc.googlesyndication.com https://videolle.viewin360.co https://www.google.com https://www.google.com/recaptcha/ https://www.googleadservices.com https://www.gstatic.com/recaptcha/ https://youtube.com https://metsa-virtual-exhibition.netlify.app https://metsa-virtual-exhibition-two.netlify.app https://cxppusa1formui01cdnsa01-endpoint.azureedge.net/ https://*.hotjar.com/ https://cxppeur1rdrect01sa02cdn.blob.core.windows.net/; report-uri https://www.metsagroup.com/api/reporting/; report-to csp-endpoint; 1 script-src 'self' 'unsafe-inline' 'unsafe-eval' *.2mdn.net *.3lift.com *.a47b.com *.acuityplatform.com *.ad-score.com *.adform.net *.adnxs.com *.ads.smartadserver.com *.adsafeprotected.com *.adsappier.com *.adsrvr.org *.adtrafficquality.google *.amazon-adsystem.com *.amazonaws.com *.ampproject.org *.azureedge.net *.b2c.com *.basis.net *.betrad.com *.bidr.io *.c3tag.com *.cdn.fastclick.net *.celtra.com *.cloudfront.net *.cog-tr3.com *.cog-tr4.com *.demdex.net *.dotomi.com *.doubleclick.net *.doubleverify.com *.evidon.com *.exelator.com *.eyeota.net *.flashtalking.com *.flx10.com *.fouanalytics.com *.ftstatic.com *.g.doubleclick.net *.getrockerbox.com *.googlesyndication.com *.googletagmanager.com *.googletagservices.com *.gumgum.com *.id5-sync.com *.innovid.com *.jivox.com *.js7k.com *.jwplayer.com *.l-dsp.inmobicdn.net *.microsoft.com *.mxptint.net *.ns1p.net *.onedsp.inmobi.com *.p.jwpcdn.com *.peer-39.com *.polarcdn.com *.poupdate.pulsepoint.com *.puzzmo.com *.quantcount.com *.quantserve.com *.rendering.sharethrough.com *.rfihub.com *.rqtrk.eu *.rubiconproject.com *.rudderlabs.com *.scorecardresearch.com *.script.ac *.smadex.com *.srv.stackadapt.com *.trustarc.com *.truste.com *.turn.com *.update.adsrvr.org *.update.indexww.com *.update.rubiconproject.com *.update.wo.gumgum.com *.yabidos.com *.ybp.yahoo.com *.yimg.com adrta.com cdn-cookieyes.com htlbid.com openfpcdn.io *.insiad.com *.browsiprod.com *.enzymic.co *.intentiq.com *.ntv.io *.padsquad.com lottingem.com; connect-src 'self' *.3lift.com *.ad-score.com *.adform.net *.adnxs.com *.ads.smartadserver.com *.adsrvr.org *.adtrafficquality.google *.amazon-adsystem.com *.amazonaws.com *.appiersig.com *.b2c.com *.c.appier.net *.c3tag.com *.casalemedia.com *.cheilmedia.com *.cloudfront.net *.cog-tr101.com *.contextweb.com *.cookieyes.com *.dotomi.com *.doubleclick.net *.doubleverify.com *.eu-1-id5-sync.com *.eu-3-id5-sync.com *.eu-4-id5-sync.com *.flashtalking.com *.fouanalytics.com *.ftstatic.com *.g.doubleclick.net *.google-analytics.com *.googlesyndication.com *.gumgum.com *.id5-sync.com *.ingest.sentry.io *.innovid.com *.jwplayer.com *.liadm.com *.lynx.cognitivlabs.com *.ns1p.net *.openx.net *.peer-39.com *.poupdate.pulsepoint.com *.prod.na.adsqtungsten.a9.amazon.dev *.pubmatic.com *.puzzmo.com *.quantserve.com *.rubiconproject.com *.rudderstack.com *.srv.stackadapt.com *.tahoe-analytics.publishers.advertising.a2z.com *.update.adsrvr.org *.update.indexww.com *.update.rubiconproject.com *.update.wo.gumgum.com *.us-east-1.cxm-bcn.publisher-services.amazon.dev *.ybp.yahoo.com wss://*.puzzmo.com cdn-cookieyes.com id5-sync.com o1223952.ingest.sentry.io *.gstatic.com *.insiad.com *.googletagmanager.com data: sevendata.fun; form-action 'none'; report-to default 1 default-src 'self'; connect-src 'self' https://px.ads.linkedin.com https://*.linkedin.com https://*.zi-scripts.com https://ws.zoominfo.com https://*.hsforms.com https://js.hubspot.com https://cta-service-cms2.hubspot.com https://*.wistia.com https://*.wistia.net https://*.litix.io https://www.googletagmanager.com https://analytics.google.com https://*.analytics.google.com https://www.google-analytics.com https://stats.g.doubleclick.net https://o936403.ingest.sentry.io https://o936403.ingest.us.sentry.io https://hubspot-forms-static-embed.s3.amazonaws.com https://cdn.livechatinc.com https://stackpath.bootstrapcdn.com https://cdnjs.cloudflare.com; font-src 'self' data: https://fonts.gstatic.com https://use.fontawesome.com https://cdnjs.cloudflare.com https://stackpath.bootstrapcdn.com https://cdn.jsdelivr.net https://*.wistia.com https://*.wistia.net; frame-ancestors 'self'; frame-src 'self' blob: https://464431.hs-sites.com https://*.hsforms.com https://*.livechatinc.com; img-src 'self' data: blob: https://www.googletagmanager.com https://stats.g.doubleclick.net https://px.ads.linkedin.com https://*.linkedin.com https://cdn.livechat-static.com https://cdn.livechat-files.com https://cdn.files-text.com https://*.hsforms.com https://*.hubspot.com https://static.hsappstatic.net https://*.wistia.com https://*.wistia.net https://cdnjs.cloudflare.com https://fonts.gstatic.com https://use.fontawesome.com; media-src 'self' blob:; object-src 'self'; script-src 'strict-dynamic' 'nonce-goWKFd+/AFEeaz3foXYcTg==' 'report-sample'; script-src-elem 'strict-dynamic' 'nonce-goWKFd+/AFEeaz3foXYcTg=='; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://use.fontawesome.com https://cdnjs.cloudflare.com https://stackpath.bootstrapcdn.com https://cdn.jsdelivr.net; style-src-elem 'self' 'unsafe-inline' https://fonts.googleapis.com https://use.fontawesome.com https://cdnjs.cloudflare.com https://stackpath.bootstrapcdn.com https://cdn.jsdelivr.net; report-uri https://hesoedxbb6.execute-api.us-west-2.amazonaws.com/prod/report 1 script-src 'self' https://www.acura.com https://stats.g.doubleclick.net https://checkoutshopper-test.adyen.com/ https://my.hondafinancialservices.com https://pal-test.adyen.com https://automobiles.honda.com/ https://cdn.cookielaw.org https://ahfc--webproj1.my.salesforce.com https://www.gstatic.com https://www.somt.honda.com https://treasuredata.com/ https://www.youtube.com https://www.google.com https://pay.google.com https://analytics.google.com blob: https://in.treasuredata.com/ https://uat2.sendyouropinions.com/ClientFiles/Honda/cnx/SPA.js https://webproj1-hondafinance.cs97.force.com/ https://www.tt.omtrdc.net https://assets.adobedtm.com/extensions/EP40e3bec801244c59a61bf06eb622a63c/AppMeasurement.min.js 'report-sample' https://www.google.co.in/ads/ga-audiences https://service.force.com/embeddedservice/ 'unsafe-eval' https://uat2.sendyouropinions.com/ClientFiles/Honda/cnx/cnx_style.css https://assets.adobedtm.com/ 'unsafe-inline' https://payments.salesforce.com/ https://cdn.treasuredata.eom/sdk/3.0/td.min.js https://www.2o7.net https://www.demdex.net https://checkoutshopper-live.adyen.com/ https://cdn.content.aws-prod1-useast1.aws.sfdc.cl/ https://consent-api.onetrust.com https://uat2.sendyouropinions.com/ https://assets.adobedtm.com/extensions/EP40e3bec801244c59a61bf06eb622a63c/AppMeasurement_Module_ActivityMap.min.js https://www.sc.omtrdc.net https://tagmanager.google.com https://www.gstatic.com/recaptcha/ https://uip.canary.lwc.dev https://assets.adobedtm.com/4d2629481466/43ad9a13e659/launch-520b4553879e.min.js https://geolocation.onetrust.com https://cdn.content.aws-dev2-uswest2.aws.sfdc.cl/ https://ahfc--webproj1--c.visualforce.com/ https://uat2.sendyouropinions.com/ClientFiles/Honda/cnx/cnx_bundle.js https://www.omt.honda.com https://www.google.com/recaptcha/ https://js.stripe.com/ https://www.googletagmanager.com import: https://www.google-analytics.com *.salesforce.com https://www.paypal.com/sdk/js https://ahfc--sfamsweb.sandbox.my.site.com; report-to sfdc-csp-ep; report-uri https://ahfc.lightning.force.com/_/ContentDomainCSPNoAuth?tenantId=00Dj0000001oPqD&networkId=0DM5b000000wk5s&type=communities 1 connect-src 'unsafe-inline' https: https://chat.tendertech.ru wss://chat.tendertech.ru:7272 https://blacklist.tendertech.ru https://storage.tendertech.ru 1 worker-src *.litter-robot.com *.litterbox.com *.whisker.com *.osano.com blob:; font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com *.elev.io *.paypalobjects.com *.klarnacdn.net 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.certcapture.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.affirm.com *.affirm.ca *.certcapture.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.osano.com *.klarna.com https://*.talkable.com 'self' 'unsafe-inline'; img-src data: *.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io widgets.automizely.com widgets.automizely.io *.googleapis.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.payments-amazon.com *.affirm.com *.affirm.ca *.certcapture.com magefan.com cm.magefan.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.adnxs.com *.adsrvr.org *.bidr.io *.bing.com *.facebook.com *.gotolstoy.com *.lightboxcdn.com *.localizecdn.com *.reddit.com *.twitter.com *.pinterest.com *.pbbl.co *.tiktok.com *.litter-robot.com *.litterbox.com *.whisker.com aa.agkn.com https://*.ordergroove.com *.klarna.com *.klarnaevt.com *.klarnacdn.net *.disqus.com *.cdn.imgeng.in *.hsforms.net *.hsforms.com 'self' data: data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com ajax.googleapis.com fonts.googleapis.com widgets.automizely.com widgets.automizely.io *.googleapis.com *.gstatic.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.affirm.com *.affirm.ca *.certcapture.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.adnxs.com *.ads-twitter.com *.adsrvr.org *.attn.tv *.bing.com *.byspotify.com *.dixa.io *.dstillery.com *.elev.io *.exponea.com *.facebook.net *.gleamjs.io *.gotolstoy.com *.hotjar.com *.impactcdn.com *.iubenda.com *.lightboxcdn.com *.localizecdn.com *.noibu.com *.onescreen.ai *.pepperjam.com *.pinimg.com *.pinterest.com *.redditstatic.com *.tiktok.com getrockerbox.com *.litter-robot.com *.litterbox.com *.whisker.com *.optimizely.com s3-us-west-2.amazonaws.com *.pbbl.co d2hrivdxn8ekm8.cloudfront.net *.osano.com https://*.ordergroove.com https://elements.sika.health *.klarna.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.disqus.com *.cdn.imgeng.in *.hsforms.net *.hsforms.com https://d2jjzw81hqbuqv.cloudfront.net https://di6re4dxelnn2.cloudfront.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com widgets.automizely.com widgets.automizely.io *.certcapture.com assets.braintreegateway.com *.gotolstoy.com *.lightboxcdn.com *.plyr.io *.litter-robot.com *.litterbox.com *.whisker.com *.osano.com *.klarnacdn.net *.adobedtm.com *.cdn.imgeng.in *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.gotolstoy.com *.litter-robot.com *.litterbox.com *.whisker.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com api.automizely.com api.automizely.io *.googleapis.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.affirm.com *.affirm.ca *.certcapture.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.adnxs.com *.attentivemobile.com *.attn.tv *.bing.com *.dixa.io *.elev.io *.exponea.com *.facebook.com *.gotolstoy.com *.hotjar.com *.iubenda.com *.localizecdn.com *.noibu.com *.onescreen.ai *.pinterest.com *.plyr.io *.reddit.com *.redditstatic.com *.spotify.com *.tiktok.com *.litter-robot.com *.litterbox.com *.whisker.com *.googlesyndication.com *.optimizely.com *.telemetry.vaultdcr.com *.osano.com https://*.ordergroove.com *.klarnaevt.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.klarna.com t.elasticsuite.io *.hsforms.net *.hsforms.com 'self' 'unsafe-inline'; child-src *.certcapture.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://472ad5a6-d25e-45ca-8d99-f4067de68ea9.sansec.watch/; report-to report-endpoint; 1 script-src 'nonce-upCKlTCpWgMLqPvuXpmjrg' 'report-sample' 'strict-dynamic' 'unsafe-eval' 'unsafe-inline' http: https:; object-src 'none'; report-uri https://csp.withgoogle.com/csp/static-on-bigtable; base-uri 'none' 1 default-src 'self' https://frontend-assets.dev.simscale.com https://ws-long-dev.simscale.com https://frontend-assets.stg.simscale.com https://ws-long-staging.simscale.com https://frontend-assets.simscale.com https://ws-long.simscale.com; img-src 'self' https://secure.gravatar.com https://scout.us3.salesloft.com https://b.6sc.co https://*.atl-paas.net https://lh3.googleusercontent.com https://lh4.googleusercontent.com https://lh7-rt.googleusercontent.com https://lh5.googleusercontent.com https://lh6.googleusercontent.com https://js.hs-banner.com https://www.google.co.za https://www.google.com.au https://*.hubspotfeedback.com https://www.google.es https://www.google.be https://www.google.com.my https://www.google.fr https://www.google.co.in https://www.google.com.ph https://www.google.com.sa https://www.google.co.uk https://www.google.fi https://encrypted-tbn0.gstatic.com https://www.google.ae https://www.google.de https://www.google.it https://fonts.gstatic.com https://usage.trackjs.com https://forms-na1.hsforms.com https://perf-na1.hsforms.com https://js.intercomcdn.com https://www.googletagmanager.com https://t.co https://analytics.twitter.com https://www.google.com https://track.hubspot.com https://px.ads.linkedin.com https://www.google.com.eg https://*.google.co.uk https://downloads.intercomcdn.com https://static.intercomassets.com https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://*.g.doubleclick.net https://*.google.com https://www.google-analytics.com https://frontend-assets.dev.simscale.com https://ws-long-dev.simscale.com https://frontend-assets.stg.simscale.com https://ws-long-staging.simscale.com https://frontend-assets.simscale.com https://ws-long.simscale.com data:; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://www.google.fi https://scout.us3.salesloft.com https://b.6sc.co https://www.google.com.eg https://j.6sc.co https://lh7-rt.googleusercontent.com https://www.google.be https://www.google.com.au https://www.google.es https://www.google.com.my https://www.google.co.za https://www.google.fr https://www.google.co.in https://*.hubspotfeedback.com https://www.google.com.ph https://www.google.com.sa https://www.google.co.uk https://t.co https://analytics.twitter.com https://px.ads.linkedin.com https://cdn-4.convertexperiments.com https://www.google.ae https://www.google.de https://www.google.it https://www.google-analytics.com https://ws.zoominfo.com https://cdn.jsdelivr.net https://www.googletagmanager.com https://*.google.co.uk https://cdn.trackjs.com https://js.hsforms.net https://cmp.osano.com https://tracking.g2crowd.com https://static.hotjar.com https://script.hotjar.com https://widget.intercom.io https://js.intercomcdn.com https://scout-cdn.salesloft.com https://js.hs-analytics.net https://js.hubspot.com https://js.hs-banner.com https://js.hsadspixel.net https://js-na1.hs-scripts.com https://snap.licdn.com https://consent.api.osano.com https://tattle.api.osano.com https://disclosure.api.osano.com https://www.googletagmanager.com/gtm.js https://static.addtoany.com https://boards.greenhouse.io/embed/job_board/js https://frontend-assets.dev.simscale.com https://ws-long-dev.simscale.com https://frontend-assets.stg.simscale.com https://ws-long-staging.simscale.com https://frontend-assets.simscale.com https://ws-long.simscale.com blob: 'nonce-8fdc900cd2507a52186a22ff807b4654'; connect-src 'self' https://ws.zoominfo.com https://cmp.osano.com https://api-iam.intercom.io wss://nexus-websocket-a.intercom.io https://forms.hsforms.com https://hubspot-forms-static-embed.s3.amazonaws.com https://www.simscale.com https://*.google-analytics.com https://pagead2.googlesyndication.com https://*.analytics.google.com https://www.google.com https://frontend-assets.dev.simscale.com https://ws-long-dev.simscale.com https://frontend-assets.stg.simscale.com https://ws-long-staging.simscale.com https://frontend-assets.simscale.com https://ws-long.simscale.com https://fonts.googleapis.com https://scout.salesloft.com https://tracking-api.g2.com https://*.g.doubleclick.net https://static.hsappstatic.net https://api.hubapi.com https://cta-service-cms2.hubspot.com https://px.ads.linkedin.com; media-src 'self' https://frontend-assets.dev.simscale.com https://ws-long-dev.simscale.com https://frontend-assets.stg.simscale.com https://ws-long-staging.simscale.com https://frontend-assets.simscale.com https://ws-long.simscale.com; style-src 'self' 'unsafe-inline' https://frontend-assets.dev.simscale.com https://ws-long-dev.simscale.com https://frontend-assets.stg.simscale.com https://ws-long-staging.simscale.com https://frontend-assets.simscale.com https://ws-long.simscale.com https://fonts.googleapis.com; font-src 'self' https://fonts.gstatic.com https://frontend-assets.dev.simscale.com https://ws-long-dev.simscale.com https://frontend-assets.stg.simscale.com https://ws-long-staging.simscale.com https://frontend-assets.simscale.com https://ws-long.simscale.com https://cdn.jsdelivr.net; worker-src 'self' blob:; object-src 'none'; frame-src 'self' https://www.googletagmanager.com https://app.hubspot.com https://demo.arcade.software; frame-ancestors 'self'; form-action 'self' https://*.hubspot.com https://*.hsforms.com https://*.greenhouse.io; 1 object-src 'none';base-uri 'self';script-src 'nonce-GQ21bCO7NdzRck75drZvmA' 'strict-dynamic' 'report-sample' 'unsafe-eval' 'unsafe-inline' https: http:;report-uri https://csp.withgoogle.com/csp/gws/other-hp 1 object-src 'none'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com https://www.google-analytics.com https://js-agent.newrelic.com cdnjs.cloudflare.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://code.jquery.com https://unpkg.com https://ws.sharethis.com https://www.google.com mdbootstrap.com stackpath.bootstrapcdn.com; script-src-attr 'self' 'unsafe-inline'; style-src 'self' cdnjs.cloudflare.com fonts.googleapis.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com mdbootstrap.com stackpath.bootstrapcdn.com use.fontawesome.com; style-src-attr 'self'; frame-ancestors 'self' 1 default-src 'self' 'unsafe-inline' 'unsafe-eval' data: https://cdn.cookielaw.org https://www.bnpparibas.de https://brasil.bnpparibas; script-src 'self' 'unsafe-eval' https://fast.wistia.com https://beacon-v2 https://analyticsgroupcom.bnpparibas.com https://cdn-group.bnpparibas.com https://cdn.cookielaw.org https://cdn.territories.bnpparibas ajax.googleapis.com www.googletagmanager.com googletagmanager.com tagmanager.google.com 'sha256-77WmSGVq6PlE+/dOVkQSZGQWCrUBl6KIyLWH507dV1o=' 'sha256-1n5k85V+yfNkk7Pd+G/nJITXsGJtMZPMLnU5q7WRQvM=' 'sha256-F+QMJISS2IIkRUd2a+c+u1owMqMSoidCaHFDAmzUgOo=' 'sha256-iqOPaRlwwgtNy7J3vh/+LSW9/QVdN+Fl+YfMS8+GcPo=' 'sha256-yZHeusBmoqYSsqdm5ylf993dfqVyosFaYa5gueKZDsA=' 'sha256-rjfSUjIA2A20p4lATAefLLG7Fy7VJssnkJ+SnJ2TXNo=' 'sha256-NoWu+BuWxBsWAc9iEH0HnQQP7HC05AcUDK7axdIDjwo=' 'sha256-RWn1w3BKiDlDNbD6vM1kYLpeWCwwWPkob0LMWJ2gKJk=' 'sha256-GKGWwa58SBAOeyIFddJQypdzbUo7JMQdQDGJaw7vero=' 'sha256-fPXetwWx4258jL256OrNtQQyvFVR4/BotkeZKtfk54Q=' 'sha256-yElBEKucE35qwHf8qWcAvqD25zOJ7TqTptcHyzGhOxw=' 'sha256-Xr7tFjKXkiF47o9/dlJ+izWVWEtr67XyWOK085/Y43E=' 'sha256-qcT/R0HkWUs2DMxvtvcMobUms6Z5/fPtfgUe2hN67gE='; style-src 'self' 'unsafe-inline' data: https://fonts.googleapis.com https://www.gstatic.com https://cdn-group.bnpparibas.com https://cdn.cookielaw.org https://cdn.territories.bnpparibas fonts.googleapis.com www.googletagmanager.com tagmanager.google.com; img-src 'self' data: https://s.w.org https://wp-rocket.me https://c.tile.openstreetmap.org https://a.tile.openstreetmap.org https://b.tile.openstreetmap.org blob: https://www.google.com/pagead/landing https://ade.googlesyndication.com https://pagead2.googlesyndication.com https://ad.doubleclick.net https://contrib.territories.bnpparibas https://cdn-group.bnpparibas.com https://cdn.cookielaw.org https://cdn.territories.bnpparibas secure.gravatar.com www.gravatar.com i.ytimg.com data: www.googletagmanager.com; connect-src 'self' https://bnp-privacy.my.onetrust.com https://geolocation.onetrust.com/cookieconsentpub/v1/geo/location https://yoast.com https://cdn.cookielaw.org https://o173685.ingest.sentry.io https://analyticsgroupcom.bnpparibas.com https://contrib.territories.bnpparibas https://www.google.com/pagead/landing https://pagead2.googlesyndication.com https://adservice.google.com https://sourcemap.devowl.io https://sourcemap.devowl.io/real-media-library/4.22.47/adb9a2f4ef22d5d85978840bd322bf76/index.js.map www.googletagmanager.com; font-src 'self' data: https://fonts.gstatic.com https://fast.wistia.com https://github.com/google/fonts https://cdn-group.bnpparibas.com https://cdn.cookielaw.org https://cdn.territories.bnpparibas fonts.gstatic.com fonts.googleapis.com data:; media-src 'self' https://asset.mediahub.bnpparibas https://upload.wikimedia.org https://broadcast.mediahub.bnpparibas data: https://mediahub.group.echonet https://my.mediahub.bnpparibas https://my.mediahub.bnpparibas/AssetLink/1cwfu8n4ki414p6d240ff18r41ver00j.mp4 https://cdn-group.bnpparibas.com https://cdn.cookielaw.org https://cdn.territories.bnpparibas; frame-src 'self' https://www.youtube.com https://wp-rocket.me https://open.spotify.com https://www.youtube-nocookie.com https://centric.bnpparibas.com https://13179764.fls.doubleclick.net https://td.doubleclick.net https://gateway.zscalertwo.net https://remove.video https://mozbar.moz.com www.youtube.com www.googletagmanager.com; child-src 'self' www.youtube.com www.googletagmanager.com; worker-src 'self' blob:; 1 default-src 'none'; form-action 'none'; frame-ancestors 'none'; report-uri; report-uri https://cybersmart.report-uri.com/r/d/csp/wizard 1 default-src 'self' https://*.pixum.com;base-uri 'self';img-src 'self' https://assets.pixum.com https://cdn.pixum.com https://pixum-cms.imgix.net data: blob: https:;script-src 'self' 'unsafe-inline' 'unsafe-eval' https://*.pixum.com https://app.usercentrics.eu https://gmm9n9.pixum.de https://bn3mcl4n8l.kameleoon.eu https://*.trustpilot.com https://widgets.trustedshops.com https://*.clarity.ms https://*.scarabresearch.com https://storage.googleapis.com/photo-prints-journey-builds/ https://*.pagent.ai https://spot.photoprintit.com https://www.paypal.com/sdk/js https://website-overlay.zenloop.com https://unpkg.com/web-vitals@3/dist/web-vitals.iife.js https://zenloop-website-overlay-production.s3.amazonaws.com https://tag.mention-me.com https://static.mention-me.com https://pixum-assets.imgix.net https://unpkg.com/core-js-bundle@3.16.2/index.js https://tcan97.pixum.co.uk;connect-src 'self' https://*.pixum.com https://*.pixum-api.com https://api.usercentrics.eu https://gmm9n9.pixum.de https://bn3mcl4n8l.kameleoon.eu https://eu-data.kameleoon.eu https://pixum-assets.imgix.net https://consent-api.service.consent.usercentrics.eu https://storage.googleapis.com/pixum-api-images/ https://*.clarity.ms https://webchannel-content.eservice.emarsys.net https://*.scarabresearch.com wss://peer-service.pixum-api.com https://www.pixum.be/5fixu6 https://www.pixum.co.uk/tcan97 https://tcan97.pixum.co.uk https://api.zenloop.com https://channels-api.zenloop.com https://website-overlay.zenloop.com https://graphql.usercentrics.eu https://tag.mention-me.com https://www.paypal.com/xoplatform/logger/api/logger https://guarantee-log.trustedshops.com https://*.pagent.ai https://aggregator.service.usercentrics.eu wss://chatbot-de.photoprintit.com https://trustbadge.api.etrusted.com https://shops-si.trustedshops.com https://pixum-cms.imgix.net https://photospicker.googleapis.com/v1/sessions/ blob: data: https://api.trustedshops.com/rest/internal/ https://api.trustbadge.etrusted.com/accounts/ https://data.kameleoon.eu https://mention-me.com/api/v2/event/ https://gum.criteo.com https://www.gstatic.com/draco/versioned/decoders/1.4.1/ https://faro-collector-prod-eu-west-0.grafana.net/collect/;style-src 'self' 'unsafe-inline' https://*.pixum.com;media-src 'self' data: https://cdn.pixum.com;font-src 'self' data: https://*.pixum.com https://assets.zenloop.com;frame-src 'self' https://widget.trustpilot.com https://dls.photoprintit.com https://mention-me.com https://www.youtube.com https://www.paypal.com blob:;worker-src 'self' blob:;child-src 'self' blob:; report-to csp-report-only; report-uri https://psi.pixum.com/?ns=content-security-policy-report-only&service=base&module=status&action=report 1 style-src 'self' 'unsafe-inline' https://emotivecdn.io *.dev-emotive.com fonts.googleapis.com;img-src 'self' data:;font-src fonts.gstatic.com;connect-src ;frame-ancestors 'self' *.dev-emotive.com https://setup-shop.emotiveapp.co *.myshopify.com;default-src 'self';frame-src ;script-src 'self' 'unsafe-inline' 'unsafe-eval' https://emotivecdn.io *.dev-emotive.com https://www.googletagmanager.com 1 base-uri 'self'; default-src 'self'; font-src 'self' data: cdn.jsdelivr.net fonts.gstatic.com use.typekit.net *.bootstrapcdn.com cdn.userway.org; manifest-src 'self'; frame-src 'self' www.google.com pay.google.com *.googletagmanager.com assets.braintreegateway.com www.facebook.com *.fls.doubleclick.net *.signifyd.com *.online-metrix.net cdn.userway.org www.affirm.com; frame-ancestors 'self'; form-action 'self' tello.com *.tello.com www.facebook.com/tr/; img-src 'self' data: blob: c.clarity.ms c.clarity.ms:443 www.google-analytics.com *.googleadservices.com *.googlesyndication.com *.doubleclick.net *.online-metrix.net img.youtube.com privacy-policy.truste.com imgs.signifyd.com www.google.com www.gstatic.com *.googletagmanager.com cdn.userway.org cdn-assets.affirm.com www.facebook.com alb.reddit.com bat.bing.com *.clarity.ms contentkit.t-mobile.com *.google.ad *.google.ae *.google.al *.google.am *.google.as *.google.at *.google.az *.google.ba *.google.be *.google.bf *.google.bg *.google.bi *.google.bj *.google.bs *.google.bt *.google.by *.google.ca *.google.cat *.google.cd *.google.cf *.google.cg *.google.ch *.google.ci *.google.cl *.google.cm *.google.cn *.google.co.ao *.google.co.bw *.google.co.ck *.google.co.cr *.google.co.id *.google.co.il *.google.co.in *.google.co.jp *.google.co.ke *.google.co.kr *.google.co.ls *.google.com *.google.co.ma *.google.com.af *.google.com.ag *.google.com.ar *.google.com.au *.google.com.bd *.google.com.bh *.google.com.bn *.google.com.bo *.google.com.br *.google.com.bz *.google.com.co *.google.com.cu *.google.com.cy *.google.com.do *.google.com.ec *.google.com.eg *.google.com.et *.google.com.fj *.google.com.gh *.google.com.gi *.google.com.gt *.google.com.hk *.google.com.jm *.google.com.kh *.google.com.kw *.google.com.lb *.google.com.ly *.google.com.mm *.google.com.mt *.google.com.mx *.google.com.my *.google.com.na *.google.com.ng *.google.com.ni *.google.com.np *.google.com.om *.google.com.pa *.google.com.pe *.google.com.pg *.google.com.ph *.google.com.pk *.google.com.pr *.google.com.py *.google.com.qa *.google.com.sa *.google.com.sb *.google.com.sg *.google.com.sl *.google.com.sv *.google.com.tj *.google.com.tr *.google.com.tw *.google.com.ua *.google.com.uy *.google.com.vc *.google.com.vn *.google.co.mz *.google.co.nz *.google.co.th *.google.co.tz *.google.co.ug *.google.co.uk *.google.co.uz *.google.co.ve *.google.co.vi *.google.co.za *.google.co.zm *.google.co.zw *.google.cv *.google.cz *.google.de *.google.dj *.google.dk *.google.dm *.google.dz *.google.ee *.google.es *.google.fi *.google.fm *.google.fr *.google.ga *.google.ge *.google.gg *.google.gl *.google.gm *.google.gr *.google.gy *.google.hn *.google.hr *.google.ht *.google.hu *.google.ie *.google.im *.google.iq *.google.is *.google.it *.google.je *.google.jo *.google.kg *.google.ki *.google.kz *.google.la *.google.li *.google.lk *.google.lt *.google.lu *.google.lv *.google.md *.google.me *.google.mg *.google.mk *.google.ml *.google.mn *.google.mu *.google.mv *.google.mw *.google.ne *.google.nl *.google.no *.google.nr *.google.nu *.google.pl *.google.pn *.google.ps *.google.pt *.google.ro *.google.rs *.google.ru *.google.rw *.google.sc *.google.se *.google.sh *.google.si *.google.sk *.google.sm *.google.sn *.google.so *.google.sr *.google.st *.google.td *.google.tg *.google.tl *.google.tm *.google.tn *.google.to *.google.tt *.google.vu *.google.ws; connect-src 'self' *.affirm.com cdnjs.cloudflare.com cdn.jsdelivr.net *.google-analytics.com *.googleadservices.com *.googlesyndication.com analytics.google.com *.analytics.google.com www.merchant-center-analytics.goog google.com www.google.com pay.google.com *.googletagmanager.com www.paypal.com www.sandbox.paypal.com payments.braintree-api.com payments.sandbox.braintree-api.com *.signifyd.com *.t-mobile.com *.doubleclick.net www.facebook.com analytics.tiktok.com analytics-ipv6.tiktokw.us bat.bing.com *.clarity.ms prodregistryv2.org *.taboola.com pixel-config.reddit.com dx.steelhousemedia.com featureassets.org api.userway.org cdn.userway.org cdn77.api.userway.org api.mapbox.com events.mapbox.com *.google.ad *.google.ae *.google.al *.google.am *.google.as *.google.at *.google.az *.google.ba *.google.be *.google.bf *.google.bg *.google.bi *.google.bj *.google.bs *.google.bt *.google.by *.google.ca *.google.cat *.google.cd *.google.cf *.google.cg *.google.ch *.google.ci *.google.cl *.google.cm *.google.cn *.google.co.ao *.google.co.bw *.google.co.ck *.google.co.cr *.google.co.id *.google.co.il *.google.co.in *.google.co.jp *.google.co.ke *.google.co.kr *.google.co.ls *.google.com *.google.co.ma *.google.com.af *.google.com.ag *.google.com.ar *.google.com.au *.google.com.bd *.google.com.bh *.google.com.bn *.google.com.bo *.google.com.br *.google.com.bz *.google.com.co *.google.com.cu *.google.com.cy *.google.com.do *.google.com.ec *.google.com.eg *.google.com.et *.google.com.fj *.google.com.gh *.google.com.gi *.google.com.gt *.google.com.hk *.google.com.jm *.google.com.kh *.google.com.kw *.google.com.lb *.google.com.ly *.google.com.mm *.google.com.mt *.google.com.mx *.google.com.my *.google.com.na *.google.com.ng *.google.com.ni *.google.com.np *.google.com.om *.google.com.pa *.google.com.pe *.google.com.pg *.google.com.ph *.google.com.pk *.google.com.pr *.google.com.py *.google.com.qa *.google.com.sa *.google.com.sb *.google.com.sg *.google.com.sl *.google.com.sv *.google.com.tj *.google.com.tr *.google.com.tw *.google.com.ua *.google.com.uy *.google.com.vc *.google.com.vn *.google.co.mz *.google.co.nz *.google.co.th *.google.co.tz *.google.co.ug *.google.co.uk *.google.co.uz *.google.co.ve *.google.co.vi *.google.co.za *.google.co.zm *.google.co.zw *.google.cv *.google.cz *.google.de *.google.dj *.google.dk *.google.dm *.google.dz *.google.ee *.google.es *.google.fi *.google.fm *.google.fr *.google.ga *.google.ge *.google.gg *.google.gl *.google.gm *.google.gr *.google.gy *.google.hn *.google.hr *.google.ht *.google.hu *.google.ie *.google.im *.google.iq *.google.is *.google.it *.google.je *.google.jo *.google.kg *.google.ki *.google.kz *.google.la *.google.li *.google.lk *.google.lt *.google.lu *.google.lv *.google.md *.google.me *.google.mg *.google.mk *.google.ml *.google.mn *.google.mu *.google.mv *.google.mw *.google.ne *.google.nl *.google.no *.google.nr *.google.nu *.google.pl *.google.pn *.google.ps *.google.pt *.google.ro *.google.rs *.google.ru *.google.rw *.google.sc *.google.se *.google.sh *.google.si *.google.sk *.google.sm *.google.sn *.google.so *.google.sr *.google.st *.google.td *.google.tg *.google.tl *.google.tm *.google.tn *.google.to *.google.tt *.google.vu *.google.ws; style-src 'report-sample' 'self' 'unsafe-inline' cdn.jsdelivr.net fonts.googleapis.com use.typekit.net p.typekit.net *.affirm.com *.bootstrapcdn.com cdn.userway.org contentkit.t-mobile.com; script-src 'nonce-f5754b47e9f24c023442e01d200c6141' 'strict-dynamic' 'report-sample' 'self' 'unsafe-eval' blob: cdn.jsdelivr.net cdn.polyfill.io cdnjs.cloudflare.com code.jquery.com firebase.google.com flatpickr.js.org getbootstrap.com jquery.com jqueryvalidation.org stackpath.bootstrapcdn.com www.gstatic.com *.googletagmanager.com doubleclick.net *.doubleclick.net pay.google.com *.signifyd.com *.online-metrix.net *.affirm.com analytics.tiktok.com dx.steelhousemedia.com; report-uri https://tello.com/csp_report; report-to csp-report; 1 default-src 'self' https:; img-src 'self' https: assets.braintreegateway.com checkout.paypal.com bam.nr-data.net staging.shirtspace.com *.googletagmanager.com data:; font-src 'self' *.typekit.net cdn.shirtspace.com *.gstatic.com *.googleapis.com *.acsbapp.com data:; object-src 'none'; script-src 'self' 'unsafe-eval' *.google-analytics.com *.google.com *.googletagmanager.com *.gstatic.com *.googleadservices.com *.g.doubleclick.net *.googlecommerce.com *.newrelic.com bam.nr-data.net *.braintreegateway.com www.paypalobjects.com *.paypal.com c.paypal.com widget.trustpilot.com connect.facebook.net graph.facebook.com bat.bing.com s.yimg.com sp.analytics.yahoo.com *.pinterest.com *.pinimg.com device.maxmind.com *.typekit.net cdn.jsdelivr.net *.honeybadger.io *.ckeditor.com io.clickguard.com acsbapp.com sc-static.net api.ipify.org cdnjs.cloudflare.com *.easysize.me *.klaviyo.com unleash.shirtspace.com unpkg.com *.frontapp.com cdn.shirtspace.com 'nonce-'; style-src 'self' cdn.shirtspace.com *.googleapis.com *.typekit.net *.typeform.com *.ckeditor.com cdnjs.cloudflare.com *.easysize.me *.klaviyo.com 'unsafe-inline' 'nonce-'; child-src 'self' assets.braintreegateway.com c.paypal.com; frame-src 'self' assets.braintreegateway.com *.paypal.com widget.trustpilot.com www.facebook.com *.g.doubleclick.net *.google.com *.googletagmanager.com *.pinterest.com www.youtube.com *.acsbapp.com accessibe.com player.vimeo.com tr.snapchat.com tpc.googlesyndication.com *.easysize.me *.typeform.com; connect-src 'self' *.braintreegateway.com 'unsafe-inline' *.google-analytics.com *.g.doubleclick.net *.google.com *.braintree-api.com *.paypal.com *.pinterest.com *.mmapiws.com widget.trustpilot.com *.typekit.net www.facebook.com s.yimg.com http://localhost:3035 ws://localhost:3035 *.acsbapp.com io.clickguard.com bam.nr-data.net *.klaviyo.com *.easysize.me unleash.shirtspace.com cdn.shirtspace.com 1 script-src 'self' 'unsafe-eval' 'unsafe-inline' data: 'self' blob: *.cloudmaestro.com backend.yoogiscloset.com frontend.yoogiscloset.com js-agent.newrelic.com *.nr-data.net backend.yoogiscloset.com frontend.yoogiscloset.com www.yoogiscloset.com xdymhcopnh.execute-api.us-east-1.amazonaws.com knrpc.olark.com www.googletagmanager.com www.googleadservices.com ajax.googleapis.com apis.google.com connect.facebook.net static.olark.com *.google-analytics.com *.listrakbi.com *.static.olark.com *.affirm.com *.firebaseapp.com *.lightwidget.com *.adroll.com *.bing.com *.doubleclick.net *.trustpilot.com storage.googleapis.com api.olark.com *.googleapis.com *.sharethis.com *.clarity.ms www.clarity.ms *.api.olark.com www.google.com connect.facebook.com www.facebook.com *.paypal.com *.paypalobjects.com www.recaptcha.net www.gstatic.com accounts.google.com *.adobedtm.com; report-uri /.webscale/csp-report 1 default-src ws: wss: http: https: data: 'unsafe-inline' 'unsafe-eval'; report-uri https://app.cyberimpact.com/csp-violation-report/ 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval'; style-src 'self' 'unsafe-inline'; img-src 'self' data:; font-src 'self'; connect-src 'self'; report-uri https://dcc-cspreport.enovation.ie/csp-report-dccdrupal.php 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com *.googletagmanager.com *.google.com *.fontawesome.com https://fonts.bunny.net https://www.google.com https://www.gstatic.com *.cloudflare.com *.twitter.com *.twimg.com *.trustedshops.com https://square-fonts-production-f.squarecdn.com/ https://d1g145x70srn7h.cloudfront.net/ https://cash-f.squarecdn.com/ https://fonts.gstatic.com/ data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.google.com *.googletagmanager.com *.googleapis.com *.facebook.com *.authorize.net *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.twitter.com https://acs-us-east-1.ndsprod.nds-sandbox-issuer.com/ 'self' 'unsafe-inline'; frame-ancestors self www.google.com *.authorize.net 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.googletagmanager.com *.facebook.com *.squarecdn.com www.google.com www.gstatic.com apis.google.com *.authorize.net c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.twitter.com https://pci-connect.squareup.com https://connect.squareup.com https://pci-connect.squareupsandbox.com https://connect.squareupsandbox.com https://sandbox.web.squarecdn.com https://web.squarecdn.com https://sandbox.kit.cash.app/ https://kit.cash.app/ https://acs-us-east-1.ndsprod.nds-sandbox-issuer.com/ https://api.squareupsandbox.com/ https://api.squareup.com/ 'self' 'unsafe-inline'; img-src 'self' data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io www.apptrian.com maps.gstatic.com *.google.com *.google.co.in *.redditstatic.com *.reddit.com https://firebasestorage.googleapis.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.facebook.com https://meetanshi.com/media/logo.png www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.cloudflare.com *.klarna.com *.googleadservices.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.cloudfront.net https://www.gstatic.com/ https://sandbox.api.cash.app/ https://site-assets.afterpay.com/ https://sandbox.web.squarecdn.com/ https://api.cash.app/ https://web.squarecdn.com/ https://api.squareupsandbox.com/ https://api.squareup.com/ https://franklin-assets.s3.amazonaws.com/ https://static.sandbox.afterpay.com/ https://static.afterpay.com/ https://static.sandbox.afterpay.com/logo/ data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com commerce-payments-sdk.adobe.io www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com www.apptrian.com maps.googleapis.com *.authorize.net *.paypal.com *.mouseflow.com localmenu.katzsdelicatessen.com *.addthis.com *.noibu.com *.redditstatic.com *.reddit.com *.tiktok.com *.tiktokw.us *.facebook.com *.vibe.co *.avada.io *.shopify.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.googleapis.com *.gstatic.com *.googletagmanager.com *.facebook.net www.termsfeed.com *.fontawesome.com player.vimeo.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com *.cloudflare.com *.twitter.com *.google-analytics.com *.twimg.com *.trustedshops.com *.usercentrics.eu https://js-sandbox.squarecdn.com https://js.squareup.com https://js.afterpay.com/ https://nd.squarecdn.com https://js.squareupsandbox.com https://sandbox.web.squarecdn.com https://web.squarecdn.com https://portal.sandbox.afterpay.com/ https://portal.afterpay.com/ https://cdn.plaid.com/ https://sandbox.kit.cash.app/ https://kit.cash.app/ https://js-sandbox.squarecdn.com/ https://js.squarecdn.com/ 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.googletagmanager.com *.google.com *.klaviyo.com *.fontawesome.com https://fonts.bunny.net https://static.klaviyo.com *.gstatic.com assets.braintreegateway.com *.cloudflare.com *.twitter.com *.twimg.com *.typekit.net *.trustedshops.com *.usercentrics.eu https://sandbox.web.squarecdn.com https://web.squarecdn.com https://sandbox.kit.cash.app/ https://kit.cash.app/ https://fonts.googleapis.com/ 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com www.apptrian.com maps.googleapis.com *.google-analytics.com *.googletagmanager.com *.googleapis.com *.doubleclick.net *.klaviyo.com *.report-uri.com *.noibu.com wss://*.noibu.com *.redditstatic.com *.reddit.com *.facebook.com *.tiktok.com *.tiktokw.us *.vibe.co https://get.geojs.io *.avada.io https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ http://dpm.demdex.net https://www.google.com https://www.gstatic.com *.authorize.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.cloudflare.com *.twitter.com *.twimg.com https://pci-connect.squareup.com https://pci-connect.squareupsandbox.com https://api.amplitude.com/ https://api.squareupsandbox.com/ https://api.squareup.com/ https://o160250.ingest.sentry.io/ https://api.lab.amplitude.com/sdk/vardata https://sandbox.plaid.com/ https://production.plaid.com/ 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.report-uri.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://katzsdelicatessen.report-uri.com/r/d/csp/enforce; report-to report-endpoint; 1 base-uri; default-src 'self' https://www.googletagmanager.com https://www.google-analytics.com https://fonts.googleapis.com https://fonts.gstatic.com https://ssl.google-analytics.com https://www.google.com https://www.gstatic.com https://analytics.google.com https://stats.g.doubleclick.net https://ajax.googleapis.com https://docs.teket.jp data:; connect-src 'self' https://www.googletagmanager.com https://www.google-analytics.com https://fonts.googleapis.com https://fonts.gstatic.com https://ssl.google-analytics.com https://www.google.com https://www.gstatic.com https://analytics.google.com https://stats.g.doubleclick.net https://ajax.googleapis.com https://teket.zendesk.com https://zendesk-eu.my.sentry.io https://static.zdassets.com https://ekr.zdassets.com https://api.smooch.io wss://api.smooch.io https://s.clarity.ms https://docs.teket.jp; form-action; frame-src https://www.google.com/ https://p01.mul-pay.jp; img-src 'self' https://www.googletagmanager.com https://www.google-analytics.com https://fonts.googleapis.com https://fonts.gstatic.com https://ssl.google-analytics.com https://www.google.com https://www.gstatic.com https://analytics.google.com https://stats.g.doubleclick.net https://ajax.googleapis.com https://teket.zendesk.com https://zendesk-eu.my.sentry.io https://static.zdassets.com https://ekr.zdassets.com https://api.smooch.io wss://api.smooch.io https://docs.teket.jp data:; object-src; script-src 'self' https://www.googletagmanager.com https://www.google-analytics.com https://fonts.googleapis.com https://fonts.gstatic.com https://ssl.google-analytics.com https://www.google.com https://www.gstatic.com https://analytics.google.com https://stats.g.doubleclick.net https://ajax.googleapis.com https://teket.zendesk.com https://zendesk-eu.my.sentry.io https://static.zdassets.com https://ekr.zdassets.com https://api.smooch.io wss://api.smooch.io https://p01.mul-pay.jp 'unsafe-inline' 'unsafe-eval' blob:; script-src-elem 'self' https://www.googletagmanager.com https://www.google-analytics.com https://fonts.googleapis.com https://fonts.gstatic.com https://ssl.google-analytics.com https://www.google.com https://www.gstatic.com https://analytics.google.com https://stats.g.doubleclick.net https://ajax.googleapis.com https://teket.zendesk.com https://zendesk-eu.my.sentry.io https://static.zdassets.com https://ekr.zdassets.com https://api.smooch.io wss://api.smooch.io https://www.clarity.ms https://cdnjs.cloudflare.com https://code.jquery.com https://connect.facebook.net 'unsafe-inline' blob:; style-src 'self' https://www.googletagmanager.com https://www.google-analytics.com https://fonts.googleapis.com https://fonts.gstatic.com https://ssl.google-analytics.com https://www.google.com https://www.gstatic.com https://analytics.google.com https://stats.g.doubleclick.net https://ajax.googleapis.com https://teket.zendesk.com https://zendesk-eu.my.sentry.io https://static.zdassets.com https://ekr.zdassets.com https://api.smooch.io wss://api.smooch.io 'unsafe-inline' 1 script-src 'nonce-42Gwis84X7llYtiKCoUh2A==' 'strict-dynamic' 'unsafe-eval' 'unsafe-inline' https: 'report-sample'; base-uri 'none'; report-uri https://events.mercadolibre.com/csp/reports?identifier=w1qeU4XKVwGbQGBuEKyE3KhFBIpr5IZSIaRiTowMc8UG7kU18vRsmBTEKL2krAj23LIS&policy_id=26548&user_id=&request_id=df622f11-32e6-4f6f-ae7f-efbb14cdac92; report-to csp-endpoint-wqeuxkvwgbqgbuekyekhfbiprizsiaritowmcugkuvrsmbteklkrajlis; object-src https://http2.mlstatic.com/ https://mlstaticquic-a.akamaihd.net/; frame-ancestors 'self' https://*.mercadolibre.cl:* https://*.mercadolibre.com:* https://*.mercadolibre.com.ve:* https://*.mercadolibre.com.ar:* https://*.mercadolivre.com.br:* https://*.mercadolibre.com.co:* https://*.mercadolibre.com.ec:* https://*.mercadolibre.com.mx:* https://*.mercadolibre.com.pe:* https://*.mercadolibre.com.uy:* https://*.mercadopago.cl:* https://*.mercadopago.com.ar:* https://*.mercadopago.com.br:* https://*.mercadopago.com.co:* https://*.mercadopago.com.mx:* https://*.mercadopago.com.pe:* https://*.mercadopago.com.uy:* https://*.mercadopago.com.ve:* https://*.mercadopago.com:* https://*.adminml.com:* https://*.mercadolibre.co.cr:* https://*.mercadolibre.com.pa:* https://*.mercadolibre.com.do:* https://*.mercadolibre.com.bo:* https://*.mercadolibre.com.py:* https://*.mercadolibre.com.gt:* https://*.mercadolibre.com.hn:* https://*.mercadolibre.com.ni:* https://*.mercadolibre.com.sv:* https://*.mercadopago.com.ec:* https://*.portalinmobiliario.com:* https://*.mercadolivre.com:* 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.klevu.com *.ksearchnet.com https://fonts.gstatic.com/ *.nosto.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.nosto.com *.nos.to *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.awin1.com *.zenaps.com *.fls.doubleclick.net account.fetchify.com https://www.googletagmanager.com/ *.nosto.com *.nos.to c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * widget.trustpilot.com simplicity.trustpilot.com *.googlesyndication.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.trustpilot.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.awin1.com *.zenaps.com *.wepowerconnections.com test-pay.dnapayments.com pay.dnapayments.com *.klevu.com *.ksearchnet.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ *.nosto.com *.nos.to www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com https://s3-eu-west-1.amazonaws.com *.cdninstagram.com *.poundshop.com *.poundland.com *.poundland.co.uk *.dealz.ie *.onetrust.com s.kelkoogroup.net c.bing.com c.clarity.ms bat.bing.com *.ometria.com *.google.ac *.google.ad *.google.ae *.google.com.af *.google.com.ag *.google.com.ai *.google.al *.google.am *.google.co.ao *.google.com.ar *.google.as *.google.at *.google.com.ua *.google.az *.google.ba *.google.com.bd *.google.be *.google.bf *.google.bg *.google.com.bh *.google.bi *.google.bj *.google.com.bn *.google.com.bo *.google.com.br *.google.bs *.google.bt *.google.co.bw *.google.by *.google.com.bz *.google.ca *.google.com.kh *.google.cc *.google.cd *.google.cf *.google.cat *.google.cg *.google.ch *.google.ci *.google.co.ck *.google.cl *.google.cm *.google.cn *.google.com.co *.google.co.cr *.google.com.cu *.google.cv *.google.com.cy *.google.cz *.google.de *.google.dj *.google.dk *.google.dm *.google.com.do *.google.dz *.google.com.ec *.google.ee *.google.com.eg *.google.es *.google.com.et *.google.fi *.google.com.fj *.google.fm *.google.fr *.google.ga *.google.ge *.google.gf *.google.gg *.google.com.gh *.google.com.gi *.google.gl *.google.gm *.google.gp *.google.gr *.google.com.gt *.google.gy *.google.com.hk *.google.hn *.google.hr *.google.ht *.google.hu *.google.co.id *.google.iq *.google.ie *.google.co.il *.google.im *.google.co.in *.google.io *.google.is *.google.it *.google.je *.google.com.jm *.google.jo *.google.co.jp *.google.co.ke *.google.ki *.google.kg *.google.co.kr *.google.com.kw *.google.kz *.google.la *.google.com.lb *.google.com.lc *.google.li *.google.lk *.google.co.ls *.google.lt *.google.lu *.google.lv *.google.com.ly *.google.co.ma *.google.md *.google.me *.google.mg *.google.mk *.google.ml *.google.com.mm *.google.mn *.google.ms *.google.com.mt *.google.mu *.google.mv *.google.mw *.google.com.mx *.google.com.my *.google.co.mz *.google.com.na *.google.ne *.google.com.nf *.google.com.ng *.google.com.ni *.google.nl *.google.no *.google.com.np *.google.nr *.google.nu *.google.co.nz *.google.com.om *.google.com.pk *.google.com.pa *.google.com.pe *.google.com.ph *.google.pl *.google.com.pg *.google.pn *.google.co.pn *.google.com.pr *.google.ps *.google.pt *.google.com.py *.google.com.qa *.google.ro *.google.rs *.google.rw *.google.com.sa *.google.com.sb *.google.sc *.google.se *.google.com.sg *.google.sh *.google.si *.google.sk *.google.com.sl *.google.sn *.google.sm *.google.so *.google.st *.google.sr *.google.com.sv *.google.td *.google.tg *.google.co.th *.google.com.tj *.google.tk *.google.tl *.google.tm *.google.to *.google.tn *.google.com.tr *.google.tt *.google.com.tw *.google.co.tz *.google.co.ug *.google.co.uk *.google.com *.google.com.uy *.google.co.uz *.google.com.vc *.google.co.ve *.google.vg *.google.co.vi *.google.com.vn *.google.vu *.google.ws *.google.co.za *.google.co.zm *.google.co.zw data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://rum.hlx.page www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.awin1.com *.dwin1.com *.zenaps.com *.wepowerconnections.com https://the.sciencebehindecommerce.com lantern.roeyecdn.com pay.dnapayments.com test-pay.dnapayments.com cdn.dnapayments.com test-cdn.dnapayments.com sentry.dnapayments.com test-sentry.dnapayments.com cc-cdn.com js.klevu.com *.ksearchnet.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ *.nosto.com *.nos.to js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.poundshop.com *.poundland.com *.poundland.co.uk *.dealz.ie s.kelkoogroup.net widget.trustpilot.com invitejs.trustpilot.com sdk.loyaltylion.net foursixty.com sdk-static.loyaltylion.net bat.bing.com *.zendesk.com static.zdassets.com *.ometria.com analytics.tiktok.com www.clarity.ms s.kk-resources.com *.googlesyndication.com *.onetrust.com *.soreto.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com *.trustpilot.com https://www.poundland.co.uk 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com cc-cdn.com *.klevu.com *.ksearchnet.com *.nosto.com *.nos.to assets.braintreegateway.com sdk.loyaltylion.net foursixty.com *.onetrust.com *.typekit.net *.stripe.network *.stripecdn.com *.amazon.com *.trustpilot.com https://statsjs.klevu.com https://js.klevu.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.wepowerconnections.com https://the.sciencebehindecommerce.com https://test-api.dnapayments.com https://api.dnapayments.com sentry.dnapayments.com test-sentry.dnapayments.com api.craftyclicks.co.uk pcls1.craftyclicks.co.uk cc-cdn.com *.klevu.com *.ksearchnet.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ *.nosto.com *.nos.to api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com sdk.loyaltylion.net foursixty.com platform.loyaltylion.com *.zendesk.com widget-mediator.zopim.com wss://widget-mediator.zopim.com analytics.tiktok.com *.clarity.ms s.kelkoogroup.net invitejs.trustpilot.com zendesk-eu.my.sentry.io *.ometria.com *.onetrust.com *.googlesyndication.com *.soreto.com googleads.g.doubleclick.net *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com 'self' 'unsafe-inline'; child-src *.awin1.com *.zenaps.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://04bdc3b5-2455-47f6-9c1d-24c9c5f93a61.sansec.watch/; report-to report-endpoint; 1 object-src 'none';base-uri 'self';script-src 'nonce-bYQjSNfrRl7EmZgHCn8wgQ' 'strict-dynamic' 'report-sample' 'unsafe-eval' 'unsafe-inline' https: http:;report-uri https://csp.withgoogle.com/csp/gws/other-hp 1 connect-src 'self' wss://*.fieldlevel.com:4000 https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://www.google.com https://*.hotjar.com https://*.hotjar.io wss://*.hotjar.com https://via.intercom.io https://api.intercom.io https://api.au.intercom.io https://api.eu.intercom.io https://api-iam.intercom.io https://api-iam.eu.intercom.io https://api-iam.au.intercom.io https://api-ping.intercom.io https://nexus-websocket-a.intercom.io wss://nexus-websocket-a.intercom.io https://nexus-websocket-b.intercom.io wss://nexus-websocket-b.intercom.io https://nexus-europe-websocket.intercom.io wss://nexus-europe-websocket.intercom.io https://nexus-australia-websocket.intercom.io wss://nexus-australia-websocket.intercom.io https://uploads.intercomcdn.com https://uploads.intercomcdn.eu https://uploads.au.intercomcdn.com https://uploads.eu.intercomcdn.com https://uploads.intercomusercontent.com https://*.litix.io https://*.mux.com https://api.mapbox.com https://events.mapbox.com;font-src 'self' https://js.intercomcdn.com https://fonts.intercomcdn.com; 1 font-src cdn.jsdelivr.net fonts.gstatic.com cdn.almapay.com https://api.systempay.fr/static/ https://applepay.cdn-apple.com *.fontawesome.com https://cdnjs.cloudflare.com applepay.cdn-apple.com *.gstatic.com 'self' data: *.avis-verifies.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com https://paiement.systempay.fr/vads-payment/ https://api.systempay.fr/api-payment/ https://api.systempay.fr/static/ https://plumrocket.com *.facebook.com *.facebook.net *.sutunam.info 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com player.vimeo.com https://www.google.com/recaptcha/ *.getalma.eu *.almapay.com/ *.stripe.com/ *.checkout.com/ *.adyen.com/ www.google.com https://paiement.systempay.fr/vads-payment/ https://api.systempay.fr/static/ *.payplug.com *.dalenys.com https://applepay.cdn-apple.com https://www.googletagmanager.com/ https://plumrocket.com *.facebook.com *.facebook.net hcaptcha.com *.hcaptcha.com api-qa.payplug.com secure-qa.payplug.com https://accounts.google.com *.doubleclick.net 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://images.unsplash.com https://paiement.systempay.fr/static/latest/images/type-carte/ https://api.systempay.fr/static/ https://paiement.systempay.fr/vads-payment/ *.openstreetmap.fr unpkg.com *.openstreetmap.org https://secure-magenta.dalenys.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ magefan.com cm.magefan.com *.facebook.com *.facebook.net *.hsforms.net *.hsforms.com 'self' data: *.avis-verifies.com *.sutunam.info cdn-cookieyes.com placehold.co *.google.fr data: 'self' 'unsafe-inline'; script-src www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ cdn.jsdelivr.net https://maps.googleapis.com https://cdn.jsdelivr.net/npm/@ryangjchandler/spruce@2.x.x/dist/spruce.umd.js www.google.com/recaptcha/ www.gstatic.com/recaptcha/ https://api.systempay.fr/api-payment/ https://api.systempay.fr/static/ unpkg.com/leaflet@1.9.4/dist/leaflet.js https://secure-magenta.dalenys.com https://applepay.cdn-apple.com api-qa.payplug.com cdn-qa.payplug.com cdn.payplug.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ unpkg.com/masonry-layout@4/dist/masonry.pkgd.min.js *.facebook.com *.facebook.net *.avada.io https://cdnjs.cloudflare.com hcaptcha.com *.hcaptcha.com applepay.cdn-apple.com https://cdn-qa.payplug.com https://accounts.google.com https://www.gstatic.com *.hsforms.net *.hsforms.com *.google.com *.gstatic.com *.skeepers.io *.avis-verifies.com cdn-cookieyes.com *.hotjar.com *.payplug.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src cdn.jsdelivr.net fonts.googleapis.com https://api.systempay.fr/static/ unpkg.com/leaflet@1.9.4/dist/leaflet.css https://secure-magenta.dalenys.com *.fontawesome.com https://fonts.googleapis.com https://cdnjs.cloudflare.com hcaptcha.com *.hcaptcha.com https://accounts.google.com https://www.gstatic.com *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.getalma.eu *.almapay.com https://maps.googleapis.com https://player.vimeo.com https://paiement.systempay.fr/vads-payment/ https://api.systempay.fr/api-payment/ nominatim.openstreetmap.org http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ *.facebook.com *.facebook.net https://get.geojs.io *.avada.io hcaptcha.com *.hcaptcha.com https://accounts.google.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com *.skeepers.io/ *.netreviews.eu api-adresse.data.gouv.fr cdn-cookieyes.com *.cookieyes.com *.google.com google.com *.hotjar.io *.jsdelivr.net unpkg.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src https://paiement.systempay.fr/vads-payment/ https://api.systempay.fr/api-payment/ https://api.systempay.fr/static/ *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 worker-src blob: *.osano.com 'self'; font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com cash-f.squarecdn.com https://*.gstatic.com *.cloudinary.com *.klarnacdn.net *.fontawesome.com https://fonts.gstatic.com https://www.google.com https://www.gstatic.com *.narvar.com *.narvar.qa *.abtasty.com cdnjs.cloudflare.com *.yottaa.net use.fontawesome.com maxcdn.bootstrapcdn.com *.yotpo.com *.googleapis.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com * *.adyen.com cloudinary.com *.cloudinary.com 'self' facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com forms.hsforms.com globalshopex.com api.ometria.com *.yotpo.com swellrewards.com *.swellrewards.com 'self' 'unsafe-inline'; frame-ancestors *.certcapture.com *.krxd.net *.attn.tv 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com * *.adyen.com cloudinary.com *.cloudinary.com cdnjs.cloudflare.com *.klarna.com facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.certcapture.com forms.hsforms.com scrubsandbeyond.ytuz.net cdn.krxd.net *.osano.com ct.pinterest.com *.studentbeans.com globalshopex.com *.attn.tv *.yotpo.com swellrewards.com *.swellrewards.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net * https://*.gstatic.com *.adyen.com cloudinary.com *.cloudinary.com blob: *.klarna.com *.klarnaevt.com *.klarnacdn.net www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.narvar.com *.narvar.qa *.ometria.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.certcapture.com *.abtasty.com aa.agkn.com *.amazonaws.com *.payments-amazon.com *.bing.com *.clarity.ms *.foregenix.com maps.gstatic.com maps.googleapis.com forms.hsforms.com track.hubspot.com nova.collect.igodigital.com logs-01.loggly.com www.ojrq.net scrubsandbeyond.ytuz.net beacon.krxd.net *.pinterest.com *.px-cloud.net track.sv.rkdms.com www.scrubsandbeyond.com track.securedvisit.com *.yottaa.net fonts.gstatic.com events.attentivemobile.com *.yotpo.com swellrewards.com *.swellrewards.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com *.cash.app *.visa.com *.mastercard.com cloudinary.com *.cloudinary.com cdnjs.cloudflare.com *.vimeo.com unpkg.com *.klarna.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.googleapis.com *.gstatic.com connect.facebook.net graph.facebook.com business.facebook.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com *.certcapture.com *.abtasty.com bat.bing.com www.clarity.ms cnstrc.com maps.googleapis.com js.hs-analytics.net js.hs-banner.com js.hscollectedforms.net js.hsforms.net *.hs-scripts.com *.igodigital.com utt.impactcdn.com d.impactradius-event.com *.krxd.net action.media6degrees.com js-agent.newrelic.com *.osano.com s.pinimg.com assets.pinterest.com cdn.roirevolution.com *.securedvisit.com seoab.io cdn.studentbeans.com *.yottaa.net rapid-cdn.yottaa.com *.yottaa-prod.com globalshopex.com cdn.noibu.com *.attn.tv *.yotpo.com swellrewards.com *.swellrewards.com platform.twitter.com *.ometria.com https://cdn.amplitude.com https://www.scrubsandbeyond.com https://tkzgz.scrubsandbeyond.com http: https: blob: 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.cash.app cloudinary.com *.cloudinary.com *.googleapis.com unpkg.com *.klarnacdn.net *.fontawesome.com *.google.com *.gstatic.com assets.braintreegateway.com *.certcapture.com *.abtasty.com *.osano.com *.yottaa.net use.typekit.net p.typekit.net www.googletagmanager.com ometria.email *.yotpo.com swellrewards.com *.swellrewards.com maxcdn.bootstrapcdn.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com cloudinary.com *.cloudinary.com *.narvar.com *.narvar.qa 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com * *.adyen.com cloudinary.com *.cloudinary.com *.klarnaevt.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.klarna.com http://dpm.demdex.net https://www.google.com https://www.gstatic.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com google.com/pay pay.google.com *.certcapture.com *.amazonaws.com *.abtasty.com bat.bing.com *.clarity.ms stats.g.doubleclick.net accounts.google.com fonts.googleapis.com maps.googleapis.com forms.hubspot.com forms.hsforms.com scrubsandbeyond.ytuz.net api.ipify.org www.iplocate.io *.ingest.sentry.io *.osano.com ct.pinterest.com *.px-cloud.net seoab.io storage.googleapis.com event-service-jtdpxp3bfa-ew.a.run.app *.yottaa.net https://*.cnstrc.com cdn.noibu.com input.noibu.com wss://input.noibu.com https://api.scrubsandbeyond.com/api/locations *.attn.tv events.attentivemobile.com tkzgz.scrubsandbeyond.com *.yotpo.com swellrewards.com *.swellrewards.com *.ometria.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com *.certcapture.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' https:; script-src 'self' 'unsafe-inline' https:; script-src-elem 'self' https:; style-src 'self' 'unsafe-inline' https:; style-src-elem 'self' https:; img-src 'self' https: data:; connect-src 'self' https:; font-src 'self' https: data:; frame-ancestors 'self'; object-src 'none'; base-uri 'self'; upgrade-insecure-requests 1 report-uri https://csp.withgoogle.com/csp/youtube_main/strict;base-uri 'self';object-src 'none';script-src 'report-sample' 'nonce-g8CbiBCjmNNQN4lFOzq63Q' 'unsafe-inline' 'strict-dynamic' https: http: 'unsafe-eval' 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://api-sogecommerce.societegenerale.eu/static/ *.fontawesome.com *.googleapis.com *.cloudflare.com *.twitter.com *.twimg.com *.trustedshops.com *.zopim.com *.zopim.io *.bushboard.co.uk *.cookiebot.com *.chatbeacon.io *.jquery.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com https://sogecommerce.societegenerale.eu/vads-payment/ https://api-sogecommerce.societegenerale.eu/api-payment/ https://api-sogecommerce.societegenerale.eu/static/ *.authorize.net *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.twitter.com *.wilsonart.com 'self' 'unsafe-inline'; frame-ancestors *.authorize.net 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com https://sogecommerce.societegenerale.eu/vads-payment/ https://api-sogecommerce.societegenerale.eu/static/ *.authorize.net c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * https://www.youtube.com http://www.sandbox.paypal.com *.twitter.com *.wilsonart.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net https://sogecommerce.societegenerale.eu/static/latest/images/type-carte/ https://api-sogecommerce.societegenerale.eu/static/ https://sogecommerce.societegenerale.eu/vads-payment/ www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com https://maps.gstatic.com/ *.cloudflare.com *.google.com *.twitter.com *.twimg.com *.google.co.in *.ytimg.com *.googleadservices.com *.fontawesome.com *.mastercard.com *.bushboard.co.uk *.cookiebot.com *.chatbeacon.io *.hotjar.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com https://api-sogecommerce.societegenerale.eu/api-payment/ https://api-sogecommerce.societegenerale.eu/static/ https://static-sogecommerce.societegenerale.eu/static/ *.fontawesome.com *.googleapis.com *.gstatic.com *.authorize.net js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://maps.googleapis.com *.cloudflare.com *.twitter.com *.google-analytics.com *.twimg.com *.trustedshops.com *.usercentrics.eu *.bing.com *.zopim.com *.zdassets.com *.bushboard.co.uk *.cookiebot.com *.chatbeacon.io *.jquery.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://api-sogecommerce.societegenerale.eu/static/ https://static-sogecommerce.societegenerale.eu/static/ *.fontawesome.com assets.braintreegateway.com *.cloudflare.com *.googleapis.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.bing.com *.bushboard.co.uk *.cookiebot.com *.chatbeacon.io *.jquery.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.zopim.com *.zopim.io *.wilsonart.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com https://sogecommerce.societegenerale.eu/vads-payment/ https://api-sogecommerce.societegenerale.eu/api-payment/ *.authorize.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com https://maps.googleapis.com www.google-analytics.com *.cloudflare.com *.twitter.com *.twimg.com *.zdassets.com *.zopim.com *.zopim.io wss://widget-mediator.zopim.com *.g.doubleclick.net *.bushboard.co.uk *.cookiebot.com *.chatbeacon.io *.jquery.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src https://sogecommerce.societegenerale.eu/vads-payment/ https://api-sogecommerce.societegenerale.eu/api-payment/ https://api-sogecommerce.societegenerale.eu/static/ 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self';font-src 'self' data: https://fonts.gstatic.com;connect-src 'self' https://brandportal.uponor.com https://*.usercentrics.eu https://*.google.com https://*.googleapis.com https://*.linkedin.com https://*.stackadapt.com https://*.doubleclick.net https://*.teads.tv https://*.clarity.ms https://*.google-analytics.com https://*.adobe.io https://*.hotjar.io wss://*.hotjar.com https://*.bing.com https://uponorna.my.site.com https://*.lumoa.me https://*.sharethis.com https://pixel-config.reddit.com https://www.redditstatic.com https://*.google.ee https://*.google.de https://*.google.cz https://*.google.se https://salesviewer.org https://*.google.fi https://bat.bing.net https://*.facebook.com https://*.google.is https://*.google.pl https://*.google.sk; frame-src https://*.youtube.com https://*.googletagmanager.com https://*.doubleclick.net https://*.force.com https://*.google.com https://*.usercentrics.eu https://*.teads.tv https://*.adobe.com https://*.tfaforms.net https://*.facebook.com https://*.bimsmith.com https://go.eu.uponor.com https://*.transistor.fm https://go.uponor.info https://youtube.com https://locator.maplet.com/ https://uponorna.my.site.com/; script-src 'self' 'nonce-R4+7mxig/zU8CmVoeyeC8phE31oX8BS8ggZ08AehnNo=' 'strict-dynamic'; img-src 'self' data: https://brandportal.uponor.com https://*.usercentrics.eu https://*.facebook.com https://*.linkedin.com https://*.teads.tv https://bat.bing.com https://maps.gstatic.com https://*.google.com https://*.doubleclick.net https://d2csxpduxe849s.cloudfront.net https://*.googletagmanager.com https://*.clarity.ms https://img.youtube.com https://*.sharethis.com https://*.uponor.com https://googleapis.com https://*.krxd.net https://*.google.lt https://*.google.hu https://*.google.dk https://alb.reddit.com https://*.google.ca https://*.google.ee https://*.google.de https://*.google.cz https://*.google.se https://*.google.co.uk https://*.google.pt https://*.globenewswire.com https://*.google.pl https://*.google.nl https://*.google.es https://*.google.ba https://cdn.midas-network.com https://*.google.fr https://*.google.si https://*.google.com.uy https://*.google.fi https://*.google.sk https://*.google.co.in https://*.google.no https://*.google.ro; style-src 'self' 'unsafe-inline' https://*.force.com https://*.usercentrics.eu https://*.stackadapt.com https://*.googleapis.com; object-src 'self' https://*.usercentrics.eu;form-action 'self' https://*.uponor.com https://*.tfaforms.net https://*.facebook.com; base-uri 'self'; 1 script-src 'nonce-+XplQquTvCHcXH1Jqhr16g==' 'strict-dynamic' 'unsafe-eval' 'unsafe-inline' https: 'report-sample'; base-uri 'none'; report-uri https://events.mercadolibre.com/csp/reports?identifier=w1qeU4XKVwGbQGBuEKyE3KhFBIpr5IZSIaRiTowMc8UG7kU18vRsmBTEKL2krAj23LIS&policy_id=26548&user_id=&request_id=716b248c-8f3d-4d9b-a10e-5cc2464f39fa; report-to csp-endpoint-wqeuxkvwgbqgbuekyekhfbiprizsiaritowmcugkuvrsmbteklkrajlis; object-src https://http2.mlstatic.com/ https://mlstaticquic-a.akamaihd.net/; frame-ancestors 'self' https://*.mercadolibre.cl:* https://*.mercadolibre.com:* https://*.mercadolibre.com.ve:* https://*.mercadolibre.com.ar:* https://*.mercadolivre.com.br:* https://*.mercadolibre.com.co:* https://*.mercadolibre.com.ec:* https://*.mercadolibre.com.mx:* https://*.mercadolibre.com.pe:* https://*.mercadolibre.com.uy:* https://*.mercadopago.cl:* https://*.mercadopago.com.ar:* https://*.mercadopago.com.br:* https://*.mercadopago.com.co:* https://*.mercadopago.com.mx:* https://*.mercadopago.com.pe:* https://*.mercadopago.com.uy:* https://*.mercadopago.com.ve:* https://*.mercadopago.com:* https://*.adminml.com:* https://*.mercadolibre.co.cr:* https://*.mercadolibre.com.pa:* https://*.mercadolibre.com.do:* https://*.mercadolibre.com.bo:* https://*.mercadolibre.com.py:* https://*.mercadolibre.com.gt:* https://*.mercadolibre.com.hn:* https://*.mercadolibre.com.ni:* https://*.mercadolibre.com.sv:* https://*.mercadopago.com.ec:* https://*.portalinmobiliario.com:* https://*.mercadolivre.com:* 1 default-src https://*.axa.ch https://*.axa-ch.intraxa; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://*.axa.ch https://www.googletagmanager.com https://cdn.cookielaw.org https://cdn.mouseflow.com https://maps.google.com https://maps.googleapis.com https://connect.facebook.net https://axa-winterthur.dimelochat.com https://pay.sandbox.datatrans.com https://pay.datatrans.com https://recaptcha.net https://www.google.com https://www.gstatic.com/recaptcha/ https://bat.bing.com https://snap.licdn.com https://www.gstatic.com https://*.teads.tv https://*.survalyzer.swiss; style-src 'self' 'unsafe-inline' https://*.axa.ch https://fonts.googleapis.com https://www.googletagmanager.com https://*.survalyzer.swiss; img-src 'self' data: blob: https://*.axa.ch https://*.google.com https://*.google.ch https://maps.gstatic.com https://cdn.cookielaw.org https://stats.g.doubleclick.net https://googleads.g.doubleclick.net https://ad.doubleclick.net https://www.facebook.com https://www.googletagmanager.com https://i.ytimg.com https://px.ads.linkedin.com https://bat.bing.com https://d5cplpsrt2s33.cloudfront.net https://bat.bing.net https://maps.googleapis.com https://region1.google-analytics.com https://*.googlesyndication.com https://connect.facebook.net https://flagcdn.com https://px.ads.linkedin.com https://www.googleadservices.com https://www.gstatic.com https://*.teads.tv https://*.survalyzer.swiss; font-src 'self' data: https://*.axa.ch https://fonts.gstatic.com https://cdn.mouseflow.com https://assets.merci-app.com; connect-src 'self' https://*.axa.ch https://gtm.axa.ch https://sgtm.axa.ch https://region1.analytics.google.com https://www.google.com https://*.tt.omtrdc.net https://europe.directline.botframework.com https://digitalassistantbot-acc.azurewebsites.net https://cdn.cookielaw.org wss://europe.directline.botframework.com https://googleads.g.doubleclick.net https://maps.googleapis.com https://stats.g.doubleclick.net https://region1.google-analytics.com https://o2.mouseflow.com https://www.google.ch https://selfadvisory-acc.azurewebsites.net https://*.onetrust.com https://bat.bing.com https://bat.bing.net https://px.ads.linkedin.com https://*.service.signalr.net https://pagead2.googlesyndication.com https://*.in.applicationinsights.azure.com https://www.googleadservices.com https://www.google-analytics.com wss://*.service.signalr.net https://*.mouseflow.com https://api.trongrid.io https://digitalassistantbot.azurewebsites.net https://www.facebook.com https://*.teads.tv https://snap.licdn.com https://*.survalyzer.swiss; frame-src https://*.axa.ch https://td.doubleclick.net https://8141516.fls.doubleclick.net https://www.youtube.com https://pay.sandbox.datatrans.com https://pay.datatrans.com https://www.google.com/recaptcha/ https://recaptcha.google.com/recaptcha/ https://recaptcha.net https://www.googletagmanager.com https://*.survalyzer.swiss; block-all-mixed-content ; report-uri https://www.acc.axa.ch/servlets/external/csp-reports.csp 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.beaconforms.com *.beaconproducts.co.uk *.bootstrapcdn.com *.calendly.com calendly.com *.cloudflare.com *.doubleclick.net *.facebook.net *.fontawesome.com *.google-analytics.com *.google.com *.googleadservices.com *.googleapis.com *.googletagmanager.com *.gravatar.com *.gstatic.com *.myfonts.net *.victimsupport.org.uk *.w.org *.wpdownloadmanager.com *.yoast.com js.stripe.com yoast.com *.youtube.com cdn-cookieyes.com s.ytimg.com; style-src 'self' 'unsafe-inline' *.fontawesome.com *.googleapis.com *.gstatic.com hello.myfonts.net stackpath.bootstrapcdn.com static.userback.io; img-src 'self' data: *.beaconforms.com *.beaconproducts.co.uk *.bootstrapcdn.com *.calendly.com *.cloudflare.com *.doubleclick.net *.facebook.net *.fontawesome.com *.google-analytics.com *.google.com *.google.ro *.google.co.uk *.googleadservices.com *.googleapis.com *.googletagmanager.com *.gravatar.com *.gstatic.com *.myfonts.net *.victimsupport.org.uk *.w.org *.wpdownloadmanager.com *.yoast.com *.youtube.com cdn-cookieyes.com s.ytimg.com www.facebook.com; font-src 'self' data: *.fontawesome.com *.googleapis.com *.gstatic.com static.userback.io; connect-src 'self' *.beaconforms.com *.beaconproducts.co.uk *.bootstrapcdn.com *.calendly.com *.cloudflare.com *.doubleclick.net *.facebook.net *.fontawesome.com *.google-analytics.com *.google.com *.google.co.uk *.googleadservices.com *.googleapis.com *.googletagmanager.com *.gravatar.com *.gstatic.com *.myfonts.net *.pagead2.googlesyndication.com *.victimsupport.org.uk *.w.org *.wpdownloadmanager.com *.yoast.com *.youtube.com *.browser-intake-datadoghq.com *.browser-intake-datadoghq.eu api.stripe.com api.userback.io cdn-cookieyes.com directory.cookieyes.com graph.facebook.com log.cookieyes.com static.userback.io www.facebook.com; frame-src 'self' *.beaconforms.com *.beaconproducts.co.uk *.bootstrapcdn.com *.calendly.com *.cloudflare.com *.doubleclick.net *.facebook.net *.fontawesome.com *.google-analytics.com *.google.com *.googleadservices.com *.googleapis.com *.googletagmanager.com *.gravatar.com *.gstatic.com *.myfonts.net *.victimsupport.org.uk *.w.org *.wpdownloadmanager.com *.yoast.com *.youtube.com calendly.com cdn-cookieyes.com js.stripe.com s.ytimg.com static.userback.io yoast.com; report-uri /csp-report; report-to csp-endpoint; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.google.com www.google-analytics.com www.googleadservices.com *.googleapis.com map.googleapis.com maps.googleapis.com *.googletagmanager.com *.google.com.ua *.google.ca *.google.co.in *.adobe.com *.adobedtm.com *.crazyegg.com *.licdn.com *.facebook.net *.facebook.com *.zoominfo.com *.adsrvr.org *.cloudfront.net js.authorize.net *.authorize.net 'self' * 'self' data: data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google-analytics.com www.googleadservices.com *.googleapis.com map.googleapis.com maps.googleapis.com *.googletagmanager.com *.google.com.ua *.google.ca *.google.co.in *.adobedtm.com *.crazyegg.com *.licdn.com *.facebook.net *.facebook.com *.zoominfo.com *.adsrvr.org *.doubleclick.net *.hubspot.com *.cloudfront.net js.authorize.net *.authorize.net *.4over.com 'self' 'self' 'unsafe-inline'; img-src *.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.google.com *.googleapis.com map.googleapis.com maps.googleapis.com *.googletagmanager.com *.google.com.ua *.google.ca *.google.co.in *.crazyegg.com *.licdn.com *.facebook.net *.facebook.com *.zoominfo.com *.adsrvr.org *.cloudfront.net js.authorize.net *.authorize.net 'self' * *.hsforms.net *.hsforms.com 'self' data: data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.googleapis.com map.googleapis.com maps.googleapis.com *.googletagmanager.com *.google.com.ua *.google.ca *.google.co.in *.crazyegg.com *.licdn.com *.facebook.net *.facebook.com *.zoominfo.com *.clickagy.com *.adsrvr.org *.hs-scripts.com *.hsleadflows.net *.hs-banner.com *.hsadspixel.net *.hs-analytics.net *.usemessages.com *.hubspotfeedback.com *.cloudfront.net js.authorize.net *.authorize.net *.4over.com 'self' *.hsforms.net *.hsforms.com *.gstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.google.com www.google-analytics.com www.googleadservices.com *.googleapis.com map.googleapis.com maps.googleapis.com *.googletagmanager.com *.google.com.ua *.google.ca *.google.co.in *.adobedtm.com *.crazyegg.com *.licdn.com *.facebook.net *.facebook.com *.zoominfo.com *.adsrvr.org *.cloudfront.net js.authorize.net *.authorize.net 'self' * *.gstatic.com 'self' 'unsafe-inline' 'unsafe-eval' 'strict-dynamic'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.google.com www.google-analytics.com www.googleadservices.com *.googleapis.com map.googleapis.com maps.googleapis.com *.googletagmanager.com *.google.com.ua *.google.ca *.google.co.in *.adobedtm.com *.crazyegg.com *.licdn.com *.facebook.net *.facebook.com *.zoominfo.com *.adsrvr.org *.cloudfront.net js.authorize.net *.authorize.net 'self' * 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.google-analytics.com *.googleapis.com map.googleapis.com maps.googleapis.com *.googletagmanager.com *.google.com.ua *.google.ca *.google.co.in *.adobe.com *.adobedtm.com *.crazyegg.com *.licdn.com *.facebook.net *.facebook.com *.zoominfo.com *.clickagy.com *.adsrvr.org *.linkedin.com *.hubspot.com *.hubapi.com *.trustpilot.com *.cloudfront.net js.authorize.net *.authorize.net *.4over.com 'self' t.elasticsuite.io *.hsforms.net *.hsforms.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com fonts.googleapis.com *.slant.co *.userway.org eadn-wc05-14712294.nxedge.io *.fontawesome.com *.klevu.com *.ksearchnet.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com https://plumrocket.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com https://static.addtoany.com/ *.instagram.com *.weltpixel.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * https://td.doubleclick.net widget.usersnap.com *.googletagmanager.com *.doubleclick.net https://plumrocket.com landofcoder.com *.google.com/ *.wesupply.xyz https://wesupplylabs.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.cdninstagram.com maps.googleapis.com maps.gstatic.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.agkn.com *.doubleclick.net *.facebook.com *.google.com *.nexcesscdn.net *.pricespider.com *.sitescout.com *.userway.org *.pixel.ad eadn-wc05-14712294.nxedge.io *.reddit.com *.google-analytics.com *.googletagmanager.com *.klevu.com *.ksearchnet.com https://firebasestorage.googleapis.com https://www.magezon.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://static.addtoany.com/ *.instagram.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com chimpstatic.com downloads.mailchimp.com *.list-manage.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.addthis.com *.crazyegg.com *.doubleclick.net *.elfsight.com *.facebook.net *.google-analytics.com *.googletagmanager.com *.klevu.com *.mapbox.com *.noibu.com *.pricespider.com *.userway.org d31qbv1cthcecs.cloudfront.net *.krxd.net *.pixel.ad *.sitescout.com *.owneriq.net eadn-wc05-14712294.nxedge.io widget.usersnap.com resources.usersnap.com *.googleadservices.com *.redditstatic.com *.reddit.com *.tiktok.com unpkg.com https://browser.sentry-cdn.com js.klevu.com *.ksearchnet.com https://ajax.cloudflare.com *.kaptcha.com landofcoder.com *.avada.io *.google.com/ *.cloudflare.com https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com downloads.mailchimp.com assets.braintreegateway.com *.mapbox.com *.pricespider.com *.userway.org eadn-wc05-14712294.nxedge.io *.tagmanager.google.com *.googletagmanager.com *.fontawesome.com *.klevu.com *.ksearchnet.com https://fonts.bunny.net https://js.klevu.com 'self' 'unsafe-inline'; object-src landofcoder.com 'self' 'unsafe-inline'; media-src *.adobe.com *.cdninstagram.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://stats.addtoany.com/menu api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.addthis.com *.crazyegg.com *.doubleclick.net *.facebook.com *.google-analytics.com *.googleapis.com *.mapbox.com *.noibu.com wss://input.noibu.com *.pricespider.com *.userway.org *.pixel.ad *.agkn.com *.sitescout.com *.owneriq.net *.elfsight.com eadn-wc05-14712294.nxedge.io widget.usersnap.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.run.app https://*.ingest.sentry.io *.klevu.com *.ksearchnet.com *.kaptcha.com landofcoder.com https://get.geojs.io *.avada.io 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://86c8b4f9-cefc-4184-9926-360586b833fe.sansec.watch/; report-to report-endpoint; 1 frame-src 'self' https://www.youtube.com https://player.vimeo.com https://www.googletagmanager.com; 1 default-src 'self'; base-uri 'self'; img-src 'self' data: https:; font-src 'self' data: https://fonts.gstatic.com; media-src 'self' https:; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://ista.piwik.pro https://*.usercentrics.eu https://www.youtube.com https://maps.googleapis.com https://*.g.doubleclick.net https://*.google-analytics.com https://*.googlesyndication.com https://*.googleapis.com https://tracking.ista.com https://www.googletagmanager.com https://www.clickcease.com https://www.googleoptimize.com https://*.hotjar.com https://siteintercept.qualtrics.com https://*.siteintercept.qualtrics.com https://www.facebook.com https://connect.facebook.net https://*.twitter.com 'report-sample'; script-src-elem 'self' 'unsafe-inline' 'unsafe-eval' https: blob: 'report-sample'; style-src 'self' 'unsafe-inline' https://*.usercentrics.eu https://fonts.googleapis.com 'report-sample'; style-src-elem 'self' 'unsafe-inline' https://fonts.gstatic.com https://fonts.googleapis.com https://www.googletagmanager.com/debug/badge.css 'report-sample'; worker-src 'self' 'unsafe-inline' 'unsafe-eval' blob: 'report-sample'; object-src 'none'; connect-src 'self' https://tracking.ista.com https://ista.piwik.pro https://*.usercentrics.eu https://fonts.googleapis.com *.google.com https://*.googleapis.com https://*.gstatic.com blob: data: https://*.google.com https://*.google.de https://*.g.doubleclick.net https://*.google-analytics.com https://*.googlesyndication.com https://siteintercept.qualtrics.com https://*.hotjar.com https://*.hotjar.io wss://*.hotjar.com; frame-src 'self' https://*.usercentrics.eu *.youtube-nocookie.com *.youtube.com *.vimeo.com *.google.com https://*.doubleclick.net https://*.g.doubleclick.net https://*.googlesyndication.com https://tracking.ista.com https://www.googletagmanager.com https://www.facebook.com https://*.twitter.com; frame-ancestors 'self'; report-uri https://www.ista.com/corporate/@http-reporting?csp=report&requestTime=1770381013420108&requestHash=c3d262c2d24233c75074f2195ae5e91821d2a551 1 default-src 'self' 'unsafe-inline' *.gardners.com; script-src 'report-sample' 'self' 'unsafe-eval' 'unsafe-inline' *.gardners.com *.braintreegateway.com *.cardinalcommerce.com *.gardners.com *.gardners.com/scripts/jquery-3.7.1.min.js *.google-analytics.com *.googletagmanager.com api.os.uk api.whichosmap.co.uk assets.braintreegateway.com code.jquery.com/jquery-migrate-3.5.2.min.js js.braintreegateway.com maps-api-ssl.google.com songbird.cardinalcommerce.com whichosmap.co.uk www.google.com www.gstatic.com www.gstatic.com/recaptcha/releases/p09oe8YIFfKgcnqQ9m9k4aiB/recaptcha__en.js; script-src-elem 'report-sample' 'self' 'unsafe-eval' 'unsafe-inline' *.gardners.com/scripts *.gardners.com/scripts/jquery-3.7.1.min.js *.googletagmanager.com *.paypal.com api.whichosmap.co.uk assets.braintreegateway.com code.jquery.com/jquery-migrate-3.5.2.min.js js.braintreegateway.com maps-api-ssl.google.com songbird.cardinalcommerce.com whichosmap.co.uk www.google-analytics.com www.google.com/recaptcha/api.js www.gstatic.com/recaptcha; style-src 'report-sample' 'self' 'unsafe-inline' *.gardners.com *.braintreegateway.com *.cardinalcommerce.com *.googleapis.com api.os.uk api.whichosmap.co.uk api.whichosmap.co.uk assets.braintreegateway.com stackpath.bootstrapcdn.com whichosmap.co.uk; style-src-elem 'report-sample' 'self' 'unsafe-inline' *.braintreegateway.com *.cardinalcommerce.com *.googleapis.com api.os.uk api.whichosmap.co.uk api.whichosmap.co.uk stackpath.bootstrapcdn.com whichosmap.co.uk; style-src-attr 'report-sample' 'self' 'unsafe-inline'; object-src 'none'; base-uri 'self'; connect-src 'self' 'unsafe-eval' 'unsafe-inline' data: *.gardners.com *.braintree-api.com *.braintreegateway.com *.cardinalcommerce.com *.google-analytics.com api.braintreegateway.com api2.smartrecruitonline.com client-analytics.braintreegateway.com maps.googleapis.com translate.googleapis.com; font-src 'report-sample' 'self' 'unsafe-inline' data: *.braintreegateway.com *.cardinalcommerce.com *.googleapis.com api.os.uk api.whichosmap.co.uk fonts.gstatic.com stackpath.bootstrapcdn.com; frame-src 'report-sample' 'self' *.cardinalcommerce.com *.paypal.com api.whichosmap.co.uk assets.braintreegateway.com whichosmap.co.uk www.google.com www.youtube.com; img-src 'report-sample' 'self' blob: data: data: https: *.braintreegateway.com *.cardinalcommerce.com *.google-analytics.com *.paypal.com *.youtube.com/ api.os.uk api.whichosmap.co.uk assets.braintreegateway.com jackets.dmmserver.com maps-api-ssl.google.com maps.gstatic.com www.googletagmanager.com; manifest-src 'self'; media-src 'self'; worker-src 'none'; report-uri https://67917890e3f085153460661d.endpoint.csper.io?v=4; 1 child-src 'self' https://*.qualified.com; default-src 'self'; frame-src 'self' https://9628652.fls.doubleclick.net https://td.doubleclick.net https://js.driftt.com https://*.qualified.com https://a8447815042.cdn-pci.optimizely.com https://ct.pinterest.com https://tealium-f.squarecdn.com; worker-src 'self' blob:; connect-src 'self' https://assets.ctfassets.net https://api.broadway.squareup.com https://campaign-hub-production-f.squarecdn.com https://api.squareup.com/v1/cdp/batch https://api.squarestagingexternal.com/v1/cdp/batch https://api.squarestagingexternal.com https://api.squareup.com https://api.squareupstaging.com *.contentsquare.net https://capi.squareup.com https://browser-intake-datadoghq.com https://*.browser-intake-datadoghq.com https://stats.g.doubleclick.net https://facebook.com https://www.facebook.com https://googleads.g.doubleclick.net http://www.google-analytics.com https://www.google-analytics.com https://google.com https://www.google.com https://us-central1-sq-sgtm-prod.cloudfunctions.net https://www.googletagmanager.com http://images.ctfassets.net https://images.ctfassets.net http://424-iab-218.mktoresp.com https://424-iab-218.mktoresp.com https://xms2-marketo.beta.stage.sqprod.co https://424-iab-218.mktoutil.com https://cdn.cookielaw.org https://geolocation.onetrust.com https://privacyportal.onetrust.com https://logx.optimizely.com https://ct.pinterest.com https://conversions-config.reddit.com https://pixel-config.reddit.com https://www.redditstatic.com *.ingest.us.sentry.io *.6sc.co https://api.sprig.com https://squareupstaging.com https://visitor-scoring-new.marketlinc.com https://api.chilipiper.com https://squareinc-sandbox.chilipiper.com https://squareinc.chilipiper.com https://www.workwithsquare.com wss://*.qualified.com https://*.qualified.com https://pw-renderer-production-c.squarecdn.com localhost:*; font-src 'self' https://cash-f.squarecdn.com https://square-fonts-production-f.squarecdn.com; img-src 'self' data: blob: https://ib.adnxs.com https://assets.ctfassets.net https://cdn.blisspointmedia.com https://campaign-hub-production-f.squarecdn.com *.contentsquare.net https://ad.doubleclick.net https://facebook.com https://www.facebook.com https://google.com https://www.google.com https://adservice.google.com https://googleads.g.doubleclick.net http://www.google-analytics.com https://www.google-analytics.com https://*.g.doubleclick.net https://www.googletagmanager.com http://images.ctfassets.net https://images.ctfassets.net https://px.ads.linkedin.com https://cdn.cookielaw.org https://pixel.pointmediatracker.com https://alb.reddit.com *.6sc.co https://api.squareup.com https://api.squareupstaging.com https://insight.adsrvr.org https://match.adsrvr.org https://*.qualified.com https://pw-renderer-production-c.squarecdn.com; manifest-src 'self' https://pw-renderer-production-c.squarecdn.com; media-src 'self' mediastream: https://assets.ctfassets.net https://js.driftt.com http://videos.ctfassets.net https://videos.ctfassets.net https://*.qualified.com; script-src 'self' *.contentsquare.net https://www.datadoghq-browser-agent.com https://js.driftt.com https://*.qualified.com https://connect.facebook.net https://www.googleadservices.com https://googleads.g.doubleclick.net http://www.google-analytics.com https://www.google-analytics.com https://www.googletagmanager.com https://campaign-hub-production-f.squarecdn.com https://lift-ai-js.marketlinc.com https://martech-development-c.squarecdn.com https://martech-production-c.squarecdn.com https://martech-staging-c.squarecdn.com http://munchkin.marketo.net https://munchkin.marketo.net https://cdn.cookielaw.org https://a8447815042.cdn-pci.optimizely.com https://s.pinimg.com https://ct.pinterest.com https://pw-renderer-production-c.squarecdn.com https://pw-renderer-staging-c.squarecdn.com https://pwt-production-c.squarecdn.com https://pwt-staging-c.squarecdn.com https://sales-bridge-production-c.squarecdn.com https://sales-bridge-staging-c.squarecdn.com https://squareinc-sandbox.chilipiper.com https://squareinc.chilipiper.com https://www.workwithsquare.com https://www.redditstatic.com *.6sc.co https://cdn.sprig.com https://xms-production-f.squarecdn.com https://www.youtube.com https://pw-renderer-production-c.squarecdn.com 'nonce-Bc7htCAt2IsLMXbligJG4A=='; style-src 'self' https://square-fonts-production-f.squarecdn.com https://sales-bridge-production-c.squarecdn.com https://sales-bridge-staging-c.squarecdn.com 'unsafe-inline' https://*.qualified.com https://pw-renderer-production-c.squarecdn.com; frame-ancestors 'self' https://app.contentful.com; report-uri https://browser-intake-datadoghq.com/api/v2/logs?dd-api-key=pubd9af00759e65a48ba7ee3ff1dfa4260b&dd-evp-origin=content-security-policy&ddsource=csp-report; report-to browser-intake-datadoghq 1 default-src 'self' *.google.com *.nr-data.net; script-src-elem 'self' 'unsafe-inline' 'unsafe-eval' https://*.pendo.io https://*.jquery.com https://*.google.com https://*.gstatic.com https://*.storage.googleapis.com https://js-agent.newrelic.com *.newrelic.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://*.googleapis.com https://*.gstatic.com *.google.com *.googleusercontent.com blob: *.newrelic.com; script-src-elem 'self' https://*.pendo.io *.newrelic.com *.googleapis.com; img-src 'self' https://*.pendo.io https://myhealthrecord.com:9999 https://*.myhealthrecord.com:9999 https://*.greenwayhealth.com:9999 https://*.googleapis.com https://*.gstatic.com *.google.com *.googleusercontent.com blob data:; font-src 'self' https://fonts.gstatic.com https://*.greenwayhealth.com https://*.login.greenwayhealth.com https://*.authstagingpoc.aws.greenwayhealth.com https://*.gisdev.aws.greenwayhealth.com data:; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com *.googleapis.com; style-src-elem 'self' 'unsafe-inline' https://*.storage.googleapis.com https://*.googleapis.com https://myhealthrecord.com:9999 https://*.myhealthrecord.com:9999 https://*.greenwayhealth.com:9999 https://pendo-static-4979136297566208.storage.googleapis.com *.googleapis.com https://*.pendo.io; style-src-elem 'self' *.googleapis.com https://pendo-static-4979136297566208.storage.googleapis.com https://*.pendo.io; connect-src 'self' https://*.pendo.io https://*.greenwayhealth.com:9004 https://*.myhealthrecord.com https://bam.nr-data.net https://bam-cell.nr-data.net *.nr-data.net https://phprod-patient-specific-documents.s3.amazonaws.com *.googleapis.com https://pendo-static-4979136297566208.storage.googleapis.com; frame-src 'self' https://*.instamed.com https://*.aws.greenwayhealth.com https://*.google.com https://*.pendo.io; report-uri https://api.myhealthrecord.com/PortalAPI/v1/CspReporting/LogCspReport 1 report-uri https://csp.withgoogle.com/csp/youtube_main/strict;base-uri 'self';object-src 'none';script-src 'report-sample' 'nonce-BpmEPPLzQfYSMdkG9yMGyw' 'unsafe-inline' 'strict-dynamic' https: http: 'unsafe-eval' 1 report-to slardar-endpoint; report-uri https://mon.zijieapi.com/monitor_browser/collect/batch/security/?bid=wukong_home_page; script-src 'self' 'unsafe-inline' 'unsafe-eval' 'wasm-unsafe-eval' 'report-sample' data: blob: 'nonce-2fa277cf00f4e81378b8915da3ccccb5-argus' 'strict-dynamic' https:; 1 default-src 'self' 'unsafe-inline' 'unsafe-eval'; report-uri https://csp-reporting.cloudflare.com/cdn-cgi/script_monitor/report?m=eOGVhRt4lon7VlV_LeZ3Zt7PVq9r53k9CGV6GYLDuLo-1770433094-1.0.1.1-NVM6rwLb8pLoDb24bbcDQUxvnErWisVq80lkZ_tHynPSUypBlETvu0cEIyH6057CoQIQ684AxsKxyVMcMCC3qkUzGM9eQJ2o1lH4imaYWcxGHzdDbvJpgc_YYm4uzT9rhQUH05Pa40d4xG2aCqvROtqrNvpbgDa3w28BogfQih5xrs13f5AW7V_8PtoVcRTYjHKDaCXVfqs.45C4oe_9dg; report-to cf-kjlmkootvrsyoxpz 1 default-src 'self'; script-src 'self' 'report-sample' 'strict-dynamic' https://ajax.googleapis.com/ https://api.tiles.mapbox.com/ https://cdn.nolt.io/ https://cdn.statuspage.io/ https://cdn.tiny.cloud/ https://cdnjs.cloudflare.com/ https://code.jquery.com/ https://j1h014tryv29.statuspage.io/ https://static.zdassets.com/ https://www.googletagmanager.com/ 'nonce-YVlhcTZYR3EwdmItUkpxZ2tqLVZHd0FBQUFB'; object-src 'none'; style-src 'self' 'report-sample' 'strict-dynamic' https://api.tiles.mapbox.com https://cdnjs.cloudflare.com https://fonts.googleapis.com 'nonce-YVlhcTZYR3EwdmItUkpxZ2tqLVZHd0FBQUFB'; font-src 'self' https://fonts.gstatic.com; form-action 'self'; frame-ancestors 'none'; base-uri 'self'; img-src 'self' data: https://sp.tinymce.com https://api.tiles.mapbox.com; frame-src 'self' https://j1h014tryv29.statuspage.io; media-src 'self' https://static.zdassets.com; connect-src 'self' https://ekr.zdassets.com https://omnilert.zendesk.com wss://widget-mediator.zopim.com; report-uri https://afiwlxkn53.execute-api.us-east-1.amazonaws.com/latest/csp_reports; report-to https://afiwlxkn53.execute-api.us-east-1.amazonaws.com/latest/csp_reports; 1 object-src 'none'; script-src * 'unsafe-inline' 'unsafe-eval'; style-src * 'unsafe-inline'; worker-src 'self' blob:; base-uri 'self'; form-action *; frame-ancestors 'self' 1 report-uri https://logs-01.loggly.com/inputs/4e92d8a9-baa6-4559-82e2-05428d10fa7b/tag/csp; report-to default 1 default-src 'self' *.ponycanyon.co.jp; font-src 'self' *.ponycanyon.co.jp fonts.gstatic.com data:; form-action 'self' *.ponycanyon.co.jp; worker-src 'self' blob: *.ponycanyon.co.jp cdnjs.cloudflare.com; connect-src 'self' *.ponycanyon.co.jp *.google-analytics.com *.analytics.google.com *.googletagmanager.com *.g.doubleclick.net *.google.com www.google.co.jp *.clarity.ms; frame-src 'self' *.ponycanyon.co.jp www.youtube.com td.doubleclick.net www.googletagmanager.com open.spotify.com embed-cdn.spotifycdn.com; img-src *; media-src 'self' blob: *.ponycanyon.co.jp; script-src 'self' 'unsafe-inline' *.ponycanyon.co.jp ajax.aspnetcdn.com cdn.jsdelivr.net cdnjs.cloudflare.com *.googletagmanager.com *.google.com www.google-analytics.com ad.jp.ap.valuecommerce.com *.clarity.ms embed-cdn.spotifycdn.com; style-src 'self' 'unsafe-inline' *.ponycanyon.co.jp cdn.jsdelivr.net cdnjs.cloudflare.com fonts.googleapis.com tagmanager.google.com; report-uri https://csp-log.ponycanyon.co.jp/; 1 font-src 'self' fonts.googleapis.com fonts.gstatic.com fonts.soundestlink.com data:;style-src 'self' 'unsafe-inline' fonts.googleapis.com fonts.gstatic.com fonts.soundestlink.com assets.mxapis.com *.cloudfront.net www.gstatic.com;style-src-elem 'self' 'unsafe-inline' fonts.googleapis.com fonts.soundestlink.com www.gstatic.com assets.mxapis.com *.cloudfront.net;script-src 'self' 'unsafe-inline' 'unsafe-eval' *.googletagmanager.com *.cookiebot.com *.google-analytics.com *.googleapis.com *.google.com *.google.lt *.google.lv *.googleadservices.com *.googlesyndication.com *.facebook.net *.bing.com *.cloudflare.com *.hotjar.com *.cloudflare.com *.doubleclick.net static.cloudflareinsights.com *.clarity.ms *.nosto.com omnisnippet1.com *.rackcdn.com *.equalweb.com *.mxapis.com *.ladesk.com cdn.dot.vu tags.creativecdn.com analytics.tiktok.com chimpstatic.com *.mailchimp.com *.list-manage.com *.cloudfront.net static.cloudflareinsights.com *.adform.net *.googleapis.com;script-src-elem 'self' 'unsafe-inline' cdn.datatables.net static.cloudflareinsights.com *.clarity.ms *.googletagmanager.com *.cookiebot.com *.google-analytics.com *.googleapis.com *.google.com *.google.lt *.google.lv *.googleadservices.com *.googlesyndication.com *.facebook.net *.bing.com *.cloudflare.com *.cloudflare.com *.doubleclick.net www.youtube.com pagead2.googlesyndication.com *.nosto.com omnisnippet1.com *.rackcdn.com *.equalweb.com *.mxapis.com *.ladesk.com cdn.dot.vu tags.creativecdn.com analytics.tiktok.com chimpstatic.com *.mailchimp.com *.list-manage.com *.cloudfront.net static.cloudflareinsights.com *.adform.net;connect-src 'self' https://api.e-menessaptieka.lv *.nordcode.io *.google-analytics.com *.doubleclick.net *.google.com *.cookiebot.com *.bing.com *.googlesyndication.com *.clarity.ms *.facebook.com adservice.google.com graph.facebook.com www.googleadservices.com www.google.com www.google.lt www.google.lv googleadservices.com google.com google.lt google.lv pagead2.googlesyndication.com *.nosto.com *.sentry.io *.googleapis.com *.equalweb.com *.soundestlink.com *.dot.vu ams.creativecdn.com analytics.tiktok.com *.e-menessaptieka.lv *.moonmart.lt *.mxapis.com *.tiktokw.us;frame-src 'self' *.cookiebot.com *.doubleclick.net *.youtube.com accounts.google.com *.ladesk.com live.dot.vu ams.creativecdn.com cdn.mxapis.com;img-src 'self' data: https://api.e-menessaptieka.lv https://images.e-menessaptieka.lv *.klix.app *.cookiebot.com *.google-analytics.com *.doubleclick.net *.googlesyndication.com *.googletagmanager.com *.google.com *.google.lt *.google.lv *.cloudflare.com *.tawk.to tawk.link *.hotjar.com *.soundestlink.com *.googleapis.com *.gstatic.com *.facebook.com *.youtube.com *.doubleclick.net *.dmxleo.com *.hotjar.com *.bing.com *.adform.net *.criteo.com *.clarity.ms *.demdex.net x.bidswitch.net ib.adnxs.com rtb-csync.smartadserver.com sync-t1.taboola.com visitor.omnitagjs.com r.casalemedia.com ad.360yield.com matching.ivitrack.com contextual.media.net exchange.mediavine.com jadserve.postrelease.com sync.outbrain.com simage2.pubmatic.com pixel.rubiconproject.com match.sharethrough.com criteo-sync.teads.tv criteo-partners.tremorhub.com eb2.3lift.com ad.yieldlab.net sync-criteo.ads.yieldmo.com e1.emxdgt.com googleads.g.doubleclick.net omnisnippet1.com csm.fr3.eu.criteo.net id5-sync.com ade.googlesyndication.com *.nosto.com *.appspot.com serve.mxapis.com *.e-menessaptieka.lv *.moonmart.lt www.googleadservices.com *.creativecdn.com static.salidzini.lv ema.ladesk.com;default-src 'self' 'unsafe-inline' 'unsafe-eval' data: https://api.e-menessaptieka.lv https://images.e-menessaptieka.lv;report-uri https://api.e-menessaptieka.lv/csp/report 1 default-src 'self'; connect-src 'self' https://gvb-apim-service-prod2.azure-api.net https://gvb-app.matomo.cloud consentcdn.cookiebot.com https://dc.services.visualstudio.com/v2/track https://*.algolia.net https://*.algolianet.com https://*.algolia.io https://*.dynamics.com https://*.azureedge.net ; script-src 'strict-dynamic' 'nonce-L+7PyRYfzHtKVltD/rFjneiyAm62ihwK1jKtrKRdJiQ=' 'sha256-X9GtzORyUShRgrb5vBVwF3p8WtKom3jBuMyocEhfL3Q=' 'self' https://cdn.matomo.cloud https://gvb-app.matomo.cloud consent.cookiebot.com consentcdn.cookiebot.com https://*.dynamics.com https://*.azureedge.net; frame-src 'self' consentcdn.cookiebot.com https://*.tiqets.com; base-uri 'self'; block-all-mixed-content; font-src 'self' https: data:; img-src * 'self' data: https; object-src 'none'; script-src-attr 'none'; style-src 'self' https://gvb-apim-service-prod2.azure-api.net 'unsafe-inline'; 1 default-src 'none'; report-uri /next-external/log/csp/violations; report-to csp-violations; connect-src 'self' wss://www.nordnet.dk https://www.googletagmanager.com https://analytics.nordnet.dk https://cdn.prod.nntech.io https://files.nordnet.dk https://api.prod.nntech.io https://api.test.nntech.io https://experimentation.public.prod.nntech.io https://www.google.com https://storage.googleapis.com https://www.recaptcha.net https://nordnettest.boost.ai; font-src 'self' https://cdn.prod.nntech.io https://files.nordnet.dk; frame-src 'self' https://analytics.nordnet.dk https://10961666.fls.doubleclick.net https://www.youtube.com https://www.youtube-nocookie.com https://player.vimeo.com https://w.soundcloud.com https://embed.acast.com https://link.tink.com https://www.tv2.no https://checkout.trustly.com https://www.recaptcha.net https://www.google.com https://t.email.nordnet.dk https://dashboard.fundrella.com; img-src 'self' https://www.googletagmanager.com https://analytics.nordnet.dk https://cdn.prod.nntech.io https://files.nordnet.dk data: blob: https://cdn.tink.se https://images.ctfassets.net https://i.vimeocdn.com https://img.youtube.com https://www.recaptcha.net https://blog.nordnet.dk https://boost-files-general-eu-west-1-test.s3-eu-west-1.amazonaws.com/files/NORDNETTEST/d929a8d5-9d88-426e-b412-3ccf7923fac3; manifest-src 'self'; media-src https://cdn.prod.nntech.io https://files.nordnet.dk https://videos.ctfassets.net; object-src 'self'; script-src 'self' 'nonce-468a9917-1847-474b-a16c-20c6815a81ab' https://analytics.nordnet.dk https://cdn.prod.nntech.io https://files.nordnet.dk https://www.recaptcha.net https://nordnettest.boost.ai https://www.google.com; script-src-attr 'none'; style-src 'unsafe-inline' 'self' https://cdn.prod.nntech.io https://files.nordnet.dk; worker-src 'none'; base-uri 'none'; form-action 'self' https://pvu.nets.no https://pvu.avtalegiro.no https://online.alandsbanken.fi https://verkkopankki.danskebank.fi https://verkkomaksu.handelsbanken.fi https://epmt.nordea.fi https://identify.nordea.com https://verkkomaksu.poppankki.fi https://verkkomaksu.saastopankki.fi https://online.s-pankki.fi https://auth.aktia.fi https://kirjaudu.aktia.fi https://ebank.aktia.fi; frame-ancestors 'self' https://app.contentful.com; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.bootstrapcdn.com *.yotpo.com *.userway.org *.klarnacdn.net *.fontawesome.com *.googleapis.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com *.wesupply.xyz https://wesupplylabs.com *.weltpixel.com *.klarna.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.googletagmanager.com *.doubleclick.net *.typeform.com *.yotpo.com https://*.online-metrix.net https://imgs.signifyd.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net https://*.scalebus.com https://scalebus.com *.userway.org *.listrakbi.com magefan.com cm.magefan.com *.klarna.com *.klarnaevt.com *.klarnacdn.net *.disqus.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.facebook.com *.reddit.com *.ads-twitter.com t.co *.twitter.com *.bing.com *.bing.net *.klaviyo.com *.pinterest.com *.pinimg.com *.clarity.ms *.google-analytics.com *.googletagmanager.com *.doubleclick.net *.google.com *.yotpo.com https://imgs.signifyd.com https://*.online-metrix.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net amcglobal.sc.omtrdc.net *.adobe.io use.typekit.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.magento-ds.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.magento-datasolutions.com https://rum.hlx.page *.abtasty.com *.alby.com https://*.scalebus.com https://scalebus.com *.northbeam.io i.govmint.com *.userway.org *.yotpo.com *.cloudfront.net *.listrakbi.com *.gstatic.com *.cloudflare.com widget.freshworks.com m2epro.freshdesk.com *.klarna.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.disqus.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googletagmanager.com *.googleadservices.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.bing.com *.clarity.ms *.klaviyo.com *.pinterest.com *.pinimg.com unpkg.com *.doubleclick.net *.typeform.com https://cdn-scripts.signifyd.com https://imgs.signifyd.com https://h64.online-metrix.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com *.bootstrapcdn.com *.userway.org *.yotpo.com *.listrakbi.com widget.freshworks.com m2epro.freshdesk.com *.klarnacdn.net *.fontawesome.com assets.braintreegateway.com *.tagmanager.google.com *.googletagmanager.com *.typeform.com *.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.magento-datasolutions.com *.magento-ds.com *.abtasty.com api.experianaperture.io *.alby.com https://*.scalebus.com https://scalebus.com *.northbeam.io i.govmint.com *.userway.org *.listrakbi.com bam.nr-data.net *.launchdarkly.com widget.freshworks.com m2epro.freshdesk.com *.klarnaevt.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.klarna.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.google-analytics.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.pinterest.com *.pinimg.com *.doubleclick.net *.run.app *.typeform.com *.yotpo.com https://imgs.signifyd.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src bam.nr-data.net 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 frame-ancestors 'self'; report-uri https://www.cairnspost.com.au/csp-reports 1 default-src 'self'; base-uri 'self'; connect-src 'self' *.google-analytics.com *.analytics.google.com *.cloudflare.com *.eesa.lh; font-src use.fontawesome.com 'self'; frame-src www.youtube.com www.google.com; img-src 'self' *.google-analytics.com *.analytics.google.com *.googletagmanager.com; object-src 'none'; script-src 'self' www.googletagmanager.com *.cloudflare.com *.google.com 'strict-dynamic' 'unsafe-inline' 'nonce-HCQ8xFpoRw+l9KtBJKKaHw=='; style-src 'self' use.fontawesome.com *.cloudflare.com 'unsafe-inline' 'nonce-HCQ8xFpoRw+l9KtBJKKaHw=='; report-uri /csp/report 1 object-src 'none'; base-uri 'self'; script-src 'self' 'nonce-px8ENcWibY_r1xNCcTN-fg' 'unsafe-inline' 'unsafe-eval' https://*.msauth.net https://*.msftauth.net https://*.msftauthimages.net https://*.msauthimages.net https://*.msidentity.com https://*.microsoftonline-p.com https://*.microsoftazuread-sso.com https://*.azureedge.net https://*.outlook.com https://*.office.com https://*.office365.com https://*.microsoft.com https://*.bing.com 'report-sample'; report-uri https://csp.microsoft.com/report/ESTS-UX-All 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://use.typekit.net https://cdn.jsdelivr.net https://www.googletagmanager.com https://www.google-analytics.com https://b.6sc.co https://j.6sc.co https://ajax.googleapis.com https://js.navattic.com https://cdn.cookielaw.org https://static.ads-twitter.com https://unpkg.com https://js.hsforms.net https://js.hs-scripts.com https://js.hs-banner.com https://js.hs-analytics.net https://js.hsadspixel.net https://js.hubspot.com https://snap.licdn.com https://www.google.com https://www.gstatic.com https://googleads.g.doubleclick.net https://boards.greenhouse.io https://fireblocks.chilipiper.com https://tracking.g2crowd.com https://cdnjs.cloudflare.com https://fast.wistia.com https://fast.wistia.net https://browser.sentry-cdn.com https://d3js.org; script-src-elem 'self' 'unsafe-inline' 'unsafe-eval' https://use.typekit.net https://cdn.jsdelivr.net https://www.googletagmanager.com https://www.google-analytics.com https://b.6sc.co https://j.6sc.co https://ajax.googleapis.com https://js.navattic.com https://cdn.cookielaw.org https://static.ads-twitter.com https://unpkg.com https://js.hsforms.net https://js.hs-scripts.com https://js.hs-banner.com https://js.hs-analytics.net https://js.hsadspixel.net https://js.hubspot.com https://snap.licdn.com https://www.google.com https://www.gstatic.com https://googleads.g.doubleclick.net https://boards.greenhouse.io https://fireblocks.chilipiper.com https://tracking.g2crowd.com https://cdnjs.cloudflare.com https://fast.wistia.com https://fast.wistia.net https://browser.sentry-cdn.com https://d3js.org; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://use.typekit.net https://p.typekit.net https://cdn.cookielaw.org https://code.jquery.com; img-src 'self' data: https: https://www.google-analytics.com; font-src 'self' data: https://fonts.gstatic.com https://use.typekit.net https://p.typekit.net https://fast.wistia.com https://fast.wistia.net; connect-src 'self' https://www.google-analytics.com https://b.6sc.co https://c.6sc.co https://ipv6.6sc.co https://analytics.google.com https://www.google.com https://cdn.cookielaw.org https://forms.hsforms.com https://api.hubapi.com https://cta-service-cms2.hubspot.com https://px.ads.linkedin.com https://tracking-api.g2.com https://stats.g.doubleclick.net https://fast.wistia.com https://fast.wistia.net https://embed-cloudfront.wistia.com https://distillery.wistia.com https://pipedream.wistia.com https://cdn.jsdelivr.net wss:; frame-src 'self' https://www.youtube.com https://fast.wistia.net https://forms.hsforms.com https://app.hubspot.com https://www.googletagmanager.com https://td.doubleclick.net https://fireblocks.chilipiper.com https://www.google.com https://capture.navattic.com https://job-boards.greenhouse.io https://lottie.host; media-src 'self' blob:; object-src 'none'; base-uri 'self'; frame-ancestors 'self'; form-action 'self' https://forms.hsforms.com; upgrade-insecure-requests; 1 script-src *.hsadspixel.net *.hs-analytics.net js.hscta.net *.hubspot.com static.hsappstatic.net *.usemessages.com *.hs-banner.com *.hubspot.net *.hscollectedforms.net *.hsleadflows.net *.hsforms.net *.hsforms.com *.hs-scripts.com *.hubspotfeedback.com feedback.hubapi.com *.googletagmanager.com *.hotjar.com 'unsafe-inline' *.mouseflow.com; img-src js.hscta.net no-cache.hubspot.com *.hubspot.com *.hubspot.net *.hsforms.net *.hsforms.com *.google-analytics.com *.googletagmanager.com *.hotjar.com *.mouseflow.com; connect-src *.hubapi.com js.hscta.net *.hubspot.com *.hs-banner.com *.hsforms.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com *.hotjar.com *.hotjar.io *.mouseflow.com; frame-src *.hubspot.com play.hubspotvideo.com *.hubspot.net *.hsforms.net *.mouseflow.com; style-src cdn2.hubspot.net *.harmonicinc.com; child-src *.hsforms.com *.mouseflow.com; font-src *.hotjar.com *.hotjar.io *.mouseflow.com; 1 object-src 'none'; base-uri 'self'; script-src 'self' 'nonce-zj_8SgzV1EdQR39mvXK0FQ' 'unsafe-inline' 'unsafe-eval' https://*.msauth.net https://*.msftauth.net https://*.msftauthimages.net https://*.msauthimages.net https://*.msidentity.com https://*.microsoftonline-p.com https://*.microsoftazuread-sso.com https://*.azureedge.net https://*.outlook.com https://*.office.com https://*.office365.com https://*.microsoft.com https://*.bing.com 'report-sample'; report-uri https://csp.microsoft.com/report/ESTS-UX-All 1 font-src *.fontawesome.com maxcdn.bootstrapcdn.com https://*.klarnacdn.net https://fonts.gstatic.com https://fonts.gstatic.com/s/lato/ data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * https://*.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.google.com *.klarna.com https://www.googletagmanager.com/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * https://*.avis-verifies.com https://*.criteo.com https://*.facebook.com https://widgets.rr.skeepers.io sandbox.sequracdn.com live.sequracdn.com sandbox.sequrapi.com live.sequrapi.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://images.unsplash.com *.klarna.com *.klarnaevt.com *.klarnacdn.net http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com https://*.quirumed.com https://www.quirumed.com https://*.onetrust.com https://*.google.es https://*.facebook.com https://*.media.net https://*.outbrain.com https://*.rubiconproject.com https://*.sharethrough.com https://*.smartadserver.com https://*.taboola.com https://*.teads.tv https://*.3lift.com https://*.adform.net https://*.omnitagjs.com https://*.casalemedia.com https://*.criteo.com https://www.sync-criteo.ads.yieldmo.com https://id5-sync.com https://www.id5-sync.com https://*.ivitrack.com https://*.mediavine.com https://*.pubmatic.com https://*.tremorhub.com https://*.yieldlab.net https://*.bidswitch.net https://*.doubleclick.net https://*.adnxs.net https://*.ib.adnxs.com https://www.ib.adnxs.com https://*.secure.adnxs.com https://secure.adnxs.com https://*.360yield.com https://*.krxd.net https://*.thebrighttag.com https://*.bing.com https://*.ups.analytics.yahoo.com https://www.ups.analytics.yahoo.com https://ib.adnxs.com https://jadserve.postrelease.com https://sync-criteo.ads.yieldmo.com https://e1.emxdgt.com https://sync.1rx.io https://sync.targeting.unrulymedia.com https://c.clarity.ms https://dev.visualwebsiteoptimizer.com https://*.visualwebsiteoptimizer.com https://*.segmentify.com https://cdn.segmentify.com https://*.sgmtfy.com https://aa.agkn.com sandbox.sequracdn.com live.sequracdn.com sandbox.sequrapi.com live.sequrapi.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com https://*.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com https://vimeo.com www.vimeo.com *.vimeocdn.com https://*.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.google.com/recaptcha/ www.gstatic.com/recaptcha/ https://maps.googleapis.com https://player.vimeo.com https://widgets.rr.skeepers.io/ https://api-product-reviews.rr.skeepers.io/ https://cl-ppr.rr.skeepers.io/ *.klarna.com *.klarnacdn.net http://www.googletagmanager.com/ https://www.googletagmanager.com/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://*.doofinder.com https://*.avis-verifies.com https://*.googlesyndication.com https://*.onetrust.com https://*.criteo.net https://*.criteo.com https://*.facebook.net https://*.googleoptimize.com https://*.datadome.co https://*.bing.com https://*.newrelic.com https://*.retailrocket.net https://*.nr-data.net https://*.quirumed.com https://*.bolt.com https://*.commerce-quick-checkout.com https://*.clarity.ms https://*.google.com https://*.googleadservices.com https://*.google-analytics.com https://*.googletagmanager.com https://*.paypal.com https://*.sandbox.paypal.com https://*.paypalobjects.com https://*.t.paypal.com https://*.s.ytimg.com https://live.sequracdn.com https://assets.adobedtm.com https://geostag.cardinalcommerce.com https://1eafstag.cardinalcommerce.com https://unpkg.com https://cdn.noibu.com https://*.klarnaservices.com https://*.klarna.com https://js.klarna.com https://*.segmentify.com https://cdn.segmentify.com https://*.sgmtfy.com https://*.sgmtfy.com/* https://cdn.sgmntfy.com https://*.cloudflare.com https://*.cloudflare.com/* https://cdnjs.cloudflare.com/* https://widgets.rr.skeepers.io https://client.rum.us-east-1.amazonaws.com sandbox.sequracdn.com live.sequracdn.com sandbox.sequrapi.com live.sequrapi.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.fontawesome.com maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com https://*.retailrocket.net https://*.klarnacdn.net https://*.cloudflare.com https://*.cloudflare.com/* https://cdnjs.cloudflare.com/* https://*.segmentify.com https://cdn.segmentify.com https://*.sgmtfy.com https://*.sgmtfy.com/* https://cdn.sgmntfy.com https://fonts.googleapis.com/* https://fonts.googleapis.com/css https://fonts.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://maps.googleapis.com https://player.vimeo.com https://widgets.rr.skeepers.io/ https://api-product-reviews.rr.skeepers.io/ https://cl-ppr.rr.skeepers.io/ *.klarnaevt.com *.klarnacdn.net *.klarna.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com https://*.doofinder.com https://*.avis-verifies.com https://*.googlesyndication.com https://*.onetrust.com https://*.google-analytics.com https://*.google.com https://*.doubleclick.net https://*.retailrocket.net https://*.nr-data.net https://*.datadome.co https://*.google.es https://www.google.es https://www.google.com https://*.bing.com https://*.newrelic.com https://*.cardinalcommerce.com https://*.paypal.com https://*.braintree-api.com https://*.client-analytics.sandbox.braintreegateway.com https://*.client-analytics.braintreegateway.com https://api.sandbox.braintreegateway.com https://api.braintreegateway.com https://t.clarity.ms https://input.noibu.com https://*.noibu.com https://cdn.noibu.com wss://input.noibu.com https://measurement-api.criteo.com https://dev.visualwebsiteoptimizer.com https://*.visualwebsiteoptimizer.com https://*.segmentify.com https://cdn.segmentify.com https://*.sgmtfy.com https://*.klarnaservices.com https://evt-eu.playground.klarnaservices.com https://widgets.rr.skeepers.io https://bat.bing.com https://api-product-reviews.cxr.skeepers.io sandbox.sequracdn.com live.sequracdn.com sandbox.sequrapi.com live.sequrapi.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'none'; report-uri /next-external/log/csp/violations; report-to csp-violations; connect-src 'self' wss://www.nordnet.no https://www.googletagmanager.com https://analytics.nordnet.no https://cdn.prod.nntech.io https://files.nordnet.no https://api.prod.nntech.io https://api.test.nntech.io https://experimentation.public.prod.nntech.io https://www.google.com https://storage.googleapis.com https://www.recaptcha.net https://nordnettest.boost.ai; font-src 'self' https://cdn.prod.nntech.io https://files.nordnet.no; frame-src 'self' https://analytics.nordnet.no https://10961666.fls.doubleclick.net https://www.youtube.com https://www.youtube-nocookie.com https://player.vimeo.com https://w.soundcloud.com https://embed.acast.com https://link.tink.com https://www.tv2.no https://checkout.trustly.com https://www.recaptcha.net https://www.google.com https://t.email.nordnet.no https://dashboard.fundrella.com; img-src 'self' https://www.googletagmanager.com https://analytics.nordnet.no https://cdn.prod.nntech.io https://files.nordnet.no data: blob: https://cdn.tink.se https://images.ctfassets.net https://i.vimeocdn.com https://img.youtube.com https://www.recaptcha.net https://blogg.nordnet.no https://boost-files-general-eu-west-1-test.s3-eu-west-1.amazonaws.com/files/NORDNETTEST/d929a8d5-9d88-426e-b412-3ccf7923fac3; manifest-src 'self'; media-src https://cdn.prod.nntech.io https://files.nordnet.no https://videos.ctfassets.net; object-src 'self'; script-src 'self' 'nonce-a7cc89e4-3571-4383-b980-8be70c0e7d34' https://analytics.nordnet.no https://cdn.prod.nntech.io https://files.nordnet.no https://www.recaptcha.net https://nordnettest.boost.ai https://www.google.com; script-src-attr 'none'; style-src 'unsafe-inline' 'self' https://cdn.prod.nntech.io https://files.nordnet.no; worker-src 'none'; base-uri 'none'; form-action 'self' https://pvu.nets.no https://pvu.avtalegiro.no https://online.alandsbanken.fi https://verkkopankki.danskebank.fi https://verkkomaksu.handelsbanken.fi https://epmt.nordea.fi https://identify.nordea.com https://verkkomaksu.poppankki.fi https://verkkomaksu.saastopankki.fi https://online.s-pankki.fi https://auth.aktia.fi https://kirjaudu.aktia.fi https://ebank.aktia.fi; frame-ancestors 'self' https://app.contentful.com; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com https://geowidget.easypack24.net https://secure.tpay.com https://secure.sandbox.tpay.com https://tpay.com https://fonts.gstatic.com https://cdn.thulium.com https://fonts.bunny.net maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com https://www.facebook.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com https://geowidget-app.inpost.pl/ https://secure.tpay.com https://secure.sandbox.tpay.com https://tpay.com *.addthis.com js.mollie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://images.unsplash.com data.imoje.pl *.disqus.com https://geowidget.easypack24.net *.easypack24.net *.inpost.pl *.openstreetmap.org https://secure.tpay.com https://secure.sandbox.tpay.com https://tpay.com https://cmp.uniconsent.com https://www.google.pl https://www.facebook.com/ https://data.imoje.pl https://imgsct.cookiebot.com https://www.google.nl https://maps.gstatic.com/ *.clarity.ms *.clarity.com https://maps.googleapis.com https://c.bing.com blob: https://cdn.thulium.com https://e24files.com https://firebasestorage.googleapis.com https://www.mollie.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://maps.googleapis.com https://cdn.jsdelivr.net/npm/@ryangjchandler/spruce@2.x.x/dist/spruce.umd.js paywall.imoje.pl sandbox.paywall.imoje.pl *.disqus.com https://geowidget.easypack24.net *.easypack24.net *.inpost.pl *.openstreetmap.org https://secure.tpay.com https://secure.sandbox.tpay.com https://tpay.com *.snrbox.com https://connect.facebook.net https://cmp.uniconsent.com https://consent.cookiebot.com https://consentcdn.cookiebot.com https://analytics.tiktok.com *.clarity.ms *.clarity.com https://unpkg.com https://cdn.thulium.com https://browser.sentry-cdn.com *.addthis.com https://z.moatads.com https://v1.addthisedge.com https://cdn.jsdelivr.net *.avada.io cdn.jsdelivr.net js.mollie.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com https://geowidget.easypack24.net https://geowidget.inpost.pl *.easypack24.net *.inpost.pl https://secure.tpay.com https://secure.sandbox.tpay.com https://tpay.com *.snrcdn.net https://fonts.googleapis.com https://cdn.jsdelivr.net https://fonts.bunny.net cdn.jsdelivr.net maxcdn.bootstrapcdn.com assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com https://geowidget.easypack24.net https://cdn.thulium.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net https://region1.analytics.google.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://maps.googleapis.com/ https://player.vimeo.com *.easypack24.net *.inpost.pl *.openstreetmap.org https://secure.tpay.com https://secure.sandbox.tpay.com https://tpay.com *.snrbox.com https://www.sentry.macopedia-dev.pl https://cmp.uniconsent.com https://region1.google-analytics.com https://stats.g.doubleclick.net https://www.google.pl https://www.google.com https://consent.cookiebot.com https://consentcdn.cookiebot.com https://pagead2.googlesyndication.com https://js-agent.newrelic.com https://googleads.g.doubleclick.net https://analytics.tiktok.com *.clarity.ms *.clarity.com https://cdn.thulium.com wss://chat-proxy-service.thulium.com https://*.ingest.sentry.io https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'none'; form-action 'none'; frame-ancestors 'none'; report-uri https://e8e515d2dcf3cd9f3b3646248ee07510.report-uri.com/r/t/csp/reportOnly; 1 default-src 'self'; script-src 'self' 'unsafe-inline' https://webalytix.th-nuernberg.de https://static.b-ite.com https://cs-assets.b-ite.com 'report-sample'; style-src-attr 'unsafe-inline' 'report-sample'; img-src 'self' https://webalytix.th-nuernberg.de data:; base-uri 'none'; frame-src https://webalytix.th-nuernberg.de https://virtuohm.ohmportal.de; connect-src 'self' https://webalytix.th-nuernberg.de https://jobs.b-ite.com; style-src 'self' 'unsafe-inline' data: 'report-sample'; object-src 'none'; font-src 'self' data:; report-uri https://www.th-nuernberg.de/@http-reporting?csp=report&requestTime=1770428800432704&requestHash=9881cec5717847c1035def1cfd3437880eec121a 1 default-src 'self'; connect-src 'self' https://t.segger.com/; font-src 'self' 'unsafe-inline' data: ; style-src 'self' 'unsafe-inline' data: ; img-src 'self' data: blob: https://t.segger.com/ https://kb.segger.com/ https://i.ytimg.com; script-src 'self' 'unsafe-inline' https://t.segger.com/; script-src-elem 'self' 'unsafe-inline' https://t.segger.com/ https://www.youtube.com/iframe_api; frame-src https://www.youtube-nocookie.com 'self'; object-src 'self' data: blob:; media-src 'self'; report-uri https://sentry.marketing-factory.de/api/23/security/?sentry_key=c95fa11bd7c34b6757a4f34eca12437f 1 font-src https://www.googletagmanager.com *.googleapis.com *.gstatic.com *.fontawesome.com https://cdnjs.cloudflare.com *.typekit.net *.yotpo.com dhv2ziothpgrr.cloudfront.net www-wp.silencercentral.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.authorize.net *.yotpo.com www-wp.silencercentral.com 'self' 'unsafe-inline'; frame-ancestors *.authorize.net www-wp.silencercentral.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com player.vimeo.com https://www.google.com/recaptcha/ *.certcapture.com https://elements.sandbox.fortis.tech https://elements.fortis.tech *.authorize.net *.yotpo.com www-wp.silencercentral.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.gstatic.com *.certcapture.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ magefan.com cm.magefan.com store.paradoxlabs.com maps.gstatic.com https://*.ipredictive.com https://www.googletagmanager.com *.gleamjs.io *.gleam.io *.yotpo.com dhv2ziothpgrr.cloudfront.net www-wp.silencercentral.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ tagmanager.google.com https://www.googletagmanager.com *.certcapture.com https://developer.adobe.com https://magento.com https://cdn.avmws.com/ http://cdn.avmws.com/ https://js.sandbox.fortis.tech https://js.fortis.tech https://elements.sandbox.fortis.tech https://elements.fortis.tech https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ code.jquery.com cdnjs.cloudflare.com *.authorize.net maps.googleapis.com https://js.ipredictive.com *.gleamjs.io *.gleam.io *.yotpo.com dhv2ziothpgrr.cloudfront.net *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com d18eg7dreypte5.cloudfront.net www-wp.silencercentral.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://www.googletagmanager.com tagmanager.google.com *.googleapis.com *.certcapture.com https://static.klaviyo.com cdnjs.cloudflare.com *.typekit.net *.yotpo.com dhv2ziothpgrr.cloudfront.net www-wp.silencercentral.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www-wp.silencercentral.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io https://www.google-analytics.com *.certcapture.com https://developer.adobe.com https://cdn.avmws.com/ http://cdn.avmws.com/ https://elements.sandbox.fortis.tech https://elements.fortis.tech https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.authorize.net maps.googleapis.com *.yotpo.com dhv2ziothpgrr.cloudfront.net *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com www-wp.silencercentral.com 'self' 'unsafe-inline'; child-src www-wp.silencercentral.com http: https: blob: 'self' 'unsafe-inline'; default-src www-wp.silencercentral.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://www.googletagmanager.com https://www.google-analytics.com https://cdn.u-srv.net https://connect.facebook.net https://static.zdassets.com https://js.zdassets.com https://bam.nr-data.net https://js-agent.newrelic.com https://gtm.uppababy.com https://cdn.cookielaw.org https://analytics.tiktok.com https://applepay.cdn-apple.com https://cdn.attn.tv https://ui.powerreviews.com https://googleads.g.doubleclick.net https://maps.googleapis.com https://maps.gstatic.com https://ekr.zdassets.com https://t.contentsquare.net https://vnuvb.uppababy.com blob:; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://static.zdassets.com https://ui.powerreviews.com https://p.typekit.net; img-src 'self' data: https://uppababy.com https://cdn.uppababy.com https://prod.uppababy.com https://back.prod.uppababy.com https://back.uppababy.com https://www.google-analytics.com https://analytics.google.com https://www.facebook.com https://static.zdassets.com https://cdn.u-srv.net https://bam.nr-data.net https://cdn.cookielaw.org https://gtm.uppababy.com https://analytics.tiktok.com https://cdn.attn.tv https://ui.powerreviews.com https://googleads.g.doubleclick.net https://maps.googleapis.com https://maps.gstatic.com https://ekr.zdassets.com https://t.contentsquare.net https://c.az.contentsquare.net https://www.google.com; font-src 'self' https://fonts.gstatic.com https://p.typekit.net https://ui.powerreviews.com https://use.typekit.net; connect-src 'self' https://back.uppababy.com https://back.prod.uppababy.com https://www.google-analytics.com https://analytics.google.com https://stats.g.doubleclick.net https://connect.facebook.net https://bam.nr-data.net https://js-agent.newrelic.com https://static.zdassets.com https://k-us1.az.contentsquare.net https://t.contentsquare.net https://c.az.contentsquare.net https://cdn.cookielaw.org https://events.attentivemobile.com https://vnuvb.uppababy.com https://uppababy-us.attn.tv https://uppababy1730824702.zendesk.com https://uppababy.zendesk.com https://ekr.zdassets.com https://analytics.tiktok.com https://cdn.attn.tv https://gtm.uppababy.com https://maps.googleapis.com https://maps.gstatic.com https://www.google.com https://ui.powerreviews.com wss://widget-mediator.zopim.com; frame-src https://www.youtube.com https://static.zdassets.com https://gtm.uppababy.com https://connect.facebook.net; media-src 'self' https://static.zdassets.com; worker-src 'self' blob:; object-src 'none'; base-uri 'self'; form-action 'self'; 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.cloudflare.com *.bing.com *.rfihub.net *.boomtrain.com *.cookielaw.org *.facebook.net *.doubleclick.net *.derbysoftsec.com *.rezync.com *.cdn.digitaloceanspaces.com *.azds.com *.sojern.com *.quantcount.com *.crazyegg.com *.quantserve.com *.cloudflareinsights.com *.stackadapt.com *.google-analytics.com *.googletagmanager.com *.tiqcdn.com *.stripe.com *.googleapis.com *.gstatic.com *.google.com *.callrail.com *.googleadservices.com *.yimg.com *.simpli.fi *.matomo.cloud plausible.io *.umami.is *.posthog.com *.threatspike.com *.qvdt3feo.com *.montage.com; script-src-elem 'self' 'unsafe-inline' *.cloudflare.com *.bing.com *.rfihub.net *.boomtrain.com *.cookielaw.org *.facebook.net *.doubleclick.net *.derbysoftsec.com *.rezync.com *.cdn.digitaloceanspaces.com *.azds.com *.sojern.com *.quantcount.com *.crazyegg.com *.quantserve.com *.cloudflareinsights.com *.stackadapt.com *.google-analytics.com *.googletagmanager.com *.tiqcdn.com *.stripe.com *.googleapis.com *.gstatic.com *.google.com *.callrail.com *.googleadservices.com *.yimg.com *.simpli.fi *.montage.com *.storage.googleapis.com plausible.io *.matomo.cloud *.sc-static.net *.posthog.com *.threatspike.com *.umami.is *.infird.com *.hotjar.com *.upsellit.com *.redditstatic.com blob:; connect-src 'self' *.azds.com *.boomtrain.com *.callrail.com *.cookielaw.org *.crazyegg.com *.doubleclick.net *.facebook.com *.g.doubleclick.net *.google-analytics.com google.com *.google.com.mx *.google.com *.google.de *.googleadservices.com *.googletagmanager.com *.googleapis.com *.google.co.uk *.onetrust.com *.sojern.com *.stackadapt.com *.tiqcdn.com *.myhotelshop.de *.awsapprunner.com *.run.app *.letsway.com *.bing.com *.bing.net *.googlesyndication.com *.matomo.cloud *.umami.dev *.yimg.com plausible.io *.pendry.com *.posthog.com *.yoast.com *.launchdarkly.com *.geoedge.com *.adsrvr.org *.yoast.com *.cloudfront.net *.adform.net *.adnxs.com *.tiktokw.us *.tiktok.com *.browsekeeper.com *.redditstatic.com *.reddit.com *.overbridgenet.com *.montage.com data:; frame-src 'self' *.doubleclick.net *.facebook.com *.googletagmanager.com *.google.com *.pcibooking.net *.rfihub.net *.rfihub.com *.sojern.com *.stripe.com *.azds.com *.zscalerthree.net *.truetour.app truetour.app visitingmedia.com *.vimeo.com *.formcrafts.com *.ibotta.com *.contextall.com *.canyonsdistrict.org *.ggusd.us *.menlosecurity.com *.zscaler.net *.snapchat.com *.montage.com blob:; style-src * 'unsafe-inline'; img-src * data: blob:; font-src * data:; media-src * 'self' data:; manifest-src * 'self'; worker-src 'self' blob:; child-src 'self' blob:; report-uri https://cfe87652b26de6b69f71ed43bef9cf37.report-uri.com/r/d/csp/reportOnly; 1 script-src 'nonce-MDIKmYGm2qaGXBbgq/RNiQ==' 'strict-dynamic' 'unsafe-eval' 'unsafe-inline' https: 'report-sample'; base-uri 'none'; report-uri https://events.mercadolibre.com/csp/reports?identifier=w1qeU4XKVwGbQGBuEKyE3KhFBIpr5IZSIaRiTowMc8UG7kU18vRsmBTEKL2krAj23LIS&policy_id=26548&user_id=&request_id=9010cdff-9198-4c0e-a137-c32a5fb1efac; report-to csp-endpoint-wqeuxkvwgbqgbuekyekhfbiprizsiaritowmcugkuvrsmbteklkrajlis; object-src https://http2.mlstatic.com/ https://mlstaticquic-a.akamaihd.net/; frame-ancestors 'self' https://*.mercadolibre.cl:* https://*.mercadolibre.com:* https://*.mercadolibre.com.ve:* https://*.mercadolibre.com.ar:* https://*.mercadolivre.com.br:* https://*.mercadolibre.com.co:* https://*.mercadolibre.com.ec:* https://*.mercadolibre.com.mx:* https://*.mercadolibre.com.pe:* https://*.mercadolibre.com.uy:* https://*.mercadopago.cl:* https://*.mercadopago.com.ar:* https://*.mercadopago.com.br:* https://*.mercadopago.com.co:* https://*.mercadopago.com.mx:* https://*.mercadopago.com.pe:* https://*.mercadopago.com.uy:* https://*.mercadopago.com.ve:* https://*.mercadopago.com:* https://*.adminml.com:* https://*.mercadolibre.co.cr:* https://*.mercadolibre.com.pa:* https://*.mercadolibre.com.do:* https://*.mercadolibre.com.bo:* https://*.mercadolibre.com.py:* https://*.mercadolibre.com.gt:* https://*.mercadolibre.com.hn:* https://*.mercadolibre.com.ni:* https://*.mercadolibre.com.sv:* https://*.mercadopago.com.ec:* https://*.portalinmobiliario.com:* https://*.mercadolivre.com:* 1 font-src *.gstatic.com data: *.googleapis.com 'self' data: *.doubleclick.net *.facebook.com *.fontawesome.com https://fonts.bunny.net https://cdnjs.cloudflare.com applepay.cdn-apple.com *.survicate.com https://github.com https://use.typekit.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.facebook.com *.monetico-services.com 'self' connect.facebook.net graph.facebook.com business.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com player.vimeo.com https://www.google.com/recaptcha/ www.google.com *.google.com *.doubleclick.net www.facebook.com *.monetico-services.com connect.facebook.net graph.facebook.com business.facebook.com api.payplug.com secure.payplug.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.gstatic.com *.googleapis.com 'self' data: *.google.com *.google.bg www.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://firebasestorage.googleapis.com connect.facebook.net graph.facebook.com business.facebook.com *.cdninstagram.com *.google.fr data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.googleapis.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.gstatic.com *.google.com *.google.bg *.googletagmanager.com www.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.avada.io *.shopify.com connect.facebook.net graph.facebook.com business.facebook.com https://cdnjs.cloudflare.com api.payplug.com applepay.cdn-apple.com https://cdn.payplug.com/js/integrated-payment/ survey.survicate.com sdk.privacy-center.org cdn.mouseflow.com *.clarity.ms 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com https://static.klaviyo.com *.fontawesome.com https://fonts.bunny.net https://fonts.googleapis.com https://cdnjs.cloudflare.com *.survicate.com *.typekit.net *.klaviyo.com *.clarity.ms 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.googleapis.com *.google-analytics.com www.facebook.com *.facebook.net *.google.com *.monetico-services.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://get.geojs.io *.avada.io connect.facebook.net graph.facebook.com business.facebook.com https://stats.g.doubleclick.net https://googleads.g.doubleclick.net https://pagead2.googlesyndication.com https://o2.mouseflow.com *.clarity.ms 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self';connect-src 'self' https://analytics.majestic.com https://analytics.majesticseo.com https://*.google-analytics.com https://*.g.doubleclick.net https://*.analytics.google.com https://*.googletagmanager.com;script-src 'self' 'unsafe-inline' 'unsafe-eval' https://analytics.majesticseo.com https://analytics.majestic.com https://info.majestic.com https://*.googletagmanager.com www.google-analytics.com https://www.googleadservices.com/ https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://platform.twitter.com/ https://challenges.cloudflare.com;style-src 'self' 'unsafe-inline';img-src 'self' data: https:;font-src 'none';object-src 'none';media-src 'none';frame-src www.openstreetmap.org www.youtube.com https://www.youtube-nocookie.com/ https://player.vimeo.com/ https://www.google.com/recaptcha/ https://platform.twitter.com/ https://player.captivate.fm/ https://syndication.twitter.com/ https://challenges.cloudflare.com;child-src www.openstreetmap.org www.youtube.com https://www.google.com/recaptcha/ https://platform.twitter.com/ https://syndication.twitter.com/;frame-ancestors https://docs.google.com https://*.googleusercontent.com;report-uri /csp/report;report-to report-endpoint 1 script-src 'self' 'unsafe-inline' 'unsafe-eval' https:; object-src 'none'; base-uri 'none'; frame-ancestors 'none'; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com maxcdn.bootstrapcdn.com *.klevu.com *.ksearchnet.com *.yotpo.com *.googleapis.com dhv2ziothpgrr.cloudfront.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors *.meetanshi.com meetanshi.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.weltpixel.com *.meetanshi.com meetanshi.com js.mollie.com *.trustpilot.com *.googletagmanager.com *.doubleclick.net 'self' data: cmp.osano.com td.doubleclick.net *.criteo.com www.googletagmanager.com static.criteo.net 23345742.hs-sites.com 'unsafe-inline' data: securemyrx.com creatives.attn.tv api.quizell.com app.quizell.com *.yotpo.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com https://images.unsplash.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com magefan.com cm.magefan.com *.disqus.com https://www.magezon.com https://redchamps.com *.klevu.com *.ksearchnet.com https://img.youtube.com *.meetanshi.com meetanshi.com https://www.mollie.com *.facebook.com *.reddit.com *.ads-twitter.com t.co *.twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.googletagmanager.com *.doubleclick.net *.google.com www.google.co.in *.hubspot.com perf-na1.hsforms.com forms.hsforms.com www.facebook.com sync.1rx.io rtb-csync.smartadserver.com x.bidswitch.net cm.g.doubleclick.net ib.adnxs.com tg.socdm.com r.casalemedia.com cs.adingo.jp ads.stickyadstv.com ad.360yield.com idsync.rlcdn.com public-prod-dspcookiematching.dmxleo.com contextual.media.net *.criteo.com sync.outbrain.com simage2.pubmatic.com pixel.rubiconproject.com sync-t1.taboola.com criteo-sync.teads.tv ade.clmbtech.com eb2.3lift.com dis.criteo.com aa.agkn.com cm.adgrx.com sync.targeting.unrulymedia.com sca1.listrakbi.com seal-utah.bbb.org s1.listrakbi.com *.pubmatic.com sync.ipredictive.com pixel-sync.sitescout.com sync.crwdcntrl.net pixel.tapad.com jelly.mdhv.io 1f2e7.v.fwmrm.net match.prod.bidr.io pr-bh.ybp.yahoo.com match.adsrvr.org pm.w55c.net et.resellerratings.com api.purechat.com *.purechat.com recs.listrakbi.com static.hsappstatic.net partner.mediawallahscript.com ap.lijit.com *.liadm.com exchange.mediavine.com jadserve.postrelease.com trends.revcontent.com tapestry.tapad.com criteo-partners.tremorhub.com ad.tpmn.io px.ads.linkedin.com d.turn.com secure.adnxs.com i.liadm.com idsync.reson8.com match.deepintent.com ad.tpmn.co.kr thrtle.com *.analytics.yahoo.com obgpm76tt0a0sgogzhdfe.redinuid.imrworldwide.com sync.mathtag.com *.tribalfusion.com events.attentivemobile.com live.rezync.com pippio.com data.adsrvr.org ce.lijit.com c1.adform.com um.simpli.fi mid.rkdms.com b1sync.outbrain.com b1sync.zemanta.com sync.srv.stackadapt.com ws.rqtrk.eu https://lantern.roeye.com https://*.listrakbi.com https://*.listrak.com *.yotpo.com dhv2ziothpgrr.cloudfront.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://maps.googleapis.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.disqus.com https://cdn.jsdelivr.net cdn.jsdelivr.net js.klevu.com *.ksearchnet.com *.meetanshi.com meetanshi.com js.mollie.com *.trustpilot.com *.googletagmanager.com *.googleadservices.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.bing.com *.clarity.ms *.klaviyo.com unpkg.com *.doubleclick.net 'unsafe-inline' data: js-agent.newrelic.com z.moatads.com cdn.listrakbi.com z.moatads.co bat.bing.com www.dwin1.com acsbapp.co cmp.osano.com app.purechat.com js.hs-scripts.com js.usemessages.com js.hs-banner.com js.hscollectedforms.net js.hubspot.com js.hs-analytics.net ajax.googleapis.com *.listrakbi.com services.listrak.com prod.purechatcdn.com acsbapp.com 23345742.hs-sites.com www.resellerratings.com *.lunio.ai *.criteo.com player.vimeo.com cdn.noibu.com catpq.vitalitymedical.com static.cloudflareinsights.com conversionteam.s3.amazonaws.com api.quizell.com https://lantern.roeyecdn.com https://js.klevu.com/core/v2/klevu.js https://cdn.callrail.com/companies/694783136/19fe0fad69757295966b/12/swap.js https://cdn.id5-sync.com/api/1.0/id5-api.js https://*.listrakbi.com https://*.listrak.com https://js.klevu.com https://cdn.ksearchnet.com https://*.ksearchnet.com https://*.klevu.com https://prod.purechatcdn.com/assets/modern_initializer.13851.js https://cdn.attn.tv/vitalitymedical/dtag.js https://cdn.attn.tv/growth-tag-assets/client-configs/T33.js https://cdn.attn.tv/tag/4-latest/unified-tag.js https://acsbapp.com/apps/app/dist/js/app.js https://prod.purechatcdn.com/assets/modern_app.13851.js https://api.purechat.com https://*.purechat.com *.yotpo.com dhv2ziothpgrr.cloudfront.net *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com d18eg7dreypte5.cloudfront.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com assets.braintreegateway.com https://cdn.jsdelivr.net cdn.jsdelivr.net maxcdn.bootstrapcdn.com *.klevu.com *.ksearchnet.com *.trustpilot.com *.tagmanager.google.com *.googletagmanager.com cdn.listrakbi.com api.quizell.com *.yotpo.com *.googleapis.com dhv2ziothpgrr.cloudfront.net https://statsjs.klevu.com https://js.klevu.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://maps.googleapis.com https://player.vimeo.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.klevu.com *.ksearchnet.com *.meetanshi.com meetanshi.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.doubleclick.net *.run.app 'self' data: bam.nr-data.net cdn.acsbapp.com cmp.osano.com *.purechat.com api.hubspot.com cta-service-cms2.hubspot.com forms.hscollectedforms.net recs.listrakbi.com measurement-api.criteo.com tattle.api.osano.com stats.g.doubleclick.net consent.api.osano.com invitejs.trustpilot.com widget.trustpilot.com static.hsappstatic.net www.resellerratings.com conversions.lunio.ai *.noibu.com catpq.vitalitymedical.com cloudflareinsights.com wss://input.noibu.com/ api.quizell.com bat.bing.com id5-sync.com t.lt02.net https://*.listrakbi.com https://*.listrak.com *.yotpo.com dhv2ziothpgrr.cloudfront.net *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' ; script-src 'self' 'unsafe-eval' 'unsafe-inline' 'nonce-5ce6b5bf-36b9-4d83-9536-c9da4c4ac498' https: data: https://js.sentry-cdn.com https://fast.wistia.com https://fast.wistia.net https://siteintercept.qualtrics.com https://browser.sentry-cdn.com https://*.siteintercept.qualtrics.com https://www.googletagmanager.com https://js.monitor.azure.com; style-src 'self' 'unsafe-inline' https://fast.wistia.com https://cdn.jsdelivr.net https://more.suse.com; img-src 'self' https: data: https://fast.wistia.com https://embed-ssl.wistia.com https://cdn.cookielaw.org https://embed-ssl.wistia.com https://fast.wistia.net https://fast.wistia.com https://cdn.cookielaw.org https://embed-ssl.wistia.com https://embed-ssl.wistia.com https://cdn.cookielaw.org https://embed-ssl.wistia.com; connect-src 'self' https: wss: https://cdn.cookielaw.org https://distillery.wistia.com https://siteintercept.qualtrics.com https://dc.services.visualstudio.com https://fast.wistia.com https://fast.wistia.net https://pipedream.wistia.com wss://ws.qualified.com https://embed-ssl.wistia.com https://apple.dxcloud.episerver.net https://cdn.jsdelivr.net https://js.monitor.azure.com wss://ws.qualified.com; font-src 'self' https: data: https://fonts.gstatic.com https://fast.wistia.net; object-src 'none' ; media-src 'self' https: blob: ; frame-src 'self' https: ; form-action 'self' https://suselinux.fra1.qualtrics.com; frame-ancestors 'self' ; base-uri 'none' ; report-uri https://www.suse.com/api/reporting/; report-to csp-endpoint; 1 font-src fonts.gstatic.com use.typekit.net *.cdnfonts.com *.cloudflare.com *.gstatic.com *.klaviyo.com *.slant.co *.yotpo.com *.zip.co sc-static.net *.zdassets.com *.zendesk.com tryme.directory *.hotjar.com *.klarnacdn.net *.klevu.com *.ksearchnet.com *.googleapis.com dhv2ziothpgrr.cloudfront.net www.sportrx.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com www.apptrian.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.yotpo.com www.sportrx.com 'self' 'unsafe-inline'; frame-ancestors www.sportrx.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.googletagmanager.com www.apptrian.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com bytedance: sslocal: www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.googletagmanager.com *.zdassets.com *.zendesk.com *.hotjar.com *.klarna.com *.yotpo.com www.sportrx.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net p.typekit.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com validator.swagger.io www.apptrian.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com analytics.tiktok.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.adsrvr.org *.avantlink.com *.bing.com *.bing.net *.cloudflare.com *.criteo.com *.criteo.net *.doubleclick.net *.facebook.com *.google-analytics.com *.google.com *.googleapis.com *.googlesyndication.com *.googletagmanager.com *.gravatar.com *.gstatic.com *.klevu.com *.linksynergy.com *.liquifire.com *.pushcrew.com *.rlcdn.com *.sharethis.com *.sportrx.com *.teamusa.org *.visualwebsiteoptimizer.com *.wileyxrx.com *.xg4ken.com *.yotpo.com *.youtube.com cdn-cookieyes.com d10lpsik1i8c69.cloudfront.net *d3k81ch9hvuctc.cloudfront.net extendcoreoffersprod-offersthemelogobucketeb21afa-1lr7le13dvgtp.s3.amazonaws.com s3.amazonaws.com *.zdassets.com *.zendesk.com *.hotjar.com *.klarna.com *.klarnaevt.com *.klarnacdn.net https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.ksearchnet.com dhv2ziothpgrr.cloudfront.net www.sportrx.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com amcglobal.sc.omtrdc.net *.adobe.io use.typekit.net www.sandbox.paypal.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com *.magento-ds.com www.googletagmanager.com www.apptrian.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com analytics.tiktok.com *.attn.tv events.attentivemobile.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.zendesk.com wss://api.smooch.io *.luckyorange.net *.luckyorange.com *.googleapis.com *.pushcrew.com *.addthis.com *.addthisedge.com *.adobedtm.com *.adsrvr.org *.bing.com *.braintreegateway.com *.cloudflare.com d10lpsik1i8c69.cloudfront.net d3k81ch9hvuctc.cloudfront.net *.criteo.com *.criteo.net *.doubleclick.net *.facebook.net *.google-analytics.com *.google.com *.googlesyndication.com *.googletagmanager.com *.invoca.net *.invocacdn.com *.klaviyo.com *.klevu.com *.linksynergy.com *.moatads.com *.noibu.com input.noibu.com wss://input.noibu.com *.sharethis.com *.tiktok.com *.visualwebsiteoptimizer.com *.xg4ken.com *.yotpo.com *.youtube.com *.zdassets.com acsbapp.com cdn.acsbapp.com *.acsbapp.com cdn-cookieyes.com google-analytics.com tryme.directory *.newrelic.com *.rakuten.com *.rlcdn.com *.hotjar.com cdn.avmws.com/1016937/ *.smooch.io *.liquifire.com *.klarnacdn.net *.klarna.com *.glasseson.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klarnaservices.com js.klevu.com *.ksearchnet.com dhv2ziothpgrr.cloudfront.net *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com d18eg7dreypte5.cloudfront.net www.sportrx.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com unsafe-inline assets.braintreegateway.com *.googleapis.com *.googletagmanager.com *.gstatic.com *.klaviyo.com *.klevu.com *.pushcrew.com *.yotpo.com *.zdassets.com *.zendesk.com *.hotjar.com https://static.klaviyo.com *.klarnacdn.net *.ksearchnet.com dhv2ziothpgrr.cloudfront.net www.sportrx.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com *.bing.com *.googleapis.com *.gstatic.com *.zdassets.com *.zendesk.com *.hotjar.com *.glasseson.com *.cloudfront.net www.sportrx.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com *.snplow.net commerce.adobedc.net api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io *.magento-datasolutions.com *.magento-ds.com *.sentry.io www.apptrian.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com analytics.tiktok.com *.attn.tv events.attentivemobile.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.zendesk.com wss://api.smooch.io *.googleapis.com *.addthis.com *.adsrvr.org *.bing.com *.bing.net *.cloudflare.com *.criteo.com *.criteo.net *.datadome.co *.doubleclick.net *.facebook.com *.google-analytics.com *.googlesyndication.com *.googletagmanager.com *.gravatar.com *.gstatic.com *.invoca.net *.invocacdn.com *.klaviyo.com *.linksynergy.com *.luckyorange.net *.luckyorange.com *.noibu.com input.noibu.com wss://input.noibu.com *.nr-data.net *.pushcrew.com *.rlcdn.com *.samsung.com *.sharethis.com *.teamusa.org *.tiktok.com *.visualwebsiteoptimizer.com *.youtube.com *.zdassets.com acsbapp.com cdn.acsbapp.com *.acsbapp.com cdn-cookieyes.com *.cookieyes.com google-analytics.com tryme.directory d10lpsik1i8c69.cloudfront.net d3k81ch9hvuctc.cloudfront.net *.hotjar.com *.klarnaevt.com *.glasseson.com *.mixpanel.com *.cloudfront.net https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klarnacdn.net *.klarna.com *.klarnaservices.com *.klevu.com *.ksearchnet.com *.yotpo.com dhv2ziothpgrr.cloudfront.net *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com www.sportrx.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com www.sportrx.com http: https: blob: wss: 'self' 'unsafe-inline'; default-src *.glasseson.com *.cloudfront.net www.sportrx.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://f67b9549-76ff-40d0-b57c-93081e358fa4.sansec.watch/; report-to report-endpoint; 1 default-src *; img-src https:; frame-src 'none' 1 font-src *.fontawesome.com https://www.gstatic.com https://fonts.gstatic.com www.redwolfairsoft.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com airwallex.com *.airwallex.com google.com *.google.com testsecureacceptance.cybersource.com secureacceptance.cybersource.com 0merchantacsstag.cardinalcommerce.com merchantacs.cardinalcommerce.com www.redwolfairsoft.com 'self' 'unsafe-inline'; frame-ancestors *.bolt.com www.gstatic.com www.redwolfairsoft.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.bolt.com www.google.com www.googletagmanager.com checkout.airwallex.com checkout-demo.airwallex.com h.online-metrix.net/ static-demo.airwallex.com pci-api-demo.airwallex.com demo-pacybsmock.airwallex.com imgs.signifyd.com airwallex.com *.airwallex.com google.com *.google.com *.online-metrix.net testflex.cybersource.com flex.cybersource.com testsecureacceptance.cybersource.com secureacceptance.cybersource.com pay.google.com sandbox.secure.checkout.visa.com secure.checkout.visa.com thm.visa.com sandbox.src.mastercard.com merchantacs.cardinalcommerce.com 0merchantacsstag.cardinalcommerce.com https://www.google.com www.redwolfairsoft.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.online-metrix.net/ checkout.airwallex.com imgs.signifyd.com checkout-demo.airwallex.com airwallex.com *.airwallex.com google.com *.google.com www.gstatic.com sandbox.secure.checkout.visa.com secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com assets.secure.checkout.visa.com thm.visa.com validate.fishpig.co.uk https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ www.redwolfairsoft.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.bolt.com *.commerce-quick-checkout.com http://localhost:8082 https://www.gstatic.com/recaptcha/ www.google.com checkout.airwallex.com checkout-demo.airwallex.com h.online-metrix.net/ static-demo.airwallex.com static.airwallex.com cdn-scripts.signifyd.com bws-demo.airwallex.com bws.airwallex.com imgs.signifyd.com h64.online-metrix.net airwallex.com *.airwallex.com google.com *.google.com *.cdn-apple.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.online-metrix.net testflex.cybersource.com flex.cybersource.com pay.google.com x.klarnacdn.net sandbox.secure.checkout.visa.com secure.checkout.visa.com sandbox-assets.secure.checkout.visa.com assets.secure.checkout.visa.com thm.visa.com sandbox.src.mastercard.com songbirdstag.cardinalcommerce.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.avada.io https://www.google.com https://www.gstatic.com www.redwolfairsoft.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://static.klaviyo.com *.fontawesome.com www.redwolfairsoft.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.redwolfairsoft.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.bolt.com checkout.airwallex.com checkout-demo.airwallex.com h.online-metrix.net/ bws-demo.airwallex.com bws.airwallex.com api-demo.airwallex.com api.airwallex.com imgs.signifyd.com airwallex.com *.airwallex.com google.com *.google.com thm.visa.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://get.geojs.io *.avada.io www.redwolfairsoft.com 'self' 'unsafe-inline'; child-src airwallex.com *.airwallex.com www.redwolfairsoft.com http: https: blob: 'self' 'unsafe-inline'; default-src airwallex.com *.airwallex.com www.redwolfairsoft.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; img-src 'self' files.booktrust.org.uk; script-src 'self' 'nonce-Y3B6bHRkY3J6ZmhrbGdkc3BnY3l2YnhqY2Zyb2lyd2lyYXp5' cdn.jsdelivr.net/npm/; style-src 'self' 'unsafe-inline'; connect-src 'self' *.algolia.io *.algolia.net; frame-src 'self' 'nonce-Y3B6bHRkY3J6ZmhrbGdkc3BnY3l2YnhqY2Zyb2lyd2lyYXp5'; 1 object-src 'none'; script-src 'self' 'report-sample' cdn.jsdelivr.net cdnjs.cloudflare.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com https://www.recaptcha.net maps.googleapis.com; style-src 'self' 'report-sample' cdn.jsdelivr.net https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com; webrtc 'block'; worker-src 'self'; base-uri 'self'; form-action 'self'; frame-ancestors 'self' 1 default-src 'report-sample' 'self' 'unsafe-inline' data: blob: *.skeb.jp *.imgix.net challenges.cloudflare.com *.pay.jp *.s3.ap-northeast-1.amazonaws.com misskey.io *.misskeyusercontent.jp www.gravatar.com *.twimg.com t.co static.ads-twitter.com analytics.twitter.com analytics.google.com *.gstatic.com *.gstatic.cn fonts.googleapis.com www.googletagmanager.com www.google-analytics.com *.doubleclick.net www.recaptcha.net *.sentry.io *.algolia.net *.algolianet.com cdn.plyr.io *.google.com *.google.ad *.google.ae *.google.com.af *.google.com.ag *.google.al *.google.am *.google.co.ao *.google.com.ar *.google.as *.google.at *.google.com.au *.google.az *.google.ba *.google.com.bd *.google.be *.google.bf *.google.bg *.google.com.bh *.google.bi *.google.bj *.google.com.bn *.google.com.bo *.google.com.br *.google.bs *.google.bt *.google.co.bw *.google.by *.google.com.bz *.google.ca *.google.cd *.google.cf *.google.cg *.google.ch *.google.ci *.google.co.ck *.google.cl *.google.cm *.google.cn *.google.com.co *.google.co.cr *.google.com.cu *.google.cv *.google.com.cy *.google.cz *.google.de *.google.dj *.google.dk *.google.dm *.google.com.do *.google.dz *.google.com.ec *.google.ee *.google.com.eg *.google.es *.google.com.et *.google.fi *.google.com.fj *.google.fm *.google.fr *.google.ga *.google.ge *.google.gg *.google.com.gh *.google.com.gi *.google.gl *.google.gm *.google.gr *.google.com.gt *.google.gy *.google.com.hk *.google.hn *.google.hr *.google.ht *.google.hu *.google.co.id *.google.ie *.google.co.il *.google.im *.google.co.in *.google.iq *.google.is *.google.it *.google.je *.google.com.jm *.google.jo *.google.co.jp *.google.co.ke *.google.com.kh *.google.ki *.google.kg *.google.co.kr *.google.com.kw *.google.kz *.google.la *.google.com.lb *.google.li *.google.lk *.google.co.ls *.google.lt *.google.lu *.google.lv *.google.com.ly *.google.co.ma *.google.md *.google.me *.google.mg *.google.mk *.google.ml *.google.com.mm *.google.mn *.google.com.mt *.google.mu *.google.mv *.google.mw *.google.com.mx *.google.com.my *.google.co.mz *.google.com.na *.google.com.ng *.google.com.ni *.google.ne *.google.nl *.google.no *.google.com.np *.google.nr *.google.nu *.google.co.nz *.google.com.om *.google.com.pa *.google.com.pe *.google.com.pg *.google.com.ph *.google.com.pk *.google.pl *.google.pn *.google.com.pr *.google.ps *.google.pt *.google.com.py *.google.com.qa *.google.ro *.google.ru *.google.rw *.google.com.sa *.google.com.sb *.google.sc *.google.se *.google.com.sg *.google.sh *.google.si *.google.sk *.google.com.sl *.google.sn *.google.so *.google.sm *.google.sr *.google.st *.google.com.sv *.google.td *.google.tg *.google.co.th *.google.com.tj *.google.tl *.google.tm *.google.tn *.google.to *.google.com.tr *.google.tt *.google.com.tw *.google.co.tz *.google.com.ua *.google.co.ug *.google.co.uk *.google.com.uy *.google.co.uz *.google.com.vc *.google.co.ve *.google.co.vi *.google.com.vn *.google.vu *.google.ws *.google.rs *.google.co.za *.google.co.zm *.google.co.zw *.google.cat;report-to csp-violation-report 1 default-src 'self'; script-src 'self' 'unsafe-inline' https://*.googlesyndication.com https://*.doubleclick.net https://googleads.g.doubleclick.net https://pagead2.googlesyndication.com https://tpc.googlesyndication.com https://www.googletagmanager.com https://www.google-analytics.com https://*.google.com https://adservice.google.com https://adservice.google.co.uk https://challenges.cloudflare.com https://www.gstatic.com https://www.recaptcha.net https://static.cloudflareinsights.com https://*.adtrafficquality.google; connect-src 'self' https:; img-src 'self' data: blob: https:; frame-src 'self' https://*.doubleclick.net https://*.googlesyndication.com https://googleads.g.doubleclick.net https://tpc.googlesyndication.com https://fundingchoicesmessages.google.com https://*.google.com https://www.gstatic.com https://www.recaptcha.net https://challenges.cloudflare.com https://*.adtrafficquality.google; style-src 'self' 'unsafe-inline' https:; font-src 'self' data: https:; base-uri 'self'; frame-ancestors 'self'; upgrade-insecure-requests; 1 default-src 'self' ; base-uri 'self' ; object-src 'none' ; style-src 'self' 'unsafe-inline' cdn.plyr.io https://fonts.googleapis.com https://devcomapbotpilot-test.azurewebsites.net/ https://chatbotapp-stage.azurewebsites.net/ https://intelibot-prod.azurewebsites.net/ ; script-src 'strict-dynamic' 'nonce-mYa6ENDTbr5RXPp2a1eChAbiABkxiS6Z' 'self' 'unsafe-inline' 'unsafe-eval' https://js.monitor.azure.com https://admin.dev.comap-control.bluehosting.cz https://chatbotapp-stage.azurewebsites.net/ https://devcomapbotpilot-test.azurewebsites.net/ https://intelibot-prod.azurewebsites.net/ ; font-src 'self' https://fonts.gstatic.com/ ; connect-src 'self' https://*.google.com https://*.logic.azure.com/ https://chatbotapp-stage.azurewebsites.net/ https://intelibot-prod.azurewebsites.net/ https://intelisearch.azurewebsites.net https://directline.botframework.com https://websearchproxy.azure-api.net wss://directline.botframework.com https://*.in.applicationinsights.azure.com/ wss://localhost:44377 ws://localhost:50602 noembed.com cdn.plyr.io ; img-src * 'self' data: ; media-src 'self' *.comap-control.com/ https://comapkenticouat6527.blob.core.windows.net ; frame-src https://www.thinglink.com youtube-nocookie.com www.youtube-nocookie.com youtube.com www.youtube.com vimeo.com www.vimeo.com https://www.google.com/ ; frame-ancestors https://admin.dev.comap-control.bluehosting.cz/ 1 default-src 'self' https://*.zorgdomein.nl; style-src 'self' 'unsafe-inline' https://*.zorgdomein.nl https://fonts.googleapis.com https://*.wootric.com https://*.wootric.eu; script-src 'self' 'nonce-1c80825a033693f8ed00cba3b41d2348' https://*.zorgdomein.nl https://*.zdassets.com https://*.zendesk.com https://*.zopim.com https://zendesk-eu.my.sentry.io wss://*.zendesk.com wss://*.zopim.com https://*.wootric.com https://*.wootric.eu https://*.googleapis.com; img-src https://* 'self' https://*.googleapis.com https://*.gstatic.com *.google.com *.googleusercontent.com data:; connect-src https://*.zorgdomein.nl wss://*.zorgdomein.nl https://*.zdassets.com https://*.zendesk.com https://*.zopim.com https://zendesk-eu.my.sentry.io wss://*.zendesk.com wss://*.zopim.com https://*.googleapis.com *.google.com https://*.gstatic.com https://*.wootric.com https://*.wootric.eu; frame-src 'self' https://*.zorgdomein.nl https://*.quicksight.aws.amazon.com *.google.com http: https:; report-uri /api/v1/report-uri; font-src 'self' https://*.zorgdomein.nl https://fonts.gstatic.com data:; base-uri 'self' 1 style-src 'self' 'unsafe-inline' data: *.ebay.com *.ebaystatic.com *.ebaystatic.cn *.gstatic.com *.fontawesome.com blob: *.googleapis.com; connect-src 'self' *.ebay.com *.ebaystatic.com data: *.google-analytics.com *.doubleclick.net *.avalon.perfdrive.com *.ebayimg.com *.ucweb.com *.akamaihd.net *.ucads.ucweb.com *.analytics.google.com *.g.doubleclick.net *.googletagmanager.com *.pinterest.com *.snapchat.com *.criteo.com *.facebook.com *.googleapis.com *.googleadservices.com blob: analytics.google.com *.us.shoplive.cloud www.facebook.com *.bing.com www.googletagmanager.com google.com *.google.com *.graphitevault.com *.amplitude.com wss://127.0.0.1:* www.redditstatic.com *.reddit.com *.quantummetric.com; script-src 'self' 'unsafe-eval' 'unsafe-inline' https://* blob: data:; frame-ancestors 'self' *.ebay.com *.ebaystatic.com; img-src 'self' data: blob: https://*; default-src 'self' blob: data: wss: mediastream: https://*; report-uri https://monitor.ebay.com/csp-report/discoveryplatformweb/HomePage?id=2939504940913871808&rid=t6gludlscuzujfwciunrce00%3C%3Dgludlscuzujfwciunrce00%2Bee%3C%3F371d0.qctp42%3F.%3D~2k%3C-19c3622491a-0x806#pd 1 default-src https: 'unsafe-inline' 'unsafe-eval'; img-src https: 'unsafe-inline' 'unsafe-eval' data:; report-uri https://www0mansion0review0jp.report-uri.com/r/d/csp/reportOnly; 1 default-src 'self' http: https://*-chcf-wp.pantheonsite.io/ https://chcf-wp.ddev.site https://*.addthis.com https://*.youtube.com; script-src 'unsafe-inline' 'unsafe-eval' http: https://*.google.com https://fonts.googleapis.com https://ajax.googleapis.com https://jnn-pa.googleapis.com https://*.googletagmanager.com https://*.youtube.com https://*.addthis.com https://*.google-analytics.com https://*.ytimg.com https://*.moatads.com https://*.doubleclick.net https://*.addthisedge.com https://cdnjs.cloudflare.com; style-src 'unsafe-inline' http: https://*.google.com https://fonts.googleapis.com https://ajax.googleapis.com https://jnn-pa.googleapis.com https://*.youtube.com; img-src 'self' http: data: https://*.ytimg.com https://*.ggpht.com https://*.gstatic.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.bookingbug.com https://geolocation.onetrust.com https://*.cookielaw.org https://fonts.googleapis.com https://ajax.googleapis.com https://jnn-pa.googleapis.com *.addtoany.com; font-src 'self' data: fonts.gstatic.com use.typekit.net use.fontawesome.com bespoke.bookingbug.com; media-src 'self' *.youtube.com *.vimeo.com *.akamaized.net; report-uri 'self'; child-src 'self'; form-action 'self'; frame-ancestors 'self'; object-src 'self'; frame-src 'self' blob: *.youtube.com *.youtube-nocookie.com *.doubleclick.net *.soundcloud.com *.facebook.com *.vimeo.com *.addtoany.com *.infogram.com *.simplecast.com; worker-src 'self'; manifest-src 'self'; navigate-to 'self'; prefetch-src 'self'; upgrade-insecure-requests 1 default-src 'self'; script-src 'self' https://www.googletagmanager.com https://tagmanager.google.com https://dig-aboprod.noncd.db.de https://*.consentmanager.net https://web-assets-stage.dc.vvs.de https://web-assets-prod.dc.vvs.de https://www-assets.vvs.de 'report-sample'; style-src-attr 'unsafe-inline' 'report-sample'; img-src 'self' data: *.ytimg.com *.vimeocdn.com https://bildermangel.de https://www.google-analytics.com https://www.googletagmanager.com https://stats.g.doubleclick.net https://*.consentmanager.net https://web-assets-stage.dc.vvs.de https://web-assets-prod.dc.vvs.de https://www-assets.vvs.de; base-uri 'self'; frame-src 'self' *.youtube-nocookie.com *.youtube.com *.vimeo.com https://www.youtube.com https://www.youtube-nocookie.com https://*.vvs.de https://vvsjobs.softgarden.io https://www.paperturn-view.com http://paperturn-view.com https://*.paperturn-view.com https://www.unserebroschuere.de https://dig-aboprod.noncd.db.de https://www.googletagmanager.com https://*.consentmanager.net; font-src 'self' https://dig-aboprod.noncd.db.de https://*.consentmanager.net https://web-assets-stage.dc.vvs.de https://web-assets-prod.dc.vvs.de https://www-assets.vvs.de; worker-src 'self' https://www.googletagmanager.com https://tagmanager.google.com https://dig-aboprod.noncd.db.de https://*.consentmanager.net https://web-assets-stage.dc.vvs.de https://web-assets-prod.dc.vvs.de https://www-assets.vvs.de https://*.vvs.de; connect-src 'self' https://apistaging.vvs.de https://*.vvs.de https://www.google-analytics.com https://stats.g.doubleclick.net https://analytics.google.com https://www.googletagmanager.com https://region1.google-analytics.com https://abo.bahn.de https://dig-aboprod.noncd.db.de https://*.consentmanager.net https://web-assets-stage.dc.vvs.de https://web-assets-prod.dc.vvs.de https://www-assets.vvs.de; object-src 'none'; style-src 'self' https://dig-aboprod.noncd.db.de https://*.consentmanager.net https://web-assets-stage.dc.vvs.de https://web-assets-prod.dc.vvs.de https://www-assets.vvs.de 'unsafe-inline' 'report-sample'; form-action 'self' https://dig-aboprod.noncd.db.de https://abo.bahn.de; script-src-attr 'none' 'report-sample'; report-uri https://www.vvs.de/@http-reporting?csp=report&requestTime=1758610862619452&requestHash=37a59644ef9051c8efc5aa5fa70c9054b934deef 1 'img-src' 'blob' 'default-src' 'self' 'unsafe-inline' 'unsafe-eval' 'blob' blob: http://blog-cms.weddingz.in https://stats.g.doubleclick.net https://securesentry.oyorooms.io https://code.getmdl.io https://assets.pinterest.com https://graph.facebook.com *.s3.amazonaws.com https://api.instagram.com https://api.pinterest.com https://connect.facebook.net *.cloudfront.net https://ds-aksb-a.akamaihd.net *.googleapis.com *.gstatic.com *.criteo.com *.criteo.net https://www.facebook.com https://www.google-analytics.com https://www.google.co.in https://www.google.com https://www.googletagmanager.com https://www.googleadservices.com https://m.weddingz.in https://media.weddingz.in https://js-agent.newrelic.com https://assets.oyoroomscdn.com https://maxcdn.bootstrapcdn.com https://weddingz.in https://www.youtube.com https://tagmanager.google.com *.instagram.com https://instagram *.tile.openstreetmap.org; report-uri /private_apis/content-security-violation/ 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com cash-f.squarecdn.com https://*.gstatic.com *.googleapis.com *.fontawesome.com smct.co *.smct.co smct.io *.smct.io *.amazonaws.com *.akamaihd.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com * *.adyen.com *.facebook.com *.google.com *.list-manage.com *.americanexpress.com *.cartasi.it *.nexi.it 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com * *.adyen.com *.sharethis.com *.iubenda.com *.livechatinc.com *.online-metrix.net *.tracead.com tracead.com *.signifyd.com img.signifyd.com *.addthis.com *.jrs5.com pubxtag1.com amc.demdex.net *.facebook.com smct.co *.smct.co smct.io *.smct.io *.amazonaws.com *.hotjar.com *.cartasi.it *.nexi.it 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io * https://*.gstatic.com *.adyen.com *.sharethis.com *.googleapis.com *.feedaty.com *.payments-amazon.com *.linksynergy.com *.nxtck.com *.mediaforge.com *.jrs5.com *.dc-storm.com *.rd.linksynergy.com *.ra.linksynergy.com *.facebook.com *.google.it *.google.com *.signifyd.com *.e.aa.online-metrix.net smct.co *.smct.co smct.io *.smct.io *.amazonaws.com *.demdex.net *.ytimg.com *.facebook.net *.akamaihd.net *.photorank.me *.zoorate.com *.nomination.com *.bing.com *.livehelp.it *.doubleclick.net *.googletagmanager.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com *.vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com *.cash.app *.visa.com *.mastercard.com https://rum.hlx.page *.sharethis.com *.googleapis.com *.gstatic.com *.feedaty.com *.iubenda.com *.googletagmanager.com *.chimpstatic.com chimpstatic.com *.doofinder.com *.signifyd.com *.livechatinc.com *.facebook.net *.rmtag.com *.tracead.com tracead.com *.addthis.com *.amazon.com *.amazonaws.com *.googleadservices.com *.google-analytics.com *.jsdelivr.net *.moatads.com *.addthisedge.com *.pinterest.com smct.co *.smct.co smct.io *.smct.io *.akamaihd.net *.zoorate.com *.cloudflare.com *.bing.com *.hotjar.com *.doubleclick.net *.livehelp.it 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.cash.app https://fonts.googleapis.com/ *.sharethis.com *.feedaty.com *.fontawesome.com *.cloudflare.com *.googleapis.com *.jsdelivr.net *.gstatic.com *.zoorate.com *.akamaihd.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com * *.adyen.com *.sharethis.com *.algolia.net *.algolia.io *.algolianet.com *.insights.algolia.io insights.algolia.io *.googleapis.com *.feedaty.com *.iubenda.com *.doofinder.com *.g.doubleclick.net *.doubleclick.net *.signifyd.com *.signifyd.com:11103 *.signifyd.com:11103/onload https://bt.signifyd.com:11103 https://bt.signifyd.com:11103/onload bt.signifyd.com *.facebook.com *.livechatinc.com *.addthis.com smct.co *.smct.co smct.io *.smct.io *.amazonaws.com *.akamaihd.net *.hotjar.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 frame-ancestors 'self'; report-uri https://www.gq.com.au/csp-reports 1 default-src 'self' https: data: wss: http: umbraco.tv packages.umbraco.org our.umbraco.org; block-all-mixed-content; form-action https:;script-src 'self' 'unsafe-inline' 'unsafe-eval' ajax.cloudflare.com static.cloudflareinsights.com umbraco.tv packages.umbraco.org our.umbraco.org code.jquery.com fonts.googleapis.com use.typekit.net unpkg.com cdn.jsdelivr.net ajax.aspnetcdn.com kit.fontawesome.com www.googletagmanager.com www.recaptcha.net www.google.com www.google-analytics.com www.gstatic.com js.authorize.net jstest.authorize.net;font-src 'self' https: data: fonts.gstatic.com use.typekit.net kit-pro.fontawesome.com;img-src 'self' https: data: umbraco.tv packages.umbraco.org our.umbraco.org p.typekit.net www.goole-analytics.com www.gstatic.com www.googletagmanager.com;media-src https: data: umbraco.tv packages.umbraco.org our.umbraco.org p.typekit.net;style-src 'self' 'unsafe-inline' https: data: use.typekit.net p.typekit.net fonts.googleapis.com kit-pro.fontawesome.com unpkg.com cdn.jsdelivr.net; 1 manifest-src https:; media-src https:; upgrade-insecure-requests; style-src 'self' https: 'unsafe-inline'; object-src 'none'; connect-src 'self' https:; frame-ancestors 'none' 1 default-src 'self'; script-src 'self' data: 'unsafe-inline' 'unsafe-eval' https:; object-src 'self' https:; style-src 'self' data: 'unsafe-inline' https:; img-src 'self' data: blob: https:; media-src 'self' data: blob: https:; frame-src 'self' data: https:; font-src 'self' data: https:; connect-src 'self' data: https:; 1 child-src 'self' https://www.googletagmanager.com https://*.liveperson.net https://cdn.appdynamics.com https://*.lpsnmedia.net https://www.facebook.com https://connect.facebook.net https://*.google.com https://widget.trustpilot.com https://*.doubleclick.net https://smct.co https://*.smct.co https://smct.io https://*.smct.io https://d2d7do8qaecbru.cloudfront.net https://*.ringcentral.com https://hcaptcha.com https://*.hcaptcha.com https://www.youtube.com https://www.zenaps.com https://*.akamaihd.net https://*.translate.naver.net https://recaptcha.net https://tr.snapchat.com https://*.abtasty.com; connect-src 'self' https://*.thcdn.com https://*.ingest.sentry.io https://*.pingdom.net https://*.doubleclick.net https://*.google-analytics.com https://capture.trackjs.com https://fp.zenaps.com https://www.facebook.com https://*.google.com https://*.thehut.net https://privacyportal-eu.onetrust.com https://geolocation.onetrust.com https://cdn.cookielaw.org wss://*.liveperson.net https://*.liveperson.net https://*.lpsnmedia.net https://smct.co https://*.smct.co https://smct.io https://*.smct.io https://cognito-identity.eu-west-1.amazonaws.com https://firehose.eu-west-1.amazonaws.com https://*.ringcentral.com wss://*.ringcentral.com https://hcaptcha.com https://*.hcaptcha.com https://services.postcodeanywhere.co.uk https://*.sciencebehindecommerce.com https://*.akamaihd.net https://*.googleapis.com https://*.trustpilot.com https://*.pinterest.com https://*.doubleclick.net https://*.bing.com https://connect.facebook.net https://*.parcellab.com https://storyboard.storystream.ai https://content.storystream.ai https://*.abtasty.com https://d3g5d7323c2i6m.cloudfront.net https://d29qb9vav0xwuc.cloudfront.net https://d7c4jjeuqag9w.cloudfront.net https://apps.storystream.ai https://upload.uploadcare.com https://598nyfqkt7.execute-api.eu-west-1.amazonaws.com https://sgtm.www.berghaus.com https://*.ometria.com https://www.berghaus.com/e2/ds/relay https://horizon-api.www.berghaus.com/graphql https://*.ingest.sentry.io https://s1.thcdn.com; font-src 'self' data: https://*.thcdn.com https://fp.zenaps.com https://cdnjs.cloudflare.com https://fonts.gstatic.com https://fonts.googleapis.com https://fonts.smct.co https://fonts.smct.io https://*.ringcentral.com blob: data: https://*.abtasty.com https://*.gstatic.com https://*.googleapis.com https://d7c4jjeuqag9w.cloudfront.net; form-action 'self' https://www.facebook.com https://m.berghaus.com https://checkout.berghaus.com https://www.berghaus.com https://connect.facebook.net https://tr.snapchat.com; img-src 'self' data: https://*.thcdn.com https://col.eum-appdynamics.com https://usage.trackjs.com https://*.lpsnmedia.net https://*.doubleclick.net https://www.google-analytics.com https://*.google.com https://cx.atdmt.com https://www.zenaps.com https://*.ringcentral.com https: blob:; media-src 'self' https://*.thcdn.com https://*.lpsnmedia.net blob: https://player.vimeo.com https://vod-progressive.akamaized.net https://download-video.akamaized.net https://d7c4jjeuqag9w.cloudfront.net https://media.storystream.ai; report-uri https://csp.thehut.net/cspReport.txt; script-src 'self' 'unsafe-eval' 'unsafe-inline' data: https://*.thcdn.com https://*.thehut.net https://rum-static.pingdom.net https://*.liveperson.net https://*.lpsnmedia.net https://*.doubleclick.net https://static.cdn-apple.com https://*.liveperson.com https://geolocation.onetrust.com https://cdn.cookielaw.org https://cdn.parcellab.com https://smct.co https://*.smct.co https://smct.io https://*.smct.io https://*.ringcentral.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com https://www.googletagmanager.com https://cdnjs.cloudflare.com https://fp.zenaps.com https://www.youtube.com https://www.google-analytics.com https://*.google.com https://connect.facebook.net https://bat.bing.com https://widget.trustpilot.com https://s.ytimg.com https://www.googletagservices.com https://*.googleapis.com https://www.facebook.com https://www.googleadservices.com https://*.gstatic.com https://*.gstatic.cn https://www.dwin1.com https://cdn.trackjs.com https://recaptcha.net https://*.sciencebehindecommerce.com https://*.akamaihd.net https://*.microsofttranslator.com https://google.com https://*.trustpilot.com https://*.translate.naver.net https://*.doubleclick.net https://*.google-analytics.com https://sc-static.net https://*.google.co.uk https://google.co.uk https://static.ads-twitter.com https://*.twitter.com https://apps.storystream.ai blob: https://*.abtasty.com https://*.googleapis.com https://ucarecdn.com https://sgtm.www.berghaus.com https://*.upsellit.com https://*.ometria.com https://s1.thcdn.com; style-src 'self' 'unsafe-inline' https://*.thcdn.com https://*.google.com https://*.googleapis.com https://fp.zenaps.com https://cdnjs.cloudflare.com https://www.googletagmanager.com https://*.lpsnmedia.net https://*.liveperson.net https://fonts.googleapis.com https://fonts.smct.co https://fonts.smct.io https://*.ringcentral.com https://hcaptcha.com https://*.hcaptcha.com https://*.googleapis.com https://*.translate.naver.net https://*.microsofttranslator.com https://cdn.parcellab.com https://*.abtasty.com https://*.gstatic.com https://*.googleapis.com https://d7c4jjeuqag9w.cloudfront.net https://*.ometria.com https://s1.thcdn.com; report-to report-endpoint; 1 font-src fonts.gstatic.com use.typekit.net maxcdn.bootstrapcdn.com 'self' data: cdnjs.cloudflare.com fonts.bunny.net cdn.jsdelivr.net data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net www.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com https://www.google.com/recaptcha/ servicepoints.sendcloud.sc c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * www.googletagmanager.com widget.trustpilot.com www.google.com consentcdn.cookiebot.com www.youtube-nocookie.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com p.typekit.net validator.swagger.io ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com log.pinterest.com ssl.google-analytics.com maps.googleapis.com maps.gstatic.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.krale-wholesale.com *.krale.shop static.pay.nl 'self' data: www.snapengage.com lh3.ggpht.com imgsct.cookiebot.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com www.google.com www.gstatic.com t.trackedlink.net assets.pinterest.com maps.googleapis.com ssl.google-analytics.com embed.sendcloud.sc js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com js-agent.newrelic.com bam.nr-data.net bam-cell.nr-data.net servicepoints.sendcloud.sc widget.trustpilot.com storage.googleapis.com www.snapengage.com static.widget.trengo.eu consent.cookiebot.com consentcdn.cookiebot.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com downloads.mailchimp.com maxcdn.bootstrapcdn.com assets.braintreegateway.com fonts.bunny.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.snapengage.com static.widget.trengo.eu 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.adobe.io performance.typekit.net *.sentry.io form-assets.mailchimp.com *.intuit.com *.amazonaws.com log.pinterest.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com bam.nr-data.net bam-cell.nr-data.net www.snapengage.com api.widget.trengo.eu ws-eu.pusher.com consentcdn.cookiebot.com *.krale.shop 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.krale-wholesale.com *.krale.shop 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'none'; connect-src 'self' https: policy.app.cookieinformation.com; font-src https:; frame-src https:; img-src 'self' data: https:; manifest-src 'self' https:; media-src 'self' https:; script-src 'unsafe-inline' https: maps.google.com; style-src 'unsafe-inline' https:; worker-src https:; base-uri https:; form-action https:; frame-ancestors 'self' https:; report-uri https://ing.dk/log-report-uri/reportOnly 1 require-trusted-types-for 'script'; report-uri https://csp.withgoogle.com/csp/uxe-owners-acl/sre_google 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com mcstaging.packersproshop.com www.packersproshop.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.demdex.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de www.google.com *.gstatic.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.payments-amazon.com magefan.com cm.magefan.com 'self' 'unsafe-inline' adobe.com *.affirm.com *.bing.com *.bing.net *.scorecardresearch.com *.cloudfront.net *.cookielaw.org *.google.com.au *.googlesyndication.com *.mathtag.com *.mimecast.com *.zonos.com mcstaging.packersproshop.com www.packersproshop.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com assets.adobedtm.com *.magento-ds.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.magento-datasolutions.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.bing.com d1z2jf7jlzjs58.cloudfront.net *.c212.net *.cookielaw.org *.everestjs.net *.iglobalstores.com *.googletagmanager.com *.googlesyndication.com *.gstatic.com www.google.com *.mathtag.com *.onetrust.com *.scorecardresearch.com *.packersproshop.com *.tiktok.com *.zonos.com acds-events.adobe.io js-agent.newrelic.com mcstaging.packersproshop.com www.packersproshop.com https://hello.zonos.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.magento-datasolutions.com *.magento-ds.com mcstaging.packersproshop.com www.packersproshop.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com api.magento.com *.magento-datasolutions.com *.magento-ds.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.adobedtm.com bam.nr-data.net *.bing.com *.bing.net *.cardinalcommerce.com *.scorecardresearch.com *.cloudfront.net *.cookielaw.org *.demdex.net *.everesttech.net *.google-analytics.com *.googlesyndication.com *.gstatic.com www.google.com *.omtrdc.net *.onetrust.com *.parsely.com *.tiktok.com *.zonos.com sedge.nfl.com mcstaging.packersproshop.com www.packersproshop.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com mcstaging.packersproshop.com www.packersproshop.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://1a78f49d-a75b-466e-a8d0-2a6f25a8e22d.sansec.watch/; report-to report-endpoint; 1 object-src 'none';base-uri 'self';script-src 'nonce-KzlpTReueKYtSDCMvbR5qg' 'strict-dynamic' 'report-sample' 'unsafe-eval' 'unsafe-inline' https: http:;report-uri https://csp.withgoogle.com/csp/gws/other-hp 1 object-src 'none';base-uri 'self';script-src 'nonce-zH92hX-SC0FV8jMm7OwSRA' 'strict-dynamic' 'report-sample' 'unsafe-eval' 'unsafe-inline' https: http:;report-uri https://csp.withgoogle.com/csp/gws/other-hp 1 font-src * data:;img-src * data:;frame-src 'self' *.sevenrooms.com *.doubleclick.net *.smartrecruiters.com *.adyen.com *.pinterest.com *.googleadservices.com *.google.com *.googletagmanager.com *.cardinalcommerce.com sevenrooms.com *.americanexpress.com *.securesuite.co.uk secure7.arcot.com *.rsa3dsauth.co.uk mycardsecure.com www.mycardsecure.com dupe.com *.opentable.com.au;script-src 'self' *.curator.io *.google-analytics.com *.googletagmanager.com *.google.com *.licdn.com *.clarity.ms *.gstatic.com *.facebook.net *.pinimg.com *.smartrecruiters.com *.hotjar.com cdn-cookieyes.com 'unsafe-eval' 'unsafe-inline' data:;script-src-elem 'self' 'unsafe-inline' *.facebook.net *.licdn.com *.google.com *.googletagmanager.com https://www.googletagmanager.com *.googleadservices.com *.google-analytics.com *.gstatic.com *.smartrecruiters.com *.curator.io *.clarity.ms *.pinimg.com *.hotjar.com cdn-cookieyes.com;style-src-elem 'self' *.honey.io *.google.com *.curator.io *.smartrecruiters.com *.facebook.net *.clarity.ms 'unsafe-inline';connect-src 'self' *.facebook.com *.google.com *.google-analytics.com *.googleapis.com melprdwebsite.azurewebsites.net crownkentico-prd-as-csearch.search.windows.net *.pinterest.com *.doubleclick.net *.curator.io *.clarity.ms *.linkedin.com *.datatoolscloud.net.au *.hotjar.io *.googleadservices.com *.googletagmanager.com *.adyen.com *.cookieyes.com cdn-cookieyes.com ws://localhost:12387 wss://ws.hotjar.com https://www.google.com/ data:;report-uri /api/logs/csp-report;report-to csp-endpoint; 1 script-src 'self' 'report-sample' blob: data: https://*.youtube.com https://firebase.googleapis.com https://share.keepshare.info https://static-web.jjdsn.vip https://bitkeep.page https://*.bitkeep.fun https://*.bitget.cloud https://keepshare.xyz https://gasutopia.com https://bitkeep.com https://*.facebook.net https://api.nileex.io https://keepshare.info https://*.google.com https://share.bitkeep.shop https://infragrid.v.network https://*.bitkeep.com https://ta.bitkeep.buzz:8993 https://bitkeep.io https://*.bitkeep.io https://www.google-analytics.com https://fp-constantid.bitkeep.vip https://*.bitkeep.page https://*.bjxnyj.com https://bitkeep.org https://*.bitgetstatic.com https://share.bwb.live https://*.bitkeep.vip https://*.bitget.site https://*.bitgetpro.site https://api.shasta.trongrid.io https://s3.infcrypto.com https://*.bitkeep.me https://*.jjdsn.vip https://*.mytokenpocket.vip https://sun.tronex.io https://goldshare.me https://*.bitget.com https://firebaseinstallations.googleapis.com https://www.googletagmanager.com https://*.googleapis.com https://share.bwb.site https://stats.g.doubleclick.net https://rpc-wallet.broearn.com https://api.trongrid.io https://*.bknode.vip https://cdn.bootcdn.net https://search.imtt.qq.com https://api-web.wwmxd.info https://api-web.wwmxd.site https://www.recaptcha.net https://ordinals.com https://www.gstatic.cn https://www.gstatic.com https://log.noxiaohao.com https://*.geetest.com https://*.geevisit.com https://*.gsensebot.com https://share.bwb.online https://share.bwb.global https://share.bwb.win https://share.bwb.inc https://share.bwb.space https://*.walletconnect.org wss://*.walletconnect.org https://*.walletconnect.com;connect-src 'self' 'report-sample' blob: data: https://*.youtube.com https://firebase.googleapis.com https://share.keepshare.info https://*.bitkeep.fun https://bitkeep.page https://*.bitget.cloud https://keepshare.xyz https://gasutopia.com https://bitkeep.com https://*.facebook.net https://api.nileex.io https://keepshare.info https://*.google.com https://share.bitkeep.shop https://infragrid.v.network https://*.bitkeep.com https://ta.bitkeep.buzz:8993 https://bitkeep.io https://*.bitkeep.io https://www.google-analytics.com https://fp-constantid.bitkeep.vip https://*.bitkeep.page https://*.bjxnyj.com https://bitkeep.org https://*.bitgetstatic.com https://share.bwb.live https://*.bitkeep.vip https://*.bitget.site https://*.bitgetpro.site https://api.shasta.trongrid.io https://s3.infcrypto.com https://*.bitkeep.me https://*.jjdsn.vip https://*.mytokenpocket.vip https://sun.tronex.io https://goldshare.me https://*.bitget.com https://firebaseinstallations.googleapis.com https://www.googletagmanager.com https://*.googleapis.com https://share.bwb.site https://stats.g.doubleclick.net https://rpc-wallet.broearn.com https://api.trongrid.io https://*.bknode.vip https://cdn.bootcdn.net https://search.imtt.qq.com https://api-web.wwmxd.info https://api-web.wwmxd.site https://ordinals.com https://www.gstatic.cn https://www.gstatic.com https://log.noxiaohao.com https://*.geetest.com https://*.geevisit.com https://*.gsensebot.com https://share.bwb.online https://share.bwb.global https://share.bwb.win https://share.bwb.inc https://share.bwb.space https://region1.google-analytics.com https://*.walletconnect.org wss://*.walletconnect.org https://*.walletconnect.com https://cloudflare-eth.com https://eth.llamarpc.com https://api-web.bitkeep.asia https://api-web.bitkeep.biz https://api-web.bitkeep.life https://api-web.chainnear.com https://api-web.bitkeep.fun;frame-src 'self' 'report-sample' https://www.google.com https://www.recaptcha.net https://*.bitget.com https://static-web.jjdsn.vip https://*.geetest.com https://*.geevisit.com https://*.gsensebot.com https://*.walletconnect.org;frame-ancestors 'self' https://bulbaswap.io https://app.bulbaswap.io https://www.bulbaswap.io https://bulba.bknode.vip https://*.bitget.com https://static-web.jjdsn.vip https://www.google.com https://www.recaptcha.net https://*.geetest.com https://*.geevisit.com https://*.gsensebot.com;report-uri https://64ad2bae905b5c797e632276.endpoint.csper.io?v=17; 1 connect-src *; frame-src *; img-src https: data: blob: about: safari-extension: safari-resource: chrome-extension:; worker-src blob: https: 'unsafe-eval' 'unsafe-inline'; script-src https: 'unsafe-eval' 'unsafe-inline'; report-uri https://portfolio.ccpsx.com/api/v1/errors/csp 1 object-src 'none';base-uri 'self';script-src 'nonce-kHXcZK05j_6tumKl5lcLcg' 'strict-dynamic' 'report-sample' 'unsafe-eval' 'unsafe-inline' https: http:;report-uri https://csp.withgoogle.com/csp/gws/other-hp 1 report-uri https://csp.withgoogle.com/csp/youtube_main/strict;base-uri 'self';object-src 'none';script-src 'report-sample' 'nonce-Juk8BZNK_8y5hO7CvzvXaQ' 'unsafe-inline' 'strict-dynamic' https: http: 'unsafe-eval' 1 default-src 'self' 'unsafe-inline' 'unsafe-eval' data: *.acuityplatform.com challenges.cloudflare.com *.cloudfunctions.net *.configcat.com storage.googleapis.com cloudflare.hcaptcha.com cf-assets.hcaptcha.com *.kooth.com global.localizecdn.com *.segment.com *.segment.io *.sentry.io *.usefathom.com *.xenzonegroup.com wss://*.xenzonegroup.com wss://*.twilio.com *.snapchat.com media.twiliocdn.com flex-api.twilio.com; script-src-elem 'self' 'unsafe-inline' data: *.acuityplatform.com challenges.cloudflare.com storage.googleapis.com *.kooth.com global.localizecdn.com *.segment.com *.usefathom.com *.xenzonegroup.com www.googletagmanager.com *.doubleclick.net connect.facebook.net sc-static.net *.snapchat.com media.twiliocdn.com flex-api.twilio.com; connect-src 'self' *.cloudfunctions.net *.configcat.com *.kooth.com global.localizecdn.com *.localizejs.com *.segment.com *.segment.io *.sentry.io *.usefathom.com *.xenzonegroup.com wss://*.xenzonegroup.com wss://*.twilio.com *.analytics.google.com *.google-analytics.com *.snapchat.com media.twiliocdn.com flex-api.twilio.com; img-src * data:; media-src * data:; style-src 'self' 'unsafe-inline' fonts.googleapis.com; font-src * data: chrome-extension: moz-extension: safari-web-extension:; frame-src 'self' vimeo.com *.vimeo.com challenges.cloudflare.com www.googletagmanager.com *.doubleclick.net *.snapchat.com; object-src 'none'; report-uri https://o367623.ingest.sentry.io/api/5691169/security/?sentry_key=d228aa23f64c4234b0ed98ff46a429d3?sentry_environment=csp_header_in_test_environments_or_csp-report-only_header_in_live 1 base-uri 'self'; form-action 'self'; frame-ancestors 'self'; frame-src https://www.googletagmanager.com; 1 default-src 'self' https://snap.licdn.com/ https://www.youtube.com/ *.youtube.com http://www.google-analytics.com https://consent.bumble.com; script-src 'self' 'unsafe-inline' 'report-sample' 'nonce-Vu3MgC09RvfriaonlEs3BA==' https://snap.licdn.com/ https://www.youtube.com/ *.youtube.com http://www.google-analytics.com https://consent.bumble.com; style-src 'self' 'unsafe-inline'; connect-src 'self' https://consent.bumble.com http://www.google-analytics.com; child-src 'self'; font-src 'self' data:; manifest-src 'self'; base-uri 'self'; frame-src 'self' https://snap.licdn.com/ https://www.youtube.com/ *.youtube.com http://www.google-analytics.com https://consent.bumble.com; img-src * data: blob:; media-src * data: blob:; report-uri /jss/csp_report.phtml?token=bumble_team_site&env=production; 1 report-uri https://csp.withgoogle.com/csp/youtube_main/strict;base-uri 'self';object-src 'none';script-src 'report-sample' 'nonce-Vo-KF-ei_T8X7sRbS0q9kA' 'unsafe-inline' 'strict-dynamic' https: http: 'unsafe-eval' 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://www.googletagmanager.com https://www.google-analytics.com https://www.googleadservices.com https://googleads.g.doubleclick.net st.softgamings.com cdn.livechatinc.com www.google.com api.livechatinc.com www.gstatic.com snap.licdn.com bat.bing.com connect.facebook.net mc.yandex.ru www.clarity.ms scripts.clarity.ms consent.cookiebot.com *.softgamings.com; style-src 'self' 'unsafe-inline' fonts.googleapis.com st.softgamings.com *.softgamings.com; font-src 'self' fonts.gstatic.com st.softgamings.com data: *.softgamings.com; img-src 'self' data: https://www.google-analytics.com https://analytics.google.com https://www.googletagmanager.com https://stats.g.doubleclick.net https://pagead2.googlesyndication.com https://www.google.com https://googleads.g.doubleclick.net st.softgamings.com www.facebook.com www.google.ru px.ads.linkedin.com cdn.files-text.com secure.gravatar.com agstatic.com bat.bing.com www.googletagmanager.com *.softgamings.com images.dmca.com; connect-src 'self' https://www.google-analytics.com https://analytics.google.com https://www.google.com https://px.ads.linkedin.com wss://mc.yandex.ru https://z.clarity.ms https://v.clarity.ms https://mc.yandex.ru *.softgamings.com https://hooks.slack.com https://bat.bing.com https://stats.g.doubleclick.net https://pagead2.googlesyndication.com https://www.googletagmanager.com https://googleads.g.doubleclick.net; frame-src 'self' https://www.google.com https://www.googletagmanager.com https://cdn.livechatinc.com https://secure.livechatinc.com https://mc.yandex.ru https://www.clarity.ms *.softgamings.com https://www.youtube.com/ https://consentcdn.cookiebot.com https://bid.g.doubleclick.net; media-src 'self' https://video.softgamings.com *.softgamings.com 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://www.googletagmanager.com *.googleapis.com https://fonts.gstatic.com *.payneglasses.com ka-f.fontawesome.com fonts.googleapis.com *.alicdn.com cdnjs.cloudflare.com vtom.neox-lab.com www.vtlicensing.com *.loginwithamazon.com *.ssl-images-amazon.com https://static.klaviyo.com *.iadvize.com wss://ws.hotjar.com *.google.co.in *.criteo.com *.facebook.com wss://xmpp-ha-alb.iadvize.com *.wikimedia.org *.pexels.com *.staticflickr.com *.defense.gov *.pinimg.com *.istockphoto.com wss://*.iadvize.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de https://plumrocket.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de https://plumrocket.com https://accounts.google.com js.mollie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * self *.payneglasses.com payneglasses.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com https://www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com https://www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net https://images.unsplash.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.payments-amazon.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://www.magezon.com https://www.mollie.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.payneglasses.com static.payneglasses.com payneglasses.com bat.bing.com google.com *.google.com ct.pinterest.com *.alicdn.com *.googleusercontent.com vtom.neox-lab.com www.vtlicensing.com *.loginwithamazon.com storage.needpix.com cdn.pixabay.com c1.peakpx.com cdn.stocksnap.io https://pagead2.googlesyndication.com https://www.googletagservices.com https://d3k81ch9hvuctc.cloudfront.net https://d2xo6khwzbhes8.cloudfront.net *.google.co.in pm.geniusmonkey.com ib.adnxs.com sync.1rx.io eb2.3lift.com ade.clmbtech.com criteo-sync.teads.tv sync-t1.taboola.com rtb-csync.smartadserver.com pixel.rubiconproject.com simage2.pubmatic.com sync.outbrain.com gum.criteo.com c.bing.com contextual.media.net idsync.rlcdn.com ad.360yield.com ads.stickyadstv.com cs.adingo.jp r.casalemedia.com tg.socdm.com cm.g.doubleclick.net x.bidswitch.net sync.targeting.unrulymedia.com *.agkn.com *.criteo.com *.v.fwmrm.net user-sync.fwmrm.net *.adsrvr.org *.yahoo.com match.prod.bidr.io public-prod-dspcookiematching.dmxleo.com *.pubmatic.com *.adform.net *.simpli.fi ad.turn.com pubmatic-match.dotomi.com www.facebook.com pixel-sync.sitescout.com sync.crwdcntrl.net sync.springserve.com sync.srv.stackadapt.com sync.ipredictive.com rtb.openx.net *.iadvize.com wss://ws.hotjar.com *.facebook.com wss://xmpp-ha-alb.iadvize.com *.wikimedia.org *.pexels.com *.staticflickr.com *.defense.gov *.pinimg.com *.istockphoto.com wss://*.iadvize.com https://*.trustpilot.com *.amazonaws.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://rum.hlx.page tagmanager.google.com https://www.googletagmanager.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://accounts.google.com https://www.gstatic.com js.mollie.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.payneglasses.com *.loginwithamazon.com *.ssl-images-amazon.com *.hotjar.com *.iadviz.net static.payneglasses.com payneglasses.com bat.bing.com *.pinimg.com analytics.tiktok.com kit.fontawesome.com *.iadvize.com *.alicdn.com cdnjs.cloudflare.com https://d2xo6khwzbhes8.cloudfront.net https://*.cloudfront.net *.facebook.net cdn.jsdelivr.net unpkg.com vtom.neox-lab.com www.vtlicensing.com cdn.convertcart.com pm.geniusmonkey.com static.criteo.net wss://ws.hotjar.com *.google.co.in *.criteo.com *.facebook.com wss://xmpp-ha-alb.iadvize.com *.wikimedia.org *.pexels.com *.staticflickr.com *.defense.gov *.istockphoto.com wss://*.iadvize.com https://*.trustpilot.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://www.googletagmanager.com tagmanager.google.com *.googleapis.com https://static.klaviyo.com https://accounts.google.com https://www.gstatic.com https://fonts.googleapis.com assets.braintreegateway.com *.payneglasses.com static.payneglasses.com payneglasses.com *.fastsimon.com ka-f.fontawesome.com *.typekit.net *.alicdn.com cdnjs.cloudflare.com cdn.jsdelivr.net unpkg.com vtom.neox-lab.com www.vtlicensing.com *.loginwithamazon.com *.ssl-images-amazon.com accounts.google.com *.iadvize.com wss://ws.hotjar.com *.google.co.in *.criteo.com *.facebook.com wss://xmpp-ha-alb.iadvize.com *.wikimedia.org *.pexels.com *.staticflickr.com *.defense.gov *.pinimg.com *.istockphoto.com wss://*.iadvize.com https://*.trustpilot.com *.stripe.network *.stripecdn.com *.amazon.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.payneglasses.com payneglasses.com *.alicdn.com vtom.neox-lab.com www.vtlicensing.com *.loginwithamazon.com *.ssl-images-amazon.com *.iadvize.com wss://ws.hotjar.com *.google.co.in *.criteo.com *.facebook.com wss://xmpp-ha-alb.iadvize.com *.wikimedia.org *.pexels.com *.staticflickr.com *.defense.gov *.pinimg.com *.istockphoto.com wss://*.iadvize.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com https://www.google-analytics.com www.googleadservices.com analytics.google.com https://www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://*.google-analytics.com https://*.analytics.google.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://accounts.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.payneglasses.com payneglasses.com doubleclick.net *.doubleclick.net bat.bing.com ct.pinterest.com analytics.tiktok.com *.iadvize.com ka-f.fontawesome.com *.alicdn.com cdnjs.cloudflare.com ip-geolocation-ipwhois-io.p.rapidapi.com vtom.neox-lab.com www.vtlicensing.com *.loginwithamazon.com *.ssl-images-amazon.com https://pagead2.googlesyndication.com https://www.googletagservices.com https://a.klaviyo.com https://static-tracking.klaviyo.com *.convertcart.com *.hotjar.com *.hotjar.io wss://ws.hotjar.com *.google.co.in *.criteo.com *.facebook.com wss://xmpp-ha-alb.iadvize.com *.wikimedia.org *.pexels.com *.staticflickr.com *.defense.gov *.pinimg.com *.istockphoto.com wss://*.iadvize.com https://*.cloudfront.net https://*.trustpilot.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com self *.payneglasses.com payneglasses.com http: https: blob: 'self' 'unsafe-inline'; default-src https://*.iadvize.com wss://*.iadvize.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 object-src 'none'; script-src 'self' 'unsafe-inline' https://cdn.matomo.cloud https://heritagefund.matomo.cloud https://cdn.ckeditor.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://player.vimeo.com https://heritagefund.matomo.cloud/; script-src-attr 'self' 'unsafe-inline'; script-src-elem 'self' 'unsafe-inline' https://cdn.matomo.cloud https://heritagefund.matomo.cloud https://cdn.ckeditor.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://player.vimeo.com; style-src 'self' 'unsafe-inline' https://p.typekit.net; style-src-attr 'self' 'unsafe-inline'; style-src-elem 'self' 'unsafe-inline' https://p.typekit.net/; frame-ancestors 'self' 1 script-src 'unsafe-inline' 'unsafe-eval' https:; style-src * 'unsafe-inline' 'unsafe-eval'; object-src 'none'; base-uri 'none'; worker-src 'self' blob:; frame-ancestors 'self'; report-to br.loccitaneaubresil.com; 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' cdn.jsdelivr.net cdnjs.cloudflare.com www.googletagmanager.com www.google-analytics.com pagead2.googlesyndication.com www.googleadservices.com www.gstatic.com securepubads.g.doubleclick.net use.typekit.net www.youtube.com s.ytimg.com js.hsforms.net www.googletagservices.com www.google.com ep2.adtrafficquality.google tpc.googlesyndication.com; style-src 'self' 'unsafe-inline' cdn.jsdelivr.net cdnjs.cloudflare.com fonts.googleapis.com use.typekit.net p.typekit.net; font-src 'self' data: fonts.gstatic.com cdn.jsdelivr.net cdnjs.cloudflare.com use.typekit.net; img-src 'self' data: *; media-src 'self' https://video.aapg.org blob: data:; connect-src 'self' * https://video.aapg.org; frame-src *; object-src 'none'; base-uri 'self'; form-action *; frame-ancestors *; 1 script-src-elem 'self' *.googletagmanager.com https://*.mopinion.com https://integration.occ7.mtel.eu https://connect.facebook.net https://snap.licdn.com https://www.clarity.ms https://c.clarity.ms/ https://www.youtube.com https://static.doubleclick.net https://api.evolveip.eu/ChatWebAzure/EipChat.js 'nonce-PLhqb//HHnox2AdhIuodXCwhZb6gFBB1iu5w8kBa8Mw='; script-src 'self' 'unsafe-eval' *.googletagmanager.com https://www.google-analytics.com https://connect.facebook.net 'sha256-TqjM/ocl9Ih4hsJxBuYJi9DiPkAJnBID1b5nkiBEnYI=' 'sha256-vemytl4W5Qmww8+4p7ijbNPmvDbs6GPIf7CXCwtOWgc=' 'nonce-PLhqb//HHnox2AdhIuodXCwhZb6gFBB1iu5w8kBa8Mw='; report-uri /umbraco/api/csp/report; default-src 'none'; font-src 'self' data: https://fonts.gstatic.com https://cdn.faceworks.nl https://*.mopinion.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://cdn.jsdelivr.net https://fonts.mopinion.com https://edge.cookieconsent.io; img-src 'self' mijn.s-bb.nl *.googletagmanager.com px.ads.linkedin.com https://www.facebook.com https://edge.cookieconsent.io https://www.toegankelijkheidsverklaring.nl; form-action 'self'; base-uri 'self'; frame-ancestors 'self'; frame-src 'self' youtube.com www.youtube.com; manifest-src 'self'; connect-src 'self' https://*.google-analytics.com https://*.mopinion.com https://*.clarity.ms https://api.cookieconsent.io https://px.ads.linkedin.com https://connect.facebook.net https://api.evolveip.eu https://ukaz-web01f.ccaas.enghouse.cloud/scripts/ChatExtension.dll 1 frame-ancestors 'self' localhost *.nexpart.com nexpart.com *.pacecomputer.com *.lordco.com prostockautoparts.com *.shopcontroller.com *.lankar.com lankar-customer-sandbox.azurewebsites.net *.nexpartqa.com nexpartqa.com *.nexpartuat.com nexpartuat.com www.davesmith.com s1.ariba.com acdelco-catalog.dstcloud.com nexcat.com www.nexcat.com usglobalautomotive.com deets.feedreader.com *.networktoolcat.com; report-uri https://www.nexpart.com/csp_violation.php 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' cdnjs.cloudflare.com *.google-analytics.com www.2checkout.com connect.facebook.net *.google.com www.googletagmanager.com www.gstatic.com *.amazon-adsystem.com; style-src 'self' 'unsafe-inline' cdnjs.cloudflare.com fonts.googleapis.com; img-src 'self' data: librarika.com covers.librarika.com:8443 storage101.lon3.clouddrive.com *.ssl.cf3.rackcdn.com *.media-amazon.com *.ssl-images-amazon.com *.amazon-adsystem.com *.amazon.com *.gstatic.com *.google-analytics.com *.google.com; font-src 'self' data: fonts.gstatic.com; frame-src *.librarika.com www.2checkout.com *.facebook.com *.google.com *.amazon-adsystem.com *.youtube.com; connect-src 'self' *.google.com www.google-analytics.com; object-src 'none'; report-uri https://5e5aa7c5f482dc373380fd2db250ce83.report-uri.com/r/d/csp/enforce 1 default-src 'self'; frame-ancestors 'self'; 1 style-src *.adobe.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com unsafe-inline assets.braintreegateway.com *.nosto.com *.nos.to https://services.postcodeanywhere.co.uk https://api.agechecked.com https://cdnjs.cloudflare.com *.hartsofstur.com https://fonts.googleapis.com *.cloudfront.net https://chat.system.gnatta.com https://*.fly.dev maxcdn.bootstrapcdn.com *.superpayments.com *.stripe.com *.trustpilot.com *.tagmanager.google.com *.googletagmanager.com fonts.googleapis.com *.typeform.com *.agechecked.com *.bootstrapcdn.com *.braintreegateway.com *.cloudflare.com d21m4dsqdd3b9h.cloudfront.net delight-custom-plugins.fly.dev *.disquscdn.com *.fontawesome.com *.gnatta.com *.googleapis.com *.gstatic.com *.postcodeanywhere.co.uk *.typekit.net 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.googleapis.com *.gstatic.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com https://the.sciencebehindecommerce.com webchat.dotdigital.com webchat.staging.dotdigital.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.nosto.com *.nos.to www.google.co.uk *.bing.net *.noibu.com *.onetrust.com www.google.com.ua www.google.it www.google.nl https://services.postcodeanywhere.co.uk https://cookie-cdn.cookiepro.com https://privacyportal.cookiepro.com https://r.lr-ingest.io https://api.agechecked.com https://stats.g.doubleclick.net https://bam-cell.nr-data.net https://bam.nr-data.net *.google-analytics.com wss://input.noibu.com https://api.livechatinc.com https://api-us-st.smartassistant.com *.amazonaws.com *.hartsofstur.com *.facebook.com *.facebook.com/tr/ https://input.noibu.com *.execute-api.us-east-1.amazonaws.com https://bat.bing.com https://*.googleapis.com https://*.gstatic.com https://*.clarity.ms https://c.bing.com https://analytics.tiktok.com https://chat.system.gnatta.com https://*.sentry.io https://*.delightglobal.io https://*.ip-api.com https://*.bing-int.com q4g4k4pw47biltffyqrfab7q7m0jaagm.lambda-url.ap-south-1.on.aws *.superpayments.com *.stripe.com stripe.com cognito-idp.eu-west-2.amazonaws.com segment.com *.segment.com *.segmentapis.com statsig.com *.statsig.com statsigapi.net *.statsigapi.net featuregates.org *.featuregates.org statsigcdn.com *.statsigcdn.com featureassets.org *.featureassets.org assetsconfigcdn.org *.assetsconfigcdn.org prodregistryv2.org *.prodregistryv2.org cdn.seondf.com *.seondnsresolve.com *.seondfresolver.com *.deviceinfresolver.com *.seonintelligence.com *.trustpilot.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.com *.klaviyo.com *.clarity.ms *.pinterest.com *.pinimg.com *.doubleclick.net *.run.app *.typeform.com *.awinblackfriday.com *.cloudflare.com *.cookiepro.com d21m4dsqdd3b9h.cloudfront.net delight-custom-plugins.fly.dev *.disqus.com gnattawatchtower.blob.core.windows.net *.googleadservices.com *.jquery.com *.kelkoogroup.net *.liadm.com *.samsung.com *.sciencebehindecommerce.com *.storyblok.com *.tiktokw.us *.wepowerconnections.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; child-src *.awin1.com *.zenaps.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.agechecked.com *.awin1.com *.bing.com *.braintreegateway.com *.cardinalcommerce.com *.cloudflare.com *.cookiepro.com d21m4dsqdd3b9h.cloudfront.net delight-custom-plugins.fly.dev delight-s3-bucket.s3.eu-west-2.amazonaws.com *.disquscdn.com *.disqus.com *.dotdigital-pages.com *.doubleclick.net *.dwin1.com *.facebook.com *.facebook.net *.gnatta.com gnattawatchtower.blob.core.windows.net *.googleadservices.com *.googleapis.com *.google.com *.googleoptimize.com *.googletagmanager.com *.gstatic.com *.kelkoogroup.net *.kk-resources.com *.liadm.com *.newrelic.com *.noibu.com *.nosto.com *.paypal.com *.paypalobjects.com *.pcapredict.com *.pinimg.com *.postcodeanywhere.co.uk *.pricerunner.com *.roeyecdn.com *.roeye.com *.sciencebehindecommerce.com *.stripe.com *.studentbeans.com *.superpayments.com *.tiktok.com *.trackedlink.net *.trackedweb.net *.trustpilot.com *.viglink.com *.youtube.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; base-uri *.cookiepro.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; report-uri https://e10203ef-faa6-4c8d-93a7-55d820287a84.sansec.watch/; report-to report-endpoint; 1 default-src 'self'; base-uri 'self'; font-src 'self' https: data:; img-src 'self' data: https:; object-src 'none'; style-src 'self' https: 'unsafe-inline'; connect-src 'self' https:; manifest-src https://s3.amazonaws.com/galore-assets/manifest.json; frame-src 'self' https://js.stripe.com https://www.recaptcha.net/ https://www.facebook.com/ https://bid.g.doubleclick.net; frame-ancestors 'self' https://www.care.com/ https://getgalore.com/; script-src 'self' https: 'unsafe-inline' http://cdn.mxpnl.com/libs/mixpanel-2.2.min.js http://connect.facebook.net/en_US/sdk.js https://connect.facebook.net/en_US/fbevents.js https://connect.facebook.net/en_US/sdk.js; upgrade-insecure-requests; report-uri https://o466311.ingest.sentry.io/api/6004104/security/?sentry_key=2c284ff228ac4d0e8b8ad9ea17497eee&sentry_release=galore-mfe@v18.267.1&sentry_environment=prod 1 default-src 'self' 'unsafe-inline' data: *.marianatek.com *.cookielaw.org *.chilipiper.com *.googletagmanager.com *.google.com *.gstatic.com *.cloudflare.com *.youtube.com *.youtube-nocookie.com *.vimeo.com *.licdn.com *.facebook.net *.clarity.ms *.google-analytics.com *.hs-scripts.com *.doubleclick.net unpkg.com *.wistia.net;upgrade-insecure-requests; 1 script-src 'nonce-DipeUU0tHdePFLEO2-n8LA' 'report-sample' 'strict-dynamic' 'unsafe-eval' 'unsafe-inline' http: https:; object-src 'none'; report-uri https://csp.withgoogle.com/csp/static-on-bigtable; base-uri 'none' 1 base-uri 'self';script-src 'self' *.aliyun.com *.alicdn.com *.qwen.ai *.alibaba.com googleads.g.doubleclick.net www.googletagmanager.com www.google.com *.cloudflare.com appleid.cdn-apple.com 'unsafe-inline' 'unsafe-eval' 'report-sample' https: http: 'nonce-Mvvh-Pd7AXr3O8iEmEUKaA' 'Strict-Dynamic' 'unsafe-hashes';frame-src 'self' *.aliyun.com *.alicdn.com td.doubleclick.net *.alibaba-inc.com qwenlm.io *.alibabacloud.com www.googletagmanager.com www.google.com *.cloudflare.com appleid.cdn-apple.com;worker-src blob: 'self';object-src 'none';frame-ancestors 'self' *.qwen.ai;report-uri /report-csp 1 default-src https://*.hint.com 'self' https://static.hsappstatic.net; img-src 'self' https://*.hint.com https://www.facebook.com https://app.hubspot.com https://*.hsforms.com https://avatars.hubspot.net https://static.hsappstatic.net https://www.google.com https://www.google.com https://t.co https://www.google-analytics.com https://analytics.twitter.com https://facebook.com https://heapanalytics.com https://p.typekit.net https://px.ads.linkedin.com https://www.google.com/ads https://www.facebook.com/tr https://track.hubspot.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://cdnjs.cloudflare.com https://www.gstatic.com https://www.google.com/recaptcha/enterprise.js https://313589.fs1.hubspotusercontent-na1.net https://platform.twitter.com https://platform.linkedin.com/in.js https://js.hsleadflows.net https://script.hotjar.com https://www.googletagmanager.com https://snap.licdn.com https://static.hotjar.com https://static.hsappstatic.net https://js.hs-scripts.com https://app.hubspot.com https://www.google-analytics.com https://static.ads-twitter.com https://cdn.heapanalytics.com https://connect.facebook.net https://my.hellobar.com https://js.hs-analytics.net https://js.hs-banner.com https://js.hscollectedforms.net https://js.hsadspixel.net https://hsleadflows.net https://googleads.g.doubleclick.net; style-src 'self' 'unsafe-inline' https://static.hsappstatic.net https://cdnjs.cloudflare.com https://fonts.googleapis.com https://www.gstatic.com https://use.typekit.net https://cdn2.hubspot.net https://p.typekit.net https://fast.fonts.net https://px.ads.linkedin.com; object-src 'self'; font-src 'self' https://2562809.fs1.hubspotusercontent-na1.net https://cdnjs.cloudflare.com https://fonts.gstatic.com https://cdn2.hubspot.net https://use.typekit.net; connect-src 'self' https://forms.hscollectforms.net https://forms.hscollectforms.net https://js.hs-banner.com https://api.hubapi.com https://www.google-analytics.com https://*.hubspot.com https://stats.g.doubleclick.net https://forms.hscollectedforms.net; frame-src https://platform.twitter.com https://www.google.com 1 default-src 'self'; style-src 'nonce-faa0db4c-c904-48af-819f-b844172fa73b' https://accounts.google.com 'unsafe-hashes' 'sha256-47DEQpj8HBSa+/TImW+5JCeuQeRkm5NMpJWZG3hSuFU=' https://*.dealoo.ch; script-src 'nonce-faa0db4c-c904-48af-819f-b844172fa73b' https://challenges.cloudflare.com https://storage.googleapis.com https://portal.zakeke.com https://*.dealoo.ch; img-src 'self' https://www.apfelkiste.ch https://cms-data.apfelkiste.ch data: blob: https://i.ytimg.com https://i.vimeocdn.com https://googleads.g.doubleclick.net https://www.google.com https://www.google.de https://www.google.ch https://www.google.fr https://*.dealoo.ch; worker-src 'self' blob:; connect-src 'self' https://devnull.apfelkiste.ch https://www.google.com https://accounts.google.com https://apis.google.com https://api.dealoo.ch https://rumdash.io https://api.zakeke.com https://*.dealoo.ch; frame-src 'self' https://www.youtube.com https://player.vimeo.com https://challenges.cloudflare.com https://accounts.google.com https://www.google.com https://portal.zakeke.com/; object-src 'self'; font-src 'self'; media-src 'self' https://cms-data.apfelkiste.ch; child-src 'self' blob:; frame-ancestors 'self' https://cms.apfelkiste.ch; report-uri https://devnull.apfelkiste.ch/api/8/security/?sentry_key=291d0d843488451caadd66b48b4a6ae4 1 default-src 'none'; form-action 'none'; frame-ancestors 'none'; script-src 'report-sha256'; report-uri https://cnty.report-uri.com/r/d/csp/wizard 1 default-src 'self'; script-src 'self' 'nonce-ZmYxODM5NjYtZTMyOC00YTMxLTlhODItYzYxZTdhODJiZWYz' 'strict-dynamic' ; style-src 'self' 'unsafe-inline' 'nonce-ZmYxODM5NjYtZTMyOC00YTMxLTlhODItYzYxZTdhODJiZWYz' https://fonts.googleapis.com https://myhealthatvanderbilt.com; style-src-attr 'self' 'unsafe-inline'; img-src 'self' blob: data: https://*.files.vanderbilthealth.com https://api.krames.com; font-src 'self' https://fonts.gstatic.com; object-src 'self' https://*.files.vanderbilthealth.com; connect-src 'self' https://edge.adobedc.net http://*.mktoresp.com http://*.swiftypecdn.com; frame-src https://myhealthatvanderbilt.com https://play.vidyard.com https://www.youtube-nocookie.com; base-uri 'self'; form-action 'self'; frame-ancestors 'self'; block-all-mixed-content; upgrade-insecure-requests; report-uri /api/v1/csp-report; report-to csp-endpoint; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.cloudflare.com *.twitter.com *.twimg.com *.trustedshops.com *.googleapis.com 'unsafe-inline' data: *.channelsight.com *.bazaarvoice.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.twitter.com *.facebook.com *.snapchat.com *.tiktok.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com *.twitter.com s.amazon-adsystem.com *.facebook.com *.doubleclick.net insight.adsrvr.org *.filestackapi.com *.addthis.com flexfaceoffsweeps.azurewebsites.net match.adsrvr.org viewinyourspace.com *.viewinyourspace.com *.myepigraph.com playcanv.as *.snapchat.com *.clinch.co *.pinterest.com https://recaptcha.google.com/recaptcha/ *.dotdigital-pages.com *.dotdigital.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src 'self' data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net data: *.bird.eu *.cloudflare.com *.klarna.com *.googleadservices.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.bazaarvoice.com *.google.com *.taboola.com *.facebook.com *.facebook.net *.hubspot.com *.hsforms.com r.turn.com *.adnxs.com pixel.mediaiqdigital.com *.gravatar.com *.channelsight.com cscoreproweustor.blob.core.windows.net *.skil.com *.googleapis.com *.doubleclick.net *.seeitinyourspace.com *.pinterest.com *.nextdoor.com *.reddit.com insight.adsrvr.org *.ispot.tv egopowerplus.com *.egopowerplus.com egopowerplus.com.au *.flexpowertools.com pixel.roymorgan.com *.myepigraph.com *.intentiq.com edge.curalate.com *.linkedin.com *.trackedlink.net *.ddlnk.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com datadash.egopowerplus.com datadash.skil.com *.cloudflare.com *.twitter.com *.google-analytics.com *.twimg.com *.gstatic.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.bazaarvoice.com *.filestackapi.com *.facebook.net *.crazyegg.com js.hs-scripts.com *.taboola.com js.adsrvr.org js.hs-analytics.net js.hs-banner.com js.hscollectedforms.net *.googleapis.com geoip-js.com secure-ds.serving-sys.com *.adnxs.com bs.serving-sys.com *.addthis.com *.addthisedge.com z.moatads.com cscoreproweustor.blob.core.windows.net flexsweepstakes2022.azurewebsites.net js.monitor.azure.com edge.curalate.com ipinfo.io *.tiktok.com sc-static.net *.channelsight.com unpkg.com *.jsdelivr.net viewinyourspace.com *.viewinyourspace.com *.cookielaw.org *.addevent.com *.pinimg.com *.nextdoor.com *.crwdcntrl.com *.crwdcntrl.net mjca-yijws.global.ssl.fastly.net cdn.480app.com cdn.nmgassets.com *.clinch.co *.vimeo.com *.redditstatic.com *.snapchat.com adriano-au.avanser.com *.amazon-adsystem.com *.licdn.com *.pinterest.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://egopowerplus.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.cloudflare.com *.googleapis.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.bazaarvoice.com cscoreproweustor.blob.core.windows.net *.channelsight.com cdn.jsdelivr.net assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com api.bazaarvoice.com *.vimeo.com vod-progressive.akamaized.net 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.cloudflare.com *.twitter.com *.twimg.com *.bazaarvoice.com *.crazyegg.com forms.hubspot.com *.channelsight.com *.doubleclick.net *.taboola.com secure-ds.serving-sys.com viewinyourspace.com *.viewinyourspace.com chervon-website-api.herokuapp.com chervon-website-api-dev.herokuapp.com *.jotform.com dc.services.visualstudio.com *.addthis.com edge.curalate.com geoip-js.com *.hsforms.com *.facebook.com *.tiktok.com *.snapchat.com *.cookielaw.org *.rain-staging.com *.seeitinyourspace.com *.gstatic.com blob: *.googleapis.com *.pinterest.com cdn.nmgassets.com jdl.nmgplatform.com colrep.sitelabweb.com lm.serving-sys.com us-central1-epigraph-product-configurator.cloudfunctions.net *.intentiq.com *.flexpowertools.com *.skil.com *.egopowerplus.com *.linkedin.com s.amazon-adsystem.com ara.paa-reporting-advertising.amazon js.monitor.azure.com *.reddit.com *.redditstatic.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 object-src 'none'; script-src 'unsafe-inline' 'unsafe-eval' 'strict-dynamic' https: http: 'nonce-rI4dYApAVKK_8GgAZwzpO-ELPuiGVP7z'; base-uri 'none' 1 script-src 'self' www.googletagmanager.com googleads.g.doubleclick.net bat.bing.com snap.licdn.com app.termly.io challenges.cloudflare.com ep2.adtrafficquality.google s.adroll.com s.pinimg.com securepubads.g.doubleclick.net visit.ws static.cloudflareinsights.com assets.pinterest.com connect.facebook.net d.adroll.com pagead2.googlesyndication.com scripts.sirv.com ct.pinterest.com; style-src 'self' www.gstatic.com use.typekit.net p.typekit.net; img-src 'self' data: images.opumo.com www.googletagmanager.com bat.bing.com d.adroll.com www.google.com px.ads.linkedin.com scontent-man2-1.cdninstagram.com www.facebook.com www.gravatar.com scontent-man2-1.xx.fbcdn.net ep1.adtrafficquality.google www.google.co.uk www.google.com.au connect.facebook.net ipv4.d.adroll.com log.pinterest.com pagead2.googlesyndication.com translate.google.com www.google.al www.google.be www.google.ca www.google.co.kr www.google.com.ph www.google.de www.google.ie www.google.is www.google.je www.google.nl www.google.pl www.google.se; font-src 'self' data: use.typekit.net; connect-src app.termly.io ct.pinterest.com ep1.adtrafficquality.google bat.bing.com px.ads.linkedin.com region1.google-analytics.com www.google-analytics.com www.google.com pagead2.googlesyndication.com www.facebook.com www.opumo.com bat.bing.net csi.gstatic.com scontent-man2-1.cdninstagram.com us.consent.api.termly.io visit.ws; media-src images.opumo.com; frame-src googleads.g.doubleclick.net ct.pinterest.com ep2.adtrafficquality.google www.googletagmanager.com pagead2.googlesyndication.com visit.ws www.google.com cm.g.doubleclick.net; manifest-src 'self'; report-uri https://opumo.report-uri.com/r/d/csp/wizard 1 object-src 'none'; base-uri 'self'; script-src 'self' 'nonce-aQVSsK4K276ph62_8lTXPQ' 'unsafe-inline' 'unsafe-eval' https://*.msauth.net https://*.msftauth.net https://*.msftauthimages.net https://*.msauthimages.net https://*.msidentity.com https://*.microsoftonline-p.com https://*.microsoftazuread-sso.com https://*.azureedge.net https://*.outlook.com https://*.office.com https://*.office365.com https://*.microsoft.com https://*.bing.com 'report-sample'; report-uri https://csp.microsoft.com/report/ESTS-UX-All 1 default-src https:;script-src 'self' 'unsafe-inline' 'unsafe-eval' https://cc.cdn.civiccomputing.com https://www.googletagmanager.com https://www.google-analytics.com https://connect.facebook.net https://reports.hrmdirect.com https://*.etcconnect.com;style-src 'self' 'unsafe-inline' https://hello.myfonts.net https://reports.hrmdirect.com https://www.highend.com https://fonts.googleapis.com https://*.etcconnect.com;object-src 'none';img-src 'self' data: https://www.google-analytics.com https://www.facebook.com https://*.etcconnect.com;report-uri /Handlers/CspReports.ashx?type=REPORTONLY; 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://cdn-cookieyes.com https://js.intercomcdn.com https://js.stripe.com https://m.stripe.network https://static.doubleclick.net https://widget.intercom.io https://widget.trustpilot.com https://www.google.com https://www.googletagmanager.com https://www.gstatic.com https://www.youtube.com https://www.google.ad https://www.google.ae https://www.google.al https://www.google.am https://www.google.as https://www.google.at https://www.google.az https://www.google.ba https://www.google.be https://www.google.bf https://www.google.bg https://www.google.bi https://www.google.bj https://www.google.bs https://www.google.bt https://www.google.by https://www.google.ca https://www.google.cat https://www.google.cd https://www.google.cf https://www.google.cg https://www.google.ch https://www.google.ci https://www.google.cl https://www.google.cm https://www.google.cn https://www.google.co.id https://www.google.co.il https://www.google.co.in https://www.google.co.jp https://www.google.co.kr https://www.google.co.nz https://www.google.co.th https://www.google.co.uk https://www.google.co.za https://www.google.com https://www.google.com.ar https://www.google.com.au https://www.google.com.bd https://www.google.com.br https://www.google.com.co https://www.google.com.eg https://www.google.com.hk https://www.google.com.mm https://www.google.com.mx https://www.google.com.my https://www.google.com.ng https://www.google.com.np https://www.google.com.pe https://www.google.com.ph https://www.google.com.pk https://www.google.com.sa https://www.google.com.sg https://www.google.com.tr https://www.google.com.tw https://www.google.com.ua https://www.google.com.uy https://www.google.com.vn https://www.google.cz https://www.google.de https://www.google.dk https://www.google.es https://www.google.fi https://www.google.fr https://www.google.gr https://www.google.hr https://www.google.hu https://www.google.ie https://www.google.is https://www.google.it https://www.google.lt https://www.google.lu https://www.google.lv https://www.google.nl https://www.google.no https://www.google.pl https://www.google.pt https://www.google.ro https://www.google.rs https://www.google.ru https://www.google.se https://www.google.si https://www.google.sk https://static.hotjar.com https://challenges.cloudflare.com https://*.b-cdn.net; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://cdn-cookieyes.com https://www.youtube.com https://*.b-cdn.net ; font-src 'self' https://fonts.gstatic.com https://fonts.intercomcdn.com; img-src 'self' data: https://cdn-cookieyes.com https://challenges.cloudflare.com https://www.youtube.com https://downloads.intercomcdn.com https://js.intercomcdn.com https://i.ytimg.com https://www.google.de https://www.google.ad https://www.google.ae https://www.google.al https://www.google.am https://www.google.as https://www.google.at https://www.google.az https://www.google.ba https://www.google.be https://www.google.bf https://www.google.bg https://www.google.bi https://www.google.bj https://www.google.bs https://www.google.bt https://www.google.by https://www.google.ca https://www.google.cat https://www.google.cd https://www.google.cf https://www.google.cg https://www.google.ch https://www.google.ci https://www.google.cl https://www.google.cm https://www.google.cn https://www.google.co.id https://www.google.co.il https://www.google.co.in https://www.google.co.jp https://www.google.co.kr https://www.google.co.nz https://www.google.co.th https://www.google.co.uk https://www.google.co.za https://www.google.com https://www.google.com.ar https://www.google.com.au https://www.google.com.bd https://www.google.com.br https://www.google.com.co https://www.google.com.eg https://www.google.com.hk https://www.google.com.mm https://www.google.com.mx https://www.google.com.my https://www.google.com.ng https://www.google.com.np https://www.google.com.pe https://www.google.com.ph https://www.google.com.pk https://www.google.com.sa https://www.google.com.sg https://www.google.com.tr https://www.google.com.tw https://www.google.com.ua https://www.google.com.uy https://www.google.com.vn https://www.google.cz https://www.google.de https://www.google.dk https://www.google.es https://www.google.fi https://www.google.fr https://www.google.gr https://www.google.hr https://www.google.hu https://www.google.ie https://www.google.is https://www.google.it https://www.google.lt https://www.google.lu https://www.google.lv https://www.google.nl https://www.google.no https://www.google.pl https://www.google.pt https://www.google.ro https://www.google.rs https://www.google.ru https://www.google.se https://www.google.si https://www.google.sk https://*.b-cdn.net; media-src 'self' https://*.b-cdn.net ; connect-src 'self' https://api-iam.intercom.io https://cdn-cookieyes.com https://challenges.cloudflare.com https://googleads.g.doubleclick.net https://m.stripe.com https://widget.trustpilot.com https://www.youtube.com wss://nexus-websocket-a.intercom.io ; frame-src 'self' https://www.youtube.com https://challenges.cloudflare.com https://js.stripe.com https://widget.trustpilot.com ; object-src 'none'; form-action 'self'; base-uri 'self'; frame-ancestors 'none' 1 script-src 'nonce-VwFy203IrN1yR/kFVGabmQ==' 'strict-dynamic' 'unsafe-eval' 'unsafe-inline' https: 'report-sample'; base-uri 'none'; report-uri https://events.mercadolibre.com/csp/reports?identifier=w1qeU4XKVwGbQGBuEKyE3KhFBIpr5IZSIaRiTowMc8UG7kU18vRsmBTEKL2krAj23LIS&policy_id=26548&user_id=&request_id=ebc4d134-9953-4299-aba7-39c626c521e7; report-to csp-endpoint-wqeuxkvwgbqgbuekyekhfbiprizsiaritowmcugkuvrsmbteklkrajlis; object-src https://http2.mlstatic.com/ https://mlstaticquic-a.akamaihd.net/; frame-ancestors 'self' https://*.mercadolibre.cl:* https://*.mercadolibre.com:* https://*.mercadolibre.com.ve:* https://*.mercadolibre.com.ar:* https://*.mercadolivre.com.br:* https://*.mercadolibre.com.co:* https://*.mercadolibre.com.ec:* https://*.mercadolibre.com.mx:* https://*.mercadolibre.com.pe:* https://*.mercadolibre.com.uy:* https://*.mercadopago.cl:* https://*.mercadopago.com.ar:* https://*.mercadopago.com.br:* https://*.mercadopago.com.co:* https://*.mercadopago.com.mx:* https://*.mercadopago.com.pe:* https://*.mercadopago.com.uy:* https://*.mercadopago.com.ve:* https://*.mercadopago.com:* https://*.adminml.com:* https://*.mercadolibre.co.cr:* https://*.mercadolibre.com.pa:* https://*.mercadolibre.com.do:* https://*.mercadolibre.com.bo:* https://*.mercadolibre.com.py:* https://*.mercadolibre.com.gt:* https://*.mercadolibre.com.hn:* https://*.mercadolibre.com.ni:* https://*.mercadolibre.com.sv:* https://*.mercadopago.com.ec:* https://*.portalinmobiliario.com:* https://*.mercadolivre.com:* 1 object-src 'none'; connect-src 'self' *.puretaboo.com cognito-identity.us-east-1.amazonaws.com backend.getbeamer.com *.comm100.io *.algolia.net insights.algolia.io *.algolianet.com *.gammaapis.com *.gammacdn.com analytics.google.com *.google-analytics.com adservice.google.com *.analytics.google.com *.doubleclick.net *.pubnub.com *.lovense.com *.handyfeeling.com www.gammaentertainment.com *.tiypa.com *.recombee.us dasasoveekepl.cloudfront.net capture.trackjs.com ws: jlduihq7lrcdxgw4vrndhdfcsq.appsync-api.us-east-1.amazonaws.com tcs4u525zrg5hnnoe5kzndxuaq.appsync-api.us-east-1.amazonaws.com xtnzefcqrb.execute-api.us-east-1.amazonaws.com 2aed6ghjsb4436qtebuqk3gfzq0xeauy.lambda-url.us-east-1.on.aws lzzos7clo5.execute-api.us-east-1.amazonaws.com *.izooto.com www.idealgasm.com 3tt0xhv5u7.execute-api.us-east-1.amazonaws.com; form-action 'self' *.puretaboo.com join.gammasecure.com; script-src 'self' *.puretaboo.com app.getbeamer.com static.getbeamer.com blob: vue.comm100.com standby.comm100vue.com *.gammacdn.com www.google-analytics.com www.googletagmanager.com www.gstatic.com www.google.com code.jquery.com d3a3ewgd1iewwz.cloudfront.net cdn.izooto.com 'unsafe-eval' 'unsafe-inline'; frame-src 'self' *.puretaboo.com push.getbeamer.com app.getbeamer.com www.google.com *.doubleclick.net cdn.izooto.com *.banhq.com; report-uri https://csp-report.browser-intake-datadoghq.com/api/v2/logs?dd-api-key=pub787d5a6164b329b26f2e4f7956bbed10&dd-evp-origin=content-security-policy&ddsource=csp-prod&ddtags=CSP-Prod; 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://altinea.fr https://cdn.astra.com https://static.elfsight.com https://core.service.elfsight.com https://www.google.com https://www.gstatic.com https://www.googletagmanager.com https://www.google-analytics.com https://www.google.com/recaptcha/api.js; style-src 'self' 'unsafe-inline' https://altinea.fr https://cdn.astra.com https://fonts.googleapis.com https://use.fontawesome.com/releases/v6.6.0/css/v4-shims.css https://use.fontawesome.com/releases/v6.6.0/css/all.css https://use.typekit.net/gme6kbk.css https://p.typekit.net/gme6kbk.css; img-src 'self' https://altinea.fr data: *.webp; font-src 'self' https://altinea.fr/wp-content/ https://fonts.gstatic.com https://use.fontawesome.com/releases/v6.6.0/fonts/ https://use.typekit.net/fonts/ data:; connect-src 'self' https://altinea.fr https://core.service.elfsight.com https://www.google.com; media-src 'self' https://altinea.fr; frame-src 'self' https://altinea.fr https://www.google.com; object-src 'none'; base-uri 'self'; form-action 'self'; upgrade-insecure-requests; report-uri https://votreservice.report-uri.com/r/d/csp/reportOnly; 1 default-src 'self'; script-src 'self' https://agrilife.org; style-src 'self' 'unsafe-inline'; img-src 'self' data: https://agrilife.org; 1 default-src *.pharm24.gr *.skroutz.gr static.zdassets.com data:; frame-src *.pharm24.gr virtual-assistants.gr *.googletagmanager.com *.skroutz.gr *.hotjar.com *.checkout.com *.dco.gr *.disqus.com *.linkwi.se *.adsrvr.org *.google.com *.googlesyndication.com *.agkn.com *.facebook.net *.facebook.com *.youtube.com *.cookiebot.com *.aimtell.com; img-src * data: *.pharm24.gr *.youtube.com *.facebook.com trustmark.gr; script-src 'self' 'unsafe-inline' *.pharm24.gr *.skroutz.gr *.google.com *.debugbear.com virtual-assistants.gr secure.dcomodo.net *.vc-portal.com *.skroutz.gr *.gstatic.com *.checkout.com salesmanago.com *.salesmanago.com *.saleago.com bat.bing.com *.clarity.ms *.adman.gr *.hotjar.com *.googleapis.com *.google.com *.cloudflareinsights.com *.cloudflare.com *.disquscdn.com *.shareaholic.com *.shareaholic.net *.stackpathcdn.com *.cloudfront.net *.adsrvr.org *.instagram.com *.ampproject.org *.googlesyndication.com *.disqus.com *.cookiebot.com trustmark.gr *.agkn.com *.zdassets.com *.trustmark.gr *.google-analytics.com *.googletagmanager.com *.googleadservices.com *.facebook.com connect.facebook.net *.facebook.net googleads.g.doubleclick.net *.doubleclick.net *.zopim.com *.linkwi.se s3.amazonaws.com *.amazonaws.com *.aimtell.com cdn-cfdnp.nitrocdn.com 'unsafe-inline' 'unsafe-eval' blob: data: gap:; style-src 'self' *.googleapis.com *.pharm24.gr *.vc-portal.com *.bootstrapcdn.com cdn-cfdnp.nitrocdn.com 'unsafe-inline'; worker-src 'self' *.aimtell.com blob: data: gap:; font-src 'self' *.hotjar.com *.stats.pharm24.gr *.pharm24.gr *.vc-portal.com *.gstatic.com *.bootstrapcdn.com *.stackpathcdn.com *.zopim.com cdn-cfdnp.nitrocdn.com data:; connect-src *.debugbear.com google.com *.checkout.com *.cookiebot.com *.zendesk.com *.saleago.com *.salesmanago.com *.salesmanago.pl *.getnitropack.com *.adman.gr *.hotjar.com *.googlesyndication.com *.trustmark.gr *.ampproject.org *.google.com *.google.gr *.disqus.com *.shareaholic.com *.shareaholic.net backup.pharm24.gr:* *.pharm24.gr *.doubleclick.net *.google-analytics.com *.agkn.com *.zdassets.com *.amazonaws.com *.zopim.com bat.bing.com a.clarity.ms *.facebook.com *.aimtell.com wss://widget-mediator.zopim.com wss://ws6.hotjar.com/api/v2/client/ws 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action https://testsecurepay.eway2pay.com/fim/est3Dgate https://bib.eway2pay.com/fim/est3Dgate *.facebook.com *.gc.sales-snap.com https://rs.raiffeisenbank.rs pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src *.googletagmanager.com *.doubleclick.net/ *.yandex.com *.facebook.com *.gc.sales-snap.com fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com *.google.com/ www.facebook.com platform.twitter.com *.weltpixel.com 'self' 'unsafe-inline'; img-src *.etrustmark.rs *.facebook.com *.google.com https://yandex.ru *.clarity.ms *.bing.com *.google.rs *.yandex.ru *.yango.com https://core.yads.tech *.doubleclick.net *.yandex.com *.gamecentar.rs https://gamecentar.rs/static/ https://gamecentar.rs/media/ *.googletagmanager.com *.google-analytics.com assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com *.googleapis.com https://firebasestorage.googleapis.com https://www.magezon.com www.facebook.com pinterest.com assets.pinterest.com syndication.twitter.com data: 'self' 'unsafe-inline'; script-src *.sales-snap.com *.facebook.net *.yandex.ru *.clarity.ms *.google-analytics.com *.googletagmanager.com mc.yango.com mc.yandex.ru mc.yandex.com assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.avada.io *.google.com/ connect.facebook.net twitter.com platform.twitter.com https://www.googletagmanager.com tagmanager.google.com unpkg.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.sales-snap.com *.adobe.com fonts.googleapis.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src *.google.com mc.yango.com *.yandex.com *.sales-snap.com *.clarity.ms *.analytics.google.com *.googleapis.com *.google-analytics.com *.clarity.ms *.googletagmanager.com *.google-analytics.com dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.braintreegateway.com *.braintree-api.com https://get.geojs.io *.avada.io *.doubleclick.net 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 script-src 'sha256-/S6GWTNiI3OOMSMLuHw+XVJ08VyiPHS5CeQ7aiIect8=' 'self' self unsafe-eval *.criteo.com; style-src self unsafe-eval; report-uri https://0771da0b-b592-4245-a1e0-f93423ca942b.sansec.watch/ 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com *.klarnacdn.net *.fontawesome.com https://fonts.bunny.net static.klaviyo.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com *.googlesyndication.com *.tiktok.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.mobilpay.ro secure.mobilpay.ro 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.innoship.ro *.klarna.com https://www.googletagmanager.com/ www.xtento.com *.cookiebot.com *.creativecdn.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.googleapis.com 'self' data: *.google.ro *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.googlesyndication.com *.roeye.com *.tiktok.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.tile.openstreetmap.org *.openstreetmap.org *.klarna.com *.klarnaevt.com *.klarnacdn.net http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ https://firebasestorage.googleapis.com t.themarketer.com cdn1.themarketer.com www.xtento.com cdn.xtento.com *.cookiebot.com *.sportguru.ro blob: *.creativecdn.com *.onesignal.com onesignal.com *.cloudfront.net *.zopim.io bat.bing.com https://cdn.tbibank.support data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.googlesyndication.com *.jsdelivr.net *.tiktok.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.klarna.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ *.avada.io *.shopify.com t.themarketer.com cdn1.themarketer.com www.xtento.com cdn.xtento.com *.cookiebot.com *.onesignal.com *.zopim.com *.hotjar.com *.zdassets.com onesignal.com *.creativecdn.com bat.bing.com www.clarity.ms static.cloudflareinsights.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com *.tiktok.com *.klarnacdn.net *.fontawesome.com https://fonts.bunny.net t.themarketer.com cdn1.themarketer.com *.onesignal.com onesignal.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ *.zdassets.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io *.googleapis.com *.google-analytics.com *.facebook.com *.facebook.net stats.g.doubleclick.net *.googlesyndication.com *.tiktok.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.klarnaevt.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.klarna.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ https://get.geojs.io *.avada.io t.themarketer.com cdn1.themarketer.com c1api.themarketer.com c2api.themarketer.com c3api.themarketer.com region1.analytics.google.com googleads.g.doubleclick.net *.cookiebot.com *.zdassets.com *.zendesk.com wss://widget-mediator.zopim.com *.creativecdn.com *.onesignal.com onesignal.com *.tbibank.ro tbibank.ro u.clarity.ms *.gstatic.com *.merchant-center-analytics.goog c4api.themarketer.com https://ro.tbibank.support 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 report-uri https://csp.withgoogle.com/csp/youtube_main/strict;base-uri 'self';object-src 'none';script-src 'report-sample' 'nonce-S30bADUq85Jzkxh7bE_rIw' 'unsafe-inline' 'strict-dynamic' https: http: 'unsafe-eval' 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com https://cdnjs.cloudflare.com maxcdn.bootstrapcdn.com https://fonts.gstatic.com *.thulium.com 'self' *.ekomiapps.de *.payu.com data: 'self' 'unsafe-inline'; form-action *.paypal.com *.facebook.com *.googlesyndication.com https://plumrocket.com 'self' 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com secure.payu.com merch-prod.snd.payu.com https://plumrocket.com *.ceneo.pl *.paypo.pl *.payu.com *.onet.pl *.googletagmanager.com youtube.com *.askspot.io paypo.pl 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io *.paypal.com *.typekit.net *.gstatic.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.googlesyndication.com *.roeye.com *.hsforms.net *.hsforms.com static.payu.com *.google.pl *.skalnik.pl 'self' *.openstreetmap.org *.pagesense.io *.ekomiapps.de *.google.de *.amazonaws.com *.bing.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com https://cdnjs.cloudflare.com *.hsforms.net *.hsforms.com secure.payu.com secure.snd.payu.com *.quartic.pl *.skalnik.pl *.ceneo.pl *.uptimiarium.eu *.luigisbox.com *.getresponse.com *.savecart.pl recostream.com *.thulium.com *.gr-wcon.com *.gr-cdn.com 'self' 'unsafe-eval' *.uptimiarum.eu 'nonce-test' 'unsafe-inline' *.tiktok.com *.clickonometrics.pl *.hotjar.com *.onet.pl *.gr-cdn-e.eu *.cloudflareinsights.com *.pagesense.io *.clarity.ms *.ekomiapps.de *.ekomi.com *.bing.com *.payu.com *.askspot.io *.tmtarget.com *.luigisbox.tech 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com https://fonts.googleapis.com https://cdnjs.cloudflare.com maxcdn.bootstrapcdn.com *.thulium.com *.luigisbox.com 'self' 'unsafe-inline' *.ekomiapps.de *.luigisbox.tech 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.thulium.com 'self' 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.google-analytics.com *.facebook.com *.facebook.net *.doubleclick.net *.googlesyndication.com t.elasticsuite.io *.hsforms.net *.hsforms.com secure.payu.com merch-prod.snd.payu.com *.luigisbox.com *.recostream.com *.savecart.pl *.getresponse.com *.thulium.com *.uptimiarium.eu 'self' *.uptimiarum.eu *.payu.com *.openstreetmap.org *.ocdn.eu *.onet.pl wss: ws.hojtar.com *.hotjar.io *.tiktok.com *.eu01.nr-data.net *.clickonometrics.pl *.skalnik.pl *.clarity.ms *.ekomiapps.de *.ekomi.com *.bing.net *.tiktokw.us bat.bing.com *.luigisbox.tech 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; script-src 'self' https://analytics.tiktok.com https://bat.bing.com https://cdn-3.convertexperiments.com https://cdn-4.convertexperiments.com https://cdn.cookielaw.org https://cdn.debugbear.com https://cdn.ometria.com https://script.hotjar.com https://code.jquery.com https://connect.facebook.net https://googleads.g.doubleclick.net https://p.teads.tv https://s.pinimg.com https://script.hotjar.com https://static.hotjar.com https://unpkg.com https://widget.trustpilot.com https://www.bing.com https://js.klarna.com https://payments.worldpay.com https://rum-static.pingdom.net https://www.awin1.com https://www.dwin1.com https://www.google.com https://www.googleadservices.com https://www.googletagmanager.com https://app.convert.com https://ct.pinterest.com https://no-cdn.convertexperiments.com https://r.bing.com https://apis.google.com https://js.playground.klarna.com https://translate-pa.googleapis.com https://translate.google.com https://translate.googleapis.com https://www.google-analytics.com https://pagead2.googlesyndication.com https://*.ssl.ak.dynamic.tiles.virtualearth.net https://www.flyingflowers.co.uk https://www.interflora.ie https://www.interflora.co.uk https://www.paypal.com https://static.zdassets.com 'report-sample'; script-src-attr 'self'; script-src-elem 'self' https://cdn-4.convertexperiments.com https://www.paypal.com https://tr.snapchat.com https://atlas.microsoft.com https://static.zdassets.com https://www.googletagmanager.com https://www.dwin1.com https://widget.trustpilot.com https://unpkg.com https://static.hotjar.com https://script.hotjar.com https://s.pinimg.com https://rum-static.pingdom.net https://js.klarna.com https://googleads.g.doubleclick.net https://ct.pinterest.com https://connect.facebook.net https://cdn.ometria.com https://cdn.debugbear.com https://cdn.cookielaw.org https://bat.bing.com https://analytics.tiktok.com https://payments.worldpay.com; connect-src 'self' https://hpp.worldpay.com https://tr.snapchat.com https://tr6.snapchat.com https://*.metrics.convertexperiments.com https://ekr.zdassets.com https://ad.doubleclick.net https://analytics.tiktok.com https://ask.hotjar.io https://bat.bing.com https://cdn-3.convertexperiments.com https://cdn.cookielaw.org https://cdn.debugbear.com https://cm.teads.tv https://content.hotjar.io https://ct.pinterest.com https://data.debugbear.com https://googleads.g.doubleclick.net https://in.hotjar.com https://insights.algolia.io https://l.teads.tv https://logs.convertexperiments.com https://metrics.hotjar.io https://msn7pvpzhu-1.algolianet.com https://msn7pvpzhu-2.algolianet.com https://msn7pvpzhu-3.algolianet.com https://msn7pvpzhu-dsn.algolia.net https://stats.g.doubleclick.net https://surveystats.hotjar.io https://t.teads.tv https://trk.ometria.com https://unpkg.com https://vc.hotjar.io https://widget.trustpilot.com wss://ws.hotjar.com https://www.bing.com https://www.facebook.com https://media.interflora.co.uk https://apis.google.com https://cdn.ometria.com https://geolocation.onetrust.com https://payments.worldpay.com https://privacyportal-eu.onetrust.com https://rum-collector-2.pingdom.net https://rum-static.pingdom.net https://www.googletagmanager.com https://www.google-analytics.com https://www.google.com https://uksouth-0.in.applicationinsights.azure.com https://region1.google-analytics.com https://pagead2.googlesyndication.com https://o4506853695881216.ingest.us.sentry.io https://*.playground.klarnaevt.com https://adservice.google.com https://cdn-4.convertexperiments.com https://connect.facebook.net https://js.klarna.com https://js.playground.klarna.com https://oc.klarnaevt.com https://eu.klarnaevt.com https://region1.analytics.google.com https://analytics.google.com https://api.edq.com https://bat.bing.net https://dev.virtualearth.net https://translate.googleapis.com https://translate-pa.googleapis.com https://www.google.co.uk https://na.klarnaevt.com https://atlas.microsoft.com https://na.klarnaevt.com https://www.interflora.ie https://www.flyingflowers.co.uk https://dc.services.visualstudio.com https://www.awin1.com https://www.googleadservices.com https://wepowerconnections.com https://fonts.gstatic.com https://google.com https://www.paypal.com https://analytics-ipv6.tiktokw.us https://www.sandbox.paypal.com https://cdn.media.amplience.net https://o24547.ingest.sentry.io; style-src 'self' 'unsafe-inline'; frame-src 'self' https://tr.snapchat.com https://*.fls.doubleclick.net https://match.adsrvr.org https://ct.pinterest.com https://hpp.worldpay.com https://js.klarna.com https://payments.worldpay.com https://td.doubleclick.net https://widget.trustpilot.com https://www.awin1.com https://www.facebook.com https://js.klarna.com https://pay.klarna.com https://www.paypal.com https://www.googletagmanager.com https://www.sandbox.paypal.com; img-src 'self' data: https://www.interflora.co.uk https://media.interflora.co.uk https://ad.doubleclick.net https://analytics.tiktok.com https://bat.bing.com https://cdn.cookielaw.org https://cm.teads.tv https://connect.facebook.net https://googleads.g.doubleclick.net https://l.teads.tv https://stats.g.doubleclick.net https://t.teads.tv https://trk.ometria.com https://www.awin1.com https://www.bing.com https://www.facebook.com https://logs.convertexperiments.com https://adservice.google.com https://media.flyingflowers.co.uk https://translate.google.com https://www.flyingflowers.co.uk https://www.googletagmanager.com https://t.ssl.ak.dynamic.tiles.virtualearth.net https://interflora.a.bigcontent.io https://ade.googlesyndication.com https://www.wepowerconnections.com https://eu.fareye.co https://cdn.media.amplience.net https://media.interflora.ie https://www.interflora.ie https://fonts.gstatic.com https://www.google.co.uk https://www.google.com https://pagead2.googlesyndication.com https://bat.bing.net https://analytics-ipv6.tiktokw.us https://google.com https://www.googleadservices.com; form-action 'self' https://payments.worldpay.com; worker-src 'self'; report-uri https://interflorauk.report-uri.com/r/t/csp/reportOnly; 1 report-uri https://csp.withgoogle.com/csp/youtube_main/strict;base-uri 'self';object-src 'none';script-src 'report-sample' 'nonce-DYdeUYhWF0KuA1i90ULszg' 'unsafe-inline' 'strict-dynamic' https: http: 'unsafe-eval' 1 font-src www.paypalobjects.com https://widgets.trustedshops.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' 'unsafe-inline'; frame-ancestors *.multisafepay.com https://pay.google.com 'self'; frame-src www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ bid.g.doubleclick.net https://www.googletagmanager.com/ *.multisafepay.com https://pay.google.com 'self' 'unsafe-inline'; img-src cdn.nonpaints.com data: widgets.magentocommerce.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com *.google-analytics.com *.analytics.google.com www.googletagmanager.com https://images.unsplash.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ magefan.com cm.magefan.com *.disqus.com https://img.youtube.com *.multisafepay.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com *.etrusted.com data: https: 'self' 'unsafe-inline'; script-src www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com https://maps.googleapis.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ *.disqus.com https://cdn.jsdelivr.net *.multisafepay.com https://pay.google.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.etrusted.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src https://cdn.jsdelivr.net *.multisafepay.com https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.etrusted.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com www.googleadservices.com *.google-analytics.com *.analytics.google.com www.googletagmanager.com https://maps.googleapis.com https://player.vimeo.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ *.multisafepay.com *.trustedshops.com *.etrusted.com https://integrations.etrusted.site 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 frame-ancestors 'self'; report-uri https://www.bestrecipes.com.au/csp-reports 1 default-src *; script-src * 'unsafe-inline' 'unsafe-eval' blob: data:; style-src * 'unsafe-inline'; img-src * data:; font-src *; connect-src * wss:; frame-src *; object-src *; 1 report-uri https://csp.withgoogle.com/csp/youtube_main/strict;base-uri 'self';object-src 'none';script-src 'report-sample' 'nonce-kE5smggxfNufS2vWT1sARA' 'unsafe-inline' 'strict-dynamic' https: http: 'unsafe-eval' 1 font-src fonts.gstatic.com use.typekit.net apps.bazaarvoice.com script.hotjar.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com api.bazaarvoice.com stg.api.bazaarvoice.com *.punchout2go.com www.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.google.com *.googletagmanager.com esqa.moneris.com www3.moneris.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com *.dotdigital-pages.com *.dotdigital.com *.punchout2go.com e.bmr.co www.facebook.net www.facebook.com ct.pinterest.com td.doubleclick.net static.addtoany.com https://*.online-metrix.net https://imgs.signifyd.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com p.typekit.net *.vimeocdn.com i.ytimg.com *.youtube.com *.googleapis.com *.gstatic.com *.google.com *.googleusercontent.com display.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com network-a.bazaarvoice.com network-stg-a.bazaarvoice.com photos-uat-us.bazaarvoice.com img.youtube.com *.trackedlink.net *.ddlnk.net https://axeptio.imgix.net apps-stg.bazaarvoice.com www.bmr.ca *.google.com *.google.ad *.google.ae *.google.com.af *.google.com.ag *.google.com.ai *.google.al *.google.am *.google.co.ao *.google.com.ar *.google.as *.google.at *.google.com.au *.google.az *.google.ba *.google.com.bd *.google.be *.google.bf *.google.bg *.google.com.bh *.google.bi *.google.bj *.google.com.bn *.google.com.bo *.google.com.br *.google.bs *.google.bt *.google.co.bw *.google.by *.google.com.bz *.google.ca *.google.cd *.google.cf *.google.cg *.google.ch *.google.ci *.google.co.ck *.google.cl *.google.cm *.google.cn *.google.com.co *.google.co.cr *.google.com.cu *.google.cv *.google.com.cy *.google.cz *.google.de *.google.dj *.google.dk *.google.dm *.google.com.do *.google.dz *.google.com.ec *.google.ee *.google.com.eg *.google.es *.google.com.et *.google.fi *.google.com.fj *.google.fm *.google.fr *.google.ga *.google.ge *.google.gg *.google.com.gh *.google.com.gi *.google.gl *.google.gm *.google.gr *.google.com.gt *.google.gy *.google.com.hk *.google.hn *.google.hr *.google.ht *.google.hu *.google.co.id *.google.ie *.google.co.il *.google.im *.google.co.in *.google.iq *.google.is *.google.it *.google.je *.google.com.jm *.google.jo *.google.co.jp *.google.co.ke *.google.com.kh *.google.ki *.google.kg *.google.co.kr *.google.com.kw *.google.kz *.google.la *.google.com.lb *.google.li *.google.lk *.google.co.ls *.google.lt *.google.lu *.google.lv *.google.com.ly *.google.co.ma *.google.md *.google.me *.google.mg *.google.mk *.google.ml *.google.com.mm *.google.mn *.google.ms *.google.com.mt *.google.mu *.google.mv *.google.mw *.google.com.mx *.google.com.my *.google.co.mz *.google.com.na *.google.com.ng *.google.com.ni *.google.ne *.google.nl *.google.no *.google.com.np *.google.nr *.google.nu *.google.co.nz *.google.com.om *.google.com.pa *.google.com.pe *.google.com.pg *.google.com.ph *.google.com.pk *.google.pl *.google.pn *.google.com.pr *.google.ps *.google.pt *.google.com.py *.google.com.qa *.google.ro *.google.ru *.google.rw *.google.com.sa *.google.com.sb *.google.sc *.google.se *.google.com.sg *.google.sh *.google.si *.google.sk *.google.com.sl *.google.sn *.google.so *.google.sm *.google.sr *.google.st *.google.com.sv *.google.td *.google.tg *.google.co.th *.google.com.tj *.google.tl *.google.tm *.google.tn *.google.to *.google.com.tr *.google.tt *.google.com.tw *.google.co.tz *.google.com.ua *.google.co.ug *.google.co.uk *.google.com.uy *.google.co.uz *.google.com.vc *.google.co.ve *.google.vg *.google.co.vi *.google.com.vn *.google.vu *.google.ws *.google.rs *.google.co.za *.google.co.zm *.google.co.zw *.google.cat static.hotjar.com script.hotjar.com survey.hotjar.com www.facebook.net www.facebook.com cdn.cookielaw.org maps.googleapis.com maps.gstatic.com aq.flippenterprise.net dam.flippenterprise.net cdn.flippenterprise.net *.wishabi.com *.wishabi.net https://imgs.signifyd.com https://*.online-metrix.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com amcglobal.sc.omtrdc.net *.adobe.io use.typekit.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com *.magento-ds.com *.googleapis.com *.gstatic.com *.google.com *.ggpht.com *.googleusercontent.com *.googletagmanager.com esqa.moneris.com www3.moneris.com apps.bazaarvoice.com apps.nexus.bazaarvoice.com apps-stg.nexus.bazaarvoice.com analytics-static.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com mpsnare.iesnare.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal *.punchout2go.com https://*.axept.io e.bmr.co js-agent.newrelic.com s.pinimg.com ct.pinterest.com static.hotjar.com script.hotjar.com connect.facebook.net connect.facebook.com plausible.io cdn.cookielaw.org maps.googleapis.com www.gstatic.com r2-t.trackedlink.net bam.nr-data.net bam-cell.nr-data.net static.addtoany.com aq.flippenterprise.net dam.flippenterprise.net cdn.flippenterprise.net p.flipp.com cdn-gateflipp.flippback.com https://cdn-scripts.signifyd.com https://imgs.signifyd.com https://h64.online-metrix.net https://www.bmr.ca 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com display.ugc.bazaarvoice.com *.punchout2go.com static.hotjar.com script.hotjar.com cdn.cookielaw.org www.gstatic.com aq.flippenterprise.net dam.flippenterprise.net cdn.flippenterprise.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.magento.com *.adobe.io performance.typekit.net commerce.adobe.io *.magento-datasolutions.com *.magento-ds.com *.sentry.io *.googleapis.com *.gstatic.com *.google.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io api.bazaarvoice.com stg.api.bazaarvoice.com apps.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com https://*.axept.io https://*.axeptio.eu https://*.axeptio.techimg-src https://axeptio.imgix.net network-a.bazaarvoice.com network-stg-a.bazaarvoice.com apps-stg.bazaarvoice.com *.google.com *.google.ad *.google.ae *.google.com.af *.google.com.ag *.google.com.ai *.google.al *.google.am *.google.co.ao *.google.com.ar *.google.as *.google.at *.google.com.au *.google.az *.google.ba *.google.com.bd *.google.be *.google.bf *.google.bg *.google.com.bh *.google.bi *.google.bj *.google.com.bn *.google.com.bo *.google.com.br *.google.bs *.google.bt *.google.co.bw *.google.by *.google.com.bz *.google.ca *.google.cd *.google.cf *.google.cg *.google.ch *.google.ci *.google.co.ck *.google.cl *.google.cm *.google.cn *.google.com.co *.google.co.cr *.google.com.cu *.google.cv *.google.com.cy *.google.cz *.google.de *.google.dj *.google.dk *.google.dm *.google.com.do *.google.dz *.google.com.ec *.google.ee *.google.com.eg *.google.es *.google.com.et *.google.fi *.google.com.fj *.google.fm *.google.fr *.google.ga *.google.ge *.google.gg *.google.com.gh *.google.com.gi *.google.gl *.google.gm *.google.gr *.google.com.gt *.google.gy *.google.com.hk *.google.hn *.google.hr *.google.ht *.google.hu *.google.co.id *.google.ie *.google.co.il *.google.im *.google.co.in *.google.iq *.google.is *.google.it *.google.je *.google.com.jm *.google.jo *.google.co.jp *.google.co.ke *.google.com.kh *.google.ki *.google.kg *.google.co.kr *.google.com.kw *.google.kz *.google.la *.google.com.lb *.google.li *.google.lk *.google.co.ls *.google.lt *.google.lu *.google.lv *.google.com.ly *.google.co.ma *.google.md *.google.me *.google.mg *.google.mk *.google.ml *.google.com.mm *.google.mn *.google.ms *.google.com.mt *.google.mu *.google.mv *.google.mw *.google.com.mx *.google.com.my *.google.co.mz *.google.com.na *.google.com.ng *.google.com.ni *.google.ne *.google.nl *.google.no *.google.com.np *.google.nr *.google.nu *.google.co.nz *.google.com.om *.google.com.pa *.google.com.pe *.google.com.pg *.google.com.ph *.google.com.pk *.google.pl *.google.pn *.google.com.pr *.google.ps *.google.pt *.google.com.py *.google.com.qa *.google.ro *.google.ru *.google.rw *.google.com.sa *.google.com.sb *.google.sc *.google.se *.google.com.sg *.google.sh *.google.si *.google.sk *.google.com.sl *.google.sn *.google.so *.google.sm *.google.sr *.google.st *.google.com.sv *.google.td *.google.tg *.google.co.th *.google.com.tj *.google.tl *.google.tm *.google.tn *.google.to *.google.com.tr *.google.tt *.google.com.tw *.google.co.tz *.google.com.ua *.google.co.ug *.google.co.uk *.google.com.uy *.google.co.uz *.google.com.vc *.google.co.ve *.google.vg *.google.co.vi *.google.com.vn *.google.vu *.google.ws *.google.rs *.google.co.za *.google.co.zm *.google.co.zw *.google.cat *.hotjar.com wss://*.hotjar.com *.hotjar.io www.facebook.com ct.pinterest.com plausible.io cdn.cookielaw.org maps.googleapis.com stats.g.doubleclick.net bam.nr-data.net bam-cell.nr-data.net aq.flippenterprise.net dam.flippenterprise.net cdn.flippenterprise.net p.flipp.com cdn-gateflipp.flippback.com https://imgs.signifyd.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://a4825dc4-e033-47b9-830c-751e434948c6.sansec.watch/; report-to report-endpoint; 1 default-src 'self' 'unsafe-inline' 'unsafe-eval' *.angusrobertson.com.au; object-src 'none'; script-src 'self' 'unsafe-inline' 'unsafe-eval' blob: *.secure-afterpay.com.au bam.nr-data.net *.hotjar.com googleads.g.doubleclick.net *.google-analytics.com *.googletagmanager.com *.googleadservices.com *.bing.com *.google.com *.gstatic.com *.forter.com *.visualwebsiteoptimizer.com *.cloudfront.net static.scarabresearch.com cdn.scarabresearch.com apis.google.com *.criteo.com static.criteo.net *.newrelic.com connect.facebook.net platform.twitter.com d.impactradius-event.com *.afterpay.com; connect-src 'self' blob: *.cloudfront.net *.google-analytics.com *.hotjar.io *.nr-data.net stats.g.doubleclick.net *.emarsys.net *.scarabresearch.com *.hotjar.com *.salecycle.com *.forter.com opentag-stats.qubit.com *.visualwebsiteoptimizer.com recommender.scarabresearch.com angusrobertson.4tqiav.net; img-src 'self' data: *.criteo.net *.google-analytics.com *.google.com *.bing.com *.google.com.au *.pinterest.com *.cloudfront.net *.visualwebsiteoptimizer.com *.facebook.com syndication.twitter.com *.secure-afterpay.com.au *.angusrobertson.com.au *.loggly.com; frame-src 'self' *.cloudfront.net *.angusrobertson.com.au *.google.com platform.twitter.com www.facebook.com staticxx.facebook.com www.youtube.com *.criteo.com *.criteo.net *.hotjar.com *.salecycle.com bid.g.doubleclick.net 1 object-src 'none'; script-src 'nonce-qvZOQpgNixEf6pDR2w1Vu3kh' 'strict-dynamic' http: https:; base-uri 'none'; 1 default-src 'self'; script-src 'self' 'nonce-C912ewW5npz3_XVOdnm0mo4kZLqMC2Z5I3UeTMJ1it_GZR8ur7RjDw' data: https://api-web.educagri.fr *.google-analytics.com https://www.googletagmanager.com https://analytics-sc.institut-agro.fr https://player.vimeo.com 'report-sample' https://ajax.googleapis.com/ https://analytics-sc.institut-agro.fr/; style-src-attr 'unsafe-inline' 'self' 'report-sample' data: https://api-web.educagri.fr https://use.fontawesome.com *.ckeditor.com; img-src 'self' data: *.ytimg.com *.vimeocdn.com https://api-web.educagri.fr https://www.google-analytics.com https://www.googletagmanager.com https://www.youtube-nocookie.com/ https://www.youtube.com/; base-uri 'self'; frame-src 'self' *.youtube-nocookie.com *.youtube.com *.vimeo.com *.data.sigea.educagri.fr *.dailymotion.com *.genially.com *.view.genial.ly https://view.genial.ly *.arteradio.com *.calameo.com *.facebook.com https://www.google.com https://fermewikisagro.fr *.francetv.fr; font-src 'self' data: https://fonts.gstatic.com https://use.fontawesome.com https://api-web.educagri.fr; connect-src 'self' data: https://api-web.educagri.fr *.google-analytics.com https://analytics-sc.institut-agro.fr https://analytics-sc.institut-agro.fr/; style-src 'self' 'report-sample' data: https://api-web.educagri.fr https://fonts.googleapis.com https://use.fontawesome.com; script-src-elem 'self' 'nonce-C912ewW5npz3_XVOdnm0mo4kZLqMC2Z5I3UeTMJ1it_GZR8ur7RjDw' data: https://api-web.educagri.fr *.google-analytics.com https://www.googletagmanager.com https://analytics-sc.institut-agro.fr https://player.vimeo.com 'report-sample'; report-uri https://cem.educagri.fr/api/csp/0/FE 1 default-src 'self' *.auditboard.com *.42chat.com *.doubleclick.net *.google.com *.googlesyndication.com *.greenhouse.io *.marketo.com *.vidyard.com *.wistia.com https://www.facebook.com https://www.youtube.com; connect-src 'self' https: *.auditboard.com wss://*.qualified.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' blob: https: *.addthis.com *.addthisedge.com *.auditboard.com *.cloudfront.net *.google-analytics.com *.googleapis.com *.marketo.com *.marketo.net *.ubembed.com *.wistia.com https://cdn.livechatinc.com https://optimize.google.com https://www.googleanalytics.com https://www.googleoptimize.com https://www.googletagmanager.com https://www.youtube.com https://use.typekit.net; frame-ancestors 'self' *.auditboard.com https://*.sanity.io; frame-src 'self' *.auditboard.com https://app.netlify.com https://app.qualified.com https://app-ab39.marketo.com *.googletagmanager.com *.vidyard.com *.visualwebsiteoptimizer.com https://www.google.com https://excon-shell-prod.web.app https://app.vwo.com https://auditboard126.outgrow.co https://auditboard126.outgrow.us https://td.doubleclick.net *.demandbase.com *.company-target.com *.addthis.com *.auditboard.com *.42chat.com *.auditboard.com.pagescdn.com *.auditboardmarketing.com.pagescdn.com *.google.com *.greenhouse.io *.marketo.com *.ps-bizzabo.com *.qualified.com *.wistia.com https://961-zqv-184.mktoweb.com https://auditboard.atlassian.net https://bid.g.doubleclick.net https://events.bizzabo.com https://js.driftt.com https://play.vidyard.com https://secure.livechatinc.com https://tpc.googlesyndication.com https://www.facebook.com https://www.googletagmanager.com https://www.visualize-roi.com https://www.youtube.com https://app.netlify.com https://marketo-lps.netlify.app *.marketodesigner.com https://na-ab39.marketodesigner.com; font-src 'self' data: *.auditboard.com *.eventscloud.com *.gstatic.com https://use.typekit.net https://marketo-lps.netlify.app https://auditboard126.outgrow.co; img-src 'self' https: data: *.auditboard.com https://optimize.google.com https://www.google-analytics.com https://p.typekit.net https://tags.srv.stackadapt.com https://srv.stackadapt.com https://ap.srv.stackadapt.com https://east.srv.stackadapt.com https://uw.srv.stackadapt.com https://eu.srv.stackadapt.com https://qvdt3feo.com; worker-src 'self' blob: *.auditboard.com; style-src 'self' 'unsafe-inline' https: *.auditboard.com *.qualified.com https://use.typekit.net https://tags.srv.stackadapt.com https://srv.stackadapt.com https://ap.srv.stackadapt.com https://east.srv.stackadapt.com https://uw.srv.stackadapt.com https://eu.srv.stackadapt.com https://qvdt3feo.com; media-src 'self' data: blob: mediastream: *.auditboard.com *.livechatinc.com *.qualified.com *.wistia.com *.wistia.net https://embedwistia-a.akamaihd.net https://js.driftt.com https://cdn.sanity.io; object-src 'self' *.auditboard.com https://embed-fastly.wistia.com https://embedwistia-a.akamaihd.net https://auditboardinc.wpengine.com; base-uri 'self'; form-action 'self' *.marketo.com *.marketo.net https://app-ab39.marketo.com https://961-zqv-184.mktoweb.com 1 default-src 'self'; script-src 'self' 'unsafe-inline' https://cdn.jsdelivr.net/npm/@gumlet/ webapp.gumlet.com snap.licdn.com googleads.g.doubleclick.net js-na2.hs-scripts.com challenges.cloudflare.com script.hotjar.com embed.savvycal.com tracking.g2crowd.com analytics.ahrefs.com cdn.firstpromoter.com www.googletagmanager.com js-na2.hsadspixel.net js-na2.hs-banner.com js-na2.hs-analytics.net static.hotjar.com app.factors.ai; style-src 'self' 'unsafe-inline'; img-src * blob: data:; font-src 'self'; media-src video.gumlet.io js.gleap.io; object-src 'none'; base-uri 'self'; form-action 'self' *.gumlet.com https://webapp.gumlet.com; connect-src *; frame-ancestors 'none'; frame-src play.gumlet.io www.googletagmanager.com savvycal.com messenger-app.gleap.io challenges.cloudflare.com; upgrade-insecure-requests; report-to gumlet-nel; 1 default-src 'self'; script-src 'self' 'unsafe-eval' 'unsafe-inline' *.bing.com *.braintreegateway.com *.cardinalcommerce.com *.doubleclick.net *.dwin1.com *.facebook.net *.getwisp.co *.google.com *.googleadservices.com *.googleapis.com *.googlesyndication.com *.googletagmanager.com *.gstatic.com *.helpscout.net *.klaviyo.com *.paypal.com *.roeyecdn.com *.trustpilot.com *.wisepops.com *.wisepops.net *.youtube.com cdn-cookieyes.com wisepops.net; style-src 'self' 'unsafe-inline' *.fontawesome.com *.googleapis.com *.gstatic.com; img-src 'self' data: *.awin1.com *.bing.com *.bing.net *.doubleclick.net *.facebook.com *.google.com *.google.co.uk *.googleadservices.com *.googlesyndication.com *.googletagmanager.com *.gstatic.com *.paypal.com *.roeye.com *.wisepops.com *.youtube.com *.ytimg.com cdn-cookieyes.com image-charts.com; font-src 'self' *.fontawesome.com *.gstatic.com; frame-src 'self' *.bing.com *.braintreegateway.com *.cardinalcommerce.com *.doubleclick.net *.facebook.com *.getwisp.co *.google.com *.googletagmanager.com *.trustpilot.com *.wisepops.com *.wisepops.net *.youtube.com wisepops.net; connect-src 'self' *.bing.com *.bing.net *.braintree-api.com *.braintreegateway.com *.cardinalcommerce.com *.cookieyes.com *.doubleclick.net *.facebook.com *.google-analytics.com *.google.com *.googlesyndication.com *.helpscout.net *.klaviyo.com *.paypal.com *.wisepops.com *.wisepops.net cdn-cookieyes.com google.com wisepops.net; frame-ancestors 'self'; form-action 'self'; base-uri 'self'; upgrade-insecure-requests; report-uri https://b965d175-0c60-4d34-b3f2-c7244d93f81a.sansec.watch/; media-src 'self'; object-src 'none'; worker-src 'self'; manifest-src 'self'; 1 connect-src *;frame-src *;img-src https: data: blob: about: safari-extension: safari-resource: chrome-extension: http://*.rackcdn.com http://*.tumblr.com http://huaban.com;worker-src https: blob:;script-src https: 'unsafe-eval' 'unsafe-inline'; report-uri /log/csp 1 script-src 'nonce-er0hQlp2OakNEGj0hJjHtw==' 'strict-dynamic' 'unsafe-eval' 'unsafe-inline' https: 'report-sample'; base-uri 'none'; report-uri https://events.mercadolibre.com/csp/reports?identifier=w1qeU4XKVwGbQGBuEKyE3KhFBIpr5IZSIaRiTowMc8UG7kU18vRsmBTEKL2krAj23LIS&policy_id=26548&user_id=&request_id=d776e470-1f9d-46d9-a375-7fa922ea61ae; report-to csp-endpoint-wqeuxkvwgbqgbuekyekhfbiprizsiaritowmcugkuvrsmbteklkrajlis; object-src https://http2.mlstatic.com/ https://mlstaticquic-a.akamaihd.net/; frame-ancestors 'self' https://*.mercadolibre.cl:* https://*.mercadolibre.com:* https://*.mercadolibre.com.ve:* https://*.mercadolibre.com.ar:* https://*.mercadolivre.com.br:* https://*.mercadolibre.com.co:* https://*.mercadolibre.com.ec:* https://*.mercadolibre.com.mx:* https://*.mercadolibre.com.pe:* https://*.mercadolibre.com.uy:* https://*.mercadopago.cl:* https://*.mercadopago.com.ar:* https://*.mercadopago.com.br:* https://*.mercadopago.com.co:* https://*.mercadopago.com.mx:* https://*.mercadopago.com.pe:* https://*.mercadopago.com.uy:* https://*.mercadopago.com.ve:* https://*.mercadopago.com:* https://*.adminml.com:* https://*.mercadolibre.co.cr:* https://*.mercadolibre.com.pa:* https://*.mercadolibre.com.do:* https://*.mercadolibre.com.bo:* https://*.mercadolibre.com.py:* https://*.mercadolibre.com.gt:* https://*.mercadolibre.com.hn:* https://*.mercadolibre.com.ni:* https://*.mercadolibre.com.sv:* https://*.mercadopago.com.ec:* https://*.portalinmobiliario.com:* https://*.mercadolivre.com:* 1 connect-src 'self' https://analytics.tiktok.com https://api.hubspot.com https://app.clearbit.com https://cdn.cookielaw.org https://cdn.dreamdata.cloud https://content.hotjar.io https://cta-service-cms2.hubspot.com https://forms.hsforms.com https://px.ads.linkedin.com https://script.crazyegg.com https://www.google-analytics.com https://www.google.com https://edge.api.brightcove.com https://bat.bing.com/ https://manifest.prod.boltdns.net https://sdl.brightcovecdn.com https://logx.optimizely.com https://*.optimizely.com; default-src 'self'; font-src 'self' data: https://use.typekit.net https://*.optimizely.com; frame-ancestors 'none'; frame-src https://www.googletagmanager.com https://googleads.g.doubleclick.net https://cm.g.doubleclick.net https://www.facebook.com https://calendly.com https://forms.hsforms.com https://a5098497884553216.cdn.optimizely.com https://a5098497884553216.cdn-pci.optimizely.com; img-src 'self' data: https://bat.bing.com https://forms-na1.hsforms.com https://ib.adnxs.com https://perf-na1.hsforms.com https://px.ads.linkedin.com https://secure.adnxs.com https://track.accountinsight.cloud https://track.hubspot.com https://www.facebook.com https://www.google.com https://www.google.com.ua https://metrics.brightcove.com https://www.googletagmanager.com https://cf-images.us-east-1.prod.boltdns.net https://cdn.optimizely.com https://app.optimizely.com; media-src 'self' blob:; script-src 'self' 'nonce-pdlVP26+Gd6017bxYlBJYg==' https://a.dpmsrv.com https://analytics.tiktok.com https://bat.bing.com https://cdn.cookielaw.org https://cdn.dreamdata.cloud https://cm.g.doubleclick.net https://connect.facebook.net https://googleads.g.doubleclick.net https://ib.adnxs.com https://js.hs-analytics.net https://js.hs-banner.com https://js.hs-scripts.com https://js.hsforms.net https://js.hubspot.com https://js.usemessages.com https://s.dpmsrv.com https://script.crazyegg.com https://script.hotjar.com https://serve.nrich.ai https://snap.licdn.com https://st.getsitecontrol.com https://static.hotjar.com https://tag.clearbitscripts.com https://widgets.getsitecontrol.com https://www.googletagmanager.com https://x.clearbitjs.com https://assets.calendly.com https://static.hsappstatic.net https://48752163.fs1.hubspotusercontent-na1.net https://cdnjs.cloudflare.com https://players.brightcove.net wss://ws.hotjar.com/ https://*.optimizely.com https://optimizely.s3.amazonaws.com https://cdn-assets-prod.s3.amazonaws.com 'unsafe-eval'; style-src 'self' 'unsafe-inline' https://*.typekit.net https://assets.calendly.com https://*.optimizely.com https://app.optimizely.com; worker-src 'self' blob:; 1 script-src 'strict-dynamic' 'self' 'nonce-+Hb/ybpa21t38Ocbj94ydg==' 'report-sample'; report-uri /gdhvb2c.onmicrosoft.com/B2C_1_signup_signin/client/cspreport?p=B2C_1_signup_signin 1 object-src 'none'; frame-ancestors https://*.workspot.com; worker-src 'self' blob:; script-src 'self' 'unsafe-inline' 'unsafe-eval' data: https://*.cloudflare.com https://pi.pardot.com https://*.cookiebot.com https://*.workspot.com https://www.google-analytics.com https://www.googletagmanager.com https://*.google.co.uk https://www.workspot.com https://*.google.com https://*.googleadservices.com https://*.googleapis.com https://*.googletagmanager.com https://*.gstatic.cn https://*.gstatic.com; font-src 'self' https://*.gstatic.com https://s0.wp.com data:; img-src 'self' https://*.cookiebot.com data: https://www.google-analytics.com https://*.google.co.uk https://*.google.com https://secure.gravatar.com https://www.googletagmanager.com; style-src 'self' 'unsafe-inline' https://*.googleapis.com; connect-src 'self' https://*.cookiebot.com https://*.google.com https://www.google-analytics.com https://stats.g.doubleclick.net yoast.com; report-uri /; 1 connect-src *.spiraxsarco.com *.onetrust.com *.onetrust.io *.google-analytics.com *.hotjar.com *.hotjar.io *.clarity.ms wss://*.hotjar.com 'self' px.ads.linkedin.com google.com analytics.google.com region1.analytics.google.com www.google-analytics.com www.googletagmanager.com pagead2.googlesyndication.com www.googleadservices.com ad.doubleclick.net stats.g.doubleclick.net 680-ryi-639.mktoresp.com forms.hubspot.com forms.hsforms.com cdn.linkedin.oribi.io hummingbirdwebsocket-nld2.cloud.adobe.io adservice.google.com translate.googleapis.com googleads.g.doubleclick.net www.google.com www.google.co.uk www.google.ae www.google.by www.google.com.gh www.google.com.mm www.google.ga www.google.am www.google.as www.google.at www.google.az www.google.ba www.google.be www.google.bg www.google.bi www.google.bs www.google.ca www.google.cd www.google.cg www.google.ch www.google.ci www.google.cl www.google.co.bw www.google.co.ck www.google.co.cr www.google.co.hu www.google.co.id www.google.co.il www.google.co.im www.google.co.in www.google.co.je www.google.co.jp www.google.co.ke www.google.co.kr www.google.co.ls www.google.co.ma www.google.co.nz www.google.co.th www.google.co.ug www.google.co.uz www.google.co.ve www.google.co.vi www.google.co.za www.google.co.zm www.google.com.af www.google.com.ag www.google.com.ar www.google.com.au www.google.com.bd www.google.com.bo www.google.com.br www.google.com.bz www.google.com.co www.google.com.cu www.google.com.cy www.google.com.do www.google.com.ec www.google.com.eg www.google.com.et www.google.com.fj www.google.com.gi www.google.com.gt www.google.com.hk www.google.com.jm www.google.com.kw www.google.com.ly www.google.com.mt www.google.com.mx www.google.com.my www.google.com.na www.google.com.nf www.google.com.ni www.google.com.np www.google.com.om www.google.com.pa www.google.com.pe www.google.com.ph www.google.com.pk www.google.com.pr www.google.com.py www.google.com.qa www.google.com.sa www.google.com.sb www.google.com.sg www.google.com.sv www.google.com.tj www.google.com.tr www.google.com.tw www.google.com.ua www.google.com.uy www.google.com.uz www.google.com.vc www.google.com.vn www.google.cn www.google.cz www.google.de www.google.dj www.google.dk www.google.dm www.google.ee www.google.es www.google.fi www.google.fm www.google.fr www.google.gg www.google.gl www.google.gm www.google.gr www.google.hn www.google.hr www.google.ht www.google.hu www.google.ie www.google.is www.google.it www.google.jo www.google.kg www.google.kz www.google.li www.google.lk www.google.lt www.google.lu www.google.lv www.google.md www.google.mn www.google.ms www.google.mu www.google.mw www.google.net www.google.nl www.google.no www.google.nr www.google.nu www.google.pl www.google.pn www.google.pt www.google.ro www.google.rs www.google.ru www.google.rw www.google.sc www.google.se www.google.sh www.google.si www.google.sk www.google.sm www.google.sn www.google.tm www.google.tn www.google.to www.google.tp www.google.tt www.google.tv www.google.uz www.google.vg www.google.vu www.google.ws www.google.co.zw www.google.dz/ads/ga-audiences www.google.al/ads/ga-audiences www.google.bf/ads/ga-audiences ttps://www.google.by/ads/ga-audiences www.google.cm/ads/ga-audiences www.google.co.ao/ads/ga-audiences ttps://www.google.co.mz/ads/ga-audiences www.google.co.tz/ads/ga-audiences www.google.com.bn/ads/ga-audiences ttps://www.google.com.gh/ads/ga-audiences www.google.com.kh/ads/ga-audiences www.google.com.lb/ads/ga-audiences ttps://www.google.com.mm/ads/ga-audiences www.google.com.ng/ads/ga-audiences www.google.com.pg/ads/ga-audiences ttps://www.google.dz/ads/ga-audiences www.google.ge/ads/ga-audiences www.google.iq/ads/ga-audiences www.google.sr/ads/ga-audiences 680-ryi-639.mktoutil.com wss://lo.msg.liveperson.net bat.bing.com js.calltrk.com mc.yandex.ru yandexmetrica.com:30103 ymetrica1.com; font-src *.onetrust.com 'self' fonts.gstatic.com use.typekit.net script.hotjar.com data:; img-src optimize.google.com www.google-analytics.com www.googletagmanager.com 'self' data: *; manifest-src 'self'; script-src *.onetrust.com *.scr.kaspersky-labs.com www.googleanalytics.com www.googleoptimize.com optimize.google.com static.ads-twitter.com 'self' 'nonce-OTNkYjZiYTctOGFlZi00ZDlmLTk4NDctZDMzMGZjMThiNjUx' 'strict-dynamic' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes' 'sha256-MhtPZXr7+LpJUY5qtMutB+qWfQtMaPccfe7QXtCcEYc=' 'sha256-NiPpcuG5iPK1KPR3YIEEEz98KT0W7243V6u7FeP7hdE=' 'sha256-gRuNVLzs+xy+3p6+I1CnZb8pDmnXUWSlO9ejbnSR/lQ=' 'sha256-ibqfaR/CmFL3wQZAxIuZ0V4RMm9txqHSln46Z5WyeVA=' 'sha256-30EB3olZggJZ3OT2ahL22VzuYSIEPTzmMb+L3StxKgI=' 'sha256-IgMQOOOedQeMPBl7lSreMVPmJvU62bc6l8HcsGXnbWc=' 'sha256-qbWCytLP5JMsZSG1DsvruBVK5O5otEfzrwtrYklbihw=' 'sha256-bkXrlHTrWu78qnQooXw+JqlG1rZijbuVZIkNBzTfagM=' 'sha256-vbs/XR7vkC12NXdDH8FEaUASiJdg/16cqF/0T3ze1ks=' 'sha256-4nxBwvGtrokGNkqD2OxOt8Y07P7caJHk00sGwjNYF5I=' 'sha256-/Fu0G2rh4wmpTYIDt4lb/x5WJp6zusqpavun8dZ8Yns=' 'sha256-yqVa7ver8F3o3KAsmdt2r10wQlIPCHuaBhkxEMbFQKE=' 'sha256-pZ/qdkaCfUhJbPDW6dxGk6IT/oRRR/mlpXeonIs9iew=' 'sha256-t2dxu6v8zWLBnuT0wS9gbS8+6dWSZKwyh8Oc1O+KFKM=' 'sha256-nOEqrdYQbjOqHNv8REn7NbgmgfgpHFGAMJeDad9+6Cc=' 'sha256-i9Hqrp5R5xqtEYAfxGINmtDPcds/LnLceINVGS0StZg=' 'sha256-5E/6sj96qbSHixz46qooKeWA+LIjK6XzdMgxXJYGMCo=' 'sha256-ZjDDDO/TrMCju3UiIns3DMC7cnl6jp0zh9NKm11JAyY=' 'sha256-pJrmX8BIQNU7+D+cF3F3p3Z/mHxe83gyTZAzRGq+YBE=' solutions.spiraxsarco.com ssl.google-analytics.com connect.facebook.net www.facebook.net www.google-analytics.com www.googletagmanager.com www.gstatic.com www.youtube.com platform.twitter.com cdn.syndication.twimg.com www.google.com accdn.lpsnmedia.net googleads.g.doubleclick.net js.hs-analytics.net js.hs-banner.com js.hs-scripts.com js.hsforms.net js.hsleadflows.net lo.v.liveperson.net lpcdn.lpsnmedia.net lptag.liveperson.net munchkin.marketo.net script.hotjar.com snap.licdn.com static.hotjar.com www.googleadservices.com www3.spiraxsarco.com cdn.calltrk.com pi.pardot.com bat.bing.com js.calltrk.com; style-src-elem *.onetrust.com 'self' solutions.spiraxsarco.com fonts.googleapis.com p.typekit.net use.typekit.net platform.twitter.com ton.twimg.com assets.calendly.com optimize.google.com www.googletagmanager.com 'unsafe-inline'; frame-src *.spiraxsarco.com *.doubleclick.net optimize.google.com vars.hotjar.com *.liveperson.net lpcdn.lpsnmedia.net www.traceparts.com traceparts-cache.s3.eu-west-1.amazonaws.com www.googletagmanager.com www.facebook.com www.google.com www.youtube.com m.youtube.com share.hsforms.com platform.twitter.com syndication.twitter.com player.vimeo.com calendly.com spiraxsarco.octadesk.com www.buzzsprout.com go.pardot.com www.linkedin.com; media-src 'self' *.spiraxsarco.com lpcdn.lpsnmedia.net; form-action 'self' resources.spiraxsarco.com; style-src-attr 'unsafe-inline'; object-src 'none'; base-uri 'self'; report-uri https://steam.report-uri.com/r/d/csp/enforce 1 object-src 'none'; script-src 'nonce-_k-FeXRWW7EshGF4oNmwFVv1' 'strict-dynamic' http: https:; base-uri 'none'; 1 ; default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.klaviyo.com *.paypalobjects.com *.licdn.com *.clarity.ms https://ttz41d7zd1.execute-api.eu-west-1.amazonaws.com/Prod/js storage.googleapis.com cdn.mxpnl.com *.finance-calculator.co.uk angus.finance-calculator.co.uk *.collector-11207.tvsquared.com collector-11207.tvsquared.com bat.bing.com cdn.sub2tech.com *.sub2tech.com dmtrk.net dmtrk.com r1.dmtrk.net r1.dmtrk.com r2.dmtrk.net r2.dmtrk.com r3.dmtrk.net r3.dmtrk.com ddlnk.net ddlnk.com r1.ddlnk.net r1.ddlnk.com r2.ddlnk.net r2.ddlnk.com r3.ddlnk.net r3.ddlnk.com t.trackedlink.net r1-t.trackedlink.net r2-t.trackedlink.net r3-t.trackedlink.net webinsight.s3.amazonaws.com static.trackedweb.net trackedweb.net r1.trackedweb.net r2.trackedweb.net r3.trackedweb.net i.emlfiles.com i.emlfiles1.com i.emlfiles2.com i.emlfiles3.com i.emlfiles4.com i.emlfiles5.com i.emlfiles6.com i.emlfiles7.com i.emlfiles8.com i.emfiles9.com r1.dotmailer-surveys.com r2.dotmailer-surveys.com r3.dotmailer-surveys.com r1.dotdigital-surveys.com r2.dotdigital-surveys.com r3.dotdigital-surveys.com *.dotdigital-pages.com script.hotjar.com player.vimeo.com www.googleoptimize.com *.bookingbug.com *.paypal.com static.trackedweb.net *.trackedlink.net *.gstatic.com static.zdassets.com *.trustpilot.com optimize.google.com tagmanager.google.com *.google.com *.google.ad *.google.ae *.google.com.af *.google.com.ag *.google.com.ai *.google.al *.google.am *.google.co.ao *.google.com.ar *.google.as *.google.at *.google.com.au *.google.az *.google.ba *.google.com.bd *.google.be *.google.bf *.google.bg *.google.com.bh *.google.bi *.google.bj *.google.com.bn *.google.com.bo *.google.com.br *.google.bs *.google.bt *.google.co.bw *.google.by *.google.com.bz *.google.ca *.google.cd *.google.cf *.google.cg *.google.ch *.google.ci *.google.co.ck *.google.cl *.google.cm *.google.cn *.google.com.co *.google.co.cr *.google.com.cu *.google.cv *.google.com.cy *.google.cz *.google.de *.google.dj *.google.dk *.google.dm *.google.com.do *.google.dz *.google.com.ec *.google.ee *.google.com.eg *.google.es *.google.com.et *.google.fi *.google.com.fj *.google.fm *.google.fr *.google.ga *.google.ge *.google.gg *.google.com.gh *.google.com.gi *.google.gl *.google.gm *.google.gr *.google.com.gt *.google.gy *.google.com.hk *.google.hn *.google.hr *.google.ht *.google.hu *.google.co.id *.google.ie *.google.co.il *.google.im *.google.co.in *.google.iq *.google.is *.google.it *.google.je *.google.com.jm *.google.jo *.google.co.jp *.google.co.ke *.google.com.kh *.google.ki *.google.kg *.google.co.kr *.google.com.kw *.google.kz *.google.la *.google.com.lb *.google.li *.google.lk *.google.co.ls *.google.lt *.google.lu *.google.lv *.google.com.ly *.google.co.ma *.google.md *.google.me *.google.mg *.google.mk *.google.ml *.google.com.mm *.google.mn *.google.ms *.google.com.mt *.google.mu *.google.mv *.google.mw *.google.com.mx *.google.com.my *.google.co.mz *.google.com.na *.google.com.ng *.google.com.ni *.google.ne *.google.nl *.google.no *.google.com.np *.google.nr *.google.nu *.google.co.nz *.google.com.om *.google.com.pa *.google.com.pe *.google.com.pg *.google.com.ph *.google.com.pk *.google.pl *.google.pn *.google.com.pr *.google.ps *.google.pt *.google.com.py *.google.com.qa *.google.ro *.google.ru *.google.rw *.google.com.sa *.google.com.sb *.google.sc *.google.se *.google.com.sg *.google.sh *.google.si *.google.sk *.google.com.sl *.google.sn *.google.so *.google.sm *.google.sr *.google.st *.google.com.sv *.google.td *.google.tg *.google.co.th *.google.com.tj *.google.tl *.google.tm *.google.tn *.google.to *.google.com.tr *.google.tt *.google.com.tw *.google.co.tz *.google.com.ua *.google.co.ug *.google.co.uk *.google.com.uy *.google.co.uz *.google.com.vc *.google.co.ve *.google.vg *.google.co.vi *.google.com.vn *.google.vu *.google.ws *.google.rs *.google.co.za *.google.co.zm *.google.co.zw *.google.cat *.facebook.net *.cquotient.com services.postcodeanywhere.co.uk cdn.cquotient.com www.googletagmanager.com googleads.g.doubleclick.net https://iploc.tryzens-analytics.com:12443 *.pcapredict.com maps.googleapis.com services.postcodeanywhere.co.uk *.collector-11207.tvsquared.com collector-11207.tvsquared.com bat.bing.com cdn.sub2tech.com *.collector-11207.tvsquared.com collector-11207.tvsquared.com *.sub2tech.com www.google-analytics.com p.cquotient.com static.hotjar.com www.googleadservices.com *.adyen.com geolocation.onetrust.com cdn.cookielaw.org *.googletagmanager.com extend.vimeocdn.com *.christopherward.com *.appointedd.com *.ratepay.com unpkg.com *.tryzens-analytics.com tally.so *.tally.so; style-src 'self' 'unsafe-inline' *.klaviyo.com angus.finance-calculator.co.uk storage.googleapis.com *.collector-11207.tvsquared.com collector-11207.tvsquared.com bat.bing.com cdn.sub2tech.com *.sub2tech.com *.paypalobjects.com dmtrk.net dmtrk.com r1.dmtrk.net r1.dmtrk.com r2.dmtrk.net r2.dmtrk.com r3.dmtrk.net r3.dmtrk.com ddlnk.net ddlnk.com r1.ddlnk.net r1.ddlnk.com r2.ddlnk.net r2.ddlnk.com r3.ddlnk.net r3.ddlnk.com t.trackedlink.net r1-t.trackedlink.net r2-t.trackedlink.net r3-t.trackedlink.net webinsight.s3.amazonaws.com static.trackedweb.net trackedweb.net r1.trackedweb.net r2.trackedweb.net r3.trackedweb.net i.emlfiles.com i.emlfiles1.com i.emlfiles2.com i.emlfiles3.com i.emlfiles4.com i.emlfiles5.com i.emlfiles6.com i.emlfiles7.com i.emlfiles8.com i.emfiles9.com r1.dotmailer-surveys.com r2.dotmailer-surveys.com r3.dotmailer-surveys.com r1.dotdigital-surveys.com r2.dotdigital-surveys.com r3.dotdigital-surveys.com *.adyen.com optimize.google.com tagmanager.google.com foursixty.com cdn.jsdelivr.net fonts.googleapis.com services.postcodeanywhere.co.uk cdn.cookielaw.org *.christopherward.com; frame-src 'self' *.doubleclick.net storage.googleapis.com *.surveymonkey.com *.finance-calculator.co.uk *.collector-11207.tvsquared.com collector-11207.tvsquared.com bat.bing.com cdn.sub2tech.com *.sub2tech.com *.dotdigital-pages.com *.bookingbug.com vars.hotjar.com *.paypal.com *.paypalobjects.com *.google.com widget.trustpilot.com *.youtube.com *.vimeo.com optimize.google.com www.facebook.com *.klarnaservices.com *.adyen.com extend.vimeocdn.com *.appointedd.com tally.so *.tally.so https://www.googletagmanager.com https://data.christopherward.com; child-src 'none'; img-src 'self' data: *.doubleclick.net *.vimeocdn.com *.clarity.ms px.ads.linkedin.com c.bing.com storage.googleapis.com angus.finance-calculator.co.uk *.paypalobjects.com dmtrk.net dmtrk.com r1.dmtrk.net r1.dmtrk.com r2.dmtrk.net r2.dmtrk.com r3.dmtrk.net r3.dmtrk.com ddlnk.net ddlnk.com r1.ddlnk.net r1.ddlnk.com r2.ddlnk.net r2.ddlnk.com r3.ddlnk.net r3.ddlnk.com t.trackedlink.net r1-t.trackedlink.net r2-t.trackedlink.net r3-t.trackedlink.net webinsight.s3.amazonaws.com static.trackedweb.net trackedweb.net r1.trackedweb.net r2.trackedweb.net r3.trackedweb.net i.emlfiles.com i.emlfiles1.com i.emlfiles2.com i.emlfiles3.com i.emlfiles4.com i.emlfiles5.com i.emlfiles6.com i.emlfiles7.com i.emlfiles8.com i.emfiles9.com r1.dotmailer-surveys.com r2.dotmailer-surveys.com r3.dotmailer-surveys.com r1.dotdigital-surveys.com r2.dotdigital-surveys.com r3.dotdigital-surveys.com www.jrni.com *.bookingbug.com *.paypal.com stats.g.doubleclick.net *.collector-11207.tvsquared.com collector-11207.tvsquared.com bat.bing.com cdn.sub2tech.com *.sub2tech.com edge.disstg.commercecloud.salesforce.com *.collector-11207.tvsquared.com collector-11207.tvsquared.com cdn.sub2tech.com *.sub2tech.com www.google-analytics.com *.paypalobjects.com static.secure-afterpay.com.au um.simpli.fi www.instagram.com www.googletagmanager.com services.postcodeanywhere.co.uk pixel.mathtag.com aa.agkn.com cx.atdmt.com www.facebook.com *.pbbl.co *.optimove.net *.google.com *.google.ad *.google.ae *.google.com.af *.google.com.ag *.google.com.ai *.google.al *.google.am *.google.co.ao *.google.com.ar *.google.as *.google.at *.google.com.au *.google.az *.google.ba *.google.com.bd *.google.be *.google.bf *.google.bg *.google.com.bh *.google.bi *.google.bj *.google.com.bn *.google.com.bo *.google.com.br *.google.bs *.google.bt *.google.co.bw *.google.by *.google.com.bz *.google.ca *.google.cd *.google.cf *.google.cg *.google.ch *.google.ci *.google.co.ck *.google.cl *.google.cm *.google.cn *.google.com.co *.google.co.cr *.google.com.cu *.google.cv *.google.com.cy *.google.cz *.google.de *.google.dj *.google.dk *.google.dm *.google.com.do *.google.dz *.google.com.ec *.google.ee *.google.com.eg *.google.es *.google.com.et *.google.fi *.google.com.fj *.google.fm *.google.fr *.google.ga *.google.ge *.google.gg *.google.com.gh *.google.com.gi *.google.gl *.google.gm *.google.gr *.google.com.gt *.google.gy *.google.com.hk *.google.hn *.google.hr *.google.ht *.google.hu *.google.co.id *.google.ie *.google.co.il *.google.im *.google.co.in *.google.iq *.google.is *.google.it *.google.je *.google.com.jm *.google.jo *.google.co.jp *.google.co.ke *.google.com.kh *.google.ki *.google.kg *.google.co.kr *.google.com.kw *.google.kz *.google.la *.google.com.lb *.google.li *.google.lk *.google.co.ls *.google.lt *.google.lu *.google.lv *.google.com.ly *.google.co.ma *.google.md *.google.me *.google.mg *.google.mk *.google.ml *.google.com.mm *.google.mn *.google.ms *.google.com.mt *.google.mu *.google.mv *.google.mw *.google.com.mx *.google.com.my *.google.co.mz *.google.com.na *.google.com.ng *.google.com.ni *.google.ne *.google.nl *.google.no *.google.com.np *.google.nr *.google.nu *.google.co.nz *.google.com.om *.google.com.pa *.google.com.pe *.google.com.pg *.google.com.ph *.google.com.pk *.google.pl *.google.pn *.google.com.pr *.google.ps *.google.pt *.google.com.py *.google.com.qa *.google.ro *.google.ru *.google.rw *.google.com.sa *.google.com.sb *.google.sc *.google.se *.google.com.sg *.google.sh *.google.si *.google.sk *.google.com.sl *.google.sn *.google.so *.google.sm *.google.sr *.google.st *.google.com.sv *.google.td *.google.tg *.google.co.th *.google.com.tj *.google.tl *.google.tm *.google.tn *.google.to *.google.com.tr *.google.tt *.google.com.tw *.google.co.tz *.google.com.ua *.google.co.ug *.google.co.uk *.google.com.uy *.google.co.uz *.google.com.vc *.google.co.ve *.google.vg *.google.co.vi *.google.com.vn *.google.vu *.google.ws *.google.rs *.google.co.za *.google.co.zm *.google.co.zw *.google.cat *.gstatic.com *.googleapis.com *.google.com *.adyen.com t1.stormiq.com cdn.cookielaw.org *.google-analytics.com *.analytics.google.com *.googletagmanager.com *.g.doubleclick.net *.christopherward.com *.cloudflare.com *.ctfassets.net bat.bing.net; font-src 'self' data: www.christopherward.com fonts.gstatic.com res.cloudinary.com *.paypalobjects.com googleads.g.doubleclick.net; connect-src 'self' *.onetrust.com *.mixpanel.com *.klaviyo.com *.collector-11207.tvsquared.com g.clarity.ms clarity.ms collector-11207.tvsquared.com bat.bing.com cdn.sub2tech.com *.sub2tech.com angus.finance-calculator.co.uk dmtrk.net dmtrk.com r1.dmtrk.net r1.dmtrk.com r2.dmtrk.net r2.dmtrk.com r3.dmtrk.net r3.dmtrk.com ddlnk.net ddlnk.com r1.ddlnk.net r1.ddlnk.com r2.ddlnk.net r2.ddlnk.com r3.ddlnk.net r3.ddlnk.com t.trackedlink.net r1-t.trackedlink.net r2-t.trackedlink.net r3-t.trackedlink.net webinsight.s3.amazonaws.com static.trackedweb.net trackedweb.net r1.trackedweb.net r2.trackedweb.net r3.trackedweb.net i.emlfiles.com i.emlfiles1.com i.emlfiles2.com i.emlfiles3.com i.emlfiles4.com i.emlfiles5.com i.emlfiles6.com i.emlfiles7.com i.emlfiles8.com i.emfiles9.com r1.dotmailer-surveys.com r2.dotmailer-surveys.com r3.dotmailer-surveys.com r1.dotdigital-surveys.com r2.dotdigital-surveys.com r3.dotdigital-surveys.com wss://*.hotjar.com *.hotjar.com *.hotjar.io *.paypal.com *.adyen.com widget.trustpilot.com wss://widget-mediator.zopim.com christopherward.zendesk.com *.trackedweb.net ekr.zdassets.com https://ttz41d7zd1.execute-api.eu-west-1.amazonaws.com/Prod/js* *.klarnaevt.com stats.g.doubleclick.net www.facebook.com https://www.tryzens-analytics.com:12280 *.pinterest.com *.klarnauserservices.com *.optimove.events www.google-analytics.com *.hotjar.com *.optimove.net *.hotjar.io https://uat.tryzens-analytics.com:12280 api.cquotient.com services.postcodeanywhere.co.uk cdn.cookielaw.org *.google-analytics.com *.analytics.google.com *.googletagmanager.com *.g.doubleclick.net *.google.com *.google.ad *.google.ae *.google.com.af *.google.com.ag *.google.com.ai *.google.al *.google.am *.google.co.ao *.google.com.ar *.google.as *.google.at *.google.com.au *.google.az *.google.ba *.google.com.bd *.google.be *.google.bf *.google.bg *.google.com.bh *.google.bi *.google.bj *.google.com.bn *.google.com.bo *.google.com.br *.google.bs *.google.bt *.google.co.bw *.google.by *.google.com.bz *.google.ca *.google.cd *.google.cf *.google.cg *.google.ch *.google.ci *.google.co.ck *.google.cl *.google.cm *.google.cn *.google.com.co *.google.co.cr *.google.com.cu *.google.cv *.google.com.cy *.google.cz *.google.de *.google.dj *.google.dk *.google.dm *.google.com.do *.google.dz *.google.com.ec *.google.ee *.google.com.eg *.google.es *.google.com.et *.google.fi *.google.com.fj *.google.fm *.google.fr *.google.ga *.google.ge *.google.gg *.google.com.gh *.google.com.gi *.google.gl *.google.gm *.google.gr *.google.com.gt *.google.gy *.google.com.hk *.google.hn *.google.hr *.google.ht *.google.hu *.google.co.id *.google.ie *.google.co.il *.google.im *.google.co.in *.google.iq *.google.is *.google.it *.google.je *.google.com.jm *.google.jo *.google.co.jp *.google.co.ke *.google.com.kh *.google.ki *.google.kg *.google.co.kr *.google.com.kw *.google.kz *.google.la *.google.com.lb *.google.li *.google.lk *.google.co.ls *.google.lt *.google.lu *.google.lv *.google.com.ly *.google.co.ma *.google.md *.google.me *.google.mg *.google.mk *.google.ml *.google.com.mm *.google.mn *.google.ms *.google.com.mt *.google.mu *.google.mv *.google.mw *.google.com.mx *.google.com.my *.google.co.mz *.google.com.na *.google.com.ng *.google.com.ni *.google.ne *.google.nl *.google.no *.google.com.np *.google.nr *.google.nu *.google.co.nz *.google.com.om *.google.com.pa *.google.com.pe *.google.com.pg *.google.com.ph *.google.com.pk *.google.pl *.google.pn *.google.com.pr *.google.ps *.google.pt *.google.com.py *.google.com.qa *.google.ro *.google.ru *.google.rw *.google.com.sa *.google.com.sb *.google.sc *.google.se *.google.com.sg *.google.sh *.google.si *.google.sk *.google.com.sl *.google.sn *.google.so *.google.sm *.google.sr *.google.st *.google.com.sv *.google.td *.google.tg *.google.co.th *.google.com.tj *.google.tl *.google.tm *.google.tn *.google.to *.google.com.tr *.google.tt *.google.com.tw *.google.co.tz *.google.com.ua *.google.co.ug *.google.co.uk *.google.com.uy *.google.co.uz *.google.com.vc *.google.co.ve *.google.vg *.google.co.vi *.google.com.vn *.google.vu *.google.ws *.google.rs *.google.co.za *.google.co.zm *.google.co.zw *.google.cat google.com/pay extend.vimeocdn.com unpkg.com *.tryzens-analytics.com player.vimeo.com download-video-ak.vimeocdn.com px.ads.linkedin.com https://data.christopherward.com ; form-action 'self' http://portal.afterpay.com http://portal-sandbox.afterpay.com *.playground.klarna.com *.klarna.com *.afterpay.com www.facebook.com *.collector-11207.tvsquared.com collector-11207.tvsquared.com bat.bing.com cdn.sub2tech.com *.sub2tech.com *.paypal.com *.adyen.com https://data.christopherward.com px.ads.linkedin.com; media-src 'self' static.zdassets.com res.cloudinary.com *.akamaized.net download-video-ak.vimeocdn.com player.vimeo.com;; report-uri https://chw-csp.tryzens-analytics.com; 1 frame-src *.force.com https://player.vimeo.com 'self' https://stats.g.doubleclick.net https://gmocloudcommunity.force.com *.youtube.co.uk https://sfdc-link-preview.hk.salesforce.com https://b99.yahoo.co.jp https://checkoutshopper-test.adyen.com/ https://pal-test.adyen.com https://www.google.co.jp *.cybersource.com *.youtube.es https://www.domainking.jp *.adis.ws https://www.wadax.ne.jp https://jpn160.sfdc-p1i6qd.salesforce.com *.youtube.ie https://www.youtube.com *.cloudinary.com https://www.google.com https://pay.google.com https://analytics.google.com *.vimeo.com *.youtube.jp bcove.video *.youtube.fr https://altus.gmocloud.com https://*.a.forceusercontent.com https://player.cloudinary.com https://dnsck.gmocloud.com https://sfdc-link-preview-staging.sfdc.sh https://s1.adis.ws *.forceusercontent.com *.youtube.com *.brightcove.net *.youtube.nl https://service.force.com/embeddedservice/ https://faq.wadax.ne.jp https://fast.wistia.net *.quip.com *.arkoselabs.com *.youtube-nocookie.com https://www.paypal.com https://appiniummastertrial.secure.force.com https://play.vidyard.com https://translation.googleapis.com *.youtube.com.br https://icl.dns.ishioka.xyz *.salesforce-experience.com *.salesforceliveagent.com https://scormanywhere.secure.force.com https://gmogshd-ch.file.force.com https://checkoutshopper-live.adyen.com/ *.sfdcfc.net *.youtube.ca https://location.force.com *.vidyard.com https://www.gstatic.com/recaptcha/ https://players.brightcove.net https://cdn.embedly.com https://www.google.com/recaptcha/ https://js.stripe.com/ https://www.sandbox.paypal.com https://support.gmocloud.com https://*.a.forceusercontent.com/lightningmaps/ https://www.googletagmanager.com *.wistia.net https://www.google-analytics.com *.salesforce.com https://www.rapidsite.jp *.youtube.pl; report-to sfdc-csp-ep; report-uri https://gmogshd-ch.lightning.force.com/_/ContentDomainCSPNoAuth?tenantId=00D10000000Hq6P&networkId=0DM5F00000001rL&type=communities 1 default-src 'self'; base-uri 'self'; object-src 'none'; frame-ancestors 'self'; frame-src 'self' https://www.googletagmanager.com https://i.liadm.com; form-action 'self'; img-src 'self' data: https:; font-src 'self' data: https://fonts.gstatic.com https://use.typekit.net; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://use.typekit.net; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://mm-uxrv.com https://www.datadoghq-browser-agent.com https://ppham.rankandstyle.com https://www.googletagmanager.com https://www.google-analytics.com https://www.google.com https://www.gstatic.com https://d1igp3oop3iho5.cloudfront.net https://cdn-magiclinks.trackonomics.net https://loader.wisepops.com https://notifications.wisepops.com https://wisepops.net https://cdn.wisepops.com https://d-code.liadm.com https://a.usbrowserspeed.com https://a.aisiteanalytics.com; script-src-elem 'self' 'unsafe-inline' https://www.googletagmanager.com https://www.google-analytics.com https://www.google.com https://www.gstatic.com https://www.datadoghq-browser-agent.com https://mm-uxrv.com https://ppham.rankandstyle.com https://d1igp3oop3iho5.cloudfront.net https://cdn-magiclinks.trackonomics.net https://loader.wisepops.com https://notifications.wisepops.com https://wisepops.net https://cdn.wisepops.com https://d-code.liadm.com https://a.usbrowserspeed.com https://a.aisiteanalytics.com; connect-src 'self' https://browser-intake-datadoghq.eu https://region1.analytics.google.com https://www.google-analytics.com https://www.google.com https://stats.g.doubleclick.net https://api.zaius.com https://activity.wisepops.com https://wisepops.net https://tracking.wisepops.com https://a.aisiteanalytics.com https://ppham.rankandstyle.com https://fr-actions.trackonomics.net https://idx.liadm.com https://rp.liadm.com; worker-src 'self' blob: https://www.datadoghq-browser-agent.com; report-uri https://europe-west3-savingsunited-production.cloudfunctions.net/csp-report 1 default-src 'self'; script-src 'self' *.salesforce.com 'report-sample'; style-src 'unsafe-inline' 'self' *.file.force.com *.salesforce.com *.visualforce.com:*; img-src *.force.com slack-mil-dev.com slack-imgs-mil-dev.com 'self' *.slack.com *.amazonaws.com blob: *.slack-imgs.com slack-imgs-gov.com *.slack-edge.mil *.salesforce-experience.com slack-imgs.com slack-gov-dev.com *.sfdcstatic.com *.slack-edge-gov.com *.salesforce.com *.twimg.com *.my-salesforce.com slack-imgs-gov-dev.com *.slack-edge.com slack-imgs.mil *.cloudinary.com data:; media-src 'self' *.salesforce.com; frame-src *.force.com *.quip.com *.arkoselabs.com 'self' *.youtube-nocookie.com *.youtube.co.uk *.cybersource.com *.youtube.com.br *.youtube.es *.salesforce-experience.com *.salesforceliveagent.com *.adis.ws *.sfdcfc.net *.youtube.ca *.youtube.ie *.cloudinary.com *.vidyard.com *.vimeo.com *.youtube.jp bcove.video *.youtube.fr *.forceusercontent.com *.youtube.com *.brightcove.net *.wistia.net *.salesforce.com *.youtube.nl *.youtube.pl; font-src *.force.com 'self' *.salesforce.com blob: data:; connect-src 'self' *.amazonaws.com *.salesforce.com api.salesforce.com *.api.salesforce.com wss://*.slack.com; report-to sfdc-csp-ep; report-uri https://csp-report.force.com/_/ContentDomainCSPNoAuth?type=login 1 default-src 'none'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com https://www.google-analytics.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; img-src 'self' data: https://elegant-harmony-f8a4c00980.strapiapp.com https://elegant-harmony-f8a4c00980.media.strapiapp.com https://cms.sandbox-london-b.fetch-ai.com https://res.cloudinary.com; font-src 'self' https://fonts.gstatic.com; media-src 'self' https://www.dropbox.com https://*.dropboxusercontent.com; connect-src 'self' https://www.google-analytics.com; frame-ancestors 'none'; base-uri 'self'; object-src 'none'; 1 base-uri 'none'; font-src 'self' data: https://sumdog.com https://*.sumdog.com netdna.bootstrapcdn.com fonts.gstatic.com fonts.googleapis.com script.hotjar.com; img-src 'self' blob: data: visualisations0.sumdog.com https://sumdog.com https://*.sumdog.com imgsct.cookiebot.com s3.eu-west-1.amazonaws.com; object-src 'none'; script-src 'self' 'unsafe-eval' 'wasm-unsafe-eval' https://sumdog.com https://*.sumdog.com https://students.sumdog.com/WebGL/Core/Build/ *.cookiebot.com www.googletagmanager.com/gtag www.google.com/recaptcha/api.js www.gstatic.com/recaptcha/* www.googleoptimize.com *.paypal.com www.paypalobjects.com *.cardinalcommerce.com *.hotjar.com 'unsafe-hashes' 'sha256-gPjlli1HEdLlR0AZTY971/wQVOdSkl9mEinLnxrPpJw=' 'nonce-49f4f8b051e75f51073fbb879e76a6b0'; style-src 'self' 'unsafe-inline' https://sumdog.com https://*.sumdog.com *.cookiebot.com assets0.sumdog.com fonts.googleapis.com accounts.google.com assets.braintreegateway.com; report-uri /csp-violation-report; connect-src * blob: data:; media-src 'self' blob: https://sumdog.com https://*.sumdog.com questions-assets0.sumdog.com; frame-src * 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.klarnacdn.net https://fonts.gstatic.com data: *.klevu.com *.flixcar.com *.flixfacts.com https://bf-content.elon.se https://c.bannerflow.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.klarna.com *.klevu.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com https://briqpay.test *.briqpay.com *.klarna.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.hotjar.com *.klarnaservices.com *.ingrid.com *.klarnaevt.com *.dibspayment.eu 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.klarna.com *.klarnaevt.com *.klarnacdn.net https://*.google.com https://*.googleapis.com https://*.googleusercontent.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.adnxs.com *.omtrdc.net *.bing.com *.cloudflare.com *.cookiebot.com *.elongroup.se *.elon.se elon.se *.facebook.com *.googleadservices.com *.google-analytics.com *.google.se *.googletagmanager.com *.googleapis.com *.imbox.io *.klevu.com *.klarnaservices.com *.vaimo.net *.ytimg.com *.pricerunner.se *.flixcar.com *.flixfacts.com *.flix360.com *.flix360.io *.jwpsrv.com *.jwplayer.com *.uc.se *.prisjakt.no *.googlesyndication.com *.where-to-buy.co *.clarity.ms *.doubleclick.net *.dialogtrail.com *.lemonpi.io *.facebook.net *.reddit.com *.elon.no *.wistia.com *.videoly.co https://where-to-buy.co https://bf-content.elon.se https://c.bannerflow.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://briqpay.test *.briqpay.com *.klarna.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.gstatic.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.adnxs.com *.bing.com *.clarity.ms *.cookiebot.com *.depict.ai *.elongroup.se *.facebook.net *.googletagmanager.com *.googleapis.com *.hotjar.com *.imbox.io *.klevu.com *.myvisitors.se *.oribi.io *.pertento.ai *.pinimg.com *.pinterest.com *.testfreaks.com *.charpstar.net *.flixfacts.com *.loadbee.com *.flix360.io *.flixcar.com *.unpkg.com *.dialogtrail.com *.adform.net *.elon.se *.cloudfront.net *.videoly.co *.scaleflex.it *.redditstatic.com *.voyado.com https://unpkg.com https://bf-content.elon.se https://c.bannerflow.net *.ingrid.com *.klarnaevt.com https://www.elon.se 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; style-src *.adobe.com fonts.googleapis.com *.klarnacdn.net https://fonts.googleapis.com https://hcaptcha.com https://*.hcaptcha.com assets.braintreegateway.com *.depict.ai *.dibspayment.eu *.googleapis.com *.gstatic.com *.klevu.com *.flixcar.com https://www.elon.se 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.flixcar.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.klarnaevt.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.klarna.com https://ipinfo.io https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.adnxs.com *.demdex.net *.clarity.ms *.cookiebot.com *.depict.ai *.dibspayment.eu *.google-analytics.com *.g.doubleclick.net *.hotjar.com *.hotjar.io *.klarnauserservices.com *.ksearchnet.com *.pertento.ai *.pinterest.com security-hub.vaimo.network *.apptus.cloud *.iconify.design *.dialogtrail.com *.flix360.io *.charpstar.net *.loadbee.com *.flixcar.com *.googlesyndication.com *.elon.no *.bing.com *.facebook.com *.reddit.com *.unisvg.com wss://ws.depict.ai wss://headless.dialogtrail.com https://bf-content.elon.se https://c.bannerflow.net 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'none'; base-uri 'self'; block-all-mixed-content; connect-src 'self' support.webkeeper.ch wss://support.webkeeper.ch www.google-analytics.com my.webkeeper.ch stats.g.doubleclick.net; font-src * data:; form-action 'self' www.webkeeper.ch; frame-ancestors 'none'; frame-src support.webkeeper.ch; img-src * data:; manifest-src 'self'; media-src support.webkeeper.ch; script-src 'self' 'unsafe-inline' 'unsafe-eval' support.webkeeper.ch www.google-analytics.com maps.googleapis.com developers.google.com treellionaire.com data:; style-src 'self' 'unsafe-inline' support.webkeeper.ch fonts.googleapis.com data:; report-uri /csp-report.php 1 default-src 'self' 'unsafe-inline' 'unsafe-eval' puravida.com.br *.puravida.com.br wake-components.fbitsstatic.net puravida.fbitsstatic.net *.wake.tech fbits.net nr-data.net newrelic.com google.com googletagmanager.com google-analytics.com facebook.net facebook.com jquery.com bootstrapcdn.com *.fbits.net *.nr-data.net *.newrelic.com *.google.com *.googletagmanager.com *.google-analytics.com *.facebook.net *.facebook.com *.jquery.com *.bootstrapcdn.com wss://signalr.fbits.net k-analytix.com *.k-analytix.com i.konduto.com static.traycheckout.com.br *.traycheckout.com.br *.yapay.com.br *.traycheckout.com.br h.online-metrix.net *.clearsale.com.br *.2listen.com.br *.googleadservices.com *.trackcmp.net *.soclminer.com.br static.hotjar.com *.hotjar.com cdn.convertbox.com googleadservices.com wss://ws11.hotjar.com wss://ws9.hotjar.com wss://ws3.hotjar.com wss://ws18.hotjar.com wss://ws21.hotjar.com wss://ws1.hotjar.com wss://ws13.hotjar.com wss://ws20.hotjar.com wss://ws23.hotjar.com *.hotjar.io vars.hotjar.com wss://ws4.hotjar.com wss://ws16.hotjar.com wss://ws8.hotjar.com wss://ws15.hotjar.com wss://ws5.hotjar.com wss://ws12.hotjar.com wss://ws14.hotjar.com wss://ws22.hotjar.com wss://ws10.hotjar.com wss://ws19.hotjar.com wss://ws6.hotjar.com wss://ws25.hotjar.com wss://ws17.hotjar.com wss://ws7.hotjar.com wss://ws2.hotjar.com wss://ws24.hotjar.com dzpxyxks1bfmb.cloudfront.net *.getblue.io *.criteo.com *.criteo.net *.g.doubleclick.net *.cloudfront.net *.dwin1.com *.awin1.com *.zenaps.com *.sciencebehindecommerce.com artfut.com *.artfut.com *.pinimg.com *.bing.com *.metaffiliation.com *.2eb4a95jq.de ws.puravida.com.br *.doubleclick.net *.rdstation.com.br googleoptimize.com smct.co browser.sentry-cdn.com *.sentry.io *.bambuser.com *.btg360.com.br *.smct.co *.smct.io *.amazonaws.com *.reclameaqui.com.br *.pinterest.com *.socialminer.com *.gstatic.com *.dsspn.com *.afftrack.pro *.clarity.ms *.cloudflare.com *.koin.com.br *.soclminer.com.br *.btg360.com.br *.socialminer.com samuraiexpertsstorage.blob.core.windows.net recorrencia-samurai.azurewebsites.net analytics.tiktok.com *.googleoptimize.com *.oli.live mautic.puravida.com.br signalrcore.fbits.net wss://signalrcore.fbits.net survey.solucx.com.br *.cloudfront.net service.smarthint.co *.useinsider.com *.mlstatic.com *.mercadopago.com *.mercadolibre.com *.mercadopago.com.br *.paypal.com *.paypalobjects.com *.licdn.com *.appspot.com *.purplemetrics.com.br *.fbitsstatic.net *.linkedin.com *.google.com.br *.googleapis.com *.unpkg.com *.fbits.store *.puravida.com.br *.adyen.com *.jsdelivr.net cdn.jsdelivr.net *.pagar.me *.mundipagg.com pvecommercefiles.blob.core.windows.net *.blob.core.windows.net *.getnet.com.br *.braintree-api.com *.braintreegateway.com *.pagseguro.com.br *.pagbank.com *.vindi.com.br *.cieloecommerce.cielo.com.br *.braspag.com.br *.pagador.com.br *.online-metrix.net bt-wake-connector.com.br *.datadoghq-browser-agent.com *.datadoghq.com *.browser-intake-us3-datadoghq.com browser-intake-us3-datadoghq.com *.pagaleve.com.br *.pagaleve.io wake-api.pagaleve.com.br securegtm.despegar.com api.ipify.org browser-intake-datadoghq.com *.datadoghq-browser-agent.com *.datadoghq.com *.specialone.io unpkg.com wake.koin.com.br temp-puravidalabs-backend-pvclub-black-friday-production.azurewebsites.net paypal-wake.s3.us-east-1.amazonaws.com puravidalabs-backend-ecommerce-optin-service-p.azurewebsites.net *.cardinalcommerce.com *.secureacs.com api.globalgetnet.com *.globalgetnet.com *.sandbox.3dsecure.io *.crmback.io *.crmback.dev *.crmback.com x.cbstatus.net *.3dsecure.io *.cookielaw.org *.googlesyndication.com puravidalabs-backend-ecommerce-orders-api-production.azurewebsites.net puravida-br.mais.social trackings.nemu.com.br *.openfpcdn.io *.ipinfo.io api.ipify.org api.bigdatacloud.net *.visualwebsiteoptimizer.com app.vwo.com puravidalabs-backend-ecommerce-customers-api-production.azurewebsites.net *.visa.com openfpcdn.io *.wake.tech *.appmax.com.br *.tunagateway.com *.pagoexpress.com.br ; img-src https: data:; style-src https: 'unsafe-inline'; font-src https: data:; frame-ancestors *.puravida.com.br puravida.com.br; report-uri https://pub-csp.fbits.net/checkout_sem_carrinho; report-to https://pub-csp.fbits.net/checkout_sem_carrinho; worker-src 'self' blob:; 1 default-src https: wss://ws.tsarvar.com wss://wst.tsarvar.com wss://wst2.tsarvar.com; script-src https: 'unsafe-eval' 'unsafe-inline'; style-src https: 'unsafe-inline'; img-src https: data:; font-src https: data: 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com cash-f.squarecdn.com maxcdn.bootstrapcdn.com *.fontawesome.com data: *.googleapis.com *.acsbapp.com acsbapp.com *.laderach.com laderach.com https://fonts.bunny.net https://fonts.gstatic.com *.cloudflare.com *.bootstrapcdn.com *.twitter.com nitropack.io *.nitrocdn.com https://cdnjs.cloudflare.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com * https://plumrocket.com www.facebook.com *.adyen.com laderach.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com * www.googletagmanager.com https://plumrocket.com consentcdn.cookiebot.com *.addthis.com *.avada.io *.paypalobjects.com www.facebook.com tpc.googlesyndication.com vars.hotjar.com *.laderach.com *.demdex.net *.vimeo.com *.doubleclick.net laderach.com policy.app.cookieinformation.com *.trustpilot.com *.twitter.com nitropack.io 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io * https://images.unsplash.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ magefan.com cm.magefan.com *.facebook.com *.google.com *.googleadservices.com *.google-analytics.com *.googletagmanager.com maps.gstatic.com *.ytimg.com *.vimeocdn.com *.facebook.net *.acsbapp.com *.googleusercontent.com *.googleapis.com *.clarity.ms *.bing.com *.google.de *.google.es *.doubleclick.net *.paypalobjects.com services.postcodeanywhere.co.uk laderach.isa-test.de www.facebook.com bat.bing.com googletagmanager.com *.google.ad *.google.ae *.google.com.af *.google.com.ag *.google.com.ai *.google.al *.google.am *.google.co.ao *.google.com.ar *.google.as *.google.at *.google.com.au *.google.az *.google.ba *.google.com.bd *.google.be *.google.bf *.google.bg *.google.com.bh *.google.bi *.google.bj *.google.com.bn *.google.com.bo *.google.com.br *.google.bs *.google.bt *.google.co.bw *.google.by *.google.com.bz *.google.ca *.google.cd *.google.cf *.google.cg *.google.ch *.google.ci *.google.co.ck *.google.cl *.google.cm *.google.cn *.google.com.co *.google.co.cr *.google.com.cu *.google.cv *.google.com.cy *.google.cz *.google.dj *.google.dk *.google.dm *.google.com.do *.google.dz *.google.com.ec *.google.ee *.google.com.eg *.google.com.et *.google.fi *.google.com.fj *.google.fm *.google.fr *.google.ga *.google.ge *.google.gg *.google.com.gh *.google.com.gi *.google.gl *.google.gm *.google.gr *.google.com.gt *.google.gy *.google.com.hk *.google.hn *.google.hr *.google.ht *.google.hu *.google.co.id *.google.ie *.google.co.il *.google.im *.google.co.in *.google.iq *.google.is *.google.it *.google.je *.google.com.jm *.google.jo *.google.co.jp *.google.co.ke *.google.com.kh *.google.ki *.google.kg *.google.co.kr *.google.com.kw *.google.kz *.google.la *.google.com.lb *.google.li *.google.lk *.google.co.ls *.google.lt *.google.lu *.google.lv *.google.com.ly *.google.co.ma *.google.md *.google.me *.google.mg *.google.mk *.google.ml *.google.com.mm *.google.mn *.google.ms *.google.com.mt *.google.mu *.google.mv *.google.mw *.google.com.mx *.google.com.my *.google.co.mz *.google.com.na *.google.com.ng *.google.com.ni *.google.ne *.google.nl *.google.no *.google.com.np *.google.nr *.google.nu *.google.co.nz *.google.com.om *.google.com.pa *.google.com.pe *.google.com.pg *.google.com.ph *.google.com.pk *.google.pl *.google.pn *.google.com.pr *.google.ps *.google.pt *.google.com.py *.google.com.qa *.google.ro *.google.ru *.google.rw *.google.com.sa *.google.com.sb *.google.sc *.google.se *.google.com.sg *.google.sh *.google.si *.google.sk *.google.com.sl *.google.sn *.google.so *.google.sm *.google.sr *.google.st *.google.com.sv *.google.td *.google.tg *.google.co.th *.google.com.tj *.google.tl *.google.tm *.google.tn *.google.to *.google.com.tr *.google.tt *.google.com.tw *.google.co.tz *.google.com.ua *.google.co.ug *.google.co.uk *.google.com.uy *.google.co.uz *.google.com.vc *.google.co.ve *.google.vg *.google.co.vi *.google.com.vn *.google.vu *.google.ws *.google.rs *.google.co.za *.google.co.zm *.google.co.zw *.google.cat *.laderach.com laderach.com *.disqus.com https://firebasestorage.googleapis.com *.cloudflare.com *.twitter.com *.contentsquare.net nitropack.io *.nitrocdn.com https://redchamps.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com *.cash.app *.visa.com *.mastercard.com *.googleapis.com https://maps.googleapis.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ connect.facebook.net *.googletagmanager.com *.googleadservices.com *.google-analytics.com consent.cookiebot.com *.addthisedge.com *.addthis.com *.moatads.com acsbapp.com *.acsbapp.com googletagmanager.com *.doubleclick.net *.gstatic.com *.paypalobjects.com static.addtoany.com lader11112.pcapredict.com services.postcodeanywhere.co.uk checkoutshopper-live.adyen.com g3367433695.co g3565518030.co g6140614385.co g15252493795.co g15450578130.co g15648662465.co *.cloudflare.com tpc.googlesyndication.com static.hotjar.com script.hotjar.com bat.bing.com *.clarity.ms *.laderach.com laderach.com *.disqus.com *.avada.io *.shopify.com https://z.moatads.com https://v1.addthisedge.com https://cdn.jsdelivr.net policy.app.cookieinformation.com *.fontawesome.com graph.facebook.com *.trustpilot.com *.vimeo.com widgets.pinterest.com *.contentsquare.com *.contentsquare.net cdn.tailwindcss.com cdn.jsdelivr.net code.jquery.com cdnjs.cloudflare.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.cash.app https://static.klaviyo.com maxcdn.bootstrapcdn.com cdnjs.cloudflare.com *.googleapis.com *.gstatic.com services.postcodeanywhere.co.uk *.laderach.com laderach.com https://fonts.bunny.net https://fonts.googleapis.com https://cdn.jsdelivr.net *.cloudflare.com *.twitter.com cdn.tailwindcss.com nitropack.io *.nitrocdn.com cdn.jsdelivr.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.youtube-nocookie.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com * *.googleapis.com https://maps.googleapis.com https://player.vimeo.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.google-analytics.com *.analytics.google.com *.googletagmanager.com stats.g.doubleclick.net googletagmanager.com *.addthis.com *.facebook.com facebook.com *.acsbapp.com *.doubleclick.net wss://ws30.hotjar.com *.hotjar.io *.hotjar.com metrics.laderach.com *.clarity.ms services.postcodeanywhere.co.uk bat.bing.com *.google.ad *.google.ae *.google.com.af *.google.com.ag *.google.com.ai *.google.al *.google.am *.google.co.ao *.google.com.ar *.google.as *.google.at *.google.com.au *.google.az *.google.ba *.google.com.bd *.google.be *.google.bf *.google.bg *.google.com.bh *.google.bi *.google.bj *.google.com.bn *.google.com.bo *.google.com.br *.google.bs *.google.bt *.google.co.bw *.google.by *.google.com.bz *.google.ca *.google.cd *.google.cf *.google.cg *.google.ch *.google.ci *.google.co.ck *.google.cl *.google.cm *.google.cn *.google.com.co *.google.co.cr *.google.com.cu *.google.cv *.google.com.cy *.google.cz *.google.de *.google.dj *.google.dk *.google.dm *.google.com.do *.google.dz *.google.com.ec *.google.ee *.google.com.eg *.google.es *.google.com.et *.google.fi *.google.com.fj *.google.fm *.google.fr *.google.ga *.google.ge *.google.gg *.google.com.gh *.google.com.gi *.google.gl *.google.gm *.google.gr *.google.com.gt *.google.gy *.google.com.hk *.google.hn *.google.hr *.google.ht *.google.hu *.google.co.id *.google.ie *.google.co.il *.google.im *.google.co.in *.google.iq *.google.is *.google.it *.google.je *.google.com.jm *.google.jo *.google.co.jp *.google.co.ke *.google.com.kh *.google.ki *.google.kg *.google.co.kr *.google.com.kw *.google.kz *.google.la *.google.com.lb *.google.li *.google.lk *.google.co.ls *.google.lt *.google.lu *.google.lv *.google.com.ly *.google.co.ma *.google.md *.google.me *.google.mg *.google.mk *.google.ml *.google.com.mm *.google.mn *.google.ms *.google.com.mt *.google.mu *.google.mv *.google.mw *.google.com.mx *.google.com.my *.google.co.mz *.google.com.na *.google.com.ng *.google.com.ni *.google.ne *.google.nl *.google.no *.google.com.np *.google.nr *.google.nu *.google.co.nz *.google.com.om *.google.com.pa *.google.com.pe *.google.com.pg *.google.com.ph *.google.com.pk *.google.pl *.google.pn *.google.com.pr *.google.ps *.google.pt *.google.com.py *.google.com.qa *.google.ro *.google.ru *.google.rw *.google.com.sa *.google.com.sb *.google.sc *.google.se *.google.com.sg *.google.sh *.google.si *.google.sk *.google.com.sl *.google.sn *.google.so *.google.sm *.google.sr *.google.st *.google.com.sv *.google.td *.google.tg *.google.co.th *.google.com.tj *.google.tl *.google.tm *.google.tn *.google.to *.google.com.tr *.google.tt *.google.com.tw *.google.co.tz *.google.com.ua *.google.co.ug *.google.co.uk *.google.com.uy *.google.co.uz *.google.com.vc *.google.co.ve *.google.vg *.google.co.vi *.google.com.vn *.google.vu *.google.ws *.google.rs *.google.co.za *.google.co.zm *.google.co.zw *.google.cat *.laderach.com laderach.com https://get.geojs.io *.avada.io maps.googleapis.com policy.app.cookieinformation.com consent.app.cookieinformation.com *.cloudflare.com *.twitter.com *.contentsquare.net *.nitrocdn.com nitropack.io 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 report-uri https://csp.withgoogle.com/csp/youtube_main/strict;base-uri 'self';object-src 'none';script-src 'report-sample' 'nonce-mpyv9oqg3bJkk0gsp77SyA' 'unsafe-inline' 'strict-dynamic' https: http: 'unsafe-eval' 1 default-src 'self' wss: *.gravatar.com *.seeclickfix.com *.civicplus.com *.civicplus.pro *.civicclerk.com engage6.azureedge.net *.audioeye.com *.pendo.io *.zdassets.com *.zendesk.com *.zopim.com *.arcgis.com *.arcgisonline.com *.services.visualstudio.com *.monitor.azure.com *.googleapis.com *.googletagmanager.com *.google-analytics.com use.fontawesome.com *.google.com *.gstatic.com gstatic.com cdn.embedly.com/widgets/platform.js cdnjs.cloudflare.com static.cloudflareinsights.com *.fontawesome.com *.countyofsb.org * 'self'; style-src * 'self' 'unsafe-inline'; img-src * 'self' data: blob:; script-src 'self' 'unsafe-inline' 'unsafe-eval' blob: *.googletagmanager.com *.seeclickfix.com *.civicplus.com *.civicplus.pro *.civicclerk.com engage6.azureedge.net *.audioeye.com *.pendo.io *.zdassets.com *.zendesk.com *.zopim.com *.arcgis.com *.arcgisonline.com *.services.visualstudio.com *.monitor.azure.com *.googleapis.com *.googletagmanager.com *.google-analytics.com use.fontawesome.com *.google.com *.gstatic.com gstatic.com cdn.embedly.com/widgets/platform.js cdnjs.cloudflare.com static.cloudflareinsights.com *.fontawesome.com * 'self' about: 'unsafe-inline' 'unsafe-eval' data:; worker-src * 'self' data: blob: 'unsafe-eval' 'unsafe-inline'; frame-src * 'self'; media-src 'self' blob: *; font-src * 'self' data: *.fontawesome.com * 'self' data:; upgrade-insecure-requests; form-action 'self'; frame-ancestors 'self';report-uri /contentsecuritypolicy/report 1 object-src 'none';base-uri 'self';script-src 'nonce-dyYRhwjs_fUZuqGhxHt1iA' 'strict-dynamic' 'report-sample' 'unsafe-eval' 'unsafe-inline' https: http:;report-uri https://csp.withgoogle.com/csp/gws/other-hp 1 object-src 'none';base-uri 'self';script-src 'nonce-20lOnOGn5kJKLwLzR5FPnw' 'strict-dynamic' 'report-sample' 'unsafe-eval' 'unsafe-inline' https: http:;report-uri https://csp.withgoogle.com/csp/gws/other-hp 1 default-src 'self' https:; script-src 'self' https: 'unsafe-inline' 'unsafe-eval'; style-src 'self' https: 'unsafe-inline'; img-src 'self' https: data: blob:; media-src 'self' https: data: blob:; object-src 'none'; frame-ancestors 'self' https://experience.adobe.com https://infopoint.audi.it; connect-src 'self' https: wss://e0k754.acquire.io; base-uri 'self'; font-src 'self' https: data:; worker-src 'self' blob:; report-uri https://www.audi.fr/api/csp-report; report-to csp-endpoint 1 default-src 'self' *.cumulusmedia.com 'report-sample'; base-uri 'self'; script-src 'strict-dynamic' 'self' 'inline-speculation-rules' *.cumulusmedia.com 'sha256-MhtPZXr7+LpJUY5qtMutB+qWfQtMaPccfe7QXtCcEYc=' *.googletagmanager.com 'sha256-GyUsdBtdHKlqtQSzGDSvNCHPdK8s1GO2S2y9jj4oYog=' *.google-analytics.com stats.wp.com 'sha256-+zMjo4vywISTRiN+RDp+W665czd5i8MOxiovBqr69F0=' 'sha256-X7SYke/fTbXP5LTn1g56zfcWCiSzQpGhzSLHvvNm0jo=' form.jotform.com cdn.jotfor.ms *.cookielaw.org 'sha256-iqOPaRlwwgtNy7J3vh/+LSW9/QVdN+Fl+YfMS8+GcPo=' *.onetrust.com connect.facebook.net s3.tradingview.com https://www.google.com/recaptcha/ https://challenges.cloudflare.com/turnstile/ 'sha256-riitXBKGtl5y5ccA7GF6ccqJuwEVP5tm8j0ff/fbw9U=' 'sha256-k8zlbQ8Yw3tO1mzGrtP0m5BxCIEa+iH8LXA4dctSEMI=' 'sha256-wBhUGm/Lzl4TA4tJsiguA/vnV9LaNE6plmk4Xn/6/Mw=' 'sha256-6wRdeNJzEHNIsDAMAdKbdVLWIqu8b6+Bs+xVNZqplQw=' 'sha256-5oZoxPs07HkLGv2K/yyNWiLlCvxwJuQdhXLKg2AXhT0=' 'nonce-hRq8Z/fSTtFIOAHXhugzM0xG' 'report-sample'; style-src 'self' 'unsafe-inline' *.cumulusmedia.com fonts.googleapis.com cdn.jotfor.ms 'report-sample'; img-src 'self' data: *.cumulusmedia.com *.wp.com *.googletagmanager.com *.google-analytics.com *.cookielaw.org *.jotform.com; font-src 'self' data: *.cumulusmedia.com fonts.gstatic.com https://www.google.com/recaptcha/; connect-src 'self' *.cumulusmedia.com *.google-analytics.com *.doubleclick.net submit.jotform.com *.cookielaw.org *.onetrust.com; object-src 'none'; frame-src 'self' *.cumulusmedia.com *.jotform.com *.youtube.com s.tradingview.com www.tradingview-widget.com challenges.cloudflare.com; report-uri https://www.cumulusmedia.com/wp-admin/admin-ajax.php?action=wpshr 1 default-src 'none'; script-src 'self' *.twitter.com *.google.com *.recaptcha.net *.googletagmanager.com *.google-analytics.com; img-src *; 1 font-src *.googleapis.com *.gstatic.com data: fonts.googleapis.com fonts.gstatic.com *.fontawesome.com * *.cloudflare.com *.twitter.com *.typekit.net *.twimg.com *.trustedshops.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.twitter.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.googletagmanager.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com *.dotdigital-pages.com *.dotdigital.com www.google.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com *.twitter.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net data: www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.gstatic.com *.googleapis.com *.trackedlink.net maps.googleapis.com maps.gstatic.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com gateway.apaylater.com gateway.atome.sg ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com *.facebook.com https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://*.g.doubleclick.net https://*.google.com *.cloudflare.com *.klarna.com *.googleadservices.com *.google-analytics.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.cloudfront.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.googletagmanager.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com *.googleapis.com *.gstatic.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal maps.googleapis.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ maps.gstatic.com fonts.googleapis.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com gateway.apaylater.com gateway.atome.sg cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com chimpstatic.com downloads.mailchimp.com *.list-manage.com *.googletagmanager.com *.facebook.net *.avada.io https://*.googletagmanager.com *.cloudflare.com *.twitter.com *.google-analytics.com *.twimg.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com unsafe-inline fonts.googleapis.com gateway.apaylater.com gateway.atome.sg cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com downloads.mailchimp.com *.fontawesome.com *.cloudflare.com *.googleapis.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.googleapis.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com webchat.dotdigital.com webchat.staging.dotdigital.com *.google-analytics.com https://get.geojs.io *.avada.io https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://*.g.doubleclick.net https://*.google.com *.cloudflare.com *.twitter.com *.twimg.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri http://csp-reporting-service.com/my-project/endpoint; report-to report-endpoint; 1 object-src 'none';base-uri 'self';script-src 'nonce-Hfo9cwgImVSJtRFN9tA0xA' 'strict-dynamic' 'report-sample' 'unsafe-eval' 'unsafe-inline' https: http:;report-uri https://csp.withgoogle.com/csp/gws/other-hp 1 default-src 'self' https://*.charteredaccountants.ie https://*.realexpayments.com https://*.payandshop.com https://*.digicert.com https://*.zendesk.com https://*.zopim.com https://*.zdassets.com https://*.youtube.com https://googleads.g.doubleclick.net https://*.licdn.com https://*.google-analytics.com https://*.cookiebot.com https://*.fontawesome.com https://*.jsdelivr.net https://*.crazyegg.com https://*.telerikstatic.com https://*.aspnetcdn.com https://*.facebook.net https://*.facebook.com https://*.cloudflare.com https://*.googleapis.com https://*.googletagmanager.com https://*.jquery.com https://*.doubleclick.net https://*.tiktok.com https://*.google.co.uk https://*.google.com https://*.google.ie https://*.googleadservices.com https://*.google.co.in https://*.bootstrapcdn.com https://*.gstatic.com https://charteredaccountantsireland.mediasite.com https://*.linkedin.com 'unsafe-inline' 'unsafe-eval' data: blob:; object-src 'none'; base-uri 'self' https://*.charteredaccountants.ie; frame-ancestors 'self' https://*.google.com https://*.charteredaccountants.ie https://*.realexpayments.com https://*.payandshop.com; report-uri https://csp.charteredaccountants.ie/index.php; worker-src blob:; 1 font-src fonts.gstatic.com use.typekit.net *.squarecdn.com *.googleapis.com *.gstatic.com *.klevu.com *.ksearchnet.com *.fontawesome.com *.tiktok.com tiktok.com maxcdn.bootstrapcdn.com *.afterpay.com *.cloudflare.com *.espssl.com *.fontshare.com *.migaku.com *.minnetonkamoccasin.com *.qantas.com *.rakuten.com sc-static.net *.slant.co unpkg.com *.userway.org data: 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * www.apptrian.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com https://plumrocket.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.tiktok.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com widgets.sandbox.afterpay.com *.cash.app *.sharethis.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * www.google.com www.apptrian.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com bytedance: sslocal: https://plumrocket.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com landofcoder.com *.tiktok.com https://*.online-metrix.net https://imgs.signifyd.com *.googletagmanager.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net *.afterpay.com/ *.cash.app *.sharethis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.googleapis.com *.gstatic.com www.apptrian.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com analytics.tiktok.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.klevu.com *.ksearchnet.com *.tiktok.com flagpedia.net https://imgs.signifyd.com https://*.online-metrix.net *.cluepixel.com *.6g2d4pn2yqc42.ent.platform.sh *.adnxs.com *.adsrvr.org *.afterpay.com *.bing.com *.casalemedia.com *.clarity.ms *.cookielaw.org *.criteo.com *.criteo.net *.curalate.com *.doubleclick.net *.espssl.com *.facebook.com *.facebook.net *.ggpht.com *.googleadservices.com *.google-analytics.com www.google.ad www.google.ae www.google.al www.google.am www.google.as www.google.at www.google.az www.google.ba www.google.be www.google.bf www.google.bg www.google.bi www.google.bj www.google.bs www.google.bt www.google.by www.google.ca www.google.cd www.google.cg www.google.ch www.google.ci www.google.cl www.google.cm www.google.cn www.google.co.ao www.google.co.bw www.google.co.ck www.google.co.cr www.google.co.id www.google.co.il www.google.co.in www.google.co.jp www.google.co.ke www.google.co.kr www.google.co.ls www.google.co.ma www.google.com.af www.google.com.ag www.google.com.ar www.google.com.au www.google.com.bd www.google.com.bh www.google.com.bn www.google.com.bo www.google.com.br www.google.com.bz www.google.com.co www.google.com.cu www.google.com.cy www.google.com.do www.google.com.ec www.google.com.eg www.google.com.et www.google.com.fj www.google.com.gh www.google.com.gi www.google.com.gt www.google.com.hk www.google.com.jm www.google.com.kh www.google.com.kw www.google.com.lb www.google.com.ly www.google.com.mm www.google.com.mt www.google.com.mx www.google.com.my www.google.com.na www.google.com.ng www.google.com.ni www.google.com.np www.google.com.om www.google.com.pa www.google.com.pe www.google.com.pg www.google.com.ph www.google.com.pk www.google.com.pr www.google.com.py www.google.com.qa www.google.com.sa www.google.com.sg www.google.com.sl www.google.com.sv www.google.com.tj www.google.com.tr www.google.com.tw www.google.com.ua www.google.com.uy www.google.com.vc www.google.com.vn www.google.co.mz www.google.co.nz www.google.co.th www.google.co.tz www.google.co.ug www.google.co.uk www.google.co.uz www.google.co.ve www.google.co.vi www.google.co.za www.google.co.zm www.google.co.zw www.google.cv www.google.cz www.google.de www.google.dj www.google.dk www.google.dm www.google.dz www.google.ee www.google.es www.google.fi www.google.fm www.google.fr www.google.ga www.google.ge www.google.gg www.google.gl www.google.gm www.google.gr www.google.gy www.google.hn www.google.hr www.google.ht www.google.hu www.google.ie www.google.im www.google.iq www.google.is www.google.it www.google.je www.google.jo www.google.kg www.google.kz www.google.la www.google.li www.google.lk www.google.lt www.google.lu www.google.lv www.google.md www.google.me www.google.mg www.google.mk www.google.ml www.google.mn www.google.mu www.google.mv www.google.mw www.google.ne www.google.nl www.google.no www.google.pl www.google.ps www.google.pt www.google.ro www.google.rs www.google.ru www.google.rw www.google.sc www.google.se www.google.si www.google.sk www.google.sn www.google.so www.google.sr www.google.tg www.google.tl www.google.tm www.google.tn www.google.tt www.google.vu *.google.com google.com *.googlesyndication.com *.googletagmanager.com id5-sync.com *.listrakbi.com *.minnetonkamoccasin.com *.online-metrix.net *.pinterest.com *.rlcdn.com *.rubiconproject.com *.snapchat.com *.typekit.net *.userway.org *.yotpo.com data: 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net amcglobal.sc.omtrdc.net commerce.adobe.net use.typekit.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com *.magento-ds.com https://portal.sandbox.afterpay.com https://portal.afterpay.com https://static.afterpay.com *.squarecdn.com https://hbiq.net *.cash.app *.sharethis.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ www.apptrian.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com analytics.tiktok.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com js.klevu.com *.ksearchnet.com landofcoder.com https://cdn.jsdelivr.net *.tiktok.com maps.googleapis.com *.googletagmanager.com https://cdn-scripts.signifyd.com https://cdn-scripts.signifyd.com/api/script-tag.js https://imgs.signifyd.com https://h64.online-metrix.net https://js.klevu.com *.cluepixel.com *.adobedtm.com *.adobe.net *.afterpay.com *.bing.com *.blackfire.io *.clarity.ms *.cloudflare.com *.cookielaw.org *.criteo.com *.criteo.net *.curalate.com d10lpsik1i8c69.cloudfront.net *.doubleclick.net *.facebook.net *.googleadservices.com *.google-analytics.com *.google.com *.googlesyndication.com googletagmanager.com *.id5-sync.com *.jsdelivr.net *.klevu.com *.listrakbi.com *.listrak.com localhost *.mczbf.com *.minnetonkamoccasin.com *.nimblecapture.com *.online-metrix.net *.pinimg.com *.pinterest.com sc-static.net *.snapchat.com unpkg.com *.userway.org *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com static.afterpay.com/ *.squarecdn.com *.cash.app *.sharethis.com unsafe-inline assets.braintreegateway.com *.klevu.com *.ksearchnet.com *.fontawesome.com *.tiktok.com tiktok.com maxcdn.bootstrapcdn.com *.gstatic.com https://statsjs.klevu.com https://js.klevu.com *.afterpay.com *.cloudflare.com *.googleapis.com *.googletagmanager.com *.listrakbi.com *.minnetonkamoccasin.com *.typekit.net *.userway.org *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; object-src landofcoder.com 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com *.bing.com *.curalate.com *.googleapis.com *.google.com *.gstatic.com *.paypal.com *.userway.org 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; manifest-src *.tiktok.com tiktok.com *.minnetonkamoccasin.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io *.magento-datasolutions.com *.magento-ds.com *.sentry.io *.afterpay.com *.squarecdn.com https://hbiq.net https://iq.afterpay-beta.com https://iq.afterpay.com *.cash.app api.lab.amplitude.com *.sharethis.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.googleapis.com www.apptrian.com tiktok.com www.tiktok.com connect.tiktok.net graph.tiktok.com analytics.tiktok.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.klevu.com *.ksearchnet.com landofcoder.com *.tiktok.com www.gstatic.com maps.googleapis.com https://imgs.signifyd.com *.cluepixel.com *.adobe.net *.adsrvr.org *.amplitude.com *.bing.com *.clarity.ms *.cookielaw.org *.criteo.com *.criteo.net *.curalate.com *.doubleclick.net *.espssl.com *.facebook.com *.googleadservices.com *.google-analytics.com www.google.ca www.google.co.jp www.google.co.kr www.google.com.pk www.google.com.vn www.google.de *.googlesyndication.com *.gstatic.com *.listrakbi.com *.listrak.com localhost *.luckyorange.net *.mczbf.com *.minnetonkamoccasin.com *.nimblecapture.com *.onetrust.com *.pinimg.com *.pinterest.com *.rlcdn.com *.samsung.com sc-static.net *.snapchat.com unpkg.com *.userway.org 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.afterpay.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; base-uri *.criteo.com *.doubleclick.net *.google.com *.klevu.com *.onetrust.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; report-uri https://2d02ba86-f55d-42ab-9b05-087fb2c163a0.sansec.watch/; report-to report-endpoint; 1 base-uri 'self'; form-action 'self'; default-src 'self'; connect-src 'self' data: https://stats.nederhost.nl/ https://zammad.nederhost.nl/ wss://zammad.nederhost.nl/; frame-ancestors 'none'; frame-src 'self'; img-src 'self' data:; report-to csp-endpoint; report-uri /_/report_csp_violation; script-src 'self' 'nonce-rQDqbHvPVf5InxXf' 'unsafe-eval' https://stats.nederhost.nl/ https://cdn.matomo.cloud/stats.nederhost.nl/ https://zammad.nederhost.nl/; style-src 'self' data: 'nonce-rQDqbHvPVf5InxXf' https://zammad.nederhost.nl/; style-src-attr 'unsafe-inline'; 1 default-src 'self' https: data: blob: wss: 'unsafe-eval' 'unsafe-inline'; script-src 'report-sample' 'self' 'unsafe-eval' 'unsafe-inline' *.%2A.civiccomputing.com *.civiccomputing.com *.clarity.ms *.cloudflare.com *.googletagmanager.com *.jsdelivr.net *.library.wales; style-src-attr 'unsafe-inline' 'report-sample'; img-src 'self' data: *.ytimg.com *.vimeocdn.com *.youtube.com https://*.googleapis.com https://*.gstatic.com *.google.com *.googleusercontent.com *.google-analytics.com *.googletagmanager.com *.g.doubleclick.net *.google.ad *.google.ae *.google.al *.google.am *.google.as *.google.at *.google.az *.google.ba *.google.be *.google.bf *.google.bg *.google.bi *.google.bj *.google.bs *.google.bt *.google.by *.google.ca *.google.cat *.google.cd *.google.cf *.google.cg *.google.ch *.google.ci *.google.cl *.google.cm *.google.cn *.google.co.ao *.google.co.bw *.google.co.ck *.google.co.cr *.google.co.id *.google.co.il *.google.co.in *.google.co.jp *.google.co.ke *.google.co.kr *.google.co.ls *.google.co.ma *.google.co.mz *.google.co.nz *.google.co.th *.google.co.tz *.google.co.ug *.google.co.uk *.google.co.uz *.google.co.ve *.google.co.vi *.google.co.za *.google.co.zm *.google.co.zw *.google.com.af *.google.com.ag *.google.com.ar *.google.com.au *.google.com.bd *.google.com.bh *.google.com.bn *.google.com.bo *.google.com.br *.google.com.bz *.google.com.co *.google.com.cu *.google.com.cy *.google.com.do *.google.com.ec *.google.com.eg *.google.com.et *.google.com.fj *.google.com.gh *.google.com.gi *.google.com.gt *.google.com.hk *.google.com.jm *.google.com.kh *.google.com.kw *.google.com.lb *.google.com.ly *.google.com.mm *.google.com.mt *.google.com.mx *.google.com.my *.google.com.na *.google.com.ng *.google.com.ni *.google.com.np *.google.com.om *.google.com.pa *.google.com.pe *.google.com.pg *.google.com.ph *.google.com.pk *.google.com.pr *.google.com.py *.google.com.qa *.google.com.sa *.google.com.sb *.google.com.sg *.google.com.sl *.google.com.sv *.google.com.tj *.google.com.tr *.google.com.tw *.google.com.ua *.google.com.uy *.google.com.vc *.google.com.vn *.google.cv *.google.cz *.google.de *.google.dj *.google.dk *.google.dm *.google.dz *.google.ee *.google.es *.google.fi *.google.fm *.google.fr *.google.ga *.google.ge *.google.gg *.google.gl *.google.gm *.google.gr *.google.gy *.google.hn *.google.hr *.google.ht *.google.hu *.google.ie *.google.im *.google.iq *.google.is *.google.it *.google.je *.google.jo *.google.kg *.google.ki *.google.kz *.google.la *.google.li *.google.lk *.google.lt *.google.lu *.google.lv *.google.md *.google.me *.google.mg *.google.mk *.google.ml *.google.mn *.google.mu *.google.mv *.google.mw *.google.ne *.google.nl *.google.no *.google.nr *.google.nu *.google.pl *.google.pn *.google.ps *.google.pt *.google.ro *.google.rs *.google.ru *.google.rw *.google.sc *.google.se *.google.sh *.google.si *.google.sk *.google.sm *.google.sn *.google.so *.google.sr *.google.st *.google.td *.google.tg *.google.tl *.google.tm *.google.tn *.google.to *.google.tt *.google.vu *.google.ws *.library.wales *.llgc.org.uk *.staticflickr.com *.ticketsource.co.uk fonts.gstatic.com play.google.com syndication.twitter.com translate.google.com; base-uri 'self'; frame-src 'self' *.youtube-nocookie.com *.youtube.com *.vimeo.com *.google.com *.doubleclick.net *.googletagmanager.com *.libanswers.com *.library.wales *.llyfrgell.cymru *.lyfrgell.cymru *.twitter.com div.show hwb.gov.wales sketchfab.com www.canva.com; style-src-elem 'report-sample' 'self' 'unsafe-inline' *.clarity.ms *.fontawesome.com *.libanswers.com *.library.wales connect.facebook.net fonts.googleapis.com; script-src-elem 'self' 'nonce-1D3q-XnbKRRgUNe38AmBE4i0_VQRia5euyIaihYB7yzQMUAX4mgFcA' https: 'unsafe-eval' blob: *.%2A.civiccomputing.com *.%2A.v2.scr.kaspersky-labs.com *.civiccomputing.com *.flickr.com *.googletagmanager.com *.libanswers.com adblockers.opera-mini.net connect.facebook.net s3.amazonaws.com wusote.hirizasune.com 'report-sample'; connect-src 'self' https: data: blob: wss: *.google.com https://*.googleapis.com https://*.gstatic.com *.googletagmanager.com *.google-analytics.com *.analytics.google.com *.g.doubleclick.net *.google.ad *.google.ae *.google.al *.google.am *.google.as *.google.at *.google.az *.google.ba *.google.be *.google.bf *.google.bg *.google.bi *.google.bj *.google.bs *.google.bt *.google.by *.google.ca *.google.cat *.google.cd *.google.cf *.google.cg *.google.ch *.google.ci *.google.cl *.google.cm *.google.cn *.google.co.ao *.google.co.bw *.google.co.ck *.google.co.cr *.google.co.id *.google.co.il *.google.co.in *.google.co.jp *.google.co.ke *.google.co.kr *.google.co.ls *.google.co.ma *.google.co.mz *.google.co.nz *.google.co.th *.google.co.tz *.google.co.ug *.google.co.uk *.google.co.uz *.google.co.ve *.google.co.vi *.google.co.za *.google.co.zm *.google.co.zw *.google.com.af *.google.com.ag *.google.com.ar *.google.com.au *.google.com.bd *.google.com.bh *.google.com.bn *.google.com.bo *.google.com.br *.google.com.bz *.google.com.co *.google.com.cu *.google.com.cy *.google.com.do *.google.com.ec *.google.com.eg *.google.com.et *.google.com.fj *.google.com.gh *.google.com.gi *.google.com.gt *.google.com.hk *.google.com.jm *.google.com.kh *.google.com.kw *.google.com.lb *.google.com.ly *.google.com.mm *.google.com.mt *.google.com.mx *.google.com.my *.google.com.na *.google.com.ng *.google.com.ni *.google.com.np *.google.com.om *.google.com.pa *.google.com.pe *.google.com.pg *.google.com.ph *.google.com.pk *.google.com.pr *.google.com.py *.google.com.qa *.google.com.sa *.google.com.sb *.google.com.sg *.google.com.sl *.google.com.sv *.google.com.tj *.google.com.tr *.google.com.tw *.google.com.ua *.google.com.uy *.google.com.vc *.google.com.vn *.google.cv *.google.cz *.google.de *.google.dj *.google.dk *.google.dm *.google.dz *.google.ee *.google.es *.google.fi *.google.fm *.google.fr *.google.ga *.google.ge *.google.gg *.google.gl *.google.gm *.google.gr *.google.gy *.google.hn *.google.hr *.google.ht *.google.hu *.google.ie *.google.im *.google.iq *.google.is *.google.it *.google.je *.google.jo *.google.kg *.google.ki *.google.kz *.google.la *.google.li *.google.lk *.google.lt *.google.lu *.google.lv *.google.md *.google.me *.google.mg *.google.mk *.google.ml *.google.mn *.google.mu *.google.mv *.google.mw *.google.ne *.google.nl *.google.no *.google.nr *.google.nu *.google.pl *.google.pn *.google.ps *.google.pt *.google.ro *.google.rs *.google.ru *.google.rw *.google.sc *.google.se *.google.sh *.google.si *.google.sk *.google.sm *.google.sn *.google.so *.google.sr *.google.st *.google.td *.google.tg *.google.tl *.google.tm *.google.tn *.google.to *.google.tt *.google.vu *.google.ws; font-src 'self' https: data: blob: wss: https://fonts.gstatic.com; worker-src 'self' 'nonce-1D3q-XnbKRRgUNe38AmBE4i0_VQRia5euyIaihYB7yzQMUAX4mgFcA' blob:; style-src 'self' https: data: blob: wss: 'unsafe-eval' 'unsafe-inline' 'inline' 'report-sample'; report-uri https://www.library.wales/@http-reporting?csp=report&requestTime=1770426836882620&requestHash=34a647eba133f2e32e82d02bc86f42f340ff9002 1 default-src 'self' 'unsafe-eval' 'unsafe-inline'; script-src 'self' 'unsafe-eval' 'unsafe-inline' 'report-sample' *.cookiebot.com:* *.fanplayr.com:* *.doubleclick.net:* *.media:* *.googletagmanager.com:* *.sc-static.net:* *.tiktok.com:* *.force.com:* *.jsdelivr.net:* *.amazon-adsystem.com:* *.amazon-adsystem.com:* *.fastclick.net:* *.crwdcntrl.net:* *.id5-sync.com:* *.cloudflare.com:* *.salesforceliveagent.com:* *.snapchat.com:* *.googleapis.com:* *.sc-static.net:* sc-static.net:* *.smilewanted.com:* *.reciteme.com:* https://c.ltmsphrcl.net https://www.googletagservices.com https://cdn.js7k.com https://ep2.adtrafficquality.google https://cadmus.script.ac https://bat.bing.com https://s2.adform.net https://snap.licdn.com https://secure.adnxs.com https://northernrail.my.salesforce.com:* https://northernrail.my.site.com:* https://track.adform.net:* *.byspotify.com:* *.geoedge.be:*; object-src 'self' 'unsafe-inline'; style-src 'self' 'unsafe-eval' 'unsafe-inline' 'report-sample' *.jsdelivr.net:* *.force.com:* *.googleapis.com:* *.reciteme.com:* *.cloudflare.com:* https://northernrail.my.salesforce.com:* https://northernrail.my.site.com:* ; img-src 'self' *.northernrailway.co.uk:* *.netlify.app:* *.snapchat.com:* *.cookiebot.com:* *.googleapis.com:* *.googletagmanager.com:* *.fanplayr.com:* data: *.reciteme.com:* https://ep1.adtrafficquality.google https://dt.adsafeprotected.com https://www.facebook.com *.googlesyndication.com https://id5-sync.com *.googleusercontent.com:*; media-src 'self'; frame-src 'self' *.cookiebot.com:* *.snapchat.com:* *.force.com:* *.northernrailway.co.uk:* *.smilewanted.com:* *.yahoo.com:* *.adnxs.com:* *.ck-ie.com:* *.33across.com:* *.smaato.net:* *.onetag-sys.com:* *.360yield.com:* onetag-sys.com:* *.smartadserver.com:* ssp-sync.criteo.com:* *.ssp-sync.criteo.com:* *.eskimi.com:* *.rubiconproject.com:* *.pubmatic.com:* *.openx.net:* dis.criteo.com:* *.sharethrough.com:* *.lijit.com:* *.doubleclick.net *.googlesyndication.com https://www.google.com https://track.adform.net:*; frame-ancestors 'self' https://game.northernrailway.co.uk:*; child-src 'self'; font-src 'self' *.gstatic.com:* *.reciteme.com:* data:; connect-src 'self' *.amazon-adsystem.com:* *.northern-trains.ddev.site *.tiktok.com:* *.snapchat.com:* *.amazon.dev:* *.criteo.com:* *.crwdcntrl.net:* *.fanplayr.com:* *.googlesyndication.com:* *.a2z.com:* *.eu-1-id5-sync.com:* id5-sync.com:* *.33across.com:* *.cookiebot.com:* *.google-analytics.com:* *.reciteme.com:* *.smilewanted.com *.doubleverify.com https://px.ads.linkedin.com https://c.ltmsphrcl.net *.doubleclick.net https://region1.analytics.google.com https://pixels.spotify.com https://web.hb.ad.cpe.dotomi.com *.4dex.io https://onetag-sys.com https://esp.rtbhouse.com https://prg.smartadserver.com https://data.ad-score.com https://fastlane.rubiconproject.com https://ad.360yield.com https://tlx.3lift.com https://northernrail.my.salesforce.com:* https://northernrail.my.site.com:* *.tiktokw.us:*; report-uri /report-csp-violation 1 report-uri https://csp.withgoogle.com/csp/youtube_main/strict;base-uri 'self';object-src 'none';script-src 'report-sample' 'nonce-7YghaZxBbt7Zi1ZhGEG6hQ' 'unsafe-inline' 'strict-dynamic' https: http: 'unsafe-eval' 1 default-src 'none';base-uri 'none';font-src 'self' https://client.crisp.chat;form-action 'self';frame-ancestors 'self';img-src 'self' https: data: blob: https://matomo.openagenda.com https://client.crisp.chat https://image.crisp.chat https://storage.crisp.chat;object-src 'none';script-src https: 'unsafe-inline' 'strict-dynamic' 'nonce-2624279206680644' https://client.crisp.chat https://settings.crisp.chat;script-src-attr 'none';style-src 'self' 'unsafe-inline' https://cdn.openagenda.com https://client.crisp.chat;media-src 'self' https: data: https://client.crisp.chat;frame-src 'self' https://service.mtcaptcha.com https://service2.mtcaptcha.com https://game.crisp.chat;connect-src 'self' https://cdn.openagenda.com https://matomo.openagenda.com https://client.crisp.chat https://storage.crisp.chat wss://client.relay.crisp.chat wss://stream.relay.crisp.chat;upgrade-insecure-requests;block-all-mixed-content;report-to default;report-uri https://openagenda.com/reports 1 default-src 'self'; base-uri 'self'; form-action 'self'; frame-ancestors 'self' https://www.synergie.fr; report-uri /api/csp-report; script-src 'self' https://cdn.synergie.fr https://www.googletagmanager.com https://chat-window.kmblabs.com http://static.axept.io https://js-agent.newrelic.com https://v2.synergie.intconv.kmblabs.com https://www.gstatic.com https://www.google.com; connect-src 'self' https://api.synergie.fr https://www.google-analytics.com https://chatwindow-v2.api.kmblabs.com https://client.axept.io https://api.axept.io https://bam.eu01.nr-data.net; img-src 'self' https://cdn.synergie.fr https://media.synergie.fr data:; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; font-src 'self' https://fonts.gstatic.com 1 default-src 'self' 'unsafe-inline' 'unsafe-eval' code.jquery.com cdn.appdynamics.com col.eum-appdynamics.com fonts.gstatic.com ajax.googleapis.com www.googleapis.com fonts.googleapis.com use.fontawesome.com www.w3schools.com home.textkernel.nl staging.textkernel.nl www.dropbox.com apis.google.com www.google.com html5shim.googlecode.com media.readspeaker.com s7.addthis.com d2sl310zdnr3q6.cloudfront.net www.google-analytics.com https://apps.knollenstein.com https://appsdev.knollenstein.com font.visma.com *.easycruit.com m.addthis.com api-public.addthis.com flowanalytic.site networkanalytics.xyz knowledge-and-support-center.visma.net m.addthisedge.com apply.indeed.com content.googleapis.com commondatastorage.googleapis.com themes.googleusercontent.com www.googletagmanager.com fast.fonts.net db.onlinewebfonts.com hello.myfonts.net cdnjs.cloudflare.com d1fc8wv8zag5ca.cloudfront.net connect.facebook.net emea3.recruitmentplatform.com tag.goldenbees.fr s.ytimg.com www.findizer.fr webfonts.zohostatic.com platform.linkedin.com zgao.nl cdn.ontame.io *.ziggeo.com *.amazonaws.com api-eu-west-1.ziggeo.com embed-cdn-eu-west-1.ziggeo.com embed-eu-west-1.ziggeo.com assets.ziggeo.com hc-cdn.visma.net cdn.wootric.com production.wootric.com eligibility.wootric.com *.onetrust.com cdn.cookielaw.org https://storage.googleapis.com/snowplow-cto-office-tracker-bucket/3.1.1/sp.js https://snowplow.visma.com/com.snowplowanalytics.snowplow/tp2 *.sharethis.com www.gstatic.com easycruit.com; img-src 'self' data: * 'unsafe-inline' 'unsafe-eval'; report-uri https://easycruit.com/api/logging/v1/csp-report 1 default-src 'self' *.typekit.net *.googletagmanager.com *.bootstrapcdn.com *.google.com *.google-analytics.com *.facebook.com *.crazyegg.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.quantserve.com https://rules.quantcount.com *.cloudflare.com *.basis.net *.doubleclick.net *.optimizely.com https://cdn.optimizely.com *.calendly.com *.tailwindcss.com *.jsdelivr.net *.gstatic.com *.google-analytics.com *.crazyegg.com *.facebook.net *.simpli.fi *.google.com *.googleapis.com *.googletagmanager.com https://code.jquery.com *.cdn4dd.com https://drive-widget.cdn4dd.com *.tribalfusion.com; connect-src 'self' *.cheetahedp.com *.crazyegg.com *.google-analytics.com *.google.com *.typekit.net *.gstatic.com *.doubleclick.net https://pixel.quantserve.com *.quantserve.com *.optimizely.com https://logx.optimizely.com; frame-src 'self' *.googletagmanager.com calendly.com *.calendly.com *.gstatic.com *.google.com *.doubleclick.net https://pixel-sync.sitescout.com *.sitescout.com *.optimizely.com https://a12600010354.cdn.optimizely.com; font-src 'self' data: *.deltaco.com *.gstatic.com *.bootstrapcdn.com *.typekit.net https://fonts.gstatic.com; style-src 'self' 'unsafe-inline' 'unsafe-eval' *.calendly.com *.googleapis.com https://fonts.googleapis.com *.typekit.net www.googletagmanager.com maxcdn.bootstrapcdn.com; img-src 'self' https: data: *.quantserve.com *.sitescout.com; report-to csp-endpoint 1 default-src https: 'unsafe-inline' 'unsafe-eval'; worker-src 'self'; img-src https: data: 1 font-src fonts.gstatic.com cdn.livechatinc.com stats.g.doubleclick.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.livechatinc.com *.dotit.com *.ncco.com dotit.wufoo.com stats.g.doubleclick.net 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.livechatinc.com stats.g.doubleclick.net dotit.wufoo.com www.wrike.com *.google.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.livechatinc.com *.disqus.com *.dotit.com *.ncco.com stats.g.doubleclick.net cp-ywz-382.chili-publish.online cp-ywz-382.chili-publish-sandbox.online https://img.youtube.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.livechatinc.com *.disqus.com stats.g.doubleclick.net chimpstatic.com *.wufoo.com www.youtube.com apis.google.com *.google.pl 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com stats.g.doubleclick.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.livechatinc.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.livechatinc.com stats.g.doubleclick.net *.analytics.google.com *.google-analytics.com dotit.wufoo.com *.smartystreets.com apis.google.com *.google.pl 'self' 'unsafe-inline'; child-src stats.g.doubleclick.net http: https: blob: 'self' 'unsafe-inline'; default-src stats.g.doubleclick.net 'self' 'unsafe-inline' 'unsafe-eval'; base-uri stats.g.doubleclick.net 'self' 'unsafe-inline'; 1 default-src 'self' *.fls.doubleclick.net *.google-analytics.com *.overdrive.com bam.nr-data.net connect.facebook.net hello.myfonts.net stats.g.doubleclick.net tracking.crazyegg.com/clock; connect-src 'self' *.google-analytics.com analytics.google.com bam.nr-data.net hello.myfonts.net manager.us.smartlook.cloud script.crazyegg.com/pages/data-scripts/0023/8294.json stats.g.doubleclick.net tracking.crazyegg.com/clock www.facebook.com/tr/ api.digioh.com jsapi.azurewebsites.net analytics.digioh.com; script-src 'self' apis.google.com/js/platform.js bam.nr-data.net connect.facebook.com connect.facebook.net js-agent.newrelic.com script.crazyegg.com servedbyadbutler.com/adserve/ servedbyadbutler.com/app.js web-sdk.smartlook.com www.google-analytics.com/analytics.js www.googletagmanager.com cdn.digioh.com scripts.digioh.com lightboxcdn.digioh.com 'unsafe-eval' 'unsafe-inline'; script-src-elem 'self' apis.google.com/ apis.google.com/_/scs/apps-static/_/js/ apis.google.com/js/platform.js bam.nr-data.net connect.facebook.net js-agent.newrelic.com/ script.crazyegg.com/pages/scripts/0023/8294.js script.crazyegg.com/pages/versioned/common-scripts/ servedbyadbutler.com/adserve/ servedbyadbutler.com/app.js web-sdk.smartlook.com www.google-analytics.com/analytics.js www.google-analytics.com/plugins/ua/ec.js www.google.com/recaptcha www.googletagmanager.com 'unsafe-inline'; style-src 'self' 'unsafe-inline'; style-src-attr 'self' 'unsafe-inline'; style-src-elem 'self' 'nonce-2N6mi1GExdwjwcuCoIiLn+6jxoI='; img-src 'self' data: images.contentreserve.com/ img1.od-cdn.com servedbyadbutler.com/getad.img/ t.co/i/ www.facebook.com/tr/ www.google-analytics.com/collect www.google.com/ads/ www.googletagmanager.com/a www.googletagmanager.com/td cdn.digioh.com *.google-analytics.com *.doubleclick.net; frame-src 'self' 9250847.fls.doubleclick.net accounts.google.com/ classroom.google.com www.facebook.com/ www.gstatic.com/; worker-src blob:; object-src 'none'; report-uri https://itsentry.overdrive.com/api/13/security/?sentry_key=86a98bc6ee19c71aed01755910f50c3c 1 img-src *.force.com slack-imgs-mil-dev.com https://d.la1-c1cs-ph2.salesforceliveagent.com 'self' https://stats.g.doubleclick.net courseraservices--c.cs62.visual.force.com https://img.youtube.com https://payments.salesforce.com/icons/ https://login.salesforce.com/icons/ https://api.media.atlassian.com https://www.gstatic.com *.slack-edge-gov.com drive.google.com https://c.na207.content.force.com *.my-salesforce.com https://d.la5-c1-ia4.salesforceliveagent.com https://business.coursera.help *.cloudinary.com https://www.google.com https://analytics.google.com *.amazonaws.com https://www.getfeedback.com blob: https://courseraservices.my.salesforce-scrt.com https://d.la1-core2.sfdc-lywfpd.salesforceliveagent.com https://d.la1-c1cs-iad.salesforceliveagent.com https://usa686.sfdc-lywfpd.salesforce.com/icons/ slack-imgs.com slack-gov-dev.com *.sfdcstatic.com *.twimg.com https://courseraservices.lightning.force.com https://*.cloudfront.net *.slack.com https://www.paypal.com https://courseraservices--uat--c.cs62.visual.force.com *.slack-imgs.com slack-imgs-gov.com https://d.la5-c1-ia5.salesforceliveagent.com https://i.ytimg.com https://cdn.content.aws-dev2-uswest2.aws.sfdc.cl/icons/ *.salesforce-experience.com https://c.usa674.content.sfdc-lywfpd.force.com https://d.la2-c1-ph2.salesforceliveagent.com https://*.walkme.com *.googleusercontent.com https://c.usa674.content.force.com courseraservices--c.visualforce.com slack-imgs-gov-dev.com https://courseraservices.my.salesforce.com https://courseraservices--c.documentforce.com *.slack-edge.com https://www.coursera.support https://cdn.content.aws-prod1-useast1.aws.sfdc.cl/icons/ slack-mil-dev.com https://www.gstatic.com/recaptcha/ https://courseraservices--c.visualforce.com https://d.la11-core2.sfdc-lywfpd.salesforceliveagent.com accounts.google.com https://d.la13-core2.sfdc-lywfpd.salesforceliveagent.com https://courseraservices.my.site.com https://courseraservices--c.na207.visual.force.com https://www.google.co.in https://www.google.com/recaptcha/ *.slack-edge.mil https://www.sandbox.paypal.com http://coursera-university-assets.s3.amazonaws.com https://courseraservices.file.force.com https://i.vimeocdn.com https://d.la2-c1cs-iad.salesforceliveagent.com https://www.googletagmanager.com https://www.google-analytics.com *.salesforce.com https://*.adyen.com slack-imgs.mil data:; report-to sfdc-csp-ep; report-uri https://courseraservices.lightning.force.com/_/ContentDomainCSPNoAuth?tenantId=00D1U000000y4UJ&networkId=0DM1U000000F7e3&type=communities 1 default-src 'self'; connect-src 'self' https://*.google-analytics.com https://*.brightcove.com https://*.boltdns.net https://*.brightcovecdn.com https://*.siteimprove.com https://www.google.com; font-src 'self' https://fonts.gstatic.com data:; frame-src 'self' https://info.mumc.nl https://www.google.com https://players.brightcove.net https://*.youtube.com https://*.vimeo.com https://heritage.mumc.nl https://www.googletagmanager.com; img-src 'self' https://metrics.brightcove.com https://*.boltdns.net https://*.ytimg.com data:; media-src 'self' https://*.brightcovecdn.com https://*.boltdns.net blob:; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://*.texthelp.com https://*.browsealoud.com https://players.brightcove.net https://vjs.zencdn.net https://cdn.rawgit.com https://www.googletagmanager.com https://www.google-analytics.com https://apis.google.com https://www.google.com https://www.gstatic.com blob: cdn.jsdelivr.net https://cdn.jsdelivr.net https://cdn.siteimprove.net https://unpkg.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com cdn.jsdelivr.net; base-uri 'self'; form-action 'self'; frame-ancestors 'self'; report-uri https://www.mumc.nl/report-uri/reportOnly; block-all-mixed-content 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.afterpay.com/ *.afterpaycdn.com *.squarecdn.com *.cash.app *.googleapis.com *.klevu.com *.ksearchnet.com *.fontawesome.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com api.bazaarvoice.com stg.api.bazaarvoice.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.certcapture.com *.stripe.com stripe.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.afterpay.com *.afterpaycdn.com *.squarecdn.com *.cash.app *.dotdigital-pages.com *.dotdigital.com *.certcapture.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.pinterest.com *.pinterdev.com commerce-app.pintergration.com photos.pixlee.co *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.afterpay.com/ *.afterpaycdn.com *.squarecdn.com *.cash.app *.trackedlink.net *.googleapis.com *.certcapture.com display.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com network-a.bazaarvoice.com network-stg-a.bazaarvoice.com photos-uat-us.bazaarvoice.com img.youtube.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.klevu.com *.ksearchnet.com *.facebook.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.pinterest.com *.pinterdev.com *.pinimg.com commerce-app.pintergration.com *.pixlee.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://rum.hlx.page *.afterpay.com *.afterpaycdn.com *.squarecdn.com *.cash.app *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal *.googleapis.com *.gstatic.com *.certcapture.com https://developer.adobe.com https://magento.com https://cdn.avmws.com/ http://cdn.avmws.com/ apps.bazaarvoice.com apps.nexus.bazaarvoice.com apps-stg.nexus.bazaarvoice.com analytics-static.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com mpsnare.iesnare.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com js.klevu.com *.ksearchnet.com *.googletagmanager.com *.facebook.net www.termsfeed.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.pinterest.com *.pinterdev.com *.pinimg.com commerce-app.pintergration.com *.pxlecdn.com *.pixlee.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com https://js.klevu.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.afterpay.com/ *.afterpaycdn.com *.squarecdn.com *.cash.app *.certcapture.com display.ugc.bazaarvoice.com *.klevu.com *.ksearchnet.com *.fontawesome.com assets.braintreegateway.com https://statsjs.klevu.com https://js.klevu.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.afterpay.com *.afterpay-beta.com *.afterpaycdn.com *.squarecdn.com *.cash.app api.lab.amplitude.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com *.googleapis.com *.certcapture.com https://developer.adobe.com https://cdn.avmws.com/ http://cdn.avmws.com/ api.bazaarvoice.com stg.api.bazaarvoice.com apps.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.klevu.com *.ksearchnet.com *.google-analytics.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.pinterest.com *.pinterdev.com commerce-app.pintergration.com https://inbound-analytics.pixlee.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com 'self' 'unsafe-inline'; child-src *.certcapture.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://224c98c5-2b57-48b9-abd5-386e2aff2a6c.sansec.watch/; report-to report-endpoint; 1 font-src fonts.googleapis.com fonts.gstatic.com *.gstatic.com data: *.googleapis.com https://fonts.gstatic.com *.cloudflare.com *.twitter.com *.typekit.net *.twimg.com *.trustedshops.com *.zopim.com *.zopim.io *.oct8ne.com *.fontawesome.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.adyen.com pay.google.com payments-eu.amazon.com *.amazon.de *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.twitter.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.adyen.com pay.google.com *.paypal.com www.google.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.weltpixel.com https://pay.kcp.co.kr https://paygw.kcp.co.kr https://testpay.kcp.co.kr https://www.youtube.com http://www.sandbox.paypal.com *.twitter.com *.hotjar.com *.pinterest.com *.pinterest.es *.criteo.com *.cookiebot.com *.doubleclick.net *.googletagmanager.com *.oct8ne.com js.mollie.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net data: www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com validator.swagger.io *.adyen.com pay.google.com *.payments-amazon.com *.media-amazon.com *.paypalobjects.com maps.googleapis.com maps.gstatic.com *.gstatic.com *.googleapis.com https://images.unsplash.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de cdn.doofinder.com https://maps.gstatic.com *.cloudflare.com *.klarna.com *.googleadservices.com *.google-analytics.com *.paypal.com *.twitter.com *.twimg.com *.ytimg.com *.bing.com *.zopim.com *.zopim.io *.doubleclick.net *.google.com *.google.co.in *.mastercard.com *.facebook.com *.pinterest.com *.google.es *.clarity.ms *.quantserve.com *.lladro.com *.yahoo.com *.3lift.com *.360yield.com *.pubmatic.com *.outbrain.com *.rubiconproject.com *.adnxs.com *.casalemedia.com *.tapad.com *.smartadserver.com *.taboola.com *.addthis.com *.dable.com *.criteo.com *.media.net *.bidswitch.net *.revcontent.com *.teads.tv *.sharethrough.com *.liadm.com *.dable.io *.yieldmo.com *.advertising.com *.clmbtech.com *.smaato.net *.dmxleo.com *.cookiebot.com visitor.omnitagis.com id5-sync.com matching.ivitrack.com exchange.mediavine.com jadserve.postrelease.com criteo-partners.tremorhub.com ad.yieldlab.net *.emxdgt.com sync.1rx.io sync.targeting.unrulymedia.com *.line.me www.googletagmanager.com visitor.omnitagjs.com *.oct8ne.com https://www.mollie.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com *.vimeocdn.com www.vimeo.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.googleapis.com https://cdn.jsdelivr.net/npm/@ryangjchandler/spruce@2.x.x/dist/spruce.umd.js www.google.com/recaptcha/ www.gstatic.com/recaptcha/ https://maps.googleapis.com *.gstatic.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de cdn.doofinder.com https://pay.kcp.co.kr https://paygw.kcp.co.kr https://testpay.kcp.co.kr *.cloudflare.com *.cloudfront.net *.twitter.com *.google-analytics.com *.twimg.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.bing.com *.zopim.com *.zdassets.com *.google.com *.googletagmanager.com *.facebook.net *.pinimg.com *.hotjar.com *.tiktok.com *.quantserve.com *.doubleclick.net *.quantcount.com *.doofinder.com *.oct8ne.com *.clarity.ms *.criteo.com *.criteo.net *.cookiebot.com www.mczbf.com *.line-scdn.net *.pinterest.com cdn.jsdelivr.net *.useberry.com js.mollie.com https://www.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.doofinder.com https://pay.kcp.co.kr https://paygw.kcp.co.kr https://testpay.kcp.co.kr https://fonts.googleapis.com *.cloudflare.com *.googleapis.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.fontawesome.com *.bing.com cdn.jsdelivr.net maxcdn.bootstrapcdn.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.zopim.com *.zopim.io 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adyen.com *.google.com www.google.com payments-eu.amazon.com *.paypal.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com https://maps.googleapis.com https://player.vimeo.com *.googleapis.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.doofinder.com wss://*.doofinder.com https://pay.kcp.co.kr https://paygw.kcp.co.kr https://testpay.kcp.co.kr *.analytics.google.com *.cloudflare.com *.twitter.com *.twimg.com *.zdassets.com *.zopim.com *.zopim.io wss://widget-mediator.zopim.com *.google-analytics.com *.doubleclick.net *.luckyorange.net *.pinterest.com *.tiktok.com *.clarity.ms *.oct8ne.com *.criteo.com www.mczbf.com *.cookiebot.com https://www.google-analytics.com 'self' 'unsafe-inline'; child-src https://pay.kcp.co.kr https://paygw.kcp.co.kr https://testpay.kcp.co.kr http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://seoulwebdev.report-uri.com/r/d/csp/reportOnly; report-to report-endpoint; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.klevu.com *.ksearchnet.com *.yotpo.com *.googleapis.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com https://plumrocket.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com *.dotdigital-pages.com *.dotdigital.com https://plumrocket.com *.iubenda.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com js.mollie.com https://accounts.google.com www.xtento.com *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: track.goggles4u.info https://track.goggles4u.info www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.trackedlink.net https://images.unsplash.com *.iubenda.com *.klevu.com *.ksearchnet.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://www.mollie.com www.google.com.ua www.xtento.com cdn.xtento.com *.yotpo.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal https://maps.googleapis.com *.iubenda.com *.klevu.com *.ksearchnet.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com js.mollie.com https://accounts.google.com https://www.gstatic.com www.xtento.com cdn.xtento.com *.yotpo.com https://js.klevu.com sst.goggles4u.com https: 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.klevu.com *.ksearchnet.com https://accounts.google.com https://www.gstatic.com *.yotpo.com *.googleapis.com https://statsjs.klevu.com https://js.klevu.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com https://maps.googleapis.com https://player.vimeo.com https://checkout.iwdagency.com *.iubenda.com *.klevu.com *.ksearchnet.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://accounts.google.com *.yotpo.com sst.goggles4u.com https: 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com https://fonts.gstatic.com *.yotpo.com *.googleapis.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.authorize.net *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors *.certcapture.com *.authorize.net 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com *.certcapture.com static.addtoany.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com *.authorize.net *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.certcapture.com mcstaging.trainworld.com *.googleapis.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://maps.googleapis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com maps.gstatic.com *.yotpo.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.certcapture.com static.addtoany.com connect.facebook.net https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://maps.googleapis.com https://cdn.jsdelivr.net www.facebook.com graph.facebook.com business.facebook.com *.authorize.net maps.googleapis.com *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.certcapture.com https://static.klaviyo.com *.fontawesome.com *.googleapis.com *.addtoany.com *.yotpo.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.certcapture.com *.doubleclick.net https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://maps.googleapis.com http://dpm.demdex.net www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.authorize.net maps.googleapis.com *.yotpo.com 'self' 'unsafe-inline'; child-src *.certcapture.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.googleapis.com *.gstatic.com data: code.ionicframework.com maxcdn.bootstrapcdn.com media.flixfacts.com media.flixcar.com *.fontawesome.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com www.google.com media.flixcar.com *.zdassets.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net *.gstatic.com *.googleapis.com gateway.apaylater.com gateway.atome.sg media.flixcar.com *.flix360.com *.flix360.io 'self' data: data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net amcglobal.sc.omtrdc.net commerce.adobe.net use.typekit.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-ds.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ gateway.apaylater.com gateway.atome.sg static.hotjar.com cdnjs.cloudflare.com js-agent.newrelic.com bam-cell.nr-data.net www.google.com www.gstatic.com media.flixcar.com media.flixfacts.com *.zendesk.com *.zdassets.com *.outbrain.com www.datadoghq-browser-agent.com *.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com gateway.apaylater.com gateway.atome.sg code.ionicframework.com *.freshchat.com maxcdn.bootstrapcdn.com media.flixcar.com *.fontawesome.com *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io commerce.adobe.net qa-api.magedevteam.com *.sentry.io *.googleapis.com bam-cell.nr-data.net *.google-analytics.com media.flixcar.com *.zendesk.com *.zdassets.com *.outbrain.com *.datadoghq.com browser-intake-datadoghq.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src https://fonts.gstatic.com userlike-cdn-umm.b-cdn.net *.gstatic.com data: *.cloudfront.net *.mey.com app.usercentrics.eu 'self' data: 'self' 'unsafe-inline';form-action secure.authorize.net test.authorize.net pilot-payflowlink.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de www.facebook.com 'self' 'unsafe-inline';frame-ancestors https://*.etracker.com www.gstatic.com 'self';frame-src *.google.com vimeo.com player.vimeo.com charger-v2.trbo.com static.trbo.com track2.trbo.com collect.trbo.com https://www.googletagmanager.com https://td.doubleclick.net player.vimeo.com *.youtube-nocookie.com *.youtube.com https://collect.mey.com https://*.criteo.com userlike-cdn-umm.b-cdn.net userlike-cdn-widgets.s3-eu-west-1.amazonaws.com api.userlike.com https://static.criteo.net *.zenaps.com *.awin1.com bid.g.doubleclick.net td.doubleclick.net ct.pinterest.com www.awin1.com fast.amc.demdex.net *.adobe.com secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.googletagmanager.com *.adyen.com www.google.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de ad.ad-srv.net *.adsrvr.org *.fls.doubleclick.net www.facebook.com opt.kuponacdn.de gum.criteo.com pixel.mathtag.comm pp.payengine.de pptest.payengine.de checkoutshopper-test.adyen.com/ checkoutshopper.adyen.com/ 'self' 'unsafe-inline';img-src *.googleusercontent.com https://*.gstatic.com https://*.googleapis.com *.cdninstagram.com static.trbo.com track2.trbo.com collect.trbo.com https://*.google.nl https://*.google.be https://*.google.at https://*.google.ch https://*.google.it https://*.google.es https://*.google.fr https://*.google.dk https://*.google.lu https://*.google.ca https://*.google.ie https://*.google.pt https://*.google.si https://*.google.co.uk https://*.google.pl https://*.google.com.hk https://*.google.gr https://*.google.com.sg https://*.google.se https://*.google.no https://*.google.ad https://*.google.ru https://*.google.fi https://*.google.co.in https://*.google.com.ua https://*.google.hr https://*.google.hu https://*.google.com https://*.google.com.tr https://*.google.co.jp https://*.google.com.sa https://*.google.md https://*.google.com.br https://*.google.rs https://*.google.com.tw https://*.google.ee https://*.google.co.th https://*.google.jo https://*.google.com.qa https://*.google.kz https://*.google.com.ar https://*.google.tn https://*.google.li https://*.google.sk https://*.google.com.vn https://*.google.ae https://*.google.lv https://*.google.co.kr https://*.google.bf https://*.google.ro https://*.google.co.il https://google.com https://www.googleadservices.com https://pagead2.googlesyndication.com https://www.google.com https://googleads.g.doubleclick.net https://www.googletagmanager.com *.vimeocdn.com https://*.outbrain.com https://*.roeye.com https://www.wepowerconnections.com userlike-store-media-files.s3.amazonaws.com www.userlike.com userlike-cdn-web.b-cdn.net userlike-cdn-operators.s3-eu-west-1.amazonaws.com userlike-cdn-operators.userlike.com ct.pinterest.com bat.bing.com *.zenaps.com *.awin1.com googleads.g.doubleclick.net www.etracker.de id5-sync.com s.thebrighttag.com beacon.krxd.net *.google.de *.google.com ads.creative-serving.com *.uimserv.net *.adnxs.com ups.analytics.yahoo.com visitor.omnitagjs.com *.ad.smaato.net matching.ivitrack.com exchange.mediavine.com *.taboola.com *.stickyadstv.com criteo-sync.teads.tv cm.adform.net sync-criteo.ads.yieldmo.com ad.sxp.smartclip.net *.emxdgt.com criteo-partners.tremorhub.com sync.outbrain.com *.3lift.com *.smartadserver.com ads.yahoo.com *.casalemedia.com *.bidswitch.net *.twiago.com contextual.media.net match.sharethrough.com *.pubmatic.com cdn.stickyadstv.com *.adscale.de ad.360yield.com sp.analytics.yahoo.com ad.yieldlab.net cotads.adscale.de *.criteo.com *.liadm.com pixel.rubiconproject.com assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.adyen.com *.gstatic.com *.googleapis.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de www.awin1.com *.bing.com *.cloudfront.net stats.g.doubleclick.net *.doubleclick.net *.g.doubleclick.net www.facebook.com www.google.com www.google.de www.googletagmanager.com *.usercentrics.eu *.adfarm1.adition.com *.adition.com *.pinterest.com pixel.mathtag.com *.adnxs.com checkoutshopper-test.adyen.com/ checkoutshopper.adyen.com/ *.mey.com *.clarity.ms app.usercentrics.eu api.usercentrics.eu aggregator.service.usercentrics.eu 'self' data: 'self' 'unsafe-inline';script-src *.googleusercontent.com https://*.ggpht.com https://*.gstatic.com https://*.googleapis.com www.instagram.com platform.instagram.com player.vimeo.com charger-v2.trbo.com static.trbo.com api-v4.trbo.com https://www.googleadservices.com https://www.google.com https://pagead2.googlesyndication.com https://googleads.g.doubleclick.net *.vimeocdn.com www.vimeo.com vimeo.com https://*.roeyecdn.com https://tagmanager.google.com https://googletagmanager.com https://www.googletagmanager.com https://*.outbrain.com ct.pinterest.com https://*.criteo.com *.zenaps.com *.awin1.com collect.mey.com userlike-cdn-umm.b-cdn.net api.userlike.com userlike-cdn-widgets.s3-eu-west-1.amazonaws.com cdn.polyfill.io www.googleoptimize.com browser.sentry-cdn.com *.etracker.de *.etracker.com *.google.de *.google.com assets.adobedtm.com *.adobe.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.googletagmanager.com *.adyen.com *.googleapis.com www.gstatic.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de jquery.sellxed.com *.adform.net *.amazon.com js.adsrvr.org www.awin1.com bat.bing.com *.dt51.net *.cloudfront.net googleads.g.doubleclick.net www.dwin1.com connect.facebook.net www.google.com *.google-analytics.com www.gstatic.com mastertag.kpcustomer.de opt.kuponacdn.de bam.nr-data.net bam.eu01.nr-data.net js-agent.newrelic.com static.shopgate.com the.sciencebehindecommerce.com tagmanager.google.com *.usercentrics.eu *.kuponacdn.de app.theadx.com browser-update.org pixel.mathtag.com pptest.payengine.de *.adnxs.com static.criteo.net s.pinimg.com sslwidget.criteo.com *.clarity.ms *.mey.com *.google.com *.gstatic.com app.usercentrics.eu 'self' 'unsafe-inline' 'unsafe-eval';style-src https://fonts.googleapis.com static.trbo.com https://tagmanager.google.com https://googletagmanager.com https://www.googletagmanager.com *.adobe.com fonts.googleapis.com *.usercentrics.eu *.cloudfront.net *.mey.com *.googleapis.com *.gstatic.com app.usercentrics.eu 'self' 'unsafe-inline';object-src 'self' 'unsafe-inline';media-src *.cdninstagram.com www.userlike.com userlike-store-media-files.s3.amazonaws.com userlike-cdn-umm.b-cdn.net *.adobe.com blob: 'self' 'unsafe-inline';manifest-src 'self' 'unsafe-inline';connect-src https://*.gstatic.com https://*.googleapis.com www.instagram.com platform.instagram.com *.cdninstagram.com vimeo.com player.vimeo.com data.trbo.com newsletter-api.trbo.com api-v4.trbo.com *.snplow.net commerce.adobedc.net *.adobe.io https://www.google.com https://google.com https://www.googleadservices.com https://pagead2.googlesyndication.com https://player.vimeo.com vimeo.com http://bat.bing.net https://*.outbrain.com www.userlike.com userlike-cdn-web.b-cdn.net umd.userlike.com wss://umd.userlike.com ct.pinterest.com https://*.etracker.de https://*.criteo.com https://*.wepowerconnections.com https://*.g.doubleclick.net https://*.google.com https://*.google.ad https://*.google.ae https://*.google.com.af https://*.google.com.ag https://*.google.al https://*.google.am https://*.google.co.ao https://*.google.com.ar https://*.google.as https://*.google.at https://*.google.com.au https://*.google.az https://*.google.ba https://*.google.com.bd https://*.google.be https://*.google.bf https://*.google.bg https://*.google.com.bh https://*.google.bi https://*.google.bj https://*.google.com.bn https://*.google.com.bo https://*.google.com.br https://*.google.bs https://*.google.bt https://*.google.co.bw https://*.google.by https://*.google.com.bz https://*.google.ca https://*.google.cd https://*.google.cf https://*.google.cg https://*.google.ch https://*.google.ci https://*.google.co.ck https://*.google.cl https://*.google.cm https://*.google.cn https://*.google.com.co https://*.google.co.cr https://*.google.com.cu https://*.google.cv https://*.google.com.cy https://*.google.cz https://*.google.de https://*.google.dj https://*.google.dk https://*.google.dm https://*.google.com.do https://*.google.dz https://*.google.com.ec https://*.google.ee https://*.google.com.eg https://*.google.es https://*.google.com.et https://*.google.fi https://*.google.com.fj https://*.google.fm https://*.google.fr https://*.google.ga https://*.google.ge https://*.google.gg https://*.google.com.gh https://*.google.com.gi https://*.google.gl https://*.google.gm https://*.google.gr https://*.google.com.gt https://*.google.gy https://*.google.com.hk https://*.google.hn https://*.google.hr https://*.google.ht https://*.google.hu https://*.google.co.id https://*.google.ie https://*.google.co.il https://*.google.im https://*.google.co.in https://*.google.iq https://*.google.is https://*.google.it https://*.google.je https://*.google.com.jm https://*.google.jo https://*.google.co.jp https://*.google.co.ke https://*.google.com.kh https://*.google.ki https://*.google.kg https://*.google.co.kr https://*.google.com.kw https://*.google.kz https://*.google.la https://*.google.com.lb https://*.google.li https://*.google.lk https://*.google.co.ls https://*.google.lt https://*.google.lu https://*.google.lv https://*.google.com.ly https://*.google.co.ma https://*.google.md https://*.google.me https://*.google.mg https://*.google.mk https://*.google.ml https://*.google.com.mm https://*.google.mn https://*.google.com.mt https://*.google.mu https://*.google.mv https://*.google.mw https://*.google.com.mx https://*.google.com.my https://*.google.co.mz https://*.google.com.na https://*.google.com.ng https://*.google.com.ni https://*.google.ne https://*.google.nl https://*.google.no https://*.google.com.np https://*.google.nr https://*.google.nu https://*.google.co.nz https://*.google.com.om https://*.google.com.pa https://*.google.com.pe https://*.google.com.pg https://*.google.com.ph https://*.google.com.pk https://*.google.pl https://*.google.pn https://*.google.com.pr https://*.google.ps https://*.google.pt https://*.google.com.py https://*.google.com.qa https://*.google.ro https://*.google.ru https://*.google.rw https://*.google.com.sa https://*.google.com.sb https://*.google.sc https://*.google.se https://*.google.com.sg https://*.google.sh https://*.google.si https://*.google.sk https://*.google.com.sl https://*.google.sn https://*.google.so https://*.google.sm https://*.google.sr https://*.google.st https://*.google.com.sv https://*.google.td https://*.google.tg https://*.google.co.th https://*.google.com.tj https://*.google.tl https://*.google.tm https://*.google.tn https://*.google.to https://*.google.com.tr https://*.google.tt https://*.google.com.tw https://*.google.co.tz https://*.google.com.ua https://*.google.co.ug https://*.google.co.uk https://*.google.com.uy https://*.google.co.uz https://*.google.com.vc https://*.google.co.ve https://*.google.co.vi https://*.google.com.vn https://*.google.vu https://*.google.ws https://*.google.rs https://*.google.co.za https://*.google.co.zm https://*.google.co.zw https://*.google.cat https://collect.mey.com https://*.googletagmanager.com *.addressy.com maps.googleapis.com userlike-cdn-umm.b-cdn.net api.userlike.com userlike-cdn-widgets.s3-eu-west-1.amazonaws.com sentry.mey.netz98.org eu-api.friendlycaptcha.eu www.etracker.de www.facebook.com www.clarity.ms dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com *.adyen.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de stats.g.doubleclick.net mey.dvinci-hr.com bam.eu01.nr-data.net the.sciencebehindecommerce.com *.usercentrics.eu aggregator.service.usercentrics.eu bat.bing.com *.pinterest.com *.google-analytics.com *.maps.googleapis.com *.mey.com *.cloudfront.net *.clarity.ms www.googletagmanager.com app.usercentrics.eu api.usercentrics.eu aggregator.service.usercentrics.eu blob: 'self' 'unsafe-inline';child-src userlike-cdn-umm.b-cdn.net userlike-cdn-widgets.s3-eu-west-1.amazonaws.com api.userlike.com http: https: blob: 'self' 'unsafe-inline';default-src https://*.outbrain.com https://*.clarity.ms https://c.bing.com *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval';base-uri 'self' 'unsafe-inline';report-uri https://sentry.mey.netz98.org/api/2/security/?sentry_key=81ac2c0efc304bedbb370dc8e745b346&sentry_environment=stage3;report-to csp-endpoint; 1 default-src https://d13qcyivyon4xf.cloudfront.net https://*.recollect.net https://www2.elpasotexas.gov https://*.piktochart.com https://elpasotx.citysourced.com https://alive5.com https://*.pure.cloud https://td.doubleclick.net https://*.userway.org https://*.powerbigov.us 'self' data:; script-src https://*.fontawesome.com https://*.googletagmanager.com https://*.google.com https://*.google-analytics.com https://*.gstatic.com https://*.jquery.com 'sha256-EFV8pmp/wh+U6PZamj4KQ0q8X4ZQK18tF7skjashMC0=' 'sha256-d470bixwKmL9bRvqX+/YcGn63ywAfKoybYPkM5Uytpg=' 'sha256-CWheM/qrotfHL9rkBHCUQoQJ26R59qBT9Y6zmdWMo4I=' https://*.cloudflare.com https://*.jsdelivr.net https://*.recollect.net 'sha256-GZcyqV0YX2St+S/OQczTu1wNNg/O+RTwzw2JTTta3P0=' https://googletagmanager.com https://acsbapp.com https://*.pure.cloud https://*.acsbapp.com 'sha256-EhQpu6NNucte8YbnJ4xqNQ3ZEr6lZr9OylXRM08U23w=' 'sha256-6LGMzcnzg+kSHN9kCfnGBfyFkTD5ralHy4kgX9bEKac=' https://*.userway.org https://alive5.com 'sha256-Ktbr5+uWaq/tdIzd+uSnzMynWRb8C1GgwNmidruZnl4=' https://*.elpasotexas.gov 'sha256-N/ojzpn0NH2iToAWgtz7/qj3VTBrzGc5Kq/wcHmeC9g=' 'sha256-32mhgs7qr26DY71TSkr2GH6b4cN1O1vqJZeD8VqK09E=' 'sha256-ogBzyJChbukfa3Sy3FmuFfBT4HErpPzLDY1mDXuD08I=' https://*.clarity.ms 'sha256-1Mtgu0LP1N914Q7hPqP5oj1G7I5kj4eUK9emzGHCGU0=' https://*.youtube.com 'sha256-ISZqhiP5lsW/o4tzWAjiLcmBSgn4ci50MHTdBAJeJzo=' https://*.googleadservices.com 'unsafe-eval' https://*.facebook.net https://*.adtrafficquality.google https://*.cloudflareinsights.com 'self' 'report-sample' 'nonce-00e551cd5f62e38d'; style-src https://*.googleapis.com https://*.fontawesome.com https://*.google.com https://*.jsdelivr.net https://*.typekit.net https://*.fastly.net https://alive5.com https://*.userway.org https://*.gstatic.com 'self' 'unsafe-inline' 'report-sample'; connect-src https://*.fontawesome.com https://*.google-analytics.com https://*.doubleclick.net https://*.google.com https://googletagmanager.com https://*.acsbapp.com https://webmessaging.usw2.pure.cloud https://*.pure.cloud https://*.userway.org https://*.alive5.com https://alive5.com https://*.clarity.ms https://*.adtrafficquality.google https://*.g.doubleclick.net https://*.googleapis.com 'self' data:; font-src https://*.gstatic.com https://*.fontawesome.com https://*.jsdelivr.net https://*.typekit.net https://*.fastly.net https://acsbapp.com https://*.userway.org 'self' data:; img-src https://*.google.com https://*.googleapis.com https://*.google-analytics.com https://*.jsdelivr.net https://*.fastly.net https://*.recollect.net https://*.piktochart.com https://*.userway.org https://*.alive5.com https://*.clarity.ms https://*.gstatic.com https://*.googletagmanager.com https://*.bing.com https://tip411.com https://*.tip411.com https://*.adtrafficquality.google https://*.g.doubleclick.net https://*.google.com.mx 'self' data:; Strict-Transport-Security max-age=31536000; frame-src https://syndicatedsearch.goog https://www2.elpasotexas.gov https://alive5.com https://*.youtube.com https://*.powerbigov.us https://*.google.com https://*.adtrafficquality.google https://*.userway.org https://googletagmanager.com https://coepgis.map.arcgis.com https://*.googletagmanager.com https://tip411.com https://*.tip411.com 'self'; media-src https://*.gstatic.com 'self'; script-src-elem https://*.fontawesome.com https://*.googletagmanager.com https://*.google.com https://*.google-analytics.com https://*.gstatic.com https://*.jquery.com 'sha256-EFV8pmp/wh+U6PZamj4KQ0q8X4ZQK18tF7skjashMC0=' 'sha256-d470bixwKmL9bRvqX+/YcGn63ywAfKoybYPkM5Uytpg=' 'sha256-CWheM/qrotfHL9rkBHCUQoQJ26R59qBT9Y6zmdWMo4I=' https://*.cloudflare.com https://*.jsdelivr.net https://*.recollect.net 'sha256-GZcyqV0YX2St+S/OQczTu1wNNg/O+RTwzw2JTTta3P0=' https://googletagmanager.com https://acsbapp.com https://*.pure.cloud https://*.acsbapp.com 'sha256-EhQpu6NNucte8YbnJ4xqNQ3ZEr6lZr9OylXRM08U23w=' 'sha256-6LGMzcnzg+kSHN9kCfnGBfyFkTD5ralHy4kgX9bEKac=' https://*.userway.org https://alive5.com 'sha256-Ktbr5+uWaq/tdIzd+uSnzMynWRb8C1GgwNmidruZnl4=' https://*.elpasotexas.gov 'sha256-N/ojzpn0NH2iToAWgtz7/qj3VTBrzGc5Kq/wcHmeC9g=' 'sha256-32mhgs7qr26DY71TSkr2GH6b4cN1O1vqJZeD8VqK09E=' 'sha256-ogBzyJChbukfa3Sy3FmuFfBT4HErpPzLDY1mDXuD08I=' https://*.clarity.ms 'sha256-1Mtgu0LP1N914Q7hPqP5oj1G7I5kj4eUK9emzGHCGU0=' https://*.youtube.com 'sha256-ISZqhiP5lsW/o4tzWAjiLcmBSgn4ci50MHTdBAJeJzo=' https://*.googleadservices.com 'unsafe-eval' https://*.facebook.net https://*.adtrafficquality.google 'sha256-RlhVC6WGhVrcsY0hAmbU/YhaSUz2iA2q1f16/7A6jLU=' 'self' 'report-sample' 'nonce-00e551cd5f62e38d'; frame-ancestors 'self'; 1 form-action 'report-sample' 'self' 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.espssl.com *.twitter.com *.google.com *.google.co.in *.facebook.com *.twimg.com *.googleapis.com *.bootstrapcdn.com *.cloudflare.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.twitter.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.ladesk.com *.twitter.com *.google.co.in *.kaptcha.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.google.com/ 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://www.magezon.com *.espssl.com *.payments-amazon.com *.listrakbi.com *.pinterest.com *.facebook.com *.google.com *.google.co.in *.klarna.com *.twitter.com *.ytimg.com stats.g.doubleclick.net *.connect.facebook.net pixel.advertising.com *.googletagmanager.com *.twimg.com *.placehold.it blob: www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.googleapis.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com cdnjs.cloudflare.com *.pinterest.com *.listrakbi.com *.listrak.com *.ladesk.com s.pinimg.com *.facebook.net *.twitter.com *.google.co.in *.facebook.com *.twimg.com *.gstatic.com connect.facebook.net *.googletagmanager.com static-na.payments-amazon.com js-agent.newrelic.com *.jquery.com 'self' js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googleapis.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.google.com/ 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com cdnjs.cloudflare.com *.jquery.com *.espssl.com *.fontawesome.com *.typekit.net https://use.typekit.net *.listrakbi.com *.googleapis.com *.twitter.com *.google.com *.google.co.in *.facebook.com *.twimg.com *.gstatic.com *.youtube.com *.bootstrapcdn.com 'unsafe-inline' unsafe-inline assets.braintreegateway.com maxcdn.bootstrapcdn.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.listrakbi.com *.doubleclick.net *.algolia.io *.pinterest.com *.twitter.com *.twimg.com *.google.co.in *.facebook.com *.braintree-api.com *.amazon.com bam.nr-data.net *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.googleapis.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de 'self' 'unsafe-inline'; child-src 'self' blob: assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://actionis.report-uri.com/a/d/g; report-to report-endpoint; 1 font-src *.googleapis.com https://www.gstatic.com *.fontawesome.com https://live.icecat.biz data: https://googletagmanager.com https://tagmanager.google.com https://fonts.gstatic.com locator.uberall.com script.hotjar.com *.hotjar.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com www.google.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com js.mollie.com dashboard.trustprofile.com td.doubleclick.net https://s3-eu-west-1.amazonaws.com/ https://td.doubleclick.net https://google-analytics.com https://objects.icecat.biz/ *.trustpilot.com https://www.google.com www.xtento.com trafic-career.talent-soft.com view.publitas.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.googleapis.com *.gstatic.com cdn.doofinder.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://www.mollie.com funtrafic.imgix.net bat.bing.com www.google.be lqip-funtrafic.imgix.net https://funtrafic-large.imgix.net/media/ https://funtrafic-thumb.imgix.net/media/ https://pdpthumb-funtrafic.imgix.net https://pdplarge-funtrafic.imgix.net https://pdpfull-funtrafic.imgix.net https://content.fun.be https://adservice.google.com https://region1.analytics.google.com https://googletagmanager.com https://tagmanager.google.com https://bat.bing.com https://pagead2.googlesyndication.com https://td.doubleclick.net https://google-analytics.com www.xtento.com cdn.xtento.com bat.bing.net catalogmedia.trafic.com funtrafic-thumb.imgix.net joko-mobile-app-media.s3.eu-west-1.amazonaws.com locator.uberall.com magentoadmin.trafic.com www.google.de www.google.fr www.google.lt www.google.lu *.google.com www.trafic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.googleapis.com https://www.gstatic.com cdn.doofinder.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com js.mollie.com static.hotjar.com eu1-config.doofinder.com widget.trustpilot.com invitejs.trustpilot.com script.hotjar.com bat.bing.com js-agent.newrelic.com https://live.icecat.biz https://bat.bing.com https://js-agent.newrelic.com https://googletagmanager.com https://tagmanager.google.com https://td.doubleclick.net https://google-analytics.com *.trustpilot.com www.xtento.com cdn.xtento.com api.mapbox.com locator.uberall.com view.publitas.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.doofinder.com *.fontawesome.com cdn.doofinder.com https://live.icecat.biz blob: https://googletagmanager.com https://tagmanager.google.com *.trustpilot.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.googleapis.com *.doofinder.com wss://*.doofinder.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com region1.analytics.google.com eu1-api.doofinder.com bam.eu01.nr-data.net https://invitejs.trustpilot.com https://live.icecat.biz https://magentoadmin.trafic.docker https://adservice.google.com https://region1.analytics.google.com https://www.google.com https://www.google.be https://googleads.g.doubleclick.net https://stats.g.doubleclick.net https://td.doubleclick.net https://google-analytics.com https://pagead2.googlesyndication.com api.mapbox.com bat.bing.com bat.bing.net content.hotjar.io events.mapbox.com locator.uberall.com surveystats.hotjar.io vc.hotjar.io *.hotjar.com wss: wss://ws.hotjar.com www.google.lu *.google.com *.mapbox.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src bat.bing.com bam.eu01.nr-data.net googleads.g.doubleclick.net 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' 'unsafe-inline' *.nationalgrideso.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.google-analytics.com *.hotjar.com *.clarity.ms bing.com *.bing.com players.brightcove.net *.nationalgrideso.com www.googletagmanager.com assets.juicer.io js.createsend1.com www.smartsurvey.co.uk assets.smartsurvey.io snap.licdn.com unpkg.com js-agent.newrelic.com *.cookieyes.com cdn-cookieyes.com my.visme.co; style-src 'self' 'unsafe-inline' *.nationalgrideso.com assets.juicer.io unpkg.com fonts.googleapis.com; img-src 'self' data: *.nationalgrideso.com *.clarity.ms www.googletagmanager.com *.google.co.uk c.bing.com www.juicer.io assets.juicer.io www.smartsurvey.co.uk *.cartocdn.com datanationalgrideso.files.wordpress.com *.tile.openstreetmap.org *.linkedin.com *.cookieyes.com cdn-cookieyes.com; frame-src 'self' *.nationalgrideso.com *.nationalgrid.com players.brightcove.net www.youtube.com app.powerbi.com my.visme.co; font-src 'self' themes.googleusercontent.com static.juicer.io fonts.googleapis.com fonts.gstatic.com; connect-src 'self' *.clarity.ms *.hotjar.io *.hotjar.com *.google-analytics.com *.analytics.google.com storage.googleapis.com www.juicer.io *.staging.datopian.com bam.nr-data.net *.cookieyes.com cdn-cookieyes.com 1 script-src 'nonce-1ea1d8f8d38f4f38eb7deca6865ac18ee6dd0669d48cd3dd8336c4280ec56ffe' 'strict-dynamic';object-src 'none';base-uri 'none';frame-ancestors 'none'; 1 object-src 'none';base-uri 'self';script-src 'nonce-mMa18soBoD5EJu2dtuHAHw' 'strict-dynamic' 'report-sample' 'unsafe-eval' 'unsafe-inline' https: http:;report-uri https://csp.withgoogle.com/csp/gws/other-hp 1 font-src fonts.gstatic.com *.googleapis.com *.gstatic.com *.klevu.com *.ksearchnet.com https://script.hotjar.com https://fonts.gstatic.com https://embed.tawk.to https://i5.walmartimages.com https://use.typekit.net 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.canadapost.ca https://sso.epost.ca www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com api.bazaarvoice.com stg.api.bazaarvoice.com testsecureacceptance.cybersource.com secureacceptance.cybersource.com 0merchantacsstag.cardinalcommerce.com merchantacs.cardinalcommerce.com https://testsecureacceptance.cybersource.com https://secureacceptance.cybersource.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.dotdigital-pages.com *.dotdigital.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com *.online-metrix.net testflex.cybersource.com flex.cybersource.com testsecureacceptance.cybersource.com secureacceptance.cybersource.com pay.google.com merchantacs.cardinalcommerce.com 0merchantacsstag.cardinalcommerce.com webchat.dotdigital.com webchat.staging.dotdigital.com www.xtento.com https://vars.hotjar.com https://testsecureacceptance.cybersource.com https://secureacceptance.cybersource.com https://testflex.cybersource.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io maps.googleapis.com mageside.com *.canadapost.ca *.googleapis.com *.gstatic.com https://www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.trackedlink.net display.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com network-a.bazaarvoice.com network-stg-a.bazaarvoice.com photos-uat-us.bazaarvoice.com img.youtube.com www.gstatic.com *.klevu.com *.ksearchnet.com www.xtento.com cdn.xtento.com https://maps.gstatic.com https://www.google.com https://www.google.ca https://stats.g.doubleclick.net https://tools.applemediaservices.com https://aq.flippenterprise.net https://f.wishabi.net https://cdn.flippenterprise.net https://apple-resources.s3.amazonaws.com magefan.com cm.magefan.com *.disqus.com https://img.youtube.com *.hsforms.net *.hsforms.com 'self' data: data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://www.googletagmanager.com maps.googleapis.com developers.google.com *.googleapis.com *.google.com *.gstatic.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal apps.bazaarvoice.com apps.nexus.bazaarvoice.com apps-stg.nexus.bazaarvoice.com analytics-static.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com mpsnare.iesnare.com *.online-metrix.net testflex.cybersource.com flex.cybersource.com pay.google.com x.klarnacdn.net centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com webchat.dotdigital.com webchat.staging.dotdigital.com *.klevu.com *.ksearchnet.com www.xtento.com cdn.xtento.com https://maps.googleapis.com https://maps.gstatic.com https://connect.facebook.net https://static.hotjar.com https://kent-esengage.live.exchangesolutions.com https://cdn.jsdelivr.net https://embed.tawk.to https://a.omappapi.com https://aq.flippenterprise.net *.disqus.com *.hsforms.net *.hsforms.com https://js.klevu.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com display.ugc.bazaarvoice.com webchat.dotdigital.com webchat.staging.dotdigital.com *.klevu.com *.ksearchnet.com https://fonts.googleapis.com https://cdn.jsdelivr.net https://a.omappapi.com https://embed.tawk.to https://aq.flippenterprise.net https://use.typekit.net https://p.typekit.net *.gstatic.com https://js.klevu.com https://kent.ca 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com api.bazaarvoice.com stg.api.bazaarvoice.com apps.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com webchat.dotdigital.com webchat.staging.dotdigital.com *.klevu.com *.ksearchnet.com https://api.omappapi.com https://maps.googleapis.com https://va.tawk.to https://embed.tawk.to https://aq.flippenterprise.net https://dam.flippenterprise.net https://app.launchdarkly.com https://region1.analytics.google.com https://cdn-gateflipp.flippback.com https://p.flipp.com https://events.launchdarkly.com https://google.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; child-src 'none'; object-src 'none'; script-src http: https: 'strict-dynamic' 'nonce-RSvySH8bz3PGggJ8FyAh8y+imnhkd6ndE0Ggzpp1ruA='; connect-src 'self' https://vitruv.uni-tuebingen.de https://services.dnb.de; worker-src blob:; style-src 'self' 'unsafe-inline'; img-src 'self' data: http://*.tile.osm.org https://*.tile.osm.org https://services.dnb.de; font-src 'self'; base-uri 'self'; frame-src 'self'; 1 frame-src *.force.com https://player.vimeo.com 'self' *.youtube.co.uk https://sfdc-link-preview.hk.salesforce.com https://checkoutshopper-test.adyen.com/ https://pal-test.adyen.com *.cybersource.com *.youtube.es https://usa856.sfdc-yfeipo.salesforce.com *.adis.ws *.youtube.ie https://www.youtube.com *.cloudinary.com https://pay.google.com *.vimeo.com *.youtube.jp bcove.video https://www.kdpcommunity.com *.youtube.fr https://*.a.forceusercontent.com https://player.cloudinary.com https://sfdc-link-preview-staging.sfdc.sh https://s1.adis.ws *.forceusercontent.com *.youtube.com *.brightcove.net *.youtube.nl https://service.force.com/embeddedservice/ https://testdata.coremetrics.com https://fast.wistia.net *.quip.com *.arkoselabs.com *.youtube-nocookie.com https://www.paypal.com https://appiniummastertrial.secure.force.com https://play.vidyard.com https://www.abebooks.com *.youtube.com.br *.salesforce-experience.com *.salesforceliveagent.com https://indiecommunity.file.force.com https://scormanywhere.secure.force.com https://checkoutshopper-live.adyen.com/ *.sfdcfc.net *.youtube.ca https://location.force.com *.vidyard.com https://www.gstatic.com/recaptcha/ https://players.brightcove.net https://cdn.embedly.com https://www.google.com/recaptcha/ https://js.stripe.com/ https://www.sandbox.paypal.com https://kdpcommunity.com https://assets.prod.abebookscdn.com https://*.a.forceusercontent.com/lightningmaps/ *.wistia.net *.salesforce.com *.youtube.pl; report-to sfdc-csp-ep; report-uri https://indiecommunity.lightning.force.com/_/ContentDomainCSPNoAuth?tenantId=00Df4000001cwvQ&networkId=0DMf4000000gttr&type=communities 1 font-src https://fonts.gstatic.com *.klevu.com *.ksearchnet.com fonts.gstatic.com blog.vintageking.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.syfpos.com *.facebook.com blog.vintageking.com 'self' 'unsafe-inline'; frame-ancestors blog.vintageking.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.affirm.com *.affirm.ca c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * syf.demdex.net *.syfpos.com *.syf.com *.weltpixel.com www.xtento.com https://www.googletagmanager.com/ *.wesupply.xyz https://wesupplylabs.com *.googletagmanager.com *.doubleclick.net https://*.online-metrix.net https://imgs.signifyd.com blog.vintageking.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://images.unsplash.com *.affirm.com *.affirm.ca https://helloextend-static-assets.s3.amazonaws.com validate.fishpig.co.uk https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.syfpos.com *.syf.com analytics.synchrony.com *.d1.sc.omtrdc.net www.xtento.com cdn.xtento.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ *.klevu.com *.ksearchnet.com *.gstatic.com *.facebook.com *.reddit.com *.ads-twitter.com t.co *.twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.google-analytics.com *.googletagmanager.com *.doubleclick.net *.google.com https://imgs.signifyd.com https://*.online-metrix.net blog.vintageking.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.affirm.com *.affirm.ca https://*.helloextend.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.syfpos.com analytics.synchrony.com *.mysynchrony.com https://*.leadmanagerfx.com https://*.marketingcloudfx.com www.xtento.com cdn.xtento.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ *.klevu.com *.ksearchnet.com *.cloudflare.com *.googletagmanager.com *.googleadservices.com *.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.bing.com *.clarity.ms *.klaviyo.com unpkg.com *.doubleclick.net https://cdn-scripts.signifyd.com https://imgs.signifyd.com blog.vintageking.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://fonts.googleapis.com https://static.klaviyo.com unsafe-inline assets.braintreegateway.com *.syfpos.com *.klevu.com *.ksearchnet.com *.tagmanager.google.com *.googletagmanager.com fonts.googleapis.com blog.vintageking.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ blog.vintageking.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.affirm.com *.affirm.ca https://*.helloextend.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.syfpos.com *.syf.com *.d1.sc.omtrdc.net https://*.leadmanagerfx.com https://*.marketingcloudfx.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ *.klevu.com *.ksearchnet.com *.google-analytics.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.doubleclick.net *.run.app https://imgs.signifyd.com blog.vintageking.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com blog.vintageking.com http: https: blob: 'self' 'unsafe-inline'; default-src blog.vintageking.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self';base-uri 'self';frame-ancestors 'self';frame-src https://* 'self' epichttp: https://pay-staging.instamed.com https://pay.instamed.com;script-src 'nonce-6dd7509dec83471ab8e657dad4bb55be' https://myhealthatvanderbilt.com 'self';img-src https://* 'self' blob: data:;connect-src 'self' epichttp:;style-src https://myhealthatvanderbilt.com 'self' 'unsafe-inline';worker-src 'self' blob:;child-src 'self' blob:;form-action https://central.mychart.org/MyChart/ 'self';media-src https://* 'self' blob:; 1 font-src fonts.gstatic.com use.typekit.net www.paypalobjects.com *.typekit.net *.gstatic.com cash-f.squarecdn.com fonts.googleapis.com *.googleapis.com data: *.fontawesome.com *.oct8ne.com oct8necdneu.azureedge.net blob: *.yotpo.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com * https://plumrocket.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.certcapture.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com * www.google.com *.certcapture.com www.xtento.com https://plumrocket.com js.mollie.com *.oct8ne.com static-eu.oct8ne.com *.yotpo.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net * https://images.unsplash.com maps.googleapis.com maps.gstatic.com *.googleapis.com *.certcapture.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ blob: www.xtento.com cdn.xtento.com https://maps.gstatic.com https://purecatamphetamine.github.io https://cdnjs.cloudflare.com https://www.mollie.com *.oct8ne.com static-eu.oct8ne.com oct8necdneu.azureedge.net *.yotpo.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com beacon-qa.magento-datasolutions.com beacon-stage.magento-ds.com beacon.magento-ds.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net amcglobal.sc.omtrdc.net *.adobe.io use.typekit.net *.commerce-payment-services.com *.magento-ds.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.magento-datasolutions.com *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com *.cash.app *.visa.com *.mastercard.com applepay.cdn-apple.com https://maps.googleapis.com https://player.vimeo.com https://rum.hlx.page maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.certcapture.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ www.xtento.com cdn.xtento.com js.mollie.com *.oct8ne.com static-eu.oct8ne.com *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com *.cash.app *.certcapture.com https://static.klaviyo.com *.fontawesome.com *.yotpo.com *.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com https://www.youtube.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.snplow.net commerce.adobedc.net p13n-mr.adobe.io *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net *.sentry.io www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.adobedc.net *.demdex.net *.magento-datasolutions.com *.magento-ds.com * https://maps.googleapis.com https://player.vimeo.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.googleapis.com *.certcapture.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://ipinfo.io/json *.oct8ne.com static-eu.oct8ne.com *.yotpo.com 'self' 'unsafe-inline'; child-src *.certcapture.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://*.gstatic.com *.yotpo.com *.googleapis.com *.fontawesome.com dhv2ziothpgrr.cloudfront.net *.klevu.com *.ksearchnet.com static.lipscore.com *.stape.io fonts.googleapis.com maxcdn.bootstrapcdn.com *.klarnaservices.com *.klarnaevt.com *.klarna.com *.klarnacdn.net *.google.com *.doubleclick.net *.pinterest.com *.tiktok.com *.nr-data.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.adyen.com *.yotpo.com *.facebook.com *.facebook.net *.amazon.co.uk 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.google.com *.braintreegateway.com *.paypal.com google.com *.adyen.com *.yotpo.com *.rvvuptech.com *.clearpay.co.uk *.sandbox.paypal.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.google.it *.google.fr *.googletagmanager.com *.stape.io www.facebook.com platform.twitter.com *.doubleclick.net *.hotjar.com *.facebook.com *.facebook.net *.vimeo.com *.pinterest.com *.newrelic.com *.zdassets.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com *.gstatic.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net validator.swagger.io *.adyen.com https://*.gstatic.com *.yotpo.com *.afterpay.com *.sandbox.paypal.com *.stats.paypal.com dhv2ziothpgrr.cloudfront.net https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com static.lipscore.com blob: img.youtube.com magefan.com cm.magefan.com *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.google.it *.google.fr *.doubleclick.net *.googletagmanager.com *.stape.io www.facebook.com pinterest.com assets.pinterest.com syndication.twitter.com *.facebook.com *.facebook.net *.klarnaservices.com *.klarnaevt.com *.klarna.com *.klarnacdn.net *.pinterest.com *.tiktok.com *.nr-data.net *.bing.com *.newrelic.com *.media-amazon.com *.payments-amazon.com *.amazon.com *.zdassets.com *.clarity.ms yotpo-editor-production.s3.amazonaws.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ *.google.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.cdn-apple.com *.braintreegateway.com *.adyen.com *.yotpo.com *.afterpay.com *.paypal.com *.sandbox.paypal.com dhv2ziothpgrr.cloudfront.net *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com d18eg7dreypte5.cloudfront.net https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com static.lipscore.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.google.it *.google.fr *.gstatic.com *.googletagmanager.com *.doubleclick.net *.stape.io connect.facebook.net twitter.com platform.twitter.com *.googleapis.com *.klarnaservices.com *.klarnaevt.com *.klarna.com *.klarnacdn.net *.pinterest.com *.tiktok.com *.bing.com *.facebook.com *.facebook.net *.visualwebsiteoptimizer.com *.pinimg.com *.matomo.cloud *.adt313.net *.adt356.net *.adt356.com *.payments-amazon.com *.amazon.com *.zdassets.com *.clarity.ms https://js.klevu.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://fonts.googleapis.com/ *.yotpo.com *.googleapis.com *.fontawesome.com dhv2ziothpgrr.cloudfront.net https://static.klaviyo.com *.klevu.com *.ksearchnet.com static.lipscore.com *.googletagmanager.com *.stape.io maxcdn.bootstrapcdn.com *.klarnaservices.com *.klarnaevt.com *.klarna.com *.klarnacdn.net *.google.com *.doubleclick.net *.pinterest.com *.tiktok.com *.nr-data.net *.bing.com https://statsjs.klevu.com https://js.klevu.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.adyen.com *.yotpo.com *.sandbox.paypal.com dhv2ziothpgrr.cloudfront.net *.smsbump.com 7kgd3hs1oh.execute-api.us-east-1.amazonaws.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com wapi.lipscore.com users.lipscore.com *.doubleclick.net *.googlesyndication.com https://www.merchant-center-analytics.goog *.stape.io *.google.co.uk *.klarnaservices.com *.klarnaevt.com *.klarna.com *.klarnacdn.net *.pinterest.com *.tiktok.com *.facebook.com *.facebook.net bat.bing.com *.bing.com *.postcodeanywhere.co.uk *.payments-amazon.com *.amazon.com *.zdassets.com *.clarity.ms *.merchant-center-analytics.goog 'self' 'unsafe-inline'; child-src *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://592944fc-ced2-48d3-a0ef-ebc9d01e03fd.sansec.watch/; report-to report-endpoint; 1 font-src https://cdnjs.cloudflare.com https://static.payzen.eu/static/ https://fonts.gstatic.com *.fontawesome.com *.typekit.net https://static.lyra.com/static/ maxcdn.bootstrapcdn.com fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net pilot-payflowlink.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de https://secure.payzen.eu/vads-payment/ https://api.payzen.eu/api-payment/ https://static.payzen.eu/static/ *.facebook.com https://secure.lyra.com/vads-payment/ https://api.lyra.com/api-payment/ https://static.lyra.com/static/ 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.google.com js.stripe.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de https://secure.payzen.eu/vads-payment/ https://static.payzen.eu/static/ *.avis-verifies.com *.botnation.ai *.doubleclick.net *.facebook.com *.googletagmanager.com *.hotjar.com *.zenaps.com https://secure.lyra.com/vads-payment/ https://static.lyra.com/static/ *.myspectro.io *.kxcdn.com *.weltpixel.com js.mollie.com www.xtento.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com https://images.unsplash.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de axeptio.imgix.net https://secure.payzen.eu/static/latest/images/type-carte/ https://static.payzen.eu/static/ https://secure.payzen.eu/vads-payment/ https://www.google.fr https://api.mapbox.com *.tile.openstreetmap.org *.avis-verifies.com *.awin1.com *.bing.com *.clarity.ms *.facebook.com *.google.com *.analytics.google.com *.lacompagniedesanimaux.com *.netreviews.eu *.twgdns.com *.zenaps.com *.youtube.com *.vumbnail.com https://secure.lyra.com/static/latest/images/type-carte/ https://static.lyra.com/static/ https://secure.lyra.com/vads-payment/ https://www.mollie.com https://maps.googleapis.com https://maps.gstatic.com *.gstatic.com *.reddit.com *.google-analytics.com *.googletagmanager.com *.doubleclick.net www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://maps.googleapis.com https://cdn.jsdelivr.net/npm/@ryangjchandler/spruce@2.x.x/dist/spruce.umd.js www.google.com/recaptcha/ www.gstatic.com/recaptcha/ js.stripe.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.axept.io https://cdnjs.cloudflare.com https://api.payzen.eu/api-payment/ https://static.payzen.eu/static/ *.plugins.emarsys.net *.scarabresearch.com widget.freshworks.com m2epro.freshdesk.com *.avis-verifies.com *.bing.com *.botnation.ai *.clarity.ms *.doubleclick.net *.dwin1.com *.facebook.net *.analytics.google.com *.hotjar.com *.iadvize.com *.newrelic.com *.nr-data.net *.remisesetprivileges.fr *.roeyecdn.com *.sciencebehindecommerce.com *.skeepers.io *.twenga.fr *.zdassets.com *.zenaps.com assets.emarsys.net https://api.lyra.com/api-payment/ https://static.lyra.com/static/ *.myspectro.io *.kxcdn.com s.kk-resources.com js.mollie.com *.googletagmanager.com *.googleadservices.com *.google.com *.redditstatic.com *.reddit.com *.tiktok.com unpkg.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src https://fonts.googleapis.com https://cdnjs.cloudflare.com https://static.payzen.eu/static/ widget.freshworks.com m2epro.freshdesk.com *.fontawesome.com *.botnation.ai *.jsdelivr.net *.typekit.net https://static.lyra.com/static/ maxcdn.bootstrapcdn.com *.tagmanager.google.com *.googletagmanager.com fonts.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.google-analytics.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com https://maps.googleapis.com https://player.vimeo.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de api.axept.io client.axept.io https://secure.payzen.eu/vads-payment/ https://api.payzen.eu/api-payment/ *.scarabresearch.com *.eservice.emarsys.net widget.freshworks.com m2epro.freshdesk.com *.fact-finder.de *.fact-finder.com *.fact-finder.co.uk *.fact-finder.fr *.fact-finder.pl *.fact-finder.it *.fact-finder.at *.fact-finder.ch *.fact-finder.cloud https://nominatim.openstreetmap.org *.botnation.ai *.clarity.ms *.doubleclick.net *.google.com *.google-analytics.com *.analytics.google.com *.googleapis.com *.iadvize.com *.nr-data.net *.remisesetprivileges.fr *.sciencebehindecommerce.com *.zdassets.com *.zendesk.com https://secure.lyra.com/vads-payment/ https://api.lyra.com/api-payment/ *.myspectro.io *.kxcdn.com s.kelkoogroup.net *.hotjar.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.run.app 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src https://secure.payzen.eu/vads-payment/ https://api.payzen.eu/api-payment/ https://static.payzen.eu/static/ https://secure.lyra.com/vads-payment/ https://api.lyra.com/api-payment/ https://static.lyra.com/static/ 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com https://fonts.bunny.net *.alothemes.com *.magepow.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.cloudflare.com *.cloudwaysapps.com *.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.paypal.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.facebook.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com data: widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com magefan.com cm.magefan.com *.disqus.com https://firebasestorage.googleapis.com *.alothemes.com *.magepow.com *.cloudflare.com *.cloudwaysapps.com *.amazonaws.com *.googleadservices.com *.facebook.com *.google.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ chimpstatic.com downloads.mailchimp.com *.list-manage.com *.disqus.com *.avada.io *.shopify.com *.alothemes.com *.magepow.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com *.cloudflare.com *.cloudwaysapps.com www.google.com www.gstatic.com *.bootstrapcdn.com *.facebook.net *.googletagmanager.com https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com downloads.mailchimp.com *.fontawesome.com https://fonts.bunny.net *.alothemes.com *.magepow.com *.stripe.network *.stripecdn.com *.amazon.com *.cloudflare.com *.cloudwaysapps.com *.bootstrapcdn.com *.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://get.geojs.io *.avada.io *.alothemes.com *.magepow.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.cloudflare.com *.cloudwaysapps.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.facebook.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 object-src 'none'; base-uri 'self'; script-src 'self' 'nonce-aH22GVP6Nw4GZqH2Y51LKA' 'unsafe-inline' 'unsafe-eval' https://*.msauth.net https://*.msftauth.net https://*.msftauthimages.net https://*.msauthimages.net https://*.msidentity.com https://*.microsoftonline-p.com https://*.microsoftazuread-sso.com https://*.azureedge.net https://*.outlook.com https://*.office.com https://*.office365.com https://*.microsoft.com https://*.bing.com 'report-sample'; report-uri https://csp.microsoft.com/report/ESTS-UX-All 1 object-src 'none';base-uri 'self';script-src 'nonce-0VB0DErcC_ZCLPIqPfcPxw' 'strict-dynamic' 'report-sample' 'unsafe-eval' 'unsafe-inline' https: http:;report-uri https://csp.withgoogle.com/csp/gws/other-hp 1 font-src https://fonts.gstatic.com https://ws.colissimo.fr *.fontawesome.com https://cdnjs.cloudflare.com *.yotpo.com *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de https://plumrocket.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors 'self' 'unsafe-inline'; frame-src fast.amc.demdex.net secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com https://plumrocket.com *.weltpixel.com *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com s.ytimg.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com https://maps.googleapis.com https://maps.gstatic.com https://ws.colissimo.fr https://*.tile.openstreetmap.fr *.gstatic.com *.yotpo.com 'self' 'unsafe-inline'; script-src assets.adobedtm.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com video.google.com vimeo.com www.vimeo.com www.youtube.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com cdn.dnky.co api.comapi.com webchat.dotdigital.com chimpstatic.com downloads.mailchimp.com *.list-manage.com https://maps.googleapis.com https://www.google.com https://www.gstatic.com https://ws.colissimo.fr https://api.mapbox.com *.avada.io https://cdnjs.cloudflare.com *.googletagmanager.com https://www.googletagmanager.com tagmanager.google.com *.yotpo.com https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src getfirebug.com cdn.dnky.co webchat.dotdigital.com downloads.mailchimp.com https://fonts.googleapis.com https://ws.colissimo.fr https://api.mapbox.com *.fontawesome.com https://cdnjs.cloudflare.com tagmanager.google.com *.yotpo.com *.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com api.comapi.com webchat.dotdigital.com https://nominatim.openstreetmap.org https://www.google-analytics.com *.yotpo.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; script-src 'self' 'unsafe-eval' 'unsafe-inline' https://*.posthog.com https://app.intercom.io https://widget.intercom.io https://js.intercomcdn.com https://www.googletagmanager.com https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://cdn.segment.com; style-src 'self' 'unsafe-inline'; img-src 'self' blob: data: https://*.posthog.com https://js.intercomcdn.com https://static.intercomassets.com https://downloads.intercomcdn.com https://downloads.intercomcdn.eu https://downloads.au.intercomcdn.com https://uploads.intercomusercontent.com https://gifs.intercomcdn.com https://video-messages.intercomcdn.com https://messenger-apps.intercom.io https://messenger-apps.eu.intercom.io https://messenger-apps.au.intercom.io https://*.intercom-attachments.com https://static.intercomassets.eu https://static.au.intercomassets.com https://www.google-analytics.com https://www.googletagmanager.com https://*.google.com https://*.doubleclick.net https://www.google.com.tr; font-src 'self' https://js.intercomcdn.com https://fonts.intercomcdn.com; connect-src 'self' https://*.posthog.com https://api-iam.intercom.io https://api-iam.eu.intercom.io https://api-iam.au.intercom.io https://api-ping.intercom.io https://nexus-websocket-a.intercom.io wss://nexus-websocket-a.intercom.io https://nexus-websocket-b.intercom.io wss://nexus-websocket-b.intercom.io https://nexus-europe-websocket.intercom.io wss://nexus-europe-websocket.intercom.io https://nexus-australia-websocket.intercom.io wss://nexus-australia-websocket.intercom.io https://uploads.intercomcdn.com https://uploads.intercomcdn.eu https://uploads.au.intercomcdn.com https://uploads.eu.intercomcdn.com https://uploads.intercomusercontent.com https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://cdn.segment.com https://api.segment.io https://vitals.vercel-insights.com https://*.doubleclick.net https://analytics.google.com https://stats.g.doubleclick.net; object-src 'none'; base-uri 'self'; form-action 'self' https://intercom.help https://api-iam.intercom.io https://api-iam.eu.intercom.io https://api-iam.au.intercom.io; frame-src https://intercom-sheets.com https://www.intercom-reporting.com https://www.youtube.com https://player.vimeo.com https://fast.wistia.net https://*.doubleclick.net; worker-src 'self' https://intercom-sheets.com https://www.intercom-reporting.com https://www.youtube.com https://player.vimeo.com https://fast.wistia.net; media-src https://js.intercomcdn.com https://downloads.intercomcdn.com https://downloads.intercomcdn.eu https://downloads.au.intercomcdn.com; frame-ancestors 'none'; manifest-src 'self' https://upstash.com; 1 font-src fonts.gstatic.com use.typekit.net fonts.googleapis.com *.googleapis.com *.gstatic.com data: *.cloudflare.com *.twitter.com *.typekit.net *.twimg.com *.trustedshops.com *.chaordicsystems.com *.useinsider.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.twitter.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com https://accounts.google.com https://www.facebook.com https://login.live.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.google.com *.twitter.com *.criteo.com *.criteo.net *.chaordicsystems.com *.googletagmanager.com *.doubleclick.net *.prospin.com.br *.facebook.com *.useinsider.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io https://images.unsplash.com maps.googleapis.com maps.gstatic.com *.gstatic.com *.googleapis.com *.cloudflare.com *.klarna.com *.googleadservices.com *.google-analytics.com *.paypal.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.google.com.br *.prospin.com.br *.criteo.com *.freshchat.com *.bat.com *.bing.com *.linximpulse.net *.linximpulse.com *.chaordicsystems.com *.doubleclick.net *.smartadserver.com *.taboola.com *.tremorhub.com *.bidswitch.net *.media.net *.adnxs.com *.casalemedia.com *.stickyadstv.com *.360yield.com *.liadm.com *.mediavine.com *.postrelease.com *.outbrain.com *.pubmatic.com *.revcontent.com *.rubiconproject.com *.clmbtech.com *.3lift.com *.adgrx.com *.agkn.com *.unrulymedia.com *.teads.tv *.1rx.io *.wikimedia.org *.clarity.ms *.hotjar.com *.useinsider.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.facebook.com *.reddit.com *.ads-twitter.com t.co *.bing.net *.klaviyo.com *.googletagmanager.com *.google.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net https://maps.googleapis.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.cloudflare.com *.twitter.com *.google-analytics.com *.twimg.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.jsdelivr.net *.addtoany.com *.fw-cdn.com *.google.com *.google.com.br 'self' data: 'self' *.linximpulse.net *.prospin.com.br *.bing.com *.clarity.com *.clarity.ms *.criteo.com *.chaordicsystems.com *.doubleclick.net *.hotjar.com *.useinsider.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.googletagmanager.com *.googleadservices.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.klaviyo.com unpkg.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.cloudflare.com *.googleapis.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.useinsider.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.tagmanager.google.com *.googletagmanager.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io https://maps.googleapis.com https://player.vimeo.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.googleapis.com *.google.com *.cloudflare.com *.twitter.com *.paypal.com *.twimg.com *.chaordicsystems.com *.linximpulse.net *.linximpulse.com *.prospin.com.br *.clarity.ms *.criteo.com *.hotjar.com *.hotjar.io *.useinsider.com *.merchant-center-analytics.goog https://ipinfo.io/json *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.google-analytics.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.bing.com *.bing.net *.klaviyo.com *.doubleclick.net *.run.app 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri *.chaordicsystems.com 'self' 'unsafe-inline'; 1 object-src 'none'; script-src 'self' 'unsafe-inline' 'unsafe-eval' adform.net *.adform.net betano.bg *.betano.bg betano.com *.betano.com betgenius.com *.betgenius.com cloudflare.com *.cloudflare.com cookielaw.org *.cookielaw.org facebook.net *.facebook.net fullstory.com *.fullstory.com gmlinteractive.com *.gmlinteractive.com creativecdn.com *.creativecdn.com googletagmanager.com *.googletagmanager.com kaizengaming.com *.kaizengaming.com kameleoon.eu *.kameleoon.eu optimove.net *.optimove.net sportradar.com *.sportradar.com stoiximan.com.cy *.stoiximan.com.cy cloudflareinsights.com *.cloudflareinsights.com app.delivery *.app.delivery lgrckt-in.com *.lgrckt-in.com tostarsbuilding.com *.tostarsbuilding.com; report-uri https://csp-reporting.cloudflare.com/cdn-cgi/script_monitor/report?m=w49Gyg7OAV9ND_Tpow9O_XEHIIJajkmpCCxaml1bjrE-1770426234-1.0.1.1-VKs3fRRM6WpOsUHk43Z0cdqXUuUb.fqu8LtQlNWwzLMmUBBDohcLc.EqvQCdepRYL13bl_yCsirWYrhQw8Jt3oYsNSZijFl4AWtsd.TPDVtW47YG62ilmfmF1.VHGWFIUWWOsZp7kzvaiedY0Vobonv7CSIRyXxsekLDx8RWHY_UlbMYfHwVXORgdGP8V1f57TCmLi2zgEONbpGu50QIYw; report-to cf-onncambtunonkwkh 1 style-src 'self' 'unsafe-inline' *.helsana.ch fonts.googleapis.com translate.googleapis.com;style-src-elem 'self' 'unsafe-inline' *.helsana.ch fonts.googleapis.com translate.googleapis.com userlike-cdn-widgets.s3-eu-west-1.amazonaws.com d3dc1lgancj6l0.cloudfront.net interaktiv.contilla.de use.fontawesome.com;img-src 'self' data: *.helsana.ch *.pinterest.com s0.2mdn.net bat.bing.com www.facebook.com connect.facebook.net cm.everesttech.net dpm.demdex.net apple-resources.s3.amazonaws.com *.applemediaservices.com *.googlesyndication.com *.gstatic.com maps.googleapis.com www.googleadservices.com www.googletagmanager.com www.google-analytics.com *.doubleclick.net t.co *.linkedin.com *.google.com *.google.ch *.google.de *.google.fr *.google.li *.google.it *.google.ad *.google.ae *.google.al *.google.at *.google.ba *.google.be *.google.bf *.google.bg *.google.bj *.google.ca *.google.cd *.google.cg *.google.ci *.google.cl *.google.cm *.google.cn *.google.cz *.google.dk *.google.dz *.google.ee *.google.es *.google.fi *.google.ga *.google.gr *.google.ht *.google.hr *.google.hu *.google.ie *.google.iq *.google.jo *.google.lk *.google.lt *.google.lu *.google.lv *.google.me *.google.mg *.google.ml *.google.mu *.google.nl *.google.no *.google.pl *.google.pt *.google.ro *.google.rs *.google.ru *.google.rw *.google.sc *.google.se *.google.si *.google.sk *.google.sn *.google.tg *.google.tn *.google.tt *.google.vg *.google.co.ao *.google.co.cr *.google.co.id *.google.co.il *.google.co.in *.google.co.jp *.google.co.ke *.google.co.kr *.google.co.ma *.google.co.th *.google.co.uk *.google.co.za *.google.com.af *.google.com.ar *.google.com.au *.google.com.bh *.google.com.bo *.google.com.br *.google.com.co *.google.com.cy *.google.com.ec *.google.com.eg *.google.com.gh *.google.com.hk *.google.com.kh *.google.com.lb *.google.com.mt *.google.com.mx *.google.com.my *.google.com.na *.google.com.ni *.google.com.pe *.google.com.pk *.google.com.py *.google.com.sa *.google.com.sg *.google.com.tr *.google.com.tw *.google.com.ua *.google.com.vn userlike-cdn-operators.s3-eu-west-1.amazonaws.com d3upe020n1uosc.cloudfront.net www.userlike.com userlike-store-media-files.s3.amazonaws.com i.ytimg.com interaktiv.contilla.de;font-src 'self' data: *.gstatic.com d3dc1lgancj6l0.cloudfront.net use.fontawesome.com *.helsana.ch;media-src 'self' data: blob: *.helsana.ch d3dc1lgancj6l0.cloudfront.net userlike-store-media-files.s3.amazonaws.com www.userlike.com;object-src 'none';worker-src 'self';script-src 'self' 'unsafe-inline' 'unsafe-eval' blob: *.helsana.ch cdn.cookielaw.org static.ads-twitter.com analytics.twitter.com *.pinterest.com s.pinimg.com *.gstatic.com api.microsofttranslator.com bat.bing.com www.google.ch www.google.com www.google.de www.google.fr *.googlesyndication.com *.doubleclick.net www.googletagservices.com consentcdn.cookiebot.com analytics.twitter.com snap.licdn.com www.googleadservices.com www.google-analytics.com connect.facebook.net consent.cookiebot.com cdn.tt.omtrdc.net maps.googleapis.com www.googletagmanager.com assets.adobedtm.com api.userlike.com userlike-cdn-widgets.s3-eu-west-1.amazonaws.com d3dc1lgancj6l0.cloudfront.net;script-src-elem 'self' 'unsafe-inline' 'unsafe-eval' blob: *.helsana.ch cdn.cookielaw.org static.ads-twitter.com snap.licdn.com analytics.twitter.com *.pinterest.com s.pinimg.com *.gstatic.com api.microsofttranslator.com bat.bing.com www.google.ch www.google.com www.google.de www.google.fr *.googlesyndication.com *.doubleclick.net www.googletagservices.com consentcdn.cookiebot.com www.googleadservices.com www.google-analytics.com connect.facebook.net consent.cookiebot.com cdn.tt.omtrdc.net maps.googleapis.com www.googletagmanager.com cdnjs.cloudflare.com assets.adobedtm.com api.userlike.com userlike-cdn-widgets.s3-eu-west-1.amazonaws.com d3dc1lgancj6l0.cloudfront.net interaktiv.contilla.de analytics.tiktok.com;connect-src 'self' wss://*.helsana.ch *.helsana.ch maps.googleapis.com privacyportal-eu.onetrust.com userlike-cdn-widgets.s3-eu-west-1.amazonaws.com *.cookielaw.org api.sitesearch360.com *.ads-twitter.com *.linkedin.com *.pinterest.com api.openweathermap.org www.facebook.com www.bing.com bat.bing.com *.googlesyndication.com *.google.com *.doubleclick.net www.google-analytics.com tt.omtrdc.net dpm.demdex.net wss://umd.userlike.com umd.userlike.com api.userlike.com d3upe020n1uosc.cloudfront.net www.userlike.com api.friendlycaptcha.com eu-api.friendlycaptcha.eu interaktiv.contilla.de;frame-src 'self' *.helsana.ch *.pinterest.ch *.pinterest.com *.google.com *.googlesyndication.com bid.g.doubleclick.net consentcdn.cookiebot.com www.youtube.com fls.doubleclick.net assets.adobedtm.com www.facebook.com api.userlike.com userlike-cdn-widgets.s3-eu-west-1.amazonaws.com d3dc1lgancj6l0.cloudfront.net www.youtube.com player.vimeo.com *.undpartner.digital;frame-ancestors 'self' *.helsana.ch;report-uri https://helsana.report-uri.com/r/d/csp/wizard;report-to wizard; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com data: 'self' data: *.doubleclick.net *.facebook.com *.fontawesome.com maxcdn.bootstrapcdn.com cdnjs.cloudflare.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com www.google.com *.doubleclick.net *.facebook.com *.iubenda.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * customer-jo4fg3675hw5zuyf.cloudflarestream.com gum.criteo.com fledge.eu.criteo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com p.typekit.net *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.googleapis.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.bird.eu ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com *.feedaty.com cdn.flbx.io *.cloudfront.net *.iubenda.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.hsforms.net *.hsforms.com customer-jo4fg3675hw5zuyf.cloudflarestream.com www.gstatic.com a.omappapi.com matching.ivitrack.com x.bidswitch.net sync-t1.taboola.com sync.outbrain.com zendesk.com sgtm.jeannebaret.com campagnolo1715786198.zendesk.com www.google.it sync.1rx.io ib.adnxs.com rtb.csync.smartserver.com r.casalemedia.com gum.criteo.com id5-sync.com ad.360yield.com contextual.media.net exchange.mediavine.com jadserve.postrelease.com simage2.pubmatic.com pixel.rubiconproject.com match.sharethrough.com criteo-sync.teads.tv criteo-partners.tremorhub.com eb2.3lift.com ad.yieldlab.net sync-criteo.ads.yieldmo.com e1.emxdgt.com *.dmxleo.com *.smartadserver.com *.omnitagjs.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com amcglobal.sc.omtrdc.net *.adobe.io use.typekit.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.magento-ds.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.magento-datasolutions.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com chimpstatic.com downloads.mailchimp.com *.list-manage.com *.feedaty.com *.getflowbox.com *.iubenda.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com songbird.cardinalcommerce.com *.hsforms.net *.hsforms.com static.zdassets.com cdn.clerk.io customer-jo4fg3675hw5zuyf.cloudflarestream.com cdn.iubenda.com api.clerk.io cs.iubenda.com js-agent.newrelic.com embed.cloudflarestream.com www.google.com www.gstatic.com dynamic.criteo.com a.omappapi.com static.hotjar.com sslwidget.criteo.com script.hotjar.com ecomm.sella.it sandbox.gestpay.net pod-29.zendesk.com sgtm.jeannebaret.com sgtm.cmpsport.com mn.cmpsport.com mn.melby.it connect.facebook.net https://static.zdassets.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com downloads.mailchimp.com *.feedaty.com *.fontawesome.com maxcdn.bootstrapcdn.com assets.braintreegateway.com www.gstatic.com a.omappapi.com cdnjs.cloudflare.com *.typekit.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.magento.com *.adobe.io performance.typekit.net commerce.adobe.io *.sentry.io *.paypal.com google.com *.google.com *.magento-datasolutions.com *.magento-ds.com *.googleapis.com *.google-analytics.com *.facebook.com *.facebook.net *.feedaty.com *.getflowbox.com *.iubenda.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com t.elasticsuite.io *.hsforms.net *.hsforms.com region1.google-analytics.com ekr.zdassets.com customer-jo4fg3675hw5zuyf.cloudflarestream.com api.openweathermap.org cmp.zendesk.com bam.nr-data.net idb.iubenda.com region1.analytics.google.com api.omappapi.com gum.criteo.com measurement-api.criteo.com wss://pod-29.zendesk.com sgtm.jeannebaret.com campagnolo1715786198.zendesk.com www.google.it connect.facebook.net *.doubleclick.net mn.cmpsport.com mn.melby.it 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com *.nr-data.net *.criteo.net *.cloudflarestream.com *.cloudflare.com *.clerk.io *.cmpsport.com *.melby.it *.zdassets.com *.chimpstatic.com *.iubenda.com *.zendesk.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src * data: blob:; script-src 'self' 'unsafe-inline' 'unsafe-eval';worker-src 'self' blob:; style-src * data: blob: 'unsafe-inline'; 1 script-src 'nonce-9dDAytO2wiAoYoWbQZlYQQ' 'report-sample' 'strict-dynamic' 'unsafe-eval' 'unsafe-inline' http: https:; object-src 'none'; report-uri https://csp.withgoogle.com/csp/static-on-bigtable; base-uri 'none' 1 default-src 'none'; connect-src 'self' https://www.google-analytics.com https://stats.g.doubleclick.net https://region1.google-analytics.com https://dgap.org https://createsend.com https://api.friendlycaptcha.com https://internationalepolitik.de https://static.elfsight.com https://core.service.elfsight.com https://universe-static.elfsightcdn.com https://matomo.dgap.org/; font-src 'self' data: dgap.org https://player.podigee-cdn.net https://fonts.gstatic.com; frame-src 'self' https://dgap.org https://www.internationalepolitik.de https://www.ip-quarterly.com https://www.youtube-nocookie.com/embed/ https://e.issuu.com https://www.google.com https://player.podigee-cdn.net https://av.dgap.org https://av.internationalepolitik.de https://av.ip-quarterly.com https://matomo.dgap.org https://www.openstreetmap.org https://cloud.dgap.org https://audio.podigee-cdn.net https://sign.dgap.dev https://www.helpmundo.de https://www.helpdirect.org https://tube.dgap.org; img-src 'self' https://www.gstatic.com https://*.met.vgwort.de https://www.googletagmanager.com https://www.google-analytics.com data: dgap.org https://matomo.dgap.org https://images.podigee-cdn.net https://region1.google-analytics.com; manifest-src 'self'; media-src 'self' https://audio.podigee-cdn.net; prefetch-src 'self'; script-src 'self' 'report-sample' 'unsafe-inline' 'unsafe-eval' 'wasm-unsafe-eval' https://dgap.org https://matomo.dgap.org https://www.google-analytics.com https://www.googletagmanager.com https://internationalepolitik.de https://ip-quarterly.com https://js.createsend1.com https://player.podigee-cdn.net https://audio.podigee-cdn.net https://www.helpmundo.de https://www.helpdirect.org cdnjs.cloudflare.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://www.google.com unpkg.com https://matomo.dgap.org/; script-src-attr 'self' 'report-sample'; script-src-elem 'self' 'report-sample' 'unsafe-inline' https://dgap.org https://www.googletagmanager.com https://www.google-analytics.com https://matomo.dgap.org https://js.createsend1.com https://player.podigee-cdn.net https://audio.podigee-cdn.net https://www.helpmundo.de https://www.helpdirect.org https://static.elfsight.com https://core.service.elfsight.com https://universe-static.elfsightcdn.com cdnjs.cloudflare.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://www.google.com unpkg.com; style-src 'self' 'report-sample' 'unsafe-inline' https://js.createsend1.com https://www.gstatic.com https://dgap.org https://player.podigee-cdn.net https://audio.podigee-cdn.net cdnjs.cloudflare.com https://cdnjs.cloudflare.com unpkg.com; style-src-attr 'self' 'report-sample' 'unsafe-inline'; style-src-elem 'self' 'report-sample' 'unsafe-inline' https://www.google.com https://dgap.org https://player.podigee-cdn.net https://audio.podigee-cdn.net cdnjs.cloudflare.com https://cdnjs.cloudflare.com unpkg.com; worker-src 'self' blob:; form-action 'self' https://www.createsend.com https://dgap.org; frame-ancestors 'self' https://dgap.org https://www.internationalepolitik.de https://www.ip-quarterly.com https://av.dgap.org https://av.internationalepolitik.de https://av.ip-quarterly.com https://sign.dgap.dev; report-uri https://dgap.org/en/system/reporting/default; report-to default 1 object-src 'none'; base-uri 'self'; script-src 'self' 'nonce-x1yTbWMg2qJ0__WK7sY7sA' 'unsafe-inline' 'unsafe-eval' https://*.msauth.net https://*.msftauth.net https://*.msftauthimages.net https://*.msauthimages.net https://*.msidentity.com https://*.microsoftonline-p.com https://*.microsoftazuread-sso.com https://*.azureedge.net https://*.outlook.com https://*.office.com https://*.office365.com https://*.microsoft.com https://*.bing.com 'report-sample'; report-uri https://csp.microsoft.com/report/ESTS-UX-All 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com *.fontawesome.com https://fonts.bunny.net *.musette.ro data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com *.googlesyndication.com *.tiktok.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.doubleclick.net *.facebook.com/ *.googlesyndication.com *.tiktok.com *.innoship.ro landofcoder.com https://www.google.com/ 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.googleapis.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.googlesyndication.com *.roeye.com *.tiktok.com *.tile.openstreetmap.org *.openstreetmap.org https://firebasestorage.googleapis.com *.musette.ro *.google.com/ads/ *.google.ro *.google.ro/ads/ *.trusted.ro/ trusted.ro/ *.profitshare.ro *.omtrdc.net musette.ro maps.googleapis.com maps.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googleapis.com *.gstatic.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.googlesyndication.com *.jsdelivr.net *.tiktok.com landofcoder.com www.termsfeed.com *.avada.io *.cloudflare.com *.twitter.com *.twimg.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.jivosite.com *.profitshare.ro profitshare.ro *.7w.ro *.aptrinsic.com *.musette.ro maps.googleapis.com chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.aptrinsic.com fonts.googleapis.com assets.braintreegateway.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com *.tiktok.com *.fontawesome.com https://fonts.bunny.net *.jivosite.com *.musette.ro *.salofarm.ro *.stormers.ro 'self' 'unsafe-inline'; object-src landofcoder.com 'self' 'unsafe-inline'; media-src *.adobe.com *.jivosite.com *.musette.ro 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.googleapis.com *.google-analytics.com *.facebook.com *.facebook.net *.doubleclick.net *.googlesyndication.com *.tiktok.com landofcoder.com https://get.geojs.io *.avada.io https://stats.g.doubleclick.net/ *.jivosite.com *.7w.ro *.aptrinsic.com maps.googleapis.com socialplugin.facebook.net region1.analytics.google.com wss://chat-eu1-4.jivosite.com *.musette.ro 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 report-uri https://events.mercadolibre.com/csp/reports?identifier=Ef90k_IcsHMKGYWJ5_MnLawZE97vBtOTiz6rs5v5T2lBZMnp-42wOZR4zQew62LsYHA=&policy_id=71&user_id=&request_id=c0268841-f498-4332-bbb4-bb3803174c90; report-to csp-endpoint-efkicshmkgywjmnlawzevbtotizrsvtlbzmnpwozrzqewlsyha; frame-ancestors 'none' 1 report-uri /core/api/Monitoring/SaveCSPReport 1 worker-src blob:; font-src *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com fonts.gstatic.com *.kxcdn.com https://fonts.cdnfonts.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com *.googlesyndication.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net https://www.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ https://secure.asxgw.com *.google.com/ *.doubleclick.net *.facebook.com *.googlesyndication.com facebook.com www.facebook.com *.kxcdn.com youtube.com www.youtube.com platform.twitter.com *.google.com *.addthis.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.gstatic.com *.googlesyndication.com *.roeye.com *.cdninstagram.com *.kxcdn.com *.twitter.com *.googleapis.com *.fbcdn.net blob: ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com https://verify.etrustmark.rs https://rs.beosport.com maps.gstatic.com *.ggpht https://www.magezon.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://asxgw.com https://asxgw.paymentsandbox.cloud https://secure.asxgw.com *.google.com/ *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com *.googleapis.com *.google.com cdn.ampproject.org connect.facebook.net googletagmanager.com *.kxcdn.com platform.twitter.com *.addthis.com *.addthisedge.com *.moatads.com chimpstatic.com downloads.mailchimp.com *.list-manage.com https://s-eu-1.pushpushgo.com form.beosport.rs/static_files/js/form.widget.js https://maps.googleapis.com https://cdnjs.cloudflare.com *.avada.io s7.addthis.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-eval' 'sha256-W5akSSK6LD5BjIlNICMcXaUObQSRAaj6bs7JHADURBA=' 'sha256-3qVqeAdyxxTdPkkRzqapjGkAUYLahxSrB7Mdup+GPQ0=' 'sha256-2rvfFrggTCtyF5WOiTri1gDS8Boibj4Njn0e+VCBmDI=' 'sha256-p8MCfMHqrovsjRYU9z0bU17dd0z81k/fVbGrtBBiM9g=' 'sha256-0pk2s4oXwBELlC6IBVb3nNaM2PjfjwI2N6OGIX5lx8Y=' 'sha256-nkEZknO0IxNxY/CkTMBhjNhwPvglpYumjx31B4fjkY8=' 'sha256-OIkmMoDWrMET+9yYXfy4kYiZBSGdTuH3/LGJwXz4dbQ=' 'sha256-sA4VQiCGZ0SoC9lRUhrksOsX2gyXQEuHg4kSBIW0NEE=' 'sha256-c0lCqfyjzjX/z/E3XbnFt91p2H29aTfAgw8EjWp/fZI=' 'sha256-vEvkWASy62ASaFxwu/PJbHplao3U4RHMscHIG0WJ/Bk=' 'sha256-kcLwbkMxoYXD1+pfTCjKcZiKwrSg1OvWbfrbGCEKCJk=' 'sha256-jFhMjIj2mk11gJ73zMfIxd2bY7KD+ytCtZ/D9ManRc8=' 'sha256-6ixR+oMcnzgWfqUMhTzL7wXbLD5XOuFMHNcTSt5qov0=' 'sha256-LDIYwFJ02I7TUBglvosPtK0tPqIZkCRZMbWutdyCCAQ=' 'sha256-nf8KOhKoAdxPSwpv2RidJS8ZZzJhFY7WlN7FC+qdWc8=' 'sha256-3WKFMY9tUFN5N13PAP/JYO8r7IKSLJh0/tgh/V9MkRQ=' 'sha256-T3EuRb1GGbNmQ0vw9RUrW9VEstcYOrsXAoxvhYdOvIk=' 'sha256-coL0pEv1rb+grF9AzX+5ontRniER4BFzra+DqTYSAis=' 'sha256-5C79GT8eq2lLXsap6ckT7RIW2BBB6xceZxo8HZDjwyE=' 'sha256-Kj8xM4xKFKZOhkroQhn0wDm7HLvSMJ5jjXf4wDD9kLQ=' 'sha256-kDNtJT2efDxEQCDHPhzf12/6ZKrOJgpR7ze4tIpOkzg=' 'sha256-Y0D3AiTZ5scvOayGpk638SU9EGZdZCxmdS81i5h7sR0=' 'sha256-bpKe9LdxDRMgKSQ0H1JxXAYFf/zUg/V89o4nC7fFLIM='; style-src *.adobe.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com *.google.com *.kxcdn.com downloads.mailchimp.com https://fonts.cdnfonts.com *.fontawesome.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://asxgw.com https://asxgw.paymentsandbox.cloud https://www.google-analytics.com *.facebook.com *.facebook.net *.google.com *.doubleclick.net *.googlesyndication.com https://www.paypal.com/xoplatform/logger/api/logger cdn.ampproject.org *.kxcdn.com *.instagram.com https://get.geojs.io *.avada.io ekr.zdassets.com/ *.google-analytics.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com google.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.googleapis.com fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.facebook.com *.facebook.com *.facebook.net *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com www.xtento.com ws.sharethis.com c.sharethis.mgr.consensu.org www.facebook.com t.sharethis.com *.weltpixel.com *.facebook.com *.facebook.net www.paypal.com www.sandbox.paypal.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * landofcoder.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net *.vimeocdn.com i.ytimg.com *.youtube.com gateway.apaylater.com gateway.atome.sg www.xtento.com cdn.xtento.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.facebook.com *.facebook.net www.paypal.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com ve01-lnx003-psr-cms.wt-id.dev stage-api-psr.wt-id.dev *.gstatic.com *.cdninstagram.com *.fbcdn.net maps.googleapis.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ gateway.apaylater.com gateway.atome.sg www.xtento.com cdn.xtento.com connect.facebook.net googletagmanager.com ws.sharethis.com maps.googleapis.com foursixty.com jscdn.appier.net click.accesstra.de goofleads.g.doubleclick.net t.sharethis.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.zdassets.com s7.addthis.com *.facebook.com *.facebook.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com ajax.googleapis.com landofcoder.com https://www.googletagmanager.com tagmanager.google.com *.instagram.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com gateway.apaylater.com gateway.atome.sg fonts.googleapis.com cdn.curator.io ws.sharethis.com https://static.klaviyo.com unsafe-inline assets.braintreegateway.com tagmanager.google.com 'self' 'unsafe-inline'; object-src landofcoder.com 'self' 'unsafe-inline'; media-src *.adobe.com *.cdninstagram.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com anylist.c.appier.net l.sharethis.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.googleapis.com *.zendesk.com ekr.zdassets.com/ *.facebook.com *.facebook.net www.paypal.com www.sandbox.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com ve01-lnx003-psr-cms.wt-id.dev stage-api-psr.wt-id.dev landofcoder.com https://www.google-analytics.com *.instagram.com *.googleusercontent.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src https://*.amazon.com https://*.media-amazon.com https://*.ssl-images-amazon.com https://*.amazon-adsystem.com https://*.paa-reporting-advertising.amazon https://*.twitch.tv https://*.newworld.com https://*.awsstatic.com https://amazonwebservices.d2.sc.omtrdc.net https://amazongamestudios.d2.sc.omtrdc.net https://*.viddler.com https://*.ctfassets.net https://sentry.amazongames.com https://dqzvgunkova5o.cloudfront.net; script-src 'nonce-bccb9724091049cd875d9423877e29aa' https://*.amazon.com https://*.media-amazon.com https://*.ssl-images-amazon.com https://*.amazon-adsystem.com https://*.paa-reporting-advertising.amazon https://*.twitch.tv https://*.newworld.com https://*.awsstatic.com https://amazonwebservices.d2.sc.omtrdc.net https://amazongamestudios.d2.sc.omtrdc.net https://*.viddler.com https://*.ctfassets.net https://sentry.amazongames.com https://dqzvgunkova5o.cloudfront.net; style-src 'self' 'nonce-bccb9724091049cd875d9423877e29aa' https://*.amazon.com https://*.media-amazon.com https://*.ssl-images-amazon.com https://*.amazon-adsystem.com https://*.paa-reporting-advertising.amazon https://*.twitch.tv https://*.newworld.com https://*.awsstatic.com https://amazonwebservices.d2.sc.omtrdc.net https://amazongamestudios.d2.sc.omtrdc.net https://*.viddler.com https://*.ctfassets.net https://sentry.amazongames.com https://dqzvgunkova5o.cloudfront.net; img-src 'self' data: https://*.amazon.com https://*.media-amazon.com https://*.ssl-images-amazon.com https://*.amazon-adsystem.com https://*.paa-reporting-advertising.amazon https://*.twitch.tv https://*.newworld.com https://*.awsstatic.com https://amazonwebservices.d2.sc.omtrdc.net https://amazongamestudios.d2.sc.omtrdc.net https://*.viddler.com https://*.ctfassets.net https://sentry.amazongames.com https://dqzvgunkova5o.cloudfront.net https://*.twimg.com https://player.twitch.tv/ https://*.ytimg.com; media-src 'self' data: https://*.amazon.com https://*.media-amazon.com https://*.ssl-images-amazon.com https://*.amazon-adsystem.com https://*.paa-reporting-advertising.amazon https://*.twitch.tv https://*.newworld.com https://*.awsstatic.com https://amazonwebservices.d2.sc.omtrdc.net https://amazongamestudios.d2.sc.omtrdc.net https://*.viddler.com https://*.ctfassets.net https://sentry.amazongames.com https://dqzvgunkova5o.cloudfront.net https://*.twimg.com https://player.twitch.tv/ https://www.youtube.com https://youtube.com https://*.googlevideo.com; frame-src https://www.youtube.com https://youtube.com https://*.googlevideo.com https://*.twimg.com https://player.twitch.tv/ https://*.amazon.com https://*.media-amazon.com https://*.ssl-images-amazon.com https://*.amazon-adsystem.com https://*.paa-reporting-advertising.amazon https://*.twitch.tv https://*.newworld.com https://*.awsstatic.com https://amazonwebservices.d2.sc.omtrdc.net https://amazongamestudios.d2.sc.omtrdc.net https://*.viddler.com https://*.ctfassets.net https://sentry.amazongames.com https://dqzvgunkova5o.cloudfront.net; report-uri https://www.amazon.com/1/batch/2/OE/mid=ATVPDKIKX0DER:sid=144-0837792-0424049:rid=E55D59948BC24600A1A1:sn=www.newworld.com 1 default-src 'none'; base-uri 'self'; frame-ancestors 'self'; object-src 'none'; upgrade-insecure-requests; block-all-mixed-content; script-src 'self' 'unsafe-inline' https://*.seniorly.com https://www.googletagmanager.com https://www.google-analytics.com https://region1.google-analytics.com https://*.googleapis.com https://cdn.segment.com https://cdn.builder.io https://cdn.accessibly.app https://connect.facebook.net; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; img-src 'self' data: blob: https://*.seniorly.com https://*.facebook.com https://*.linkedin.com https://*.gstatic.com https://*.googleapis.com https://www.google-analytics.com https://*.doubleclick.net https://i.ytimg.com https://d1qiigpe5txw4q.cloudfront.net https://cdn.builder.io; font-src 'self' data: https://*.seniorly.com https://fonts.gstatic.com; connect-src 'self' https://*.seniorly.com https://api.segment.io https://cdn-settings.segment.com https://www.google-analytics.com https://region1.google-analytics.com https://*.doubleclick.net https://*.googleapis.com https://dash.accessibly.app https://alt-tags.accessibly.app; frame-src 'self' https://www.youtube.com https://player.vimeo.com my.matterport.com https://dash.accessibly.app; media-src 'self' https://*.seniorly.com; form-action 'self' https://*.seniorly.com; worker-src 'self' blob:; manifest-src 'self'; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://fonts.gstatic.com https://ws.colissimo.fr payment.payline.com payment-2.payline.com homologation-payment.payline.com homologation-payment-2.payline.com payment.cdn.payline.com homologation-payment.cdn.payline.com maxcdn.bootstrapcdn.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net https://www.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com https://form.typeform.com https://www.googletagmanager.com/ payment.payline.com payment-2.payline.com homologation-payment.payline.com homologation-payment-2.payline.com payment.cdn.payline.com homologation-payment.cdn.payline.com *.google.com/ 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io *.paypal.com *.typekit.net *.gstatic.com cdn.doofinder.com https://maps.googleapis.com https://maps.gstatic.com https://ws.colissimo.fr https://*.tile.openstreetmap.fr https://*.onyourmap.com https://google.fr http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ magefan.com cm.magefan.com https://www.magezon.com payment.payline.com payment-2.payline.com homologation-payment.payline.com homologation-payment-2.payline.com payment.cdn.payline.com homologation-payment.cdn.payline.com *.disqus.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ cdn.doofinder.com https://maps.googleapis.com https://www.google.com https://www.gstatic.com https://ws.colissimo.fr https://api.mapbox.com https://*.typeform.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ payment.payline.com payment-2.payline.com homologation-payment.payline.com homologation-payment-2.payline.com payment.cdn.payline.com homologation-payment.cdn.payline.com *.google.com/ *.disqus.com https://widgets.rr.skeepers.io/ https://api-product-reviews.cxr.skeepers.io/ https://cl-ppr.rr.skeepers.io/ https://cl-pbr.cxr.skeepers.io/ 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.doofinder.com https://fonts.googleapis.com https://ws.colissimo.fr https://api.mapbox.com https://*.typeform.com payment.payline.com payment-2.payline.com homologation-payment.payline.com homologation-payment-2.payline.com payment.cdn.payline.com homologation-payment.cdn.payline.com *.fontawesome.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.doofinder.com wss://*.doofinder.com https://ws.colissimo.fr https://maps.googleapis.com https://nominatim.openstreetmap.org https://*.onyourmap.com https://*.mapbox.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ payment.payline.com payment-2.payline.com homologation-payment.payline.com homologation-payment-2.payline.com payment.cdn.payline.com homologation-payment.cdn.payline.com https://widgets.rr.skeepers.io/ https://api-product-reviews.cxr.skeepers.io/ https://cl-ppr.rr.skeepers.io/ https://cl-pbr.cxr.skeepers.io/ 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 form-action 'self' www.paypal.com securepayments.paypal.com www.facebook.com www.cbz.at www.fontis-shop.ch; report-uri https://www.scm-shop.de/csp-report; report-to csp-endpoint 1 script-src 'strict-dynamic' 'nonce-bb358b0340b227e236d40ce9446fd502' 'unsafe-inline' 'unsafe-eval' https: ; frame-ancestors 'self' ; base-uri 'self'; object-src 'none'; report-uri https://csp.phenompeople.com/violations; 1 font-src fonts.gstatic.com use.typekit.net www.paypalobjects.com *.typekit.net *.gstatic.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.demdex.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com https://www.googletagmanager.com/ 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net api.mundipagg.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ magefan.com cm.magefan.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net assets.adobedtm.com *.adobe.io *.commerce-payment-services.com *.magento-ds.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.magento-datasolutions.com https://rum.hlx.page api.mundipagg.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.magento-datasolutions.com *.magento-ds.com *.fontawesome.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.magento-datasolutions.com *.magento-ds.com api.mundipagg.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 frame-ancestors 'self'; report-uri https://www.geelongadvertiser.com.au/csp-reports 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com static.harveynorman.si static.mage.harvey.optiweb.serv.si media.flixfacts.com media.flixcar.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com https://lapp.leanpay.hr https://app.leanpay.hr https://stage-app.leanpay.si https://app.leanpay.si https://stage-app.leanpay.ro https://vendor.leanpay.ro https://stage-checkout.leanpay.si *.facebook.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.weltpixel.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io *.paypal.com *.typekit.net *.gstatic.com https://firebasestorage.googleapis.com *.harveynorman.si *.harvey.optiweb.serv.si *.cookiebot.com *.doubleclick.net *.criteo.com *.criteo.net www.google.si *.creativecdn.com blob: *.facebook.com *.reddit.com static.youreko.com *.cloudfront.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com media.flixcar.com media.flixfacts.com rt.flix360.com logo.flix360.io data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.commerce-payment-services.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com s7.addthis.com *.avada.io *.segmentify.com cdn.sgmntfy.com api.squalomail.com *.criteo.com *.criteo.net *.googleapis.com cdnjs.cloudflare.com *.hotjar.com *.cookiebot.com *.harveynorman.si *.livechatinc.com *.creativecdn.com www.gstatic.com static.harveynorman.si static.mage.harvey.optiweb.serv.si https://www.googletagmanager.com tagmanager.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com unpkg.com maps.googleapis.com static.youreko.com api.youreko.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.loadbee.com media.flixcar.com media.flixfacts.com prod.flixgvid.flix360.io 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.segmentify.com cdnjs.cloudflare.com www.googletagmanager.com static.harveynorman.si static.mage.harvey.optiweb.serv.si tagmanager.google.com static.youreko.com assets.braintreegateway.com media.flixcar.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com ekr.zdassets.com/ https://get.geojs.io *.avada.io *.segmentify.com *.criteo.com *.cookiebot.com pagead2.googlesyndication.com *.hotjar.io *.doubleclick.net *.creativecdn.com *.harveynorman.si capig.stape.host static.mage.harvey.optiweb.serv.si *.google-analytics.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.run.app maps.googleapis.com api.youreko.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com media.flixcar.com pk.takoleasy.si *.loadbee.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.cloudflare.com fonts.gstatic.com *.bootstrapcdn.com *.maxcdn.com *.googleapis.com *.gstatic.com data: 'self' 'unsafe-inline'; form-action 'self' 'unsafe-inline'; frame-ancestors www.google.com www.gstatic.com 'self'; frame-src bid.g.doubleclick.net player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ td.doubleclick.net *.facebook.com www.googletagmanager.com www.google.com *.standout.com.br 'self' 'unsafe-inline'; img-src data: widgets.magentocommerce.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com *.analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com *.youtube.com *.cloudflare.com www.google.com.br device.clearsale.com.br *.ebit.com.br *.ebitempresa.com.br newimgebit-a.akamaihd.net *.googleapis.com *.gstatic.com *.google.com *.googleadservices.com *.google-analytics.com *.googletagmanager.com *.openpix.com.br s3.amazonaws.com flagpedia.net data: 'self' 'unsafe-inline'; script-src googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.cloudflare.com *.githubusercontent.com *.addthis.com device.clearsale.com.br *.ebit.com.br *.googleapis.com *.gstatic.com apis.google.com connect.facebook.net *.googletagmanager.com *.googleadservices.com *.google-analytics.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ maps.googleapis.com s3-sa-east-1.amazonaws.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.maxcdn.com *.bootstrapcdn.com *.cloudflare.com *.githubusercontent.com fonts.googleapis.com *.ebit.com.br *.gstatic.com 'self' 'unsafe-inline'; object-src data: 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.googleadservices.com www.google-analytics.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.bootstrapcdn.com www.google.com www.google.com.br googleads.g.doubleclick.net device.clearsale.com.br *.ebit.com.br newimgebit-a.akamaihd.net *.googleapis.com apis.google.com *.google-analytics.com *.googletagmanager.com stats.g.doubleclick.net *.openpix.com.br *.gstatic.com s3.amazonaws.com www.gstatic.com maps.googleapis.com s3-sa-east-1.amazonaws.com *.standout.com.br 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 script-src 'self' 'unsafe-inline' 'unsafe-eval' https://*.hsadspixel.net https://js.hs-banner.com https://*.hs-analytics.net https://js.hscta.net https://*.hubspot.com https://static.hsappstatic.net https://*.usemessages.com https://*.hubspot.net https://*.hscollectedforms.net https://*.hsleadflows.net https://*.hsforms.net https://*.hsforms.com https://*.hs-scripts.com https://*.hubspotfeedback.com https://feedback.hubapi.com https://website-assets.atlan.com https://www.googletagmanager.com https://googletagmanager.com https://tagmanager.google.com https://www.googleoptimize.com https://*.googletagmanager.com https://*.google-analytics.com https://www.googleadservices.com https://www.google.com https://googleads.g.doubleclick.net https://cdn.jsdelivr.net https://ajax.googleapis.com https://unpkg.com https://embedsocial.com https://platform.twitter.com http://*.ads-twitter.com https://cdn.syndication.twimg.com https://static.ads-twitter.com https://*.clarity.ms https://bat.bing.com https://ipgeolocation.abstractapi.com https://platform.linkedin.com https://snap.licdn.com https://*.quora.com https://*.zi-scripts.com https://*.zoominfo.com https://player.vimeo.com https://f.vimeocdn.com https://*.vimeocdn.com https://*.salesloft.com https://*.demandbase.com https://*.company-target.com https://cdn.dreamdata.cloud https://www.redditstatic.com https://cdn.seersco.com https://*.sibforms.com https://*.ashbyhq.com https://plausible.io https://*.plausible.io https://darkvisitors.com https://*.darkvisitors.com https://connect.facebook.net https://*.facebook.com https://www.youtube.com https://s.ytimg.com https://js.blazeverify.com https://js.emailable.com/v1 https://www.gartner.com https://gartner.com *.crazyegg.com https://builder.io https://*.calendly.com https://cdnjs.cloudflare.com https://cloudflare.com https://static.cloudflareinsights.com https://cdn.rollbar.com https://*.rollbar.com https://*.chatbase.co https://*.emailable.com https://cdn-cookieyes.com https://*.cookieyes.com https://*.default.com https://*.lindy.ai https://*.g2.com https://groas.ai https://*.groas.ai https://tofuhq.com https://*.tofuhq.com;object-src 'none';worker-src blob:;report-uri https://o4507661801488384.ingest.sentry.io/api/4507683673866240/security/?sentry_key=b5327dda5a6527e6c04e9aa0de05fe22; report-to csp-endpoint 1 default-src 'self' https:; base-uri 'self'; object-src 'none'; frame-ancestors 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https: https://www.googletagmanager.com https://www.google-analytics.com https://www.gstatic.com https://*.google.com; style-src 'self' 'unsafe-inline' https: data:; img-src 'self' data: https: http://news.agnesscott.org https://www.googletagmanager.com https://www.google-analytics.com https://*.google-analytics.com https://*.analytics.google.com; connect-src 'self' https: https://www.googletagmanager.com https://www.google.com https://*.google-analytics.com https://*.analytics.google.com; font-src 'self' data: https:; frame-src 'self' https:; upgrade-insecure-requests; 1 font-src www.paypalobjects.com https://fonts.gstatic.com *.cloudflare.com *.googleapis.com *.gstatic.com *.fontawesome.com https://www.google.com https://www.gstatic.com *.development.scalapay.com *.staging.scalapay.com *.integration.scalapay.com *.scalapay.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com https://0merchantacsstag.cardinalcommerce.com 'self' 'unsafe-inline'; frame-ancestors https://api.clerk.io https://cdn.clerk.io 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ https://assets.braintreegateway.com https://c.paypal.com https://tst.kaptcha.com https://geostag.cardinalcommerce.com https://0merchantacsstag.cardinalcommerce.com https://centinelapistag.cardinalcommerce.com https://checkout.paypal.com https://www.google.com https://player.vimeo.com static.addtoany.com *.addthis.com *.cookiebot.com *.criteo.com *.fls.doubleclick.net *.awin1.com *.zenaps.com *.wesupply.xyz https://wesupplylabs.com *.trustpilot.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com data: widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://www.google.it https://b.stats.paypal.com https://c.paypal.com https://dub.stats.paypal.com blob: https://maps.google.com https://maps.gstatic.com *.facebook.com *.google.it *.bidswitch.net *.doubleclick.net *.adnxs.com *.media.net *.rubiconproject.com *.sharethrough.com *.smartadserver.com *.taboola.com *.teads.tv *.3lift.com *.ups.analytics.yahoo.com *.adform.net *.omnitagjs.com *.casalemedia.com id5-sync.com *.360yield.com *.ivitrack.com *.mediavine.com/ *.outbrain.com *.pubmatic.com *.tremorhub.com *.yieldlab.net *.krxd.net *.thebrighttag.com *.cookiebot.com *.roeye.com *.emxdgt.com *.yieldmo.com *.postrelease.com *.criteo.com *.1rx.com *.dmxleo.com *.unrulymedia.com *.googleapis.com *.gstatic.com *.awin1.com *.zenaps.com *.wepowerconnections.com *.bird.eu https://cdn.clerk.io *.development.scalapay.com *.staging.scalapay.com *.integration.scalapay.com *.scalapay.com *.hsforms.net *.hsforms.com 'self' data: data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://www.google.com https://www.gstatic.com https://c.paypal.com https://songbirdstag.cardinalcommerce.com https://maps.google.com https://maps.googleapis.com static.addtoany.com connect.facebook.net *.addthis.com *.moatads.com *.addthisedge.com *.cookiebot.com *.criteo.com *.gestpay.net *.dwin1.com *.hotjar.com *.sella.it *.roeyecdn.com *.preciso.net *.2trk.info *.googleapis.com *.gstatic.com *.awin1.com *.zenaps.com *.wepowerconnections.com https://the.sciencebehindecommerce.com lantern.roeyecdn.com https://api.clerk.io https://cdn.clerk.io *.google.com *.development.scalapay.com *.staging.scalapay.com *.integration.scalapay.com *.scalapay.com *.hsforms.net *.hsforms.com *.cloudflare.com *.trustpilot.com https://www.googletagmanager.com tagmanager.google.com unpkg.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://fonts.googleapis.com https://www.gstatic.com *.cloudflare.com fonts.googleapis.com https://api.clerk.io https://cdn.clerk.io *.fontawesome.com *.googleapis.com *.google.com *.gstatic.com *.addtoany.com *.development.scalapay.com *.staging.scalapay.com *.integration.scalapay.com *.scalapay.com *.trustpilot.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://payments.sandbox.braintree-api.com https://api.sandbox.braintreegateway.com https://origin-analytics-sand.sandbox.braintree-api.com https://centinelapistag.cardinalcommerce.com https://kg668dbov0.execute-api.us-east-1.amazonaws.com https://writer.cardinalcommerce.com https://www.sandbox.paypal.com https://vimeo.com https://maps.googleapis.com *.addthis.com *.googleapis.com *.doubleclick.net *.cookiebot.com *.google.com *.criteo.com *.wepowerconnections.com https://the.sciencebehindecommerce.com http://dpm.demdex.net https://www.google.com https://www.gstatic.com *.development.scalapay.com *.staging.scalapay.com *.integration.scalapay.com *.scalapay.com *.gstatic.com t.elasticsuite.io *.hsforms.net *.hsforms.com analytics.google.com 'self' 'unsafe-inline'; child-src *.awin1.com *.zenaps.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src cdn.jsdelivr.net fonts.gstatic.com *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com https://cdnjs.cloudflare.com *.fontawesome.com *.klarna.com *.klarnacdn.net usizy-media.s3.eu-west-1.amazonaws.com *.alothemes.com *.magepow.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.adyen.com pay.google.com payments-eu.amazon.com *.amazon.de *.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src bid.g.doubleclick.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.adyen.com pay.google.com *.paypal.com *.google.com *.doubleclick.net *.facebook.com c.paypal.com checkout.paypal.com assets.braintreegateway.com *.cardinalcommerce.com * *.klarna.com *.klarnaservices.com *.trustpilot.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com https://flagcdn.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.adyen.com pay.google.com *.payments-amazon.com *.media-amazon.com *.paypalobjects.com https://images.unsplash.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.gstatic.com cdn.doofinder.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.jsdelivr.net magefan.com cm.magefan.com *.ekinsport.com *.klarna.com *.klarnacdn.net *.klarnaevt.com media.usizy.es static.usizy.es https://*.googleapis.com https://maps.gstatic.com *.alothemes.com *.magepow.com data: 'self' 'unsafe-inline'; script-src www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com cdn.jsdelivr.net *.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com cdn.doofinder.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com https://cdnjs.cloudflare.com *.jsdelivr.net https://polyfill-fastly.io https://browser.sentry-cdn.com *.klarna.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com static.axept.io static.usizy.es media.usizy.es sgtm.ekinsport.com https://*.googleapis.com *.alothemes.com *.magepow.com cdn.brevo.com sibautomation.com *.trustpilot.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src cdn.jsdelivr.net fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.doofinder.com unsafe-inline assets.braintreegateway.com https://fonts.googleapis.com https://cdnjs.cloudflare.com *.fontawesome.com *.jsdelivr.net *.klarna.com *.klarnacdn.net static.usizy.es *.alothemes.com *.magepow.com maxcdn.bootstrapcdn.com *.trustpilot.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adyen.com *.google.com payments-eu.amazon.com *.paypal.com *.getalma.eu *.google-analytics.com *.facebook.com *.facebook.net *.doofinder.com wss://*.doofinder.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com google.com https://*.ingest.sentry.io *.klarnaservices.com *.klarna.com *.klarnacdn.net x.klarnacdn.net *.klarnaevt.com client.axept.io api.axept.io usizy.com media.usizy.es https://*.googleapis.com *.alothemes.com *.magepow.com in-automate.brevo.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' data: blob: https:; script-src 'self' 'unsafe-inline' 'unsafe-eval' https: https://www.googletagmanager.com https://www.google-analytics.com https://connect.facebook.net https://static.zalo.me https://sp.zalo.me; style-src 'self' 'unsafe-inline' https: https://fonts.googleapis.com; img-src 'self' data: https: https://*.mailchimp.com https://mcusercontent.com https://www.google-analytics.com; media-src 'self' https://www.youtube.com https://www.youtu.be; font-src 'self' https://fonts.gstatic.com; connect-src 'self' https://www.google-analytics.com https://region1.google-analytics.com https://*.mailchimp.com https://zalo.me https://*.zalo.me; frame-src 'self' https://www.youtube.com https://www.youtu.be https://www.canva.com https://*.canva.com https://www.facebook.com https://*.facebook.com https://zalo.me https://*.zalo.me; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'none'; upgrade-insecure-requests 1 frame-ancestors 'none'; report-uri /csp_logger/; 1 default-src 'self'; img-src 'self' data: https://tile.openstreetmap.org; object-src 'none'; script-src 'self' 'nonce-Q05qMmFMRjJLWExuNGIyd3Y1WjlBOQ=='; style-src 'self' 'unsafe-inline'; report-to csp; report-uri /csp-report?parent_request_id=0018gj9oo6v5p8chjl20&parent_request_id_hmac=44fcaf679203058ec3fb64a8d08d494080a40eef 1 default-src 'self'; script-src 'self' data: 'unsafe-inline' 'unsafe-hashes' 'unsafe-eval' *.google.com *.googleadservices.com *.googletagmanager.com *.jquery.com *.facebook.net *.cookiebot.com *.doubleclick.net *.privacymanager.io *.disqus.com *.twitter.com *.trustpilot.com *.clarity.ms *.gstatic.com *.youtube.com youtube.com; style-src 'self' data: 'unsafe-inline' https://fonts.googleapis.com; img-src 'self' data: https://a.disquscdn.com https://c.clarity.ms https://c.disquscdn.com https://clm.nektony.com https://googleads.g.doubleclick.net https://imgsct.cookiebot.com https://nektony.com https://ps.w.org https://referrer.disqus.com https://secure.gravatar.com https://ssl.gstatic.com https://syndication.twitter.com https://www.google.com https://www.google.com.ua https://www.googletagmanager.com *.facebook.com *.bing.com; font-src 'self' data: https://fonts.gstatic.com https://nektony.com; connect-src *; media-src 'self'; frame-src 'self' https://consentcdn.cookiebot.com https://disqus.com https://store.payproglobal.com https://td.doubleclick.net https://widget.trustpilot.com https://www.facebook.com https://www.google.com https://www.googletagmanager.com https://www.youtube-nocookie.com https://www.youtube.com; worker-src 'self'; upgrade-insecure-requests; report-uri https://nektony.com/csp-report-mode1.php; manifest-src 'self'; 1 font-src fonts.gstatic.com use.typekit.net fonts.googleapis.com *.googleapis.com *.gstatic.com data: *.cloudflare.com *.twitter.com *.typekit.net *.twimg.com *.trustedshops.com *.zopim.com *.zopim.io https://use.fontawesome.com/ https://bam.nr-data.net/ *.sharethis.com *.elfsight.com *.nr-data.net *.addthis.com *.hsforms.net *.hsforms.com *.youtube.com *.office.net *.cdninstagram.com *.listrakbi.com *.jsdelivr.net *.affirm.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.twitter.com *.addthis.com *.hsforms.net *.hsforms.com *.youtube.com *.office.net *.cdninstagram.com *.listrakbi.com *.jsdelivr.net *.affirm.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.certcapture.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com www.google.com *.affirm.com *.affirm.ca *.certcapture.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * http://www.sandbox.paypal.com *.twitter.com *.zendesk.com http://www.w3.org/2000/svg https://bam.nr-data.net/ *.sharethis.com *.elfsight.com *.nr-data.net *.addthis.com *.hsforms.net *.hsforms.com *.office.net *.cdninstagram.com *.listrakbi.com *.jsdelivr.net *.google.com/ *.googleapis.com *.google.com *.weltpixel.com https://*.online-metrix.net https://imgs.signifyd.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com p.typekit.net *.vimeocdn.com i.ytimg.com *.youtube.com *.ftcdn.net *.behance.net validator.swagger.io https://images.unsplash.com maps.googleapis.com maps.gstatic.com *.gstatic.com *.googleapis.com *.affirm.com *.affirm.ca *.certcapture.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.cloudflare.com *.addthis.com *.googleadservices.com *.google-analytics.com *.twitter.com *.twimg.com *.ytimg.com *.bing.com *.zopim.com *.zopim.io *.doubleclick.net *.google.com *.google.co.in *.mastercard.com http://www.w3.org/2000/svg https://bam.nr-data.net/ *.sharethis.com *.cvoptical.com *.ggpht.com *.elfsight.com *.nr-data.net *.hsforms.net *.hsforms.com *.office.net *.cdninstagram.com *.listrakbi.com *.jsdelivr.net https://www.magezon.com https://redchamps.com https://imgs.signifyd.com https://*.online-metrix.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com amcglobal.sc.omtrdc.net *.adobe.io use.typekit.net magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com *.magento-ds.com https://maps.googleapis.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.affirm.com *.affirm.ca *.certcapture.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.cloudflare.com *.twitter.com *.google-analytics.com *.twimg.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.bing.com *.zopim.com *.zdassets.com *.google.com/ *.zendesk.com http://www.w3.org/2000/svg https://js-agent.newrelic.com/ https://bam.nr-data.net/ *.sharethis.com *.elfsight.com https://static.elfsight.com/ *.addthis.com *.moatads.com *.addthisedge.com *.hsforms.net *.hsforms.com *.office.net *.cdninstagram.com *.listrakbi.com *.jsdelivr.net assets.shipperhq.com https://www.googletagmanager.com tagmanager.google.com unpkg.com https://cdn-scripts.signifyd.com https://imgs.signifyd.com https://h64.online-metrix.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com *.certcapture.com unsafe-inline assets.braintreegateway.com *.cloudflare.com *.googleapis.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.fontawesome.com *.bing.com https://use.fontawesome.com/ https://bam.nr-data.net/ *.sharethis.com *.elfsight.com *.nr-data.net *.addthis.com *.hsforms.net *.hsforms.com *.youtube.com *.office.net *.cdninstagram.com *.listrakbi.com *.jsdelivr.net *.affirm.com maxcdn.bootstrapcdn.com assets.shipperhq.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.zopim.com *.zopim.io https://static.zdassets.com/ https://bam.nr-data.net/ *.sharethis.com *.nr-data.net *.addthis.com *.hsforms.net *.hsforms.com *.youtube.com *.office.net *.cdninstagram.com *.listrakbi.com *.jsdelivr.net *.affirm.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.magento.com *.adobe.io performance.typekit.net commerce.adobe.io *.magento-datasolutions.com *.magento-ds.com *.sentry.io https://maps.googleapis.com https://player.vimeo.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.googleapis.com *.affirm.com *.affirm.ca *.certcapture.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.cloudflare.com *.twitter.com *.twimg.com *.zdassets.com *.zopim.com *.zopim.io wss://widget-mediator.zopim.com *.google-analytics.com https://stats.g.doubleclick.net *.zendesk.com http://www.w3.org/2000/svg https://bam.nr-data.net/ *.sharethis.com *.elfsight.com *.addthis.com *.hsforms.net *.hsforms.com *.youtube.com *.office.net *.cdninstagram.com *.listrakbi.com *.jsdelivr.net ovs.shipperhq.com rms.shipperhq.com https://rms.shipperhq.com wss://rms.shipperhq.com *.doubleclick.net https://imgs.signifyd.com 'self' 'unsafe-inline'; child-src *.certcapture.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.jsdelivr.net *.affirm.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src cdn.jsdelivr.net fonts.gstatic.com cdn.almapay.com https://applepay.cdn-apple.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.getalma.eu *.almapay.com/ *.stripe.com/ *.checkout.com/ *.adyen.com/ *.instagram.com https://www.googletagmanager.com/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.payplug.com *.dalenys.com https://applepay.cdn-apple.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.cdninstagram.com cdn.doofinder.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ https://img.youtube.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com https://secure-magenta.dalenys.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ cdn.jsdelivr.net *.instagram.com cdn.doofinder.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ s7.addthis.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://secure-magenta.dalenys.com https://applepay.cdn-apple.com api-qa.payplug.com cdn-qa.payplug.com api.payplug.com cdn.payplug.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com cdn.jsdelivr.net fonts.googleapis.com *.doofinder.com unsafe-inline assets.braintreegateway.com https://secure-magenta.dalenys.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.cdninstagram.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.getalma.eu *.almapay.com *.doofinder.com wss://*.doofinder.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ ekr.zdassets.com/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.fontawesome.com *.fonts.googleapis.com *.gstatic.com data: *.cloudflare.com *.elecrow.com *.chromestatus.com *.bootcss.com maxcdn.bootstrapcdn.com *.googleapis.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com https://store.plumrocket.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.google.com *.addthis.com *.pinterest.com *.amazonaws.com *.awin1.com *.zenaps.com *.fls.doubleclick.net c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * https://store.plumrocket.com cashier1.uat.useepay.com cashier.useepay.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.cloudflare.com *.cdn.klarna.com *.s.ytimg.com *.widgets.magentocommerce.com *.fpdbs.paypal.com *.t.paypal.com *.paypal.com *.fpdbs.sandbox.paypal.com *.googleapis.com *.gstatic.com *.addthis.com *.pinterest.com *.cdninstagram.com *.elecrow.com *.shopify.com github.com *.githubusercontent.com *.wp.com *.imgur.com bitronics.store www.longan-labs.cc www.facebook.com elecrow.s3.us-west-1.amazonaws.com *.sharethis.com *.awin1.com *.zenaps.com *.wepowerconnections.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com 'self' data: blob: 'unsafe-inline' data: data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.googleapis.com *.google-analytics.com *.addthis.com *.moatads.com *.addthisedge.com *.facebook.com *.facebook.net *.pinterest.com *.instagram.com *.dwin1.com *.livechatinc.com *.elecrow.com *.bootcdn.net *.googletagmanager.com *.doubleclick.net t.contentsquare.net *.awin1.com *.zenaps.com *.wepowerconnections.com https://the.sciencebehindecommerce.com lantern.roeyecdn.com s7.addthis.com *.fontawesome.com *.gstatic.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com cashier.useepay.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.googleapis.com *.bootcss.com maxcdn.bootstrapcdn.com *.fontawesome.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.cloudflare.com *.paypal.com *.googleapis.com *.addthis.com *.cardinalcommerce.com *.graph.instagram.com *.google-analytics.com *.elecrow.com *.googletagmanager.com *.doubleclick.net *.amazonaws.com *.wepowerconnections.com https://the.sciencebehindecommerce.com ekr.zdassets.com/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com 'self' 'unsafe-inline'; child-src *.awin1.com *.zenaps.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.fontawesome.com maxcdn.bootstrapcdn.com *.gstatic.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com 'self' 'unsafe-inline'; frame-ancestors *.multisafepay.com https://pay.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ *.multisafepay.com https://pay.google.com *.sendcloud.sc *.jsdelivr.net consentcdn.cookiebot.com metrics.azerty.nl www.googletagmanager.com td.doubleclick.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net *.vimeocdn.com i.ytimg.com *.youtube.com https://images.unsplash.com magefan.com cm.magefan.com *.multisafepay.com *.amazonaws.com *.hsforms.net *.hsforms.com 'self' data: bat.bing.com www.facebook.com www.google.nl imgsct.cookiebot.com metrics.azerty.nl azerty.nl bat.bing.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net amcglobal.sc.omtrdc.net commerce.adobe.net use.typekit.net magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.magento-ds.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com https://maps.googleapis.com *.avada.io *.multisafepay.com https://pay.google.com *.sendcloud.sc *.jsdelivr.net *.hsforms.net *.hsforms.com *.google.com *.gstatic.com app.aiden.cx consent.cookiebot.com sgtm.azerty.nl bat.bing.com d5yoctgpv4cpx.cloudfront.net consentcdn.cookiebot.com metrics.azerty.nl connect.facebook.net www.clarity.ms js-agent.newrelic.com cdn.ablyft.com ocean.kieskeurig.nl sgtm.azertyzakelijk.nl script.clarity.ms 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com *.fontawesome.com *.multisafepay.com maxcdn.bootstrapcdn.com *.sendcloud.sc *.jsdelivr.net *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net commerce.adobe.io *.sentry.io *.magento-datasolutions.com *.magento-ds.com https://maps.googleapis.com https://player.vimeo.com https://get.geojs.io *.avada.io *.multisafepay.com *.sendcloud.sc *.cdn.jsdelivr.net *.mapbox.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com p2iqhncxyh.execute-api.eu-central-1.amazonaws.com metrics.azerty.nl l.clarity.ms q.clarity.ms consentcdn.cookiebot.com bam.nr-data.net pro.ip-api.com bat.bing.com www.google.com google.com www.facebook.com get.geojs.io pagead2.googlesyndication.com bat.bing.net 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com bat.bing.com l.clarity.ms bam.nr-data.net www.google.com bat.bing.net pagead2.googlesyndication.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 script-src 'unsafe-inline' 'unsafe-eval' 'self' blob: data: https:; style-src 'self' 'unsafe-inline' blob: data: https:; default-src 'self' https:; img-src https: blob: data: android-webview-video-poster:; frame-src blob: data: https:; worker-src blob: data: https:; child-src blob: data: https:; object-src 'self'; font-src 'self' https: blob: data: safari-extension://*; media-src 'self' blob: data: https:; connect-src wss: blob: data: https:; report-uri /csp_ep 1 font-src *.easypack24.net *.cloudflare.com *.twitter.com *.gstatic.com *.typekit.net *.twimg.com *.trustedshops.com *.googleapis.com *.fontawesome.com maxcdn.bootstrapcdn.com https://fonts.gstatic.com api.stripe.com js.stripe.com m.stripe.com x.klarnacdn.net klarna.com na.playground.klarnaevt.com eu.playground.klarnaevt.com klarna-payments-eu.playground.klarna.com klarna-payments-na.playground.klarna.com 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.twitter.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.twitter.com *.consensu.org *.sharethis.com https://player.vimeo.com api.stripe.com js.stripe.com m.stripe.com x.klarnacdn.net klarna.com na.playground.klarnaevt.com eu.playground.klarnaevt.com klarna-payments-eu.playground.klarna.com klarna-payments-na.playground.klarna.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com s.ytimg.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.easypack24.net *.inpost.pl *.inpost.com *.openstreetmap.org *.cloudflare.com *.klarna.com *.googleadservices.com *.google-analytics.com *.paypal.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.sharethis.com *.cdninstagram.com *.shippypro.com https://updates.themepunch.tools http://updates.themepunch.tools https://updates.themepunch-ext-a.tools http://updates.themepunch-ext-a.tools https://updates.themepunch-ext-b.tools http://updates.themepunch-ext-b.tools 'self' 'unsafe-inline'; script-src assets.adobedtm.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com video.google.com vimeo.com www.vimeo.com www.youtube.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de widget.freshworks.com m2epro.freshdesk.com *.inpost.pl *.inpost.it *.easypack24.net *.googleapis.com *.cloudflare.com *.twitter.com *.google-analytics.com *.twimg.com *.gstatic.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.nr-data.net *.newrelic.com *.trackedlink.net *.google.com *.sharethis.com *.shippypro.com *.klarna.com *.klarnaservices.com *.avada.io https://player.vimeo.com https://www.youtube.com maps.googleapis.com https://cdn.scalapay.com api.stripe.com js.stripe.com m.stripe.com x.klarnacdn.net klarna.com na.playground.klarnaevt.com eu.playground.klarnaevt.com klarna-payments-eu.playground.klarna.com klarna-payments-na.playground.klarna.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src getfirebug.com widget.freshworks.com m2epro.freshdesk.com geowidget.easypack24.net *.cloudflare.com *.googleapis.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.fontawesome.com maxcdn.bootstrapcdn.com https://fonts.googleapis.com http://fonts.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de widget.freshworks.com m2epro.freshdesk.com *.inpost.pl *.inpost.it *.googleapis.com *.easypack24.net maps.googleapis.com *.cloudflare.com *.twitter.com *.paypal.com *.twimg.com *.googleadservices.com *.google-analytics.com *.sandbox.paypal.com *.paypalobjects.com *.trackedlink.net *.nr-data.net *.newrelic.com *.ampproject.org *.sharethis.com *.shippypro.com *.klarna.com *.klarnaservices.com https://get.geojs.io *.avada.io https://fonts.googleapis.com https://fonts.gstatic.com api.stripe.com js.stripe.com m.stripe.com x.klarnacdn.net klarna.com na.playground.klarnaevt.com eu.playground.klarnaevt.com klarna-payments-eu.playground.klarna.com klarna-payments-na.playground.klarna.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://gate.rapidsec.net/g/r/csp/eca81d68-abac-4bee-ae30-6ec3924dc803/0/0/3?sct=a01a04be-309d-45a5-9fa6-6a1ffcd59f0d&dpos=report; report-to report-endpoint; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com *.facebook.net *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' data: *.payu.in https://plumrocket.com 'self' 'unsafe-inline'; frame-ancestors 'self' data: *.payu.in *.facebook.com *.flydubai.com *.myshopify.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com landofcoder.com *.facebook.com *.facebook.net *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.google.it *.google.fr *.googletagmanager.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' data: *.payu.in *.flydubai.com *.myshopify.com https://plumrocket.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.googleapis.com magefan.com cm.magefan.com *.facebook.com *.facebook.net *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.google.it *.google.fr *.doubleclick.net *.googletagmanager.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.googleapis.com *.gstatic.com landofcoder.com *.facebook.com *.facebook.net *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.google.it *.google.fr *.googletagmanager.com *.doubleclick.net js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.payu.in 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.googletagmanager.com assets.braintreegateway.com 'self' 'unsafe-inline'; object-src landofcoder.com 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.googleapis.com https://www.sandbox.paypal.com https://www.paypal.com landofcoder.com *.facebook.com *.facebook.net *.doubleclick.net *.googlesyndication.com https://www.merchant-center-analytics.goog api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.payu.in 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; script-src 'report-sample' 'self' 'unsafe-inline' 'unsafe-eval' https://www.clarity.ms/ https://scripts.clarity.ms/ *.wp.com https://fast.wistia.com/ https://analytics.wpmucdn.com/ https://cdn.jotfor.ms/ https://cdnjs.cloudflare.com/ https://sidebar.bugherd.com/ https://maps.googleapis.com/ https://www.google.com/ https://www.gstatic.com/ https://payfacto.bamboohr.com/ https://www.bugherd.com/ https://cdn-cookieyes.com/ https://hb.wpmucdn.com/maitredpos.com/ https://www.googletagmanager.com/ https://stats.wpmucdn.com/ https://cdn.callrail.com/ https://js.callrail.com/ https://j.6sc.co/ https://www.gstatic.com/ https://static.hotjar.com/ https://script.hotjar.com/; style-src 'report-sample' 'self' 'unsafe-inline' https://use.fontawesome.com/ https://ams.wpml.org/ https://fonts.bunny.net/ https://hb.wpmucdn.com/maitredpos.com/ https://fonts.googleapis.com/; object-src 'none'; base-uri 'self'; connect-src 'self' https://y.clarity.ms/collect https://analytics3.wpmudev.com/ https://sessions.bugsnag.com/ wss://ws-mt1.pusher.com/ https://sockjs.pusher.com/ https://epsilon.6sense.com/ https://cdn.ampproject.org/ https://ams.wpml.org/ https://maps.google.com/ https://maps.googleapis.com/ https://app.callrail.com/ https://www.google-analytics.com/ https://metrics.hotjar.io/ wss://ws.hotjar.com/ https://content.hotjar.io/ https://distillery.wistia.com/ https://payfacto.bamboohr.com/ https://stats.g.doubleclick.net/ https://c.6sc.co/ https://analytics.google.com/ https://ipv6.6sc.co/ https://js.callrail.com/ https://cdn-cookieyes.com/ https://log.cookieyes.com/ https://stats1.wpmudev.com/; font-src 'self' data: https://use.fontawesome.com/ https://fonts.bunny.net/ https://fonts.gstatic.com/; frame-src 'self' about: blob: data: https://form.jotform.com/ https://maps.google.com/ https://www.google.com/ https://sidebar.bugherd.com/ https://www.google.com/ https://forms.zohopublic.com; img-src 'self' data: https://www.googletagmanager.com/ https://c.clarity.ms/c.gif https://c.bing.com/ *.smushcdn.com *.wp.com https://d2iiunr5ws5ch1.cloudfront.net/ https://ps.w.org/ https://secure.gravatar.com/ https://wpmudev.com/ https://i0.wp.com/ https://www.google.ca/ https://resources.bamboohr.com/ https://b.6sc.co/ https://cdn-cookieyes.com/ https://b3550802.smushcdn.com/; manifest-src 'self'; media-src 'self'; worker-src blob:; frame-ancestors 'self' https://google.com/; 1 default-src 'self';script-src 'self' 'unsafe-inline' 'unsafe-eval' https://cdn-web.zinio.com https://js-agent.newrelic.com https://*.nr-data.net https://www.googleadservices.com https://www.google.com https://www.googleadservices.com https://googleads.g.doubleclick.net https://*.paypal.com https://www.paypalobjects.com https://*.braintreegateway.com https://*.cardinalcommerce.com https://www.googletagmanager.com https://www.google-analytics.com https://d1fc8wv8zag5ca.cloudfront.net/2.10.2/sp.js https://cdn.jsdelivr.net https://recaptcha.net https://www.gstatic.com https://sleeknotecustomerscripts.sleeknote.com https://sleeknotestaticcontent.sleeknote.com;style-src 'self' 'unsafe-inline' https://*.audiencemedia.com data:;img-src 'self' data: blob: https://*.ziniopro.com https://*.audiencemedia.com https://googleads.g.doubleclick.net https://www.google.com https://*.paypal.com https://*.braintreegateway.com https://discover.zinio.com https://sleeknotestaticcontent.sleeknote.com https://analytics.sleeknote.com https://www.google-analytics.com https://www.googletagmanager.com;media-src 'self';connect-src 'self' https://*.audiencemedia.com https://*.ziniopro.com https://*.nr-data.net https://googleads.g.doubleclick.net https://adservice.google.com https://cdn.jsdelivr.net https://*.braintree-api.com https://*.braintreegateway.com https://*.cardinalcommerce.com https://www.paypal.com https://*.google-analytics.com https://*.analytics.google.com https://analytics.google.com https://collector.datacloud.zinio.com https://cdnjs.cloudflare.com https://fonts.googleapis.com https://images.sleeknote.com https://sleeknotestaticcontent.sleeknote.com https://sleeknotecustomerscripts.sleeknote.com https://sdk.iad-07.braze.com;font-src 'self' https://*.audiencemedia.com https://fonts.gstatic.com https://sleeknotestaticcontent.sleeknote.com;frame-src 'self' https://td.doubleclick.net https://*.paypal.com https://*.braintreegateway.com https://recaptcha.net https://*.sleeknote.com;frame-ancestors none 1 font-src *.fontawesome.com https://fonts.bunny.net *.cloudflare.com *.gstatic.com *.googleapis.com *.typekit.net 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com https://secure-test.worldpay.com/shopper/3ds/ddc.html *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.clearpay.co.uk https://pay.google.com https://secure-test.worldpay.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.google.com 5900250.fls.doubleclick.net *.payments-amazon.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.afterpay.com *.clearpay.co.uk *.cloudflare.com *.gstatic.com *.google-analytics.com *.hsforms.net *.hsforms.com https://firebasestorage.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.klarna.com *.googleadservices.com *.google.com *.google.co.uk *.run4it.com *.fbcdn.net d23yuld0pofhhw.cloudfront.net ut.ra.linksynergy.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.afterpay.com *.clearpay.co.uk *.squarecdn.com https://hbiq.net https://www.google.com/recaptcha/api.js *.gstatic.com *.cloudflare.com https://pay.google.com/gp/p/js/pay.js https://applepay.cdn-apple.com/jsapi/v1/apple-pay-sdk.js *.google-analytics.com https://payments.worldpay.com/resources/cse/js/worldpay-cse-1.0.2.min.js *.hsforms.net *.hsforms.com *.avada.io *.shopify.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googletagmanager.com *.googleapis.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.feefo.com *.run4it.com *.klevu.com *.payments-amazon.com connect.facebook.net tag.rmp.rakuten.com *.typekit.net *.google.com theed11117.pcapredict.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.afterpay.com/ *.squarecdn.com *.cloudflare.com *.fontawesome.com https://fonts.bunny.net unsafe-inline assets.braintreegateway.com *.googleapis.com *.gstatic.com *.klevu.com *.run4it.com *.postcodeanywhere.co.uk unpkg.cm 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.clearpay.co.uk *.squarecdn.com https://hbiq.net https://iq.afterpay-beta.com https://iq.afterpay.com t.elasticsuite.io *.hsforms.net *.hsforms.com api.addressy.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.cloudflare.com *.feefo.com *.instagram.com *.amazon.com *.google-analytics.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.fontawesome.com maxcdn.bootstrapcdn.com *.cloudflare.com *.twitter.com *.gstatic.com *.typekit.net *.twimg.com *.trustedshops.com https://fonts.gstatic.com cdn1.stamped.io stamped.io *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.twitter.com 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.twitter.com *.trustpilot.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com cdn.stamped.io static.addtoany.com *.cookiebot.com *.doubleclick.net consentcdn.cookiebot.com bat.bing.com hose.gardeningexpress.co.uk pipe.gardeningexpress.co.uk consent.cookiebot.com pixel.thoughtmetric.io www.clarity.ms stats.g.doubleclick.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://images.unsplash.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com *.google.com *.googleadservices.com *.google-analytics.com *.googletagmanager.com *.cloudflare.com *.klarna.com *.paypal.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.cloudfront.net cdn1.stamped.io stamped.io www.google.com.ua mageside.com cdn.stamped.io www.ojrq.net *.clarity.ms *.bing.com *.cookiebot.com help.gardeningexpress.co.uk/ flagpedia.net www.google.de www.google.co.uk bat.bing.com hose.gardeningexpress.co.uk fonts.gstatic.com bat.bing.net https://pipe.gardeningexpress.co.uk data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ polyfill.io chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com connect.facebook.net *.googletagmanager.com *.googleadservices.com *.google-analytics.com *.cloudflare.com *.twitter.com *.twimg.com *.gstatic.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.googleapis.com *.trustpilot.com cdn1.stamped.io stamped.io *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com cdn.stamped.io static.addtoany.com *.cookiebot.com *.clarity.ms bam.nr-data.net cdn.jsdelivr.net *.impactcdn.com *.newrelic.com maps.googleapis.com consent.cookiebot.com ajax.googleapis.com bat.bing.com pagead2.googlesyndication.com pipe.gardeningexpress.co.uk pixel.thoughtmetric.io www.clarity.ms stats.g.doubleclick.net https://pipe.gardeningexpress.co.uk 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com downloads.mailchimp.com *.fontawesome.com maxcdn.bootstrapcdn.com *.cloudflare.com *.googleapis.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.trustpilot.com cdn1.stamped.io stamped.io *.stripe.network *.stripecdn.com *.amazon.com *.addtoany.com www.googletagmanager.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com cdn1.stamped.io stamped.io 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io form-assets.mailchimp.com *.intuit.com *.amazonaws.com https://gardeningexpress.us12.list-manage.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com stats.g.doubleclick.net *.cloudflare.com *.twitter.com *.paypal.com *.twimg.com cdn1.stamped.io stamped.io *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com http://dpm.demdex.net cdn.stamped.io static.addtoany.com *.cookiebot.com *.clarity.ms bam.nr-data.net cdn.jsdelivr.net *.impactcdn.com pagead2.googlesyndication.com gardeningexpress.pxf.io *.doubleclick.net *.google.com www.gstatic.com maps.googleapis.com bat.bing.com hose.gardeningexpress.co.uk google.com bat.bing.net pipe.gardeningexpress.co.uk consent.cookiebot.com pixel.thoughtmetric.io www.clarity.ms data.thoughtmetric.io https://pipe.gardeningexpress.co.uk 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src bat.bing.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' https://cdn.ckeditor.com https://proxy-event.ckeditor.com; connect-src 'self' https://script.crazyegg.com https://tracking.crazyegg.com https://assets-tracking.crazyegg.com https://pagestates-tracking.crazyegg.com https://www.googletagmanager.com https://analytics.google.com https://*.linkedin.com https://cdn.cookielaw.org https://geolocation.onetrust.com https://lift3assets.lift.acquia.com https://privacyportal-eu.onetrust.com https://www.google.com https://www.google-analytics.com; font-src 'self'; frame-src 'self' https://player.vimeo.com https://w.soundcloud.com https://www.podbean.com https://www.googletagmanager.com; img-src 'self' https://cdn.cookielaw.org https://*.global.siteimproveanalytics.io https://www.google.com https://px.ads.linkedin.com https://www.google-analytics.com https://www.googletagmanager.com; object-src 'self' https://player.vimeo.com https://w.soundcloud.com https://www.podbean.com; script-src 'self' https://analytics.clickdimensions.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://script.crazyegg.com https://unpkg.com 'nonce-BX1n2MmeZsVcoMVTuK378w'; script-src-attr 'self'; script-src-elem 'self' https://script.crazyegg.com https://events.mintz.com https://viewpoints.mintz.com https://news.mintz.com https://www.googletagmanager.com https://extend.vimeocdn.com https://analytics.google.com https://*.acquia.com https://labs.ceros.com https://sdk.ceros.com https://www.google-analytics.com https://siteimproveanalytics.com https://*.licdn.com https://*.cookielaw.org https://cdn.cookielaw.org https://analytics.clickdimensions.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com 'nonce-BX1n2MmeZsVcoMVTuK378w'; style-src 'self' https://script.crazyegg.com https://events.mintz.com https://viewpoints.mintz.com https://news.mintz.com https://www.googletagmanager.com https://extend.vimeocdn.com https://analytics.google.com https://*.acquia.com https://labs.ceros.com https://sdk.ceros.com https://www.google-analytics.com https://siteimproveanalytics.com https://*.licdn.com https://*.cookielaw.org https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com; style-src-attr 'self' 'unsafe-inline'; style-src-elem 'self' 'unsafe-inline' https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com; form-action 'self'; frame-ancestors 'self'; report-uri https://www.mintz.com/log-report-uri/reportOnly 1 frame-ancestors 'self'; report-uri https://www.weeklytimesnow.com.au/csp-reports 1 base-uri 'self'; block-all-mixed-content; child-src 'self' blob:; default-src 'self'; form-action 'self'; frame-ancestors 'self'; object-src 'none'; report-to csp-endpoint; report-uri https://sentry.nadapada.net/api/136/security/?sentry_key=7d3cea7bc0a6a8fb9a3fc5fe14a1ee02&sentry_environment=production; worker-src 'self' blob:; connect-src 'self' blob: data: https://analytics.google.com https://analytics.talentbrew.io https://content.hotjar.io https://google-analytics.com https://maps.googleapis.com https://*.werkenbijdefensie.nl https://overbridgenet.com https://p.typekit.net https://pagead2.googlesyndication.com https://pulse.werkenbijdefensie.nl https://region1.analytics.google.com https://region1.google-analytics.com https://sentry.nadapada.net/api/136/ https://stats.g.doubleclick.net https://use.typekit.net https://www.google-analytics.com https://www.google.ad https://www.google.ae https://www.google.al https://www.google.am https://www.google.as https://www.google.at https://www.google.az https://www.google.ba https://www.google.be https://www.google.bf https://www.google.bg https://www.google.bi https://www.google.bj https://www.google.bs https://www.google.bt https://www.google.by https://www.google.ca https://www.google.cat https://www.google.cd https://www.google.cf https://www.google.cg https://www.google.ch https://www.google.ci https://www.google.cl https://www.google.cm https://www.google.cn https://www.google.co.ao https://www.google.co.bw https://www.google.co.ck https://www.google.co.cr https://www.google.co.id https://www.google.co.il https://www.google.co.in https://www.google.co.jp https://www.google.co.ke https://www.google.co.kr https://www.google.co.ls https://www.google.co.ma https://www.google.co.mz https://www.google.co.nz https://www.google.co.th https://www.google.co.tz https://www.google.co.ug https://www.google.co.uk https://www.google.co.uz https://www.google.co.ve https://www.google.co.vi https://www.google.co.za https://www.google.co.zm https://www.google.co.zq https://www.google.co.zw https://www.google.com https://www.google.com.af https://www.google.com.ag https://www.google.com.ar https://www.google.com.au https://www.google.com.bd https://www.google.com.bh https://www.google.com.bn https://www.google.com.bo https://www.google.com.br https://www.google.com.bz https://www.google.com.co https://www.google.com.cu https://www.google.com.cy https://www.google.com.do https://www.google.com.ec https://www.google.com.eg https://www.google.com.et https://www.google.com.fj https://www.google.com.gh https://www.google.com.gi https://www.google.com.gt https://www.google.com.hk https://www.google.com.jm https://www.google.com.kh https://www.google.com.kw https://www.google.com.lb https://www.google.com.ly https://www.google.com.mm https://www.google.com.mt https://www.google.com.mx https://www.google.com.my https://www.google.com.na https://www.google.com.ng https://www.google.com.ni https://www.google.com.np https://www.google.com.om https://www.google.com.pa https://www.google.com.pe https://www.google.com.pg https://www.google.com.ph https://www.google.com.pk https://www.google.com.pr https://www.google.com.py https://www.google.com.qa https://www.google.com.sa https://www.google.com.sb https://www.google.com.sg https://www.google.com.sl https://www.google.com.sv https://www.google.com.tj https://www.google.com.tr https://www.google.com.tw https://www.google.com.ua https://www.google.com.uy https://www.google.com.vc https://www.google.com.vn https://www.google.cv https://www.google.cz https://www.google.de https://www.google.dj https://www.google.dk https://www.google.dm https://www.google.dz https://www.google.ee https://www.google.es https://www.google.fi https://www.google.fm https://www.google.fr https://www.google.ga https://www.google.ge https://www.google.gg https://www.google.gh https://www.google.gr https://www.google.gy https://www.google.hn https://www.google.hr https://www.google.ht https://www.google.hu https://www.google.ie https://www.google.im https://www.google.iq https://www.google.is https://www.google.it https://www.google.je https://www.google.jo https://www.google.kg https://www.google.ki https://www.google.kz https://www.google.la https://www.google.li https://www.google.lk https://www.google.lt https://www.google.lu https://www.google.lv https://www.google.md https://www.google.me https://www.google.mg https://www.google.mk https://www.google.ml https://www.google.mn https://www.google.mu https://www.google.mv https://www.google.mw https://www.google.ne https://www.google.nl https://www.google.no https://www.google.nr https://www.google.nu https://www.google.ph https://www.google.pl https://www.google.pn https://www.google.ps https://www.google.pt https://www.google.ro https://www.google.rs https://www.google.ru https://www.google.rw https://www.google.sc https://www.google.se https://www.google.sh https://www.google.si https://www.google.sk https://www.google.sm https://www.google.sn https://www.google.so https://www.google.sr https://www.google.st https://www.google.td https://www.google.tg https://www.google.tl https://www.google.tm https://www.google.tn https://www.google.to https://www.google.tt https://www.google.vu https://www.google.ws https://www.googleadservices.com wss://ws.hotjar.com ; font-src 'self' data: https://fonts.gstatic.com https://use.typekit.net/af/494550/0000000000000000774b907b/30/ ; frame-src 'self' https://c1.adform.net https://links.intractive.app https://track.adform.net https://web.intractive.app https://www.google.com https://www.googletagmanager.com https://www.youtube.com https://login.werkenbijdefensie.nl ; img-src 'self' data: blob: https://analytics.talentbrew.io https://fonts.gstatic.com https://i.ytimg.com https://maps.googleapis.com https://maps.gstatic.com https://media.werkenbijdefensie.nl https://pagead2.googlesyndication.com https://server.seadform.net https://stats.g.doubleclick.net https://translate.google.com https://www.google-analytics.com https://www.google.ad/ads/ https://www.google.ae/ads/ https://www.google.al/ads/ https://www.google.am/ads/ https://www.google.as/ads/ https://www.google.at/ads/ https://www.google.az/ads/ https://www.google.ba/ads/ https://www.google.be/ads/ https://www.google.bf/ads/ https://www.google.bg/ads/ https://www.google.bi/ads/ https://www.google.bj/ads/ https://www.google.bs/ads/ https://www.google.bt/ads/ https://www.google.by/ads/ https://www.google.ca/ads/ https://www.google.cat/ads/ https://www.google.cd/ads/ https://www.google.cf/ads/ https://www.google.cg/ads/ https://www.google.ch/ads/ https://www.google.ci/ads/ https://www.google.cl/ads/ https://www.google.cm/ads/ https://www.google.cn/ads/ https://www.google.co.ao/ads/ https://www.google.co.bw/ads/ https://www.google.co.ck/ads/ https://www.google.co.cr/ads/ https://www.google.co.id/ads/ https://www.google.co.il/ads/ https://www.google.co.in/ads/ https://www.google.co.jp/ads/ https://www.google.co.ke/ads/ https://www.google.co.kr/ads/ https://www.google.co.ls/ads/ https://www.google.co.ma/ads/ https://www.google.co.mz/ads/ https://www.google.co.nz/ads/ https://www.google.co.th/ads/ https://www.google.co.tz/ads/ https://www.google.co.ug/ads/ https://www.google.co.uk/ads/ https://www.google.co.uz/ads/ https://www.google.co.ve/ads/ https://www.google.co.vi/ads/ https://www.google.co.za/ads/ https://www.google.co.zm/ads/ https://www.google.co.zw/ads/ https://www.google.com/ads/ https://www.google.com.af/ads/ https://www.google.com.ag/ads/ https://www.google.com.ar/ads/ https://www.google.com.au/ads/ https://www.google.com.bd/ads/ https://www.google.com.bh/ads/ https://www.google.com.bn/ads/ https://www.google.com.bo/ads/ https://www.google.com.br/ads/ https://www.google.com.bz/ads/ https://www.google.com.co/ads/ https://www.google.com.cu/ads/ https://www.google.com.cy/ads/ https://www.google.com.do/ads/ https://www.google.com.ec/ads/ https://www.google.com.eg/ads/ https://www.google.com.et/ads/ https://www.google.com.fj/ads/ https://www.google.com.gh/ads/ https://www.google.com.gi/ads/ https://www.google.com.gt/ads/ https://www.google.com.hk/ads/ https://www.google.com.jm/ads/ https://www.google.com.kh/ads/ https://www.google.com.kw/ads/ https://www.google.com.lb/ads/ https://www.google.com.ly/ads/ https://www.google.com.mm/ads/ https://www.google.com.mt/ads/ https://www.google.com.mx/ads/ https://www.google.com.my/ads/ https://www.google.com.na/ads/ https://www.google.com.ng/ads/ https://www.google.com.ni/ads/ https://www.google.com.np/ads/ https://www.google.com.om/ads/ https://www.google.com.pa/ads/ https://www.google.com.pe/ads/ https://www.google.com.pg/ads/ https://www.google.com.ph/ads/ https://www.google.com.pk/ads/ https://www.google.com.pr/ads/ https://www.google.com.py/ads/ https://www.google.com.qa/ads/ https://www.google.com.sa/ads/ https://www.google.com.sb/ads/ https://www.google.com.sg/ads/ https://www.google.com.sl/ads/ https://www.google.com.sv/ads/ https://www.google.com.tj/ads/ https://www.google.com.tr/ads/ https://www.google.com.tw/ads/ https://www.google.com.ua/ads/ https://www.google.com.uy/ads/ https://www.google.com.vc/ads/ https://www.google.com.vn/ads/ https://www.google.com/ads/ https://www.google.com/ccm/collect https://www.google.com/pagead/ https://www.google.cv/ads/ https://www.google.cz/ads/ https://www.google.de/ads/ https://www.google.dj/ads/ https://www.google.dk/ads/ https://www.google.dm/ads/ https://www.google.dz/ads/ https://www.google.ee/ads/ https://www.google.es/ads/ https://www.google.fi/ads/ https://www.google.fm/ads/ https://www.google.fr/ads/ https://www.google.ga/ads/ https://www.google.ge/ads/ https://www.google.gg/ads/ https://www.google.gh/ads/ https://www.google.gl/ads/ https://www.google.gm/ads/ https://www.google.gr/ads/ https://www.google.gy/ads/ https://www.google.hn/ads/ https://www.google.hr/ads/ https://www.google.ht/ads/ https://www.google.hu/ads/ https://www.google.ie/ads/ https://www.google.im/ads/ https://www.google.iq/ads/ https://www.google.is/ads/ https://www.google.it/ads/ https://www.google.je/ads/ https://www.google.jo/ads/ https://www.google.kg/ads/ https://www.google.ki/ads/ https://www.google.kz/ads/ https://www.google.la/ads/ https://www.google.li/ads/ https://www.google.lk/ads/ https://www.google.lt/ads/ https://www.google.lu/ads/ https://www.google.lv/ads/ https://www.google.md/ads/ https://www.google.me/ads/ https://www.google.mg/ads/ https://www.google.mk/ads/ https://www.google.ml/ads/ https://www.google.mn/ads/ https://www.google.mu/ads/ https://www.google.mv/ads/ https://www.google.mw/ads/ https://www.google.ne/ads/ https://www.google.nl/ads/ https://www.google.no/ads/ https://www.google.nr/ads/ https://www.google.nu/ads/ https://www.google.ph/ads/ https://www.google.pl/ads/ https://www.google.pn/ads/ https://www.google.ps/ads/ https://www.google.pt/ads/ https://www.google.ro/ads/ https://www.google.rs/ads/ https://www.google.ru/ads/ https://www.google.rw/ads/ https://www.google.sc/ads/ https://www.google.se/ads/ https://www.google.sh/ads/ https://www.google.si/ads/ https://www.google.sk/ads/ https://www.google.sm/ads/ https://www.google.sn/ads/ https://www.google.so/ads/ https://www.google.sr/ads/ https://www.google.st/ads/ https://www.google.td/ads/ https://www.google.tg/ads/ https://www.google.tl/ads/ https://www.google.tm/ads/ https://www.google.tn/ads/ https://www.google.to/ads/ https://www.google.tt/ads/ https://www.google.vu/ads/ https://www.google.ws/ads/ https://www.googleadservices.com https://www.googletagmanager.com ; media-src 'self' https://media.werkenbijdefensie.nl ; script-src 'self' 'unsafe-eval' 'unsafe-inline' https://ajax.googleapis.com/ajax/libs/jquery/3.7.1/jquery.min.js https://apply.talentbrew.io https://cdn.jsdelivr.net/npm/sockjs-client@1.4.0/dist/sockjs.min.js https://connect.facebook.net https://maps.googleapis.com/$rpc/ https://maps.googleapis.com/maps-api-v3/ https://maps.googleapis.com/maps/ https://s2.adform.net https://sc-static.net/webview-autofill.min.js https://sentry.nadapada.net https://track.adform.net https://www.google-analytics.com/analytics.js https://www.google.com/recaptcha/ https://www.googletagmanager.com https://www.gstatic.com/recaptcha/ https://www.youtube.com/iframe_api https://www.youtube.com/s/player/ https://cdn.matomo.cloud ; script-src-elem 'self' 'unsafe-eval' 'unsafe-inline' blob: https://ajax.googleapis.com/ajax/libs/jquery/3.7.1/jquery.min.js https://apply.talentbrew.io https://cdn.jsdelivr.net/npm/sockjs-client@1.4.0/dist/sockjs.min.js https://connect.facebook.net https://embed.intractive.app https://maps.googleapis.com/$rpc/ https://maps.googleapis.com/maps-api-v3/ https://maps.googleapis.com/maps/ https://s2.adform.net https://sc-static.net/webview-autofill.min.js https://script.hotjar.com https://sentry.nadapada.net https://static.hotjar.com https://track.adform.net https://use.typekit.net/rmg6mik.css https://www.google-analytics.com/analytics.js https://www.google.com/recaptcha/ https://www.googletagmanager.com https://www.gstatic.com/recaptcha/ https://www.youtube.com/iframe_api https://www.youtube.com/s/player/ https://cdn.matomo.cloud ; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://p.typekit.net/p.css https://use.typekit.net/rmg6mik.css https://www.googletagmanager.com https://www.gstatic.com ; 1 default-src 'self' *.nscc.ca; img-src 'self' *.nscc.ca *.gstatic.com *.fontawesome.com *.google.ca *.google.com www.google-analytics.com app.careerbeacon.com s3.amazonaws.com syndication.twitter.com www.facebook.com *.monsido.com data: www.googletagmanager.com maps.googleapis.com https://ad.doubleclick.net https://px.ads.linkedin.com/ https://www.linkedin.com/px/ https://i.ytimg.com/vi_webp/ https://syndicatedsearch.goog https://ep1.adtrafficquality.google; font-src 'self' *.nscc.ca *.fontawesome.com *.googleapis.com *.gstatic.com cdn.kendostatic.com data:; style-src 'self' *.nscc.ca *.fontawesome.com *.googleapis.com *.google.com app.simplycast.ca widget.alongside.com cdn.kendostatic.com kendo.cdn.telerik.com tags.srv.stackadapt.com www.googletagmanager.com static-assets-ca.libanswers.com https://kendo.cdn.telerik.com 'unsafe-inline'; script-src 'self' *.nscc.ca *.google.com *.googleapis.com *.gstatic.com https://googleads.g.doubleclick.net *.fontawesome.com *.google-analytics.com *.googletagmanager.com app.simplycast.ca *.youtube.com widget.alongside.com platform.twitter.com lgapi-ca.libapps.com https://ep2.adtrafficquality.google islpronto.islonline.net ca.libraryh3lp.com api3-ca.libcal.com cdn.kendostatic.com *.monsido.com *.crazyegg.com connect.facebook.net tags.srv.stackadapt.com js.adsrvr.org blob: static-assets-ca.libanswers.com https://jsonip.com https://server402.islonline.net/live/islpronto https://code.jquery.com https://unpkg.com https://cdn.kendostatic.com/2023.3.1010/js/* https://kendo.cdn.telerik.com https://qvdt3feo.com/events.js https://snap.licdn.com/li.lms-analytics/insight.min.js https://analytics.tiktok.com/i18n/pixel/events.js https://analytics.tiktok.com/i18n/pixel/static/ 'unsafe-inline'; connect-src 'self' *.nscc.ca www.google-analytics.com https://www.google.com https://ad.doubleclick.net csp.withgoogle.com ka-p.fontawesome.com kit.fontawesome.com api3-ca.libcal.com *.crazyegg.com tags.srv.stackadapt.com *.monsido.com analytics.google.com stats.g.doubleclick.net maps.googleapis.com https://px.ads.linkedin.com/ https://px.ads.linkedin.com/wa/ https://analytics.tiktok.com/api/v2/pixel https://analytics.tiktok.com/api/v2/pixel/act https://ep1.adtrafficquality.google; frame-src 'self' *.youtube.com *.google.com https://www.googletagmanager.com syndication.twitter.com platform.twitter.com ca.libraryh3lp.com *.fls.doubleclick.net insight.adsrvr.org cckc.airtime.pro www.facebook.com https://player.vimeo.com https://td.doubleclick.net https://app.simplycast.ca https://match.adsrvr.org/track/upb/* https://ep2.adtrafficquality.google; frame-ancestors 'self' *.nscc.ca:*; 1 report-to *.usercentrics.eu; font-src https://www.googletagmanager.com *.googleapis.com *.gstatic.com maxcdn.bootstrapcdn.com https://geowidget.easypack24.net https://widgets.trustedshops.com *.fontawesome.com *.usercentrics.eu data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.usercentrics.eu 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * secure.payu.com merch-prod.snd.payu.com https://geowidget-app.inpost.pl/ https://sandbox-easy-geowidget.easypack24.net/ *.usercentrics.eu *.google.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.gstatic.com https://images.unsplash.com *.googleapis.com static.payu.com https://geowidget.easypack24.net *.easypack24.net *.inpost.pl *.openstreetmap.org https://widgets.trustedshops.com https://widgets-qa.trustedshops.com *.usercentrics.eu https://admin.helikon-tex.com *.etrusted.com *.googlesyndication.com *.google.pl *.facebook.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com tagmanager.google.com https://www.googletagmanager.com https://cdn.jsdelivr.net/npm/@ryangjchandler/spruce@2.x.x/dist/spruce.umd.js *.googleapis.com *.gstatic.com secure.payu.com secure.snd.payu.com https://geowidget.easypack24.net *.easypack24.net *.inpost.pl *.openstreetmap.org https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.avada.io *.usercentrics.eu https://id1247.entirem.com *.cloudflareinsights.com *.trustedshops.com *.clarity.ms https://mailing.entirem.com *.ahrefs.com *.crazyegg.com *.gr-cdn.com *.gr-wcon.com *.facebook.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com unsafe-inline assets.braintreegateway.com https://www.googletagmanager.com tagmanager.google.com *.googleapis.com fonts.googleapis.com maxcdn.bootstrapcdn.com https://geowidget.easypack24.net https://geowidget.inpost.pl https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.fontawesome.com *.usercentrics.eu *.etrusted.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com https://geowidget.easypack24.net 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com https://www.google-analytics.com https://*.google-analytics.com https://*.analytics.google.com *.googleapis.com secure.payu.com merch-prod.snd.payu.com *.easypack24.net *.inpost.pl *.openstreetmap.org *.trustedshops.com *.etrusted.com https://integrations.etrusted.site https://get.geojs.io *.avada.io *.usercentrics.eu https://id1247.entirem.com *.cloudflareinsights.com *.frankfurter.app *.doubleclick.net *.clarity.ms *.getresponse.com *.ahrefs.com *.crazyegg.com *.facebook.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.hs-scripts.com *.hs-analytics.net static.hsappstatic.net *.hsforms.net *.hsforms.com *.hsadspixel.net js.hscta.net js-eu1.hscta.net *.hubspot.com *.usemessages.com *.hs-banner.com *.hubspotusercontent00.net *.hubspotusercontent10.net *.hubspotusercontent20.net *.hubspotusercontent30.net *.hubspotusercontent40.net *.hubspot.net *.hscollectedforms.net *.hsleadflows.net *.hubspotfeedback.com feedback.hubapi.com feedback-eu1.hubapi.com www.googletagmanager.com www.google-analytics.com snap.licdn.com genio.co; style-src 'self' 'unsafe-inline' static.hsappstatic.net fonts.googleapis.com *.hubspotusercontent00.net *.hubspotusercontent10.net *.hubspotusercontent20.net *.hubspotusercontent30.net *.hubspotusercontent40.net cdn2.hubspot.net genio.co; img-src 'self' data: *.hubspot.com *.hs-scripts.com www.google-analytics.com licdn.com js.hscta.net js-eu1.hscta.net no-cache.hubspot.com *.hubspotusercontent00.net *.hubspotusercontent10.net *.hubspotusercontent20.net *.hubspotusercontent30.net *.hubspotusercontent40.net *.hubspot.net cdn2.hubspot.net *.hsforms.net *.hsforms.com; connect-src 'self' *.hubapi.com js.hscta.net js-eu1.hscta.net *.hubspot.com *.hs-banner.com *.hscollectedforms.net *.hsforms.com *.hs-analytics.net *.azure.com *.posthog.com www.google-analytics.com; frame-src 'self' *.hubspot.com *.hs-sites.com *.hs-sites-eu1.com play.hubspotvideo.com play-eu1.hubspotvideo.com *.hubspot.net *.hsforms.net *.hsforms.com www.youtube.com player.vimeo.com genio.co; child-src *.hsforms.com; font-src 'self' static.hsappstatic.net fonts.gstatic.com; upgrade-insecure-requests; 1 font-src https://cdnjs.cloudflare.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * test.saferpay.com www.saferpay.com saferpay.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * test.saferpay.com www.saferpay.com saferpay.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://www.google.fr https://api.mapbox.com *.tile.openstreetmap.org https://maps.googleapis.com https://maps.gstatic.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com test.saferpay.com www.saferpay.com saferpay.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.google.com/recaptcha/ www.gstatic.com/recaptcha/ https://cdnjs.cloudflare.com https://maps.googleapis.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com test.saferpay.com www.saferpay.com saferpay.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://fonts.googleapis.com https://cdnjs.cloudflare.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://nominatim.openstreetmap.org api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com test.saferpay.com www.saferpay.com saferpay.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src test.saferpay.com www.saferpay.com saferpay.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' https://d1g5x7b3jtu99v.cloudfront.net;script-src 'self' 'unsafe-inline' https://www2.chromatic.com js.stripe.com widget.intercom.io js.intercomcdn.com cdn.segment.com cdn.lr-in-prod.com https://*.google-analytics.com api.figma.com https://d1g5x7b3jtu99v.cloudfront.net data: connect.facebook.net https://googleads.g.doubleclick.net https://*.googletagmanager.com cdn.jsdelivr.net js.hs-scripts.com js.hscollectedforms.net js.hs-banner.com js.hs-analytics.net js.hsforms.net static.hsappstatic.net https://www.googleadservices.com https://www.google.com https://pagead2.googlesyndication.com https://cdn.vector.co/pixel.js https://*.clarity.ms https://api.app.bullseye.so cdn.getkoala.com js.hsadspixel.net cdn.cr-relay.com a.usbrowserspeed.com d-code.liadm.com https://web.cmp.usercentrics.eu https://assets.revenuehero.io snap.licdn.com;style-src 'self' 'unsafe-inline' fonts.googleapis.com https://d1g5x7b3jtu99v.cloudfront.net https://www2.chromatic.com;img-src *;font-src 'self' fonts.gstatic.com https://fonts.intercomcdn.com https://d1g5x7b3jtu99v.cloudfront.net;media-src 'self' https://js.intercomcdn.com https://d1g5x7b3jtu99v.cloudfront.net;connect-src 'self' https://*.chromatic.com https://index.chromatic.com snapshots.chromatic.com api-iam.intercom.io nexus-websocket-a.intercom.io wss://nexus-websocket-a.intercom.io https://cdn.segment.com https://*.google-analytics.com https://analytics.google.com https://api.segment.io https://stats.g.doubleclick.net https://api-us-east-1.graphcms.com https://r.lr-in-prod.com webmention.io hichroma.us15.list-manage.com https://*.ingest.sentry.io api.figma.com https://pagead2.googlesyndication.com https://forms.hscollectedforms.net https://api.hsforms.com forms.hsforms.com https://*.googletagmanager.com https://www.googleadservices.com https://www.google.com https://google.com api.vector.co https://*.clarity.ms https://api.app.bullseye.so https://pro.ip-api.com api.cr-relay.com https://www.facebook.com api.getkoala.com https://api.hubapi.com https://*.usercentrics.eu https://app.revenuehero.io px.ads.linkedin.com;child-src 'self' blob:;frame-src 'self' https://www.chromatic.com https://index.chromatic.com snapshots.chromatic.com js.stripe.com https://www.youtube.com https://chromatic-interactive-demo.netlify.app https://*.chromatic.com https://td.doubleclick.net https://*.googletagmanager.com https://meetings.hubspot.com https://forms.hsforms.com https://popup.schedulehero.io;frame-ancestors 'self' https://*.chromatic.com 1 frame-ancestors 'self' https://app.contentful.com; worker-src blob:; default-src 'self' gap: ws: 'unsafe-inline' 'unsafe-eval' data: api.country.is vercel.live vercel.app *.vercel.live *.vercel.app safevisit.online contentful.com *.contentful.com *.googleapis.com *.youtube.com *.youtube-nocookie.com *.paypal.com *.googletagmanager.com *.google-analytics.com *.google.com *.google.com.ph *.google.ca *.google.ie *.google.co.in *.facebook.com *.amazonaws.com *.cloudfront.net *.googletagservices.com pay.google.com *.s3.amazonaws.com google.com *.sitkagear.com js.narvar.com cdn.searchspring.net js.klarna.com manifest.webmanifest cdn.tailwindcss.com cdn.cookielaw.org api.yotpo.com cdn-widgetsrepository.yotpo.com *.yotpo.com *.searchspring.io *.bigcommerce.com *.locally.com *.ctfassets.net *.onetrust.com *.criteo.com *.avmws.com *.safevisit.online *.gtm-msr.appspot *.dynamic.criteo.com *.facebook.net *.klaviyo.com *.zdassets.com *.browser-intake-datadoghq *.vercel-insights.com *.csper.io klarnaservices.com *.klarnaservices.com datadoghq-browser-agent.com *.datadoghq-browser-agent.com browser-intake-datadoghq.com *.browser-intake-datadoghq.com *.gstatic.com *.bing.com *.typekit.net *.doubleclick.net *.bidswitch.net *.adnxs.com *.media.net *.rubiconproject.com *.smartadserver.com *.taboola.com *.aralego.com criteo-sync.teads.tv *.3lift.com *.yahoo.net *.socdm.com *.casalemedia.com *.dable.io *.adingo.jp *.stickyadstv.com *.360yield.com *.rlcdn.com *.outbrain.com *.pubmatic.com *.smaato.net *.clmbtech.com *.yieldmo.com *.klarnacdn.net vercel.com assets.vercel.com *.experticity.com 10974823.collect.igodigital.com *.collect.igodigital.com *.bazaarvoice.com gore-rebrand-fonts.surge.sh viev-fonts.surge.sh googleads.g.doubleclick.net envoydev.co track.securedvisit.com bh.contextweb.com stats.g.doubleclick.net public-prod-dspcookiematching.dmxleo.com match.adsrvr.org trends.revcontent.com match.sharethrough.com tapestry.tapad.com criteo-partners.tremorhub.com ad.tpmn.co.kr e1.emxdgt.com cm.g.doubleclick.net partner.mediawallahscript.com visitor.omnitagjs.com i.liadm.com exchange.mediavine.com 1f2e7.v.fwmrm.net tags.bluekai.com dpm.demdex.net ws-us3.pusher.co eu.klarnaevt.com sockjs-us3.pusher.com ws-us3.pusher.com aa.agkn.com track.sv.rkdms.com sync.crwdcntrl.net *.hotjar.com widget-mediator.zopim.com aorta.clickagy.com *.searchspring.net *.googlesyndication.com *.liadm.com *.abtasty.com appclip.loopid.com noembed.com *.klarnaevt.com *.usablenet.com *.usablenet.dev *.gorewear.com *.rebrand.gorewear.com rebrand.gorewear.com www.sandbox.paypal.com cdn.sand.us.zip.co localhost:* *.origin.gorewear.com origin.gorewear.com 1 default-src 'self' https://stats.g.doubleclick.net; connect-src 'self' https: wss: data: https://www.facebook.com https://graph.facebook.com https://*.nr-data.net https://bam.nr-data.net https://bam.eu01.nr-data.net https://js-agent.newrelic.com https://www.bpp.com https://*.google-analytics.com https://pro.ip-api.com/json https://stats.g.doubleclick.net https://ad.doubleclick.net https://td.doubleclick.net https://*.doubleclick.net https://tpc.googlesyndication.com https://*.onetrust.com https://pagead2.googlesyndication.com https://bat.bing.com https://u.clarity.ms https://*.clarity.ms https://px.ads.linkedin.com https://www.googleadservices.com https://www.google.com https://googleads.g.doubleclick.net https://tagmanager.google.com https://www.googletagmanager.com https://*.googletagmanager.com https://secure.leadforensics.com https://*.agile-company-365.com https://*.igodigital.com https://connect.facebook.net https://snap.licdn.com https://www.google-analytics.com https://cdn.mouseflow.com https://*.mouseflow.com wss://*.mouseflow.com https://aiden.learnwise.ai https://*.learnwise.ai https://tags.srv.stackadapt.com https://*.usbrowserspeed.com https://*.salesforceliveagent.com; font-src 'self' data: https://fonts.gstatic.com https://*.cdn.office.net https://use.typekit.net https://use.typekit.com; frame-src 'self' data: https://www.youtube-nocookie.com https://www.youtube.com https://*.fls.doubleclick.net https://td.doubleclick.net https://www.facebook.com https://www.googletagmanager.com https://*.doubleclick.net https://adservice.google.com https://chat.learnwise.ai https://*.learnwise.ai https://match.adsrvr.org https://insight.adsrvr.org; img-src 'self' https: data: https://*.cloudfunctions.net https://www.google-analytics.com https://www.facebook.com https://www.google.com/ads/ga-audiences https://www.google.co.uk/ads/ga-audiences https://*.onetrust.com https://www.googleadservices.com https://www.googletagmanager.com https://ade.googlesyndication.com https://tpc.googlesyndication.com https://c.clarity.ms https://px.ads.linkedin.com https://*.doubleclick.net https://bat.bing.com https://c.bing.com https://pixel.byspotify.com https://*.igodigital.com https://www.datocms-assets.com https://*.mouseflow.com https://www.bpp.com; media-src 'self' https: data: blob:; object-src 'none'; script-src 'self' 'unsafe-eval' 'unsafe-inline' blob: data: * 'nonce-Y2E2NzJjOTctY2I0Zi00ZjlkLWI4YjMtZmNkMTE4ZWY4ZjA5' 'strict-dynamic' http: https: https://js-agent.newrelic.com https://bam.nr-data.net https://bam.eu01.nr-data.net https://www.googletagmanager.com https://tagmanager.google.com https://*.googletagmanager.com https://www.google-analytics.com https://www.googleoptimize.com https://connect.facebook.net https://*.onetrust.com https://bat.bing.com https://snap.licdn.com https://secure.agile-company-365.com https://*.agile-company-365.com https://px.ads.linkedin.com https://www.clarity.ms https://*.clarity.ms https://www.clarity.com https://ts.clarity.com https://v.clarity.com https://ad.doubleclick.net https://*.doubleclick.net https://adservice.google.com https://adservice.google.co.uk https://googleads.g.doubleclick.net https://pagead2.googlesyndication.com https://securepubads.g.doubleclick.net https://stats.g.doubleclick.net https://tpc.googlesyndication.com https://secure.leadforensics.com https://pixel.byspotify.com https://*.igodigital.com https://*.infinity-tracking.com https://cdn.mouseflow.com https://aiden.learnwise.ai https://*.learnwise.ai https://tags.srv.stackadapt.com https://*.usbrowserspeed.com https://*.salesforceliveagent.com; style-src 'self' 'unsafe-inline' blob: data: * https://fonts.googleapis.com https://aiden.learnwise.ai https://*.learnwise.ai; upgrade-insecure-requests; report-uri https://o4508693778268160.ingest.de.sentry.io/api/4509629814800465/security/?sentry_key=7af8eb49226dd30e4cc31a2e2f6ea5cc; 1 default-src 'self'; base-uri 'self'; child-src 'self' blob: *.doubleclick.net *.facebook.com *.google.com *.googlesyndication.com *.vimeo.com connect.facebook.net vimeo.com www.googletagmanager.com; connect-src 'self' 'strict-dynamic' *.acsbapp.com *.analytics.google.com *.bsnteamsports.com *.fancloth.shop *.fontawesome.com *.google.com *.google-analytics.com *.googletagmanager.com *.hotjar.com *.hotjar.io *.nr-data.net *.optimizely.com *.zdassets.com *.zendesk.com *.zopim.com *.zopim.io acsbapp.com ajax.googleapis.com browser-intake-datadoghq.com cdn.cookielaw.org code.jquery.com dev.visualwebsiteoptimizer.com fonts.googleapis.com fonts.gstatic.com geolocation.onetrust.com privacyportal.onetrust.com settings.luckyorange.net stats.g.doubleclick.net vimeo.com vimeocdn.com www.facebook.com www.ssgecom.com wss://*.hotjar.com wss://in.visitors.live wss://visitors.live wss://widget-mediator.zopim.co https://chat-assets.cdn.gladly.com https://chat-sdk.cdn.gladly.com https://cdn.gladly.com https://us-1.gladly.com https://api.us-1.gladly.chat wss://ws.us-1.gladly.chat https://api.smooch.io https://*.config.smooch.io wss://api.smooch.io https://gladly-production.sinter-collect.com https://js.verygoodvault.com https://js2.verygoodvault.com https://st-ea.hiw19909.jscrambler.com https://hiw19909.jscrambler.com https://jscrambler.com; font-src 'self' data: *.bsnteamsports.com *.fancloth.shop *.bootstrapcdn.com *.bsnteamsports.com *.fancloth.shop *.fontawesome.com *.gladly.com *.typekit.net *.zopim.com cdnjs.cloudflare.com fonts.googleapis.com fonts.gstatic.com script.hotjar.com static.zdassets.com; form-action 'self' *.facebook.com *.google.com connect.facebook.net; frame-src 'self' *.paymetric.combid.g.doubleclick.net *.vimeo.com xiecomm.worldpay.com cert-xiecomm.worldpay.com vars.hotjar.com www.google.com www.googletagmanager.com td.doubleclick.net https://js.verygoodvault.com https://js2.verygoodvault.com; img-src 'self' data: blob: *.bsnteamsports.com *.fancloth.shop *.bsnteamsports.com *.bsnsports.com *.google.com *.google-analytics.com *.googletagmanager.com *.gstatic.com *.nr-data.net *.zdassets.com *.zdusercontent.com *.zendesk.com *.zopim.com *.zopim.io *.vimeo.com *.vimeocdn.com ajax.googleapis.com cdn.cookielaw.org code.jquery.com dev.visualwebsiteoptimizer.com googleads.g.doubleclick.net imfarm.bsnsports.com pulse.art.bsnsports.com script.hotjar.com ssgsales.com www.facebook.com stats.g.doubleclick.net https://chat-assets.cdn.gladly.com https://media.cdn.gladly.com https://media.smooch.io; media-src *.vimeo.com static.zdassets.com vimeo.com https://chat-sdk.cdn.gladly.com https://cdn.gladly.com; object-src 'none'; script-src 'self' 'strict-dynamic' 'unsafe-eval' 'report-sample' https: 'unsafe-inline' 'nonce-KXrmqzW6VobpipmjCEQvpQ=='; style-src 'self' 'report-sample' 'unsafe-inline' *.bsnteamsports.com *.fancloth.shop *.bootstrapcdn.com *.fontawesome.com *.google.com *.googleapis.com *.typekit.net *.zdassets.com cdn.jsdelivr.net cdnjs.cloudflare.com code.jquery.com fonts.googleapis.com tagmanager.google.com unpkg.com www.googletagmanager.com https://chat-sdk.cdn.gladly.com https://cdn.gladly.com; upgrade-insecure-requests; report-uri https://62e17a85e7a4e344fdd77145.endpoint.csper.io?v=1; worker-src 'self' blob: www.google.com 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.audioeye.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.demdex.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.brightcove.net *.brightcove.com *.weltpixel.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com *.wesupply.xyz https://wesupplylabs.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net annies-livesearch.s3.amazonaws.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.brightcove.net *.brightcove.com *.boltdns.net *.googlesyndication.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com maps.gstatic.com *.facebook.com *.reddit.com *.adtrafficquality.google *.cookielaw.org *.lightboxcdn.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com annies-livesearch.s3.amazonaws.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net assets.adobedtm.com commerce.adobe.net *.commerce-payment-services.com *.magento-ds.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.magento-datasolutions.com https://rum.hlx.page js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.brightcove.net *.brightcove.com *.ordergroove.com *.attn.tv events.attentivemobile.com *.googlesyndication.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com maps.googleapis.com *.cloudflare.com https://www.googletagmanager.com tagmanager.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com unpkg.com *.adtrafficquality.google *.audioeye.com *.clarity.ms *.cookielaw.org *.gstatic.com *.lightboxcdn.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net annies-livesearch.s3.amazonaws.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.magento-datasolutions.com *.magento-ds.com assets.braintreegateway.com *.typekit.net *.googlesyndication.com tagmanager.google.com *.audioeye.com *.lightboxcdn.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net annies-livesearch.s3.amazonaws.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.typekit.net *.googlesyndication.com 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com annies-livesearch.s3.amazonaws.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.typekit.net *.googlesyndication.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com annies-livesearch.s3.amazonaws.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.magento-datasolutions.com *.magento-ds.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.brightcove.net *.brightcove.com *.boltdns.net *.brightcovecdn.com maps.googleapis.com *.ordergroove.com *.attn.tv events.attentivemobile.com *.googlesyndication.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.google-analytics.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.doubleclick.net *.run.app *.adtrafficquality.google *.audioeye.com *.clarity.ms *.cookielaw.org *.onetrust.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net annies-livesearch.s3.amazonaws.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.brightcovecdn.com *.typekit.net *.googlesyndication.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' guatemaladigital.com:* ; form-action 'none' ; frame-src 'self' googleads.g.doubleclick.net tpc.googlesyndication.com www.google.com/recaptcha/ recaptcha.google.com/recaptcha/ td.doubleclick.net; frame-ancestors 'none' ; style-src 'self' 'unsafe-inline' ; script-src 'self' 'unsafe-inline' www.statcounter.com www.google-analytics.com ssl.google-analytics.com www.google.com www.googletagmanager.com www.gstatic.com pagead2.googlesyndication.com partner.googleadservices.com tpc.googlesyndication.com www.googletagservices.com adservice.google.com adservice.google.com.gt adservice.google.com.sv adservice.google.co.cr static.hotjar.com tools.luckyorange.com websdk.smartlook.com script.hotjar.com settings.luckyorange.com ssl.mousestats.com www.clarity.ms a.plerdy.com ; img-src 'self' data: d3w3rr05w2dn4u.cloudfront.net *.amazonaws.com images-na.ssl-images-amazon.com/images/ m.media-amazon.com/images/ i.ebayimg.com/images/ www.googletagmanager.com pagead2.googlesyndication.com www.google-analytics.com www.google.com.gt ; connect-src 'self' data: guatemaladigital.com:* pagead2.googlesyndication.com c.statcounter.com www.google-analytics.com settings.luckyorange.com vc.hotjar.io ws.hotjar.com content.hotjar.io wss://ws.hotjar.com analytics.google.com i.clarity.ms ; media-src 'self' gd-archivos.s3.amazonaws.com ; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://www.googletagmanager.com *.googleapis.com https://fonts.gstatic.com https://ws.colissimo.fr https://api-sogecommerce.societegenerale.eu/static/ *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com fonts.googleapis.com https://cdnjs.cloudflare.com 'self' data: https://widgets.trustedshops.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * https://sogecommerce.societegenerale.eu/vads-payment/ https://api-sogecommerce.societegenerale.eu/api-payment/ https://api-sogecommerce.societegenerale.eu/static/ 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * https://www.youtube.com https://form.typeform.com https://www.google.com https://www.gstatic.com https://sogecommerce.societegenerale.eu/vads-payment/ https://api-sogecommerce.societegenerale.eu/static/ *.trustpilot.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io a.tile.openstreetmap.org b.tile.openstreetmap.org c.tile.openstreetmap.org magefan.com cm.magefan.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.disqus.com https://maps.googleapis.com https://maps.gstatic.com https://ws.colissimo.fr https://*.tile.openstreetmap.fr https://*.onyourmap.com https://google.fr integrations.etrusted.com res-1.cloudinary.com t4.my-probance.one https://sogecommerce.societegenerale.eu/static/latest/images/type-carte/ https://api-sogecommerce.societegenerale.eu/static/ https://sogecommerce.societegenerale.eu/vads-payment/ https://img.youtube.com https://firebasestorage.googleapis.com *.openstreetmap.org maps.googleapis.com maps.gstatic.com *.hsforms.net *.hsforms.com 'self' data: https://widgets.trustedshops.com https://widgets-qa.trustedshops.com *.etrusted.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com tagmanager.google.com https://www.googletagmanager.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.disqus.com https://maps.googleapis.com https://www.google.com https://www.gstatic.com https://ws.colissimo.fr https://api.mapbox.com https://*.typeform.com app.zipchat.ai app.trygr.io cdn.trygr.io s.pinimg.com cdn.caast.tv ct.pinterest.com static.hotjar.com script.hotjar.com fast-static.smarketer.de widgets.trustedshops.com t4.my-probance.one https://api-sogecommerce.societegenerale.eu/api-payment/ https://api-sogecommerce.societegenerale.eu/static/ *.avada.io *.shopify.com player.vimeo.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com https://cdnjs.cloudflare.com *.hsforms.net *.hsforms.com *.gstatic.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.etrusted.com *.trustpilot.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://www.googletagmanager.com tagmanager.google.com *.googleapis.com assets.braintreegateway.com https://fonts.googleapis.com https://ws.colissimo.fr https://api.mapbox.com https://*.typeform.com integrations.etrusted.com https://api-sogecommerce.societegenerale.eu/static/ *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com https://cdnjs.cloudflare.com *.gstatic.com https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.etrusted.com *.trustpilot.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://www.google-analytics.com https://*.google-analytics.com https://*.analytics.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com https://ws.colissimo.fr https://maps.googleapis.com https://nominatim.openstreetmap.org https://*.onyourmap.com https://*.mapbox.com app.zipchat.ai app.trygr.io cache.caast.tv ct.pinterest.com content.hotjar.io wss://ws.hotjar.com fast.smarketer.de https://sogecommerce.societegenerale.eu/vads-payment/ https://api-sogecommerce.societegenerale.eu/api-payment/ https://get.geojs.io *.avada.io maps.googleapis.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com *.trustedshops.com *.etrusted.com https://integrations.etrusted.site 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src https://sogecommerce.societegenerale.eu/vads-payment/ https://api-sogecommerce.societegenerale.eu/api-payment/ https://api-sogecommerce.societegenerale.eu/static/ *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://csp-reporting-service.com/my-project/endpoint; report-to report-endpoint; 1 script-src 'strict-dynamic' 'nonce-9uTlNphwi+83NH1dGAoOILFSHQUuMy3FDwSiXjlPAe8='; base-uri 'none'; connect-src 'self' https://*.fontawesome.com https://*.googleapis.com https://*.googlesyndication.com https://consentcdn.cookiebot.com https://analytics.tiktok.com https://*.google-analytics.com https://*.analytics.google.com https://*.g.doubleclick.net; img-src data: 'self' https://*.googleapis.com https://*.gstatic.com https://*.google-analytics.com https://cdn.startpeople.be https://img.youtube.com https://i.ytimg.com https://imgsct.cookiebot.com https://vumbnail.com/ https://i.vimeocdn.com; object-src 'none'; style-src 'self' https://cdn.jsdelivr.net/npm/@fancyapps/ui/dist/fancybox.css https://cdnjs.cloudflare.com/ajax/libs/bootstrap-datepicker/1.9.0/css/bootstrap-datepicker3.min.css https://cdn.jsdelivr.net/npm/bootstrap@5.3.0-alpha3/dist/css/bootstrap.min.css https://cdn.jsdelivr.net/npm/select2@4.0.13/dist/css/select2.min.css https://cdn.jsdelivr.net/npm/select2-bootstrap-5-theme@1.3.0/dist/select2-bootstrap-5-theme.min.css https://cdn.jsdelivr.net/npm/bootstrap-icons@1.10.3/font/bootstrap-icons.css https://fonts.googleapis.com; frame-src 'strict-dynamic' 'self' https://consentcdn.cookiebot.com https://www.google.com/recaptcha/ https://www.youtube-nocookie.com/ https://player.vimeo.com/; report-to csp-endpoint; report-uri https://csp-dxp.rgfstaffing.be/csp 1 object-src 'none'; base-uri 'self'; script-src 'self' 'nonce-tdlBATLpseHO75H6PeyUpQ' 'unsafe-inline' 'unsafe-eval' https://*.msauth.net https://*.msftauth.net https://*.msftauthimages.net https://*.msauthimages.net https://*.msidentity.com https://*.microsoftonline-p.com https://*.microsoftazuread-sso.com https://*.azureedge.net https://*.outlook.com https://*.office.com https://*.office365.com https://*.microsoft.com https://*.bing.com 'report-sample'; report-uri https://csp.microsoft.com/report/ESTS-UX-All 1 default-src 'self' blob: data: 'unsafe-inline' 'unsafe-eval' *.adobedtm.com *.coutts.com *.amazon-adsystem.com *.atdmt.com *.avocet.io *.blubrry.com *.clicktale.net *.demdex.net *.doubleclick.net *.everesttech.net *.facebook.com *.facebook.net *.fca.org.uk *.google.co.uk *.google.com *.google.ie *.googleadservices.com *.jwpcdn.com *.jwpltx.com *.liveperson.net *.lpsnmedia.net *.neolane.net *.omtrdc.net *.pinimg.com *.pinterest.com *.userzoom.com *.youtube.com *.ytimg.com *.contentsquare.net *.contentsquare.com https://geolocation.onetrust.com https://privacyportal-eu.onetrust.com https://googleads.g.doubleclick.net https://www.googleadservices.com snap.licdn.com cdn.cookielaw.org www.gstatic.com www.googletagmanager.com www.google-analytics.com googleapis.com; upgrade-insecure-requests; block-all-mixed-content; 1 default-src 'self'; script-src 'self' 'unsafe-eval' 'unsafe-inline' 'nonce-7f8c2b26848cfd888e3bbf238ebf8ff2' 'strict-dynamic' https://www.googletagmanager.com/ https://securepubads.g.doubleclick.net/tag/js/gpt.js https://static.hotjar.com/ https://cdn.cookielaw.org/ https://imasdk.googleapis.com/ https://*.hotjar.io/ https://connect.facebook.net/ https://*.facebook.com/ https://*.facebook.net/ https://analytics.tiktok.com/ https://galt.hit.gemius.pl/ ; style-src 'self' 'unsafe-inline' https://cdn.cookielaw.org/ https://fonts.googleapis.com/ https://www.biathlonworld.com/embedded-player.css https://www.atletiek.nl/build/css/css-ebu.build.css; img-src 'self' data: https://imageservice.evsports.opentv.com/images/v1/image/Sport/ https://cabi.evsports.sports.opentv.com/ https://*.sports.opentv.com/ https://www.googletagmanager.com/ https://static.hotjar.com/ https://cdn.cookielaw.org/logos/ https://www.google.com/ https://www.google.co.uk/ https://www.facebook.com/ https://*.g.doubleclick.net/ https://ep1.adtrafficquality.google/pagead/ https://*.googlesyndication.com/ https://www.ebu.ch/files/live/sites/ebu/files/images/ https://*.cloudfront.net/EBU/; font-src 'self' data: https://fonts.gstatic.com/; connect-src 'self' https://cdn.cookielaw.org/ https://api.evsports.opentv.com/metadata/delivery/ https://www.google.com/pagead/form-data/ https://www.google.com/ccm/form-data/ https://*.sports.opentv.com/ https://www.googletagmanager.com/ https://*.googlesyndication.com/ https://ep1.adtrafficquality.google/getconfig/sodar https://securepubads.g.doubleclick.net/pagead/ https://securepubads.g.doubleclick.net/gampad/ https://analytics.tiktok.com/ https://www.facebook.com/ https://*.tiktokw.us/ https://*.hotjar.com/ https://galt.hit.gemius.pl/ https://firebase.googleapis.com/ https://firebaseremoteconfig.googleapis.com/v1/projects/eurovision-sport-prod-772510/ https://firebaseinstallations.googleapis.com/v1/projects/eurovision-sport-prod-772510/ https://firebaseremoteconfig.googleapis.com/v1/projects/eurovision-sport-dev-511366/ https://firebaseinstallations.googleapis.com/v1/projects/eurovision-sport-dev-511366/ https://*.facebook.com/ https://*.fbcdn.net/ https://*.facebook.net/ https://*.google-analytics.com/ https://*.onetrust.com/ https://*.hotjar.io/ wss://ws.hotjar.com/ https://*.akamaized.net/ https://*.anycast.nagra.com/ https://evs-dtvsports-vod-secure2.akamaized.net/ https://*.ampproject.org/ https://api.evsports.opentv.com/ https://api.evsports.opentv.com/useractivityvault/v1/useractivity/; frame-src https://files.eurovisionsport.com/ https://www.google.com/ https://ep2.adtrafficquality.google/ https://www.googletagmanager.com/ https://*.g.doubleclick.net/ https://*.safeframe.googlesyndication.com/ http://imasdk.googleapis.com/ http://console.googletagservices.com/ https://www.ebu.ch/ https://eurovisionsport.com/; media-src 'self' blob: https://*.akamaized.net/ https://*.anycast.nagra.com/ https://*.sports.opentv.com/; script-src-elem 'self' 'nonce-7f8c2b26848cfd888e3bbf238ebf8ff2' https://cdn.ampproject.org/ https://*.hotjar.com/ https://connect.facebook.net/ https://analytics.tiktok.com/ https://cdn.cookielaw.org/ https://www.googletagmanager.com/ https://securepubads.g.doubleclick.net/ https://imasdk.googleapis.com/js/sdkloader/ima3.js https://*.hotjar.io/; object-src 'none'; base-uri 'self'; form-action 'self'; 1 object-src 'none';base-uri 'self';script-src 'nonce-W3gehoG2_Do4j1-_8uOfBw' 'strict-dynamic' 'report-sample' 'unsafe-eval' 'unsafe-inline' https: http:;report-uri https://csp.withgoogle.com/csp/gws/other-hp 1 font-src fonts.gstatic.com use.typekit.net *.fontawesome.com www.searchanise.com *.searchserverapi.com staticw2.yotpo.com https://*.hotjar.com use.fontawesome.com maxcdn.bootstrapcdn.com *.yotpo.com *.googleapis.com *.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.adyen.com testsecureacceptance.cybersource.com secureacceptance.cybersource.com 0merchantacsstag.cardinalcommerce.com merchantacs.cardinalcommerce.com www.searchanise.com *.searchserverapi.com *.twitter.com *.yotpo.com swellrewards.com *.swellrewards.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.googletagmanager.com *.adyen.com www.google.com *.online-metrix.net testflex.cybersource.com flex.cybersource.com testsecureacceptance.cybersource.com secureacceptance.cybersource.com merchantacs.cardinalcommerce.com 0merchantacsstag.cardinalcommerce.com *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com *.hub-box.com www.searchanise.com *.searchserverapi.com *.twitter.com secure.livechatinc.com widget.trustpilot.com frame.hubbox.com *.yotpo.com swellrewards.com *.swellrewards.com *.1account.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net p.typekit.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.adyen.com *.twitter.com *.twimg.com www.google.com www.google.ru www.searchanise.com *.searchserverapi.com s3.amazonaws.com services.postcodeanywhere.co.uk *.google-analytics.com *.analytics.google.com https://*.hotjar.com *.yotpo.com swellrewards.com *.swellrewards.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com amcglobal.sc.omtrdc.net *.adobe.io magento-recs-sdk.adobe.net www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com *.magento-ds.com www.googletagmanager.com *.adyen.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.online-metrix.net testflex.cybersource.com flex.cybersource.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.trackedlink.net *.trackedweb.net searchanise-ef84.kxcdn.com ajax.aspnetcdn.com www.searchanise.com *.searchserverapi.com *.searchanise.com api.amplitude.com cdn.cookie-script.com cdn.livechatinc.com api.livechatinc.com js-agent.newrelic.com bam.nr-data.net bam-cell.nr-data.net widget.trustpilot.com searchserverapi.com cpage11112.pcapredict.com services.postcodeanywhere.co.uk analytics.ahrefs.com www.googleoptimize.com *.clarity.ms https://*.hotjar.com *.yotpo.com swellrewards.com *.swellrewards.com *.1account.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com www.searchanise.com *.searchserverapi.com searchanise-ef84.kxcdn.com *.twitter.com services.postcodeanywhere.co.uk maxcdn.bootstrapcdn.com https://*.hotjar.com *.yotpo.com swellrewards.com *.swellrewards.com *.1account.net *.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com *.snplow.net commerce.adobedc.net api.magento.com *.adobe.io performance.typekit.net pilot-payflowlink.paypal.com commerce.adobe.io *.magento-datasolutions.com *.magento-ds.com *.sentry.io *.adyen.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com *.hub-box.com api.amplitude.com stats.g.doubleclick.net bam.nr-data.net bam-cell.nr-data.net services.postcodeanywhere.co.uk api.livechatinc.com *.google-analytics.com *.analytics.google.com mcprod.vapeuk.co.uk *.clarity.ms api.pwnedpasswords.com analytics.ahrefs.com https://*.hotjar.com https://*.hotjar.io wss://*.hotjar.com *.yotpo.com swellrewards.com *.swellrewards.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'none'; base-uri 'self'; connect-src 'self' https://www.google-analytics.com; font-src 'self' https://fonts.gstatic.com; frame-ancestors 'none'; frame-src https://www.google.com; img-src 'self' https://www.google-analytics.com; manifest-src 'self'; media-src 'self'; object-src 'none'; script-src 'report-sample' 'self' https://s.go-mpulse.net https://www.googletagmanager.com https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/; style-src 'report-sample' 'self' https://fonts.googleapis.com; worker-src 'none' 1 default-src 'self' https:; connect-src 'self' https: wss:; script-src 'unsafe-inline' 'self' https:; worker-src blob:; style-src 'unsafe-inline' 'self' https:; object-src 'none'; img-src 'self' data: https:; frame-ancestors 'self' 1 script-src 'nonce-DGF+0RkB6K47cHkwlFOfxw==' 'strict-dynamic' 'unsafe-eval' 'unsafe-inline' https: 'report-sample'; base-uri 'none'; report-uri https://events.mercadolibre.com/csp/reports?identifier=w1qeU4XKVwGbQGBuEKyE3KhFBIpr5IZSIaRiTowMc8UG7kU18vRsmBTEKL2krAj23LIS&policy_id=26548&user_id=&request_id=e9683ea4-9110-4971-8fab-25899815892d; report-to csp-endpoint-wqeuxkvwgbqgbuekyekhfbiprizsiaritowmcugkuvrsmbteklkrajlis; object-src https://http2.mlstatic.com/ https://mlstaticquic-a.akamaihd.net/; frame-ancestors 'self' https://*.mercadolibre.cl:* https://*.mercadolibre.com:* https://*.mercadolibre.com.ve:* https://*.mercadolibre.com.ar:* https://*.mercadolivre.com.br:* https://*.mercadolibre.com.co:* https://*.mercadolibre.com.ec:* https://*.mercadolibre.com.mx:* https://*.mercadolibre.com.pe:* https://*.mercadolibre.com.uy:* https://*.mercadopago.cl:* https://*.mercadopago.com.ar:* https://*.mercadopago.com.br:* https://*.mercadopago.com.co:* https://*.mercadopago.com.mx:* https://*.mercadopago.com.pe:* https://*.mercadopago.com.uy:* https://*.mercadopago.com.ve:* https://*.mercadopago.com:* https://*.adminml.com:* https://*.mercadolibre.co.cr:* https://*.mercadolibre.com.pa:* https://*.mercadolibre.com.do:* https://*.mercadolibre.com.bo:* https://*.mercadolibre.com.py:* https://*.mercadolibre.com.gt:* https://*.mercadolibre.com.hn:* https://*.mercadolibre.com.ni:* https://*.mercadolibre.com.sv:* https://*.mercadopago.com.ec:* https://*.portalinmobiliario.com:* https://*.mercadolivre.com:* 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.youtube.com *.ytimg.com *.wistia.com *.wistia.net *.qq.com *.gtimg.cn *.cookiefirst.com *.googletagmanager.com *.google-analytics.com *.analytics.google.com *.doubleclick.net *.linkedin.com snap.licdn.com *.facebook.com *.facebook.net connect.facebook.net *.dynamics.com *.microsoftonline.com *.friendlycaptcha.com friendlycaptcha.com *.heraeus-web.com *.cookiefirst.com; script-src-elem 'self' 'unsafe-inline' *.youtube.com *.wistia.com *.wistia.net *.qq.com *.cookiefirst.com *.googletagmanager.com *.google-analytics.com *.analytics.google.com *.linkedin.com *.facebook.com *.facebook.net *.dynamics.com *.friendlycaptcha.com *.sociablekit.com localtesting.com *.azureedge.net *.maptiler.com *.licdn.com *.heraeus-web.com; style-src 'self' 'unsafe-inline' *.wistia.com *.wistia.net *.friendlycaptcha.com *.sociablekit.com *.cookiefirst.com *.heraeus-web.com; style-src-elem 'self' 'unsafe-inline' fonts.googleapis.com *.heraeus-web.com *.cookiefirst.com *.sociablekit.com; img-src 'self' data: blob: *.youtube.com *.ytimg.com *.googlevideo.com *.wistia.com *.wistia.net *.qq.com *.gtimg.cn *.cookiefirst.com *.googletagmanager.com *.google-analytics.com *.analytics.google.com *.doubleclick.net *.linkedin.com *.facebook.com *.facebook.net *.dynamics.com *.friendlycaptcha.com *.sociablekit.com *.licdn.com *.azureedge.net *.heraeus.com *.heraeus-web.com; font-src 'self' data: *.wistia.com *.wistia.net *.heraeus-web.com; connect-src 'self' *.youtube.com *.wistia.com *.wistia.net *.qq.com *.cookiefirst.com *.googletagmanager.com *.google-analytics.com *.analytics.google.com *.doubleclick.net *.linkedin.com *.facebook.com *.facebook.net *.dynamics.com *.microsoftonline.com *.friendlycaptcha.com friendlycaptcha.com *.heraeus-web.com *.accentapi.com *.heraeus.com *.azurewebsites.net *.azureedge.net *.sociablekit.com *.maptiler.com sgtm.argor-heraeus.com sgtm.heraeus-medical.com sgtm.heraeus-medevio.com sgtm.heraeus-group.com sgtm.heraeus-electronics.com sgtm.heraeus-precious-metals.com sgtm.heraeus-printed-electronics.com sgtm.heraeus-remloy.com sgtm.heraeus-electro-nite.com sgtm.heraeus-epurio.com sgtm.heraeus-amloy.com sgtm.heraeus.com; frame-src 'self' *.youtube.com *.youtube-nocookie.com *.wistia.com *.wistia.net *.qq.com *.linkedin.com *.facebook.com *.dynamics.com *.friendlycaptcha.com friendlycaptcha.com *.powerapps.com *.heraeus-web.com *.heraeus.com heraeus.sharepoint.com login.microsoftonline.com sgtm.argor-heraeus.com sgtm.heraeus-medical.com sgtm.heraeus-medevio.com sgtm.heraeus-group.com sgtm.heraeus-electronics.com sgtm.heraeus-precious-metals.com sgtm.heraeus-printed-electronics.com sgtm.heraeus-remloy.com sgtm.heraeus-electro-nite.com sgtm.heraeus-epurio.com sgtm.heraeus-amloy.com sgtm.heraeus.com; frame-ancestors 'self' *.heraeus-web.com *.heraeus.com; media-src 'self' data: blob: *.wistia.com *.wistia.net *.heraeus-web.com *.heraeus.com; child-src 'self' blob:; object-src 'none'; base-uri 'self'; form-action 'self' *.dynamics.com; report-uri /api/csp-report 1 object-src 'none'; connect-src 'self' *.21sextury.com *.21members.com cognito-identity.us-east-1.amazonaws.com backend.getbeamer.com *.comm100.io *.algolia.net insights.algolia.io *.algolianet.com *.gammaapis.com *.gammacdn.com analytics.google.com *.google-analytics.com adservice.google.com *.analytics.google.com *.doubleclick.net *.pubnub.com *.lovense.com *.handyfeeling.com www.gammaentertainment.com *.tiypa.com *.recombee.us dasasoveekepl.cloudfront.net capture.trackjs.com ws: jlduihq7lrcdxgw4vrndhdfcsq.appsync-api.us-east-1.amazonaws.com tcs4u525zrg5hnnoe5kzndxuaq.appsync-api.us-east-1.amazonaws.com xtnzefcqrb.execute-api.us-east-1.amazonaws.com 2aed6ghjsb4436qtebuqk3gfzq0xeauy.lambda-url.us-east-1.on.aws lzzos7clo5.execute-api.us-east-1.amazonaws.com *.izooto.com www.idealgasm.com 3tt0xhv5u7.execute-api.us-east-1.amazonaws.com; form-action 'self' *.21sextury.com *.21members.com join.gammasecure.com; script-src 'self' *.21sextury.com *.21members.com app.getbeamer.com static.getbeamer.com blob: vue.comm100.com standby.comm100vue.com *.gammacdn.com www.google-analytics.com www.googletagmanager.com www.gstatic.com www.google.com code.jquery.com d3a3ewgd1iewwz.cloudfront.net cdn.izooto.com 'unsafe-eval' 'unsafe-inline'; frame-src 'self' *.21sextury.com *.21members.com push.getbeamer.com app.getbeamer.com www.google.com *.doubleclick.net cdn.izooto.com *.banhq.com; report-uri https://csp-report.browser-intake-datadoghq.com/api/v2/logs?dd-api-key=pub787d5a6164b329b26f2e4f7956bbed10&dd-evp-origin=content-security-policy&ddsource=csp-prod&ddtags=CSP-Prod; 1 default-src 'self';style-src 'self' 'unsafe-inline';style-src-elem 'unsafe-inline' 'self' https://*.intercomcdn.com/ https://fonts.googleapis.com/css2;script-src 'unsafe-eval' https://*.intercom.io;script-src-elem 'self' 'unsafe-inline' https://*.intercom.io/ https://*.intercomcdn.com/ https://www.googletagmanager.com/gtag/ https://fonts.googleapis.com/css2;img-src 'self' data: blob: https://images.stealthex.io https://stealthex.io/blog/wp-content/ https://*.intercomassets.com https://*.intercomcdn.com https://fc-use1-00-pics-bkt-00.s3.amazonaws.com/;media-src https://*.intercom.io;frame-src https://*.intercom.io https://intercom-sheets.com;worker-src 'self' blob: https://*.intercom.io/;font-src 'self' data: https://fonts.gstatic.com/ https://*.intercomcdn.com/;connect-src 'self' https://stealthex.io/api/ https://www.google-analytics.com/g/collect https://*.ingest.sentry.io/api/ wss://*.intercom.io/ https://*.intercom.io/;report-uri https://stealthex.report-uri.com/r/d/csp/reportOnly 1 default-src 'self' https:; script-src 'self' https: 'unsafe-inline' 'unsafe-eval'; style-src 'self' https: 'unsafe-inline'; img-src 'self' https: data: blob:; media-src 'self' https: data: blob:; object-src 'none'; frame-ancestors 'self' https://experience.adobe.com https://infopoint.audi.it; connect-src 'self' https: wss://e0k754.acquire.io; base-uri 'self'; font-src 'self' https: data:; worker-src 'self' blob:; report-uri https://www.audi.co.jp/api/csp-report; report-to csp-endpoint 1 default-src 'self';base-uri 'self';frame-ancestors 'self' https://cancercarespecialists.org/mychart/;frame-src https://* 'self' epichttp: https://*.appcues.com https://*.dermengine.com https://*.gyantts.com/ https://*.intranet.osfnet.org/ https://*.kyruus.com/ https://*.mixpanel.com https://*.neurotrack.com/ https://*.neurotrack.io/ https://*.osfhealthcare.org/ https://*.skin.app https://*.stripe.com https://*.zipnosis.com/ https://d2y285dhddzdli.cloudfront.net https://integrations-core.fabrichealth.com https://integrations-core.stage.fabrichealth.com https://mychart-stg.personapay.com https://mychart.personapay.com https://pay.instamed.com https://premier.trustcommerce.com https://s3.amazonaws.com/assets.gyant.com/ https://securecheckout-test.onplanprocessing.com https://securecheckout.onplanprocessing.com https://stagepremier.trustcommerce.com wss://*.gyantts.com/;script-src 'nonce-1ca9dddcbe0445baa80502141e681cb8' https://www.osfmychart.org 'self' https://*.appcues.com https://*.dermengine.com https://*.gyantts.com/ https://*.intranet.osfnet.org/ https://*.kyruus.com/ https://*.mixpanel.com https://*.neurotrack.com/ https://*.neurotrack.io/ https://*.osfhealthcare.org/ https://*.skin.app https://*.stripe.com https://d2y285dhddzdli.cloudfront.net https://s3.amazonaws.com/assets.gyant.com/ https://siteimproveanalytics.com/ wss://*.gyantts.com/;img-src https://* 'self' blob: data: https://*.appcues.com https://*.dermengine.com https://*.gyantts.com/ https://*.intranet.osfnet.org/ https://*.kyruus.com/ https://*.mixpanel.com https://*.neurotrack.com/ https://*.neurotrack.io/ https://*.osfhealthcare.org/ https://*.skin.app https://*.stripe.com https://d2y285dhddzdli.cloudfront.net https://s3.amazonaws.com/assets.gyant.com/ wss://*.gyantts.com/;connect-src 'self' epichttp: https://*.appcues.com https://*.dermengine.com https://*.gyantts.com/ https://*.intranet.osfnet.org/ https://*.kyruus.com/ https://*.mixpanel.com https://*.neurotrack.com/ https://*.neurotrack.io/ https://*.osfhealthcare.org/ https://*.skin.app https://*.stripe.com https://d2y285dhddzdli.cloudfront.net https://s3.amazonaws.com/assets.gyant.com/ wss://*.gyantts.com/;style-src https://www.osfmychart.org 'self' 'unsafe-inline' https://*.appcues.com https://*.dermengine.com https://*.gyantts.com/ https://*.intranet.osfnet.org/ https://*.kyruus.com/ https://*.mixpanel.com https://*.neurotrack.com/ https://*.neurotrack.io/ https://*.osfhealthcare.org/ https://*.skin.app https://*.stripe.com https://d2y285dhddzdli.cloudfront.net https://s3.amazonaws.com/assets.gyant.com/ wss://*.gyantts.com/;manifest-src 'self' https://*.appcues.com https://*.dermengine.com https://*.gyantts.com/ https://*.intranet.osfnet.org/ https://*.kyruus.com/ https://*.mixpanel.com https://*.neurotrack.com/ https://*.neurotrack.io/ https://*.osfhealthcare.org/ https://*.skin.app https://*.stripe.com https://d2y285dhddzdli.cloudfront.net https://s3.amazonaws.com/assets.gyant.com/ wss://*.gyantts.com/;worker-src 'self' blob: https://*.appcues.com https://*.dermengine.com https://*.gyantts.com/ https://*.intranet.osfnet.org/ https://*.kyruus.com/ https://*.mixpanel.com https://*.neurotrack.com/ https://*.neurotrack.io/ https://*.osfhealthcare.org/ https://*.skin.app https://*.stripe.com https://d2y285dhddzdli.cloudfront.net https://s3.amazonaws.com/assets.gyant.com/ wss://*.gyantts.com/;child-src 'self' blob: https://*.appcues.com https://*.dermengine.com https://*.gyantts.com/ https://*.intranet.osfnet.org/ https://*.kyruus.com/ https://*.mixpanel.com https://*.neurotrack.com/ https://*.neurotrack.io/ https://*.osfhealthcare.org/ https://*.skin.app https://*.stripe.com https://d2y285dhddzdli.cloudfront.net https://s3.amazonaws.com/assets.gyant.com/ wss://*.gyantts.com/;font-src 'self' https://*.appcues.com https://*.dermengine.com https://*.gyantts.com/ https://*.intranet.osfnet.org/ https://*.kyruus.com/ https://*.mixpanel.com https://*.neurotrack.com/ https://*.neurotrack.io/ https://*.osfhealthcare.org/ https://*.skin.app https://*.stripe.com https://d2y285dhddzdli.cloudfront.net https://s3.amazonaws.com/assets.gyant.com/ wss://*.gyantts.com/;object-src 'self' https://*.appcues.com https://*.dermengine.com https://*.gyantts.com/ https://*.intranet.osfnet.org/ https://*.kyruus.com/ https://*.mixpanel.com https://*.neurotrack.com/ https://*.neurotrack.io/ https://*.osfhealthcare.org/ https://*.skin.app https://*.stripe.com https://d2y285dhddzdli.cloudfront.net https://s3.amazonaws.com/assets.gyant.com/ wss://*.gyantts.com/;form-action https://central.mychart.org/MyChart/ 'self' https://*.appcues.com https://*.dermengine.com https://*.gyantts.com/ https://*.intranet.osfnet.org/ https://*.kyruus.com/ https://*.mixpanel.com https://*.neurotrack.com/ https://*.neurotrack.io/ https://*.osfhealthcare.org/ https://*.skin.app https://*.stripe.com https://*.zipnosis.com/ https://d2y285dhddzdli.cloudfront.net https://s3.amazonaws.com/assets.gyant.com/ wss://*.gyantts.com/;media-src https://* 'self' blob: https://*.appcues.com https://*.dermengine.com https://*.gyantts.com/ https://*.intranet.osfnet.org/ https://*.kyruus.com/ https://*.mixpanel.com https://*.neurotrack.com/ https://*.neurotrack.io/ https://*.osfhealthcare.org/ https://*.skin.app https://*.stripe.com https://d2y285dhddzdli.cloudfront.net https://s3.amazonaws.com/assets.gyant.com/ wss://*.gyantts.com/; 1 default-src 'self'; style-src 'self' 'unsafe-inline' https://*.typekit.net https://fonts.googleapis.com https://cdn.jsdelivr.net https://*.gstatic.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://*.google.com https://*.googletagmanager.com https://*.google-analytics.com https://*.googleapis.com https://*.loginwithamazon.com https://*.doubleclick.net https://cdn-cookieyes.com https://js.hs-scripts.com https://js.hs-banner.com https://js.usemessages.com https://js.hsadspixel.net https://js.hs-analytics.net https://snap.licdn.com https://*.zdassets.com https://*.facebook.net https://*.c-ctrip.com https://*.quantummetric.com https://*.scriptcdn.net https://*.alipayobjects.com https://*.navahididi.com https://cdn.brightwrite.com https://cdn.brightwrite-staging.com https://*.fullstory.com https://fullstory.com https://*.xcover.com; connect-src 'self' https://*.sentry.io https://sentry.io https://*.amazonaws.com https://*.amazon.com https://*.google.com https://google.com https://*.google.com.au https://*.google.com.br https://*.google.com.co https://*.google.com.mt https://*.google.com.mx https://*.google.com.sg https://*.google.com.sv https://*.google.com.ph https://*.googleapis.com https://*.google-analytics.com https://*.google.ae https://*.google.at https://*.google.be https://*.google.ch https://*.google.cz https://*.google.de https://*.google.es https://*.google.fr https://*.google.hu https://*.google.ie https://*.google.it https://*.google.nl https://*.google.no https://*.google.pl https://*.google.pt https://*.google.co.id https://*.google.co.jp https://*.google.co.kr https://*.google.com.my https://*.google.com.tr https://*.google.com.tw https://*.google.co.uk https://*.google.co.za https://*.doubleclick.net https://*.linkedin.com https://*.hubapi.com https://*.cookieyes.com https://cdn-cookieyes.com https://*.brightwrite.com https://brightwrite-data.com https://*.fullstory.com https://*.hubspot.com https://*.adyen.com https://*.zdassets.com https://*.xcover.com https://*.covergenius.biz https://*.zendesk.com https://*.hsforms.com blob: https://browser-intake-datadoghq.eu https://*.datadoghq.eu; img-src 'self' https: data:; font-src 'self' https: data:; frame-src 'self' https://*.google.com https://*.googletagmanager.com https://*.amazon.com https://*.doubleclick.net https://*.adyen.com https://*.web.app https://*.xcover.com; upgrade-insecure-requests; report-uri https://csp-report.browser-intake-datadoghq.eu/api/v2/logs?dd-api-key=pube2daa5996f2fad21d085fd09ecccdd5d&dd-evp-origin=content-security-policy&ddsource=csp-report&ddtags=service%3Axcover-website%2Ccluster-group%3Axcover%2Cenv%3Aproduction 1 font-src fonts.gstatic.com use.typekit.net *.gstatic.com data: d1hcctelsiwksg.cloudfront.net mcstaging-cdn.lilyanncabinets.com dk5s5cje1o3yr.cloudfront.net *.answerbase.com *.static.klaviyo.com *.static-tracking.klaviyo.com *.klaviyo.com *.fontawesome.com https://fonts.gstatic.com https://www.google.com https://www.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com *.freshmarketer.com *.answerbase.com *.static.klaviyo.com *.static-tracking.klaviyo.com *.klaviyo.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.certcapture.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.demdex.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com www.google.com *.certcapture.com *.getbread.com *.breadpayments.com *.rbcpayplan.com *.hotjar.com www.facebook.com *.pinterest.com *.g.doubleclick.net *.zinrelo.com *.google.com *.google.co.in *.freshchat.com *.freshmarketer.com *.adroll.com panorama.2020.net *.ampproject.org *.answerbase.com *.static.klaviyo.com *.static-tracking.klaviyo.com *.klaviyo.com *.lilyanncabinets.com *.lilyanncabinets.local c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com *.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.demdex.net searchautocompleteqa.magento-datasolutions.com lilyanncabinets.local t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net data: *.certcapture.com *.getbread.com *.breadpayments.com *.rbcpayplan.com *.visualwebsiteoptimizer.com bat.bing.com *.bing.com www.google.co.in *.facebook.com *.facebook.net *.pinterest.com cdn.pushcrew.com *.magecomp.com *.googletagmanager.com *.shopperapproved.com *.clarity.ms *.lilyanncabinets.com *.cloudfront.net *.amazonaws.com *.adroll.com d1hcctelsiwksg.cloudfront.net mcstaging-cdn.lilyanncabinets.com pixel.rubiconproject.com pixel.advertising.com sync.outbrain.com sync.taboola.com eb2.3lift.com dsum-sec.casalemedia.com image2.pubmatic.com ups.analytics.yahoo.com dk5s5cje1o3yr.cloudfront.net *.ytimg.com *.pinimg.com *.heatmap.it *.gstatic.com maps.googleapis.com *.hotjar.io *.hotjar.com *.answerbase.com *.static.klaviyo.com *.static-tracking.klaviyo.com *.klaviyo.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com store.paradoxlabs.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com searchautocompleteqa.magento-datasolutions.com lilyanncabinets.local livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ www.google.com assets.adobedtm.com *.magento-datasolutions.com *.magento-ds.com *.certcapture.com *.getbread.com *.breadpayments.com *.rbcpayplan.com bat.bing.com *.woopra.com chimpstatic.com dev.visualwebsiteoptimizer.com cdn.pushcrew.com connect.facebook.net s.pinimg.com apis.google.com *.freshchat.com *.freshmarketer.com www.gstatic.com *.googletagmanager.com *.clarity.ms *.smartlook.com *.cardinalcommerce.com *.shopperapproved.com *.googlecommerce.com *.zinrelo.com *.cloudfront.net webmoder.space *.adroll.com *.hotjar.com d1hcctelsiwksg.cloudfront.net mcstaging-cdn.lilyanncabinets.com *.pinterest.com dk5s5cje1o3yr.cloudfront.net downloads.mailchimp.com mc.us2.list-manage.com ajax.googleapis.com *.heatmap.it *.fw-cdn.com *.klaviyo.com maps.googleapis.com https://analytics.tiktok.com *.fwusercontent.com *.ampproject.org *.answerbase.com cdn.skypack.dev *.static.klaviyo.com *.static-tracking.klaviyo.com *.cdnjs.cloudflare.com *.ttwstatic.com fw-cdn.com https://s.pinimg.com data-management-external.magento-ds.com *.lilyanncabinets.local *.gstatic.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.list-manage.com *.googleapis.com *.google.com *.authorize.net js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net searchautocompleteqa.magento-datasolutions.com lilyanncabinets.local *.magento-datasolutions.com *.magento-ds.com *.certcapture.com cdn.pushcrew.com *.freshchat.com *.freshmarketer.com d1hcctelsiwksg.cloudfront.net mcstaging-cdn.lilyanncabinets.com *.adroll.com *.pinterest.com dk5s5cje1o3yr.cloudfront.net downloads.mailchimp.com mc.us2.list-manage.com *.hotjar.io *.hotjar.com *.answerbase.com *.static.klaviyo.com *.static-tracking.klaviyo.com *.klaviyo.com *.ttwstatic.com *.shopperapproved.com *.fontawesome.com *.gstatic.com https://static.klaviyo.com *.googleapis.com *.google.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net searchautocompleteqa.magento-datasolutions.com lilyanncabinets.local https://lilyanncabinets.com *.cdninstagram.com *.amazonaws.com d1hcctelsiwksg.cloudfront.net mcstaging-cdn.lilyanncabinets.com *.lilyanncabinets.com dk5s5cje1o3yr.cloudfront.net *.answerbase.com *.static.klaviyo.com *.static-tracking.klaviyo.com *.klaviyo.com 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com searchautocompleteqa.magento-datasolutions.com lilyanncabinets.local 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com searchautocompleteqa.magento-datasolutions.com lilyanncabinets.local livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.magento.com performance.typekit.net *.magento-datasolutions.com *.magento-ds.com *.adobe.io *.certcapture.com *.getbread.com *.breadpayments.com *.rbcpayplan.com *.klaviyo.com *.visualwebsiteoptimizer.com *.clarity.ms ct.pinterest.com *.doubleclick.net *.cardinalcommerce.com *.google-analytics.com *.smartlook.cloud *.smartlook.com *.demdex.net *.chimpstatic.com *.facebook.com *.woopra.com *.hotjar.com *.hotjar.io ws34.hotjar.com *.adroll.com *.pinterest.com d1hcctelsiwksg.cloudfront.net mcstaging-cdn.lilyanncabinets.com *.lilyanncabinets.com *.lilyanncabinets.local dk5s5cje1o3yr.cloudfront.net *.freshmarketer.com maps.googleapis.com ws23.hotjar.com *.tiktok.com *.fw-cdn.com *.fwusercontent.com *.ampproject.org *.answerbase.com *.google.co.in *.googleadservices.com *.algolia.io prod-init.100ms.live wss://*.100ms.live wss://rts-us-fcht.freshworksapi.com *.static.klaviyo.com *.static-tracking.klaviyo.com *.app.zinrelo.com wss://*.hotjar.com www.google.com https://google.com bat.bing.com *.bing.com *.breadgateway.net data-management-external.magento-ds.com *.gstatic.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ http://dpm.demdex.net https://www.google.com https://www.gstatic.com *.authorize.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.google.com google.com 'self' 'unsafe-inline'; child-src *.certcapture.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net searchautocompleteqa.magento-datasolutions.com lilyanncabinets.local *.getbread.com *.chimpstatic.com *.cloudfront.net *.adroll.com *.pinterest.com *.klaviyo.com *.hotjar.io *.hotjar.com ws23.hotjar.com *.fw-cdn.com *.ampproject.org *.answerbase.com *.static.klaviyo.com *.static-tracking.klaviyo.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 object-src 'none'; base-uri 'self'; script-src 'self' 'nonce-COlGfJyr6JyPO_JkZQwtkg' 'unsafe-inline' 'unsafe-eval' https://*.msauth.net https://*.msftauth.net https://*.msftauthimages.net https://*.msauthimages.net https://*.msidentity.com https://*.microsoftonline-p.com https://*.microsoftazuread-sso.com https://*.azureedge.net https://*.outlook.com https://*.office.com https://*.office365.com https://*.microsoft.com https://*.bing.com 'report-sample'; report-uri https://csp.microsoft.com/report/ESTS-UX-All 1 report-uri /api/v1/csp/violation; script-src https://*.intercom.io https://js.intercomcdn.com https://www.google-analytics.com 'unsafe-inline' https://optimize.google.com 'self' https://widget.trustpilot.com https://cdn.segment.com https://*.typekit.net https://www.googletagmanager.com https://cdn.mxpnl.com https://*.fullstory.com https://fullstory.com https://connect.facebook.net https://ajax.googleapis.com https://js.stripe.com https://bat.bing.com https://www.googleadservices.com 'unsafe-eval'; plugin-types application/pdf; frame-ancestors 'none'; child-src https://share.intercom.io https://intercom-sheets.com https://www.youtube.com https://player.vimeo.com https://fast.wistia.net https://*.doubleclick.net https://js.stripe.com; font-src https://js.intercomcdn.com https://fonts.gstatic.com 'self' https://*.typekit.net; media-src https://js.intercomcdn.com 'self'; base-uri 'none'; connect-src https://*.intercom.io wss://*.intercom.io https://uploads.intercomcdn.com https://uploads.intercomusercontent.com https://app.getsentry.com 'self' https://www.google-analytics.com https://*.doubleclick.net https://api.mixpanel.com https://*.fullstory.com https://*.typekit.net https://api.segment.io https://adservice.google.com https://*.launchdarkly.com; form-action 'self'; style-src 'unsafe-inline' https://optimize.google.com https://fonts.googleapis.com 'self' https://*.cloudfront.net https://*.typekit.net; object-src 'self'; default-src 'none'; frame-src https://optimize.google.com https://js.stripe.com https://*.doubleclick.net; img-src https://*.intercomcdn.com https://static.intercomassets.com https://uploads.intercomusercontent.com https://www.google-analytics.com https://optimize.google.com https: data: 1 font-src data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ js.mollie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com https://www.mollie.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ chimpstatic.com downloads.mailchimp.com *.list-manage.com js.mollie.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com downloads.mailchimp.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 frame-ancestors 'self'; report-uri https://www.townsvillebulletin.com.au/csp-reports 1 default-src 'self' https://d3f6h8s0w402y5.cloudfront.net; script-src 'self' 'unsafe-inline' 'unsafe-eval' www.googletagmanager.com seal.digicert.com widget.trustpilot.com cdn.what3words.com cdn.evgnet.com walls.io l.getsitecontrol.com guidedrec.preferabli.com www.google.com www.gstatic.com services.postcodeanywhere.co.uk c1.rfihub.net d3f6h8s0w402y5.cloudfront.net www.tag4arm.com snap.licdn.com static.ads-twitter.com cdn.taboola.com s.pinimg.com connect.facebook.net smct.co s.yimg.com static.chartbeat.com assets.apollo.io client.prod.mplat-ppcprotect.com cdn.datalabsgroup.com cdnjs.cloudflare.com www.googleadservices.com googleads.g.doubleclick.net 6261229.collect.igodigital.com trc.taboola.com bat.bing.com s2.getsitecontrol.com ct.pinterest.com apis.google.com accounts.google.com a.img-statics.com service.force.com d.la11-core1.sfdc-cehfhs.salesforceliveagent.com d.la1-c1-cdg.salesforceliveagent.com static.lightning.force.com virginwines.my.salesforce-sites.com www.fastuktrack.com apps.rokt.com virginwines.my.salesforce.com s.kk-resources.com blob: netfree.link secured-pixel.com data1.klastaf.com js.braintreegateway.com assets.braintreegateway.com songbird.cardinalcommerce.com c.paypal.com www.paypal.com *.webtrends-optimize.com *.webtrends-optimize.workers.dev *.azurewebsites.net *.contentsquare.net app.contentsquare.com *.tradedoubler.com a.imgstatics.com apis.google.com accounts.google.com *.googleapis.com xzdeav5g.micpn-eu.com analytics.tiktok.com analytics-ipv6.tiktokw.us ads.tiktok.com; style-src 'self' 'unsafe-inline' fonts.googleapis.com guidedrec.preferabli.com services.postcodeanywhere.co.uk d3f6h8s0w402y5.cloudfront.net service.force.com virginwines.my.salesforce-sites.com virginwines.my.salesforce.com *.webtrends-optimize.com *.webtrends-optimize.workers.dev; frame-src 'self' *; connect-src 'self' l.getsitecontrol.com region1.google-analytics.com api-js.mixpanel.com services.postcodeanywhere.co.uk api.preferabli.com guidedrec.preferabli.com px.ads.linkedin.com region1.analytics.google.com bat.bing.com c.contentsquare.net 6261229.collect.igodigital.com www.tag4arm.com stats.g.doubleclick.net psb.taboola.com click.prod.mplat-ppcprotect.com aplo-evnt.com api.ipify.org ct.pinterest.com events.getsitectrl.com srm.ba.contentsquare.net s.yimg.com trc-events.taboola.com k-aeu1.contentsquare.net pclick.prod.mplat-ppcprotect.com zu7k3v809b.execute-api.eu-west-1.amazonaws.com www.facebook.com s.kelkoogroup.net virginwines.my.salesforce-sites.com trc.taboola.com apis.google.com analytics.google.com www.google.co.uk www.google-analytics.com ad.doubleclick.net a.imgstatics.com bat.bing.net api.privacy-protector-adblocker.com pagead2.googlesyndication.com api.braintreegateway.com client-analytics.braintreegateway.com *.braintree-api.com www.paypal.com *.cloudfront.net *.cardinalcommerce.com *.contentsquare.net *.contentsquare.com fonts.googleapis.com *.webtrends-optimize.com *.webtrends-optimize.workers.dev *.azurewebsites.net apis.google.com accounts.google.com *.googleapis.com https://www.google.com google.com 6abynomjpa.execute-api.eu-west-1.amazonaws.com www.googleadservices.com *.google.com *.pinterest.com kg668dbov0.execute-api.us-east-1.amazonaws.com api.what3words.com https://www.facebook.com *.doubleclick.net *.conviva.com analytics.tiktok.com analytics-ipv6.tiktokw.us ads.tiktok.com; font-src 'self' https: data:; img-src 'self' https: data: analytics.twitter.com t.co ad.doubleclick.net px.ads.linkedin.com *.webtrends-optimize.com *.contentsquare.net; report-to csp-collector; 1 default-src * 'unsafe-inline' 'unsafe-eval' data: blob:; report-uri https://www.miteksystems.com/report-uri/reportOnly 1 default-src *; script-src *; object-src *; style-src *; img-src *; media-src *; frame-src *; font-src *; connect-src * 1 default-src 'self'; child-src ad.ipredictive.com match.adsrvr.org; connect-src 'self' *; font-src 'self' data: fonts.gstatic.com use.typekit.net; frame-ancestors 'self'; frame-src ad.ipredictive.com c1.adform.net ct.pinterest.com https://fast.wistia.net https://pay.google.com https://www.loumalnatis.com insight.adsrvr.org lmgiftcardwebportal.azurewebsites.net match.adsrvr.org www.facebook.com www.google.com www.googletagmanager.com www.opentable.com www.youtube.com; img-src 'self' data: * ; media-src https://embed-ssl.wistia.com; object-src http://video.limelight.com; script-src 'self' 'unsafe-eval' 'unsafe-inline' *.googleusercontent.com cdn.segment.com cdnjs.cloudflare.com https://a2.adform.net https://analytics.tiktok.com https://cdn-cookieyes.com https://connect.facebook.net https://googleads.g.doubleclick.net https://js.adsrvr.org https://s.pinimg.com https://snap.licdn.com https://static.cloudflareinsights.com https://www.loumalnatis.com js.ipredictive.com pixel.byspotify.com s2.adform.net static-tracking.klaviyo.com static.klaviyo.com www.googletagmanager.com; script-src-attr 'unsafe-inline'; script-src-elem 'self' 'unsafe-inline' *.googleusercontent.com a2.adform.net ajax.googleapis.com analytics.tiktok.com api.tripleseat.com cdn-cookieyes.com cdn.segment.com cdnjs.cloudflare.com connect.facebook.net ct.pinterest.com googleads.g.doubleclick.net https://browser.sentry-cdn.com https://fast.wistia.com https://fast.wistia.net https://secure.myshopcouponmac.com https://www.loumalnatis.com js.adsrvr.org js.ipredictive.com maps.googleapis.com pixel.byspotify.com https://pixel.byspotify.com/ping.min.js https://pixel.byspotify.com s.pinimg.com s2.adform.net snap.licdn.com static-tracking.klaviyo.com static.cloudflareinsights.com static.klaviyo.com www.google.com www.googletagmanager.com www.gstatic.com; style-src 'self' 'unsafe-inline' fonts.googleapis.com https://p.typekit.net https://use.typekit.net https://www.loumalnatis.com; style-src-attr 'unsafe-inline'; style-src-elem 'self' 'unsafe-inline' fonts.googleapis.com https://static-tracking.klaviyo.com https://www.gstatic.com https://www.loumalnatis.com p.typekit.net static.klaviyo.com use.typekit.net; worker-src blob:; upgrade-insecure-requests; report-uri https://ec7450941579f753c1181c8512dda65e.report-uri.com/r/t/csp/reportOnly 1 default-src 'self'; script-src 'self' 'nonce-RandomString123456' https://metaswitch.com https://*.metaswitch.com 'strict-dynamic' 'nonce-PslV1BYUz/ARJamoVUvEAA=='; style-src 'self' 'nonce-RandomString123456' https://metaswitch.com https://*.metaswitch.com; img-src 'self' data: https://metaswitch.com https://*.metaswitch.com; font-src 'self' https://metaswitch.com https://*.metaswitch.com; connect-src 'self' https://metaswitch.com https://*.metaswitch.com; frame-src 'self' https://metaswitch.com https://*.metaswitch.com; object-src 'none'; base-uri 'self'; form-action 'self'; report-uri https://770a769bea45352cd46f7e284097b330.report-uri.com/r/d/csp/reportOnly 1 default-src 'self'; script-src 'unsafe-inline' 'unsafe-eval' 'self' https://*.googleapis.com https://www.google-analytics.com https://www.googleanalytics.com https://www.googleoptimize.com https://optimize.google.com *.google.com https://*.google.com https://*.googleusercontent.com https://*.ggpht.com https://googleads.g.doubleclick.net https://www.googletagmanager.com https://*.gstatic.com https://*.googleadservices.com http://s3.amazonaws.com https://snap.licdn.com https://connect.facebook.net https://www.facebook.com https://static.hotjar.com https://script.hotjar.com http://*.tiqcdn.com https://pageimprove.io https://*.linkedin.com https://partenamut.activehosted.com https://*.tealiumiq.com https://*.youtube.com https://*.decibelinsight.net https://wurfl.io https://bat.bing.com https://*.googlesyndication.com https://*.teads.tv https://*.clarity.ms/ https://dev.visualwebsiteoptimizer.com https://tags.partenamut.be/partenamut-site/prod/utag.sync.js https://tags.partenamut.be/partenamut-site/prod/utag.js https://tags.partenamut.be https://analytics.tiktok.com https://analytics.tiktok.com/i18n/pixel/events.js https://collect.partenamut.be; style-src 'unsafe-inline' 'self' https://*.googleapis.com https://fonts.googleapis.com https://optimize.google.com https://unpkg.com https://script.hotjar.com https://static.hotjar.com https://*.gstatic.com https://fonts.bunny.net; img-src 'self' https://*.googleapis.com https://*.gstatic.com https://*.google.com *.googleusercontent.com https://*.google.be https://*.google-analytics.com https://googleads.g.doubleclick.net https://*.linkedin.com https://*.partenamut.be https://*.facebook.com https://dummyimage.com https://placehold.co https://www.googletagmanager.com http://www.w3.org/2000/svg https://*.tealiumiq.com https://s535jira.mutworld.be https://flagcdn.com https://script.hotjar.com https://static.hotjar.com https://bat.bing.com https://ad.doubleclick.net https://*.teads.tv https://dev.visualwebsiteoptimizer.com https://tags.partenamut.be/partenamut-site/prod/utag.js https://*.clarity.ms https://c.bing.com https://www.google.com/pagead/form-data https://survey-images.hotjar.com data:; frame-src 'self' https://*.google.com https://optimize.google.com https://vars.hotjar.com/ https://*.youtube.com https://*.partenamut.be https://cloud.cavai.com/ www.facebook.com https://idp.iamfas.belgium.be/ https://td.doubleclick.net/ https://*.teads.tv/ https://td.doubleclick.net.x.ccf80dde0e0820444b0b8f9038e392127391.d045232a.id.opendns.com https://10649093.fls.doubleclick.net https://maternity-leave---partena.bubbleapps.io; font-src 'self' https://fonts.gstatic.com https://script.hotjar.com https://fonts.bunny.net; object-src 'self' data: 'unsafe-eval'; media-src 'self'; child-src 'self'; form-action 'self'; frame-ancestors 'self'; base-uri 'self'; navigate-to *; connect-src 'self' https://*.cloud.es.io https://*.googleapis.com *.google.com https://*.google.com https://*.google.com https://*.gstatic.com https://*.google-analytics.com https://*.facebook.com https://*.linkedin.oribi.io https://*.hotjar.io https://*.hotjar.com https://pageimprove.io https://*.tealiumiq.com https://*.decibelinsight.net wss://*.hotjar.com https://*.cloud.es.io https://bat.bing.com https://*.linkedin.com https://*.googlesyndication.com wss://*.decibelinsight.net https://wurfl.io https://*.g.doubleclick.net https://*.teads.tv https://*.clarity.ms/ https://dev.visualwebsiteoptimizer.com https://adservice.google.com https://www.google.com/pagead/form-data https://google.com/ccm/form-data/1035243604 https://google.com:433/ccm/form-data/1035243604 https://*.adservice.google.com https://adservice.google.com https://analytics.tiktok.com https://*.partenamut.be data: blob:; worker-src 'self' blob:;;report-uri https://mutualit.uriports.com/reports; report-to default 1 default-src amplitude.com *.amplitude.com cash.app *.cash.app cloudflare.com *.cloudflare.com cloudflareinsights.com *.cloudflareinsights.com datatables.net *.datatables.net doubleclick.net *.doubleclick.net google-analytics.com *.google-analytics.com google.com *.google.com googletagmanager.com *.googletagmanager.com jquery.com *.jquery.com paypal.com *.paypal.com sentry.io *.sentry.io tiny.cloud *.tiny.cloud tinymce.com *.tinymce.com citconpay.com *.citconpay.com facebook.net *.facebook.net google.co.uk *.google.co.uk kcp.co.kr *.kcp.co.kr ngrok-free.app *.ngrok-free.app sift.com *.sift.com 'unsafe-inline' 'unsafe-eval' 'self'; report-uri https://csp-reporting.cloudflare.com/cdn-cgi/script_monitor/report?m=radet6k.tBt72_nc7oFiEbidERW5eCuiOox_sQrzcxQ-1770430378.6922524-1.0.1.1-XhDqV4KnsqSh0wmDu9BE7jiJ6WEOa88GoO9aahFnq15ezRJ3CWYRR.K12SOl5rNbE.k4pQ9UFDafI4oLb5_g0R04bawXHyQROwGdLN6pZ0PBa7JBZt0muL1jLml5yahBO7edPsw3GgPlN6zCNjpv9TIi.Zul2xgJruL1PNyOMzyiHqZfOGBeBC39g9AXdLQN; report-to cf-euyxwpysvlratutt 1 font-src fonts.googleapis.com fonts.gstatic.com *.googleapis.com *.gstatic.com data: *.development.scalapay.com *.staging.scalapay.com *.scalapay.com *.easypack24.net *.klarnacdn.net *.fontawesome.com maxcdn.bootstrapcdn.com https://*.accessiblyapp.com https://*.accessibly.app https://*.dnafactory.it https://*.dnalab.online https://*.feedaty.com https://*.cloudflare.com https://*.scalapay.com https://*.oct8ne.com https://*.channelize.io data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://*.dnafactory.it https://*.dnalab.online https://*.feedaty.com https://*.cloudflare.com https://*.scalapay.com https://*.channelize.io *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com https://api.clerk.io https://cdn.clerk.io 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.google.com https://www.googletagmanager.com/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.klarna.com https://*.accessiblyapp.com https://*.accessibly.app https://*.dnafactory.it https://*.dnalab.online https://*.feedaty.com https://*.cloudflare.com https://*.scalapay.com https://*.channelize.io c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://images.unsplash.com maps.googleapis.com maps.gstatic.com *.gstatic.com *.googleapis.com https://cdn.clerk.io *.connectif.cloud *.feedaty.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ *.development.scalapay.com *.staging.scalapay.com *.scalapay.com cdn.doofinder.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.easypack24.net *.inpost.pl *.inpost.com *.openstreetmap.org *.klarna.com *.klarnaevt.com *.klarnacdn.net intpaye.netsgroup.com https://*.accessiblyapp.com https://*.accessibly.app https://*.dnafactory.it https://*.dnalab.online https://*.feedaty.com https://*.cloudflare.com https://*.clarity.ms https://*.bing.com https://*.awin1.com https://*.scalapay.com https://*.anticafarmaciaorlandi.it https://*.oct8ne.com https://*.google.it https://*.channelize.io www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com www.gstatic.com pay.google.com google.com/pay ecomms2s.sella.it sandbox.gestpay.net img.riskified.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.googleapis.com *.gstatic.com https://cdn.jsdelivr.net/npm/@ryangjchandler/spruce@2.x.x/dist/spruce.umd.js www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.channelize.io https://api.clerk.io https://cdn.clerk.io https://*.connectif.cloud *.feedaty.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ *.development.scalapay.com *.staging.scalapay.com *.scalapay.com cdn.doofinder.com chimpstatic.com downloads.mailchimp.com *.list-manage.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.inpost.pl *.inpost.it *.easypack24.net *.klarna.com *.klarnacdn.net *.klarnaservices.com *.avada.io https://*.clerk.io https://*.accessiblyapp.com https://*.accessibly.app https://*.dnafactory.it https://*.dnalab.online https://*.facebook.net https://*.feedaty.com https://*.cloudflare.com https://*.clarity.com https://*.clarity.ms https://*.outbrain.com https://*.onesignal.com https://*.dwin1.com https://*.gestpay.net https://*.scalapay.com https://*.iubenda.com https://*.oct8ne.com https://*.getblue.io https://*.channelize.io https://*.bing.com https://*.cookieless-data.com https://*.sddan.com https://*.airtable.com https://*.awin1.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com www.google.com www.gstatic.com beacon.riskified.com tracking.trovaprezzi.it www.trovaprezzi.it tps.trovaprezzi.it 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://api.clerk.io https://cdn.clerk.io *.feedaty.com *.development.scalapay.com *.staging.scalapay.com *.scalapay.com *.googleapis.com *.gstatic.com *.doofinder.com downloads.mailchimp.com geowidget.easypack24.net *.klarnacdn.net *.fontawesome.com maxcdn.bootstrapcdn.com https://*.accessiblyapp.com https://*.accessibly.app https://*.dnafactory.it https://*.dnalab.online https://*.feedaty.com https://*.cloudflare.com https://*.scalapay.com https://*.channelize.io unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://*.accessiblyapp.com https://*.accessibly.app https://*.dnafactory.it https://*.dnalab.online https://*.feedaty.com https://*.cloudflare.com https://*.scalapay.com https://*.channelize.io 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.googleapis.com *.channelize.io https://*.connectif.cloud *.feedaty.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ *.doofinder.com wss://*.doofinder.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.inpost.pl *.inpost.it *.easypack24.net *.klarnaevt.com *.klarnacdn.net *.klarna.com *.klarnaservices.com https://get.geojs.io *.avada.io *.paypal.com https://*.accessiblyapp.com https://*.accessibly.app https://*.dnafactory.it https://*.dnalab.online https://*.google.com https://google.com https://*.google-analytics.com https://*.feedaty.com https://*.cloudflare.com https://*.outbrain.com https://*.clarity.ms https://*.amplitude.com https://*.bing.com https://*.scalapay.com https://*.iubenda.com https://*.oct8ne.com https://*.channelize.io https://*.wepowerconnections.com https://*.sciencebehindecommerce.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.google.com google.com www.google.com www.gstatic.com pay.google.com google.com/pay ecomms2s.sella.it sandbox.gestpay.net c.riskified.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src www.paypalobjects.com cash-f.squarecdn.com https://www.gstatic.com https://fonts.gstatic.com 'self' 'self' data: https://*.tawk.to data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com * 'self' https://*.adyen.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com * https://www.googletagmanager.com/ https://*.google.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com 'self' https://consentcdn.cookiebot.com 'self' 'unsafe-inline'; img-src cdn.zitmaxx.nl https://pim.zitmaxx.nl assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com data: widgets.magentocommerce.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com * https://images.unsplash.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ www.googletagmanager.com magefan.com cm.magefan.com *.disqus.com https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.googleusercontent.com 'self' data: https: http: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com *.newrelic.com *.nr-data.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com *.cash.app *.visa.com *.mastercard.com applepay.cdn-apple.com https://cdn.ablyft.com https://maps.googleapis.com https://player.vimeo.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ *.disqus.com https://www.google.com https://www.gstatic.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com https://cdn.jsdelivr.net 'self' 'unsafe-inline' 'unsafe-eval' https://*.google-analytics.com https://www.googletagmanager.com https://www.googleoptimize.com https://*.tawk.to https://secure.adnxs.com https://*.expivi.net d5yoctgpv4cpx.cloudfront.net https://consent.cookiebot.com https://consentcdn.cookiebot.com https://sst.zitmaxx.nl 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.cash.app https://fonts.googleapis.com https://hcaptcha.com https://*.hcaptcha.com https://cdn.jsdelivr.net 'self' 'unsafe-inline' https://*.tawk.to https://*.expivi.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src https://pim.zitmaxx.nl dpm.demdex.net amcglobal.sc.omtrdc.net *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com * https://maps.googleapis.com https://player.vimeo.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ https://ipinfo.io https://*.google.com https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com 'self' https://*.google-analytics.com wss://*.tawk.to rkkck31tec.execute-api.eu-central-1.amazonaws.com https: 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.fontawesome.com maxcdn.bootstrapcdn.com 'unsafe-inline' data: *.gstatic.com 'self' data: www.designsbyjuju.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com pinterest.com www.pinterest.com ct.pinterest.com *.authorize.net *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * www.designsbyjuju.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.certcapture.com *.authorize.net www.designsbyjuju.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.google.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com pinterest.com www.pinterest.com ct.pinterest.com *.certcapture.com https://www.googletagmanager.com/ *.authorize.net c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * https://www.youtube.com https://c.paypal.com/ *.weltpixel.com www.designsbyjuju.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com pinterest.com www.pinterest.com ct.pinterest.com *.certcapture.com store.paradoxlabs.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com https://b.stats.paypal.com/ https://slc.stats.paypal.com/ https://c.paypal.com/ 'self' data: blog.designsbyjuju.com www.designsbyjuju.com *.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.google.com/recaptcha/ www.gstatic.com/recaptcha/ www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com pinterest.com www.pinterest.com s.pinimg.com *.attn.tv events.attentivemobile.com *.certcapture.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ player.vimeo.com *.authorize.net js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.fontawesome.com *.google-analytics.com https://bam.nr-data.net https://bam-cell.nr-data.net https://c.paypal.com *.google.com *.gstatic.com embedsocial.com sec.webeyez.com https://www.googletagmanager.com tagmanager.google.com www.designsbyjuju.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.certcapture.com *.fontawesome.com maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com *.googleapis.com *.gstatic.com embedsocial.com tagmanager.google.com www.designsbyjuju.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com pinterest.com www.pinterest.com ct.pinterest.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ www.designsbyjuju.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com pinterest.com www.pinterest.com ct.pinterest.com *.attn.tv events.attentivemobile.com *.certcapture.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ *.authorize.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.google-analytics.com https://bam.nr-data.net https://bam-cell.nr-data.net https://payments.sandbox.braintree-api.com/ https://origin-analytics-sand.sandbox.braintree-api.com/ send.webeyez.com sec.webeyez.com cognito-identity.eu-west-1.amazonaws.com firehose.eu-west-1.amazonaws.com https://www.google-analytics.com www.designsbyjuju.com 'self' 'unsafe-inline'; child-src *.certcapture.com assets.braintreegateway.com c.paypal.com *.paypal.com www.designsbyjuju.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com www.designsbyjuju.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://smartsolutions.report-uri.com/r/d/csp/reportOnly; report-to report-endpoint; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.userway.org *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: *.ftcdn.net *.behance.net *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.paypal.com *.typekit.net *.gstatic.com https://images.unsplash.com *.userway.org *.automann.com *.google.com *.googleadservices.com *.google-analytics.com *.googletagmanager.com magefan.com cm.magefan.com https://firebasestorage.googleapis.com *.pixriot.com *.storeimaging.com data: 'self' 'unsafe-inline'; style-src *.adobe.com fonts.googleapis.com *.userway.org *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; connect-src *.clarity.ms dpm.demdex.net amcglobal.sc.omtrdc.net *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.adobe.io performance.typekit.net *.sentry.io www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io https://maps.googleapis.com https://player.vimeo.com *.userway.org *.amazonaws.com wss://transcribestreaming.us-east-1.amazonaws.com:8443 *.google-analytics.com *.analytics.google.com *.googletagmanager.com stats.g.doubleclick.net https://get.geojs.io *.avada.io webservices.purolator.com devwebservices.purolator.com *.pixriot.com *.storeimaging.com 'self' 'unsafe-inline'; frame-src automann-scanner.global.ssl.fastly.net fast.amc.demdex.net *.adobe.com *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com player.vimeo.com https://www.google.com/recaptcha/ bid.g.doubleclick.net *.braintreegateway.com *.paypal.com google.com *.google.com *.livechatinc.com *.userway.org www.googletagmanager.com webservices.purolator.com devwebservices.purolator.com 'self' 'unsafe-inline'; script-src *.clarity.ms *.cloudfront.net assets.adobedtm.com *.adobe.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://cdn.jsdelivr.net/ https://maps.googleapis.com browser-update.org *.userway.org *.livechatinc.com connect.facebook.net *.googletagmanager.com *.googleadservices.com *.google-analytics.com *.avada.io *.shopify.com 'self' 'unsafe-inline' 'unsafe-eval'; 1 default-src 'self';base-uri 'self';frame-ancestors 'self';frame-src https://* 'self' epichttp: https://kelseyseyboldepiciframe-pp-prtl.spectrumretailnet.com;script-src 'nonce-10ab2bb62b774c6287050c3872f7d408' https://mykelseyonline.com 'self' 'unsafe-eval' https://play.vidyard.com/ repo-stg.rakanto.com repo.rakanto.com;img-src https://* 'self' blob: data:;connect-src 'self' cse.rakanto.com epichttp: https://stage-cse.rakanto.com www.google.com;style-src https://mykelseyonline.com 'self' 'unsafe-inline' www.gstatic.com;worker-src 'self' blob:;child-src 'self' blob:;form-action https://central.mychart.org/MyChart/ 'self';media-src https://* 'self' blob:;report-uri /MkoApi/api/CspReport; 1 default-src 'self'; font-src 'self' fonts.gstatic.com; img-src 'self' cdn.conservadoresdigitales.cl www.google-analytics.com www.googletagmanager.com; script-src 'self' www.googletagmanager.com www.google-analytics.com www.gstatic.com www.google.com ajax.googleapis.com analytics.google.com; style-src 'self' inline fonts.googleapis.com; frame-ancestors 'self' 1 default-src 'self' 'unsafe-inline' 'unsafe-eval' *.thuis.nl *.camcammer.com *.sensemakers.com *.test.paysafe.com *.cloudflare.com *.exoclick.com cdn.pushcrew.com *.ingest.sentry.io *.paysafe.com *.google.com *.google.nl *.google.sr *.google.be *.google.gr *.google.fr *.google-analytics.com stats.g.doubleclick.net *.doubleclick.net *.slack-edge.com *.googletagmanager.com analytics.sensemakers.nl *.hotjar.com *.hotjar.io; connect-src 'self' 'unsafe-inline' 'unsafe-eval' wss://*.thuis.nl/ wss://*.sensemakers.com wss://ws.hotjar.com/ *.sensemakers.com stats.g.doubleclick.net *.ingest.sentry.io analytics.sensemakers.nl *.google.com *.google.nl *.google.sr *.google.be *.google.gr *.google.fr *.analytics.google.com stats.g.doubleclick.net *.hotjar.io *.hotjar.com *.test.paysafe.com *.paysafe.com *.thuis.nl *.google-analytics.com; img-src * 'self' data: https: blob: https; font-src * 'self' data:; report-uri https://analytics.sensemakers.nl/csp/ 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com *.cloudflare.com *.twitter.com *.twimg.com *.trustedshops.com *.googleapis.com *.versapay.com *.paynup.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.twitter.com *.versapay.com *.paynup.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com 'self' 'unsafe-inline'; frame-ancestors *.certcapture.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.demdex.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.certcapture.com *.twitter.com *.paynup.com *.versapay.com *.dotdigital-pages.com *.dotdigital.com webchat.dotdigital.com webchat.staging.dotdigital.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.weltpixel.com *.googletagmanager.com *.doubleclick.net *.typeform.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net data: *.certcapture.com *.amazonaws.com *.google.co.in t.co.in t.co *.cloudflare.com *.klarna.com *.googleadservices.com *.google-analytics.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.versapay.com *.paynup.com *.trackedlink.net magefan.com cm.magefan.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com maps.gstatic.com *.facebook.com *.reddit.com *.ads-twitter.com *.bing.com *.bing.net *.klaviyo.com *.pinterest.com *.pinimg.com *.clarity.ms *.googletagmanager.com *.doubleclick.net *.google.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net assets.adobedtm.com *.adobe.io *.commerce-payment-services.com commerce-payments-sdk.adobe.io *.magento-ds.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.magento-datasolutions.com https://rum.hlx.page *.certcapture.com *.ads-twitter.com *.pinimg.com *.qualtrics.com *.hotjar.com *.pinterest.com *.cloudflare.com *.twitter.com *.google-analytics.com *.twimg.com *.gstatic.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.versapay.com *.paynup.com *.datadoghq.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal webchat.dotdigital.com webchat.staging.dotdigital.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com maps.googleapis.com *.googletagmanager.com *.googleadservices.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.bing.com *.clarity.ms *.klaviyo.com sc-static.net *.snapchat.com unpkg.com *.doubleclick.net *.typeform.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.magento-datasolutions.com *.magento-ds.com *.certcapture.com *.cloudflare.com *.googleapis.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.versapay.com *.paynup.com webchat.dotdigital.com webchat.staging.dotdigital.com assets.braintreegateway.com *.tagmanager.google.com *.googletagmanager.com *.typeform.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.magento-datasolutions.com *.magento-ds.com *.certcapture.com *.pinterest.com *.googleapis.com *.qualtrics.com *.hotjar.com *.hotjar.io stats.g.doubleclick.net wss://ws.hotjar.com *.google.co.in *.cloudflare.com *.twitter.com *.twimg.com *.versapay.com *.paynup.com *.datadoghq.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com maps.googleapis.com *.google-analytics.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.pinimg.com sc-static.net *.snapchat.com *.doubleclick.net *.run.app *.typeform.com 'self' 'unsafe-inline'; child-src *.certcapture.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri http://127.0.0.1/magento_os/; report-to report-endpoint; 1 default-src 'none' ; img-src 'self' data: https://blob.userflow.com https://cdn.userflow.com https://js.userflow.com https://storage.googleapis.com/studio1-prod-blob/ * ; connect-src 'self' https://browser-intake-datadoghq.eu https://rum.browser-intake-datadoghq.eu https://logs.browser-intake-datadoghq.eu https://session-replay.browser-intake-datadoghq.eu https://api.analytics.pigment.app https://cdn.analytics.pigment.app https://auth.pigment.app https://staging-login.pigment.app wss://pigment.app wss://e.userflow.com https://cdn.userflow.com https://e.userflow.com https://js.userflow.com https://rs.fullstory.com wss://rs.fullstory.com https://edge.fullstory.com https://global.oktacdn.com https://api.segment.io https://cdn.segment.com https://api.maptiler.com https://api.vitally-eu.io https://app.vitally-eu.io https://use.typekit.net https://fonts.googleapis.com https://fonts.gstatic.com cdn.vitally-eu.io ; script-src 'self' cdn.analytics.pigment.app edge.fullstory.com rs.fullstory.com js.userflow.com cdn.userflow.com cdn.announcekit.app cdn.segment.com cdn.vitally-eu.io ; frame-src announcekit.co auth.pigment.app staging-login.pigment.app https://fast.wistia.net pigmentforms.typeform.com ; style-src 'self' 'unsafe-inline' js.userflow.com cdn.userflow.com fonts.googleapis.com cdn.announcekit.co https://use.typekit.net https://p.typekit.net ; worker-src blob: ; font-src 'self' https://use.typekit.net fonts.gstatic.com data: ; manifest-src 'self' ; object-src 'none' ; media-src https://blob.userflow.com https://cdn.userflow.com https://storage.googleapis.com/studio1-prod-blob/ ; frame-ancestors https://pigment7-dev-ed.develop.lightning.force.com/ https://pigment7-dev-ed--c.develop.vf.force.com/ https://wiki.klarna.net/ ; base-uri 'self' ; form-action https://announcekit.co ; report-uri https://pigment.uriports.com/reports/report ; report-to report ; 1 default-src 'self'; script-src 'self' https://vercel.live https://static.hotjar.com https://script.hotjar.com https://www.googletagmanager.com https://beacon.riskified.com https://static.moonpay.com https://cdn.checkout.com https://s3.tradingview.com https://static.zdassets.com https://cdn.gsght.com https://connect.facebook.net https://www.google-analytics.com https://www.redditstatic.com 'unsafe-inline'; style-src 'self' 'unsafe-inline'; connect-src 'self' * https://listing-api.openloot.com https://vault-api.openloot.com https://auth-api.openloot.com https://www.google-analytics.com; frame-src 'self' https://vercel.live https://export.turnkey.com/ https://auth.turnkey.com/ https://alchemy-rpc.dev.bigtimestudios.net https://s3.tradingview.com https://www.tradingview-widget.com https://buy.moonpay.com https://buy-sandbox.moonpay.com https://www.googletagmanager.com; img-src 'self' https: data:; media-src 'self' https:; font-src 'self' data:; object-src 'none'; base-uri 'self'; form-action 'self' https://auth-api.openloot.com/oauth/v1/decision https://bigtime720.activehosted.com/proc.php; frame-ancestors 'self'; report-uri https://vault-api.openloot.com/v2/csp-report; report-to csp-endpoint; 1 font-src fonts.googleapis.com fonts.gstatic.com https://geowidget.easypack24.net *.spotify.com *.cepd.tech *.drogerienatura.pl *.gstatic.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com https://geowidget-app.inpost.pl/ secure.payu.com merch-prod.snd.payu.com *.spotify.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://images.unsplash.com maps.googleapis.com maps.gstatic.com *.salesmanago.pl *.salesmanago.es *.salesmanago.com *.googletagmanager.com *.google-analytics.com ssl.gstatic.com www.gstatic.com https://geowidget.easypack24.net *.easypack24.net *.inpost.pl *.openstreetmap.org static.payu.com https://img.youtube.com *.spotify.com *.cepd.tech *.drogerienatura.pl *.syndigo.cloud trustmate.io cdn.cookiesaur.com google.pl *.google.pl visitor.omnitagjs.com sync.addlv.smt.docomo.ne.jp hbx.media.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.hsforms.net *.hsforms.com 'self' data: data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://cdn.jsdelivr.net/npm/@ryangjchandler/spruce@2.x.x/dist/spruce.umd.js maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.salesmanago.pl *.salesmanago.es *.salesmanago.com *.googletagmanager.com tagmanager.google.com https://geowidget.easypack24.net *.easypack24.net *.inpost.pl *.openstreetmap.org secure.payu.com secure.snd.payu.com pay.google.com applepay.cdn-apple.com https://scripts.luigisbox.tech https://cdn.luigisbox.tech https://live.luigisbox.tech https://api.luigisbox.tech s7.addthis.com *.spotify.com *.cookiesaur.com *.jsdelivr.net *.cloudflare.com *.syndigo.com *.cepd.tech *.drogerienatura.pl *.newrelic.com *.nr-data.net trustmate.io static.hotjar.com tags.creativecdn.com connect.facebook.net s2.adform.net script.hotjar.com track.adform.net js.braintreegateway.com assets.braintreegateway.com c.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.hsforms.net *.hsforms.com *.google.com *.gstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com tagmanager.google.com fonts.google.com https://geowidget.easypack24.net https://geowidget.inpost.pl https://scripts.luigisbox.tech https://cdn.luigisbox.tech https://live.luigisbox.tech https://api.luigisbox.tech *.spotify.com *.cloudflare.com *.cepd.tech *.drogerienatura.pl trustmate.io unsafe-inline assets.braintreegateway.com *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com https://geowidget.easypack24.net 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.salesmanago.pl *.salesmanago.es *.salesmanago.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com *.easypack24.net *.inpost.pl *.openstreetmap.org secure.payu.com merch-prod.snd.payu.com https://scripts.luigisbox.tech https://cdn.luigisbox.tech https://live.luigisbox.tech https://api.luigisbox.tech ekr.zdassets.com/ *.spotify.com *.cookiesaur.com *.syndigo.com trustmate.io *.newrelic.com *.nr-data.net *.cepd.tech *.drogerienatura.pl ams.creativecdn.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com t.elasticsuite.io *.hsforms.net *.hsforms.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.salesmanago.pl *.salesmanago.es *.salesmanago.com *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.gstatic.com *.googleapis.com https://client.crisp.chat https://fonts.gstatic.com https://ws.colissimo.fr https://applepay.cdn-apple.com applepay.cdn-apple.com *.fontawesome.com https://fonts.bunny.net fonts.googleapis.com fonts.gstatic.com https://cdnjs.cloudflare.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com https://connect-v2.fintecture.com https://connect-v2-sbx.fintecture.com *.monetico-services.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.google.com https://www.youtube.com https://form.typeform.com *.payplug.com *.dalenys.com https://applepay.cdn-apple.com *.monetico-services.com api-qa.payplug.com secure-qa.payplug.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com https://flagcdn.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.google.com *.gstatic.com *.doubleclick.net *.imgix.net *.twic.pics *.googleapis.com https://images.unsplash.com a.tile.openstreetmap.org b.tile.openstreetmap.org c.tile.openstreetmap.org *.connectif.cloud https://image.crisp.chat https://assets.fintecture.com https://maps.googleapis.com https://maps.gstatic.com https://ws.colissimo.fr https://*.tile.openstreetmap.fr https://*.onyourmap.com https://google.fr https://secure-magenta.dalenys.com https://firebasestorage.googleapis.com https://www.magezon.com *.openstreetmap.org maps.googleapis.com maps.gstatic.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.hsforms.net *.hsforms.com 'self' data: data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.facebook.net *.facebook.com *.imgix.net *.axept.io *.googletagmanager.com *.google.com *.gstatic.com *.doubleclick.net *.googleapis.com https://maps.googleapis.com https://player.vimeo.com *.connectif.cloud https://client.crisp.chat https://www.google.com https://www.gstatic.com https://ws.colissimo.fr https://api.mapbox.com https://*.typeform.com https://secure-magenta.dalenys.com https://applepay.cdn-apple.com api-qa.payplug.com cdn-qa.payplug.com cdn.payplug.com https://widgets.rr.skeepers.io/ https://api-product-reviews.cxr.skeepers.io/ https://cl-ppr.rr.skeepers.io/ https://cl-pbr.cxr.skeepers.io/ applepay.cdn-apple.com https://cdn.payplug.com https://cdn-qa.payplug.com *.avada.io maps.googleapis.com maps.gstatic.com fonts.googleapis.com https://cdnjs.cloudflare.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.hsforms.net *.hsforms.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.googleapis.com *.googletagmanager.com fonts.googleapis.com https://client.crisp.chat https://fonts.googleapis.com https://ws.colissimo.fr https://api.mapbox.com https://*.typeform.com https://secure-magenta.dalenys.com *.fontawesome.com https://fonts.bunny.net https://cdnjs.cloudflare.com unsafe-inline assets.braintreegateway.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.facebook.com *.axept.io *.google-analytics.com *.google.com *.doubleclick.net *.googleapis.com https://maps.googleapis.com https://player.vimeo.com https://ws.colissimo.fr *.onyourmap.com https://*.mapbox.com *.connectif.cloud https://client.crisp.chat wss://client.relay.crisp.chat https://plugins.crisp.chat https://nominatim.openstreetmap.org https://*.onyourmap.com *.monetico-services.com https://widgets.rr.skeepers.io/ https://api-product-reviews.cxr.skeepers.io/ https://cl-ppr.rr.skeepers.io/ https://cl-pbr.cxr.skeepers.io/ https://get.geojs.io *.avada.io maps.googleapis.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com google.com t.elasticsuite.io *.hsforms.net *.hsforms.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.googleapis.com *.gstatic.com data: *.klarnacdn.net *.cdn-apple.com *.fontawesome.com https://www.google.com https://www.gstatic.com https://fonts.bunny.net *.development.scalapay.com *.staging.scalapay.com *.scalapay.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnaevt.com *.link.com *.amazon.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com www.google.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.klarna.com *.playground.klarna.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.stripe.com klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.gstatic.com *.googleapis.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.payments-amazon.com *.facebook.com *.bing.com *.coccinelle.com stileo.it *.cookiebot.com *.google.it *.klarnacdn.net *.klarnaservices.com *.playground.klarnaservices.com *.klarna.com *.klarnaevt.com *.worldline-solutions.com *.secured-by-ingenico.com https://firebasestorage.googleapis.com *.webtrekk.net *.wt-eu02.net https://fbc.wcfbc.net https://*.flx1.com/ https://dmp.adform.net/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.development.scalapay.com *.staging.scalapay.com *.scalapay.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://rum.hlx.page *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de kit.fontawesome.com *.cookiebot.com *.jsdelivr.net *.facebook.net *.clarity.ms *.bing.com glamipixel.com *.coccinelle.com *.rakuten.com *.rmtag.com *.criteo.com *.adobedtm.com *.cardinalcommerce.com *.doubleclick.net *.google.com *.r-data.net *.accelasearch.io *.klarnacdn.net *.klarnaservices.com *.playground.klarnaservices.com *.klarna.com x.klarnacdn.net *.cdn-apple.com *.avada.io https://responder.wt-safetag.com https://*.flx1.com/ https://www.googletagmanager.com https://*.gstatic.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.development.scalapay.com *.staging.scalapay.com *.scalapay.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarnaevt.com *.amazon.com *.link.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.klarnacdn.net *.gstatic.com *.fontawesome.com *.googleapis.com *.google.com https://fonts.bunny.net unsafe-inline assets.braintreegateway.com *.development.scalapay.com *.staging.scalapay.com *.scalapay.com *.stripe.network *.stripecdn.com *.amazon.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.cloudfront.net *.amazonaws.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.googleapis.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.cookiebot.com *.googlesyndication.com *.google-analytics.com *.doubleclick.net *.coccinelle.com *.criteo.com *.klarnaevt.com *.playground.klarnaevt.com *.klarnaservices.com *.playground.klarnaservices.com *.klarnacdn.net x.klarnacdn.net *.klarna.com *.worldline-solutions.com http://dpm.demdex.net https://www.google.com https://www.gstatic.com https://get.geojs.io *.avada.io https://*.flx1.com/ https://*.gstatic.com https://jamie.g.shortest-route.com https://*.googleapis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.stripe.com klarna.com *.link.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 img-src https://higherlogicdownload.s3.amazonaws.com/UNIFORMLAWS/ https://cdn.jsdelivr.net/jquery.slick/ https://higherlogic-holdingpen-us-east-1.s3.amazonaws.com/UNIFORMLAWS/ https://img.youtube.com/vi/ https://static.filestackapi.com/picker/ https://d2x5ku95bkycr3.cloudfront.net https://higherlogiclongterm.s3.amazonaws.com/UNIFORMLAWS/ blob: https://d132x6oi8ychic.cloudfront.net 'self'; style-src https://d132x6oi8ychic.cloudfront.net 'unsafe-inline' https://higherlogiccloudfront.s3.amazonaws.com https://cdn.jsdelivr.net/jquery.slick/ https://cdnjs.cloudflare.com/ajax/libs/prism/ https://d2x5ku95bkycr3.cloudfront.net/ https://ajax.googleapis.com/ajax/libs/jqueryui/ https://use.fortawesome.com/ https://static.filestackapi.com/picker/ https://fonts.googleapis.com/ https://d3uf7shreuzboy.cloudfront.net/ https://higherlogic-holdingpen-us-east-1.s3.amazonaws.com/UNIFORMLAWS/ https://higherlogicdownload.s3.amazonaws.com/UNIFORMLAWS/ https://higherlogiclongterm.s3.amazonaws.com/UNIFORMLAWS/ 'self'; font-src https://fonts.googleapis.com/ https://fonts.gstatic.com/ https://cdn.jsdelivr.net/jquery.slick/ https://higherlogiccloudfront.s3.amazonaws.com https://higherlogicdownload.s3.amazonaws.com/UNIFORMLAWS/ https://higherlogic-holdingpen-us-east-1.s3.amazonaws.com/UNIFORMLAWS/ 'self' https://higherlogiclongterm.s3.amazonaws.com/UNIFORMLAWS/ https://maxcdn.bootstrapcdn.com/font-awesome/ https://d2x5ku95bkycr3.cloudfront.net https://d132x6oi8ychic.cloudfront.net data:; script-src-elem https://www.google.com/recaptcha/ https://www.recaptcha.net/recaptcha/ https://d2x5ku95bkycr3.cloudfront.net/HigherLogic/jquery/jquery-ui-1.13.3.min.js https://d3uf7shreuzboy.cloudfront.net/ https://static.filestackapi.com/picker/ https://d2x5ku95bkycr3.cloudfront.net/HigherLogic/jquery/jquery-3.7.1.min.js https://d2x5ku95bkycr3.cloudfront.net/ https://cdnjs.cloudflare.com/ajax/libs/prism/ https://www.gstatic.com/recaptcha/ https://static.filestackapi.com/filestack-js/ 'self' https://ajax.aspnetcdn.com/ajax/ 'unsafe-eval' 'unsafe-inline'; media-src https://higherlogiclongterm.s3.amazonaws.com/UNIFORMLAWS/ https://higherlogicdownload.s3.amazonaws.com/UNIFORMLAWS/ https://higherlogic-holdingpen-us-east-1.s3.amazonaws.com/UNIFORMLAWS/ https://higherlogicstream.s3.amazonaws.com/UNIFORMLAWS/ 'self' https://d132x6oi8ychic.cloudfront.net; script-src https://higherlogiclongterm.s3.amazonaws.com/UNIFORMLAWS/ https://higherlogicdownload.s3.amazonaws.com/UNIFORMLAWS/ https://ajax.aspnetcdn.com/ajax/ https://cdn.jsdelivr.net/jquery.slick/ https://d2x5ku95bkycr3.cloudfront.net/HigherLogic/jquery/jquery-ui-1.13.3.min.js https://d132x6oi8ychic.cloudfront.net https://cdn.informz.net 'unsafe-eval' https://use.fortawesome.com/ https://higherlogic-holdingpen-us-east-1.s3.amazonaws.com/UNIFORMLAWS/ https://cdnjs.cloudflare.com/ajax/libs/prism/ 'unsafe-inline' https://d2x5ku95bkycr3.cloudfront.net/ https://higherlogiccloudfront.s3.amazonaws.com https://static.filestackapi.com https://d2x5ku95bkycr3.cloudfront.net/HigherLogic/jquery/jquery-3.7.1.min.js https://d3uf7shreuzboy.cloudfront.net/ 'self'; frame-src https://www.google.com/recaptcha/ https://www.recaptcha.net/recaptcha/ https://api.connectedcommunity.org/ 'self' https://www.youtube.com/embed/; connect-src https://upload.filestackapi.com https://static.filestackapi.com https://cloud.filestackapi.com/folder/list/ 'self' https://hl-managedservices.informz.net https://d3uf7shreuzboy.cloudfront.net/ blob:; worker-src 'self'; default-src 'self'; base-uri 'self'; frame-ancestors https://*.connectedcommunity.org/ 'self'; object-src 'none'; manifest-src 'self'; 1 default-src 'self' https://*.alltuu.live https://alltuu-frontend-log-tracking.cn-hangzhou.log.aliyuncs.com https://alltuu-frontend-log.cn-hangzhou.log.aliyuncs.com https://www.gstatic.com https://alltuu-help-video.oss-cn-shanghai.aliyuncs.com https://open.work.weixin.qq.com https://cdn.jsdelivr.net https://cdnjs.cloundflare.com https://gw.alipayobjects.com https://lf1-cdn-tos.bytegoofy.com https://alltuu.cc https://alltuu.pw https://alltuu.co https://alltuu.tv https://s9.cnzz.com https://zz.bdstatic.com https://v1.cnzz.com https://g.alicdn.com https://mp.weixin.qq.com https://res.wx.qq.com https://open.weixin.qq.com https://turing.captcha.qcloud.com https://sp0.baidu.com/ https://turing.captcha.gtimg.com https://at.alicdn.com data: blob: https://*.alltuu.ren https://*.alltuu.com 'unsafe-eval' 'unsafe-inline'; report-uri https://csp-page.alltuu.com;connect-src 'self' https://*.alltuu.live https://mcs.snssdk.com https://alltuu-storage.oss-accelerate.aliyuncs.com https://alltuu-prsoon-private.oss-cn-hangzhou.aliyuncs.com https://aegis.qq.com https://mp.weixin.qq.com/ https://alltuu-msg.cn-hangzhou.log.aliyuncs.com/ https://alltuu-flashapp.cn-hangzhou.log.aliyuncs.com https://ai-platform-data-analysis.cn-hangzhou.log.aliyuncs.com https://ai-data-analysis.cn-hangzhou.log.aliyuncs.com https://*.alltuu.com wss://*.alltuu.com https://alltuu-frontend-log.cn-hangzhou.log.aliyuncs.com https://videocloud.cn-hangzhou.log.aliyuncs.com https://alltuu-storage.oss-cn-hangzhou.aliyuncs.com https://alltuu-frontend-log-tracking.cn-hangzhou.log.aliyuncs.com data: blob:;frame-src 'self' https://* blob: data: ; 1 script-src 'self' 'unsafe-inline' 'unsafe-eval' http://*.mogucdn.com https://*.mogucdn.com http://*.juangua.com https://*.juangua.com http://*.meilishuo.com https://*.meilishuo.com http://*.meilishuo.net https://*.meilishuo.net http://*.mogujie.com https://*.mogujie.com http://*.qq.com https://*.qq.com http://*.mogujie.org https://*.mogujie.org http://*.meili-inc.com https://*.meili-inc.com http://*.mogu.com https://*.mogu.com http://*.mogu-inc.com https://*.mogu-inc.com; report-uri http://sd.mogujie.com/index.php 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com fonts.googleapis.com *.googleapis.com https://*.gstatic.com data: https://*.typekit.net *.klarnacdn.net *.klevu.com *.ksearchnet.com *.cloudfront.net *.reviews.io *.reviews.co.uk *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnaevt.com *.link.com *.amazon.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.reviews.io *.reviews.co.uk *.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com https://static.addtoany.com/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.google.com *.clearpay.co.uk *.iubenda.com https://*.doubleclick.net https://*.google.com https://*.hotjar.com *.klarna.com js.mollie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.reviews.io *.reviews.co.uk *.stripe.com klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.weltpixel.com *.googletagmanager.com *.doubleclick.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net https://images.unsplash.com maps.googleapis.com maps.gstatic.com *.googleapis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.afterpay.com *.clearpay.co.uk ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.iubenda.com https://*.doubleclick.net https://*.google.com https://*.google.co.uk *.cloudfront.net *.klarna.com *.klarnaevt.com *.klarnacdn.net *.klevu.com *.ksearchnet.com https://www.mollie.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.reviews.io *.reviews.co.uk *.facebook.com *.reddit.com *.ads-twitter.com t.co *.twitter.com *.bing.com *.clarity.ms *.google-analytics.com *.googletagmanager.com *.doubleclick.net *.google.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://static.addtoany.com/ https://maps.googleapis.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.googleapis.com https://www.gstatic.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.afterpay.com *.clearpay.co.uk *.squarecdn.com https://hbiq.net chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.iubenda.com https://*.pcapredict.com/js/sensor.js https://www.googletagmanager.com https://www.google.com https://*.hotjar.com https://*.doubleclick.net https://secure.leadforensics.com https://*.googleapis.com *.klarna.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.klevu.com *.ksearchnet.com js.mollie.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.reviews.io *.reviews.co.uk *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarnaevt.com *.amazon.com *.link.com *.googletagmanager.com *.googleadservices.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.bing.com *.clarity.ms unpkg.com *.doubleclick.net https://js.klevu.com https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.afterpay.com/ *.squarecdn.com downloads.mailchimp.com https://static.klaviyo.com https://*.googleapis.com https://*.typekit.net *.klarnacdn.net *.klevu.com *.ksearchnet.com assets.braintreegateway.com *.cloudfront.net *.reviews.io *.reviews.co.uk *.stripe.network *.stripecdn.com *.amazon.com *.tagmanager.google.com *.googletagmanager.com https://statsjs.klevu.com https://js.klevu.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://stats.addtoany.com/menu https://maps.googleapis.com https://player.vimeo.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.googleapis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.clearpay.co.uk *.squarecdn.com https://hbiq.net https://iq.afterpay-beta.com https://iq.afterpay.com form-assets.mailchimp.com *.intuit.com *.amazonaws.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.iubenda.com https://*.hotjar.com https://*.adobedc.net https://*.nr-data.net *.klarnaevt.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.klarna.com *.klevu.com *.ksearchnet.com api.addressy.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.cloudfront.net *.reviews.io *.reviews.co.uk *.stripe.com klarna.com *.link.com *.amazon.com *.google-analytics.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.com *.clarity.ms *.doubleclick.net *.run.app 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.gstatic.com *.stape.io static.klaviyo.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de https://plumrocket.com www.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.google.it *.google.fr *.googletagmanager.com *.stape.io js.mollie.com https://plumrocket.com https://accounts.google.com *.consentmanager.net ridersdeal.mycleverpush.com www.sovendus-benefits.com www.facebook.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.ftcdn.net *.behance.net d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.payments-amazon.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ magefan.com cm.magefan.com *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.google.it *.google.fr *.gstatic.com *.doubleclick.net *.googletagmanager.com *.stape.io https://www.mollie.com *.consentmanager.net cookie-cdn.cookiepro.com www.googletagmanager.com pagead2.googlesyndication.com www.facebook.com *.hsforms.net *.hsforms.com 'self' data: data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net amcglobal.sc.omtrdc.net *.adobe.io use.typekit.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.magento-ds.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com www.googletagmanager.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.google.com *.google.com.ua *.google.co.uk *.google.nl *.google.be *.google.de *.google.it *.google.fr *.gstatic.com *.googletagmanager.com *.doubleclick.net *.stape.io js.mollie.com https://accounts.google.com https://www.gstatic.com ridersdeal.app.baqend.com *.kameleoon.io *.kameleoon.com *.kameleoon.eu *.kameleoon.net *.consentmanager.net maps.googleapis.com 'self' *.sovendus.com chimpstatic.com *.googlesyndication.com *.cookiepro.com connect.facebook.net *.hotjar.com static.cleverpush.com *.zdassets.com apis.google.com www.google.com www.gstatic.com cdn.jsdelivr.net magento-recs-sdk.adobe.net static-eu.payments-amazon.com *.hsforms.net *.hsforms.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com https://static.klaviyo.com *.googleapis.com *.googletagmanager.com *.stape.io https://accounts.google.com https://www.gstatic.com *.gstatic.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io *.sentry.io *.magento-datasolutions.com *.magento-ds.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.google-analytics.com *.google.com *.doubleclick.net *.googlesyndication.com https://www.merchant-center-analytics.goog *.stape.io https://accounts.google.com api.cleverpush.com *.cookiepro.com data.ridersdeal.com *.zdassets.com ridersdeal.zendesk.com maps.googleapis.com *.sovendus.com www.chatbase.co bam.nr-data.net ridersdeal-web.talk.insaight.io t.elasticsuite.io *.hsforms.net *.hsforms.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 base-uri 'self'; default-src 'none'; frame-ancestors 'none'; font-src 'self' https://fonts.gstatic.com; form-action 'self'; frame-src 'self' https://td.doubleclick.net; connect-src 'self' https://swile-privacy.my.onetrust.com https://cdn.cookielaw.org https://static.axept.io https://api.axept.io https://client.axept.io https://swile.containers.piwik.pro https://swile.piwik.pro/ https://adservice.google.com https://googleads.g.doubleclick.net https://www.google.com; img-src 'self' blob: data: https://cdn.cookielaw.org https://static.axept.io https://axeptio.imgix.net https://www.google.fr https://www.googletagmanager.com https://fonts.gstatic.com; manifest-src 'self'; object-src 'none'; report-uri https://csp-report.browser-intake-datadoghq.eu/api/v2/logs?dd-api-key=pub1f7041eb55ec9a12eea50b161be3d8c0&dd-evp-origin=content-security-policy&ddsource=csp-report; report-to csp; script-src 'nonce-ZmEyYWEwMWMtNjc1Ny00ZDE0LTkzOGMtN2Q0MDRlZDI5NzQ1' 'strict-dynamic' https://static.axept.io; style-src 'self' 'unsafe-inline' https://www.googletagmanager.com https://fonts.googleapis.com 1 default-src 'none'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://cdn.ing.com https://www.google.com https://www.gstatic.com https://tags.tiqcdn.com; connect-src 'self' https://api.www.homebank.ro https://api.homebank.ro https://cdn.ing.com https://*.googlevideo.com https://jnn-pa.googleapis.com https://analytics.homebank.ro https://ingbankromania.sc.omtrdc.net; img-src 'self' https://analytics.homebank.ro https://dealwise-static.homebank.ro https://dw-static.homebank.ro https://i.ytimg.com https://yt3.ggpht.com https://ing.ro https://www.ing.ro data: blob:; style-src 'self' 'unsafe-inline'; font-src 'self' https://fonts.gstatic.com data:; frame-ancestors 'self'; child-src 'self'; form-action 'self'; upgrade-insecure-requests; frame-src 'self' https:; media-src https://*.googlevideo.com blob:; 1 default-src 'self'; base-uri 'self'; object-src 'none'; frame-ancestors 'none'; img-src 'self' data: https:; font-src 'self' data: https:; style-src 'self' 'unsafe-inline' https:; script-src 'self' https:; connect-src 'self' https:; upgrade-insecure-requests; block-all-mixed-content 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://*.publitas.com *.fontawesome.com *.kohlerbycochez.com https://script.hotjar.com *.algolia.com *.googleapis.com *.bootstrapcdn.com https://*.bazaarvoice.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com testsecureacceptance.cybersource.com secureacceptance.cybersource.com 0merchantacsstag.cardinalcommerce.com merchantacs.cardinalcommerce.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.online-metrix.net testflex.cybersource.com flex.cybersource.com testsecureacceptance.cybersource.com secureacceptance.cybersource.com pay.google.com merchantacs.cardinalcommerce.com 0merchantacsstag.cardinalcommerce.com https://*.publitas.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com c.paypal.com checkout.paypal.com assets.braintreegateway.com *.cardinalcommerce.com * *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net www.gstatic.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.kohlerbycochez.com network-a.bazaarvoice.com maps.gstatic.com *.algolia.com media.flixcar.com rt.flix360.com *.google.com *.google-analytics.com *.googleadservices.com https://www.google.com https://www.google.com.co maps.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.facebook.com *.reddit.com https://*.bazaarvoice.com https://*.google.com.pa data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.online-metrix.net testflex.cybersource.com flex.cybersource.com pay.google.com x.klarnacdn.net centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com https://*.publitas.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://apps.bazaarvoice.com *.kohlerbycochez.com apps.bazaarvoice.com static.hotjar.com script.hotjar.com h.online-metrix.net js-agent.newrelic.com www.google.com www.gstatic.com maps.googleapis.com *.algolia.com media.flixfacts.com media.flixcar.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://www.googletagmanager.com tagmanager.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com unpkg.com https://cdn.jsdelivr.net https://view.publitas.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://*.publitas.com *.fontawesome.com *.kohlerbycochez.com *.algolia.com *.google.com *.googleapis.com *.gstatic.com *.bootstrapcdn.com assets.braintreegateway.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com videos.pexels.com *.algolia.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.kohlerbycochez.com bam.nr-data.net maps.googleapis.com https://surveystats.hotjar.io media.flixcar.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.google-analytics.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.doubleclick.net *.run.app https://*.bazaarvoice.com https://*.hotjar.io 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src bam.nr-data.net *.kohlerbycochez.com ws.hotjar.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 report-uri /api/csp 1 default-src 'self'; connect-src *; font-src data: *; frame-src *; img-src data: *; media-src *; object-src *; script-src 'self' 'unsafe-eval' 'unsafe-inline' *; style-src 'self' 'unsafe-inline'; report-uri https://csp-reports.firmseek.com/hodgsonruss; 1 report-uri https://csp.withgoogle.com/csp/youtube_main/strict;base-uri 'self';object-src 'none';script-src 'report-sample' 'nonce-nc6i08AtO5ZdWdRfyRo3Bw' 'unsafe-inline' 'strict-dynamic' https: http: 'unsafe-eval' 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com cash-f.squarecdn.com *.googleapis.com maxcdn.bootstrapcdn.com *.myfeelback.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com * *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com bpcepaymentservices-3ds-vdm.wlp-acs.com *.modirum.com *.cic.fr *.cafis-paynet.jp *.creditmutuel.fr *.lcl.fr *.americanexpress.com *.dnp-cdms.jp *.sg.fr *.viseca.ch *.redsys.es *.monext.fr *.rpc-raiffeisen.com *.sparda.de *.citibank.com sicher-bezahlen.sparkasse.at 3ds-challenge.n26.com esecure.sia.eu *.uobgroup.com *.revolut.com *.fssnet.co.in *.e-i.com *.neuflizeobc.net *.cm-cic.com *.apata.io *.nexigroup.com *.cardcenter.ch *.gps.com.bh *.bkm.com.tr *.airplus.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com * *.lamaisonduchocolat.com *.avis-verifies.com *.reetags.com *.prismic.io vimeo.com *.googletagmanager.com *.weltpixel.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypalobjects.com bpcepaymentservices-3ds-vdm.wlp-acs.com *.modirum.com *.wlp-acs.com *.cic.fr *.cafis-paynet.jp *.creditmutuel.fr www.googletagmanager.com *.lcl.fr *.americanexpress.com *.dnp-cdms.jp *.sg.fr *.viseca.ch *.redsys.es *.monext.fr *.rpc-raiffeisen.com *.sparda.de *.citibank.com sicher-bezahlen.sparkasse.at *.arcot.com 3ds-challenge.n26.com esecure.sia.eu *.uobgroup.com *.revolut.com *.fssnet.co.in *.e-i.com *.neuflizeobc.net *.cm-cic.com *.apata.io *.nexigroup.com *.cardcenter.ch *.gps.com.bh *.bkm.com.tr *.monzo.com *.airplus.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com * *.googleapis.com *.lamaisonduchocolat.com https://bat.bing.com https://sdk.privacy-center.org https://cm.g.doubleclick.net https://www.facebook.com https://www.google.com https://www.google.fr *.linkedin.com https://rum-metrics.quanta.io *.reetags.com https://sync-t1.taboola.com https://ad.360yield.com https://ad.yieldlab.net https://contextual.media.net https://e1.emxdgt.com https://eb2.3lift.com https://exchange.mediavine.com https://ib.adnxs.com https://id5-sync.com https://jadserve.postrelease.com https://matching.ivitrack.com https://match.sharethrough.com https://pixel.rubiconproject.com https://r.casalemedia.com https://rtb-csync.smartadserver.com https://secure.adnxs.com https://simage2.pubmatic.com https://sync.1rx.io https://sync.outbrain.com https://visitor.omnitagjs.com https://x.bidswitch.net *.prismic.io https://images.unsplash.com flagpedia.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com lamaisonduchocolat.com *.clarity.ms *.google.com *.bing.com *.google.co.jp *.google.com.hk *.doubleclick.net *.google.ro *.google.com.sg *.google.at *.a8.net *.google.com.tw www.americanexpress.com *.googleusercontent.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com *.cash.app *.visa.com *.mastercard.com *.googleapis.com *.gstatic.com https://widgets.rr.skeepers.io/ https://api-product-reviews.rr.skeepers.io/ https://cl-ppr.rr.skeepers.io/ *.lamaisonduchocolat.com https://bat.bing.com https://sdk.privacy-center.org https://googleads.g.doubleclick.net https://connect.facebook.net https://snap.licdn.com https://www.clarity.ms https://appstatic.quanta.io *.reetags.com https://*.taboola.com https://analytics.tiktok.com https://acdn.adnxs.com https://ad.avtm.fr https://analytics.optimalpeople.fr https://trk.adbutter.net prismic.io https://maps.googleapis.com maps.googleapis.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com https://www.googletagmanager.com tagmanager.google.com *.zdassets.com *.vimeo.com *.a8.net *.tradedoubler.com *.algolia.net *.algolianet.com *.prismic.io *.myfeelback.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.cash.app *.lamaisonduchocolat.com *.reetags.com maxcdn.bootstrapcdn.com *.gstatic.com assets.braintreegateway.com tagmanager.google.com *.myfeelback.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.lamaisonduchocolat.com *.prismic.io *.zdassets.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com * *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io *.googleapis.com https://widgets.rr.skeepers.io/ https://api-product-reviews.rr.skeepers.io/ https://cl-ppr.rr.skeepers.io/ *.lamaisonduchocolat.com *.privacy-center.org https://googleads.g.doubleclick.net https://www.facebook.com https://www.google.com *.linkedin.com *.reetags.com https://*.taboola.com https://analytics.tiktok.com https://analytics.optimalpeople.fr https://ib.adnxs.com https://maps.googleapis.com https://player.vimeo.com www.gstatic.com maps.googleapis.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com https://www.google-analytics.com yubinbango.github.io *.clarity.ms rum-metrics.quanta.io *.zdassets.com *.zendesk.com *.bing.com *.bing.net *.googlesyndication.com *.vimeo.com *.trackingplan.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self';script-src 'self' 'unsafe-inline' 'nonce-FWtORleNGPNCKbOnj0zPoCOw' 'unsafe-eval' https://pixel.byspotify.com *.travcorpservices.com https://www.google.com https://www.google-analytics.com https://www.googleoptimize.com https://www.googletagmanager.com https://ajax.googleapis.com https://www.gstatic.com https://googleads.g.doubleclick.net https://api.feefo.com https://register.feefo.com https://bat.bing.com https://cdn.evgnet.com https://connect.facebook.net https://i.clarity.ms https://static-ssl.responsetap.com *.hotjar.com https://tag.simpli.fi https://unpkg.com https://www.bugherd.com https://decagon.ai https://www.datadoghq-browser-agent.com https://assetscdn.stackla.com/media/js https://vjs.zencdn.net https://cdn.amplitude.com/libs https://sdk.joinsherpa.io https://apps.mypurecloud.com https://consentcdn.cookiebot.com https://cdnjs.cloudflare.com https://ttc-contiki.entry.promo https://cdn.optimizely.com https://www.riddle.com;style-src 'self' 'unsafe-inline' https://assetscdn.stackla.com/media/components/stackla-uikit/dist https://fonts.googleapis.com https://p.typekit.net https://use.typekit.net https://vjs.zencdn.net https://apps.mypurecloud.com;img-src 'self' https://bat.bing.com https://c.clarity.ms https://i.ytimg.com https://www.facebook.com https://www.google-analytics.com https://www.google.com https://www.uplift-platform.com data:;frame-src 'self' https://10006172.fls.doubleclick.net https://uplift-cdn-stg.uplift.com https://vars.hotjar.com https://widget.stackla.com https://www.google.com https://apps.joinsherpa.io https://www.googletagmanager.com https://a25408250069.cdn.optimizely.com;font-src 'self' https://assetscdn.stackla.com https://fonts.gstatic.com https://use.typekit.net https://vjs.zencdn.net https://apps.mypurecloud.com;connect-src 'self' *.travcorpservices.com *.travcorp.com *.corp.ttc:7443 https://api.feefo.com https://bat.bing.com https://in.hotjar.com https://ws11.hotjar.com/api https://l.clarity.ms https://metrics.responsetap.com/infinity https://noembed.com https://pm-mrkt.prodgw.uplift-platform.com https://rum.browser-intake-datadoghq.com https://session-replay.browser-intake-datadoghq.com https://ttctravel.germany-2.evergage.com https://www.facebook.com https://www.google-analytics.com https://logx.optimizely.com https://region1.analytics.google.com https://ttc.contiki.com 1 script-src 'nonce-RglGxn5Dv6lX88ZVGOaP7w==' 'strict-dynamic' 'unsafe-eval' 'unsafe-inline' https: 'report-sample'; base-uri 'none'; report-uri https://events.mercadolibre.com/csp/reports?identifier=w1qeU4XKVwGbQGBuEKyE3KhFBIpr5IZSIaRiTowMc8UG7kU18vRsmBTEKL2krAj23LIS&policy_id=26548&user_id=&request_id=a44522ca-ebcb-48ee-891b-842e3c6ac628; report-to csp-endpoint-wqeuxkvwgbqgbuekyekhfbiprizsiaritowmcugkuvrsmbteklkrajlis; object-src https://http2.mlstatic.com/ https://mlstaticquic-a.akamaihd.net/; frame-ancestors 'self' https://*.mercadolibre.cl:* https://*.mercadolibre.com:* https://*.mercadolibre.com.ve:* https://*.mercadolibre.com.ar:* https://*.mercadolivre.com.br:* https://*.mercadolibre.com.co:* https://*.mercadolibre.com.ec:* https://*.mercadolibre.com.mx:* https://*.mercadolibre.com.pe:* https://*.mercadolibre.com.uy:* https://*.mercadopago.cl:* https://*.mercadopago.com.ar:* https://*.mercadopago.com.br:* https://*.mercadopago.com.co:* https://*.mercadopago.com.mx:* https://*.mercadopago.com.pe:* https://*.mercadopago.com.uy:* https://*.mercadopago.com.ve:* https://*.mercadopago.com:* https://*.adminml.com:* https://*.mercadolibre.co.cr:* https://*.mercadolibre.com.pa:* https://*.mercadolibre.com.do:* https://*.mercadolibre.com.bo:* https://*.mercadolibre.com.py:* https://*.mercadolibre.com.gt:* https://*.mercadolibre.com.hn:* https://*.mercadolibre.com.ni:* https://*.mercadolibre.com.sv:* https://*.mercadopago.com.ec:* https://*.portalinmobiliario.com:* https://*.mercadolivre.com:* 1 font-src *.googleapis.com *.gstatic.com data: 'self' data: *.doubleclick.net *.facebook.com maxcdn.bootstrapcdn.com https://widgets.trustedshops.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.google.com *.google.com *.doubleclick.net *.facebook.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.gstatic.com *.googleapis.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com www.google.com.ua ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.googleapis.com *.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com chimpstatic.com downloads.mailchimp.com *.list-manage.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com gzuvq.sanitairkamer.nl https: 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com downloads.mailchimp.com maxcdn.bootstrapcdn.com https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.googleapis.com *.google-analytics.com *.facebook.com *.facebook.net *.google.com *.trustedshops.com *.etrusted.com https://integrations.etrusted.site gzuvq.sanitairkamer.nl https: 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://monitor.bigbridgedev.nl/csp; report-to report-endpoint; 1 connect-src 'self' https://*.greenbone.net https://www.cloud.ccm19.de https://pagead2.googlesyndication.com https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://*.g.doubleclick.net https://*.google.com https://*.google.pt https://www.googleadservices.com https://bat.bing.com; default-src 'none'; font-src 'self' data:; frame-src 'self' https://www.googletagmanager.com https://www.cloud.ccm19.de https://bid.g.doubleclick.net; img-src 'self' data: blob: https://mautic.greenbone.net https://www.cloud.ccm19.de https://*.googletagmanager.com https://*.google-analytics.com https://*.g.doubleclick.net https://*.google.com https://*.google.pt https://bat.bing.com; script-src 'self' 'unsafe-inline' https://www.cloud.ccm19.de https://matomo.greenbone.net https://*.googletagmanager.com https://www.googleadservices.com https://*.g.doubleclick.net https://www.google.com https://bat.bing.com https://app.varify.io; style-src 'self' 'unsafe-inline' https://www.cloud.ccm19.de; 1 default-src 'self';base-uri 'self';frame-ancestors 'self';frame-src https://* 'self' epichttp: https://premier.trustcommerce.com;script-src 'nonce-611d967ff06540fe9ac3fc10313e48dc' https://www.myconnectnyc.org 'self';img-src https://* 'self' blob: data:;connect-src 'self' epichttp:;style-src https://www.myconnectnyc.org 'self' 'unsafe-inline';worker-src 'self' blob:;child-src 'self' blob:;form-action https://central.mychart.org/MyChart/ 'self';media-src https://* 'self' blob:; 1 report-uri https://www.yelp.com/csp_report_only?id=f3956c20e8fa2203&page=csp_report_frame_directives%2Cfull_site_ssl_csp_report_directives&policy_hash=41d0c45536d2a082f11d1cd0e00fde7f&site=www×tamp=1770428527; frame-ancestors 'self' https://*.yelp.com; default-src https:; img-src https: data: blob:; script-src https: data: 'unsafe-inline' 'unsafe-eval' blob:; style-src https: 'unsafe-inline' data:; font-src data: https:; child-src https: yelp-webview://* yelp://* data:; object-src 'none'; worker-src blob: https:; base-uri 'self'; form-action https: 1 default-src 'self'; connect-src 'self' *.nixonpeabody.com *.nixonpeabody.localhost stats.g.doubleclick.net analytics.google.com region1.analytics.google.com *.typekit.net *.vercel.app *.linkedin.com *.clarity.ms *.bing.com *.onetrust.com *.google.com *.doubleclick.net apps.sitecore.net cdn.cookielaw.org googletagmanager.com www.google-analytics.com www.googleadservices.com snap.licdn.com cdn.pdst.fm pixels.spotify.com youtube.com www.youtube.com player.vimeo.com open.spotify.com vercel.com vercel.live vitals.vercel-insights.com wss://ws-us3.pusher.com www.googletagmanager.com *.google.com *.google.ca *.google.co.uk *.google.com.au *.google.co.in *.google.de *.google.fr *.google.it *.google.es *.google.jp *.google.com.br *.google.co.kr *.google.co.za *.google.com.mx *.google.nl *.google.se *.google.dk *.google.no *.google.ch *.google.be *.google.ie *.google.pl *.google.ro *.google.ru *.google.com.hk *.google.sg *.google.com.tw *.google.co.nz *.google.fi *.google.pt; script-src 'self' 'unsafe-inline' *.searchstax.com *.clarity.ms cdn.cookielaw.org www.googletagmanager.com tagmanager.google.com snap.licdn.com vercel.live cdn.pdst.fm player.vimeo.com static.searchstax.com *.doubleclick.net; script-src-elem 'self' 'unsafe-inline' *.searchstax.com *.clarity.ms cdn.cookielaw.org www.googletagmanager.com tagmanager.google.com snap.licdn.com vercel.live cdn.pdst.fm player.vimeo.com static.searchstax.com *.doubleclick.net googleads.g.doubleclick.net; img-src * data: blob:; style-src 'self' 'unsafe-inline' *.typekit.net use.typekit.net vercel.live *.googletagmanager.com tagmanager.google.com fonts.googleapis.com; style-src-elem 'self' 'unsafe-inline' *.typekit.net use.typekit.net vercel.live *.googletagmanager.com tagmanager.google.com fonts.googleapis.com; object-src 'self' data: blob:; base-uri 'self'; form-action 'self'; font-src 'self' data: *.typekit.net use.typekit.net vercel.live assets.vercel.com fonts.gstatic.com; frame-src 'self' vercel.live *.doubleclick.net player.vimeo.com youtube.com www.youtube.com cdn.yoshki.com open.spotify.com www.googletagmanager.com; frame-ancestors 'none'; upgrade-insecure-requests; report-to csp-report; 1 default-src 'self' https://*.cookieinformation.com https://assets.bolia.com; connect-src 'self' data: https://*.altapaysecure.com https://*.analytics.google.com https://*.apple.com https://*.bolia.com https://*.clarity.ms https://*.cookieinformation.com https://*.doubleclick.net https://*.google-analytics.com https://*.google.com https://*.google.dk https://*.googleadservices.com https://*.googleapis.com https://*.googlesyndication.com https://*.googletagmanager.com https://*.hotjar.com https://*.hotjar.io https://*.kindly.ai https://*.kindlycdn.com https://*.linkedin.com https://*.pinterest.com https://*.sleeknote.com https://*.zdassets.com https://*.zendesk.com https://analytics-ipv6.tiktokw.us https://analytics.tiktok.com https://assets-bolia.com https://bolia-com-apigtw-prod.azurewebsites.net https://bolia.customizer.services https://boliad365prodstorage.blob.core.windows.net https://connect.facebook.net https://googlesyndication.com https://kindlycdn.com https://sockjs-eu.pusher.com https://static.zdassets.com https://widget.trustpilot.com https://www.facebook.com https://www.google.ch https://www.google.de https://www.google.dk https://www.google.es https://www.google.fr https://www.google.lt https://www.google.nl https://www.google.no https://www.google.se https://www.google.co.uk wss://*.hotjar.com wss://*.pusher.com; script-src 'self' 'unsafe-eval' 'unsafe-inline' https://*.adform.net https://*.bolia.com https://*.cdn-apple.com https://*.cdninstagram.com https://*.cookieinformation.com https://*.doubleclick.net https://*.googleapis.com https://*.googletagmanager.com https://*.instagram.com https://*.kindlycdn.com https://connect.facebook.net https://static.zdassets.com https://unpkg.com https://www.google.com https://www.gstatic.com; script-src-elem 'self' 'unsafe-eval' 'unsafe-inline' blob: https://*.adform.ms https://*.adform.net https://*.altapaysecure.com https://*.bolia.com https://*.clarity.ms https://*.cloudflare.com https://*.cookieinformation.com https://*.doubleclick.net https://*.facebook.net https://*.googleapis.com https://*.googlesyndication.com https://*.googletagmanager.com https://*.hotjar.com https://*.kindlycdn.com https://*.pinimg.com https://*.pinterest.com https://*.sleeknote.com https://analytics.tiktok.com https://assets-bolia.com https://bolia.customizer.services https://connect.facebook.net https://s.pinimg.com https://snap.licdn.com https://static.zdassets.com https://unpkg.com https://widget.trustpilot.com https://www.clarity.ms https://www.google-analytics.com https://www.google.com/recaptcha/api.js https://www.gstatic.com; frame-src https://*.adform.net https://*.altapaysecure.com https://*.bolia.com https://*.cdninstagram.com https://*.cookieinformation.com https://*.doubleclick.net https://*.facebook.com https://*.googletagmanager.com https://*.instagram.com https://*.klarna.com https://*.opendns.com https://*.pinterest.com https://*.vimeo.com https://*.youtube-nocookie.com https://*.youtube.com https://*.zscaler.com https://gateway.zscloud.net https://vimeo.com https://widget.trustpilot.com https://www.google.com; frame-ancestors 'self'; style-src 'self' 'unsafe-inline' blob: https://*.altapay.com https://*.bolia.com https://*.googleapis.com https://assets-bolia.com https://bolia.customizer.services; font-src 'self' data: https://*.bolia.com https://*.googleapis.com https://*.gstatic.com https://*.kindlycdn.com https://*.migaku.com https://cdn.megabonus.com https://cdn.scite.ai https://iframe.rbpartner.dk https://r2cdn.perplexity.ai https://res-1.cdn.office.net https://use.typekit.net; img-src 'self' blob: data: https://*.analytics.google.com https://*.bing.com https://*.bolia.com https://*.cdninstagram.com https://*.clarity.ms https://*.doubleclick.net https://*.facebook.com https://*.facebook.net https://*.google.com https://*.google.com.tr https://*.googleadservices.com https://*.googlesyndication.com https://*.googletagmanager.com https://*.instagram.com https://*.kindly.ai https://*.kindlycdn.com https://*.linkedin.com https://*.seadform.net https://*.sleeknote.com https://*.vimeocdn.com https://*.youtube.com https://assets-bolia.com https://bolia.altapaysecure.com https://bolia.customizer.services https://maps.googleapis.com https://maps.gstatic.com https://www.google.at https://www.google.be https://www.google.bg https://www.google.ca https://www.google.ch https://www.google.cl https://www.google.co.cr https://www.google.co.hu https://www.google.co.id https://www.google.co.il https://www.google.co.in https://www.google.co.jp https://www.google.co.ke https://www.google.co.kr https://www.google.co.ma https://www.google.co.nz https://www.google.co.th https://www.google.co.tz https://www.google.co.uk https://www.google.co.ug https://www.google.co.ve https://www.google.co.za https://www.google.com https://www.google.com.ar https://www.google.com.au https://www.google.com.bd https://www.google.com.bo https://www.google.com.br https://www.google.com.co https://www.google.com.do https://www.google.com.ec https://www.google.com.eg https://www.google.com.gr https://www.google.com.gt https://www.google.com.hk https://www.google.com.jm https://www.google.com.kh https://www.google.com.kw https://www.google.com.lb https://www.google.com.my https://www.google.com.mx https://www.google.com.ng https://www.google.com.np https://www.google.com.pa https://www.google.com.pe https://www.google.com.ph https://www.google.com.pk https://www.google.com.pr https://www.google.com.sa https://www.google.com.sg https://www.google.com.tr https://www.google.com.tw https://www.google.com.ua https://www.google.com.uy https://www.google.com.vn https://www.google.dk https://www.google.de https://www.google.es https://www.google.fi https://www.google.fr https://www.google.gr https://www.google.hr https://www.google.hu https://www.google.ie https://www.google.is https://www.google.it https://www.google.lt https://www.google.lu https://www.google.lv https://www.google.md https://www.google.me https://www.google.mk https://www.google.nl https://www.google.no https://www.google.pl https://www.google.pt https://www.google.ro https://www.google.rs https://www.google.ru https://www.google.se https://www.google.si https://www.google.sk https://ui-avatars.com https://yastatic.net; media-src 'self' https://*.vimeo.com https://*.vimeocdn.com https://images-bolia.com https://images.bolia.com; worker-src blob: https://*.bolia.com https://www.bolia.com/service-worker.js; manifest-src 'self' https://www.bolia.com;report-to csp-report-endpoint; 1 img-src 'self' data: dev.visualwebsiteoptimizer.com cdn.cookielaw.org www.googletagmanager.com *.siteimproveanalytics.io *.intoxalock.com *.facebook.com *.lpsnmedia.net *.gstatic.com *.googleapis.com i.ytimg.com 'self' data: dev.visualwebsiteoptimizer.com cdn.cookielaw.org www.googletagmanager.com *.siteimproveanalytics.io *.intoxalock.com *.facebook.com *.lpsnmedia.net *.gstatic.com *.googleapis.com i.ytimg.com px.ads.linkedin.com; script-src m555.bluemod.us cdn.cookielaw.org www.googletagmanager.com js.monitor.azure.com *.liveperson.net *.liveperson.com *.lpsnmedia.net unpkg.com getrockerbox.com siteimproveanalytics.com *.infinity-tracking.com *.facebook.com *.intoxalock.com *.facebook.net *.ubembed.com *.googleapis.com https://www.google.com/recaptcha/api.js *.gstatic.com m555.bluemod.us *.googletagmanager.com *.gstatic.com mindrco.blueconic.net dev.visualwebsiteoptimizer.com snap.licdn.com www.youtube.com 'self' 'unsafe-inline' 'nonce-TabSnSRCVl9t/xIepNANwDfwmdaG5+oD17hCTDsFqk4='; font-src 'self' data: *.gstatic.com; connect-src dev.visualwebsiteoptimizer.com *.applicationinsights.azure.com cdn.cookielaw.org *.google.com *.infinity-tracking.com *.googleapis.com *.onetrust.com dev.visualwebsiteoptimizer.com *.onetrust.com t081.intoxalock.com r5.visualwebsiteoptimizer.com px.ads.linkedin.com ad.doubleclick.net www.google-analytics.com 'self'; frame-src 'self' *.trustpilot.com www.googletagmanager.com td.doubleclick.net lpcdn.lpsnmedia.net *.liveperson.net *.youtube.com https://www.google.com https://locations.intoxalock.com.yext-cdn.com https://www.zeemaps.com/ 'self' *.trustpilot.com www.googletagmanager.com td.doubleclick.net lpcdn.lpsnmedia.net *.liveperson.net *.youtube.com https://www.google.com https://locations.intoxalock.com.yext-cdn.com https://www.zeemaps.com https://13396136.fls.doubleclick.net https://www.facebook.com; style-src *.googleapis.com 'self' 'unsafe-inline'; worker-src 'self' blob:; default-src 'self'; 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://*.googletagmanager.com https://www.google.com https://www.gstatic.com https://webforms.pipedrive.com https://cdn.cmh-1.pipedriveassets.com https://cdn.was-1.pipedriveassets.com https://client.crisp.chat https://static.hotjar.com https://script.hotjar.com https://use.typekit.net https://cdn-cookieyes.com; connect-src 'self' https://*.googletagmanager.com https://www.google.com https://www.gstatic.com https://client.crisp.chat wss://client.relay.crisp.chat https://api.weglot.com https://cdn-cookieyes.com https://log.cookieyes.com https://vc.hotjar.io https://stats.g.doubleclick.net; frame-src 'self' https://www.google.com https://webforms.pipedrive.com https://*.googletagmanager.com https://www.youtube.com https://www.youtube-nocookie.com https://datastudio.google.com https://lookerstudio.google.com; img-src 'self' data: https: https://image.crisp.chat https://img.youtube.com; style-src 'self' 'unsafe-inline' https://client.crisp.chat https://use.typekit.net https://p.typekit.net; font-src 'self' data: https: https://use.typekit.net; object-src 'none'; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.weltpixel.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * landofcoder.com accounts.google.com appleid.cdn-apple.com iheartjane.com *.googletagmanager.com *.doubleclick.net 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.googleapis.com magefan.com cm.magefan.com *.disqus.com https://img.youtube.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.facebook.com *.reddit.com *.ads-twitter.com t.co *.twitter.com *.bing.com *.klaviyo.com *.clarity.ms *.googletagmanager.com *.doubleclick.net *.google.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.googleapis.com *.gstatic.com *.disqus.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com landofcoder.com accounts.google.com appleid.cdn-apple.com cdn.moengage.com fpnpmcdn.net iheartjane.com t.contentsquare.net tags.srv.stackadapt.com *.googletagmanager.com *.googleadservices.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.bing.com *.clarity.ms *.klaviyo.com unpkg.com *.doubleclick.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com assets.braintreegateway.com *.tagmanager.google.com *.googletagmanager.com 'self' 'unsafe-inline'; object-src landofcoder.com 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.googleapis.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com landofcoder.com iheartjane.com fpnpmcdn.net cdn.moengage.com t.contentsquare.net tags.srv.stackadapt.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.com *.klaviyo.com *.clarity.ms *.doubleclick.net *.run.app 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' *.tillamook.com tillamook.com stackpath.bootstrapcdn.com; img-src 'self' data: *.ctfassets.net ctfassets.net *.cookielaw.org cookielaw.org www.google.com/ads/ www.google-analytics.com/ www.facebook.com/ c.lytics.io/c/b5c7317d218cb2a0ef160219694b5a9e www.googletagmanager.com; media-src 'self' *.ctfassets.net ctfassets.net; script-src 'self' 'unsafe-inline' 'unsafe-eval' blob: destinilocators.com https://connect.facebook.net/ *.hotjar.com hotjar.com *.klaviyo.com klaviyo.com *.cookielaw.org cookielaw.org www.google-analytics.com/ www.googletagmanager.com/ www.google.com/recaptcha/ www.gstatic.com/recaptcha/ www.clarity.ms givebutter.com/ destinilocators.com/ www.googleoptimize.com/ cdnjs.cloudflare.com/polyfill/v3/polyfill.min.js cdnjs.cloudflare.com/ajax/libs/iframe-resizer/2.8.10/iframeResizer.min.js cdnjs.cloudflare.com/ajax/libs/easyXDM/2.4.20/easyXDM.min.js va.vercel-scripts.com/v1/speed-insights/script.debug.js widget.intercom.io js.intercomcdn.com www.recaptcha.net analytics.tiktok.com/i18n/pixel/events.js; style-src 'self' 'unsafe-inline' *.typekit.net typekit.net api.tiles.mapbox.com www.exploretock.com stackpath.bootstrapcdn.com/font-awesome/4.7.0/css/font-awesome.min.css fonts.googleapis.com/css; style-src-elem 'self' 'unsafe-inline' *.typekit.net stackpath.bootstrapcdn.com fonts.googleapis.com; font-src 'self' *.tillamook.com tillamook.com *.typekit.net typekit.net www.exploretock.com stackpath.bootstrapcdn.com fonts.gstatic.com; connect-src 'self' wss: *.tillamook.com tillamook.com *.tillamaps.com tillamaps.com *.hotjar.com hotjar.com *.klaviyo.com klaviyo.com *.doubleclick.net doubleclick.net *.ingest.sentry.io *.ingest.us.sentry.io *.ctfassets.net ctfassets.net *.mapbox.com mapbox.com *.algolianet.com *.algolia.net *.onetrust.com onetrust.com *.cookielaw.org cookielaw.org analytics.google.com api.addresszen.com *.clarity.ms/collect www.recaptcha.net preview.contentful.com/ www.google-analytics.com/ vitals.vercel-insights.com/ cdn.contentful.com/ analytics.google.com/ d2k6913brarspg.cloudfront.net/ www.facebook.com/tr/ analytics.tiktok.com/api/v2/pixel qcjajnmiprtqkimhahis.supabase.co; frame-src 'self' https://vars.hotjar.com https://www.facebook.com/ https://www.google.com/ https://www.youtube.com https://www.youtube-nocookie.com https://destinilocators.com/ https://td.doubleclick.net/; frame-ancestors https://app.contentful.com; worker-src 'self' blob:; child-src 'self' blob:; report-uri https://16x3230g.uriports.com/reports/report; report-to default 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.fontawesome.com *.bootstrapcdn.com *.gstatic.com 'self' data: www.googleadservices.com www.googletagmanager.com *.reevoo.com/ *.googleapis.com *.feefo.com *.speedex.gr data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com unpkg.com *.unpkg.com *.magedeploy.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ bid.g.doubleclick.net challenges.cloudflare.com unpkg.com *.unpkg.com cdnjs.cloudflare.com 'self' 'unsafe-inline'; img-src data: widgets.magentocommerce.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com *.google-analytics.com *.analytics.google.com www.googletagmanager.com https://images.unsplash.com *.designer-images.net 'self' data: unpkg.com *.unpkg.com www.themart.gr cdn.themart.gr *.cdninstagram.com sp.analytics.yahoo.com *.cookiebot.com *.google.gr *.sharethrough.com *.outbrain.com *.bidswitch.net *.dnxs.com *.smartadserver.com *.taboola.com *.omnitagjs.com *.casalemedia.com *.criteo.com id5-sync.com *.360yield.com *.ivitrack.com *.media.net *.mediavine.com *.adnxs.com *.id5-sync.com *.pubmatic.com *.postrelease.com *.rubiconproject.com *.teads.tv *.tremorhub.com *.3lift.com *.yieldlab.net *.emxdgt.com *.yieldmo.com *.unrulymedia.com *.1rx.io data: 'self' 'unsafe-inline'; script-src www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com https://maps.googleapis.com https://player.vimeo.com *.stat-track.com polyfill.io *.moosend.com challenges.cloudflare.com *.google.com *.gstatic.com unpkg.com *.unpkg.com cdnjs.cloudflare.com *.feefo.com *.clarity.ms skroutza.skroutz.gr static.cloudflareinsights.com *.skroutz.gr dynamic.criteo.com sslwidget.criteo.com widgets.reevoo.com go.linkwi.se s.yimg.com measurement-api.criteo.com metrics.find.gr plausible.io *.cookiebot.com *.hotjar.com *.pinimg.com *.pinterest.com *.magedeploy.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com *.fontawesome.com *.moosend.com *.bootstrapcdn.com *.googleapis.com *.gstatic.com unpkg.com *.unpkg.com *.reevoo.com/ *.feefo.com *.speedex.gr *.magedeploy.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io www.googleadservices.com *.google-analytics.com *.analytics.google.com www.googletagmanager.com https://maps.googleapis.com https://player.vimeo.com *.stat-track.com *.m-pages.com *.m-operations.com unpkg.com *.unpkg.com *.feefo.com *.hotjar.com wss://ws.hotjar.com *.hotjar.io widgets.reevoo.com skynet.reevoo.com measurement-api.criteo.com s.yimg.com metrics.find.gr plausible.io *.doubleclick.net *.pinterest.com *.clarity.ms *.cookiebot.com *.magedeploy.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 style-src-elem 'unsafe-inline' cdn.listrakbi.com *.googleapis.com *.livehelpnow.net *.shipperhq.com tcc.test cary.test *.userway.org thecarycompany.com *.thecarycompany.com; font-src fonts.gstatic.com use.typekit.net www.paypalobjects.com data: *.hawksearch.com *.hawksearch.net *.userway.org *.livehelpnow.net *.shipperhq.com *.gstatic.com *.googleapis.com tcc.test cary.test *.thecarycompany.com thecarycompany.com fonts.googleapis.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com testsecureacceptance.cybersource.com secureacceptance.cybersource.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com 'self' 'unsafe-inline'; frame-ancestors *.certcapture.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.youtube.com *.youtube-nocookie.com bid.g.doubleclick.net www.googletagmanager.com player.vimeo.com https://www.google.com/recaptcha/ www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com *.certcapture.com data: *.avis-verifies.com *.livechatinc.com *.shipperhq.com *.userway.org *.trustpilot.com guarantee-cdn.com *.pinterest.com *.google.com services.listrak.com *.online-metrix.net testflex.cybersource.com flex.cybersource.com testsecureacceptance.cybersource.com secureacceptance.cybersource.com https://www.googletagmanager.com/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com *.googleapis.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com p.typekit.net *.vimeocdn.com i.ytimg.com *.youtube.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com validator.swagger.io *.certcapture.com tcc.test cary.test *.thecarycompany.com www.thecarycompany.com *.adobedtm.com *.wistia.com *.wistia.net *.akamaihd.net seal-chicago.bbb.org *.listrakbi.com maps.gstatic.com *.bing.com *.linkedin.com *.google.com nsg.symantec.com tcs-analytics-tracker.now.sh tcs-analytics-tracker.vercel.app guarantee-cdn.com www.facebook.com hn.inspectlet.com thecarycompany.com *.livehelpnow.net googleadservices.com *.cookielaw.org *.userway.org http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ connect.facebook.net graph.facebook.com business.facebook.com *.googleapis.com maps.googleapis.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com assets.adobedtm.com amcglobal.sc.omtrdc.net *.adobe.io use.typekit.net s.ytimg.com www.googleapis.com *.vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.magento-ds.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com *.magento-datasolutions.com https://rum.hlx.page *.certcapture.com 'unsafe-inline' data: *.wistia.com *.wistia.net seal-chicago.bbb.org *.listrakbi.com nsg.symantec.com *.online-metrix.net *.shipperhq.com *.authorize.net secure.authorize.net test.authorize.net *.licdn.com *.chatservice.co *.inspectlet.com www.facebook.com *.msecnd.net *.bing.com *.doubleclick.net *.google.com *.googleadservices.com *.google-analytics.com *.googlecommerce.com *.googletagmanager.com *.googleapis.com *.gstatic.com guarantee-cdn.com *.cardinalcommerce.com.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.trustpilot.com *.cookielaw.org *.userway.org *.livehelpnow.net *.sentry-cdn.com *.thomasnet.com ip.convirza.com tcc.test cary.test thecarycompany.com *.thecarycompany.com cdn.jsdelivr.net *.pinimg.com *.fontawesome.com *.pinterest.com services.listrak.com testflex.cybersource.com flex.cybersource.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ x.klarnacdn.net connect.facebook.net graph.facebook.com business.facebook.com assets.shipperhq.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com *.certcapture.com data: *.listrakbi.com *.shipperhq.com *.userway.org *.livehelpnow.net tcc.test cary.test *.googleapis.com *.thecarycompany.com thecarycompany.com assets.shipperhq.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com data: *.wistia.com *.wistia.net *.akamaihd.net *.userway.org tcc.test cary.test *.thecarycompany.com thecarycompany.com *.livehelpnow.net http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com vimeo.com *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net api.magento.com *.adobe.io performance.typekit.net commerce.adobe.io *.sentry.io www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.magento-datasolutions.com *.magento-ds.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io *.certcapture.com data: *.wistia.com *.litix.io *.shipperhq.com wss://rms.shipperhq.com *.doubleclick.net *.chatservice.co *.inspectlet.com ws.inspectlet.com tcs-analytics-tracker.now.sh tcs-analytics-tracker.vercel.app *.google.com *.googleapis.com *.bing.com *.trustpilot.com *.cookielaw.org developer.livehelpnow.net *.userway.org *.livehelpnow.net wss://app.livehelpnow.net ip.convirza.com dni.logmycalls.com tcc.test cary.test *.thecarycompany.com thecarycompany.com geolocation.onetrust.com *.linkedin.com *.pinterest.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com rms.shipperhq.com https://rms.shipperhq.com ovs.shipperhq.com 'self' 'unsafe-inline'; child-src *.certcapture.com http: https: blob: 'self' 'unsafe-inline'; default-src *.trustpilot.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://5502b8453f99696234832a80aaf978ec.report-uri.com/r/d/csp/reportOnly; report-to report-endpoint; 1 default-src 'self' *.gstatic.com; img-src 'self' * data:; frame-src 'self' *.retargetly.com *.doubleclick.net; font-src 'self' data: fonts.gstatic.com fonts.googleapis.com; connect-src 'self' *.hypera.com.br http://cdn.evgnet.com/beacon/hyperapharma/hypera/scripts/evergage.min.js https://hyperapharma.us-4.evergage.com https://banner-geolocalizacao.hypera-pharma-s-account.workers.dev https://mapa-gripe.hypera-pharma-s-account.workers.dev *.viacep.com.br *.google-analytics.com *.google.com *.clarity.ms *.hypera.com.br *.retargetly.com *.doubleclick.net; script-src 'self' 'nonce-a9f8efbf1bcb58eaca003c7ff01f8a54' 'nonce-b0d5fee76a0621e54ddbf831efa5a9ba8a4cf33d' 'sha256-R3cSZrKmnEGSaH0zEuTcZ3nnqtzhpC8vkSt+e0OLnGQ=' 'sha256-CmiKzOpf2CeiuZKn3xy9MmkCQwoc1MdoIcO9XfHrnbE=' *.googletagmanager.com *.viacep.com.br *.google.com *.gtm.js https://www.googletagmanager.com *.google-analytics.com *.retargetly.com *.navdmp.com *.gstatic.com *.facebook.net *.clarity.ms *.cloudfront.net cdn.jsdelivr.net *.hypera.com.br api.hypera.com.br hypera.com.br http://cdn.evgnet.com/beacon/hyperapharma/hypera/scripts/evergage.min.js https://hyperapharma.us-4.evergage.com; style-src 'self' 'unsafe-inline' fonts.gstatic.com fonts.googleapis.com *.hypera.com.br 1 script-src 'self' 'nonce-1nz17A0m9C+zPu9W8IbnjqH+Su8=' 'strict-dynamic' 'unsafe-eval'; object-src 'none'; 1 frame-ancestors 'self' *.liantis.be; 1 font-src fonts.gstatic.com use.typekit.net *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com https://www.gstatic.com https://fonts.gstatic.com static.zip.co *.afterpay.com *.yotpo.com *.googleapis.com *.cloudflare.com *.font.im *.optimonk.com *.nikon.co.in *.slant.co *.alicdn.com *.loli.net *.migaku.com *.ziplyne.com *.googleusercontent.com *.nikon.com.au *.hsappstatic.net *.nikon.com.sg *.fontshare.com smc.org.in *.nikon-asia.com *.nikon-mea.com unpkg.com *.nikon.co.th *.crisp.chat *.githack.com yastatic.net *.cdn-apple.com *.jsdelivr.net *.zohocdn.com *.tiktok.com *.vixverify.com *.gstatic.cn use.fontawesome.com maxcdn.bootstrapcdn.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com api.bazaarvoice.com stg.api.bazaarvoice.com *.yotpo.com https://secure-test.worldpay.com/shopper/3ds/ddc.html swellrewards.com *.swellrewards.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ widgets.sandbox.afterpay.com widgets.sandbox.clearpay.co.uk *.sharethis.com https://*.google.com *.doubleclick.net *.facebook.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com *.yotpo.com *.googletagmanager.com https://pay.google.com https://secure-test.worldpay.com swellrewards.com *.swellrewards.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com www.xtento.com zip.co sandbox.zip.co zipmoney.com.au sandbox.zipmoney.com.au checkout.gb.zip.co checkout.quadpay.com checkout-sandbox.quadpay.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.ftcdn.net *.behance.net https://static.afterpay.com https://site-assets.afterpay.com/ *.sharethis.com 'self' data: https://*.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.gstatic.com display.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com network-a.bazaarvoice.com network-stg-a.bazaarvoice.com photos-uat-us.bazaarvoice.com img.youtube.com *.files-text.com *.livechatinc.com *.livechat-files.com *.livechat-static.com https://*.googleapis.com https://*.googleusercontent.com https://maps.gstatic.com zip.co static.zip.co bpi.zip.co *.google.com.au *.linkedin.com *.yahoo.com *.adroll.com *.afterpay.com *.yotpo.com *.bazaarvoice.com *.nikon-mea.com *.nikon.com.hk *.solone.net vumbnail.com www.google.ae www.google.al www.google.am www.google.at www.google.az www.google.ba www.google.be www.google.bf www.google.bi www.google.bj www.google.bs www.google.bt www.google.by www.google.ca www.google.cd www.google.cg www.google.ch www.google.ci www.google.cl www.google.cm www.google.co.ao www.google.co.bw www.google.co.cr www.google.co.id www.google.co.il www.google.co.in www.google.co.jp www.google.co.ke www.google.co.kr www.google.co.ls www.google.co.ma www.google.co.mz www.google.co.nz www.google.co.th www.google.co.tz www.google.co.ug www.google.co.uk www.google.co.uz www.google.co.ve www.google.co.vi www.google.co.za www.google.co.zm www.google.co.zw www.google.com.af www.google.com.ag www.google.com.ar www.google.com.bd www.google.com.bh www.google.com.bn www.google.com.bo www.google.com.br www.google.com.co www.google.com.cy www.google.com.do www.google.com.ec www.google.com.eg www.google.com.et www.google.com.fj www.google.com.gh www.google.com.gt www.google.com.hk www.google.com.jm www.google.com.kh www.google.com.kw www.google.com.lb www.google.com.ly www.google.com.mm www.google.com.mt www.google.com.mx www.google.com.my www.google.com.na www.google.com.ng www.google.com.ni www.google.com.np www.google.com.om www.google.com.pa www.google.com.pe www.google.com.pg www.google.com.ph www.google.com.pk www.google.com.pr www.google.com.py www.google.com.qa www.google.com.sa www.google.com.sb www.google.com.sg www.google.com.sl www.google.com.sv www.google.com.tr www.google.com.tw www.google.com.ua www.google.com.uy www.google.com.vc www.google.com.vn www.google.cz www.google.de www.google.dk www.google.dm www.google.dz www.google.ee www.google.es www.google.fi www.google.fr www.google.ge www.google.gg www.google.gm www.google.gr www.google.hn www.google.hr www.google.ht www.google.hu www.google.ie www.google.im www.google.iq www.google.is www.google.it www.google.jo www.google.kg www.google.kz www.google.la www.google.li www.google.lk www.google.lt www.google.lu www.google.lv www.google.md www.google.me www.google.mg www.google.mk www.google.mn www.google.mu www.google.mv www.google.mw www.google.nl www.google.no www.google.pl www.google.ps www.google.pt www.google.ro www.google.rs www.google.ru www.google.rw www.google.sc www.google.se www.google.si www.google.sk www.google.sn www.google.so www.google.tl www.google.tn www.google.to www.google.tt www.google.vu www.google.ws yastatic.net *.google.com *.mynikonlife.com.au *.nikon.co.in *.nikon.com.au www.google.ad www.google.as www.google.cf www.google.co.ck www.google.com.bz www.google.com.cu www.google.com.gi www.google.com.tj www.google.cv www.google.dj www.google.fm www.google.ga www.google.gl www.google.gy www.google.je www.google.ki www.google.ml www.google.ne www.google.sr www.google.st www.google.td www.google.tg www.google.tm *.baidu.com *.giphy.com *.ibb.co *.riskified.com *.stackadapt.com *.qvdt3feo.com *.truecreatorstudio.com www.google.cn *.nikon.com.sg *.optimonk.com *.crwdcntrl.net *.ctnsnet.com *.ggpht.com *.nikon-asia.com *.nikon.co.th www.google.com.au *.tiktok.com bucket-ip-website.s3.eu-central-1.amazonaws.com www.google.sm bitly.com dakotaram.com s3.amazonaws.com www.google.nu *.3lift.com *.adnxs.com *.adsrvr.org *.amazon-adsystem.com *.bidswitch.net *.bing.com *.bluekai.com *.casalemedia.com *.googleadservices.com *.openx.net *.outbrain.com *.pubmatic.com *.rlcdn.com *.rubiconproject.com *.scorecardresearch.com *.taboola.com *.tapad.com google.com www.google.nr nikon-asia.com *.ytimg.com *.vixverify.com *.yotpoapi.com *.cloudflare.com swellrewards.com *.swellrewards.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com maps.gstatic.com www.xtento.com cdn.xtento.com t.zip.co static.zipmoney.com.au data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com amcglobal.sc.omtrdc.net commerce.adobe.net use.typekit.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-ds.com https://portal.sandbox.clearpay.co.uk https://portal.clearpay.co.uk https://portal.sandbox.afterpay.com https://portal.afterpay.com https://static.afterpay.com https://js.sandbox.afterpay.com https://js.afterpay.com *.sharethis.com *.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.gstatic.com apps.bazaarvoice.com apps.nexus.bazaarvoice.com apps-stg.nexus.bazaarvoice.com analytics-static.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com mpsnare.iesnare.com *.livechatinc.com *.livechat-static.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://maps.googleapis.com snapwidget.com *.zip.co d35p4vvdul393k.cloudfront.net *.yotpo.com *.optimonk.com *.tiktok.com *.crazyegg.com *.adroll.com snap.licdn.com consentag.eu ctnsnet.com *.newrelic.com *.bazaarvoice.com *.disqus.com *.tailwindcss.com *.truecreatorstudio.com *.vimeo.com unpkg.com *.googleapis.com *.nikon.co.in *.alicdn.com *.riskified.com *.stackadapt.com *.qvdt3feo.com translate.google.com.hk *.googleadservices.com *.33across.com *.ctnsnet.com *.instagram.com *.cloudflare.com *.nikon.com.au d16i99j5zwwv51.cloudfront.net *.nikon.com.sg *.nikon-asia.com dakotaram.com *.cfjump.com *.nikon-mea.com *.ucweb.com *.nikon.co.th *.crisp.chat googletagmanager.com yastatic.net *.adobe.net *.adobedtm.com *.cdn-apple.com *.google-analytics.com *.jsdelivr.net *.licdn.com *.mynikonlife.com.au *.netcoresmartech.com localhost *.vixverify.com npmcdn.com *.gstatic.cn https://*.riskified.com https://www.google.com/recaptcha/api.js https://pay.google.com/gp/p/js/pay.js https://applepay.cdn-apple.com/jsapi/v1/apple-pay-sdk.js *.payments.worldpay.com/resources/cse/js/worldpay-cse-1.0.2.min.js https://d35p4vvdul393k.cloudfront.net/sdk_library/us/stg/ops/pc_gsmpi_web_sdk.js https://d16i99j5zwwv51.cloudfront.net/sdk_library/us/prd/ops/pc_gsmpi_web_sdk.js https://payments.worldpay.com/resources/hpp/integrations/embedded/js/hpp-embedded-integration-library.js swellrewards.com *.swellrewards.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com maps.googleapis.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com www.xtento.com cdn.xtento.com static.zipmoney.com.au zip.co 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com static.afterpay.com/ js.sandbox.afterpay.com js.afterpay.com *.sharethis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com display.ugc.bazaarvoice.com *.livechatinc.com https://fonts.googleapis.com zip.co bpi.zip.co *.afterpay.com *.yotpo.com *.bazaarvoice.com *.optimonk.com *.nikon.co.in *.stackadapt.com *.qvdt3feo.com *.truecreatorstudio.com *.nikon.com.au *.nikon.com.sg *.nikon-asia.com *.nikon-mea.com *.nikon.co.th *.mynikonlife.com.au *.vixverify.com unpkg.com *.cloudflare.com swellrewards.com *.swellrewards.com maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com *.stripe.network *.stripecdn.com *.amazon.com 'self' 'unsafe-inline'; object-src *.livechatinc.com 'self' 'unsafe-inline'; media-src *.adobe.com *.livechatinc.com *.livechat-static.com *.vimeocdn.com *.gstatic.com nikon-asia.com *.google.com *.nikon.com.au 'self' 'unsafe-inline'; manifest-src *.netcoresmartech.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io commerce.adobe.net qa-api.magedevteam.com *.sentry.io static.afterpay.com static.sandbox.afterpay.com js.sandbox.afterpay.com js.afterpay.com *.sharethis.com *.google-analytics.com *.facebook.com *.facebook.net https://*.google.com api.bazaarvoice.com stg.api.bazaarvoice.com apps.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com *.livechatinc.com *.text.com api.addressy.com https://ipinfo.io https://*.gstatic.com https://*.googleapis.com https://maps.googleapis.com *.zipmoney.com.au *.zip.co *.afterpay.com *.optimonk.com *.crazyegg.com *.linkedin.com *.tiktok.com ctnsnet.com *.nr-data.net *.googletagmanager.com *.google.com *.googleadservices.com *.yotpo.com *.bazaarvoice.com *.crwdcntrl.net *.doubleclick.net *.truecreatorstudio.com localhost truecreatorstudio.com www.google.ae www.google.al www.google.am www.google.at www.google.az www.google.ba www.google.be www.google.bf www.google.bg www.google.bs www.google.bt www.google.by www.google.ca www.google.cg www.google.ch www.google.cl www.google.co.ao www.google.co.bw www.google.co.cr www.google.co.id www.google.co.il www.google.co.in www.google.co.jp www.google.co.ke www.google.co.kr www.google.co.ma www.google.co.mz www.google.co.nz www.google.co.th www.google.co.tz www.google.co.ug www.google.co.uk www.google.co.uz www.google.co.ve www.google.co.vi www.google.co.za www.google.co.zm www.google.co.zw www.google.com.af www.google.com.ar www.google.com.au www.google.com.bd www.google.com.bh www.google.com.bn www.google.com.bo www.google.com.br www.google.com.co www.google.com.cy www.google.com.ec www.google.com.eg www.google.com.et www.google.com.fj www.google.com.gh www.google.com.gt www.google.com.hk www.google.com.jm www.google.com.kh www.google.com.kw www.google.com.lb www.google.com.mm www.google.com.mt www.google.com.mx www.google.com.my www.google.com.ng www.google.com.np www.google.com.om www.google.com.pa www.google.com.pe www.google.com.pg www.google.com.ph www.google.com.pk www.google.com.py www.google.com.qa www.google.com.sa www.google.com.sg www.google.com.tr www.google.com.tw www.google.com.ua www.google.com.vn www.google.cz www.google.de www.google.dk www.google.dz www.google.ee www.google.es www.google.fi www.google.fr www.google.ge www.google.gm www.google.gr www.google.hn www.google.hr www.google.ht www.google.hu www.google.ie www.google.iq www.google.is www.google.it www.google.jo www.google.kg www.google.kz www.google.la www.google.lk www.google.lt www.google.lu www.google.lv www.google.md www.google.me www.google.mg www.google.mk www.google.mn www.google.mu www.google.mv www.google.mw www.google.nl www.google.no www.google.pl www.google.ps www.google.pt www.google.ro www.google.rs www.google.ru www.google.rw www.google.sc www.google.se www.google.si www.google.sk www.google.tn www.google.to www.google.vu *.nikon.co.in www.google.bj www.google.cd www.google.ci www.google.cm www.google.com.cu www.google.com.ly www.google.com.ni www.google.com.pr www.google.com.sl www.google.com.sv www.google.com.tj www.google.dj www.google.ga www.google.im www.google.je www.google.ml www.google.ne www.google.sn www.google.so www.google.sr www.google.td www.google.tg www.google.tl www.google.tt www.google.ws *.baidu.com *.riskified.com *.stackadapt.com *.qvdt3feo.com www.google.com.na www.google.com.uy www.google.gg *.ctnsnet.com www.google.com.sb www.google.bi lottie.host *.nikon.com.au www.google.ad www.google.com.do *.nikon.com.sg www.google.com.ag www.google.gl *.nikon-asia.com www.google.co.ls www.google.ki www.google.com.bz *.nikon-mea.com www.google.cf *.ucweb.com *.nikon.co.th www.google.tm www.google.st www.google.co.ck *.netcoresmartech.com *.openfpcdn.io *.samsung.com google.com kg668dbov0.execute-api.us-east-1.amazonaws.com www.google.nr www.google.cn www.google.com.gi www.google.cv www.google.gy www.google.sm *.conversionsapigateway.com mpc-prod-1-1053047382554.us-central1.run.app mpc-prod-2-1053047382554.us-central1.run.app mpc-prod-18-s6uit34pua-uc.a.run.app www.google.com.vc www.google.li *.vixverify.com *.alicdn.com mpc-prod-14-s6uit34pua-ue.a.run.app test-drive-20-1053047382554.us-central1.run.app mpc-prod-15-s6uit34pua-uw.a.run.app mpc-prod-16-s6uit34pua-uk.a.run.app www.google.dm mpc2-prod-28-is5qnl632q-ue.a.run.app *.yotpoapi.com www.google.fm swellrewards.com *.swellrewards.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com t.elasticsuite.io *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com 'self' 'unsafe-inline'; child-src *.livechatinc.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.crazyegg.com *.optimonk.com *.facebook.com *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri *.riskified.com 'self' 'unsafe-inline'; report-uri https://c147cc3c-0a23-4d12-a977-70db96924fb4.sansec.watch/; report-to report-endpoint; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net www.searchanise.com *.searchserverapi.com searchserverapi.com *.searchserverapi1.com searchserverapi1.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.gstatic.com www.belle-lingerie.co.uk data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * www.searchanise.com *.searchserverapi.com *.searchserverapi1.com *.twitter.com www.belle-lingerie.co.uk 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.link.com *.amazon.com www.belle-lingerie.co.uk 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de account.fetchify.com js.mollie.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * www.searchanise.com *.searchserverapi.com *.searchserverapi1.com *.twitter.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.trustpilot.com *.googletagmanager.com www.belle-lingerie.co.uk 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io https://images.unsplash.com d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.payments-amazon.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://www.mollie.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.twitter.com *.twimg.com www.google.ru www.searchanise.com *.searchserverapi.com searchserverapi.com *.searchserverapi1.com searchserverapi1.com s3.amazonaws.com *.googletagmanager.com ssl.gstatic.com www.gstatic.com www.belle-lingerie.co.uk data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net https://maps.googleapis.com *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de cc-cdn.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ js.mollie.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com searchanise-ef84.kxcdn.com s3.amazonaws.com ajax.aspnetcdn.com www.searchanise.com *.searchserverapi.com searchserverapi.com *.searchserverapi1.com searchserverapi1.com *.searchanise.com api.amplitude.com *.twitter.com *.twimg.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com *.trustpilot.com *.googletagmanager.com tagmanager.google.com www.belle-lingerie.co.uk 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com cc-cdn.com https://static.klaviyo.com assets.braintreegateway.com www.searchanise.com *.searchserverapi.com searchserverapi.com *.searchserverapi1.com searchserverapi1.com searchanise-ef84.kxcdn.com s3.amazonaws.com *.twitter.com ton.twimg.com *.stripe.network *.stripecdn.com *.amazon.com *.trustpilot.com tagmanager.google.com fonts.google.com www.belle-lingerie.co.uk 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.belle-lingerie.co.uk 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io https://maps.googleapis.com https://player.vimeo.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de api.craftyclicks.co.uk pcls1.craftyclicks.co.uk cc-cdn.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com api.amplitude.com stats.g.doubleclick.net www.google-analytics.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.googletagmanager.com www.belle-lingerie.co.uk 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com www.belle-lingerie.co.uk http: https: blob: 'self' 'unsafe-inline'; default-src www.belle-lingerie.co.uk 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://assets.adobedtm.com https://static.cloud.coveo.com https://www.gstatic.com https://www.google.com https://maps.googleapis.com https://dpm.demdex.net; https://analytics.cloud.coveo.com https://marketplace.api.healthcare.gov https://viewlicense.adobe.io https://smetrics.bcbsnd.com https://px.ads.linkedin.com https://geo.fcc.gov; style-src-attr 'self' 'unsafe-inline'; style-src-elem 'self' 'unsafe-inline'; script-src-attr 'self' 'unsafe-inline'; script-src-elem 'self' 'unsafe-inline' https://assets.adobedtm.com https://static.cloud.coveo.com https://acrobatservices.adobe.com https://www.gstatic.com https://www.google.com https://maps.googleapis.com https://www.youtube.com https://player.vimeo.com https://connect.facebook.net https://api.dmcdn.net https://googleads.g.doubleclick.net https://snap.licdn.com https://www.googletagmanager.com https://ipapi.co; connect-src 'self' https://dpm.demdex.net https://analytics.cloud.coveo.com https://platform.cloud.coveo.com https://platformhipaa.cloud.coveo.com https://marketplace.api.healthcare.gov https://viewlicense.adobe.io https://smetrics.bcbsnd.com https://px.ads.linkedin.com https://maps.googleapis.com https://www.google.com https://api.bcbsnd.com https://geo.fcc.gov; img-src 'self' data: https://cm.everesttech.net https://maps.gstatic.com https://smetrics.bcbsnd.com https://www.google.co.in https://www.facebook.com https://www.google.com; media-src 'self' https://dai.ly https://dl6.webmfiles.org https://fb.watch https://vimeo.com https://youtube.com https://youtu.be; frame-src 'self' https://bcbsnd.demdex.net https://acrobatservices.adobe.com https://www.googletagmanager.com https://www.google.com https://player.vimeo.com https://www.youtube.com; report-to csp-endpoint; report-uri /services/bcbsnd/cspViolation 1 base-uri 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' assets.talentio.com cdn.ravenjs.com widget.intercom.io js.intercomcdn.com www.google-analytics.com analytics.google.com translate.googleapis.com www.googletagmanager.com ; img-src 'self' data: blob: https: http:; child-src 'self' blob:; form-action 'self' www.facebook.com id.talentio.com api-iam.intercom.io ; font-src 'self' data: assets.talentio.com fonts.gstatic.com use.fontawesome.com use.typekit.net fonts.intercomcdn.com ; frame-ancestors 'self'; frame-src 'self' blob: youtube.com *.youtube.com speakerdeck.com *.speakerdeck.com slideshare.net *.slideshare.net twitter.com *.twitter.com note.com *.note.com google.com *.google.com google.co.jp *.google.co.jp facebook.com *.facebook.com backcheck.jp *.backcheck.jp s3.ap-northeast-1.amazonaws.com intercom-sheets.com; manifest-src 'none'; object-src 'self' blob: s3.ap-northeast-1.amazonaws.com; style-src 'self' 'unsafe-inline' assets.talentio.com fonts.googleapis.com use.typekit.net p.typekit.net use.fontawesome.com translate.googleapis.com ; media-src 'none'; worker-src 'self' blob:; connect-src 'self' assets.talentio.com *.sentry.io sentry.io api-iam.intercom.io uploads.intercomcdn.com wss://nexus-websocket-a.intercom.io www.google-analytics.com analytics.google.com s3.ap-northeast-1.amazonaws.com translate.googleapis.com 1 default-src 'self' https: data: blob: wss: 'unsafe-eval' 'unsafe-inline'; script-src 'report-sample' 'self' 'unsafe-eval' 'unsafe-inline' *.%2A.civiccomputing.com *.civiccomputing.com *.clarity.ms *.cloudflare.com *.googletagmanager.com *.jsdelivr.net *.library.wales; style-src-attr 'unsafe-inline' 'report-sample'; img-src 'self' data: *.ytimg.com *.vimeocdn.com *.youtube.com https://*.googleapis.com https://*.gstatic.com *.google.com *.googleusercontent.com *.google-analytics.com *.googletagmanager.com *.g.doubleclick.net *.google.ad *.google.ae *.google.al *.google.am *.google.as *.google.at *.google.az *.google.ba *.google.be *.google.bf *.google.bg *.google.bi *.google.bj *.google.bs *.google.bt *.google.by *.google.ca *.google.cat *.google.cd *.google.cf *.google.cg *.google.ch *.google.ci *.google.cl *.google.cm *.google.cn *.google.co.ao *.google.co.bw *.google.co.ck *.google.co.cr *.google.co.id *.google.co.il *.google.co.in *.google.co.jp *.google.co.ke *.google.co.kr *.google.co.ls *.google.co.ma *.google.co.mz *.google.co.nz *.google.co.th *.google.co.tz *.google.co.ug *.google.co.uk *.google.co.uz *.google.co.ve *.google.co.vi *.google.co.za *.google.co.zm *.google.co.zw *.google.com.af *.google.com.ag *.google.com.ar *.google.com.au *.google.com.bd *.google.com.bh *.google.com.bn *.google.com.bo *.google.com.br *.google.com.bz *.google.com.co *.google.com.cu *.google.com.cy *.google.com.do *.google.com.ec *.google.com.eg *.google.com.et *.google.com.fj *.google.com.gh *.google.com.gi *.google.com.gt *.google.com.hk *.google.com.jm *.google.com.kh *.google.com.kw *.google.com.lb *.google.com.ly *.google.com.mm *.google.com.mt *.google.com.mx *.google.com.my *.google.com.na *.google.com.ng *.google.com.ni *.google.com.np *.google.com.om *.google.com.pa *.google.com.pe *.google.com.pg *.google.com.ph *.google.com.pk *.google.com.pr *.google.com.py *.google.com.qa *.google.com.sa *.google.com.sb *.google.com.sg *.google.com.sl *.google.com.sv *.google.com.tj *.google.com.tr *.google.com.tw *.google.com.ua *.google.com.uy *.google.com.vc *.google.com.vn *.google.cv *.google.cz *.google.de *.google.dj *.google.dk *.google.dm *.google.dz *.google.ee *.google.es *.google.fi *.google.fm *.google.fr *.google.ga *.google.ge *.google.gg *.google.gl *.google.gm *.google.gr *.google.gy *.google.hn *.google.hr *.google.ht *.google.hu *.google.ie *.google.im *.google.iq *.google.is *.google.it *.google.je *.google.jo *.google.kg *.google.ki *.google.kz *.google.la *.google.li *.google.lk *.google.lt *.google.lu *.google.lv *.google.md *.google.me *.google.mg *.google.mk *.google.ml *.google.mn *.google.mu *.google.mv *.google.mw *.google.ne *.google.nl *.google.no *.google.nr *.google.nu *.google.pl *.google.pn *.google.ps *.google.pt *.google.ro *.google.rs *.google.ru *.google.rw *.google.sc *.google.se *.google.sh *.google.si *.google.sk *.google.sm *.google.sn *.google.so *.google.sr *.google.st *.google.td *.google.tg *.google.tl *.google.tm *.google.tn *.google.to *.google.tt *.google.vu *.google.ws *.library.wales *.llgc.org.uk *.staticflickr.com *.ticketsource.co.uk fonts.gstatic.com play.google.com syndication.twitter.com translate.google.com; base-uri 'self'; frame-src 'self' *.youtube-nocookie.com *.youtube.com *.vimeo.com *.google.com *.doubleclick.net *.googletagmanager.com *.libanswers.com *.library.wales *.llyfrgell.cymru *.lyfrgell.cymru *.twitter.com div.show hwb.gov.wales sketchfab.com www.canva.com; style-src-elem 'report-sample' 'self' 'unsafe-inline' *.clarity.ms *.fontawesome.com *.libanswers.com *.library.wales connect.facebook.net fonts.googleapis.com; script-src-elem 'self' 'nonce-r6Zp9llP797TGgg60x-1lZS3jSuBsgeSiIDZKnDr-5m26qMRqTtx0A' https: 'unsafe-eval' blob: *.%2A.civiccomputing.com *.%2A.v2.scr.kaspersky-labs.com *.civiccomputing.com *.flickr.com *.googletagmanager.com *.libanswers.com adblockers.opera-mini.net connect.facebook.net s3.amazonaws.com wusote.hirizasune.com 'report-sample'; connect-src 'self' https: data: blob: wss: *.google.com https://*.googleapis.com https://*.gstatic.com *.googletagmanager.com *.google-analytics.com *.analytics.google.com *.g.doubleclick.net *.google.ad *.google.ae *.google.al *.google.am *.google.as *.google.at *.google.az *.google.ba *.google.be *.google.bf *.google.bg *.google.bi *.google.bj *.google.bs *.google.bt *.google.by *.google.ca *.google.cat *.google.cd *.google.cf *.google.cg *.google.ch *.google.ci *.google.cl *.google.cm *.google.cn *.google.co.ao *.google.co.bw *.google.co.ck *.google.co.cr *.google.co.id *.google.co.il *.google.co.in *.google.co.jp *.google.co.ke *.google.co.kr *.google.co.ls *.google.co.ma *.google.co.mz *.google.co.nz *.google.co.th *.google.co.tz *.google.co.ug *.google.co.uk *.google.co.uz *.google.co.ve *.google.co.vi *.google.co.za *.google.co.zm *.google.co.zw *.google.com.af *.google.com.ag *.google.com.ar *.google.com.au *.google.com.bd *.google.com.bh *.google.com.bn *.google.com.bo *.google.com.br *.google.com.bz *.google.com.co *.google.com.cu *.google.com.cy *.google.com.do *.google.com.ec *.google.com.eg *.google.com.et *.google.com.fj *.google.com.gh *.google.com.gi *.google.com.gt *.google.com.hk *.google.com.jm *.google.com.kh *.google.com.kw *.google.com.lb *.google.com.ly *.google.com.mm *.google.com.mt *.google.com.mx *.google.com.my *.google.com.na *.google.com.ng *.google.com.ni *.google.com.np *.google.com.om *.google.com.pa *.google.com.pe *.google.com.pg *.google.com.ph *.google.com.pk *.google.com.pr *.google.com.py *.google.com.qa *.google.com.sa *.google.com.sb *.google.com.sg *.google.com.sl *.google.com.sv *.google.com.tj *.google.com.tr *.google.com.tw *.google.com.ua *.google.com.uy *.google.com.vc *.google.com.vn *.google.cv *.google.cz *.google.de *.google.dj *.google.dk *.google.dm *.google.dz *.google.ee *.google.es *.google.fi *.google.fm *.google.fr *.google.ga *.google.ge *.google.gg *.google.gl *.google.gm *.google.gr *.google.gy *.google.hn *.google.hr *.google.ht *.google.hu *.google.ie *.google.im *.google.iq *.google.is *.google.it *.google.je *.google.jo *.google.kg *.google.ki *.google.kz *.google.la *.google.li *.google.lk *.google.lt *.google.lu *.google.lv *.google.md *.google.me *.google.mg *.google.mk *.google.ml *.google.mn *.google.mu *.google.mv *.google.mw *.google.ne *.google.nl *.google.no *.google.nr *.google.nu *.google.pl *.google.pn *.google.ps *.google.pt *.google.ro *.google.rs *.google.ru *.google.rw *.google.sc *.google.se *.google.sh *.google.si *.google.sk *.google.sm *.google.sn *.google.so *.google.sr *.google.st *.google.td *.google.tg *.google.tl *.google.tm *.google.tn *.google.to *.google.tt *.google.vu *.google.ws; font-src 'self' https: data: blob: wss: https://fonts.gstatic.com; worker-src 'self' 'nonce-r6Zp9llP797TGgg60x-1lZS3jSuBsgeSiIDZKnDr-5m26qMRqTtx0A' blob:; style-src 'self' https: data: blob: wss: 'unsafe-eval' 'unsafe-inline' 'inline' 'report-sample'; report-uri https://www.library.wales/@http-reporting?csp=report&requestTime=1770427623530555&requestHash=3a0654465113019032297a59309aa081749a9b01 1 script-src 'self' 'unsafe-inline' 'unsafe-eval' hubspot.mintlify.dev app.hubspot.com cdn-3.convertexperiments.com cdnjs.cloudflare.com connect.facebook.net cta-service-cms2.hubspot.com js.hsforms.net js.hs-analytics.net js.hs-banner.com js.hsleadflows.net js.hubspotfeedback.com js.usemessages.com platform.twitter.com play.vidyard.com run.pstmn.io script.crazyegg.com script.hotjar.com static.hotjar.com static.hsappstatic.net use.typekit.net www.googletagmanager.com www.google-analytics.com www.hubspot.com 'strict-dynamic' 'nonce-V5pD+rJBe/GrGxT+4JgUPA=='; report-uri https://send.hsbrowserreports.com/csp/report 1 default-src 'self';base-uri 'self';frame-ancestors 'self';frame-src https://* 'self' epichttp:;script-src 'nonce-13613564fcbe4835a43649cf1b3c4d48' https://www.viewmychart.com 'self';img-src https://* 'self' blob: data:;style-src https://www.viewmychart.com 'self' 'unsafe-inline';worker-src 'self' blob:;child-src 'self' blob:;form-action https://central.mychart.org/MyChart/ 'self';media-src https://* 'self' blob:; 1 frame-src 'self'; report-uri http://events.convio.com/site/XFrameViolation 1 font-src fonts.gstatic.com use.typekit.net *.googleapis.com https://www.gstatic.com https://fonts.gstatic.com *.fontawesome.com maxcdn.bootstrapcdn.com https://widgets.trustedshops.com https://fonts.googleapis.com https://cdnjs.cloudflare.com https://cdn.jsdelivr.net https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action 'self' 'unsafe-inline'; frame-ancestors *.meetanshi.com 'self'; frame-src bid.g.doubleclick.net www.youtube.com *.youtube-nocookie.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ https://www.paypal.com https://www.sandbox.paypal.com https://hostedfields-externalapi.alpha.buckaroo.aws https://hostedfields-externalapi.prod-pci.buckaroo.io www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com magento-cloudflare.jetrails.com https://*.google.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com *.meetanshi.com www.googletagmanager.com 'self' 'unsafe-inline'; img-src data: widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io *.googleapis.com https://*.gstatic.com www.apptrian.com https://portal.payconiq.com https://static.buckaroo.nl https://www.buckaroo.nl https://www.paypalobjects.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.ytimg.com https://*.google.com https://*.googleapis.com https://*.googleusercontent.com *.meetanshi.com *.google.com *.googleadservices.com *.googletagmanager.com https://widgets.trustedshops.com https://widgets-qa.trustedshops.com *.etrusted.com https://minicar-parts.nl https://mylivechat.com https://uk.mylivechat.com https://integrations.etrusted.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; script-src www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.commerce-payment-services.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.googleapis.com https://*.gstatic.com www.apptrian.com https://static.buckaroo.nl https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl https://buckaroo.nl https://www.paypal.com https://www.sandbox.paypal.com https://applepay.cdn-apple.com https://hostedfields-externalapi.alpha.buckaroo.aws https://hostedfields-externalapi.prod-pci.buckaroo.io www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://*.google.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com *.meetanshi.com *.googletagmanager.com *.googleadservices.com *.google-analytics.com https://www.postcode-checkout.nl/api/international/v1/autocomplete/* https://widgets.trustedshops.com https://widgets-qa.trustedshops.com https://integrations.etrusted.com https://integrations.etrusted.site https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.etrusted.com https://www.feedbackcompany.com https://mylivechat.com https://uk.mylivechat.com https://*.widget.trengo.eu https://www.clarity.ms https://consent.cookiebot.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com https://static.buckaroo.nl https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl https://fonts.googleapis.com https://hcaptcha.com https://*.hcaptcha.com *.fontawesome.com maxcdn.bootstrapcdn.com https://widgets.trustedshops.com https://static-app.connect.trustedshops.com https://static-app.connect-qa.trustedshops.com *.etrusted.com https://uk.mylivechat.com https://integrations.etrusted.com https://fonts.bunny.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src www.apptrian.com https://*.widget.trengo.eu 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com vimeo.com *.adobe.io performance.typekit.net *.sentry.io *.googleapis.com www.apptrian.com wss://websocketservice-externalapi.prod.buckaroo.io https://static.buckaroo.nl wss://websockets.buckaroo.io/ https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl https://hostedfields-externalapi.alpha.buckaroo.aws https://hostedfields-externalapi.prod-pci.buckaroo.io https://applepay.buckaroo.io https://www.paypal.com https://www.sandbox.paypal.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://ipinfo.io https://*.google.com https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com *.meetanshi.com *.googletagmanager.com stats.g.doubleclick.net https://www.postcode-checkout.nl/api/international/v1/autocomplete/* *.trustedshops.com *.etrusted.com https://integrations.etrusted.site https://www.feedbackcompany.com https://mylivechat.com https://uk.mylivechat.com https://*.widget.trengo.eu https://inc.minicar-parts.nl https://*.clarity.ms https://*.cookiebot.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src https:; font-src https: data:; style-src 'unsafe-inline' https:; object-src 'self';connect-src https: wss:; script-src 'nonce-m+6PTAkl/U46I1GFiNOL8CBF9e2i0ZwMS6cmwSskJZw=' 'strict-dynamic' 'unsafe-eval' 'unsafe-inline' https: 'report-sample'; img-src https: data:; report-uri /webhooks/csp-log/create 1 frame-ancestors 'self' https://www.google.com; script-src 'self' https://www.google.com https://www.google-analytics.com https://www.gstatic.com https://embed.tawk.to https://www.googletagmanager.com https://vamosbets.net https://cdn.jsdelivr.net 'unsafe-eval' 'unsafe-inline'; style-src 'self' https://vamosbets.net https://embed.tawk.to 'unsafe-inline'; img-src 'self' https://assetsbm.plqcdn.com https://assetsbm.plqcdn.com https://cdn.jsdelivr.net https://s3.amazonaws.com https://translate.google.com/ https://www.googletagmanager.com https://fonts.gstatic.com https://vamosbets.net https://assets.plqcdn.com https://embed.tawk.to https://tawk.link https://i.ytimg.com data:; font-src 'self' https://fonts.gstatic.com https://vamosbets.net https://embed.tawk.to data:; manifest-src 'self' https://vamosbets.net; report-uri https://smain.requestcatcher.com/test 1 script-src 'self' 'report-sample' https://static.mycasavi.com 'sha256-HqcrltV/add35ktFKnghPtUZD86xFk2tNSOVuSxlxZI=' 'sha256-nP0EI9B9ad8IoFUti2q7EQBabcE5MS5v0nkvRfUbYnM=' https://cdn.eu.pendo.io https://pendo-eu-static.storage.googleapis.com https://pendo-eu-static-5744612903485440.storage.googleapis.com https://app.intercom.io https://widget.intercom.io/ https://js.intercomcdn.com https://browser.sentry-cdn.com https://widget.moin.ai https://cdn.crowdin.com https://crowdin.com https://cdn-a.cumul.io https://static.hotjar.com https://script.hotjar.com https://maps.googleapis.com https://cdn.jsdelivr.net https://agent.b4u-cloud.de 'nonce-b/FHBaVhwUTca6amqoYH8A==';worker-src 'self' blob: https://static.mycasavi.com;report-uri /csp-report;base-uri 'self';frame-ancestors 'self';object-src 'none';script-src-attr 'none' 1 default-src 'self' 846-hel-222.mktoresp.com 173-dti-322.mktoresp.com 059-alg-683.mktoresp.com js.zi-scripts.com static.addtoany.com stats.g.doubleclick.net tracking-api.g2.com play.google.com www.google.com; connect-src 'self' 846-hel-222.mktoweb.com analytics.google.com c.6sc.co ipv6.6sc.co cdn.cookielaw.org distillery.wistia.com fast.wistia.com pipedream.wistia.com geolocation.onetrust.com epsilon.6sense.com secure.adnxs.com ws.zoominfo.com px.ads.linkedin.com www.google.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net jnn-pa.googleapis.com api.simplecast.com cdn.simplecast.com givebutter.com umsafoundation.org www.youtube.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com pagead2.googlesyndication.com google.com stats.g.doubleclick.net js.zi-scripts.com privacyportal-eu.onetrust.com 846-hel-222.mktoresp.com app.qualified.com tracking-api.g2.com tr.capterra.com 173-dti-322.mktoresp.com embed-cloudfront.wistia.com *.clarity.ms 173-dti-322.mktoutil.com www.google.com.co; font-src 'self' www.perforce.com www.blazemeter.com www.gliffy.com www.jrebel.com www.openlogic.com www.zend.com www.puppet.com www.perfecto.io fonts.gstatic.com cdn.simplecast.com data: fast.wistia.com use.typekit.net www.gartner.com; frame-src 'self' 846-hel-222.mktoweb.com 173-dti-322.mktoresp.com 059-alg-683.mktoresp.com resources.perforce.com static.addtoany.com www.googletagmanager.com www.perforce.com www.blazemeter.com www.gliffy.com www.jrebel.com www.openlogic.com www.zend.com www.puppet.com www.perfecto.io fast.wistia.net player.simplecast.com www.youtube.com umsafoundation.org live-totalview.pantheonsite.io live-imsl.pantheonsite.io www.google.com app.qualified.com fast.wistia.com player.vimeo.com player.captivate.fm 605957.extforms.netsuite.com www.gartner.com; img-src 'self' data: b.6sc.co c.bing.com bat.bing.com *.clarity.ms cdn.cookielaw.org cdn2.hubspot.net embed-ssl.wistia.com f.hubspotusercontent00.net pic.trendemon.com px.ads.linkedin.com trackingapi.trendemon.com analytics.twitter.com cdn.bizible.com cdn.bizibly.com googleads.g.doubleclick.net t.co track.hubspot.com www.facebook.com www.gliffy.com www.google.com www.linkedin.com www.perforce.com www.blazemeter.com www.jrebel.com www.openlogic.com www.zend.com www.puppet.com www.perfecto.io umsafoundation.org live-mondrian.pantheonsite.io i.ytimg.com image.simplecastcdn.com yt3.ggpht.com fast.wistia.net googletagmanager.com ssl.gstatic.com www.gstatic.com *.google-analytics.com *.googletagmanager.com www.googletagmanager.com pagead2.googlesyndication.com www.googleadservices.com google.com www.google.com.tw www.google.mn fast.wistia.com www.google.co.uk www.google.com.br www.google.no fonts.gstatic.com www.google.co.in www.google.com.ec www.google.pl; manifest-src 'self' 846-hel-222.mktoresp.com 173-dti-322.mktoresp.com 059-alg-683.mktoresp.com js.zi-scripts.com static.addtoany.com stats.g.doubleclick.net tracking-api.g2.com play.google.com www.google.com www.perforce.com www.blazemeter.com www.gliffy.com www.jrebel.com www.openlogic.com www.zend.com www.puppet.com www.perfecto.io; media-src 'self' blob: app.qualified.com fast.wistia.com embed-ssl.wistia.com data: embed-fastly.wistia.com embed-cloudfront.wistia.com; object-src 'self'; script-src 'self' 'report-sample' 'unsafe-eval' 846-hel-222.mktoweb.com assets.trendemon.com browser.sentry-cdn.com cdn.cookielaw.org cdn.jsdelivr.net cdnjs.cloudflare.com fast.wistia.com fast.wistia.net googleads.g.doubleclick.net j.6sc.co js.zi-scripts.com munchkin.marketo.net resources.perforce.com *.clarity.ms snap.licdn.com static.addtoany.com static.cloudflareinsights.com trackingapi.trendemon.com tracking.g2crowd.com ct.capterra.com cdn.bizible.com cdn.getmoreproof.com js.hs-analytics.net js.hs-banner.com js.hs-scripts.com connect.facebook.net static.ads-twitter.com p-js.s3.amazonaws.com player.simplecast.com widgets.givebutter.com www.google.com www.googletagmanager.com www.perforce.com www.blazemeter.com www.gliffy.com www.jrebel.com www.openlogic.com www.zend.com www.puppet.com www.perfecto.io umsafoundation.org www.youtube.com googletagmanager.com tagmanager.google.com *.googletagmanager.com www.googleadservices.com pagead2.googlesyndication.com https://cdn.ckeditor.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://code.highcharts.com https://fast.wistia.com https://resources.perforce.com https://resources.roguewave.com https://static.addtoany.com https://unpkg.com info.perforce.com 'nonce-PVCqz_OIHRw8o4_ajlw0Cw'; script-src-elem 'self' feedback.perforce.com js.qualified.com cdn.cookielaw.org googleads.g.doubleclick.net ct.capterra.com gist.github.com j.6sc.co munchkin.marketo.net trackingapi.trendemon.com scripts.clarity.ms js.zi-scripts.com cdnjs.cloudflare.com https://cdn.ckeditor.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://code.highcharts.com https://fast.wistia.com https://resources.perforce.com https://resources.roguewave.com https://static.addtoany.com https://unpkg.com info.perforce.com resources.perforce.com 'nonce-PVCqz_OIHRw8o4_ajlw0Cw'; style-src 'self' 'report-sample' 'unsafe-inline' 846-hel-222.mktoweb.com cdnjs.cloudflare.com resources.perforce.com www.perforce.com www.blazemeter.com www.gliffy.com www.jrebel.com www.openlogic.com www.zend.com www.puppet.com www.perfecto.io fonts.googleapis.com www.youtube.com googletagmanager.com tagmanager.google.com app-ab48.marketo.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://code.highcharts.com https://unpkg.com; style-src-elem 'self' feedback.perforce.com resources.perforce.com www.googletagmanager.com cdnjs.cloudflare.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://code.highcharts.com https://unpkg.com; webrtc 'block'; worker-src 'self' blob:; base-uri 'self'; form-action 'self' https://feedback.perforce.com; frame-ancestors 'self' www.perforce.com 1 default-src 'self' 'nonce-qLf0JuC+ROhvf9AkrGL6ug==' *.google-analytics.com *.googlesyndication.com *.gstatic.com *.youtube.com *.fontawesome.com *.googletagmanager.com *.trustpilot.com; script-src 'strict-dynamic' 'unsafe-eval' 'nonce-qLf0JuC+ROhvf9AkrGL6ug==' *.unpkg.com *.addtoany.com *.trustpilot.com https://www.googletagmanager.com https://www.googleadservices.com https://googleads.g.doubleclick.net https://www.google.com *.jsdelivr.net *.vimeo.com *.godaddy.com *.cloudflare.com *.google-analytics.com; style-src 'unsafe-inline' 'self' *.jsdelivr.net *.cloudflare.com *.typekit.net https://tagmanager.google.com https://fonts.googleapis.com; connect-src 'self' https://lottie.host/ *.6sense.com *.pingdom.net *.salesloft.com http://ib.adnxs.com https://secure.adnxs.com/ https://pagead2.googlesyndication.com https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://*.g.doubleclick.net https://*.google.com https://*.google.co.uk *.cookiebot.com *.linkedin.com *.6sc.co; frame-src 'self' 'nonce-qLf0JuC+ROhvf9AkrGL6ug==' *.addtoany.com https://www.googletagmanager.com https://td.doubleclick.net *.youtube.com *.vimeo.com *.google.com *.cookiebot.com *.trustpilot.com *.doubleclick.net; font-src 'self' 'nonce-qLf0JuC+ROhvf9AkrGL6ug==' data: *.jsdelivr.net *.cloudflare.com *.typekit.net *.fontawesome.com https://fonts.gstatic.com; img-src 'self' data: https://www.quartix.com/ https://b.sf-syn.com/ https://www.google.com https://googleads.g.doubleclick.net https://pagead2.googlesyndication.com https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://ssl.gstatic.com https://www.gstatic.com *.gravatar.com *.google.co.uk *.6sc.co *.facebook.com *.facebook.net *.linkedin.com *.metricool.com *.cookiebot.com; object-src 'nonce-qLf0JuC+ROhvf9AkrGL6ug=='; 1 font-src fonts.gstatic.com use.typekit.net maxcdn.bootstrapcdn.com *.fontawesome.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.demdex.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com www.facebook.com platform.twitter.com td.doubleclick.net 13605183.fls.doubleclick.net www.google.com cdn.octadesk.com *.infonet.com.py *.infonet.com.py:8888/ https://vpos.infonet.com.py:8888/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net www.facebook.com pinterest.com assets.pinterest.com syndication.twitter.com static.tacdn.com ad.doubleclick.net www.google.com.py adservice.google.com c.clarity.ms c.bing.com cellshop.com.py integration-5ojmyuq-qoiivjresdo6e.us-5.magentosite.cloud cdn.leadster.com.br *.googletagmanager.com ssl.gstatic.com www.gstatic.com *.google.co.in https://desa.infonet.com.py:8035/ https://firebasestorage.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com maps.gstatic.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net assets.adobedtm.com *.adobe.io www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com *.magento-ds.com connect.facebook.net twitter.com platform.twitter.com static.addtoany.com static.cloudflareinsights.com js-agent.newrelic.com www.tripadvisor.com unpkg.com www.tripadvisor.es www.google.com static.tacdn.com www.gstatic.com www.clarity.ms www.jscache.com vpos.infonet.com.py www.tripadvisor.com.br cdn.octadesk.com *.cellshop.com.py *.googletagmanager.com https://www.googleadservices.com https://googleads.g.doubleclick.net https://www.google.com tagmanager.google.com ssl.google-analytics.com *.infonet.com.py:8888/ *.avada.io js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com maps.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.magento-datasolutions.com *.magento-ds.com static.tacdn.com tagmanager.google.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.magento-datasolutions.com *.magento-ds.com stats.addtoany.com *.infonet.com.py:8888 *.infonet.com.py bam.nr-data.net t.clarity.ms *.analytics.google.com *.google-analytics.com *.googletagmanager.com *.g.doubleclick.net *.google.com https://viacep.com.br https://www.viacep.com.br https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com google.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com bam.nr-data.net t.clarity.ms commerce.adobedc.net 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.googleapis.com fonts.gstatic.com celebrosnlp.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.facebook.com *.facebook.com *.facebook.net *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ www.xtento.com ws.sharethis.com c.sharethis.mgr.consensu.org www.facebook.com t.sharethis.com *.weltpixel.com *.facebook.com *.facebook.net www.paypal.com www.sandbox.paypal.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * landofcoder.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net *.vimeocdn.com i.ytimg.com *.youtube.com gateway.apaylater.com gateway.atome.sg www.xtento.com cdn.xtento.com https://a.klaviyo.com *.facebook.com *.facebook.net www.paypal.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.gstatic.com *.cdninstagram.com *.fbcdn.net maps.googleapis.com celebrosnlp.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ gateway.apaylater.com gateway.atome.sg www.xtento.com cdn.xtento.com connect.facebook.net googletagmanager.com ws.sharethis.com maps.googleapis.com foursixty.com jscdn.appier.net click.accesstra.de goofleads.g.doubleclick.net t.sharethis.com https://static.klaviyo.com https://fast.a.klaviyo.com s7.addthis.com *.facebook.com *.facebook.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com landofcoder.com https://www.googletagmanager.com tagmanager.google.com ajax.googleapis.com *.instagram.com celebrosnlp.com ai.celebros-analytics.com *.celebros.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com gateway.apaylater.com gateway.atome.sg fonts.googleapis.com cdn.curator.io ws.sharethis.com unsafe-inline assets.braintreegateway.com tagmanager.google.com celebrosnlp.com 'self' 'unsafe-inline'; object-src landofcoder.com 'self' 'unsafe-inline'; media-src *.adobe.com *.cdninstagram.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com vimeo.com anylist.c.appier.net l.sharethis.com https://static.klaviyo.com https://fast.a.klaviyo.com ekr.zdassets.com/ *.facebook.com *.facebook.net www.paypal.com www.sandbox.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com landofcoder.com https://www.google-analytics.com *.instagram.com *.googleusercontent.com *.celebros.com *.celebros.com:446 *.celebros-analytics.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self';base-uri 'self';frame-ancestors 'self';frame-src https://* 'self' epichttp: https://pay.instamed.com https://premier.trustcommerce.com;script-src 'nonce-59d8de1f08bd47169154a130c3012710' https://essentiamychart.org 'self';img-src https://* 'self' blob: data:;connect-src 'self' epichttp:;style-src https://essentiamychart.org 'self' 'unsafe-inline';worker-src 'self' blob:;child-src 'self' blob:;form-action https://central.mychart.org/MyChart/ 'self';media-src https://* 'self' blob:; 1 base-uri widget.sleeknote.com widget.solvemate.com 'self' 'unsafe-inline'; 1 object-src 'none'; worker-src 'self' blob:; base-uri 'self'; frame-ancestors 'self' 1 child-src self; connect-src self; default-src self; font-src self; img-src self; manifest-src self; media-src self; prefetch-src self; object-src self; script-src 'strict-dynamic' 'sha256-SR8bN339OMynNJtiOzokEXzJnun61AQRM3sZP6Vm+M4=' 'sha256-q3zEDUi6jsrAJ7yXcvfYY8d0Of1fXCLY/i1LV+xLmM8=' 'nonce-ZGRmZjE0NDNmZDc5OGVjYTQ5ZDZiYWViNjQ3ZTMzYzE4ZDE2NjExODNhYzZkM2Q0ODBmZTcwMDA0MzYwNzMzNDdmMTRmNzBiNDQxMjU4Yzk1NTc0YmVjY2RjNGI5ZWI5MGFkNzcyYTJlZjZmOWFiMGNjOGY5ZjA2NTc1MmNiNWI=' self; style-src 'nonce-ZGRmZjE0NDNmZDc5OGVjYTQ5ZDZiYWViNjQ3ZTMzYzE4ZDE2NjExODNhYzZkM2Q0ODBmZTcwMDA0MzYwNzMzNDdmMTRmNzBiNDQxMjU4Yzk1NTc0YmVjY2RjNGI5ZWI5MGFkNzcyYTJlZjZmOWFiMGNjOGY5ZjA2NTc1MmNiNWI=' self; worker-src self; frame-ancestors 'self' 1 default-src 'self'; script-src 'report-sample' 'self' 'unsafe-eval' https://googleads.g.doubleclick.net/pagead/viewthroughconversion/823935011/ https://js.monitor.azure.com/scripts/b/ai.2.min.js https://player.vimeo.com/api/player.js https://www.clarity.ms https://www.googletagmanager.com/gtm.js; script-src-elem 'self' 'unsafe-inline' https://www.googletagmanager.com/gtm.js https://www.googletagmanager.com/gtag/js https://player.vimeo.com/api/player.js https://f.vimeocdn.com https://googleads.g.doubleclick.net https://snap.licdn.com https://www.clarity.ms https://www.google.com/recaptcha/api.js https://www.googletagmanager.com/gtag/destination https://www.gstatic.com/recaptcha/releases/ https://www.youtube.com/iframe_api https://www.youtube.com/s/player/; style-src 'report-sample' 'self' 'unsafe-inline'; object-src 'none'; base-uri 'self'; connect-src 'self' https://eastus-0.in.applicationinsights.azure.com https://*.clarity.ms https://www.google-analytics.com https://www.google.com https://px.ads.linkedin.com https://www.googleadservice.com/pagead; font-src 'self'; frame-src 'self' https://td.doubleclick.net https://www.googletagmanager.com https://ai.appraisalinstitute.org/ https://embed.podcasts.apple.com/ https://player.vimeo.com/ https://www.google.com/ https://www.youtube.com/; img-src 'self' data: https://*.appraisalinstitute.org https://dummyimage.com https://placedog.net https://via.placeholder.com https://*.clarity.ms https://www.google.com https://www.googletagmanager.com https://appraisalinstitute-org-authoring-2023.azurewebsites.net https://px.ads.linkedin.com https://*.bing.com; manifest-src 'self'; media-src 'self'; worker-src 'none'; frame-ancestors 'self' https://appraisal-org-local-2023.bluemod.me/ https://appraisal-cms-local-2023.bluemod.me/ https://appraisal-org-dev-2023.bluemod.us/ https://appraisal-cms-dev-2023.bluemod.us/ https://appraisal-org-test-2023.bluemod.us/ https://appraisal-cms-test-2023.bluemod.us/ https://appraisalinstitute-org-authoring-2023.azurewebsites.net/ https://appraisalinstitute-cms-authoring-2023.azurewebsites.net/ https://www.appraisalinstitute.org/ https://appraisalinstitute-cms-prod-2023.azurewebsites.net/; 1 default-src blob: https://*.mhcache.com;font-src 'self' https://*.myheritage.com https://*.mhcache.com https://fonts.gstatic.com;frame-src 'self' https://*.mhcache.com https://portal.allyable.com https://mh-site-files-5c53d6a9947c.s3.amazonaws.com https://myheritage-container.com https://www.myheritage-partners.com https://www.myheritage.com https://*.mk-sense.com https://player.vimeo.com https://*.facebook.com https://*.googleapis.com https://*.google.com https://tpc.googlesyndication.com https://*.doubleclick.net https://accounts.google.com/gsi/;script-src https://accounts.google.com/gsi/client https://www.datadoghq-browser-agent.com https://*.googleapis.com https://appleid.cdn-apple.com *.myheritage.com.br https://www.myheritage.com.br 'unsafe-eval' 'nonce-3fe6b727fe2b769828fc385098c3d153' 'strict-dynamic';style-src data: blob: 'unsafe-inline' 'self' https://*.myheritage.com https://*.mhcache.com https://fonts.googleapis.com https://accounts.google.com/gsi/style;connect-src data: 'self' https://*.myheritage.com https://portal.allyable.com https://*.mhcache.com https://adservice.google.com https://*.logs.datadoghq.com https://*.browser-intake-datadoghq.com https://browser-intake-datadoghq.com https://sentry.io https://*.bing.com https://*.facebook.com https://*.doubleclick.net https://*.mk-sense.com https://*.filae.com https://accounts.google.com/gsi/ https://www.google.com/pagead/landing https://*.googleapis.com https://maps.googleapis.com/maps/api/mapsjs/gen_204 https://translate.googleapis.com https://www.google.com/ccm/collect https://cdn.builder.io *.myheritage.com.br;media-src 'self' https://*.myheritage.com https://*.mhcache.com;frame-ancestors 'self' https://builder.io;img-src * data:;object-src 'none';base-uri 'self' https://*.mhcache.com;report-uri /FP/API/ContentSecurityPolicy/report-violation.php?report_mode=report&canonical_page_id=/company/home/ 1 font-src *.bglobale.com *.global-e.com https://www.gstatic.com https://fonts.gstatic.com *.fontawesome.com https://cdnjs.cloudflare.com *.maisonkitsune.com *.maisonkitsune.test maisonkitsune.com preprod-m2.maisonkitsune.com maisonkitsune.test vestiaire.maisonkitsune.com preprod-vest.maisonkitsune.com vestiaire.test data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.bglobale.com *.global-e.com https://*.google.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com https://www.googletagmanager.com/ ssmkt.maisonkitsune.com/ *.fitle.com *.cookieinformation.com https://open.spotify.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://images.unsplash.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.bird.eu *.bglobale.com *.global-e.com https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.googleusercontent.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ *.maisonkitsune.com *.maisonkitsune.test maisonkitsune.com preprod-m2.maisonkitsune.com maisonkitsune.test vestiaire.maisonkitsune.com preprod-vest.maisonkitsune.com vestiaire.test *.line.me *.bing.com https://bat.bing.net https://cdn.cookielaw.org data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://cdn.jsdelivr.net/npm/@ryangjchandler/spruce@2.x.x/dist/spruce.umd.js www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.bglobale.com *.global-e.com https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ *.avada.io https://cdnjs.cloudflare.com *.maisonkitsune.com *.maisonkitsune.test maisonkitsune.com preprod-m2.maisonkitsune.com maisonkitsune.test vestiaire.maisonkitsune.com preprod-vest.maisonkitsune.com vestiaire.test *.fitle.com *.cookieinformation.com *.bing.com *.line-scdn.net *.jsdelivr.net *.zdassets.com https://cdn.cookielaw.org wss://widget-mediator.zopim.com https://ssmkt.maisonkitsune.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.bglobale.com *.global-e.com https://fonts.googleapis.com https://hcaptcha.com https://*.hcaptcha.com *.fontawesome.com https://cdnjs.cloudflare.com *.maisonkitsune.com *.maisonkitsune.test maisonkitsune.com preprod-m2.maisonkitsune.com maisonkitsune.test vestiaire.maisonkitsune.com preprod-vest.maisonkitsune.com vestiaire.test 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ *.zdassets.com https://cdn.cookielaw.org 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://ipinfo.io https://*.google.com https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ https://get.geojs.io *.avada.io *.maisonkitsune.com *.maisonkitsune.test maisonkitsune.com preprod-m2.maisonkitsune.com maisonkitsune.test vestiaire.maisonkitsune.com preprod-vest.maisonkitsune.com vestiaire.test *.fitle.com https://bat.bing.net *.googlesyndication.com *.cookieinformation.com *.zendesk.com *.zdassets.com wss://widget-mediator.zopim.com https://cdn.cookielaw.org *.onetrust.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' https:; script-src 'self' https: 'unsafe-inline' 'unsafe-eval'; style-src 'self' https: 'unsafe-inline'; img-src 'self' https: data: blob:; media-src 'self' https: data: blob:; object-src 'none'; frame-ancestors 'self' https://experience.adobe.com https://infopoint.audi.it; connect-src 'self' https: wss://e0k754.acquire.io; base-uri 'self'; font-src 'self' https: data:; worker-src 'self' blob:; report-uri https://www.audi.pl/api/csp-report; report-to csp-endpoint 1 default-src 'self';base-uri 'self';frame-ancestors 'self';frame-src https://* 'self' epichttp: https://epic.gateway.patientco.com https://pay.instamed.com;script-src 'nonce-79bdfa230a6649faba8d0283bc03cde2' https://www.mylvhn.org 'self' https://www.google.com/reCaptcha/enterprise.js;img-src https://* 'self' blob: data:;connect-src 'self' epichttp: https://www.google.com;style-src https://www.mylvhn.org 'self' 'unsafe-inline';worker-src 'self' blob:;child-src 'self' blob:;form-action https://central.mychart.org/MyChart/ 'self';media-src https://* 'self' blob:; 1 connect-src *.bundesregierung.de analytics.bundesregierung.de 'self' https://hls-hd.myrasec.de *.stage.bio ; style-src *.bundesregierung.de 'self' 'unsafe-inline' ; script-src *.bundesregierung.de 'self' ; script-src-elem 'self' *.bundesregierung.de 'nonce-LJy0nm8E2tv8/zql1EllmUYFcNAdlhGSdm93TPmsqOZwqXVtz0Yr0PZ0RrnPkp/E1etUsko5OOpTn1ZfDK28sWnm4+WMsYOevduj+ULdPIn2V72YHYpABKg92xBHMtajlBV5MkvFdw07qmvbPH0uJQtEZJCX1IC8Nqe4+gN1MVo=' *.stage.bio ; frame-src *.bundesregierung.de 'self' ; media-src *.bundesregierung.de 'self' http://video.bundesregierung.de https://zdf-hls-18.akamaized.net *.stage.bio ; frame-ancestors *.bundesregierung.de 'self' ; img-src 'self' *.bundesregierung.de https://*.tile.openstreetmap.de data: *.stage.bio ; default-src *.bundesregierung.de 'self' ; font-src *.bundesregierung.de 'self' ; report-uri https://www.bundeskanzler.de/service/csp-report ; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.klevu.com *.ksearchnet.com *.yotpo.com *.googleapis.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com https://plumrocket.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com *.dotdigital-pages.com *.dotdigital.com https://plumrocket.com *.iubenda.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com js.mollie.com https://accounts.google.com www.xtento.com *.yotpo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: track.goggles4u.info https://track.goggles4u.info www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.trackedlink.net https://images.unsplash.com *.iubenda.com *.klevu.com *.ksearchnet.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://www.mollie.com www.google.com.ua www.xtento.com cdn.xtento.com *.yotpo.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal https://maps.googleapis.com *.iubenda.com *.klevu.com *.ksearchnet.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com js.mollie.com https://accounts.google.com https://www.gstatic.com www.xtento.com cdn.xtento.com *.yotpo.com https://js.klevu.com sst.goggles4u.co.uk https: 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.klevu.com *.ksearchnet.com https://accounts.google.com https://www.gstatic.com *.yotpo.com *.googleapis.com https://statsjs.klevu.com https://js.klevu.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com https://maps.googleapis.com https://player.vimeo.com https://checkout.iwdagency.com *.iubenda.com *.klevu.com *.ksearchnet.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://accounts.google.com *.yotpo.com sst.goggles4u.co.uk https: 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; style-src 'self' 'unsafe-inline' https://*.posthog.com https://fonts.googleapis.com; script-src 'self' 'nonce-4EMn7hFCa7wjfz3bM54FBn' https://*.posthog.com https://*.i.posthog.com; font-src 'self' https://*.posthog.com https://app-static.eu.posthog.com https://app-static-prod.posthog.com https://d1sdjtjk6xzm7.cloudfront.net https://fonts.gstatic.com https://cdn.jsdelivr.net https://assets.faircado.com https://use.typekit.net; worker-src 'self'; child-src 'none'; object-src 'none'; media-src https://res.cloudinary.com; img-src 'self' data: https://*.posthog.com https://posthog.com https://www.gravatar.com https://res.cloudinary.com https://platform.slack-edge.com https://raw.githubusercontent.com; frame-ancestors https://posthog.com https://preview.posthog.com https://vercel.com; connect-src 'self' https://status.posthog.com https://*.posthog.com https://raw.githubusercontent.com https://api.github.com; frame-src https:; manifest-src 'self'; base-uri 'self'; report-uri https://us.i.posthog.com/report/?token=sTMFPsFhdP1Ssg&sample_rate=0.1&v=2; report-to posthog 1 script-src-elem 'self' 'unsafe-inline' 'unsafe-eval' https://cdn.jsdelivr.net https://cdn.cupio.ro https://ss.cupio.ro https://www.googletagmanager.com https://www.google-analytics.com https://googleads.g.doubleclick.net https://*.googleapis.com https://www.googleoptimize.com https://www.googleadservices.com https://www.google.ro https://www.google.com https://connect.facebook.net https://*.facebook.com https://*.pinterest.com https://ct.pinterest.com https://s.pinimg.com https://*.cookieyes.com https://cdn-cookieyes.com https://*.snapchat.com https://sc-static.net https://bat.bing.com https://bat.bing.net https://event.2performant.com https://attr-2p.com https://*.klarna.com https://*.klarnacdn.net https://*.revolut.com https://aqurate.ai https://cdn.channelize.io https://trusted.ro https://js.stripe.com cupio.ro https://*.themarketer.com https://*.mktr2.com https://unpkg.com https://*.mczbf.com https://*.gstatic.com https://*.clarity.ms https://*.tiktok.com; font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com maxcdn.bootstrapcdn.com *.revolut.com *.google.com google.com *.cdn-apple.com pay.google.com https://*.gstatic.com *.cloudflare.com *.twitter.com *.twimg.com *.trustedshops.com https://fonts.googleapis.com *.zopim.com *.zopim.io *.klarnacdn.net https://fonts.bunny.net 'self' data: https://cdn.cupio.ro https://*.themarketer.com https://*.mktr2.com https://*.mczbf.com https://*.clarity.ms https://*.tiktok.com https://fonts.cdnfonts.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnaevt.com *.link.com *.amazon.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://plumrocket.com *.twitter.com *.cupio.ro https://www.facebook.com https://payflowlink.paypal.com https://sandbox.payu.ro/ https://secure.payu.ro/ https://cdn.channelize.io https://*.revolut.com https://*.themarketer.com https://*.mktr2.com https://*.mczbf.com https://*.gstatic.com https://*.clarity.ms https://*.tiktok.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.revolut.com *.google.com *.cdn-apple.com google.com pay.google.com *.gstatic.com *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com https://*.facebook.com https://connect.facebook.net graph.facebook.com business.facebook.com www.google.com *.innoship.ro https://plumrocket.com https://*.revolut.com *.cdn-apple.com *.google.com/ pay.google.com https://*.gstatic.com https://accounts.google.com *.weltpixel.com https://www.youtube.com http://www.sandbox.paypal.com *.twitter.com https://*.klarna.com 'self' *.cupio.ro https://ss.cupio.ro https://*.pinterest.com https://s.pinimg.com *.vimeo.com https://cdn-cookieyes.com https://*.snapchat.com https://bat.bing.com https://event.2performant.com https://js.stripe.com https://hooks.stripe.com https://*.themarketer.com https://*.mktr2.com https://*.mczbf.com https://*.clarity.ms https://*.tiktok.com https://*.klarnaservices.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.googletagmanager.com *.doubleclick.net 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://*.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.tiktok.com *.tile.openstreetmap.org *.openstreetmap.org https://www.magezon.com *.revolut.com *.google.com *.cdn-apple.com https://*.google.com pay.google.com https://*.gstatic.com *.cloudflare.com *.klarna.com *.googleadservices.com https://www.google-analytics.com *.twitter.com *.twimg.com https://*.vimeocdn.com *.ytimg.com *.bing.com *.zopim.com *.zopim.io *.doubleclick.net *.google.co.in *.mastercard.com https://*.klarna.com *.klarnaevt.com *.klarnacdn.net magefan.com cm.magefan.com https://firebasestorage.googleapis.com 'self' cupio.ro *.cupio.ro https://*.google.ro https://www.googleadservices.com https://trusted.ro https://*.ytimg.com https://*.pinterest.com https://s.pinimg.com https://*.klarnacdn.net https://cdn-cookieyes.com https://*.snapchat.com https://bat.bing.com https://bat.bing.net https://event.2performant.com https://*.themarketer.com https://*.mktr2.com https://*.mczbf.com https://*.clarity.ms https://*.tiktok.com https://www.google.com https://redchamps.com *.facebook.com *.reddit.com *.googletagmanager.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://connect.facebook.net connect.facebook.net graph.facebook.com business.facebook.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.tiktok.com *.channelize.io https://cdn.jsdelivr.net https://*.revolut.com *.google.com/ pay.google.com https://*.gstatic.com https://accounts.google.com https://www.gstatic.com *.cloudflare.com *.twitter.com https://www.google-analytics.com *.twimg.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com https://bat.bing.com *.zopim.com *.zdassets.com https://*.klarna.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com *.avada.io *.shopify.com 'self' 'unsafe-inline' 'unsafe-eval' https://cdn.cupio.ro https://ss.cupio.ro https://www.googletagmanager.com https://googleads.g.doubleclick.net https://*.googleapis.com https://www.googleoptimize.com https://www.googleadservices.com https://www.google.ro https://*.facebook.com https://*.pinterest.com https://ct.pinterest.com https://s.pinimg.com https://*.cookieyes.com https://*.snapchat.com https://sc-static.net https://bat.bing.net https://event.2performant.com https://attr-2p.com https://*.klarnacdn.net https://aqurate.ai https://cdn.channelize.io https://trusted.ro https://www.trusted.ro cupio.ro https://*.themarketer.com https://*.mktr2.com https://unpkg.com https://*.mczbf.com https://*.clarity.ms https://*.tiktok.com https://www.google.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnaevt.com *.amazon.com *.link.com *.googletagmanager.com *.googleadservices.com *.facebook.net *.redditstatic.com *.reddit.com unpkg.com *.doubleclick.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com maxcdn.bootstrapcdn.com https://accounts.google.com https://www.gstatic.com *.cloudflare.com https://fonts.googleapis.com *.twitter.com *.twimg.com https://*.gstatic.com *.typekit.net *.trustedshops.com *.bing.com *.klarnacdn.net https://fonts.bunny.net 'self' 'unsafe-inline' https://cdn.jsdelivr.net https://cdn.cupio.ro https://*.klarnacdn.net https://*.themarketer.com https://*.mktr2.com https://*.mczbf.com https://*.clarity.ms https://*.tiktok.com https://unpkg.com *.stripe.network *.stripecdn.com *.amazon.com *.tagmanager.google.com *.googletagmanager.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.zopim.com *.zopim.io 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.tiktok.com *.channelize.io https://*.revolut.com *.cdn-apple.com pay.google.com https://*.gstatic.com https://accounts.google.com www.google-analytics.com *.cloudflare.com *.twitter.com *.twimg.com *.zdassets.com *.zopim.com *.zopim.io wss://widget-mediator.zopim.com https://www.google-analytics.com https://stats.g.doubleclick.net *.klarnaevt.com *.klarnacdn.net x.klarnacdn.net *.klarnaservices.com https://*.klarna.com https://get.geojs.io *.avada.io 'self' *.cupio.ro https://ss.cupio.ro https://*.googleapis.com https://www.googletagmanager.com https://*.cookieyes.com https://cdn-cookieyes.com https://*.snapchat.com https://bat.bing.com https://bat.bing.net https://event.2performant.com https://attr-2p.com https://directory.cookieyes.com https://*.klarnacdn.net https://*.klarnaservices.com https://aqurate.ai https://analytics-ipv6.tiktokw.us https://cdn.channelize.io https://api.stripe.com https://*.themarketer.com https://*.mktr2.com https://unpkg.com https://*.mczbf.com https://*.clarity.ms https://*.tiktok.com https://ct.pinterest.com https://cdn.jsdelivr.net *.stripe.com klarna.com *.klarna.com *.link.com *.amazon.com *.facebook.net *.redditstatic.com *.reddit.com *.doubleclick.net *.run.app 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' *.google.com google.com *.google.de google.de *.google.at google.at *.google.be google.be *.google.fi google.fi *.google.no google.no *.google.ru google.ru *.google.se google.se *.google.co.uk google.co.uk *.google.nl google.nl *.google.fr google.fr *.google.pl google.pl *.google.es google.es *.google.it google.it *.google.ch google.ch *.google.dk google.dk *.google.it google.it *.google.cz google.cz *.google-analytics.com google-analytics.com *.googletagmanager.com googletagmanager.com *.googleapis.com googleapis.com *.sharp.de sharp.de *.sharp.at sharp.at *.sharp.be sharp.be *.sharp.fi sharp.fi *.sharp.no sharp.no *.sharp.ru sharp.ru *.sharp.se sharp.se *.sharp.co.uk sharp.co.uk *.sharp.nl sharp.nl *.sharp.fr sharp.fr *.sharp.pl sharp.pl *.sharp.es sharp.es *.sharp.it sharp.it *.sharp.ch sharp.ch *.sharp.se sharp.se *.sharp.dk sharp.dk *.sharp.cz sharp.cz *.sharp.eu sharp.eu *.sharpmarketing.eu imgs.aws.sharp.eu *.actonsoftware.com *.cookielaw.org *.onetrust.com onetrust.com stats.g.doubleclick.net; script-src 'self' 'unsafe-inline' *.actonservice.com actonservice.com *.googletagmanager.com googletagmanager.com *.google-analytics.com *.google.com googleapis.com *.googleapis.com *.youtube.com youtube.com bam.nr-data.net js-agent.newrelic.com *.cookielaw.org *.onetrust.com *.sharpmarketing.eu *.gstatic.com *.hotjar.com snap.licdn.com bat.bing.com; style-src 'self' 'unsafe-inline' *.sharpmarketing.eu; img-src 'self' data: *.cookielaw.org cookielaw.org *.onetrust.com onetrust.com *.google.ca google.ca *.google.co.in google.co.in *.google.ro google.ro *.google.co.jp google.co.jp *.gogle.co.id google.co.id *.google.co.th google.co.th *.google.ae google.ae *.google.co.nz google.co.nz *.google.com google.com *.google.de google.de *.google.at google.at *.google.be google.be *.google.fi google.fi *.google.no google.no *.google.ru google.ru *.google.se google.se *.google.co.uk google.co.uk *.google.nl google.nl *.google.fr google.fr *.google.pl google.pl *.google.es google.es *.google.it google.it *.google.ch google.ch *.google.dk google.dk *.google.lt google.it *.google.cz google.cz imgs.aws.sharp.eu i.ytimg.com d35hoao4dw4qk2.cloudfront.net www.google-analytics.com *.sharpmarketing.eu *.actonsoftware.com px.ads.linkedin.com bat.bing.com px4.ads.linkedin.com www.google.co.za www.google.bg googleads.g.doubleclick.net www.google.gr; frame-src *; frame-ancestors 'self' *.sharp.de sharp.de *.sharp.at sharp.at *.sharp.be sharp.be *.sharp.fi sharp.fi *.sharp.no sharp.no *.sharp.ru sharp.ru *.sharp.sk sharp.sk *.sharp.se sharp.se *.sharp.co.uk sharp.co.uk *.sharp.nl sharp.nl *.sharp.fr sharp.fr *.sharp.pl sharp.pl *.sharp.es sharp.es *.sharp.it sharp.it *.sharp.ch sharp.ch *.sharp.se sharp.se *.sharp.dk sharp.dk *.sharp.hu sharp.hu *.sharp.it sharp.it *.sharp.co.jp sharp.co.jp *.sharp.cz sharp.cz *.sharp.eu sharp.eu; child-src *; font-src 'self' data:; connect-src 'self' *.google-analytics.com google-analytics.com cdn.linkedin.oribi.io bam.nr-data.net *.onetrust.com *.cookielaw.org stats.g.doubleclick.net privacyportal-eu.onetrust.com *.sharpmarketing.eu *.hotjar.com vc.hotjar.io bat.bing.com; report-uri https://apps.sharp.eu/sharp/apps/eu/csp-violation/report.php; upgrade-insecure-requests 1 script-src 'none'; report-uri https://csp-reporting.cloudflare.com/cdn-cgi/script_monitor/report?m=xzDvd_aw4MyM3XFbekdu1FJ9pyoVkKJ0hQHK_RUEqrA-1770435071.4451177-1.0.1.1-XJDGMfm7yBskDGpOaxFO9xTLJXz408QtH2P3hN9Cr.NzCrTZJaykpbwTHexkBkz3Y3B8Lu8tITB6eB2UrjAZwvnOmPgDoo0Zqlp6pTjK.HCrOtilD0TOCC.rgPieFhl2NQSdFO.15IOcPn4FPcE9va7osgl66Loe0aY9Hao_SNQ; report-to cf-csp-endpoint 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com *.klarnacdn.net *.klevu.com *.ksearchnet.com fonts.googleapis.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnaevt.com *.link.com *.amazon.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de https://seo.mageplaza.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.google.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.klarna.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.iubenda.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com *.stripe.com klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de *.payments-amazon.com *.salesmanago.pl *.salesmanago.es *.salesmanago.com *.feedaty.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com *.klarna.com *.klarnaevt.com *.klarnacdn.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.iubenda.com *.klevu.com *.ksearchnet.com https://firebasestorage.googleapis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.salesmanago.pl *.salesmanago.es *.salesmanago.com *.feedaty.com chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com *.klarna.com *.klarnacdn.net x.klarnacdn.net js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com songbird.cardinalcommerce.com *.iubenda.com *.klarnaservices.com js.klevu.com *.ksearchnet.com *.avada.io *.shopify.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarnaevt.com *.amazon.com *.link.com tracking.trovaprezzi.it www.trovaprezzi.it https://js.klevu.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.feedaty.com *.fontawesome.com downloads.mailchimp.com assets.braintreegateway.com *.klarnacdn.net *.klevu.com *.ksearchnet.com https://fonts.bunny.net maxcdn.bootstrapcdn.com *.stripe.network *.stripecdn.com *.amazon.com https://statsjs.klevu.com https://js.klevu.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de *.salesmanago.pl *.salesmanago.es *.salesmanago.com *.feedaty.com form-assets.mailchimp.com *.intuit.com *.amazonaws.com *.klarnaevt.com *.klarnacdn.net x.klarnacdn.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.iubenda.com *.klarnaservices.com *.klarna.com *.klevu.com *.ksearchnet.com https://get.geojs.io *.avada.io www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.stripe.com klarna.com *.link.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.salesmanago.pl *.salesmanago.es *.salesmanago.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' *.localphone.com *.localphone.co.uk; img-src * data:; child-src *; frame-src *; script-src 'self' 'unsafe-inline' *.localphone.com https://js.stripe.com https://*.google.com https://ajax.googleapis.com http://www.google-analytics.com https://*.gstatic.com https://*.g.doubleclick.net https://www.googleadservices.com https://www.facebook.com https://cdn.jsdelivr.net; style-src 'self' 'unsafe-inline' *.localphone.com https://*.googleapis.com https://cdn.jsdelivr.net; font-src 'self' data: fonts.gstatic.com https://sxt.cdn.skype.com; connect-src 'self' *.localphone.com; 1 upgrade-insecure-requests; report-to https://652d4e11b6167cf8f68c6359.endpoint.csper.io/?v=0;; report-uri https://652d4e11b6167cf8f68c6359.endpoint.csper.io/?v=0;; 1 default-src 'none'; worker-src 'self' blob:; base-uri 'self'; img-src * data:; frame-ancestors 'self' soderhamnnara.se *.gavlenet.se gavlenet.se gavleenergi.se; form-action 'self'; script-src 'self' 'unsafe-eval' 'nonce-gTtXga7mRy6kDAVUqCuTyQ' 'nonce-4vXbpQD' api.livechatinc.com cdn.livechatinc.com functions.janjoo.se/js/informera-rss/app.js bankid.lime-technologies.com ajax.googleapis.com code.jquery.com *.gavlenet.se *.gavleenergi.se kit.fontawesome.com googletagmanager.com stats.gavleenergi.se cdn.gavleenergi.se t.adii.se https://bankid.lime-technologies.com/api/v2/js/bankid-modal.js; connect-src 'self' code.jquery.com maxcdn.bootstrapcdn.com gavchat.uc.tele2.se functions.janjoo.se *.gavleenergi.se maps.googleapis.com stats.gavleenergi.se simpliform.gavleenergi.se ka-p.fontawesome.com www.gavleenergi.se gavleenergi.se kit.fontawesome.com; style-src 'unsafe-inline' 'self' fonts.googleapis.com kit.fontawesome.com ka-p.fontawesome.com code.jquery.com maxcdn.bootstrapcdn.com cdn.gavleenergi.se; frame-src 'self' secure.livechatinc.com *.youtube.com youtube.com gavleenergi.se *.gavlenet.se *.gavleenergi.se app.bwz.se gavleenergiab.webapp.virtaglobal.com; font-src *.fontawesome.com use.typekit.net fonts.gstatic.com data: *.gavleenergi.se www.gavleenergi.se/wp-includes/fonts/ maxcdn.bootstrapcdn.com; object-src 'none' 1 font-src https://analytics.google.com/ https://www.google.com/ *.googlevideo.com/ https://www.facebook.com/ *.facebook.net/ https://www.youtube.com/ https://img.youtube.com/ https://www.youtube-nocookie.com/ https://yt3.ggpht.com/ https://vimeo.com/ *.vimeocdn.com/ https://static.placetopay.com/ https://*.googleapis.com/ *.googleapis.com *.gstatic.com *.bootstrapcdn.com 'self' data: data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.bolt.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com https://www.youtube.com/ *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com *.bolt.com https://www.google.com/recaptcha/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://analytics.google.com/ https://www.google.com/ *.googlevideo.com/ https://www.facebook.com/ *.facebook.net/ https://img.youtube.com/ https://www.youtube-nocookie.com/ https://yt3.ggpht.com/ https://vimeo.com/ *.vimeocdn.com/ https://static.placetopay.com/ https://*.googleapis.com/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com https://www.youtube.com/ validator.swagger.io www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://analytics.google.com/ https://www.google.com/ *.googlevideo.com/ https://www.facebook.com/ *.facebook.net/ https://img.youtube.com/ https://www.youtube-nocookie.com/ https://yt3.ggpht.com/ https://vimeo.com/ *.vimeocdn.com/ https://static.placetopay.com/ maps.googleapis.com *.google.com *.gstatic.com *.google-analytics.com *.googleadservices.com *.paypal.com https://www.google.com https://www.google.com.co https://* www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com maps.gstatic.com *.hsforms.net *.hsforms.com 'self' data: data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com https://vimeo.com/ www.vimeo.com *.vimeocdn.com https://www.youtube.com/ *.bolt.com *.commerce-quick-checkout.com http://localhost:8082 https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://*.hotjar.io/ https://analytics.google.com/ *.google.com *.googlevideo.com/ https://www.facebook.com/ *.facebook.net/ https://img.youtube.com/ https://www.youtube-nocookie.com/ https://yt3.ggpht.com/ *.vimeocdn.com/ https://bam.nr-data.net/ https://js-agent.newrelic.com/ https://static.placetopay.com/ maps.googleapis.com https://*.hotjar.com/ https://*.cloudfront.net/ wss://ws.hotjar.com https://*.hotjar.io https://metrics.hotjar.io https://stats.g.doubleclick.net https://www.google-analytics.com https://analytics.google.com https://www.googletagmanager.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.hsforms.net *.hsforms.com *.gstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.google.com *.googleapis.com *.gstatic.com *.bootstrapcdn.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com https://analytics.google.com/ https://www.google.com/ *.googlevideo.com/ https://www.facebook.com/ *.facebook.net/ https://www.youtube.com/ https://img.youtube.com/ https://www.youtube-nocookie.com/ https://yt3.ggpht.com/ https://vimeo.com/ *.vimeocdn.com/ https://static.placetopay.com/ https://*.googleapis.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.bolt.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://metrics.hotjar.io https://*.hotjar.io wss://ws.hotjar.com https://stats.g.doubleclick.net https://www.google-analytics.com https://analytics.google.com https://www.googletagmanager.com https://*.clarity.ms maps.googleapis.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 img-src https://higherlogicdownload.s3.amazonaws.com/ACCA/ https://cdn.jsdelivr.net/jquery.slick/ https://higherlogic-holdingpen-us-east-1.s3.amazonaws.com/ACCA/ https://img.youtube.com/vi/ https://static.filestackapi.com/picker/ https://d2x5ku95bkycr3.cloudfront.net https://higherlogiclongterm.s3.amazonaws.com/ACCA/ blob: https://d132x6oi8ychic.cloudfront.net 'self'; style-src https://d132x6oi8ychic.cloudfront.net 'unsafe-inline' https://higherlogiccloudfront.s3.amazonaws.com https://cdn.jsdelivr.net/jquery.slick/ https://cdnjs.cloudflare.com/ajax/libs/prism/ https://d2x5ku95bkycr3.cloudfront.net/ https://ajax.googleapis.com/ajax/libs/jqueryui/ https://use.fortawesome.com/ https://static.filestackapi.com/picker/ https://fonts.googleapis.com/ https://d3uf7shreuzboy.cloudfront.net/ https://higherlogic-holdingpen-us-east-1.s3.amazonaws.com/ACCA/ https://higherlogicdownload.s3.amazonaws.com/ACCA/ https://higherlogiclongterm.s3.amazonaws.com/ACCA/ 'self'; font-src https://fonts.googleapis.com/ https://fonts.gstatic.com/ https://cdn.jsdelivr.net/jquery.slick/ https://higherlogiccloudfront.s3.amazonaws.com https://higherlogicdownload.s3.amazonaws.com/ACCA/ https://higherlogic-holdingpen-us-east-1.s3.amazonaws.com/ACCA/ 'self' https://higherlogiclongterm.s3.amazonaws.com/ACCA/ https://maxcdn.bootstrapcdn.com/font-awesome/ https://d2x5ku95bkycr3.cloudfront.net https://d132x6oi8ychic.cloudfront.net data:; script-src-elem https://www.google.com/recaptcha/ https://www.recaptcha.net/recaptcha/ https://d2x5ku95bkycr3.cloudfront.net/HigherLogic/jquery/jquery-ui-1.13.3.min.js https://d3uf7shreuzboy.cloudfront.net/ https://static.filestackapi.com/picker/ https://d2x5ku95bkycr3.cloudfront.net/HigherLogic/jquery/jquery-3.7.1.min.js https://d2x5ku95bkycr3.cloudfront.net/ https://cdnjs.cloudflare.com/ajax/libs/prism/ https://www.gstatic.com/recaptcha/ https://static.filestackapi.com/filestack-js/ 'self' https://ajax.aspnetcdn.com/ajax/ 'unsafe-eval' 'unsafe-inline'; media-src https://higherlogiclongterm.s3.amazonaws.com/ACCA/ https://higherlogicdownload.s3.amazonaws.com/ACCA/ https://higherlogic-holdingpen-us-east-1.s3.amazonaws.com/ACCA/ https://higherlogicstream.s3.amazonaws.com/ACCA/ 'self' https://d132x6oi8ychic.cloudfront.net; script-src https://higherlogiclongterm.s3.amazonaws.com/ACCA/ https://higherlogicdownload.s3.amazonaws.com/ACCA/ https://ajax.aspnetcdn.com/ajax/ https://cdn.jsdelivr.net/jquery.slick/ https://d2x5ku95bkycr3.cloudfront.net/HigherLogic/jquery/jquery-ui-1.13.3.min.js https://d132x6oi8ychic.cloudfront.net https://cdn.informz.net 'unsafe-eval' https://use.fortawesome.com/ https://higherlogic-holdingpen-us-east-1.s3.amazonaws.com/ACCA/ https://cdnjs.cloudflare.com/ajax/libs/prism/ 'unsafe-inline' https://d2x5ku95bkycr3.cloudfront.net/ https://higherlogiccloudfront.s3.amazonaws.com https://static.filestackapi.com https://d2x5ku95bkycr3.cloudfront.net/HigherLogic/jquery/jquery-3.7.1.min.js https://d3uf7shreuzboy.cloudfront.net/ 'self'; frame-src https://www.google.com/recaptcha/ https://www.recaptcha.net/recaptcha/ https://api.connectedcommunity.org/ 'self' https://www.youtube.com/embed/ https://10176109.fls.doubleclick.net/ https://www.googletagmanager.com/; connect-src https://upload.filestackapi.com https://static.filestackapi.com https://cloud.filestackapi.com/folder/list/ 'self' https://hl-managedservices.informz.net https://d3uf7shreuzboy.cloudfront.net/ blob:; worker-src 'self'; default-src 'self'; base-uri 'self'; frame-ancestors https://*.connectedcommunity.org/ 'self'; object-src 'none'; manifest-src 'self'; 1 script-src https://www.charly.com/ 'nonce-a3ZxcGFoY3pwcWh3bDRobnkzdXlyeTJtOHZhN2Ixc21sODZja2YxZnluZW95' 'self' 'unsafe-eval' *.adobe.com *.adobe.io *.adobedtm.com *.braintreegateway.com *.magento-datasolutions.com *.magento-ds.com *.newrelic.com *.nr-data.net *.paypal.com *.paypalobjects.com *.search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com *.sentry-cdn.com *.sentry.io *.vimeocdn.com *.youtube.com amcglobal.sc.omtrdc.net cdn.jsdelivr.net/npm/@adobe/ commerce.adobe.net developers.google.com https://h64.online-metrix.net https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ js.magento-datasolutions.com magento-recs-sdk.adobe.net maps.googleapis.com https://*.googleapis.com https://*.gstatic.com *.google.com https://*.ggpht.com *.googleusercontent.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com unpkg.com/@adobe/ use.typekit.net vimeo.com www.vimeo.com byspotify.com tiktok.com global-cache.online infird.com gstatic.com paypalobjects.com googleapis.com facebook.net facebook.com connect.facebook.net *.googletagmanager.com *.google-analytics.com *.google.com pinimg.com pinterest.com; style-src 'self' blob: 'unsafe-inline' https://www.charly.com/ 'unsafe-hashes' *.fonts.googleapis.com https://fonts.googleapis.com; img-src data: 'self' https://www.charly.com/ *.google.ie *.paypal.com *.paypalobjects.com *.facebook.com *.facebook.net connect.facebook.net google.com gstatic.com paypal.com flagcdn.com *.googletagmanager.com wolfcharly.com mcstaging.wolfcharly.com googleapis.com google.cctld com.mxmedia *.paypalobjects.com *.maps.gstatic.com *.maps.googleapis.com https://*.googleapis.com https://*.gstatic.com *.google.com *.googleusercontent.com; object-src 'none'; base-uri 'none'; child-src 'self'; font-src 'self' fonts.gstatic.com use.typekit.net *fonts.googleapis.com https://fonts.gstatic.com cdnfonts.com; frame-src assets.braintreegateway.com *.google.com *.youtube.com *.youtu.be *.vimeo.com *.adobe.com *.braintreegateway.com *.demdex.net fast.amc.demdex.net *.paypal.com *.paypalobjects.com *.youtube-nocookie.com schools-blocked.s3-website-us-east-1.amazonaws.com opendns.com paypal.com doubleclick.net pinterest.com *.googletagmanager.com *.google-analytics.com; report_uri https://82b58f34-a752-41e9-b0d2-7837f734aca7.sansec.watch/; report-to report-endpoint; frame-ancestors 'self' https://www.charly.com/; manifest-src 'self' 'unsafe-inline' https://www.charly.com/; connect-src 'self' https://www.charly.com/ *.adobe.io *.analytics.google.com *.braintreegateway.com 'unsafe-inline' *.magento-datasolutions.com *.magento-ds.com *.newrelic.com *.nr-data.net *.paypal.com *.paypalobjects.com *.search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com *.sentry-cdn.com *.sentry.io *.snplow.net *.telemetry-dev.adobe.io *.telemetry.adobe.io amcglobal.sc.omtrdc.net api.magento.com commerce.adobedc.net dpm.demdex.net maps.googleapis.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com search-admin-ui-qa.magento-datasolutions.com search-admin-ui.magento-ds.com www.facebook.com; worker-src 'self'; 1 default-src 'self'; font-src 'self'; img-src 'self'; script-src 'self'; style-src 'self'; frame-ancestors 'self'; report-uri https://syonmedia.uriports.com/reports/report; report-to default 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com 'self' data: p.typekit.net static.klaviyo.com libs.intiaro.com likeshop.me data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.certcapture.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com www.google.com *.certcapture.com *.weltpixel.com *.googletagmanager.com *.doubleclick.net 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.certcapture.com *.googleapis.com cdn.metalocator.com cdn.brandfolder.io log.pinterest.com cdn.cookielaw.org https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.facebook.com *.reddit.com *.ads-twitter.com t.co *.twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.googletagmanager.com *.doubleclick.net *.google.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.certcapture.com *.gstatic.com *.googleapis.com use.fontawesome.com js-agent.newrelic.com bam.nr-data.net bam-cell.nr-data.net code.metalocator.com assets.pinterest.com libs.intiaro.com cdn.dashhudson.com cdn.cookielaw.org sec.webeyez.com js.hellomedian.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.googletagmanager.com *.googleadservices.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.bing.com *.clarity.ms *.klaviyo.com unpkg.com *.doubleclick.net https://js-agent.newrelic.com https://cdn.visenze.com https://home-c61.nice-incontact.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.certcapture.com *.gstatic.com *.googleapis.com use.fontawesome.com use.typekit.net p.typekit.net libs.intiaro.com https://static.klaviyo.com *.tagmanager.google.com *.googletagmanager.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io *.certcapture.com *.gstatic.com *.googleapis.com bam.nr-data.net bam-cell.nr-data.net analytics.data.visenze.com api.likeshop.me search.visenze.com kravet.prinpay.com wss://wss.public-api.intiaro.com cdn.cookielaw.org hlg.tokbox.com wss://socket.hellomedian.com app.hellomedian.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.doubleclick.net *.run.app 'self' 'unsafe-inline'; child-src *.certcapture.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri /_csp/report; report-to report-endpoint; 1 font-src *.bootstrapcdn.com *.gstatic.com *.googleapis.com *.paypal.com *.juicer.io/fonts/ *.fontawesome.com https://fonts.gstatic.com fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com https://plumrocket.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors *.certcapture.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.certcapture.com *.google.com https://plumrocket.com *.weltpixel.com *.googletagmanager.com *.doubleclick.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.certcapture.com *.bootstrapcdn.com *.googleapis.com *.paypal.com *.gstatic.com *.paypalobjects.com *.omtrdc.net magefan.com cm.magefan.com *.google.com *.mageside.com mageside.com *.disqus.com *.juicer.io https://img.youtube.com *.facebook.com *.reddit.com *.ads-twitter.com t.co *.twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.google-analytics.com *.googletagmanager.com *.doubleclick.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.certcapture.com https://developer.adobe.com https://magento.com https://cdn.avmws.com/ http://cdn.avmws.com/ *.bootstrapcdn.com *.googleapis.com www.google.com *.paypal.com *.gstatic.com chimpstatic.com freegeoip.net *.ipstack.com *.google.com *.disqus.com *.juicer.io/embed.js cdn.jsdelivr.net services.sheerid.com *.googletagmanager.com *.googleadservices.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.ads-twitter.com *.bing.com *.clarity.ms *.klaviyo.com unpkg.com *.doubleclick.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.certcapture.com *.bootstrapcdn.com *.googleapis.com *.paypal.com *.gstatic.com *.juicer.io/embed.css cdn.jsdelivr.net *.fontawesome.com https://fonts.googleapis.com *.tagmanager.google.com *.googletagmanager.com fonts.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.certcapture.com https://developer.adobe.com https://cdn.avmws.com/ http://cdn.avmws.com/ *.juicer.io *.google-analytics.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.doubleclick.net *.run.app 'self' 'unsafe-inline'; child-src *.certcapture.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 frame-ancestors 'self' https://dsa.no/ https://dsa.no/ https://storymaps.arcgis.com https://miljostatus.miljodirektoratet.no/ https://storymaps.arcgis.com/stories/ https://miljotall.miljodirektoratet.no/ https://play.libsyn.com/ https://www.miljodirektoratet.no/; 1 font-src fonts.gstatic.com use.typekit.net *.squarecdn.com *.fontawesome.com maxcdn.bootstrapcdn.com *.cloudflare.com *.cloudfront.net *.gstatic.com *.typekit.net *.trustedshops.com *.trustpilot.com *.googleapis.com *.klaviyo.com *.zip.co data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com *.paymentexpress.com *.windcave.com *.klaviyo.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.demdex.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com widgets.sandbox.afterpay.com *.cash.app winathuntingandfishing.co.nz *.laybuy.com *.addthis.com *.facebook.com huntingandfishing.freshdesk.com zip.co sandbox.zip.co zipmoney.com.au sandbox.zipmoney.com.au checkout.gb.zip.co checkout.quadpay.com checkout-sandbox.quadpay.com *.paymentexpress.com *.windcave.com www.xtento.com *.doubleclick.net *.issuu.com app.redpepperdigital.net *.afterpay.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net *.afterpay.com/ *.cash.app magefan.com cm.magefan.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.disqus.com https://img.youtube.com *.cloudflare.com *.cloudfront.net https://cdn.klarna.com *.gstatic.com *.paypal.com *.afterpay.com https://s.ytimg.com *.usercentrics.eu *.trustpilot.com *.googleapis.com *.cdninstagram.com *.instagram.com *.facebook.net *.facebook.com *.clarity.ms *.bing.com t.zip.co static.zipmoney.com.au *.paymentexpress.com *.windcave.com www.xtento.com cdn.xtento.com *.google.co.nz *.zip.co partpayassets.blob.core.windows.net tags.srv.stackadapt.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net assets.adobedtm.com *.adobe.io www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com *.magento-ds.com https://api.addressfinder.io https://portal.sandbox.afterpay.com https://portal.afterpay.com https://static.afterpay.com *.squarecdn.com https://hbiq.net *.cash.app https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.disqus.com *.cloudflare.com *.cloudfront.net foursixty.com *.trustedshops.com *.usercentrics.eu *.trustpilot.com *.googleapis.com *.intercomcdn.com *.intercom.io *.addthis.com *.addthisedge.com *.moatads.com *.facebook.net *.clarity.ms *.freshworks.com s3.amazonaws.com/assets.freshdesk.com/ static.zipmoney.com.au zip.co *.paymentexpress.com *.windcave.com www.xtento.com cdn.xtento.com *.hotjar.com *.zip.co zipmoney.com.au app.redpepperdigital.net tags.srv.stackadapt.com *.google.co.nz 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.magento-datasolutions.com *.magento-ds.com https://api.addressfinder.io static.afterpay.com/ *.squarecdn.com *.cash.app https://static.klaviyo.com *.fontawesome.com maxcdn.bootstrapcdn.com *.cloudflare.com *.cloudfront.net *.typekit.net foursixty.com *.trustedshops.com *.usercentrics.eu *.trustpilot.com *.googleapis.com *.freshworks.com s3.amazonaws.com/assets.freshdesk.com/ *.zip.co tags.srv.stackadapt.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.cdninstagram.com *.instagram.com 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.magento-datasolutions.com *.magento-ds.com https://api.addressfinder.io *.afterpay.com *.squarecdn.com https://hbiq.net https://iq.afterpay-beta.com https://iq.afterpay.com *.cash.app api.lab.amplitude.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.cloudflare.com *.cloudfront.net foursixty.com *.paypal.com *.googleapis.com *.addthis.com *.addthisedge.com *.moatads.com *.intercom.io *.cdninstagram.com *.instagram.com *.clarity.ms *.doubleclick.net *.freshworks.com google.com *.hotjar.io *.zip.co tags.srv.stackadapt.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 upgrade-insecure-requests; report-to www.uoh.cl; report-uri www.uoh.cl; 1 object-src 'none'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://www.google.com/ https://cse.google.com/ https://www.eventbrite.com/ https://apply.ciis.edu https://apply-ciis-edu.cdn.technolutions.net/ https://slate-technolutions-net.cdn.technolutions.net/ https://fw.cdn.technolutions.net/ https://bbox.blackbaudhosting.com/ https://mx.technolutions.net/ https://player.vimeo.com/ https://www.googletagmanager.com/ https://payments.blackbaud.com/ https://www.gstatic.com/ apply.ciis.edu https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com; script-src-attr 'self' 'unsafe-inline'; script-src-elem 'self' 'unsafe-inline' https://www.google.com/ https://cse.google.com/ https://www.eventbrite.com/ https://apply.ciis.edu https://apply-ciis-edu.cdn.technolutions.net/ https://slate-technolutions-net.cdn.technolutions.net/ https://fw.cdn.technolutions.net/ https://bbox.blackbaudhosting.com/ https://mx.technolutions.net/ https://player.vimeo.com/ https://www.googletagmanager.com/ https://payments.blackbaud.com/ https://www.gstatic.com/ apply.ciis.edu https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com; style-src 'self' 'unsafe-inline' https://use.typekit.net/ https://p.typekit.net/ https://www.google.com/ https://www.eventbrite.com/ https://apply.ciis.edu https://apply-ciis-edu.cdn.technolutions.net/ https://slate-technolutions-net.cdn.technolutions.net/ https://fw.cdn.technolutions.net/ https://bbox.blackbaudhosting.com/ https://mx.technolutions.net/ https://player.vimeo.com/ https://www.googletagmanager.com/ https://payments.blackbaud.com/ https://www.gstatic.com/ cdnjs.cloudflare.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com https://use.typekit.net; style-src-attr 'self' 'unsafe-inline'; frame-ancestors 'self' https://www.eventbrite.com/ https://apply.ciis.edu https://apply-ciis-edu.cdn.technolutions.net/ https://slate-technolutions-net.cdn.technolutions.net/ https://fw.cdn.technolutions.net/ https://bbox.blackbaudhosting.com/ https://mx.technolutions.net/ https://player.vimeo.com/ https://www.googletagmanager.com/ https://payments.blackbaud.com/ https://www.gstatic.com/ 1 object-src 'none';base-uri 'self';script-src 'nonce-7g-08rApQ4F0_gbfFfbELQ' 'strict-dynamic' 'report-sample' 'unsafe-eval' 'unsafe-inline' https: http:;report-uri https://csp.withgoogle.com/csp/gws/other-hp 1 font-src *.fontawesome.com maxcdn.bootstrapcdn.com geowidget.easypack24.net fonts.gstatic.com *.tophifi.pl data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors *.googlesyndication.com 'self'; frame-src bid.g.doubleclick.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.youtube-nocookie.com *.google.com/ pay.google.com play.google.com *.autopay.eu *.weltpixel.com *.cookiebot.com *.cookiebot.eu creativecdn.com *.criteo.com td.doubleclick.net www.googletagmanager.com *.tophifi.pl tbs.tradedoubler.com www.youtube.com *.googletagmanager.com *.doubleclick.net 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://www.magezon.com platnosci.bm.pl platnosci-accept.bm.pl www.gstatic.com *.autopay.eu https://*.openstreetmap.org tile.openstreetmap.org mapa.orlenpaczka.pl ruch-osm.sysadvisors.pl magefan.com cm.magefan.com *.google-analytics.com *.bing.com *.clarity.ms *.cookiebot.com *.usercentrics.eu *.g.doubleclick.net geowidget.easypack24.net www.facebook.com www.google.pl *.google.com *.googleapis.com pagead2.googlesyndication.com *.googletagmanager.com *.gstatic.com ssl.ceneo.pl *.tophifi.pl *.user.com *.facebook.com *.reddit.com *.doubleclick.net data: 'self' 'unsafe-inline'; script-src www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.google.com/ *.autopay.eu pay.google.com *.google-analytics.com *.googletagmanager.com mapa.orlenpaczka.pl cdn.jsdelivr.net analytics.ahrefs.com *.bing.com ssl.ceneo.pl *.clarity.ms static.cloudflareinsights.com *.cookiebot.com *.cookiebot.eu *.criteo.com dc.cux.io geowidget.easypack24.net connect.facebook.net *.google.com maps.googleapis.com www.gstatic.com ec.monplat-cdn.com *.tophifi.pl wrap.tradedoubler.com *.user.com wss://tophifi.user.com *.googleadservices.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com unpkg.com *.doubleclick.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.fontawesome.com *.autopay.eu *.googleapis.com maxcdn.bootstrapcdn.com cdn.jsdelivr.net geowidget.easypack24.net tagmanager.google.com fonts.googleapis.com googletagmanager.com *.tophifi.pl *.tagmanager.google.com *.googletagmanager.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src video.cdninstagram.com *.user.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com vimeo.com *.google-analytics.com https://*.openstreetmap.org nominatim.openstreetmap.org analytics.ahrefs.com *.clarity.ms *.cookiebot.com *.cookiebot.eu *.criteo.com *.g.doubleclick.net api-shipx-pl.easypack24.net www.facebook.com *.google.com *.googleapis.com pagead2.googlesyndication.com *.googletagmanager.com csr.onet.pl *.tophifi.pl tophifi.user.com wss://tophifi.user.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.bing.com *.doubleclick.net *.run.app 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 report-uri https://csp.withgoogle.com/csp/youtube_main/strict;base-uri 'self';object-src 'none';script-src 'report-sample' 'nonce-PaeKNC5QJ7RYBssa16r4DQ' 'unsafe-inline' 'strict-dynamic' https: http: 'unsafe-eval' 1 img-src https://celesio.file.force.com *.force.com https://content.instrumentation.getconga.com slack-imgs-mil-dev.com https://*.aah.co.uk https://www.linkedin.com 'self' https://stats.g.doubleclick.net https://img.youtube.com https://gbr122.sfdc-5pakla.salesforce.com/icons/ https://celesio.my.site.com https://payments.salesforce.com/icons/ https://login.salesforce.com/icons/ https://*.googleapis.com https://ariane.abtasty.com https://www.gstatic.com https://celesio--c.um3.content.force.com *.slack-edge-gov.com https://composer.congamerge.com *.my-salesforce.com https://*.onetrust.com https://*.youtube.com *.cloudinary.com https://www.google.com *.amazonaws.com https://region1.google-analytics.com blob: https://cdn-ukwest.onetrust.com https://*.salesforce.com https://region1.analytics.google.com slack-imgs.com slack-gov-dev.com *.sfdcstatic.com https://data.instrumentation.getconga.com https://ssl.gstatic.com *.twimg.com https://*.supplier-point.com https://*.cookielaw.org *.slack.com https://www.paypal.com https://youtu.be *.slack-imgs.com slack-imgs-gov.com https://i.ytimg.com https://cdn.content.aws-dev2-uswest2.aws.sfdc.cl/icons/ *.salesforce-experience.com https://*.aah-point.com https://celesio.my.salesforce-scrt.com https://celesio--4cdevflu--livepreview.cs110.force.com https://*.force.com https://dcinfos-cache.abtasty.com slack-imgs-gov-dev.com *.slack-edge.com https://cdn.content.aws-prod1-useast1.aws.sfdc.cl/icons/ https://*.linkedin.com slack-mil-dev.com https://*.trustarc.com https://tagmanager.google.com https://www.gstatic.com/recaptcha/ https://celesio.my.salesforce.com https://*.medecator.co.uk https://www.google.com/recaptcha/ *.slack-edge.mil https://www.sandbox.paypal.com https://editor-assets.abtasty.com https://i.vimeocdn.com https://px.ads.linkedin.com https://www.googletagmanager.com https://www.google-analytics.com *.salesforce.com https://www.google.co.uk https://*.adyen.com slack-imgs.mil data:; report-to sfdc-csp-ep; report-uri https://celesio.lightning.force.com/_/ContentDomainCSPNoAuth?tenantId=00D24000000aWJn&networkId=0DM4H000000TnMn&type=communities 1 font-src fonts.gstatic.com use.typekit.net *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com https://static.klaviyo.com *.klaviyo.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.demdex.net www.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.googletagmanager.com *.google.com *.doubleclick.net *.facebook.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * js.stripe.com *.hotjar.com www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.ftcdn.net *.behance.net 'self' data: *.google.com *.google.bg www.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.gstatic.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com bat.bing.com *.google.co.uk *.googleadservices.com *.google-analytics.com *.magentocommerce.com *.widgets.magentocommerce.com *.paypalobjects.com *.postcodeanywhere.co.uk www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net assets.adobedtm.com *.adobe.io www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com *.magento-ds.com https://rum.hlx.page *.google.com *.google.bg *.googletagmanager.com connect.facebook.net *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com songbird.cardinalcommerce.com js-agent.newrelic.com bam.nr-data.net *.pcapredict.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.magento-datasolutions.com *.magento-ds.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com https://static.klaviyo.com unsafe-inline assets.braintreegateway.com services.postcodeanywhere.co.uk *.typekit.net 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.magento-datasolutions.com *.magento-ds.com *.google-analytics.com *.facebook.com *.facebook.net *.google.co.uk https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.googlesyndication.com *.doubleclick.net 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'none'; img-src 'self' https: ; script-src 'self' https: ; style-src 'self'; object-src 'none' 1 default-src * 'unsafe-inline' 'unsafe-eval' data: blob:; report-uri /csp-report; 1 default-src 'self'; script-src 'self' 'nonce-1dee91a6-a448-4ff7-b537-f49e9097db25' 'strict-dynamic' https: http:; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://accounts.google.com https://googletagmanager.com https://tagmanager.google.com https://www.googletagmanager.com https://www.gstatic.com; font-src 'self' https://fonts.gstatic.com data: https://fonts.googleapis.com; frame-src 'self' 'nonce-1dee91a6-a448-4ff7-b537-f49e9097db25' https://js.driftt.com https://www.google.com https://www.googletagmanager.com https://c.sandbox.paypal.com https://c.paypal.com https://accounts.google.com https://td.doubleclick.net https://api.recurly.com https://www.youtube.com https://www.youtube-nocookie.com; connect-src 'self' 'nonce-1dee91a6-a448-4ff7-b537-f49e9097db25' https://*.analytics.google.com https://bat.bing.com https://api.rollbar.com https://px.ads.linkedin.com https://api.recurly.com https://*.google-analytics.com http://rum-collector-2.pingdom.net https://www-data.neat.com https://www.googleadservices.com https://stats.g.doubleclick.net https://www.facebook.com https://accounts.google.com https://m1.openfpcdn.io https://docs.google.com https://*.googletagmanager.com https://pagead2.googlesyndication.com https://google.com https://analytics.google.com https://bat.bing.net https://cx.neat.com https://edge.fullstory.com https://rs.fullstory.com https://manager.eu.smartlook.cloud https://*.google.com https://*.google.ad https://*.google.ae https://*.google.com.af https://*.google.com.ag https://*.google.al https://*.google.am https://*.google.co.ao https://*.google.com.ar https://*.google.as https://*.google.at https://*.google.com.au https://*.google.az https://*.google.ba https://*.google.com.bd https://*.google.be https://*.google.bf https://*.google.bg https://*.google.com.bh https://*.google.bi https://*.google.bj https://*.google.com.bn https://*.google.com.bo https://*.google.com.br https://*.google.bs https://*.google.bt https://*.google.co.bw https://*.google.by https://*.google.com.bz https://*.google.ca https://*.google.cd https://*.google.cf https://*.google.cg https://*.google.ch https://*.google.ci https://*.google.co.ck https://*.google.cl https://*.google.cm https://*.google.cn https://*.google.com.co https://*.google.co.cr https://*.google.com.cu https://*.google.cv https://*.google.com.cy https://*.google.cz https://*.google.de https://*.google.dj https://*.google.dk https://*.google.dm https://*.google.com.do https://*.google.dz https://*.google.com.ec https://*.google.ee https://*.google.com.eg https://*.google.es https://*.google.com.et https://*.google.fi https://*.google.com.fj https://*.google.fm https://*.google.fr https://*.google.ga https://*.google.ge https://*.google.gg https://*.google.com.gh https://*.google.com.gi https://*.google.gl https://*.google.gm https://*.google.gr https://*.google.com.gt https://*.google.gy https://*.google.com.hk https://*.google.hn https://*.google.hr https://*.google.ht https://*.google.hu https://*.google.co.id https://*.google.ie https://*.google.co.il https://*.google.im https://*.google.co.in https://*.google.iq https://*.google.is https://*.google.it https://*.google.je https://*.google.com.jm https://*.google.jo https://*.google.co.jp https://*.google.co.ke https://*.google.com.kh https://*.google.ki https://*.google.kg https://*.google.co.kr https://*.google.com.kw https://*.google.kz https://*.google.la https://*.google.com.lb https://*.google.li https://*.google.lk https://*.google.co.ls https://*.google.lt https://*.google.lu https://*.google.lv https://*.google.com.ly https://*.google.co.ma https://*.google.md https://*.google.me https://*.google.mg https://*.google.mk https://*.google.ml https://*.google.com.mm https://*.google.mn https://*.google.com.mt https://*.google.mu https://*.google.mv https://*.google.mw https://*.google.com.mx https://*.google.com.my https://*.google.co.mz https://*.google.com.na https://*.google.com.ng https://*.google.com.ni https://*.google.ne https://*.google.nl https://*.google.no https://*.google.com.np https://*.google.nr https://*.google.nu https://*.google.co.nz https://*.google.com.om https://*.google.com.pa https://*.google.com.pe https://*.google.com.pg https://*.google.com.ph https://*.google.com.pk https://*.google.pl https://*.google.pn https://*.google.com.pr https://*.google.ps https://*.google.pt https://*.google.com.py https://*.google.com.qa https://*.google.ro https://*.google.ru https://*.google.rw https://*.google.com.sa https://*.google.com.sb https://*.google.sc https://*.google.se https://*.google.com.sg https://*.google.sh https://*.google.si https://*.google.sk https://*.google.com.sl https://*.google.sn https://*.google.so https://*.google.sm https://*.google.sr https://*.google.st https://*.google.com.sv https://*.google.td https://*.google.tg https://*.google.co.th https://*.google.com.tj https://*.google.tl https://*.google.tm https://*.google.tn https://*.google.to https://*.google.com.tr https://*.google.tt https://*.google.com.tw https://*.google.co.tz https://*.google.com.ua https://*.google.co.ug https://*.google.co.uk https://*.google.com.uy https://*.google.co.uz https://*.google.com.vc https://*.google.co.ve https://*.google.co.vi https://*.google.com.vn https://*.google.vu https://*.google.ws https://*.google.rs https://*.google.co.za https://*.google.co.zm https://*.google.co.zw https://*.google.cat; img-src 'self' 'nonce-1dee91a6-a448-4ff7-b537-f49e9097db25' https://*.google-analytics.com https://www.facebook.com https://bat.bing.com https://px.ads.linkedin.com https://seal-dc-easternpa.bbb.org https://*.googletagmanager.com data: https://www-data.neat.com https://ct.capterra.com https://googleads.g.doubleclick.net https://i.ytimg.com https://neat-cms-staging.s3.amazonaws.com https://neat-cms-prod.s3.amazonaws.com https://connect.facebook.net https://www.linkedin.com https://ssl.gstatic.com https://www.gstatic.com https://pagead2.googlesyndication.com https://www.googleadservices.com https://google.com https://fonts.gstatic.com https://googletagmanager.com https://bat.bing.net https://*.google.com https://*.google.ad https://*.google.ae https://*.google.com.af https://*.google.com.ag https://*.google.al https://*.google.am https://*.google.co.ao https://*.google.com.ar https://*.google.as https://*.google.at https://*.google.com.au https://*.google.az https://*.google.ba https://*.google.com.bd https://*.google.be https://*.google.bf https://*.google.bg https://*.google.com.bh https://*.google.bi https://*.google.bj https://*.google.com.bn https://*.google.com.bo https://*.google.com.br https://*.google.bs https://*.google.bt https://*.google.co.bw https://*.google.by https://*.google.com.bz https://*.google.ca https://*.google.cd https://*.google.cf https://*.google.cg https://*.google.ch https://*.google.ci https://*.google.co.ck https://*.google.cl https://*.google.cm https://*.google.cn https://*.google.com.co https://*.google.co.cr https://*.google.com.cu https://*.google.cv https://*.google.com.cy https://*.google.cz https://*.google.de https://*.google.dj https://*.google.dk https://*.google.dm https://*.google.com.do https://*.google.dz https://*.google.com.ec https://*.google.ee https://*.google.com.eg https://*.google.es https://*.google.com.et https://*.google.fi https://*.google.com.fj https://*.google.fm https://*.google.fr https://*.google.ga https://*.google.ge https://*.google.gg https://*.google.com.gh https://*.google.com.gi https://*.google.gl https://*.google.gm https://*.google.gr https://*.google.com.gt https://*.google.gy https://*.google.com.hk https://*.google.hn https://*.google.hr https://*.google.ht https://*.google.hu https://*.google.co.id https://*.google.ie https://*.google.co.il https://*.google.im https://*.google.co.in https://*.google.iq https://*.google.is https://*.google.it https://*.google.je https://*.google.com.jm https://*.google.jo https://*.google.co.jp https://*.google.co.ke https://*.google.com.kh https://*.google.ki https://*.google.kg https://*.google.co.kr https://*.google.com.kw https://*.google.kz https://*.google.la https://*.google.com.lb https://*.google.li https://*.google.lk https://*.google.co.ls https://*.google.lt https://*.google.lu https://*.google.lv https://*.google.com.ly https://*.google.co.ma https://*.google.md https://*.google.me https://*.google.mg https://*.google.mk https://*.google.ml https://*.google.com.mm https://*.google.mn https://*.google.com.mt https://*.google.mu https://*.google.mv https://*.google.mw https://*.google.com.mx https://*.google.com.my https://*.google.co.mz https://*.google.com.na https://*.google.com.ng https://*.google.com.ni https://*.google.ne https://*.google.nl https://*.google.no https://*.google.com.np https://*.google.nr https://*.google.nu https://*.google.co.nz https://*.google.com.om https://*.google.com.pa https://*.google.com.pe https://*.google.com.pg https://*.google.com.ph https://*.google.com.pk https://*.google.pl https://*.google.pn https://*.google.com.pr https://*.google.ps https://*.google.pt https://*.google.com.py https://*.google.com.qa https://*.google.ro https://*.google.ru https://*.google.rw https://*.google.com.sa https://*.google.com.sb https://*.google.sc https://*.google.se https://*.google.com.sg https://*.google.sh https://*.google.si https://*.google.sk https://*.google.com.sl https://*.google.sn https://*.google.so https://*.google.sm https://*.google.sr https://*.google.st https://*.google.com.sv https://*.google.td https://*.google.tg https://*.google.co.th https://*.google.com.tj https://*.google.tl https://*.google.tm https://*.google.tn https://*.google.to https://*.google.com.tr https://*.google.tt https://*.google.com.tw https://*.google.co.tz https://*.google.com.ua https://*.google.co.ug https://*.google.co.uk https://*.google.com.uy https://*.google.co.uz https://*.google.com.vc https://*.google.co.ve https://*.google.co.vi https://*.google.com.vn https://*.google.vu https://*.google.ws https://*.google.rs https://*.google.co.za https://*.google.co.zm https://*.google.co.zw https://*.google.cat https://*.paypal.com https://stats.g.doubleclick.net; object-src 'none'; base-uri 'self'; media-src 'self' data:; report-uri https://www.neat.com/api/csp/report; report-to csp-report-endpoint 1 frame-ancestors 'none'; default-src https://www.czater.pl 'self'; script-src https://www.googletagmanager.com https://*.analytics.google.com https://*.google-analytics.com https://googleads.g.doubleclick.net https://*.czater.pl 'self' 'unsafe-inline'; img-src https://static.sprintdatacenter.pl https://rapiddc.pl https://www.googletagmanager.com https://*.analytics.google.com https://*.google-analytics.com https://*.google.com https://*.google.pl https://googleads.g.doubleclick.net https://www.googleadservices.com data: 'self'; style-src https://www.czater.pl 'self' 'unsafe-inline' fonts.googleapis.com; font-src 'self' fonts.gstatic.com; form-action 'self'; connect-src https://*.googletagmanager.com https://*.analytics.google.com https://*.google-analytics.com https://*.google.com https://googleads.g.doubleclick.net https://pagead2.googlesyndication.com https://www.googleadservices.com wss://s2.czater.pl 1 default-src 'self' https://*.cathaycargo.com; script-src 'self' blob: 'nonce-fd7e3bedb3a2f58ff418b89ee3232576' 'unsafe-eval' https://analytics.cathaypacific.com https://tags.cathaycargo.com https://tags.tiqcdn.com https://*.qualtrics.com https://www.googletagmanager.com https://js.adsrvr.org https://ad.doubleclick.net https://connect.facebook.net https://api.mapbox.com https://cgocms.cathaypacific.com https://*.jsdelivr.net https://assets.cathaypacific.com https://snap.licdn.com https://www.youtube.com; style-src 'self' api.mapbox.com 'unsafe-inline'; img-src 'self' data: https://metrics.cathaycargo.com https://cm.everesttech.net https://*.googlesyndication.com https://www.facebook.com https://*.qualtrics.com https://px.ads.linkedin.com https://ad.doubleclick.net https://www.googletagmanager.com https://www.google.com https://i.ytimg.com https://connect.facebook.net https://www.googleadservices.com https://*.linkedin.com; connect-src 'self' https://assets.cathaypacific.com https://*.qualtrics.com https://insight.adsrvr.org https://www.google.com https://ad.doubleclick.net https://dpm.demdex.net https://*.cathaycargo.com https://www.facebook.com https://*.px-cloud.net https://*.px-cdn.net https://*.mapbox.com https://*.akamaihd.net https://api.cathaypacific.com https://px.ads.linkedin.com https://*.akstat.io https://pagead2.googlesyndication.com https://www.googleadservices.com https://collector-pxstetiejf.pxchk.net https://www.googletagmanager.com; font-src 'self' data:; worker-src 'self' chrome blob:; frame-src 'self' https://13315781.fls.doubleclick.net https://asiamiles.demdex.net https://*.adsrvr.org https://cgocms.cathaypacific.com https://cathaypacific.eu.qualtrics.com https://www.youtube.com https://login.microsoftonline.com; frame-ancestors 'self'; 1 font-src https://www.gstatic.com https://fonts.gstatic.com maxcdn.bootstrapcdn.com fonts.gstatic.com https://maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com https://www.google.com/recaptcha/ https://www.google.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com https://accounts.google.com https://*.google.com https://*.hotjar.com https://vars.hotjar.com https://www.facebook.com https://*.criteo.com https://gum.criteo.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.googleusercontent.com public.montonio.com https://www.facebook.com https://www.google.com https://www.google.ee https://www.google-analytics.com rx.apotheka.ee data: http: https: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://browser.sentry-cdn.com https://*.google.com https://*.gstatic.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com public.montonio.com https://www.google-analytics.com https://www.googletagmanager.com https://connect.facebook.net https://www.google.com https://www.gstatic.com rx.apotheka.ee http: https: 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://fonts.googleapis.com https://hcaptcha.com https://*.hcaptcha.com maxcdn.bootstrapcdn.com fonts.googleapis.com https://maxcdn.bootstrapcdn.com rx.apotheka.ee http: https: 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com https://*.ingest.sentry.io https://ipinfo.io https://*.google.com https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com https://www.google-analytics.com https://stats.g.doubleclick.net rx.apotheka.ee http: https: wss: 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src blob: https://*.mhcache.com;font-src 'self' https://*.myheritage.com https://*.mhcache.com https://fonts.gstatic.com;frame-src 'self' https://*.mhcache.com https://portal.allyable.com https://mh-site-files-5c53d6a9947c.s3.amazonaws.com https://myheritage-container.com https://www.myheritage-partners.com https://www.myheritage.com https://*.mk-sense.com https://player.vimeo.com https://*.facebook.com https://*.googleapis.com https://*.google.com https://tpc.googlesyndication.com https://*.doubleclick.net https://accounts.google.com/gsi/;script-src https://accounts.google.com/gsi/client https://www.datadoghq-browser-agent.com https://*.googleapis.com https://appleid.cdn-apple.com *.myheritage.dk https://www.myheritage.dk 'unsafe-eval' 'nonce-d739cd723a83fa99f126c2ef20de8491' 'strict-dynamic';style-src data: blob: 'unsafe-inline' 'self' https://*.myheritage.com https://*.mhcache.com https://fonts.googleapis.com https://accounts.google.com/gsi/style;connect-src data: 'self' https://*.myheritage.com https://portal.allyable.com https://*.mhcache.com https://adservice.google.com https://*.logs.datadoghq.com https://*.browser-intake-datadoghq.com https://browser-intake-datadoghq.com https://sentry.io https://*.bing.com https://*.facebook.com https://*.doubleclick.net https://*.mk-sense.com https://*.filae.com https://accounts.google.com/gsi/ https://www.google.com/pagead/landing https://*.googleapis.com https://maps.googleapis.com/maps/api/mapsjs/gen_204 https://translate.googleapis.com https://www.google.com/ccm/collect https://cdn.builder.io *.myheritage.dk;media-src 'self' https://*.myheritage.com https://*.mhcache.com;frame-ancestors 'self' https://builder.io;img-src * data:;object-src 'none';base-uri 'self' https://*.mhcache.com;report-uri /FP/API/ContentSecurityPolicy/report-violation.php?report_mode=report&canonical_page_id=/company/home/ 1 default-src 'self'; script-src 'self'; style-src 'self'; img-src 'self' data:; font-src 'self'; object-src 'none'; base-uri 'self'; 1 font-src fonts.gstatic.com use.typekit.net *.klarnacdn.net *.fontawesome.com *.cloudfront.net *.zopim.com *.sfdcstatic.com https://c1.sfdcstatic.com/etc/clientlibs/sfdc-aem-master/clientlibs_base/fonts/SalesforceSans-Regular.ttf use.fontawesome.com maxcdn.bootstrapcdn.com *.yotpo.com *.googleapis.com *.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * https://plumrocket.com *.yotpo.com swellrewards.com *.swellrewards.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.klarna.com landofcoder.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * https://plumrocket.com speedsize.com *.speedsize.com www.xtento.com *.yotpo.com swellrewards.com *.swellrewards.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net widgets.automizely.com widgets.automizely.io d3sbl0c71oxeok.cloudfront.net dhkkzdfmpzvap.cloudfront.net d2bpzs5y44q6e0.cloudfront.net d37shgu97oizpd.cloudfront.net d1zlqll3enr74n.cloudfront.net d1jynp0fpwn93a.cloudfront.net d2cb3tokgpwh3v.cloudfront.net d1re8bfxx3pw6e.cloudfront.net d35u8xwkxs8vpe.cloudfront.net d13s9xffygp5o.cloudfront.net d388nbw0dwi1jm.cloudfront.net d11p2vtu3dppaw.cloudfront.net d3r89hiip86hka.cloudfront.net dc7snq0c8ipyk.cloudfront.net d5c7kvljggzso.cloudfront.net d2h8yg3ypfzua1.cloudfront.net d1b556x7apj5fb.cloudfront.net draz1ib3z71v2.cloudfront.net dr6hdp4s5yzfc.cloudfront.net d2bomicxw8p7ii.cloudfront.net d3aypcdgvjnnam.cloudfront.net d2a3iuf10348gy.cloudfront.net d23yuld0pofhhw.cloudfront.net *.ssl-images-amazon.com *.ssl-images-amazon.co.uk *.ssl-images-amazon.co.jp *.ssl-images-amazon.jp *.ssl-images-amazon.it *.ssl-images-amazon.fr *.ssl-images-amazon.es *.ssl-images-amazon.de *.media-amazon.com *.media-amazon.co.uk *.media-amazon.co.jp *.media-amazon.jp *.media-amazon.it *.media-amazon.fr *.media-amazon.es *.media-amazon.de static-eu.payments-amazon.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.klarna.com *.klarnaevt.com *.klarnacdn.net https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://img.youtube.com *.facebook.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com *.scosche.com *.google.co.in *.sharethis.com *.adnxs.com *.adsrvr.org *.b1img.com *.amazon.com/* http://b1img.com *.force.com *.cloudfront.net speedsize.com *.speedsize.com www.xtento.com cdn.xtento.com *.yotpo.com swellrewards.com *.swellrewards.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com amcglobal.sc.omtrdc.net *.adobe.io use.typekit.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com *.magento-ds.com ajax.googleapis.com fonts.googleapis.com widgets.automizely.com widgets.automizely.io *.payments-amazon.com *.payments-amazon.co.uk *.payments-amazon.co.jp *.payments-amazon.jp *.payments-amazon.it *.payments-amazon.fr *.payments-amazon.es *.payments-amazon.de *.thecustomproductbuilder.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.klarna.com *.klarnacdn.net *.klarnaservices.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.kaptcha.com landofcoder.com s7.addthis.com *.googletagmanager.com *.facebook.net js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.cardinalcommerce.com g.doubleclick.net *.google.com *.zdassets.com *.nmgassets.com *.expertrec.com *.tiktok.com *.trackedweb.net *.shop.pe *.google.co.in *.sharethis.com *.zopim.com *.adnxs.com *.b1js.com *.cloudfront.net *.hotjar.com *.b1img.com http://shop.pe *.amazonaws.com http://b1img.com *.jsdelivr.net *.zendesk.com *.newrelic.com *.force.com https://service.force.com/embeddedservice/5.0/esw.min.js *.shopbox.ai https://shopbox-widgets-storybook.pages.dev/sbmain.min.js https://d.la1-core1.sfdc-lywfpd.salesforceliveagent.com *.salesforceliveagent.com https://d41000002lgrjea2.my.salesforce-sites.com *.my.salesforce-sites.com https://d41000002lgrjea2.my.salesforce.com/lightning/lightning.out.js https://d41000002lgrjea2.my.salesforce.com/lightning/lightning.out.delegate.js https://cdnjs.cloudflare.com/ajax/libs/dompurify/1.0.10/purify.js https://cmp.osano.com/AzqbnpTQhAyVm3E99/8df62698-cfde-462e-8a72-94fe3192c7c1/osano.js https://s.pinimg.com/ct/core.js https://s.pinimg.com/ct/lib/main.15f60036.js https://d41000002lgrjea2.my.salesforce-sites.com/liveAgentSetupFlow/embeddedService/sidebarApp.app *.iesnare.com *.pinimg.com *.pinterest.com speedsize.com *.speedsize.com www.xtento.com cdn.xtento.com *.yotpo.com swellrewards.com *.swellrewards.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com widgets.automizely.com widgets.automizely.io *.klarnacdn.net https://static.klaviyo.com *.fontawesome.com unsafe-inline assets.braintreegateway.com *.cloudfront.net *.addshoppers.com *.force.com https://d41000002lgrjea2.my.salesforce-sites.com https://d.la1-core1.sfdc-lywfpd.salesforceliveagent.com *.salesforceliveagent.com *.my.salesforce-sites.com https://static-tracking.klaviyo.com/onsite/js/532.fa051703115da6a50763.css *.klaviyo.com speedsize.com *.speedsize.com *.yotpo.com swellrewards.com *.swellrewards.com maxcdn.bootstrapcdn.com *.googleapis.com 'self' 'unsafe-inline'; object-src landofcoder.com 'self' 'unsafe-inline'; media-src *.adobe.com *.iesnare.com *.zdassets.com speedsize.com *.speedsize.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io *.magento-datasolutions.com *.magento-ds.com *.sentry.io api.automizely.com api.automizely.io *.amazon.com *.amazon.co.uk *.amazon.co.jp *.amazon.jp *.amazon.it *.amazon.fr *.amazon.es *.amazon.de *.amazonpay.com *.amazonpay.co.uk *.amazonpay.co.jp *.amazonpay.jp *.amazonpay.it *.amazonpay.fr *.amazonpay.es *.amazonpay.de mws.amazonservices.com mws.amazonservices.co.uk mws.amazonservices.co.jp mws.amazonservices.jp mws.amazonservices.it mws.amazonservices.fr mws.amazonservices.es mws.amazonservices.de www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.klarnaevt.com *.klarnacdn.net *.klarna.com *.klarnaservices.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.kaptcha.com landofcoder.com ekr.zdassets.com/ *.google-analytics.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.sharethis.com *.trackedweb.net *.klaviyo.com *.zopim.com *.zendesk.com *.hotjar.io *.shop.pe wss://widget-mediator.zopim.com wss://pod-27.zendesk.com *.nr-data.net https://bam.nr-data.net *.jsdelivr.net *.my.sentry.io *.hotjar.com/* wss://ws.hotjar.com *.safeopt.com *.scosche.com *.force.com *.run.app *.a.run.app https://d.la1-core1.sfdc-lywfpd.salesforceliveagent.com *.salesforceliveagent.com https://d41000002lgrjea2.my.salesforce-sites.com *.my.salesforce-sites.com *.tiktok.com *.pinterest.com *.googleapis.com *.iesnare.com *.osano.com *.api.osano.com wss://mpsnare.iesnare.com/star speedsize.com *.speedsize.com *.yotpo.com swellrewards.com *.swellrewards.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src speedsize.com *.speedsize.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.squarecdn.com assets.bounceexchange.com *.bounceexchange.com *.bsscommerce.com fonts.googleapis.com *.googleapis.com *.arkswimwear.com *.licdn.com *.pingdom.net *.criteo.com *.adobe.net *.fontawesome.com *.adobedtm.com *.cardinalcommerce.com *.ccdc02.com *.magento-datasolutions.com *.magento-ds.com *.sentry.io *.sentry-cdn.com *.newrelic.com *.nr-data.net *.vimeocdn.com *.youtube.com *.bolt.com *.commerce-quick-checkout.com *.addthis.com *.vimeo.com *.paypal.com *.google.co.in *.braintreegateway.com *.everesttech.net *.demdex.net *.ytimg.com *.swagger.io *.ftcdn.net *.behance.net *.magentocommerce.com *.doubleclick.net *.bidswitch.net *.yieldmo.com *.adnxs.com *.clmbtech.com *.smaato.net *.pubmatic.com *.taboola.com *.teads.tv *.3lift.com *.socdm.com *.casalemedia.com *.dable.io *.adingo.jp *.360yield.com *.rlcdn.com *.bing.com *.outbrain.com *.yahoo.com *.smartadserver.com *.rubiconproject.com *.media.net *.stickyadstv.com *.aralego.com *.dmxleo.com *.omtrdc.net *.snplow.net *.adobedc.net *.google-analytics.com *.googleadservices.com *.googletagmanager.com *.magedevteam.com *.linkedin.com *.braintree-api.com *.magento.com *.ampproject.org *.avada.io *.zdassets.com *.geojs.io *.razorpay.com *.paytm.in *.yellowmessenger.com *.facebook.net *.netcoresmartech.com *.bunny.net *.bidr.io *.paypalobjects.com *.yellow.ai *.facebook.com wss://r0.cloud.yellow.ai/websocket/ wss://cloud.yellow.ai/websocket/ *.linkedin.com/ wss://securegw.paytm.in/websocket/ *.cdninstagram.com https://plugin-magento-ui.glopalservice.com maxcdn.bootstrapcdn.com cdn1.stamped.io stamped.io data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com widgets.sandbox.afterpay.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com assets.bounceexchange.com dash.bounceexchange.com dash-staging.bounceexchange.com *.bounceexchange.com *.arkswimwear.com *.bsscommerce.com web-writer.sg.smartlook.cloud *.sg.smartlook.cloud c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * zip.co static.zip.co sandbox.zip.co zipmoney.com.au sandbox.zipmoney.com.au checkout.gb.zip.co checkout.quadpay.com checkout-sandbox.quadpay.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.afterpay.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com maps.gstatic.com *.calcurates.com assets.bounceexchange.com events.bouncex.net *.bounceexchange.com *.bouncex.net *.bsscommerce.com bam.nr-data.net *.nr-data.net *.adobedtm.com *.arkswimwear.com *.assets.adobedtm.com *.z.clarity.ms *.clarity.ms rec.smartlook.com *.smartlook.com t.cfjump.com *.cfjump.com *.zip.co static.zipmoney.com.au *.zipmoney.com.au tagmanager.google.com *.google.com www.google.co.in *.google.co.in *.sc.omtrdc.net *.demdex.net dpm.demdex.net cm.everesttech.net *.everesttech.net *.magentocommerce.com www.googleadservices.com *.googleadservices.com www.google-analytics.com *.analytics.yahoo.com www.paypalobjects.com *.paypalobjects.com x.bidswitch.net cm.g.doubleclick.net dsum-sec.casalemedia.com us-u.openx.net sync.taboola.com sync.outbrain.com image2.pubmatic.com ups.analytics.yahoo.com eb2.3lift.com pixel.rubiconproject.com *.bidswitch.net *.doubleclick.net *.casalemedia.com *.openx.net *.taboola.com *.outbrain.com *.pubmatic.com *.3lift.com *.rubiconproject.com *.ftcdn.net *.behance.net p.typekit.net *.typekit.net fpdbs.paypal.com fpdbs.sandbox.paypal.com *.ytimg.com validator.swagger.io static.afterpay.com site-assets.afterpay.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com cdn-redirector.glopal.com plugin-magento-ui.glopalservice.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com cdn1.stamped.io stamped.io *.gstatic.com *.sandbox.paypal.com *.swagger.io *.facebook.com *.glopal.com *.glopalservice.com *.braintreegateway.com *.stamped.io d.adroll.com *.adroll.com c.bing.com *.bing.com *.googletagmanager.com ib.adnxs.com *.adnxs.com s3-us-west-2.amazonaws.com *.amazonaws.com js-agent.newrelic.com *.newrelic.com *.sandbox.my.site.com hello.zonos.com *.zonos.com idsync.rlcdn.com *.rlcdn.com pos.baidu.com *.baidu.com bh.contextweb.com *.contextweb.com crb.kargo.com *.kargo.com *.criteo.com gum.criteo.com match.prod.bidr.io *.prod.bidr.io loadm.exelator.com secure-gl.imrworldwide.com *.exelator.com *.imrworldwide.com ads.scorecardresearch.com *.scorecardresearch.com d.turn.com *.turn.com pm.w55c.net *.w55c.net web-writer.sg.smartlook.cloud *.sg.smartlook.cloud ml314.com pixel.tapad.com *.tapad.com match.adsrvr.org *.adsrvr.org https://cdn-redirector.glopal.com https://plugin-magento-ui.glopalservice.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com cdn1.stamped.io stamped.io t.zip.co static.zip.co data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com commerce-payments-sdk.adobe.io www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://portal.sandbox.afterpay.com https://portal.afterpay.com https://static.afterpay.com *.squarecdn.com https://hbiq.net www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.attn.tv events.attentivemobile.com *.googleapis.com *.bsscommerce.com *.arkswimwear.com *.adobedtm.com *.assets.adobedtm.com *.z.clarity.ms *.clarity.ms rec.smartlook.com *.smartlook.com t.cfjump.com *.cfjump.com *.zip.co static.zipmoney.com.au *.zipmoney.com.au tagmanager.google.com www.google.co.in a.adroll.com *.adroll.com x.bidswitch.net cm.g.doubleclick.net dsum-sec.casalemedia.com us-u.openx.net sync.taboola.com sync.outbrain.com image2.pubmatic.com ups.analytics.yahoo.com eb2.3lift.com pixel.rubiconproject.com *.bidswitch.net *.doubleclick.net *.casalemedia.com *.openx.net *.taboola.com *.outbrain.com *.pubmatic.com *.google-analytics.com *.3lift.com *.rubiconproject.com *.google.co.in *.sc.omtrdc.net *.demdex.net dpm.demdex.net cm.everesttech.net *.everesttech.net *.magentocommerce.com widgets.magentocommerce.com www.googleadservices.com *.googleadservices.com www.google-analytics.com www.paypalobjects.com *.paypalobjects.com *.paypal.com *.ftcdn.net *.behance.net p.typekit.net *.typekit.net fpdbs.paypal.com fpdbs.sandbox.paypal.com *.ytimg.com validator.swagger.io static.afterpay.com site-assets.afterpay.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com cdn-redirector.glopal.com plugin-magento-ui.glopalservice.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com cdn1.stamped.io stamped.io *.gstatic.com *.sandbox.paypal.com *.swagger.io *.afterpay.com *.facebook.com *.glopal.com *.glopalservice.com *.braintreegateway.com *.stamped.io d.adroll.com c.bing.com *.bing.com *.googletagmanager.com ib.adnxs.com *.adnxs.com s3-us-west-2.amazonaws.com *.amazonaws.com js-agent.newrelic.com *.sandbox.my.site.com hello.zonos.com *.zonos.com bam.nr-data.net idsync.rlcdn.com *.rlcdn.com bh.contextweb.com *.contextweb.com crb.kargo.com *.kargo.com *.criteo.com gum.criteo.com match.prod.bidr.io *.prod.bidr.io loadm.exelator.com secure-gl.imrworldwide.com *.exelator.com *.imrworldwide.com ads.scorecardresearch.com *.scorecardresearch.com d.turn.com *.turn.com pm.w55c.net *.w55c.net web-writer.sg.smartlook.cloud *.sg.smartlook.cloud tag.wknd.ai tag.bounceexchange.com assets.bounceexchange.com api.bounceexchange.com dev.bounceexchange.com dash.bounceexchange.com dash-staging.bounceexchange.com *.wknd.ai *.bounceexchange.com https://cdn-redirector.glopal.com https://plugin-magento-ui.glopalservice.com cdn-renderer.glopalstore.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com cdn1.stamped.io stamped.io static.zip.co zip.co 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com static.afterpay.com/ *.squarecdn.com *.arkswimwear.com *.bsscommerce.com *.bounceexchange.com https://cdn-redirector.glopal.com https://plugin-magento-ui.glopalservice.com *.fontawesome.com maxcdn.bootstrapcdn.com assets.braintreegateway.com cdn1.stamped.io stamped.io 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.bsscommerce.com bam.nr-data.net *.nr-data.net *.arkswimwear.com *.adobedtm.com *.assets.adobedtm.com *.z.clarity.ms *.clarity.ms rec.smartlook.com *.smartlook.com t.cfjump.com *.cfjump.com *.zip.co static.zipmoney.com.au *.zipmoney.com.au tagmanager.google.com *.google.com www.google.co.in a.adroll.com *.adroll.com x.bidswitch.net cm.g.doubleclick.net dsum-sec.casalemedia.com us-u.openx.net sync.taboola.com sync.outbrain.com image2.pubmatic.com ups.analytics.yahoo.com eb2.3lift.com pixel.rubiconproject.com *.bidswitch.net *.doubleclick.net *.casalemedia.com *.openx.net *.taboola.com *.outbrain.com *.pubmatic.com *.google-analytics.com *.3lift.com *.rubiconproject.com *.google.co.in *.sc.omtrdc.net *.demdex.net dpm.demdex.net cm.everesttech.net *.everesttech.net *.magentocommerce.com widgets.magentocommerce.com www.googleadservices.com *.googleadservices.com www.google-analytics.com www.paypalobjects.com *.paypalobjects.com t.paypal.com *.paypal.com *.ftcdn.net *.behance.net p.typekit.net *.typekit.net fpdbs.paypal.com fpdbs.sandbox.paypal.com *.ytimg.com validator.swagger.io static.afterpay.com site-assets.afterpay.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com cdn-redirector.glopal.com plugin-magento-ui.glopalservice.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com cdn1.stamped.io stamped.io *.gstatic.com *.sandbox.paypal.com *.swagger.io *.afterpay.com *.facebook.com *.glopal.com *.glopalservice.com *.braintreegateway.com *.stamped.io d.adroll.com c.bing.com *.bing.com *.googletagmanager.com ib.adnxs.com *.adnxs.com s3-us-west-2.amazonaws.com *.amazonaws.com js-agent.newrelic.com *.newrelic.com *.sandbox.my.site.com hello.zonos.com *.zonos.com idsync.rlcdn.com *.rlcdn.com bh.contextweb.com *.contextweb.com crb.kargo.com *.kargo.com *.criteo.com gum.criteo.com match.prod.bidr.io *.prod.bidr.io loadm.exelator.com secure-gl.imrworldwide.com *.exelator.com *.imrworldwide.com ads.scorecardresearch.com *.scorecardresearch.com d.turn.com *.turn.com pm.w55c.net *.w55c.net cdn1.stamped.io stamped.io 'self' 'unsafe-inline'; manifest-src *.bsscommerce.com *.arkswimwear.com *.licdn.com *.pingdom.net *.criteo.com *.adobe.net *.googleapis.com *.fontawesome.com *.adobedtm.com *.cardinalcommerce.com *.ccdc02.com *.magento-datasolutions.com *.magento-ds.com *.sentry.io *.sentry-cdn.com *.newrelic.com *.nr-data.net *.vimeocdn.com *.youtube.com *.bolt.com *.commerce-quick-checkout.com *.gstatic.com *.addthis.com *.vimeo.com *.paypal.com *.google.co.in *.braintreegateway.com *.everesttech.net *.typekit.net *.demdex.net *.ytimg.com *.swagger.io *.ftcdn.net *.behance.net *.magentocommerce.com *.doubleclick.net *.bidswitch.net *.yieldmo.com *.adnxs.com *.clmbtech.com *.smaato.net *.pubmatic.com *.taboola.com *.teads.tv *.3lift.com *.socdm.com *.casalemedia.com *.dable.io *.adingo.jp *.360yield.com *.rlcdn.com *.bing.com *.outbrain.com *.yahoo.com *.smartadserver.com *.rubiconproject.com *.media.net *.stickyadstv.com *.aralego.com *.dmxleo.com *.omtrdc.net *.snplow.net *.adobedc.net *.google-analytics.com *.googleadservices.com *.googletagmanager.com *.magedevteam.com *.linkedin.com *.braintree-api.com *.magento.com *.ampproject.org *.avada.io *.zdassets.com *.geojs.io *.razorpay.com *.paytm.in *.yellowmessenger.com *.facebook.net *.netcoresmartech.com *.bunny.net *.bidr.io *.paypalobjects.com *.yellow.ai *.facebook.com wss://r0.cloud.yellow.ai/websocket/ wss://cloud.yellow.ai/websocket/ *.linkedin.com/ wss://securegw.paytm.in/websocket/ *.cdninstagram.com web-writer.sg.smartlook.cloud *.sg.smartlook.cloud 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.afterpay.com *.squarecdn.com https://hbiq.net https://iq.afterpay-beta.com https://iq.afterpay.com www.facebook.com *.facebook.com graph.facebook.com business.facebook.com *.attn.tv events.attentivemobile.com *.googleapis.com events.bouncex.net coupons.bounceexchange.com *.cdnwidget.com *.cdnbasket.net *.bsscommerce.com bam.nr-data.net *.arkswimwear.com *.z.clarity.ms *.clarity.ms stats.g.doubleclick.net *.g.doubleclick.net manager.eu.smartlook.cloud *.smartlook.com www.google.co.in *.adobedtm.com *.adobe.com *.assets.adobedtm.com rec.smartlook.com t.cfjump.com *.cfjump.com *.zip.co static.zipmoney.com.au *.zipmoney.com.au tagmanager.google.com *.google.co.in *.sc.omtrdc.net *.demdex.net dpm.demdex.net cm.everesttech.net *.everesttech.net *.magentocommerce.com widgets.magentocommerce.com www.googleadservices.com *.googleadservices.com www.google-analytics.com *.analytics.yahoo.com www.paypalobjects.com *.paypalobjects.com t.paypal.com x.bidswitch.net cm.g.doubleclick.net dsum-sec.casalemedia.com us-u.openx.net sync.taboola.com sync.outbrain.com image2.pubmatic.com ups.analytics.yahoo.com eb2.3lift.com pixel.rubiconproject.com *.bidswitch.net *.doubleclick.net *.casalemedia.com *.openx.net *.taboola.com *.outbrain.com *.pubmatic.com *.3lift.com *.rubiconproject.com *.ftcdn.net *.behance.net p.typekit.net *.typekit.net fpdbs.paypal.com fpdbs.sandbox.paypal.com *.ytimg.com validator.swagger.io static.afterpay.com site-assets.afterpay.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com cdn-redirector.glopal.com plugin-magento-ui.glopalservice.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com cdn1.stamped.io stamped.io *.gstatic.com *.sandbox.paypal.com *.swagger.io *.glopal.com *.glopalservice.com *.braintreegateway.com *.stamped.io d.adroll.com *.adroll.com c.bing.com *.bing.com *.googletagmanager.com ib.adnxs.com *.adnxs.com s3-us-west-2.amazonaws.com *.amazonaws.com js-agent.newrelic.com *.sandbox.my.site.com hello.zonos.com *.zonos.com idsync.rlcdn.com *.rlcdn.com bh.contextweb.com *.contextweb.com crb.kargo.com *.kargo.com *.criteo.com gum.criteo.com match.prod.bidr.io *.prod.bidr.io loadm.exelator.com secure-gl.imrworldwide.com *.exelator.com *.imrworldwide.com ads.scorecardresearch.com *.scorecardresearch.com d.turn.com *.turn.com pm.w55c.net *.w55c.net web-writer.sg.smartlook.cloud *.sg.smartlook.cloud https://api-plugin-facade.glopalservice.com https://cognito-idp.eu-west-1.amazonaws.com api.glopaltranslator.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com cdn1.stamped.io stamped.io 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 object-src 'none';base-uri 'self';script-src 'nonce--NxUIpo7YgSwwC5n7x1Zsg' 'strict-dynamic' 'report-sample' 'unsafe-eval' 'unsafe-inline' https: http:;report-uri https://csp.withgoogle.com/csp/gws/other-hp 1 object-src 'none';base-uri 'self';script-src 'nonce-DU-I5hOtKFVxy2BAsMaeJw' 'strict-dynamic' 'report-sample' 'unsafe-eval' 'unsafe-inline' https: http:;report-uri https://csp.withgoogle.com/csp/gws/other-hp 1 report-uri https://csp.withgoogle.com/csp/youtube_main/strict;base-uri 'self';object-src 'none';script-src 'report-sample' 'nonce-X-hsIhcL6zMgD9WJOYjtwQ' 'unsafe-inline' 'strict-dynamic' https: http: 'unsafe-eval' 1 default-src 'self' https: data: blob: 'unsafe-inline' 'unsafe-eval' 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com www.searchanise.com *.searchserverapi.com *.tawk.to v2.zopim.com embed.tawk.to *.commerce-connector.com *.flixcar.com fonts.cdnfonts.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * www.searchanise.com *.searchserverapi.com *.twitter.com *.tawk.to 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.sameday.ro c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * www.searchanise.com *.searchserverapi.com *.twitter.com *.tawk.to *.weltpixel.com *.2performant.com *.doubleclick.net *.pinterest.com *.force.com *.facebook.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io https://images.unsplash.com cdn.kfea.ro shopmania.ro *.openstreetmap.org t.themarketer.com cdn1.themarketer.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.twitter.com *.twimg.com www.google.ru www.searchanise.com *.searchserverapi.com s3.amazonaws.com *.tawk.to tawk.link cdn.jsdelivr.net s3.amazonaws.com/ v2assets.zopim.io *.google.ro *.facebook.com *.widgetwhats.com compari.ro ct.pinterest.com *.flix360.com *.flixcar.com *.flix360.io *.bing.com bat.bing.com cdn-cookieyes.com cdn1.mktr2.com c.clarity.ms data: 'self' 'unsafe-inline'; script-src www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://maps.googleapis.com https://player.vimeo.com *.sameday.ro unpkg.com/map-fanbox-points@0.0.5/umd/map-fanbox-points.js *.themarketer.com cdn1.themarketer.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com searchanise-ef84.kxcdn.com s3.amazonaws.com ajax.aspnetcdn.com www.searchanise.com searchserverapi.com *.searchanise.com api.amplitude.com *.twitter.com *.twimg.com *.tawk.to cdn.jsdelivr.net https://www.googletagmanager.com tagmanager.google.com *.zdassets.com v2.zopim.com *.facebook.net *.facebook.com attr-2p.com *.widgetwhats.com chimpstatic.com embed.tawk.to *.jsdelivr.net *.hotjar.com *.arukereso.com *.gstatic.com *.clarity.ms *.pinimg.com *.pinterest.com *.enzuzo.com cdn-cookieyes.com *.googlesyndication.com *.commerce-connector.com *.force.com *.salesforceliveagent.com aqurate.ai *.flixcar.com *.flix360.io *.flixfacts.com popupsmart.com *.sharethis.com *.tiktok.com *.omniconvert.com *.2performant.com *.bing.com bat.bing.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com *.sameday.ro t.themarketer.com cdn1.themarketer.com assets.braintreegateway.com www.searchanise.com *.searchserverapi.com searchanise-ef84.kxcdn.com s3.amazonaws.com *.twitter.com ton.twimg.com *.tawk.to cdn.jsdelivr.net tagmanager.google.com *.googleapis.com *.widgetwhats.com embed.tawk.to *.googletagmanager.com tpc.googlesyndication.com *.cloudfront.net *.commerce-connector.com *.force.com *.popupsmart.com popupsmart.com *.flixcar.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.tawk.to tawk.link *.zdassets.com cdn1.mktr2.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://maps.googleapis.com https://player.vimeo.com *.fancourier.ro *.themarketer.com cdn1.themarketer.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com api.amplitude.com stats.g.doubleclick.net *.tawk.to wss://*.tawk.to https://www.google-analytics.com ekr.zdassets.com wss://widget-mediator.zopim.com pagead2.googlesyndication.com *.google.ro googleads.g.doubleclick.net region1.analytics.google.com *.2performant.com *.widgetwhats.com zdata-ro-bellabike.s3.eu-west-1.amazonaws.com kfea.zendesk.com api.edrone.me *.pinterest.com *.clarity.ms *.commerce-connector.com *.facebook.com *.hotjar.com *.hotjar.io *.google-analytics.com *.sharethis.com *.enzuzo.com *.flixcar.com *.tiktok.com *.omniconvert.com region1.google-analytics.com *.cookieyes.com log.cookieyes.com cdn-cookieyes.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src widget-mediator.zopim.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; script-src 'self' 'unsafe-inline' https://matomo.eah-jena.de/matomo.js https://*.openstreetmap.org 'report-sample'; style-src-attr 'unsafe-inline' 'report-sample'; img-src 'self' data: *.ytimg.com *.vimeocdn.com https://*.openstreetmap.org https://www.studycheck.de https://*.typo3.org https://https//www.studycheck.de/%2A https://matomo.eah-jena.de/matomo.php; base-uri 'self'; frame-src 'self' *.youtube-nocookie.com *.youtube.com *.vimeo.com https://www2.hochschulsport.eah-jena.de; connect-src 'self' data: https://*.openstreetmap.org https://www.eah-jena.de https://matomo.eah-jena.de; media-src 'self' blob:; font-src 'self' data:; style-src blob: data: 'self' 'unsafe-inline' 'report-sample'; worker-src blob: 'report-sample'; report-uri https://www.eah-jena.de/@http-reporting?csp=report&requestTime=1770429260924657&requestHash=3800ac2e4916cdd7e7fc11b3775f7322e41cb154 1 connect-src 'self' https://api.stripe.com https://*.webtrends-optimize.com https://*.webtrends-optimize.workers.dev https://*.thedonkeysanctuary.org.uk https://*.googlesyndication.com https://ds.cookiehub.net https://consent.cookiehub.net https://region-eu.cookiehub.net https://consent-eu.cookiehub.net https://cookiehub.net https://cdn.cookiehub.eu https://api.edq.com https://*.google-analytics.com/ sentry.io https://www.google-analytics.com https://www.googletagmanager.com; frame-src 'self' https://*.js.stripe.com https://js.stripe.com https://hooks.stripe.com https://www.googletagmanager.com https://live.streamdays.com https://*.google.com; img-src 'self' https://*.webtrends-optimize.com https://planyo-ch.s3.eu-central-2.amazonaws.com https://www.planyo.com data: https://*.googlesyndication.com https://i.ytimg.com https://www.google-analytics.com https://www.googletagmanager.com; object-src 'none'; script-src 'self' 'report-sample' 'unsafe-inline' 'unsafe-eval' https://*.js.stripe.com https://*.webtrends-optimize.com https://*.webtrends-optimize.workers.dev https://cookiehub.net https://cdn.cookiehub.eu cdnjs.cloudflare.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://github.com https://js.stripe.com https://www.gstatic.com https://www.planyo.com; script-src-elem 'self' 'unsafe-inline' https://*.webtrends-optimize.com https://maxcdn.bootstrapcdn.com https://www.googletagmanager.com https://cdn.cookiehub.eu https://live.streamdays.com https://ajax.googleapis.com https://*.googlesyndication.com https://www.google.com/recaptcha/ cdnjs.cloudflare.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://github.com https://js.stripe.com https://www.gstatic.com https://www.planyo.com; style-src 'self' 'report-sample' 'unsafe-inline' https://*.webtrends-optimize.com https://*.webtrends-optimize.workers.dev https://cookiehub.net https://cdn.cookiehub.eu https://cdnjs.cloudflare.com; style-src-elem 'self' 'unsafe-inline' https://fonts.googleapis.com https://www.planyo.com https://assets.planyoexperts.com https://cdn.cookiehub.eu https://cookiehub.net https://cdnjs.cloudflare.com; worker-src 'self'; base-uri 'self'; form-action 'self'; frame-ancestors 'self' 1 default-src blob: https://*.mhcache.com;font-src 'self' https://*.myheritage.com https://*.mhcache.com https://fonts.gstatic.com;frame-src 'self' https://*.mhcache.com https://portal.allyable.com https://mh-site-files-5c53d6a9947c.s3.amazonaws.com https://myheritage-container.com https://www.myheritage-partners.com https://www.myheritage.com https://*.mk-sense.com https://player.vimeo.com https://*.facebook.com https://*.googleapis.com https://*.google.com https://tpc.googlesyndication.com https://*.doubleclick.net https://accounts.google.com/gsi/;script-src https://accounts.google.com/gsi/client https://www.datadoghq-browser-agent.com https://*.googleapis.com https://appleid.cdn-apple.com *.myheritage.it https://www.myheritage.it 'unsafe-eval' 'nonce-cc03c29acbd424e791b92a031c1273b4' 'strict-dynamic';style-src data: blob: 'unsafe-inline' 'self' https://*.myheritage.com https://*.mhcache.com https://fonts.googleapis.com https://accounts.google.com/gsi/style;connect-src data: 'self' https://*.myheritage.com https://portal.allyable.com https://*.mhcache.com https://adservice.google.com https://*.logs.datadoghq.com https://*.browser-intake-datadoghq.com https://browser-intake-datadoghq.com https://sentry.io https://*.bing.com https://*.facebook.com https://*.doubleclick.net https://*.mk-sense.com https://*.filae.com https://accounts.google.com/gsi/ https://www.google.com/pagead/landing https://*.googleapis.com https://maps.googleapis.com/maps/api/mapsjs/gen_204 https://translate.googleapis.com https://www.google.com/ccm/collect https://cdn.builder.io *.myheritage.it;media-src 'self' https://*.myheritage.com https://*.mhcache.com;frame-ancestors 'self' https://builder.io;img-src * data:;object-src 'none';base-uri 'self' https://*.mhcache.com;report-uri /FP/API/ContentSecurityPolicy/report-violation.php?report_mode=report&canonical_page_id=/company/home/ 1 worker-src blob: 'self' *.noibu.com wss://*.noibu.com; font-src fonts.gstatic.com *.yotpo.com *.googleapis.com *.gstatic.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com https://hpp.worldpay.com/app/hpp-iframe/integration/wpg/corporate https://secure-test.worldpay.com/shopper/3ds/ddc.html https://secure.worldpay.com/shopper/3ds/ddc.html https://payments-test.worldpay.com/app/hpp-iframe/integration/wpg/corporate https://payments-live.hpp.apps.eu-west-1-7z55k.dev.msp.worldpay.io/app/hpp-iframe/integration/wpg/corporate https://payments.worldpay.com/app/hpp-iframe/integration/wpg/corporate *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors https://pay.google.com/ 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net www.googletagmanager.com www.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.dotdigital-pages.com *.dotdigital.com webchat.dotdigital.com webchat.staging.dotdigital.com *.hub-box.com https://payments-test.worldpay.com/app/hpp-iframe/integration/wpg/corporate https://payments.worldpay.com/app/hpp-iframe/integration/wpg/corporate https://payments-live.hpp.apps.eu-west-1-7z55k.dev.msp.worldpay.io/app/hpp-iframe/integration/wpg/corporate https://pay.google.com https://secure-test.worldpay.com https://hpp.worldpay.com/ *.yotpo.com www.xtento.com *.fls.doubleclick.net *.worldpay.com *.trustarc.com sdx.microsoft.com *.googleapis.com *.google.com blob: *.dwin1.com *.awin1.com *.zenaps.com *.sciencebehindecommerce.com *.dam.wexup.com fidelitepro.screwfix.fr 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.trackedlink.net *.dycdn.net *.cloudflare.com *.gstatic.com *.yotpo.com www.xtento.com cdn.xtento.com *.googleapis.com https://*.ggpht.com media.screwfix.fr media.screwfix.eu consent.trustarc.com *.doubleclick.net *.contentsquare.net *.postcodeanywhere.co.uk yotpo-editor-production.s3.amazonaws.com sp.analytics.yahoo.com s.yimg.com p1.zemanta.com *.googletagmanager.com *.googleusercontent.com *.google.com *.google.ad *.google.ae *.google.com.af *.google.com.ag *.google.com.ai *.google.al *.google.am *.google.co.ao *.google.com.ar *.google.as *.google.at *.google.com.au *.google.az *.google.ba *.google.com.bd *.google.be *.google.bf *.google.bg *.google.com.bh *.google.bi *.google.bj *.google.com.bn *.google.com.bo *.google.com.br *.google.bs *.google.bt *.google.co.bw *.google.by *.google.com.bz *.google.ca *.google.cd *.google.cf *.google.cg *.google.ch *.google.ci *.google.co.ck *.google.cl *.google.cm *.google.cn *.google.com.co *.google.co.cr *.google.com.cu *.google.cv *.google.com.cy *.google.cz *.google.de *.google.dj *.google.dk *.google.dm *.google.com.do *.google.dz *.google.com.ec *.google.ee *.google.com.eg *.google.es *.google.com.et *.google.fi *.google.com.fj *.google.fm *.google.fr *.google.ga *.google.ge *.google.gg *.google.com.gh *.google.com.gi *.google.gl *.google.gm *.google.gr *.google.com.gt *.google.gy *.google.com.hk *.google.hn *.google.hr *.google.ht *.google.hu *.google.co.id *.google.ie *.google.co.il *.google.im *.google.co.in *.google.iq *.google.is *.google.it *.google.je *.google.com.jm *.google.jo *.google.co.jp *.google.co.ke *.google.com.kh *.google.ki *.google.kg *.google.co.kr *.google.com.kw *.google.kz *.google.la *.google.com.lb *.google.li *.google.lk *.google.co.ls *.google.lt *.google.lu *.google.lv *.google.com.ly *.google.co.ma *.google.md *.google.me *.google.mg *.google.mk *.google.ml *.google.com.mm *.google.mn *.google.ms *.google.com.mt *.google.mu *.google.mv *.google.mw *.google.com.mx *.google.com.my *.google.co.mz *.google.com.na *.google.com.ng *.google.com.ni *.google.ne *.google.nl *.google.no *.google.com.np *.google.nr *.google.nu *.google.co.nz *.google.com.om *.google.com.pa *.google.com.pe *.google.com.pg *.google.com.ph *.google.com.pk *.google.pl *.google.pn *.google.com.pr *.google.ps *.google.pt *.google.com.py *.google.com.qa *.google.ro *.google.ru *.google.rw *.google.com.sa *.google.com.sb *.google.sc *.google.se *.google.com.sg *.google.sh *.google.si *.google.sk *.google.com.sl *.google.sn *.google.so *.google.sm *.google.sr *.google.st *.google.com.sv *.google.td *.google.tg *.google.co.th *.google.com.tj *.google.tl *.google.tm *.google.tn *.google.to *.google.com.tr *.google.tt *.google.com.tw *.google.co.tz *.google.com.ua *.google.co.ug *.google.co.uk *.google.com.uy *.google.co.uz *.google.com.vc *.google.co.ve *.google.vg *.google.co.vi *.google.com.vn *.google.vu *.google.ws *.google.rs *.google.co.za *.google.co.zm *.google.co.zw *.google.cat *.bing.com *.microsoft.com *.dwin1.com *.awin1.com *.zenaps.com *.sciencebehindecommerce.com cdn.optimizely.com *.tealiumiq.com *.facebook.com *.facebook.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal webchat.dotdigital.com webchat.staging.dotdigital.com *.dycdn.net dn1i8v75r669j.cloudfront.net dkpklk99llpj0.cloudfront.net ds9p2a60lh6fp.cloudfront.net d1y9qtn9cuc3xw.cloudfront.net d81mfvml8p5ml.cloudfront.net *.freshrelevance.com *.dotdigital.com https://www.google.com/recaptcha/api.js www.gstatic.com cdnjs.cloudflare.com https://pay.google.com/gp/p/js/pay.js https://applepay.cdn-apple.com/jsapi/v1/apple-pay-sdk.js https://payments.worldpay.com/resources/cse/js/worldpay-cse-1.0.2.min.js https://payments.worldpay.com/resources/hpp/integrations/embedded/js/hpp-embedded-integration-library.js https://d35p4vvdul393k.cloudfront.net/sdk_library/us/stg/ops/pc_gsmpi_web_sdk.js https://d16i99j5zwwv51.cloudfront.net/sdk_library/us/prd/ops/pc_gsmpi_web_sdk.js *.yotpo.com *.sdiapi.com www.xtento.com cdn.xtento.com *.googleapis.com storage.googleapis.com consent.trustarc.com js-agent.newrelic.com bam.nr-data.net tags.tiqcdn.com www.res-x.com *.googletagmanager.com unsafe-inline t.contentsquare.net app.contentsquare.com payments.worldpay.com *.pcapredict.com services.postcodeanywhere.co.uk www.google.com *.contentsquare.net *.truste.com sp.analytics.yahoo.com s.yimg.com js-tag.zemanta.com *.google.com *.google.ad *.google.ae *.google.com.af *.google.com.ag *.google.com.ai *.google.al *.google.am *.google.co.ao *.google.com.ar *.google.as *.google.at *.google.com.au *.google.az *.google.ba *.google.com.bd *.google.be *.google.bf *.google.bg *.google.com.bh *.google.bi *.google.bj *.google.com.bn *.google.com.bo *.google.com.br *.google.bs *.google.bt *.google.co.bw *.google.by *.google.com.bz *.google.ca *.google.cd *.google.cf *.google.cg *.google.ch *.google.ci *.google.co.ck *.google.cl *.google.cm *.google.cn *.google.com.co *.google.co.cr *.google.com.cu *.google.cv *.google.com.cy *.google.cz *.google.de *.google.dj *.google.dk *.google.dm *.google.com.do *.google.dz *.google.com.ec *.google.ee *.google.com.eg *.google.es *.google.com.et *.google.fi *.google.com.fj *.google.fm *.google.fr *.google.ga *.google.ge *.google.gg *.google.com.gh *.google.com.gi *.google.gl *.google.gm *.google.gr *.google.com.gt *.google.gy *.google.com.hk *.google.hn *.google.hr *.google.ht *.google.hu *.google.co.id *.google.ie *.google.co.il *.google.im *.google.co.in *.google.iq *.google.is *.google.it *.google.je *.google.com.jm *.google.jo *.google.co.jp *.google.co.ke *.google.com.kh *.google.ki *.google.kg *.google.co.kr *.google.com.kw *.google.kz *.google.la *.google.com.lb *.google.li *.google.lk *.google.co.ls *.google.lt *.google.lu *.google.lv *.google.com.ly *.google.co.ma *.google.md *.google.me *.google.mg *.google.mk *.google.ml *.google.com.mm *.google.mn *.google.ms *.google.com.mt *.google.mu *.google.mv *.google.mw *.google.com.mx *.google.com.my *.google.co.mz *.google.com.na *.google.com.ng *.google.com.ni *.google.ne *.google.nl *.google.no *.google.com.np *.google.nr *.google.nu *.google.co.nz *.google.com.om *.google.com.pa *.google.com.pe *.google.com.pg *.google.com.ph *.google.com.pk *.google.pl *.google.pn *.google.com.pr *.google.ps *.google.pt *.google.com.py *.google.com.qa *.google.ro *.google.ru *.google.rw *.google.com.sa *.google.com.sb *.google.sc *.google.se *.google.com.sg *.google.sh *.google.si *.google.sk *.google.com.sl *.google.sn *.google.so *.google.sm *.google.sr *.google.st *.google.com.sv *.google.td *.google.tg *.google.co.th *.google.com.tj *.google.tl *.google.tm *.google.tn *.google.to *.google.com.tr *.google.tt *.google.com.tw *.google.co.tz *.google.com.ua *.google.co.ug *.google.co.uk *.google.com.uy *.google.co.uz *.google.com.vc *.google.co.ve *.google.vg *.google.co.vi *.google.com.vn *.google.vu *.google.ws *.google.rs *.google.co.za *.google.co.zm *.google.co.zw *.google.cat region1.google-analytics.com bat.bing.com r.bing.com *.dwin1.com *.awin1.com *.zenaps.com *.sciencebehindecommerce.com *.optimizely.com optimizely.s3.amazonaws.com cdn-assets-prod.s3.amazonaws.com strict-dynamic *.confirmit.com *.creativecdn.com *.tealiumiq.com *.facebook.com *.facebook.net *.noibu.com wss://*.noibu.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com webchat.dotdigital.com webchat.staging.dotdigital.com *.dycdn.net cdnjs.cloudflare.com https://fonts.googleapis.com/css *.yotpo.com *.googleapis.com payments.worldpay.com services.postcodeanywhere.co.uk *.bing.com *.dwin1.com *.awin1.com unsafe-inline 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com *.dycdn.net *.freshrelevance.com wss://am.freshrelevance.com wss://am.dycdn.net dn1i8v75r669j.cloudfront.net *.dotdigital.com *.hub-box.com https://www.google.com/pay https://pay.google.com/gp/p/web_manifest.json https://pay.google.com/gp/p/payment_method_manifest.json https://pay.google.com/ https://google.com/pay *.worldpay.com https://hpp.worldpay.com/app/hpp/135-0/telemetry https://hpp.worldpay.com/app/hpp/135-0/payment/paypalsmartbutton/continue https://payments.worldpay.com/app/hpp/135-0/telemetry/iframe *.yotpo.com *.sdiapi.com *.googleapis.com stats.g.doubleclick.net bam.nr-data.net *.contentsquare.net media.screwfix.fr *.postcodeanywhere.co.uk sp.analytics.yahoo.com s.yimg.com *.bing.com wss://*.bing.com region1.google-analytics.com *.analytics.google.com *.sciencebehindecommerce.com *.google.com *.google.co.uk *.optimizely.com *.creativecdn.com *.confirmit.com *.tealiumiq.com *.facebook.com *.facebook.net *.noibu.com wss://*.noibu.com 'self' 'unsafe-inline'; child-src blob: http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://e90dc890-c7f3-4322-adbb-3a37b4df98b3.sansec.watch/; report-to report-endpoint; 1 font-src https://cdn.checkout.com use.fontawesome.com maxcdn.bootstrapcdn.com fonts.gstatic.com *.cloudflare.com *.twitter.com *.gstatic.com *.typekit.net *.twimg.com *.trustedshops.com *.googleapis.com *.google.com *.youtube.com maps.googleapis.com scontent.cdninstagram.com cdn.lightwidget.com lightwidget.com cdn.beautyamora.com cdn.beautyamora.com.au cdn.beautyamora.co.uk data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com yotpo.com *.yotpo.com swellrewards.com *.swellrewards.com *.twitter.com *.google.com *.youtube.com maps.googleapis.com scontent.cdninstagram.com cdn.lightwidget.com lightwidget.com *.cardinalcommerce.com *.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com https://js.checkout.com *.klarna.com yotpo.com *.yotpo.com swellrewards.com *.swellrewards.com *.twitter.com *.google.com maps.googleapis.com scontent.cdninstagram.com cdn.lightwidget.com lightwidget.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net data: www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com validator.swagger.io yotpo.com *.yotpo.com swellrewards.com *.swellrewards.com *.cloudflare.com *.klarna.com *.googleadservices.com *.google-analytics.com *.paypal.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.google.com *.youtube.com maps.googleapis.com scontent.cdninstagram.com cdn.lightwidget.com lightwidget.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com cdn.beautyamora.com cdn.beautyamora.com.au g-image.beautyamora.com cdn.beautyamora.co.uk *.google.com.hk *.pinterest.com c.clarity.ms c.bing.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.googletagmanager.com https://cdn.checkout.com *.klarnacdn.net yotpo.com *.yotpo.com swellrewards.com *.swellrewards.com *.cloudflare.com *.twitter.com *.google-analytics.com *.twimg.com *.gstatic.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.google.com *.youtube.com maps.googleapis.com scontent.cdninstagram.com cdn.lightwidget.com lightwidget.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com cdn.beautyamora.com cdn.beautyamora.com.au cdn.beautyamora.co.uk *.helpscout.net *.g.doubleclick.net *.pinimg.com *.pinterest.com *.clarity.ms 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://cdn.checkout.com yotpo.com *.yotpo.com swellrewards.com *.swellrewards.com fonts.googleapis.com maxcdn.bootstrapcdn.com *.cloudflare.com *.googleapis.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.google.com *.youtube.com maps.googleapis.com scontent.cdninstagram.com cdn.lightwidget.com lightwidget.com unsafe-inline cdn.beautyamora.com cdn.beautyamora.com.au cdn.beautyamora.co.uk 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://js.checkout.com *.klarnaevt.com yotpo.com *.yotpo.com swellrewards.com *.swellrewards.com *.cloudflare.com *.twitter.com *.paypal.com *.twimg.com *.google.com *.youtube.com maps.googleapis.com scontent.cdninstagram.com cdn.lightwidget.com lightwidget.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com cdn.beautyamora.com cdn.beautyamora.com.au cdn.beautyamora.co.uk *.g.doubleclick.net *.clarity.ms 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 report-uri /_csp/report-uri; report-to csp-endpoint; default-src 'self'; script-src 'report-sample' 'unsafe-inline' vk.com *.yandex.ru *.yandex.net *.carrotquest.app *.amocrm.ru 'nonce-MQy0aJcdIn3ewZjSgjDNPxsbDZGXYrwn'; style-src 'report-sample' 'self' 'unsafe-inline' 'nonce-MQy0aJcdIn3ewZjSgjDNPxsbDZGXYrwn'; connect-src wss://rts-v2.carrotquest.app *.amocrm.ru; object-src 'none'; worker-src 'none'; base-uri 'none'; block-all-mixed-content; require-trusted-types-for 'script' 1 default-src 'self' solutionreach.okta.com login.solutionreach.com *.oktacdn.com; connect-src 'self' solutionreach.okta.com solutionreach-admin.okta.com login.solutionreach.com *.oktacdn.com *.mixpanel.com *.mapbox.com solutionreach.kerberos.okta.com solutionreach.mtls.okta.com https://oinmanager.okta.com data:; script-src 'unsafe-inline' 'unsafe-eval' 'self' 'report-sample' solutionreach.okta.com login.solutionreach.com *.oktacdn.com; style-src 'unsafe-inline' 'self' 'report-sample' solutionreach.okta.com login.solutionreach.com *.oktacdn.com; frame-src 'self' solutionreach.okta.com solutionreach-admin.okta.com login.solutionreach.com login.okta.com; img-src 'self' solutionreach.okta.com login.solutionreach.com *.oktacdn.com *.tiles.mapbox.com *.mapbox.com data: blob:; font-src 'self' solutionreach.okta.com login.solutionreach.com data: *.oktacdn.com fonts.gstatic.com; frame-ancestors 'self' 1 default-src 'self'; script-src 'report-sample' 'self' https://cdnjs.cloudflare.com/ajax/libs/lottie-web/5.8.1/lottie.min.js https://www.google-analytics.com/analytics.js https://www.googletagmanager.com/gtag/js https://player.vimeo.com/api/player.js 'sha256-FSevH+aW1elUrWYqKfiu3xdrYlsrq1pzbI5VpKisyLM='; style-src 'report-sample' 'self' https://fonts.googleapis.com 'sha256-47DEQpj8HBSa+/TImW+5JCeuQeRkm5NMpJWZG3hSuFU='; object-src 'none'; base-uri 'self'; connect-src 'self' https://analytics.google.com https://www.google-analytics.com https://o969560.ingest.sentry.io https://stats.g.doubleclick.net; font-src 'self' data: https://fonts.gstatic.com; frame-src 'self' https://player.vimeo.com; img-src https: data:; manifest-src 'self'; media-src 'self' https://assts.stories.sc https://player.vimeo.com https://*.vimeocdn.com; report-uri https://o969560.ingest.sentry.io/api/5920728/security/?sentry_key=e6ced77cc723478fad969f5f3ba00b06 worker-src 'none'; 1 object-src 'none';base-uri 'self';script-src 'nonce-tVq2CZg4LJlisFhFVpwe_g' 'strict-dynamic' 'report-sample' 'unsafe-eval' 'unsafe-inline' https: http:;report-uri https://csp.withgoogle.com/csp/gws/other-hp 1 object-src 'none'; connect-src 'self' *.adulttime.xxx *.adulttime.com cognito-identity.us-east-1.amazonaws.com backend.getbeamer.com *.comm100.io *.algolia.net insights.algolia.io *.algolianet.com *.gammaapis.com *.gammacdn.com analytics.google.com *.google-analytics.com adservice.google.com *.analytics.google.com *.doubleclick.net *.pubnub.com *.lovense.com *.handyfeeling.com www.gammaentertainment.com *.tiypa.com *.recombee.us dasasoveekepl.cloudfront.net capture.trackjs.com ws: jlduihq7lrcdxgw4vrndhdfcsq.appsync-api.us-east-1.amazonaws.com tcs4u525zrg5hnnoe5kzndxuaq.appsync-api.us-east-1.amazonaws.com xtnzefcqrb.execute-api.us-east-1.amazonaws.com 2aed6ghjsb4436qtebuqk3gfzq0xeauy.lambda-url.us-east-1.on.aws lzzos7clo5.execute-api.us-east-1.amazonaws.com *.izooto.com www.idealgasm.com 3tt0xhv5u7.execute-api.us-east-1.amazonaws.com; form-action 'self' *.adulttime.xxx *.adulttime.com join.gammasecure.com; script-src 'self' *.adulttime.xxx *.adulttime.com app.getbeamer.com static.getbeamer.com blob: vue.comm100.com standby.comm100vue.com *.gammacdn.com www.google-analytics.com www.googletagmanager.com www.gstatic.com www.google.com code.jquery.com d3a3ewgd1iewwz.cloudfront.net cdn.izooto.com 'unsafe-eval' 'unsafe-inline'; frame-src 'self' *.adulttime.xxx *.adulttime.com push.getbeamer.com app.getbeamer.com www.google.com *.doubleclick.net cdn.izooto.com *.banhq.com; report-uri https://csp-report.browser-intake-datadoghq.com/api/v2/logs?dd-api-key=pub787d5a6164b329b26f2e4f7956bbed10&dd-evp-origin=content-security-policy&ddsource=csp-prod&ddtags=CSP-Prod; 1 connect-src fanatics.live *.fanatics.live stream-io-api.com *.stream-io-api.com 'self' wss: https://os.fanatics.live https://*.fanatics.live *.live-video.net https://websdk.appsflyer.com https://sdk.split.io https://streaming.split.io https://auth.split.io https://events.split.io https://sdk.iad-05.braze.com https://cdn.segment.com https://api.segment.io https://www.googletagmanager.com https://connect.facebook.net https://*.google-analytics.com https://td.doubleclick.net/ https://browser-intake-datadoghq.com https://*.browser-intake-datadoghq.com https://us1.browser-intake-datadoghq.com https://us3.browser-intake-datadoghq.com https://us5.browser-intake-datadoghq.com https://datadoghq.com https://*.datadoghq.com https://*.livekit.cloud https://*.cloudfront.net https://*.amazonaws.com/web-prod-assets-0l9t/ https://*.amazonaws.com/web-staging-assets-0l9t/ https://*.amazonaws.com/fl-application-assets/ https://*.amazonaws.com/fl-application-asset/ https://d2wpy28tlhnoxg.cloudfront.net/media_convert https://google.com https://www.google.com/ccm/collect https://*.appsflyer.com https://fanatics.live/api/auth/session https://*.algolia.net https://*.algolianet.com https://*.algolia.io https://ekr.zdassets.com https://fanaticslive.zendesk.com https://unpkg.com https://cdn.jsdelivr.net https://cdn.cookielaw.org/ https://*.onetrust.com https://*.rive.app fonts.googleapis.com *.fonts.googleapis.com marker.io *.marker.io sentry.io *.sentry.io fullstory.com *.fullstory.com stripe.com *.stripe.com tiktok.com *.tiktok.com https://chat-insights.getstream.io; default-src fanatics.live *.fanatics.live fonts.googleapis.com *.fonts.googleapis.com fullstory.com *.fullstory.com google-analytics.com *.google-analytics.com googletagmanager.com *.googletagmanager.com zdassets.com *.zdassets.com stripe.com *.stripe.com stream-io-api.com *.stream-io-api.com sentry.io *.sentry.io marker.io *.marker.io live-video.net *.live-video.net 'self' https://cdn.jsdelivr.net 'unsafe-inline'; font-src https://fonts.gstatic.com/* https://fonts.gstatic.com fanatics.live *.fanatics.live jsdelivr.net *.jsdelivr.net https://cdn.jsdelivr.net; frame-src 'self' https://js.stripe.com/ https://td.doubleclick.net https://www.google.com/ https://odyssey.dev.fanatics.live/ https://odyssey.staging.fanatics.live/ https://odyssey.fanatics.live/ https://www.googletagmanager.com https://use.fontawesome.com https://fonts.googleapis.com https://cdn.appsflyer.com/; frame-ancestors https://docs.fanatics.live https://topps.com https://*.topps.com/ https://*.vercel.app/ https://*.dacwdev.com/ https://*.dacardworld.com/ https://*.wweshop.com/ https://*.wweshop.com https://shop.wwe.com https://*.wwe.com https://ufcstore.com https://*.ufcstore.com https://ufc.com https://*.ufc.com; img-src * blob: 'self' data:; media-src * blob:; script-src 'self' 'sha256-6EL/zz29Q8UFwqahdj1cGAxqbH5Xd+he4QVXaoQno44=' https://cdn.segment.com https://js.stripe.com https://js.appboycdn.com https://sdk.iad-05.braze.com https://www.googletagmanager.com https://connect.facebook.net https://www.google.com/recaptcha/ https://*.datadoghq-browser-agent.com https://static.zdassets.com https://pod-29.zendesk.com https://*.fullstory.com https://cdn.cookielaw.org/ https://*.onetrust.com https://analytics.tiktok.com 'unsafe-eval' marker.io *.marker.io live-video.net *.live-video.net fanatics.live *.fanatics.live 'unsafe-inline'; worker-src 'self' blob: https://*.datadoghq.com https://*.datadoghq-browser-agent.com; report-uri https://csp-reporting.cloudflare.com/cdn-cgi/script_monitor/report?m=WQgHV9O6jalKBe_aC0av2I6PsuEPT_9EglgI2dVFh.g-1770435312-1.0.1.1-C8Hsqw6Oo_6WDUKJN.EI60ZsdNEcZoSAfQ8ZcTq21os2lQRAdbp13VoNC0IeT1hQqNPcpzMjcpQinZ81wBFCV.r9S5AXeIC6WngVK0nQriIXFK4QhyIlO.ijrsKwuHjMrbhaRvPQz7IexFn8tZGthE7TCI0z7wCpS9ydmNfFxICH8Ryx_FS5ls6ohiMXdMsoaGtN6c0yKZ_VavdVKG.47Q; report-to cf-xlbcvracumhnijip 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com https://use.typekit.net https://www.gstatic.com https://fonts.gstatic.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action *.paypal.com *.facebook.com *.googlesyndication.com *.tiktok.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com https://*.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com *.dotdigital-pages.com *.dotdigital.com https://www.facebook.com https://tpc.googlesyndication.com https://consentcdn.cookiebot.com https://assets.braintreegateway.com https://*.paypal.com https://interfaces.zapier.com https://*.zapier.app https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net 'self' data: https://*.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.googlesyndication.com *.roeye.com *.tiktok.com *.trackedlink.net *.ddlnk.net https://www.google.fi https://maps.gstatic.com https://maps.googleapis.com https://log.pinterest.com https://eckerolinechatbottest.blob.core.windows.net https://fonts.gstatic.com https://assets.braintreegateway.com https://*.paypal.com https://imgsct.cookiebot.com https://px.ads.linkedin.com https://*.gstatic.com https://*.googleapis.com https://*.googleusercontent.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com commerce-payments-sdk.adobe.io s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://rum.hlx.page https://*.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com *.jsdelivr.net *.tiktok.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal https://ajax.cloudflare.com https://js-agent.newrelic.com https://bam-cell.nr-data.net https://bam.eu01.nr-data.net https://bam.nr-data.net https://assets.pinterest.com https://maps.googleapis.com https://eckerolinechatbottest.blob.core.windows.net https://api.videoly.co https://www.google.fi https://www.googleadservices.com https://tpc.googlesyndication.com https://consent.cookiebot.com https://consentcdn.cookiebot.com https://js.braintreegateway.com https://assets.braintreegateway.com https://www.paypalobjects.com https://*.paypal.com https://snap.licdn.com https://interfaces.zapier.com https://dapi.videoly.co https://*.gstatic.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com https://www.eckeroline.fi 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com *.tiktok.com https://fast.fonts.net https://eckerolinechatbottest.blob.core.windows.net https://use.typekit.net https://p.typekit.net https://assets.braintreegateway.com https://fonts.googleapis.com https://hcaptcha.com https://*.hcaptcha.com maxcdn.bootstrapcdn.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.facebook.com *.facebook.net https://*.google.com *.doubleclick.net *.googlesyndication.com *.tiktok.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com https://bam-cell.nr-data.net https://bam.eu01.nr-data.net https://bam.nr-data.net https://stats.g.doubleclick.net https://googleads.g.doubleclick.net https://maps.googleapis.com https://fonts.gstatic.com https://vimeo.com https://consentcdn.cookiebot.com https://api.sandbox.braintreegateway.com https://client-analytics.sandbox.braintreegateway.com https://*.braintree-api.com https://api.braintreegateway.com https://client-analytics.braintreegateway.com https://*.paypal.com https://px.ads.linkedin.com https://ipinfo.io https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com 'self' 'unsafe-inline'; child-src https://assets.braintreegateway.com https://*.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src *.fontawesome.com maxcdn.bootstrapcdn.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com https://seo.mageplaza.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ maps.googleapis.com chart.googleapis.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io flagpedia.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ maps.googleapis.com chart.googleapis.com *.gstatic.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.fontawesome.com maxcdn.bootstrapcdn.com *.gstatic.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src maps.googleapis.com chart.googleapis.com 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com maps.googleapis.com chart.googleapis.com www.gstatic.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 object-src 'none'; script-src 'self' cdnjs.cloudflare.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com https://www.recaptcha.net unpkg.com; style-src 'self' cdnjs.cloudflare.com fonts.googleapis.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com unpkg.com; worker-src 'self'; base-uri 'self'; form-action 'self'; frame-ancestors 'self' 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com cdn.jsdelivr.net cdn.almapay.com *.googleapis.com *.mauboussin.fr data: * *.fontawesome.com maxcdn.bootstrapcdn.com applepay.cdn-apple.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.adyen.com *.google.com *.mauboussin.fr * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.adyen.com *.getalma.eu *.gstatic.com *.mauboussin.fr * www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com https://www.googletagmanager.com/ api-qa.payplug.com secure-qa.payplug.com *.payplug.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io *.paypal.com *.typekit.net *.gstatic.com *.adyen.com *.googleapis.com *.mauboussin.fr * www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ https://secure-magenta.dalenys.com maps.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.adyen.com cdn.jsdelivr.net *.googleapis.com *.gstatic.com *.mauboussin.fr * www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ applepay.cdn-apple.com api-qa.payplug.com cdn-qa.payplug.com https://cdn-qa.payplug.com https://secure-magenta.dalenys.com maps.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com cdn.jsdelivr.net *.googleapis.com/ *.mauboussin.fr * *.fontawesome.com maxcdn.bootstrapcdn.com https://secure-magenta.dalenys.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.adyen.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io *.getalma.eu *.googleapis.com *.mauboussin.fr * www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ maps.googleapis.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.gstatic.com *.mauboussin.fr *.criteo.net *.pinterest.com *.googletagmanager.com *.snapppt.com *.360yield.com * 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' https: data: blob; script-src 'self' https: 'unsafe-inline'; style-src 'self' https: 'unsafe-inline'; img-src 'self' https: data: blob; font-src 'self' https: data:; connect-src 'self' https:; frame-ancestors 'self'; frame-src https:; object-src 'none'; base-uri 'self'; form-action 'self' https:; upgrade-insecure-requests 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com *.klevu.com *.ksearchnet.com *.fontawesome.com *.cloudflare.com *.bootstrapcdn.com *.twitter.com nitropack.io *.nitrocdn.com *.cakebox.com fonts.googleapis.com cdn.jsdelivr.net *.klaviyo.com cdnjs.cloudflare.com *.cdn-apple.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com consentcdn.cookiebot.com consentcdn.cookiebot.eu *.addthis.com *.trustpilot.com *.twitter.com *.vimeo.com *.doubleclick.net nitropack.io *.weltpixel.com *.adobedtm.com widget.trustpilot.com vars.hotjar.com app.involve.me ssl.kaptcha.com *.onetrust.com js.ryft.com embedded.ryftpay.com *.googleapis.com *.gstatic.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.googleapis.com *.cookiebot.com imgsct.cookiebot.eu https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com magefan.com cm.magefan.com *.disqus.com https://img.youtube.com *.cloudflare.com *.twitter.com *.contentsquare.net nitropack.io *.nitrocdn.com *.adobedtm.com s.ytimg.com services.postcodeanywhere.co.uk bat.bing.com *.facebook.com *.google.co.in lantern.roeye.com static-tracking.klaviyo.com *.cloudfront.net *.cakebox.com *.cookiepro.com *.googletagmanager.com *.wepowerconnections.com *.zenaps.com ad.doubleclick.net cm.g.doubleclick.net *.google.com *.google.com.vn *.google.co.uk *.onetrust.com *.adroll.com x.bidswitch.net ml314.com pixel.tapad.com dsum-sec.casalemedia.com dsync.rlcdn.com pixel.rubiconproject.com *.openx.net sync.outbrain.com idsync.rlcdn.com *.pubmatic.com sync.taboola.com ib.adnxs.com eb2.3lift.com match.adsrvr.org *.stickyadstv.com *.sitescout.com *.springserve.com *.ipredictive.com *.turn.com *.mdhv.io dsp.360yield.com www.eggfreecake.co.uk *.usercentrics.eu https://www.ryft.com embedded.ryftpay.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com *.vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.googleapis.com *.gstatic.com *.cookiebot.com consent.cookiebot.eu https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ js.klevu.com *.ksearchnet.com *.disqus.com *.addthis.com *.cloudflare.com *.fontawesome.com *.google-analytics.com googletagmanager.com graph.facebook.com *.moatads.com *.trustpilot.com widgets.pinterest.com *.contentsquare.com *.contentsquare.net cdn.tailwindcss.com cdn.jsdelivr.net https://www.googletagmanager.com tagmanager.google.com *.adobedtm.com *.cardinalcommerce.com unpkg.com *.braintreegateway.com *.paypal.com *.livechatinc.com *.pcapredict.com storage.googleapis.com maps.google.com services.postcodeanywhere.co.uk bat.bing.com *.hotjar.com s.pinimg.com c3.adalyser.com connect.facebook.net rum-static.pingdom.net ct.pinterest.com lantern.roeyecdn.com *.soakandsleep.com cdn.bronto.com dynamic.criteo.com *.apptrian.com *.dwin1.com paperplaneslive.com *.cloudfront.net *.cookiepro.com *.googletagmanager.com stats.g.doubleclick.net *.amplitude.com *.sovendus.com *.zenaps.com www.google.com *.involve.me *.onetrust.com *.adroll.com www.subconvertize.com js-agent.newrelic.com *.googlesyndication.com *.config-security.com *.triplewhale.com *.cookiebot.eu *.ryftpay.com https://embedded.ryftpay.com/v2/ryft.min.js 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://static.klaviyo.com *.klevu.com *.ksearchnet.com *.fontawesome.com *.cloudflare.com *.googleapis.com *.gstatic.com *.twitter.com cdn.tailwindcss.com nitropack.io cdnjs.cloudflare.com *.nitrocdn.com cdn.jsdelivr.net *.trustpilot.com tagmanager.google.com static-tracking.klaviyo.com *.soakandsleep.com services.postcodeanywhere.co.uk www.google.com *.typekit.net *.cdn-apple.com https://statsjs.klevu.com https://js.klevu.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.googleapis.com consentcdn.cookiebot.com consentcdn.cookiebot.eu consent.cookiebot.com consent.cookiebot.eu https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com *.ksearchnet.com *.cloudflare.com *.twitter.com *.contentsquare.net *.nitrocdn.com nitropack.io https://www.google-analytics.com *.adobedtm.com *.adobe.com *.braintreegateway.com *.gstatic.com *.telemetry-dev.adobe.io services.postcodeanywhere.co.uk ct.pinterest.com rum-collector-2.pingdom.net api.livechatinc.com paperplaneslive.com *.cloudfront.net *.trustpilot.com api2.amplitude.com *.googletagmanager.com *.onetrust.com invitejs.trustpilot.com *.sovendus.com *.cookiepro.com *.bing.com www.google.com stats.g.doubleclick.net *.involve.me *.adroll.com bam.nr-data.net *.hotjar.* wss://ws.hotjar.com content.hotjar.io *.config-security.com *.ryftpay.com https://embedded.ryftpay.com/v2/ryft.min.js.map embedded.ryftpay.com smp-paymentservices.apple.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com a.omappapi.com *.fontawesome.com *.alothemes.com *.magepow.com *.google.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://seo.mageplaza.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.pagar.me *.netsgroup.com *.sibs.pt *.seglan.com *.secureacs.com *.rsa3dsauth.com *.apata.io *.cardinalcommerce.com *.santander.com.br *.bradesco.com.br *.bradesco *.stone.com.br *.nubank.com.br *.itau.com.br *.bb.com.br *.caixa.gov.br *.inter.co *.bancointer.com.br *.c6bank.com.br *.bancobmg.com.br *.safra.com.br *.sicoob.com.br *.banrisul.com.br *.banrisul.b.br *.banorte.com *.xpi.com.br *.btgpactual.com *.btgpactualdigital.com *.picpay.com *.amedigital.com *.neon.tech *.neon.com.br *.wise.com *.revolut.com *.sandbox.3dsecure.io *.google.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com www.google.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com event.getblue.io static.omni.chat *.criteo.com static.criteo.net td.doubleclick.net *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com js.mollie.com *.pagar.me *.netsgroup.com *.sibs.pt *.seglan.com *.secureacs.com *.rsa3dsauth.com *.apata.io *.cardinalcommerce.com *.santander.com.br *.bradesco.com.br *.bradesco *.stone.com.br *.nubank.com.br *.itau.com.br *.bb.com.br *.caixa.gov.br *.inter.co *.bancointer.com.br *.c6bank.com.br *.bancobmg.com.br *.safra.com.br *.sicoob.com.br *.banrisul.com.br *.banrisul.b.br *.banorte.com *.xpi.com.br *.btgpactual.com *.btgpactualdigital.com *.picpay.com *.amedigital.com *.neon.tech *.neon.com.br *.wise.com *.revolut.com *.sandbox.3dsecure.io c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com * *.googletagmanager.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net https://images.unsplash.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com www.oceandrop.com.br c.clarity.ms *.bing.com www.google.com.br cm.g.doubleclick.net collect.vendavalida.com.br *.criteo.com *.omappapi.com a.mgid.com *.alothemes.com *.magepow.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com https://www.mollie.com cdn.mundipagg.com api.pagar.me www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.googletagmanager.com *.google-analytics.com ssl.gstatic.com www.gstatic.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net amcglobal.sc.omtrdc.net *.adobe.io use.typekit.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.magento-ds.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.magento-datasolutions.com https://rum.hlx.page www.google.com/recaptcha/ www.gstatic.com/recaptcha/ https://maps.googleapis.com https://player.vimeo.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com event.getblue.io widget.getblue.io static.omni.chat a.omappapi.com oceandrop-br.mais.social js-agent.newrelic.com www.clarity.ms *.hotjar.com bat.bing.com www.googleoptimize.com collect.vendavalida.com.br *.criteo.com secure.afilio.com.br a.mgid.com *.ubembed.com rum.hlx.page widget.freshworks.com m2epro.freshdesk.com *.alothemes.com *.magepow.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com js.mollie.com 3ds2.pagar.me 3ds2-sdx.pagar.me js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com oceandrop-br.mais.social a.omappapi.com widget.freshworks.com m2epro.freshdesk.com *.fontawesome.com *.alothemes.com *.magepow.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.googleapis.com *.google.com assets.braintreegateway.com tagmanager.google.com fonts.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.magento-datasolutions.com *.magento-ds.com https://maps.googleapis.com https://player.vimeo.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com oceandrop-br.mais.social omnichat-web-chat.omni.chat webchat-adapter.omni.chat *.omappapi.com *.clarity.ms bam.nr-data.net ws.hotjar.com *.hotjar.io *.criteo.com stats.g.doubleclick.net collect.vendavalida.com.br bat.bing.com widget.freshworks.com m2epro.freshdesk.com *.alothemes.com *.magepow.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com api.mundipagg.com api.pagar.me brasilapi.com.br viacep.com.br servicodados.ibge.gov.br pay.sandbox.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' *.doubleclick.net get.geojs.io sgtm.adagio-city.com; child-src 'self' blob:; connect-src 'self' cdn.cookielaw.org maps.googleapis.com *.googletagmanager.com *.cedexis.com *.google-analytics.com *.contentsquare.net connect.facebook.net *.tradelab.fr ib.adnxs.com *.googleadservices.com ad.avtm.fr *.google.com.ua *.cardinalcommerce.com *.online-metrix.net *.fastlylb.net *.facebook.com *.execute-api.us-east-1.amazonaws.com *.google.nl *.metaffiliation.com *.wonderpush.com *.analytics.google.com googleads.g.doubleclick.net *.cedexis-radar.net *.google.com *.doubleclick.net ipinfo.io *.gstatic.com a-cedexis.msedge.net *.onetrust.com *.fastlyb.net swrap.tradedoubler.com sgtm.adagio-city.com *.pinterest.com s.pinimg.com get.geojs.io analytics.tiktok.com *.nr-data.net *.us-east-1.amazonaws.com *.kontorolabs.com *.sojern.com bat.bing.net bat.bing.com *.ip-api.com https://www.google-analytics.com https://www.googletagmanager.com; font-src *; frame-src 'self' *.cedexis-test.com *.doubleclick.net static.addtoany.com *.google.com *.youtube.com my.matterport.com *.citrix-itm-test.com *.facebook.com *.fbcdn.net *.citm-test.com *.cardinalcommerce.com *.online-metrix.net cedexis-test.gcorelabs.com *.contentsquare.net csxd.all.accor.com csxd.mag-adagio.com ct.pinterest.com s.pinimg.com *.adagio-city.com *.googletagmanager.com sgtm.adagio-city.com *.itm.cloud.com *.by.wonderpush.com data: blob:; img-src * data:; media-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' 'wasm-unsafe-eval' adagio.nonce cdn.cookielaw.org maps.googleapis.com *.googletagmanager.com *.cedexis.com *.google-analytics.com ssl.google-analytics.com *.contentsquare.net connect.facebook.net *.tradelab.fr ib.adnxs.com *.googleadservices.com googleads.g.doubleclick.net *.cedexis-radar.net *.google.com *.doubleclick.net ipinfo.io *.gstatic.com a-cedexis.msedge.net *.onetrust.com *.fastlyb.net swrap.tradedoubler.com ad.avtm.fr *.google.com.ua *.google.de *.cardinalcommerce.com *.elitrack.com *.metaffiliation.com *.wonderpush.com ct.pinterest.com s.pinimg.com *.sojern.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://github.com https://static.addtoany.com https://try.abtasty.com https://www.google.com staticaws.fbwebprogram.com; script-src-attr 'self' 'unsafe-hashes' 'unsafe-inline'; script-src-elem 'self' 'unsafe-inline' cdn.cookielaw.org maps.googleapis.com *.googletagmanager.com *.cedexis.com *.google-analytics.com *.contentsquare.net connect.facebook.net *.tradelab.fr ib.adnxs.com *.googleadservices.com googleads.g.doubleclick.net *.cedexis-radar.net *.google.com *.doubleclick.net ipinfo.io *.gstatic.com a-cedexis.msedge.net *.onetrust.com *.fastlyb.net swrap.tradedoubler.com ad.avtm.fr *.google.com.ua *.cardinalcommerce.com *.online-metrix.net *.elitrack.com *.metaffiliation.com *.wonderpush.com s.pinimg.com cdn.jsdelivr.net *.adagio-city.com analytics.tiktok.com ct.pinterest.com bat.bing.com *.sojern.com surveys-static-prd.survicate-cdn.com survey.survicate.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://github.com https://static.addtoany.com https://try.abtasty.com https://www.google.com staticaws.fbwebprogram.com; style-src 'self' 'unsafe-inline' fonts.googleapis.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com; style-src-attr 'self' 'unsafe-hashes' 'unsafe-inline'; style-src-elem * 'unsafe-inline'; frame-ancestors 'self' 1 require-trusted-types-for 'script'; report-uri https://csp.withgoogle.com/csp/uxe-owners-acl/passwords_google 1 font-src fonts.gstatic.com use.typekit.net https://*.gstatic.com *.pikolin.com/es *.pikolin.com/pt *.magentosite.cloud *.beds.es *.googleapis.com *.gstatic.com https://script.hotjar.com *.landbot.io cash-f.squarecdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.adyen.com *.pikolin.com/es *.pikolin.com/pt *.magentosite.cloud *.beds.es api.paycomet.com *.ogone.com *.v-psp.com https://www.facebook.com *.redsys.es * 'self' 'unsafe-inline'; frame-ancestors *.pikolin.com/es *.pikolin.com/pt *.magentosite.cloud *.beds.es *.adobe.com https://bid.g.doubleclick.net https://www.linkbux.com/ 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.demdex.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.adyen.com *.dotdigital-pages.com *.dotdigital.com *.awin1.com *.zenaps.com *.fls.doubleclick.net *.pikolin.com/es *.pikolin.com/pt *.magentosite.cloud *.beds.es www.google.com api.paycomet.com *.doubleclick.net pay.google.com service.force.com hal9000.redintelligence.net https://pikolinrecommend.botslovers.com https://*.soreto.com https://ams.creativecdn.com/ https://www.facebook.com/ https://www.awin1.com/ *.redsys.es https://www.googletagmanager.com * https://sandbox.sequracdn.com https://live.sequracdn.com https://sandbox.sequrapi.com https://live.sequrapi.com *.trustpilot.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net *.adyen.com https://*.gstatic.com *.trackedlink.net *.awin1.com *.zenaps.com *.wepowerconnections.com *.pikolin.com https://pikolin.com *.magentosite.cloud *.beds.es *.gstatic.com *.adotmob.com *.facebook.com *.facebook.net *.google.com *.google.es *.googleapis.com *.omtrdc.net https://*.g.doubleclick.net/ *.doubleclick.net https://*.googletagmanager.com *.google-analytics.com *.analytics.google.com *.media-amazon.com https://cdn.cookielaw.org https://cookie-cdn.cookiepro.com https://ade.googlesyndication.com https://lantern.roeyecdn.com https://lantern.roeye.com https://pikolinrecommend.botslovers.com https://*.tagmanager.google.com https://pikolin.botslovers.com https://cdn.botslovers.com https://t.teads.tv/ https://c.clarity.ms/ https://*.bing.com/ https://static.hotjar.com https://script.hotjar.com https://survey-images.hotjar.com https://rt.udmserve.net/ https://pixel.rubiconproject.com https://www.awin1.com/ https://eb2.3lift.com/ https://secure.adnxs.com/ https://ih.adscale.de/ https://sync.outbrain.com/ https://ssp-csync.smartadserver.com/ https://ads.stickyadstv.com https://ads.yieldmo.com/ https://api.soreto.com/ https://cdn.doofinder.com/ https://ib.adnxs.com/ eu1-doofinderuser.s3.amazonaws.com https://*.collect.igodigital.com * https://sandbox.sequracdn.com https://live.sequracdn.com https://sandbox.sequrapi.com https://live.sequrapi.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net assets.adobedtm.com *.adobe.io www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com *.magento-ds.com *.adyen.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal *.awin1.com *.dwin1.com *.zenaps.com *.wepowerconnections.com https://the.sciencebehindecommerce.com lantern.roeyecdn.com *.pikolin.com/es *.pikolin.com/pt *.magentosite.cloud *.beds.es www.google.com https://maps.googleapis.com *.gstatic.com *.zdassets.com js-agent.newrelic.com *.serving-sys.com *.facebook.net *.doubleclick.net *.zopim.com *.cstatic.weborama.fr https://cdn.cookielaw.org https://pikolin.botslovers.com.co https://pikolin.botslovers.com https://pikolinrecommend.botslovers.com https://cdn.landbot.io *.payments-amazon.com pay.google.com https://service.force.com https://cdn.doofinder.com *.clarity.ms *.hotjar.com https://www.dwin1.com https://www.wepowerconnections.com https://lantern.roeyecdn.com https://espadesa.my.salesforce.com/ https://*.googletagmanager.com https://*.tagmanager.google.com https://*.google-analytics.com https://www.googleadservices.com https://p.teads.tv/ https://*.soreto.com https://cdn.frizbit.com/ https://js.cookieless-data.com/ https://*.adform.net/ https://js.sddan.com/ https://tags.creativecdn.com/ https://*.bing.com https://www.awin1.com/ https://the.sciencebehindecommerce.com/ https://*.datnova.com/ https://static.lightning.force.com https://espadesa.secure.force.com https://d.la11-core1.sfdc-cehfhs.salesforceliveagent.com/ https://d.la2-c1-cdg.salesforceliveagent.com/ *.redsys.es https://sslwidget.criteo.com/ https://dynamic.criteo.com/ https://pikolin--presandbox.sandbox.my.site.com/ https://pikolin.my.site.com/ https://*.collect.igodigital.com *.paypal.com *.ratepay.com *.cash.app *.visa.com *.mastercard.com https://sandbox.sequracdn.com https://live.sequracdn.com https://sandbox.sequrapi.com https://live.sequrapi.com *.trustpilot.com https://assets.adobedtm.com https://510004498.collect.igodigital.com https://pikolin.my.site.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.magento-datasolutions.com *.magento-ds.com https://fonts.googleapis.com/ *.pikolin.com/es *.pikolin.com/pt *.magentosite.cloud *.beds.es *.googleapis.com service.force.com *.clarity.ms https://cdn.doofinder.com https://*.googletagmanager.com https://*.tagmanager.google.com https://static.hotjar.com https://script.hotjar.com https://cdn.frizbit.com/ https://espadesa.secure.force.com/ https://pikolin--presandbox.sandbox.my.site.com/ https://pikolin.my.site.com/ *.cash.app *.trustpilot.com 'self' 'unsafe-inline'; object-src *.pikolin.com/es *.pikolin.com/pt *.magentosite.cloud *.beds.es 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.pikolin.com https://pikolin.com *.magentosite.cloud *.beds.es *.zdassets.com 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.pikolin.com/es *.pikolin.com/pt *.magentosite.cloud *.beds.es 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.magento-datasolutions.com *.magento-ds.com *.adyen.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com *.wepowerconnections.com https://the.sciencebehindecommerce.com *.pikolin.com/es *.pikolin.com/pt pikolin.tt.omtrdc.net *.magentosite.cloud *.beds.es *.zdassets.com *.zendesk.com *.zopim.com wss://widget-mediator.zopim.com *.serving-sys.com *.google-analytics.com *.analytics.analytics.com *.analytics.google.com *.googletagmanager.com *.g.doubleclick.net *.demdex.net *.paypal.com *.doubleclick.net https://cdn.cookielaw.org https://cookie-cdn.cookiepro.com https://maps.googleapis.com https://google.com https://www.google.es https://www.google.com https://pagead2.googlesyndication.com pay.google.com https://payments-eu.amazon.com *.amazon.com eu1-layer.doofinder.com wss://eu1-layer.doofinder.com/ *.clarity.ms https://*.hotjar.io https://*.hotjar.com wss://*.hotjar.com https://pikolinrecommend.botslovers.com *.tt.omtrdc.net https://pikolin.botslovers.com https://cdn.botslovers.com/ https://www.facebook.com/ https://cm.teads.tv/ https://t.teads.tv/ https://www.wepowerconnections.com https://*.soreto.com https://*.frizbit.com/ https://ams.creativecdn.com/ https://the.sciencebehindecommerce.com/ https://geolocation.onetrust.com https://privacyportal.onetrust.com https://privacyportal-eu.onetrust.com https://*.bing.com/ https://espadesa.secure.force.com/ *.googleapis.com *.landbot.io * https://sandbox.sequracdn.com https://live.sequracdn.com https://sandbox.sequrapi.com https://live.sequrapi.com https://*.trustpilot.com/ 'self' 'unsafe-inline'; child-src *.awin1.com *.zenaps.com *.pikolin.com/es *.pikolin.com/pt *.magentosite.cloud *.beds.es https://*.soreto.com http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri *.pikolin.com/es *.pikolin.com/pt *.magentosite.cloud *.beds.es 'self' 'unsafe-inline'; report-uri https://pikolin.report-uri.com/r/d/csp/reportOnly; report-to report-endpoint; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.klevu.com *.ksearchnet.com *.cloudflare.com *.googleapis.com *.zopim.com *.tawk.to *.jsdelivr.net media.flixfacts.com 'unsafe-inline' data: data: 'self' 'unsafe-inline'; frame-ancestors *.hana.ondemand.com 'self'; img-src widgets.magentocommerce.com 'unsafe-inline' data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.paypal.com *.typekit.net *.gstatic.com *.klevu.com *.ksearchnet.com oppwa.com *.oppwa.com *.peachpayments.com *.eu-west-1.amazonaws.com *.cloudflare.com *.google.com *.google.lv *.google.co.za *.google.com.na *.google.na *.zopim.com *.nosto.com *.hotjar.com *.hotjar.io *.googletagmanager.com *.zopim.io *.sfdr.co sfdr.co *.tawk.to tawk.link *.tawk.link *.addthis.com *.jsdelivr.net *.facebook.com *.azurewebsites.net maps.googleapis.com app.mobicredwidget.co.za amcglobal.sc.omtrdc.net media.flixcar.com rt.flix360.com assets.secure.checkout.visa.com data: 'self' 'unsafe-inline'; script-src googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com s.ytimg.com www.googleapis.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://browser.sentry-cdn.com js.klevu.com *.ksearchnet.com landofcoder.com maps.googleapis.com chart.googleapis.com *.oppwa.com oppwa.com *.peachpayments.com *.zopim.com *.videoly.co sfdr.co *.cnetcontent.com *.cloudfront.net *.newrelic.com *.klevu.com *.google.lv *.google.co.za *.google.com.na *.google.na *.cloudflare.com *.cloudflareinsights.com *.nosto.com *.hotjar.com *.googletagmanager.com *.criteo.net *.criteo.com *.sfdr.co *.tawk.to *.tawk.link *.jsdelivr.net *.addthis.com *.addthisedge.com *.moatads.com *.mouseflow.com *.nr-data.net *.facebook.com *.what3words.com commerce.adobedtm.com magento-recs-sdk.adobe.net static.zdassets.com app.mobicredwidget.co.za www.gstatic.com connect.facebook.net bam.nr-data.net js.testfreaks.com media.flixfacts.com media.flixcar.com security-hub.vaimo.network 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com *.klevu.com *.ksearchnet.com oppwa.com *.oppwa.com *.peachpayments.com *.cloudflare.com *.googleapis.com *.jsdelivr.net www.gstatic.com media.flixcar.com 'unsafe-inline' data: 'self' 'unsafe-inline'; object-src landofcoder.com maps.googleapis.com chart.googleapis.com 'self' 'unsafe-inline'; media-src *.zdassets.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.adobe.io performance.typekit.net *.sentry.io www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://*.ingest.sentry.io *.klevu.com *.ksearchnet.com landofcoder.com maps.googleapis.com chart.googleapis.com oppwa.com *.oppwa.com *.peachpayments.com *.testfreaks.com *.nosto.com *.hotjar.io *.hotjar.com *.doubleclick.net *.zendesk.com *.tawk.to wss://*.tawk.to *.tawk.link *.addthis.com *.addthisedge.com *.nr-data.net *.what3words.com *.googleapis.com vsb111.tawk.to ekr.zdassets.com api.magento.com commerce.adobedc.net app.mobicredwidget.co.za wss://widget-mediator.zopim.com bam.nr-data.net *.googletagmanager.com security-hub.vaimo.network 'unsafe-eval' data: 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; form-action *.cognitoforms.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com https://secure.paygate.co.za/payweb3/process.trans oppwa.com *.oppwa.com peachpayments.com *.peachpayments.com *.facebook.com webchat.jdg.co.za *.jdg.co.za 'self' 'unsafe-inline'; frame-src *.cognitoforms.com *.peachpayments.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com player.vimeo.com https://www.google.com/recaptcha/ www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com *.braintreegateway.com *.paypal.com google.com *.google.com landofcoder.com maps.googleapis.com chart.googleapis.com oppwa.com *.oppwa.com peachpayments.com *.nosto.com *.issuu.com *.hotjar.com *.hotjar.io *.googletagmanager.com *.criteo.net *.criteo.com *.addthis.com *.facebook.com webchat.jdg.co.za *.jdg.co.za 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com *.kueskipay.com https://fonts.gstatic.com https://www.google.com https://www.gstatic.com *.googleapis.com maxcdn.bootstrapcdn.com *.cdnfonts.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.kueskipay.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com *.kueskipay.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.sandbox.paypal.com *.paypalobjects.com landofcoder.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.kueskipay.com *.google.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.mercadolivre.com.br *.mercadolibre.com.mx *.mercadolibre.com.ar gnc.com.mx *.gnc.com.mx *.mercadopago.com.mx *.google.com.mx *.bing.com *.clarity.ms https://cdn.aplazo.mx/ assets.instantsearchplus.com *.akamaized.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.sandbox.paypal.com *.paypalobjects.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net amcglobal.sc.omtrdc.net commerce.adobe.net use.typekit.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.magento-ds.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.magento-datasolutions.com *.acp-magento.appspot.com *.akamaized.net *.instantsearchplus.com *.fastsimon.com fastsimon-grid.akamaized.net cdnjs.cloudflare.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.kueskipay.com *.googletagmanager.com *.mxpnl.com *.googleapis.com *.gstatic.com *.fontawesome.com player.vimeo.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.getblue.io *.scarabresearch.com *.facebook.net *.appspot.com *.convertexperiments.com *.clarity.ms *.hotjar.com *.zdassets.com *.survicate.com *.recapture.io *.bing.com *.tiktok.com *.zendesk.com wss://widget-mediator.zopim.com/ https://api.aplazo.net https://posbifrost.aplazo.net https://api.aplazo.mx https://posbifrost.aplazo.mx js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.sandbox.paypal.com *.paypalobjects.com https://cdn.recapture.io landofcoder.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com *.fontawesome.com *.kueskipay.com *.googletagmanager.com *.mxpnl.com *.googleapis.com *.google.com *.gstatic.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com maxcdn.bootstrapcdn.com *.cdnfonts.com *.fastsimon.com assets.braintreegateway.com *.paypal.com *.sandbox.paypal.com *.paypalobjects.com 'self' 'unsafe-inline'; object-src landofcoder.com 'self' 'unsafe-inline'; media-src *.adobe.com *.zdassets.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io *.sentry.io *.paypal.com google.com *.google.com *.magento-datasolutions.com *.magento-ds.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.kueskipay.com *.doubleclick.net http://dpm.demdex.net https://www.google.com https://www.gstatic.com *.mercadopago.com *.mercadolivre.com *.mercadolibre.com *.mercadolibre.com.br https://mercadopago.com.br *.mercadopago.com.br *.mlstatic.com *.fastsimon.com *.scarabresearch.com *.zdassets.com *.zendesk.com *.zopim.com *.clarity.ms *.tiktok.com wss://widget-mediator.zopim.com/ *.hotjar.com *.googleapis.com https://api.aplazo.net https://posbifrost.aplazo.net https://api.aplazo.mx https://posbifrost.aplazo.mx api.instantsearchplus.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com *.sandbox.paypal.com *.paypalobjects.com https://app.recapture.io landofcoder.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 child-src 'self' bid.g.doubleclick.net *.bitexen.com www.google.com; connect-src 'self' *.bitexen.com firebase.googleapis.com firebaseinstallations.googleapis.com salesiq.zoho.com salesiq.zohopublic.com sdkapi.netmera.com stats.g.doubleclick.net www.google-analytics.com api.intotheblock.com desk.zoho.com vts.zohopublic.com www.tradingview.com app.adjust.com app.adjust.net.in app.adjust.world fonts.gstatic.com koinbulteni.com region1.google-analytics.com wasm.regulaforensics.com; font-src 'self' css.zohocdn.com fonts.gstatic.com css.zohocdn.com css.zohostatic.com; form-action 'self' *.bitexen.com; frame-ancestors 'self'; frame-src 'self' bid.g.doubleclick.net pixel.sitescout.com s.tradingview.com *.hcaptcha.com *.geetest.com *.bitexen.com www.google.com; img-src 'self' data: *.bitexen.com pixel.sitescout.com salesiq.zohopublic.com sdkapi.netmera.com www.facebook.com www.google.com www.google.com.tr accounts.zoho.com googleads.g.doubleclick.net koinbulteni.com s3.eu-west-1.amazonaws.com ssl.google-analytics.com web.facebook.com www.google-analytics.com region1.google-analytics.com static.geetest.com static.geevisit.com www.gstatic.com *.hcaptcha.com www.googletagmanager.com; manifest-src 'self'; script-src-attr 'unsafe-inline'; script-src-elem 'self' 'unsafe-inline' cdn.jsdelivr.net cdn.netmera-web.com connect.facebook.net firebasestorage.googleapis.com googleads.g.doubleclick.net js.zohocdn.com salesiq.zoho.com secure.adnxs.com www.google-analytics.com www.google.com www.googleadservices.com www.googletagmanager.com www.gstatic.com app.intotheblock.com code.jquery.com js-agent.newrelic.com js.zohostatic.com ntm.netmera-web.com s3.tradingview.com ssl.google-analytics.com d17nz991552y2g.cloudfront.net *.geetest.com *.geevisit.com; script-src 'self' 'unsafe-eval' cdn.netmera-web.com js-agent.newrelic.com g792337344.co connect.facebook.net *.hcaptcha.com app.intotheblock.com firebasestorage.googleapis.com googleads.g.doubleclick.net js.zohocdn.com js.zohostatic.com ntm.netmera-web.com s3.tradingview.com salesiq.zoho.com secure.adnxs.com www.google-analytics.com www.google.com www.googleadservices.com www.googletagmanager.com www.gstatic.com *.geetest.com *.hcaptcha.com; style-src-attr 'unsafe-inline'; style-src-elem 'self' 'unsafe-inline' data: cdn.datatables.net cdn.jsdelivr.net cdnjs.cloudflare.com css.zohocdn.com fonts.googleapis.com use.fontawesome.com css.zohostatic.com *.geetest.com *.hcaptcha.com; style-src 'unsafe-eval' data: cdnjs.cloudflare.com css.zohocdn.com css.zohostatic.com fonts.googleapis.com *.hcaptcha.com *.geetest.com *.bitexen.com; worker-src *.bitexen.com; object-src 'none'; report-uri https://reporturi.bitexen.com/r/d/csp/wizard 1 default-src 'self'; img-src *; style-src 'self' 'unsafe-inline'; script-src 'self' 'unsafe-inline' 'unsafe-eval' 1 object-src 'none';base-uri 'self';script-src 'nonce-80y7OjT8PHCNxIs2I9bktQ' 'strict-dynamic' 'report-sample' 'unsafe-eval' 'unsafe-inline' https: http:;report-uri https://csp.withgoogle.com/csp/gws/other-hp 1 require-trusted-types-for 'script'; 1 font-src maxcdn.bootstrapcdn.com fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com www.facebook.com platform.twitter.com *.weltpixel.com *.googletagmanager.com *.doubleclick.net www.xtento.com *.fw-cdn.com/20195190/105526.js https://widget.freshworks.com *.freshchat.com googleapis.com *.googleapis.com googletagmanager.com googlesyndication.com *.googlesyndication.com google.com *.google.com google.co.nz *.google.co.nz doubleclick.net staticcdn.co.nz *.staticcdn.co.nz newrelic.com *.newrelic.com nr-data.net *.nr-data.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io www.facebook.com pinterest.com assets.pinterest.com syndication.twitter.com *.gstatic.com *.facebook.com *.reddit.com *.google-analytics.com *.googletagmanager.com *.doubleclick.net *.google.com www.xtento.com cdn.xtento.com *.fw-cdn.com/20195190/105526.js https://widget.freshworks.com *.freshchat.com googleapis.com *.googleapis.com googletagmanager.com googlesyndication.com *.googlesyndication.com google.com google.co.nz *.google.co.nz doubleclick.net staticcdn.co.nz *.staticcdn.co.nz newrelic.com *.newrelic.com nr-data.net *.nr-data.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com connect.facebook.net twitter.com platform.twitter.com *.googletagmanager.com *.googleadservices.com *.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com unpkg.com *.doubleclick.net *.maxmind.com www.xtento.com cdn.xtento.com *.fw-cdn.com/20195190/105526.js https://widget.freshworks.com *.freshchat.com googleapis.com *.googleapis.com googlesyndication.com *.googlesyndication.com google.com google.co.nz *.google.co.nz doubleclick.net staticcdn.co.nz *.staticcdn.co.nz newrelic.com nr-data.net stripe.com *.stripe.com *.wetanz.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com maxcdn.bootstrapcdn.com *.tagmanager.google.com *.googletagmanager.com fonts.googleapis.com *.fw-cdn.com/20195190/105526.js https://widget.freshworks.com *.freshchat.com googletagmanager.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com *.google-analytics.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.doubleclick.net *.run.app *.mmapiws.com *.fw-cdn.com/20195190/105526.js https://widget.freshworks.com *.freshchat.com googleapis.com *.googleapis.com googletagmanager.com *.googletagmanager.com googlesyndication.com *.googlesyndication.com google.com *.google.com google.co.nz *.google.co.nz doubleclick.net staticcdn.co.nz *.staticcdn.co.nz newrelic.com nr-data.net 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'none'; media-src 'self'; object-src 'none'; worker-src 'self' blob:; child-src 'self' blob:; manifest-src 'self'; base-uri 'none'; form-action 'self'; img-src 'self' data: *.america250.org *.classy.org classy.org america-250.helloprobability.io fonts.gstatic.com fonts.googleapis.com maps.googleapis.com maps.gstatic.com *.googleapis.com *.gstatic.com i.ytimg.com *.ytimg.com www.youtube.com *.youtube.com manage.america250.org; frame-src 'self' *.america250.org *.classy.org classy.org america-250.helloprobability.io fonts.gstatic.com fonts.googleapis.com maps.googleapis.com maps.gstatic.com *.googleapis.com *.gstatic.com i.ytimg.com *.ytimg.com www.youtube.com *.youtube.com manage.america250.org; frame-ancestors 'none'; script-src 'self' *.america250.org *.classy.org classy.org america-250.helloprobability.io fonts.gstatic.com fonts.googleapis.com maps.googleapis.com maps.gstatic.com *.googleapis.com *.gstatic.com i.ytimg.com *.ytimg.com www.youtube.com *.youtube.com manage.america250.org 'unsafe-inline'; style-src 'self' *.america250.org *.classy.org classy.org america-250.helloprobability.io fonts.gstatic.com fonts.googleapis.com maps.googleapis.com maps.gstatic.com *.googleapis.com *.gstatic.com i.ytimg.com *.ytimg.com www.youtube.com *.youtube.com manage.america250.org 'unsafe-inline'; font-src 'self' https://fonts.gstatic.com; connect-src 'self' *.america250.org *.classy.org classy.org america-250.helloprobability.io fonts.gstatic.com fonts.googleapis.com maps.googleapis.com maps.gstatic.com *.googleapis.com *.gstatic.com i.ytimg.com *.ytimg.com www.youtube.com *.youtube.com manage.america250.org; upgrade-insecure-requests 1 report-uri https://o7202.ingest.us.sentry.io/api/278133/security/?sentry_key=3fa89efb7ac645f5820f641a4e80c50f&sentry_environment=production; report-to csp-endpoint; default-src * 'unsafe-inline' 'unsafe-eval' data: blob:; script-src * 'unsafe-inline' 'unsafe-eval' data: blob:; connect-src * data: blob:; img-src * data: blob:; style-src * 'unsafe-inline' data: blob:; media-src * data: blob:; font-src * data: blob:; object-src * data: blob:; frame-src * data: blob:; worker-src * data: blob:; manifest-src * data: blob:; frame-ancestors *; 1 img-src 'self' data: https://*.siteimproveanalytics.io; script-src 'self' https://siteimproveanalytics.com cdn.jsdelivr.net https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://www.google.com; script-src-attr 'self'; script-src-elem 'self' https://js-agent.newrelic.com https://bam.nr-data.net https://www.google.com/recaptcha/api.js https://www.gstatic.com/recaptcha/releases/V6_85qpc2Xf2sbe3xTnRte7m/recaptcha__en.js cdn.jsdelivr.net https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://www.google.com; style-src 'self' 'unsafe-inline' https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://fonts.googleapis.com; style-src-attr 'self' 'unsafe-inline'; frame-ancestors 'self' 1 default-src 'self' https: data: blob:; script-src https: 'unsafe-inline' 'unsafe-eval'; style-src 'self' 'unsafe-inline' https:; img-src 'self' data: blob: https:; font-src 'self' data: https:; frame-src 'self' https:; connect-src 'self' data: blob: https: wss:; media-src 'self' https: blob:; worker-src 'self' blob:; object-src 'none'; base-uri 'self'; form-action 'self' https:; frame-ancestors 'self'; report-uri https://napi.jumbomail.me/api/reports/csp-report; 1 default-src 'self' https://*.keva.fi https://disqus.com https://*.disquscdn.com https://static.aim.front.ai https://905keva.boost.ai; style-src 'self' 'unsafe-inline' *.tinymce.com *.tiny.cloud https://*.googleapis.com https://*.episerver.net https://*.disquscdn.com https://cdn.datatables.net https://cdnjs.cloudflare.com https://ton.twimg.com https://platform.twitter.com https://hello.myfonts.net https://fonts.googleapis.com https://cdn.reactandshare.com https://static.aim.front.ai; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.tinymce.com *.tiny.cloud https://*.reactandshare.com https://*.keva.fi https://disqus.com https://keva-fi.disqus.com https://*.disquscdn.com https://cdn.syndication.twimg.com https://api.twitter.com https://platform.twitter.com https://*.snoobi.com https://insight.fonecta.fi https://netdna.bootstrapcdn.com https://*.episerver.net https://code.jquery.com https://ajax.aspnetcdn.com https://cdn.datatables.net https://cdnjs.cloudflare.com https://*.vo.msecnd.net https://connect.facebook.net https://*.krxd.net https://survey.taloustutkimus.fi https://www.googleadservices.com https://snap.licdn.com https://unpkg.com https://js.monitor.azure.com https://static.aim.front.ai/ https://905keva.boost.ai; img-src 'self' data: blob: kevadevstorage.blob.core.windows.net *.tinymce.com *.tiny.cloud https://*.reactandshare.com https://*.adsymptotic.com/ https://*.gstatic.com https://*.keva.fi https://*.episerver.net https://*.twitter.com https://*.twimg.com https://insight.fonecta.fi https://cdn.shopify.com https://nuget.episerver.com https://raw.githubusercontent.com https://www.facebook.com https://referrer.disqus.com https://*.disquscdn.com https://beacon.krxd.net https://*.snoobi.com https://www.linkedin.com https://*.ads.linkedin.com https://static.aim.front.ai https://boost-files-general-eu-west-1-prod.s3-eu-west-1.amazonaws.com; connect-src wss: https: ws: https://dc.services.visualstudio.com https://static.aim.front.ai https://905keva.boost.ai; font-src 'self' *.tinymce.com *.tiny.cloud https://*.cloudflare.com https://*.keva.fi https://netdna.bootstrapcdn.com https://fonts.gstatic.com https://cdn.reactandshare.com https://static.aim.front.ai https://*.cloudfront.net; frame-src 'self' *.tinymce.com *.tiny.cloud https://*.keva.fi https://*.twitter.com https://www.youtube.com https://disqus.com https://staticxx.facebook.com https://cdn.krxd.net https://survey.taloustutkimus.fi https://player.vimeo.com https://www.riddle.com https://*.soundcloud.com https://app.powerbi.com https://dashboard.find.episerver.net/; object-src 'self'; 1 default-src 'self' https:; script-src 'self' https: 'unsafe-inline' 'unsafe-eval'; style-src 'self' https: 'unsafe-inline'; img-src 'self' https: data: blob:; media-src 'self' https: data: blob:; object-src 'none'; frame-ancestors 'self' https://experience.adobe.com https://infopoint.audi.it; connect-src 'self' https: wss://e0k754.acquire.io; base-uri 'self'; font-src 'self' https: data:; worker-src 'self' blob:; report-uri https://www.audi.com.tr/api/csp-report; report-to csp-endpoint 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com cash-f.squarecdn.com 'self' data: *.doubleclick.net *.facebook.com *.fontawesome.com https://fonts.bunny.net *.alothemes.com *.magepow.com maxcdn.bootstrapcdn.com *.klarnacdn.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com * *.facebook.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.demdex.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com * *.doubleclick.net *.facebook.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com consentcdn.cookiebot.com service.force.com *.trustpilot.com www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com img.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net s.ytimg.com * *.bird.eu 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com https://firebasestorage.googleapis.com *.alothemes.com *.magepow.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.adobedtm.com dev.visualwebsiteoptimizer.com *.exacttarget.com *.google.it/pagead/1p-user-list serverside.stiga.com *.cookiebot.com via.placeholder.com maps.googleapis.com *.teads.tv www.xtento.com *.trustpilot.com imgsct.cookiebot.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net *.adobe.io *.commerce-payment-services.com *.magento-ds.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.magento-datasolutions.com www.youtube.com video.google.com *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com *.cash.app *.visa.com *.mastercard.com https://rum.hlx.page *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.avada.io *.shopify.com *.alothemes.com *.magepow.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com maps.googleapis.com *.klarna.com consent.cookiebot.com *.collect.igodigital.com serverside.stiga.com cdnjs.cloudflare.com service.force.com *.salesforceliveagent.com *.salesforce-scrt.com *.site.com *.mczbf.com *.emjcd.com dev.visualwebsiteoptimizer.com *.clarity.ms *.imedia.cz consentcdn.cookiebot.com *.teads.tv *.seznam.cz *.xtento.com *.trustpilot.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.magento-datasolutions.com *.magento-ds.com getfirebug.com *.cash.app *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.fontawesome.com https://fonts.bunny.net *.alothemes.com *.magepow.com maxcdn.bootstrapcdn.com assets.braintreegateway.com service.force.com *.klarnacdn.net *.site.com *.trustpilot.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.magento-datasolutions.com *.magento-ds.com * *.google-analytics.com *.facebook.com *.facebook.net api.addressy.com https://get.geojs.io *.avada.io *.alothemes.com *.magepow.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com maps.googleapis.com consentcdn.cookiebot.com *.googlesyndication.com dev.visualwebsiteoptimizer.com serverside.stiga.com *.klarna.com *.klarnaevt.com trustpilot.com googleads.g.doubleclick.net *.teads.tv *.clarity.ms noembed.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' plausible.io *.bing.com *.boomtrain.com *.callrail.com *.cdn.digitaloceanspaces.com *.cloudflare.com *.cloudflareinsights.com *.cookielaw.org *.crazyegg.com *.derbysoftsec.com *.doubleclick.net *.facebook.net *.gstatic.com *.google-analytics.com *.google.com *.googleadservices.com *.googleapis.com *.googletagmanager.com *.quantcount.com *.quantserve.com *.rezync.com *.rfihub.net *.sojern.com *.stackadapt.com *.stripe.com *.tiqcdn.com *.azds.com *.qvdt3feo.com *.pendry.com; script-src-elem 'self' 'unsafe-inline' plausible.io *.bing.com *.boomtrain.com *.callrail.com *.cdn.digitaloceanspaces.com *.cloudflare.com *.cloudflareinsights.com *.cookielaw.org *.crazyegg.com *.derbysoftsec.com *.doubleclick.net *.facebook.net *.gstatic.com *.google-analytics.com *.google.com *.googleadservices.com *.googleapis.com *.googletagmanager.com *.quantcount.com *.quantserve.com *.rezync.com *.rfihub.net *.sojern.com *.stackadapt.com *.stripe.com *.storage.googleapis.com *.tiqcdn.com *.azds.com *.acumbamail.com *.threatspike.com *.acumbamail.com *.tms-plugins.com *.sc-static.net *.googlesyndication.com *.infird.com *.pendry.com blob:; connect-src 'self' *.azds.com *.boomtrain.com *.callrail.com *.cookielaw.org *.crazyegg.com *.doubleclick.net *.facebook.com *.g.doubleclick.net *.google-analytics.com google.com *.google.com *.googleadservices.com *.googletagmanager.com *.googleapis.com *.google.com.mx *.google.pl *.google.ca *.onetrust.com *.sojern.com *.stackadapt.com *.tiqcdn.com *.myhotelshop.de *.awsapprunner.com *.run.app *.letsway.com *.bing.com *.bing.net *.googlesyndication.com *.quantcount.com *.quantserve.com plausible.io *.emlsend.com *.yoast.com *.cloudfront.net *.launchdarkly.com *.overbridgenet.com *.geoedge.com *.dreamsadnetwork.com *.pendry.com; frame-src 'self' *.doubleclick.net *.facebook.com *.googletagmanager.com *.google.com *.pcibooking.net *.rfihub.net *.rfihub.com *.sojern.com *.stripe.com *.azds.com *.techloq.com *.ibosscloud.com *.wikimedia.org *.zscalerthree.net *.zscaler.net visitingmedia.com *.vimeo.com *.formcrafts.com *.menlosecurity.com *.dadco.com *..dpisd.org *.linewize.net *.pendry.com blob:; img-src * data: blob:; font-src * data:; media-src * 'self' data:; manifest-src * 'self'; style-src * 'unsafe-inline' data:; worker-src 'self' blob:; report-uri https://cfe87652b26de6b69f71ed43bef9cf37.report-uri.com/r/d/csp/reportOnly; 1 default-src 'none'; script-src 'self' 'unsafe-inline' https://cdnjs.cloudflare.com https://static.cloudflareinsights.com https://www.googletagmanager.com https://www.google-analytics.com https://login.microsoftonline.com https://secure.aadcdn.microsoftonline-p.com; style-src 'self' 'unsafe-inline' https://cdnjs.cloudflare.com https://fonts.googleapis.com; img-src 'self' data: https:; font-src 'self' data: https://cdnjs.cloudflare.com https://fonts.gstatic.com; connect-src 'self' https:; frame-src 'self' https:; object-src 'none'; base-uri 'self'; form-action 'self' https://planetaryscienceinstitute.kindful.com; frame-ancestors 'self'; 1 default-src 'self'; base-uri 'self'; upgrade-insecure-requests; style-src 'self' 'unsafe-inline'; style-src-elem 'self' 'unsafe-inline' mfstatic.com static.mediaflowpro.com dl.episerver.net; style-src-attr 'self' 'unsafe-inline'; font-src 'self' mfstatic.com dl.episerver.net static.mediaflowpro.com; form-action 'self' information.his.se; frame-src 'self' *.imbox.io *.kaltura.nordu.net www.youtube.com play.mediaflowpro.com web103.reachmee.com; frame-ancestors 'self'; img-src 'self' data: *.mediaflowpro.com *.mediaflow.com *.his.se i.ytimg.com dl.episerver.net *.inviewer.se mfstatic.com *.mfstatic.com; object-src 'none'; script-src 'self' 'unsafe-eval' 'unsafe-inline' *.matomo.cloud *.imbox.io mfstatic.com www.youtube.com cdn.siteimprove.net web103.reachmee.com; script-src-elem 'self' 'unsafe-eval' 'unsafe-inline' *.matomo.cloud *.imbox.io mfstatic.com www.youtube.com cdn.siteimprove.net web103.reachmee.com static.mediaflowpro.com *.inviewer.se dl.episerver.net; worker-src 'self' blob:; connect-src 'self' *.matomo.cloud noembed.com *.mediaflow.com mfstatic.com stats.mediaflowpro.com *.siteimprove.com; media-src 'self' blob: *.mediaflow.com *.mediaflowpro.com; report-uri /csp-report; 1 base-uri 'self'; child-src 'self'; connect-src 'self' ws: https://*.psychologytools.com https://a.optinmonster.com https://a.omappapi.com https://api.omappapi.com https://checkout.stripe.com https://api.stripe.com https://maps.googleapis.com https://plausible.io https://hemsync.clickagy.com https://aorta.clickagy.com https://js.zi-scripts.com https://ws.zoominfo.com; default-src 'self'; font-src 'self' https://fonts.gstatic.com https://*.psychologytools.com https://fonts.bunny.net data:; form-action 'self' https://*.psychologytools.com; frame-src 'self' https://*.psychologytools.com https://checkout.stripe.com https://connect-js.stripe.com https://js.stripe.com https://*.js.stripe.com https://hooks.stripe.com https://www.youtube.com https://hemsync.clickagy.com; img-src 'self' data: https://*.psychologytools.com https://psychologytools-com-local.s3.eu-west-1.amazonaws.com https://psychology-tools-dev-files.s3.eu-west-1.amazonaws.com https://media-engine-local-public.s3.eu-west-2.amazonaws.com https://media-engine-local-private.s3.eu-west-2.amazonaws.com https://media-engine-dev-public.s3.eu-west-2.amazonaws.com https://media-engine-staging-public.s3.eu-west-2.amazonaws.com https://media-engine-production-public.s3.eu-west-2.amazonaws.com https://media-engine-production-public.s3.eu-west-2.amazonaws.com https://*.stripe.com https://gravatar.com https://*.cloudfront.net; manifest-src 'self'; media-src 'self'; object-src 'none'; script-src 'nonce-3FGQdinAioMm5pw0b2bkHSdNvV3ETPKj' 'self' 'unsafe-eval' https://*.psychologytools.com https://checkout.stripe.com https://connect-js.stripe.com https://js.stripe.com https://*.js.stripe.com https://maps.googleapis.com https://js.zi-scripts.com https://ws.zoominfo.com https://tags.clickagy.com https://cdn.jsdelivr.net blob:; script-src-attr 'self' 'unsafe-inline' https://*.psychologytools.com https://cdn.jsdelivr.net https://psychologytools-com-local.s3.eu-west-1.amazonaws.com https://media-engine-local-public.s3.eu-west-2.amazonaws.com https://media-engine-local-private.s3.eu-west-2.amazonaws.com https://media-engine-dev-public.s3.eu-west-2.amazonaws.com https://media-engine-staging-public.s3.eu-west-2.amazonaws.com https://media-engine-production-public.s3.eu-west-2.amazonaws.com https://media-engine-production-public.s3.eu-west-2.amazonaws.com; script-src-elem 'self' 'unsafe-inline' https://*.psychologytools.com https://a.omappapi.com https://cdn.jsdelivr.net https://plausible.io https://ws-assets.zoominfo.com https://js.zi-scripts.com blob:; style-src 'self' 'unsafe-inline' https://*.psychologytools.com https://cdn.jsdelivr.net; style-src-attr 'self' 'unsafe-inline' https://*.psychologytools.com https://cdn.jsdelivr.net; style-src-elem 'self' 'unsafe-inline' https://*.psychologytools.com https://fonts.googleapis.com https://a.omappapi.com https://cdn.jsdelivr.net https://fonts.bunny.net; 1 font-src fonts.gstatic.com use.typekit.net cdn.jsdelivr.net cdn.almapay.com *.googleapis.com https://www.gstatic.com data: fonts.googleapis.com https://cdnjs.cloudflare.com https://fonts.gstatic.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.adyen.com pay.google.com payments-eu.amazon.com *.amazon.de www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.adyen.com pay.google.com *.paypal.com *.getalma.eu *.almapay.com/ www.google.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com https://www.googletagmanager.com/ *.google.com/ https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com https://www.youtube.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net validator.swagger.io *.adyen.com pay.google.com *.payments-amazon.com *.media-amazon.com *.paypalobjects.com https://*.gstatic.com *.googleapis.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.bird.eu *.openstreetmap.org maps.googleapis.com maps.gstatic.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ https://www.magezon.com https://*.google.com https://*.googleapis.com https://*.googleusercontent.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.adyen.com pay.google.com *.payments-amazon.com *.paypal.com *.ratepay.com cdn.jsdelivr.net *.almapay.com *.googleapis.com https://*.gstatic.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ https://cdnjs.cloudflare.com https://polyfill-fastly.io https://browser.sentry-cdn.com sentry.bird.eu *.google.com/ https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com cdn.jsdelivr.net *.almapay.com https://fonts.googleapis.com https://cdnjs.cloudflare.com https://hcaptcha.com https://*.hcaptcha.com *.fontawesome.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.adyen.com *.google.com https://*.google.com payments-eu.amazon.com *.paypal.com *.getalma.eu *.almapay.com *.googleapis.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com maps.googleapis.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ https://*.ingest.sentry.io sentry.bird.eu https://ipinfo.io https://*.gstatic.com https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 child-src blob: data: https:; connect-src https: wss:; default-src blob: data: https: 'report-sample' 'unsafe-eval' 'unsafe-inline'; font-src data: https:; form-action https:; frame-src data: https:; img-src blob: data: https:; media-src blob: data: https:; object-src https:; script-src https: 'unsafe-eval' 'unsafe-inline'; script-src-elem https: 'nonce-OnwlItaG7Dd9shgagBz/7w=='; style-src https: 'unsafe-inline'; report-uri https://csp.ffx.io/; report-to csp-endpoint 1 default-src 'self'; base-uri 'self'; object-src 'none'; frame-ancestors 'self'; form-action 'self'; frame-src 'self' https://www.youtube.com https://www.youtube-nocookie.com; script-src 'self' 'unsafe-inline' 'wasm-unsafe-eval' https://www.googletagmanager.com https://www.google-analytics.com https://static.cloudflareinsights.com https://cdn.onesignal.com https://api.onesignal.com https://accounts.google.com https://cdn.apple-mapkit.com; connect-src 'self' https://www.google-analytics.com https://region1.google-analytics.com https://feature-flag.fazwaz.tech https://accounts.google.com https://api.onesignal.com https://cdn.apple-mapkit.com https://gsp10.apple-mapkit.com; img-src 'self' data: https: https://img.fazwaz.com; style-src 'self' 'unsafe-inline' https:; font-src 'self' data: https://cdn.fazwaz.com; worker-src 'self' blob:; upgrade-insecure-requests 1 script-src * 'unsafe-inline' 'unsafe-eval'; style-src 'self' https: 'unsafe-inline'; object-src 'none'; base-uri 'self'; connect-src 'self' https:; font-src 'self' https: data:; frame-src 'self' https:; img-src 'self' https: data:; manifest-src 'self' https:; media-src 'self'; worker-src 'self'; frame-ancestors 'self'; 1 default-src 'self';base-uri 'self';frame-ancestors 'self';frame-src https://* 'self' epichttp: google.com https://affiliates.baptistchart.com pay.instamed.com;script-src 'nonce-c6bd9daed4ec448e83bcbba9f5fbffb6' https://my.baptistchart.com 'self';img-src https://* 'self' blob: data: google.com https://affiliates.baptistchart.com;connect-src 'self' epichttp: google.com https://affiliates.baptistchart.com https://www.google.com;style-src https://my.baptistchart.com 'self' 'unsafe-inline';worker-src 'self' blob:;child-src 'self' blob:;form-action https://central.mychart.org/MyChart/ 'self' google.com https://affiliates.baptistchart.com;media-src https://* 'self' blob:; 1 report-uri /CspReportLogger.php; default-src 'self'; script-src 'self' https://*.googleapis.com https://*.google-analytics.com https://*.googletagmanager.com; script-src-elem 'self' https://*.googleapis.com https://*.google-analytics.com https://*.googletagmanager.com; style-src 'self' 'unsafe-inline' https://*.googleapis.com; style-src-attr 'self' 'unsafe-inline'; style-src-elem 'self' 'unsafe-inline' https://*.googleapis.com; object-src 'self'; base-uri 'self'; connect-src 'self' https://www.google-analytics.com; font-src 'self'; frame-src 'self' https://www.youtube-nocookie.com; img-src 'self' https://*.googleapis.com https://*.gstatic.com https://*.google-analytics.com https://*.googletagmanager.com data:; manifest-src 'self'; media-src 'self'; worker-src 'none'; 1 font-src fonts.gstatic.com use.typekit.net https://cdnjs.cloudflare.com applepay.cdn-apple.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.demdex.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com api.payplug.com secure.payplug.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net https://www.google.fr https://api.mapbox.com *.tile.openstreetmap.org https://maps.googleapis.com https://maps.gstatic.com *.googletagmanager.com *.google-analytics.com ssl.gstatic.com www.gstatic.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com assets.adobedtm.com *.adobe.io www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com *.magento-ds.com cdn.jsdelivr.net https://cdnjs.cloudflare.com https://maps.googleapis.com api.payplug.com applepay.cdn-apple.com https://cdn.payplug.com/js/integrated-payment/ *.googletagmanager.com tagmanager.google.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.magento-datasolutions.com *.magento-ds.com cdn.jsdelivr.net https://fonts.googleapis.com https://cdnjs.cloudflare.com tagmanager.google.com fonts.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io *.snplow.net commerce.adobedc.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.magento-datasolutions.com *.magento-ds.com *.getalma.eu https://nominatim.openstreetmap.org *.google-analytics.com *.analytics.google.com *.googletagmanager.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 report-uri https://csp.withgoogle.com/csp/youtube_main/strict;base-uri 'self';object-src 'none';script-src 'report-sample' 'nonce-g69WXq9p6soV-5-qnxQTZA' 'unsafe-inline' 'strict-dynamic' https: http: 'unsafe-eval' 1 font-src *.googleapis.com *.gstatic.com data: maxcdn.bootstrapcdn.com *.fontawesome.com https://fonts.bunny.net fonts.gstatic.com *.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.vivapayments.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.cardlink.gr *.alphaecommerce.gr 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ https://static.addtoany.com/ www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.google.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: https://www.google.gr https://www.google-analytics.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.gstatic.com *.googleapis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.apptrian.com magefan.com cm.magefan.com *.disqus.com https://firebasestorage.googleapis.com *.designer-images.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com https://v2.zopim.com https://go.linkwi.se https://skroutza.skroutz.gr *.skroutz.gr https://static.zdassets.com *.addthis.com *.google-analytics.com https://*.octocom.ai cdn.stat-track.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ https://static.addtoany.com/ *.googleapis.com *.gstatic.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ www.apptrian.com *.vivapayments.com *.disqus.com *.avada.io *.stat-track.com polyfill.io *.moosend.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://*.octocom.ai fonts.googleapis.com maxcdn.bootstrapcdn.com *.fontawesome.com https://fonts.bunny.net *.moosend.com *.bootstrapcdn.com assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com https://static.zdassets.com www.apptrian.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net https://*.zdassets.com https://ianos-chat.zendesk.com https://www.merchant-center-analytics.goog *.zopim.com widget-mediator.zopim.com https://region1.google-analytics.com/ wss://*.zopim.com wss://widget-mediator.zopim.com *.googlesyndication.com *.doubleclick.net https://*.octocom.ai www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com https://stats.addtoany.com/menu *.googleapis.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.apptrian.com https://get.geojs.io *.avada.io *.stat-track.com *.m-pages.com *.m-operations.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src https://static.zdassets.com https://ekr.zdassets.com https://ekr.zendesk.com wss://*.zopim.com wss://widget-mediator.zopim.com *.google-analytics.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com https://static.dhlecommerce.nl https://fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com *.googlesyndication.com *.tiktok.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com *.tiktok.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.googlesyndication.com *.roeye.com *.tiktok.com https://portal.payconiq.com https://static.buckaroo.nl https://maps.googleapis.com https://maps.gstatic.com imgsct.cookiebot.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com *.jsdelivr.net *.tiktok.com https://static.buckaroo.nl https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl https://buckaroo.nl https://static.dhlecommerce.nl https://maps.googleapis.com consent.cookiebot.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com songbird.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com *.tiktok.com https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl https://static.dhlecommerce.nl https://maps.googleapis.com https://fonts.googleapis.com assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.google-analytics.com *.facebook.com *.facebook.net *.doubleclick.net *.googlesyndication.com *.tiktok.com wss://websocketservice-externalapi.prod.buckaroo.io https://static.buckaroo.nl wss://websockets.buckaroo.io/ https://checkout.buckaroo.nl https://testcheckout.buckaroo.nl https://applepay.buckaroo.io https://api-gw.dhlparcel.nl https://static.dhlecommerce.nl https://maps.googleapis.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com cdn.jsdelivr.net cdn.almapay.com https://cdnjs.cloudflare.com *.fontawesome.com https://www.gstatic.com https://fonts.gstatic.com horace.com cdn.kustomerapp.com static.klaviyo.com *.klarnacdn.net https://fonts.bunny.net maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.sharethis.com *.getalma.eu *.almapay.com/ *.stripe.com/ *.checkout.com/ *.adyen.com/ *.klarna.com js.stripe.com js.mollie.com *.weltpixel.com *.googletagmanager.com *.doubleclick.net https://www.google.com td.doubleclick.net www.facebook.com tr.snapchat.com tr6.snapchat.com www.googletagmanager.com *.paidonresults.net *.paidonresults.com portgk.com porjs.com 'self' 'unsafe-inline'; img-src data: widgets.magentocommerce.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com *.google-analytics.com *.analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com *.sharethis.com https://images.unsplash.com *.klarna.com *.klarnaevt.com *.klarnacdn.net https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://www.mollie.com https://maps.googleapis.com https://maps.gstatic.com *.facebook.com *.reddit.com *.googletagmanager.com *.doubleclick.net *.google.com maps.googleapis.com maps.gstatic.com horace.com www.facebook.com bat.bing.net c.contentsquare.net cdn.cookielaw.org bat.bing.com www.google.fr cdn.prod2.kustomerhostedcontent.com www.google.es www.google.us www.google.co.uk www.google.de www.google.ir tr.snapchat.com tr6.snapchat.com https://firebasestorage.googleapis.com https://www.google.fr https://api.mapbox.com *.tile.openstreetmap.org data: 'self' 'unsafe-inline'; script-src googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.sharethis.com cdn.jsdelivr.net https://maps.googleapis.com *.klarna.com *.klarnacdn.net x.klarnacdn.net js.stripe.com widget.freshworks.com m2epro.freshdesk.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ js.mollie.com https://cdnjs.cloudflare.com *.googletagmanager.com *.googleadservices.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com unpkg.com *.doubleclick.net maps.googleapis.com https://www.google.com https://www.gstatic.com cdn.cookielaw.org horace.com browser.sentry-cdn.com polyfill-fastly.io static.klaviyo.com connect.facebook.net try.abtasty.com static-tracking.klaviyo.com www.artfut.com bat.bing.com www.tag4arm.com t.contentsquare.net static.affilae.com sc-static.net analytics.tiktok.com www.clarity.ms cdn.amplitude.com cdn.kustomerapp.com ajax.cloudflare.com tr.snapchat.com k-aeu1.contentsquare.net porjs.com *.paidonresults.net *.paidonresults.com portgk.com *.klarnaservices.com *.avada.io *.shopify.com https://browser.sentry-cdn.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com *.sharethis.com cdn.jsdelivr.net widget.freshworks.com m2epro.freshdesk.com https://static.klaviyo.com https://fonts.googleapis.com https://cdnjs.cloudflare.com *.fontawesome.com *.tagmanager.google.com *.googletagmanager.com horace.com *.klarnacdn.net https://fonts.bunny.net maxcdn.bootstrapcdn.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src download-video-ak.vimeocdn.com player.vimeo.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.googleadservices.com *.google-analytics.com *.analytics.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.sharethis.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io *.getalma.eu *.almapay.com https://maps.googleapis.com https://player.vimeo.com *.klarnaevt.com *.klarnacdn.net x.klarnacdn.net widget.freshworks.com m2epro.freshdesk.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.doubleclick.net *.run.app maps.googleapis.com horace.com region1.analytics.google.com cdn.cookielaw.org o4508795589427200.ingest.de.sentry.io fast.a.klaviyo.com static-forms.klaviyo.com v.clarity.ms j.clarity.ms ariane.abtasty.com try.abtasty.com dcinfos-cache.abtasty.com region1.google-analytics.com horace.api.kustomerapp.com k-aeu1.contentsquare.net www.google-analytics.com tr.snapchat.com tr6.snapchat.com s.clarity.ms bat.bing.net c.contentsquare.net www.tag4arm.com matomo.horace.app api.eu.amplitude.com *.paidonresults.net *.paidonresults.com portgk.com porjs.com *.klarnaservices.com *.klarna.com https://get.geojs.io *.avada.io https://nominatim.openstreetmap.org https://*.ingest.sentry.io 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src horace.com bat.bing.com bat.bing.net c.contentsquare.net k-aeu1.contentsquare.net v.clarity.ms j.clarity.ms googleads.g.doubleclick.net www.tag4arm.com matomo.horace.app tr6.snapchat.com analytics.tiktok.com www.google.fr www.google.com porjs.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 report-uri https://shop.southco.com/csp-report.php; font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.klevu.com *.ksearchnet.com *.fontawesome.com https://fonts.bunny.net 'self' data: testmedia.southco.com devmedia.southco.com preprodmedia.southco.com media.southco.com maxcdn.bootstrapcdn.com dev.southco.com preprod.southco.com test.southco.com southco.com preprodstatic.southco.com staticassets.southco.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.yotpo.com *.googleapis.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * southco.my.salesforce.com d.la1-core2.sfdc-lywfpd.salesforceliveagent.com cloud.e.southco.com southco.com.br preprod.southco.com.br dev.southco.com.br https://cl.s12.exct.net/DEManager.aspx cl.s12.exct.net https://secure.ccavenue.com https://test.ccavenue.com 'self' form-action: *.icicibank.com *.wibmo.com *.americanexpress.com *.starlingbank.com www.rsa3dsauth.com acs.revolut.com *.live.ext.prod.enfuce.com authentication-acs.marqeta.com acs.capitalone.com *.acssecure.com *.danskebank.com *.facebook.com *.yotpo.com 'self' 'unsafe-inline'; frame-ancestors *.certcapture.com *.meetanshi.com meetanshi.com * *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com *.certcapture.com *.dotdigital-pages.com *.dotdigital.com *.weltpixel.com *.addthis.com *.google.com/ *.meetanshi.com meetanshi.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.wesupply.xyz https://wesupplylabs.com guarantee-cdn.com *.googletagmanager.com *.doubleclick.net *.yotpo.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.certcapture.com *.klevu.com *.ksearchnet.com https://firebasestorage.googleapis.com https://www.magezon.com *.meetanshi.com meetanshi.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.hsforms.net *.hsforms.com 'self' data: testmedia.southco.com devmedia.southco.com preprodmedia.southco.com media.southco.com preprodstatic.southco.com staticassets.southco.com dev.visualwebsiteoptimizer.com px.ads.linkedin.com www.google.co.in imgsct.cookiebot.com www.linkedin.com shop.southco.com testshop.southco.com devshop.southco.com preprodshop.southco.com dev.southco.com preprod.southco.com test.southco.com southco.com www.mageworx.com image.e.southco.com southco.box.com blob: guarantee-cdn.com *.facebook.com *.reddit.com *.googletagmanager.com *.doubleclick.net *.google.com maps.googleapis.com *.yotpo.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.certcapture.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com js.klevu.com *.ksearchnet.com *.addthis.com *.moatads.com *.addthisedge.com *.pinterest.com *.avada.io *.shopify.com *.meetanshi.com meetanshi.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.hsforms.net *.hsforms.com *.gstatic.com testmedia.southco.com devmedia.southco.com preprodmedia.southco.com media.southco.com preprodstatic.southco.com staticassets.southco.com dev.visualwebsiteoptimizer.com static.hotjar.com consent.cookiebot.com service.force.com s.saleswingsapp.com snap.licdn.com secure.intelligent-data-247.com script.hotjar.com d.la4-c1-phx.salesforceliveagent.com southco.my.salesforce.com d.la1-core2.sfdc-lywfpd.salesforceliveagent.com test.southco.com dev.southco.com preprod.southco.com southco.com consentcdn.cookiebot.com www.gstatic.com www.google.com js-agent.newrelic.com cdnjs.cloudflare.com cloudpages.mc-content.com southco.secure.force.com static.lightning.force.com southco.my.salesforce-sites.com cdn.jsdelivr.net *.salesforceliveagent.com player.vimeo.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com *.cloudflare.com guarantee-cdn.com ajax.googleapis.com *.googletagmanager.com *.googleadservices.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com unpkg.com *.doubleclick.net https://www.googletagmanager.com tagmanager.google.com maps.googleapis.com *.yotpo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.certcapture.com *.klevu.com *.ksearchnet.com *.fontawesome.com *.googleapis.com https://fonts.bunny.net assets.braintreegateway.com *.gstatic.com service.force.com/ testmedia.southco.com devmedia.southco.com preprodmedia.southco.com media.southco.com preprodstatic.southco.com staticassets.southco.com maxcdn.bootstrapcdn.com test.southco.com dev.southco.com preprod.southco.com southco.com southco.secure.force.com southco.my.salesforce-sites.com cdn.jsdelivr.net *.stripe.network *.stripecdn.com *.amazon.com *.tagmanager.google.com *.googletagmanager.com tagmanager.google.com *.yotpo.com https://statsjs.klevu.com https://js.klevu.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.certcapture.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com *.klevu.com *.ksearchnet.com api.addressy.com *.addthis.com https://get.geojs.io *.avada.io *.meetanshi.com meetanshi.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com t.elasticsuite.io *.hsforms.net *.hsforms.com test.southco.com dev.southco.com preprod.southco.com southco.com to.go.saleswingsapp.com px.ads.linkedin.com stats.g.doubleclick.net wss://ws.hotjar.com content.hotjar.io testmedia.southco.com devmedia.southco.com preprodmedia.southco.com media.southco.com metrics.hotjar.io consentcdn.cookiebot.com preprodstatic.southco.com staticassets.southco.com vc.hotjar.io cl.s12.exct.net southco.secure.force.com pagead2.googlesyndication.com southcosearch.netsmartz.us *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.doubleclick.net *.run.app https://www.google-analytics.com *.yotpo.com 'self' 'unsafe-inline'; child-src *.certcapture.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com southco.my.salesforce.com d.la1-core2.sfdc-lywfpd.salesforceliveagent.com cl.s12.exct.net *.cardinalcommerce.com *.paypal.com pilot-payflowlink.paypal.com cloud.e.southco.com static.lightning.force.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; script-src 'self' *.hubspot.com *.hs-analytics.net *.hs-scripts.com; connect-src 'self' *.hubspot.com *.hubapi.com; img-src 'self' *.hs-analytics.net *.hubspotusercontent##.net; frame-src 'self' *.hubspotvideo.com *.hscollectedforms.net; style-src 'self' *.hubspotusercontent##.net; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.sagepay.com *.opayo.eu.elavon.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.stripe.com *.stripe.network *.google.com *.sagepay.com *.opayo.eu.elavon.com 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.stripe.network *.link.com *.amazon.com *.google.com pay.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.sagepay.com *.opayo.eu.elavon.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.googleapis.com *.stripe.com *.stripe.network *.google.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com *.sagepay.com *.opayo.eu.elavon.com assets.emailmeform.com files.emailmeform.com images.dmca.com dev.mastershoe.co.uk www.mastershoe.co.uk *.sooqr.com cdn-cookieyes.com www.google.pl meetanshi.com services.postcodeanywhere.co.uk itfa.org data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.googleapis.com *.gstatic.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com chimpstatic.com downloads.mailchimp.com *.list-manage.com *.sagepay.com *.opayo.eu.elavon.com player.vimeo.com assets.emailmeform.com www.emailmeform.com images.dmca.com static.sooqr.com giles11128.pcapredict.com analytics.webgains.io rum-static.pingdom.net cdn-cookieyes.com dynamic.sooqr.com services.postcodeanywhere.co.uk ajax.cloudflare.com static.cloudflareinsights.com cdn.mouseflow.com dev.mastershoe.co.uk www.mastershoe.co.uk https://www.googletagmanager.com tagmanager.google.com https://chimpstatic.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.stripe.network *.stripecdn.com *.amazon.com *.google.com downloads.mailchimp.com *.sagepay.com *.opayo.eu.elavon.com *.fontawesome.com static.sooqr.com assets.emailmeform.com app.emailmeform.com services.postcodeanywhere.co.uk dev.mastershoe.co.uk www.mastershoe.co.uk tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.googleapis.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.sagepay.com *.opayo.eu.elavon.com cognito-identity.eu-central-1.amazonaws.com firehose.eu-central-1.amazonaws.com cdn-cookieyes.com log.cookieyes.com rum-collector-2.pingdom.net stats.g.doubleclick.net directory.cookieyes.com region1.google-analytics.com services.postcodeanywhere.co.uk dev.mastershoe.co.uk www.mastershoe.co.uk https://www.google-analytics.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 object-src 'none';base-uri 'self';script-src 'nonce-YZcHS8eMRF-XGxCHY-pA-Q' 'strict-dynamic' 'report-sample' 'unsafe-eval' 'unsafe-inline' https: http:;report-uri https://csp.withgoogle.com/csp/gws/other-hp 1 script-src 'nonce-2a979997d939f5412042efd851e087754364fd4a56839e89911aaf2b4003420a' assets.adobedtm.com *.adobe.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.salesmanago.pl *.salesmanago.es *.salesmanago.com *.autopay.eu pay.google.com *.google-analytics.com *.googletagmanager.com www.xtento.com cdn.xtento.com secure.payu.com secure.snd.payu.com https://cdnjs.cloudflare.com *.packeta.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com songbird.cardinalcommerce.com sandbox.przelewy24.pl secure.przelewy24.pl apm.przelewy24.pl *.facebook.net *.allekurier.pl *.hsforms.net *.hsforms.com *.gstatic.com 'self' *.trustpilot.com 'sha256-W5akSSK6LD5BjIlNICMcXaUObQSRAaj6bs7JHADURBA=' 'sha256-3qVqeAdyxxTdPkkRzqapjGkAUYLahxSrB7Mdup+GPQ0=' 'sha256-2rvfFrggTCtyF5WOiTri1gDS8Boibj4Njn0e+VCBmDI=' 'sha256-p8MCfMHqrovsjRYU9z0bU17dd0z81k/fVbGrtBBiM9g=' 'sha256-0pk2s4oXwBELlC6IBVb3nNaM2PjfjwI2N6OGIX5lx8Y=' 'sha256-nkEZknO0IxNxY/CkTMBhjNhwPvglpYumjx31B4fjkY8=' 'sha256-F20iqiqGicuuiFlhCPv0sBKJFT9sCplzelbf57o8GsI=' 'sha256-syV/eNOnvdKZkC4mI0Qgl6a+j1+UDhVcxAdH9K2eMUw='; style-src *.adobe.com fonts.googleapis.com *.autopay.eu *.googleapis.com https://fonts.googleapis.com https://cdnjs.cloudflare.com *.fontawesome.com maxcdn.bootstrapcdn.com assets.braintreegateway.com *.typekit.net *.gstatic.com 'self' 'unsafe-inline' *.trustpilot.com; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.salesmanago.pl *.salesmanago.es *.salesmanago.com platnosci.bm.pl platnosci-accept.bm.pl www.gstatic.com *.autopay.eu www.xtento.com cdn.xtento.com static.payu.com magefan.com cm.magefan.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com static.przelewy24.pl gstatic.com puccini.pl *.puccini.pl puccini.cz *.puccini.cz puccini.hu *.puccini.hu puccini.ro *.puccini.ro puccini.sk *.puccini.sk puccini.ua *.puccini.ua *.allekurier.pl *.wittchen.com *.hsforms.net *.hsforms.com 'self' data: 'self'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.salesmanago.pl *.salesmanago.es *.salesmanago.com *.google-analytics.com secure.payu.com merch-prod.snd.payu.com *.packeta.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com sandbox.przelewy24.pl secure.przelewy24.pl wss://sandbox-ws.przelewy24.pl wss://secure-ws.przelewy24.pl apple-pay-gateway.apple.com apm.przelewy24.pl www.google.com pay.google.com t.elasticsuite.io *.hsforms.net *.hsforms.com 'self'; media-src *.adobe.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com pay.google.com play.google.com *.autopay.eu www.xtento.com secure.payu.com merch-prod.snd.payu.com *.dhl.pl *.dhl24.com.pl *.packeta.com c.paypal.com checkout.paypal.com assets.braintreegateway.com *.cardinalcommerce.com * apm.przelewy24.pl *.googletagmanager.com 'self' *.trustpilot.com; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * sandbox.przelewy24.pl secure.przelewy24.pl 'self'; font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com https://cdnjs.cloudflare.com *.fontawesome.com maxcdn.bootstrapcdn.com 'self' data: 'self'; default-src *.salesmanago.pl *.salesmanago.es *.salesmanago.com *.googleapis.com 'self'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com 'self'; frame-ancestors pay.google.com; object-src 'self'; 1 child-src 'self' *.youtube.com; default-src * 'unsafe-inline'; font-src 'self' https://fonts.gstatic.com https://fonts.intercomcdn.com data:; frame-src 'self' https://challenges.cloudflare.com *.plaid.com js.stripe.com *.youtube.com https://www.googletagmanager.com https://*.doubleclick.net https://www.facebook.com/ https://tpc.googlesyndication.com https://intercom-sheets.com/ https://calendly.com https://*.calendly.com https://capture.navattic.com https://guideline.navattic.com https://insight.adsrvr.org https://iframe.cloudflarestream.com/ https://customer-x5mykgv2c1zv0440.cloudflarestream.com/ https://match.adsrvr.org; img-src 'self' *.guideline.io https://cms-assets.guideline.com https://imagedelivery.net https://*.googletagmanager.com https://ssl.gstatic.com https://www.gstatic.com https://googleads.g.doubleclick.net https://www.google.com https://*.google-analytics.com https://pagead2.googlesyndication.com https://www.facebook.com ads-twitter.com *.bing.com *.microsoft.com https://*.adsymptotic.com https://t.co https://*.linkedin.com https://analytics.twitter.com https://cdn.cookielaw.org https://trkn.us https://www.gravatar.com https://*.googleadservices.com https://alb.reddit.com https://*.intercomcdn.com https://*.intercomassets.com https://*.intercomusercontent.com data:; manifest-src 'self'; media-src 'self'; object-src 'none'; script-src 'self' https://challenges.cloudflare.com https://cdn-assets-prod.s3.amazonaws.com https://app.intercom.io https://widget.intercom.io https://js.intercomcdn.com https://tracking-api.g2.com https://cdn.prod.uidapi.com https://*.googletagmanager.com https://tagmanager.google.com 'unsafe-eval' 'nonce-587c9269639321d22653660370b24fe5' 'strict-dynamic'; worker-src 'self' *.youtube.com; base-uri 'self'; frame-ancestors 'self' https://*.squareup.com https://squareup.com https://*.squareupstaging.com https://squareupstaging.com https://*.checkhq.com https://*.eddy.com https://eddy.com https://app.belfrysoftware.com https://*.joinwarp.com https://*.monograph.com https://*.enkempass.com https://*.central.inc https://*.keka.com https://*.lumberfi.com https://*.workstream.us https://pro.housecallpro.com https://*.tryplayground.com https://*.7shifts.com https://app.getthera.com https://dashboard.miter.com https://*.zenoti.com https://*.prod.aioapp.com https://app.gosteelhead.com https://*.encompassfi.com https://*.joinhomebase.com; report-uri https://sentry2.guideline.com/api/6/security/?sentry_key=f678b7ad3eade55e6da26393e869e420; 1 script-src 'unsafe-eval' blob: 'self' *.wikimedia.org *.wikipedia.org *.wikinews.org *.wiktionary.org *.wikibooks.org *.wikiversity.org *.wikisource.org wikisource.org *.wikiquote.org *.wikidata.org *.wikifunctions.org *.wikivoyage.org *.mediawiki.org 'unsafe-inline' auth.wikimedia.org; default-src 'self' data: blob: upload.wikimedia.org https://commons.wikimedia.org *.wikimedia.org *.wikipedia.org *.wikinews.org *.wiktionary.org *.wikibooks.org *.wikiversity.org *.wikisource.org wikisource.org *.wikiquote.org *.wikidata.org *.wikifunctions.org *.wikivoyage.org *.mediawiki.org wikimedia.org en.wikipedia.org en.wikibooks.org en.wikinews.org en.wikiquote.org en.wikisource.org en.wikiversity.org en.wikivoyage.org en.wiktionary.org www.mediawiki.org api.wikimedia.org commons.wikimedia.org foundation.wikimedia.org incubator.wikimedia.org species.wikimedia.org wikimania.wikimedia.org www.wikidata.org www.wikifunctions.org auth.wikimedia.org; style-src 'self' data: blob: upload.wikimedia.org https://commons.wikimedia.org *.wikimedia.org *.wikipedia.org *.wikinews.org *.wiktionary.org *.wikibooks.org *.wikiversity.org *.wikisource.org wikisource.org *.wikiquote.org *.wikidata.org *.wikifunctions.org *.wikivoyage.org *.mediawiki.org wikimedia.org 'unsafe-inline'; object-src 'none'; report-uri /w/api.php?action=cspreport&format=json&reportonly=1 1 font-src fonts.gstatic.com use.typekit.net *.googleapis.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com uat.pinepg.in https://uat.pinepg.in/api/PG/V2 secure.pinepg.in https://secure.pinepg.in/payment 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.demdex.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.google.com landofcoder.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.ftcdn.net *.behance.net *.googleapis.com maps.gstatic.com www.pinelabs.com https://www.pinelabs.com/img/logo.png *.gstatic.com https://www.magezon.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net assets.adobedtm.com *.adobe.io *.commerce-payment-services.com *.magento-ds.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ maps.googleapis.com https://www.gstatic.com https://www.googletagmanager.com tagmanager.google.com *.googleapis.com landofcoder.com https://storage.googleapis.com *.googletagmanager.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.magento-datasolutions.com *.magento-ds.com *.fontawesome.com tagmanager.google.com 'self' 'unsafe-inline'; object-src landofcoder.com 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.magento-datasolutions.com *.magento-ds.com maps.googleapis.com https://www.google-analytics.com https://fonts.gstatic.com *.googleapis.com https://www.gstatic.com landofcoder.com https://storage.googleapis.com *.googletagmanager.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri www.googleadservices.com 'self' 'unsafe-inline'; 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://www.google.com https://www.gstatic.com https://widget-react.raychat.io https://www.googletagmanager.com https://www.clarity.ms https://scripts.clarity.ms; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://widget-react.raychat.io; font-src 'self' data: https://fonts.gstatic.com https://widget-react.raychat.io; img-src 'self' data: blob: https://*.raychat.io https://*.clarity.ms https://www.googletagmanager.com; connect-src 'self' https://*.raychat.io wss://*.raychat.io https://*.clarity.ms https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; frame-src https://www.google.com; object-src 'none'; 1 default-src blob: https://*.mhcache.com;font-src 'self' https://*.myheritage.com https://*.mhcache.com https://fonts.gstatic.com;frame-src 'self' https://*.mhcache.com https://portal.allyable.com https://mh-site-files-5c53d6a9947c.s3.amazonaws.com https://myheritage-container.com https://www.myheritage-partners.com https://www.myheritage.com https://*.mk-sense.com https://player.vimeo.com https://*.facebook.com https://*.googleapis.com https://*.google.com https://tpc.googlesyndication.com https://*.doubleclick.net https://accounts.google.com/gsi/;script-src https://accounts.google.com/gsi/client https://www.datadoghq-browser-agent.com https://*.googleapis.com https://appleid.cdn-apple.com *.myheritage.no https://www.myheritage.no 'unsafe-eval' 'nonce-0ce9a81c52a356d348344885cb7f28f9' 'strict-dynamic';style-src data: blob: 'unsafe-inline' 'self' https://*.myheritage.com https://*.mhcache.com https://fonts.googleapis.com https://accounts.google.com/gsi/style;connect-src data: 'self' https://*.myheritage.com https://portal.allyable.com https://*.mhcache.com https://adservice.google.com https://*.logs.datadoghq.com https://*.browser-intake-datadoghq.com https://browser-intake-datadoghq.com https://sentry.io https://*.bing.com https://*.facebook.com https://*.doubleclick.net https://*.mk-sense.com https://*.filae.com https://accounts.google.com/gsi/ https://www.google.com/pagead/landing https://*.googleapis.com https://maps.googleapis.com/maps/api/mapsjs/gen_204 https://translate.googleapis.com https://www.google.com/ccm/collect https://cdn.builder.io *.myheritage.no;media-src 'self' https://*.myheritage.com https://*.mhcache.com;frame-ancestors 'self' https://builder.io;img-src * data:;object-src 'none';base-uri 'self' https://*.mhcache.com;report-uri /FP/API/ContentSecurityPolicy/report-violation.php?report_mode=report&canonical_page_id=/company/home/ 1 object-src *; script-src 'self' https://stats.inalco.fr/matomo.js https://cdnjs.cloudflare.com; script-src-attr 'self' 1 font-src data: fonts.gstatic.com *.fontawesome.com https://fonts.gstatic.com *.gstatic.com 'self' data: maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com www.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com *.hotjar.com *.doubleclick.net td.doubleclick.net https://*.moneris.com/ www.facebook.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com track.hubspot.com servedbyadbutler.com img.youtube.com www.facebook.com www.google.co.in twin-iq.kickfire.com ad.doubleclick.net c.clarity.ms c.bing.com maps.googleapis.com store.paradoxlabs.com *.hsforms.net *.hsforms.com 'self' data: maps.gstatic.com *.pixriot.com *.storeimaging.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.hotjar.com js.hs-banner.com js.hs-scripts.com js.hs-analytics.net servedbyadbutler.com js.hscollectedforms.net js.hubspot.com js.hsadspixel.net tracker.gaconnector.com www.clarity.ms tag.simpli.fi twin-iq.kickfire.com js.usemessages.com https://*.moneris.com/ *.avada.io *.hsforms.net *.hsforms.com *.google.com *.gstatic.com maps.googleapis.com connect.facebook.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://*.moneris.com/ *.fontawesome.com *.googleapis.com *.gstatic.com maxcdn.bootstrapcdn.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com stats.g.doubleclick.net maps.googleapis.com www.google.com *.hotjar.com cta-service-cms2.hubspot.com forms.hscollectedforms.net api.hubapi.com api.hubspot.com wss://ws.hotjar.com *.hotjar.io *.clarity.ms www.facebook.com https://get.geojs.io *.avada.io t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com www.googleapis.com *.pixriot.com *.storeimaging.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net www.paypalobjects.com *.typekit.net *.gstatic.com *.oney.io *.staging.oney.io *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.demdex.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com *.gelproximity.com *.hipay-tpp.com *.hipay.com *.googleapis.com https://www.googletagmanager.com/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.openstreetmap.org *.salesmanago.pl *.salesmanago.es *.salesmanago.com https://maps.googleapis.com *.hipay.com *.googleapis.com *.oney.io *.staging.oney.io http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ magefan.com cm.magefan.com *.disqus.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net assets.adobedtm.com *.adobe.io *.commerce-payment-services.com *.magento-ds.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.magento-datasolutions.com *.gelproximity.com *.hipay.com *.hipay-tpp.com https://mpsnare.iesnare.com *.zdassets.com *.salesmanago.pl *.salesmanago.es *.salesmanago.com widget.freshworks.com m2epro.freshdesk.com mpsnare.iesnare.com *.paypal.com *.googleapis.com *.oney.io *.staging.oney.io http://www.googletagmanager.com/ https://www.googletagmanager.com/ *.disqus.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com cdn.scalapay.com b2c-cdn.scalapay.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.magento-datasolutions.com *.magento-ds.com widget.freshworks.com m2epro.freshdesk.com *.hipay.com *.googleapis.com *.fontawesome.com assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.zdassets.com data: mpsnare.iesnare.com *.googleapis.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.magento-datasolutions.com *.magento-ds.com *.zendesk.com *.zdassets.com *.zopim.com *.salesmanago.pl *.salesmanago.es *.salesmanago.com *.openstreetmap.org https://maps.googleapis.com widget.freshworks.com m2epro.freshdesk.com *.hipay-tpp.com *.hipay.com wss://mpsnare.iesnare.com *.googleapis.com *.oney.io *.staging.oney.io http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com *.salesmanago.pl *.salesmanago.es *.salesmanago.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 script-src https://player.vimeo.com/api/player.js https://player.vimeo.com 'unsafe-inline' https://t.contentsquare.net/uxa/smb/tag.js 'self' https://payments.salesforce.com/ https://checkoutshopper-test.adyen.com/ https://pal-test.adyen.com https://static.hj.contentsquare.net https://hmproxy.luckyorange.com https://static.hj.contentsquare.net/c/csq-5351645.js https://checkoutshopper-live.adyen.com/ https://cdn.content.aws-prod1-useast1.aws.sfdc.cl/ https://settings.luckyorange.com https://s3.amazonaws.com https://djtflbt20bdde.cloudfront.net https://pay.google.com https://www.gstatic.com/recaptcha/ https://uip.canary.lwc.dev https://cdn.content.aws-dev2-uswest2.aws.sfdc.cl/ https://static.hj.contentsquare.net/c/csq https://static.hj.contentsquare.net/c/csq-5345367.js blob: https://www.googletagmanager.com/gtag/js https://www.google.com/recaptcha/ https://js.stripe.com/ https://static.hj.contentsquare.net/c/csq-5353938.js https://*.luckyorange.com https://www.googletagmanager.com import: https://use.fontawesome.com https://www.google-analytics.com *.salesforce.com https://www.paypal.com/sdk/js 'report-sample' https://storage.googleapis.com https://service.force.com/embeddedservice/ 'unsafe-eval'; report-to sfdc-csp-ep; report-uri https://cpaacademy.lightning.force.com/_/ContentDomainCSPNoAuth?tenantId=00DC0000000PiAN&networkId=0DMQh0000000DQI&type=communities 1 base-uri 'self'; form-action 'self'; frame-ancestors 'self'; frame-src 'self'; upgrade-insecure-requests; block-all-mixed-content 1 font-src *.force.com https://mzmoment-test.app https://vev--c.visualforce.com https://www.vevromerike.no 'self' https://stats.g.doubleclick.net https://vevromerike.no https://vev.my.site.com https://e360-tracking-service-cdp1.sfdc-yzvdd4.svc.sfdcfc.net https://a.tiles.mapbox.com https://vev.my.salesforce.com lightning.force.com https://assets.mapquestapi.com https://d.la11-core1.sfdc-urlt2q.salesforceliveagent.com *.doubleclick.net https://www.mapquestapi.com https://www.youtube-nocookie.com *.vevromerike.no https://www.googleoptimize.com https://fonts.gstatic.com/ https://romerikebb.sharepoint.com https://commonapi-gw.get.no https://d.tiles.mapbox.com https://artikler.get.no https://region1.google-analytics.com https://mapconfig.mqcdn.com blob: https://vev.lightning.force.com https://m83tkyrsgfqwkylcgqzgkzlbgy.c360a.salesforce.com https://monitoringpublic.solaredge.com *.vev.lightning.force.com https://www.arrowcommunications.co.uk *.facebook.com https://d.la1-core1.sfdc-urlt2q.salesforceliveagent.com https://www.telia.no https://c.tiles.mapbox.com https://tileproxy.cloud.mapquest.com https://www.googletagmanager.com https://d.la3-c2-fra.salesforceliveagent.com https://mzmoment.app https://www.google-analytics.com https://b.tiles.mapbox.com *.salesforce.com https://vev--c.vf.force.com https://vev.my.salesforce-scrt.com https://service.force.com https://vev.live-preview.salesforce-experience.com data:; report-to sfdc-csp-ep; report-uri https://vev.lightning.force.com/_/ContentDomainCSPNoAuth?tenantId=00D24000000Zs0w&networkId=0DM08000000sXzv&type=communities 1 default-src 'unsafe-inline' *.tulotero.es *.es.tulotero.net tulotero.es es.tulotero.net tulotero.net *.redsys.es api.fpjs.io static.tulotero.net tulotero-prod-es-public-files.s3.eu-west-3.amazonaws.com wa.appsflyer.com websdk.appsflyer.com wa.onelink.me wa.appsflyer.com websdk.appsflyer.com wa.onelink.me *.hotjar.com *.hotjar.io *.googleusercontent.com *.google.es *.google.com *.google-analytics.com *.googleapis.com www.googletagmanager.com www.googleadservices.com tpc.googlesyndication.com *.g.doubleclick.net td.doubleclick.net *.gstatic.com *.twitter.com t.co static.ads-twitter.com platform.twitter.com *.facebook.com connect.facebook.net fpnpmcdn.net graph.facebook.com bat.bing.com *.tiktok.com t.resfu.com data: blob: 'self'; frame-src 'self' sis.redsys.es td.doubleclick.net data: blob: ; frame-ancestors *.tulotero.es *.es.tulotero.net tulotero.es es.tulotero.net tulotero.net *.redsys.es api.fpjs.io static.tulotero.net tulotero-prod-es-public-files.s3.eu-west-3.amazonaws.com wa.appsflyer.com websdk.appsflyer.com wa.onelink.me wa.appsflyer.com websdk.appsflyer.com wa.onelink.me *.hotjar.com *.hotjar.io 'self'; report-uri https://csp-reports.es.tulotero.net/report/v13; block-all-mixed-content;manifest-src 'self'; 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval'; style-src 'self' 'unsafe-inline'; img-src 'self' data: blob: https:; font-src 'self' data:; connect-src 'self'; media-src 'self'; object-src 'none'; frame-src 'self'; frame-ancestors 'self'; form-action 'self'; base-uri 'self' 1 default-src 'self' http: https: data: blob: 'unsafe-inline' 'unsafe-eval' 1 font-src fonts.gstatic.com use.typekit.net *.fontawesome.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.bootstrapcdn.com *.gstatic.com *.typekit.net *.hotjar.com *.audioeye.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com api.bazaarvoice.com stg.api.bazaarvoice.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * https://plumrocket.com *.authorize.net 'self' 'unsafe-inline'; frame-ancestors *.authorize.net *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.googletagmanager.com *.affirm.com *.affirm.ca display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com *.dotdigital-pages.com *.dotdigital.com webchat.dotdigital.com webchat.staging.dotdigital.com https://www.gstatic.com/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * https://plumrocket.com *.authorize.net *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.weltpixel.com https://*.online-metrix.net https://imgs.signifyd.com *.doubleclick.net *.leasestation.com *.kaptcha.com *.google.com *.google.co.in *.networkmerchants.com *.paypalobjects.com *.cdn-btsg.com *.audioeye.com *.milwaukeetool.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com p.typekit.net *.vimeocdn.com i.ytimg.com validator.swagger.io www.apptrian.com *.affirm.com *.affirm.ca display.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com network-a.bazaarvoice.com network-stg-a.bazaarvoice.com photos-uat-us.bazaarvoice.com img.youtube.com *.trackedlink.net *.ddlnk.net ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com form-assets.mailchimp.com store.paradoxlabs.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com https://redchamps.com *.googletagmanager.com *.google-analytics.com www.googletagmanager.com ssl.gstatic.com www.gstatic.com https://imgs.signifyd.com https://*.online-metrix.net *.ohiopowertool.com https://seal-centralohio.bbb.org *.google.com *.google.co.in *.bing.com *.clarity.ms *.amazonaws.com *.shareasale.com *.nexmart.com *.noibu.com *.cdn-btsg.com *.quickspark.com *.bazaarvoice.com https://arttrk.com/ *.hotjar.com *.userway.org *.ojrq.net *.linkedin.com https://cdn.cookielaw.org data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com www.sandbox.paypal.com t.paypal.com amcglobal.sc.omtrdc.net *.adobe.io use.typekit.net magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com *.magento-ds.com www.googletagmanager.com www.apptrian.com *.affirm.com *.affirm.ca apps.bazaarvoice.com apps.nexus.bazaarvoice.com apps-stg.nexus.bazaarvoice.com analytics-static.ugc.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com display.ugc.bazaarvoice.com api.bazaarvoice.com stg.api.bazaarvoice.com mpsnare.iesnare.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal webchat.dotdigital.com webchat.staging.dotdigital.com chimpstatic.com downloads.mailchimp.com *.list-manage.com form-assets.mailchimp.com utt.impactcdn.com *.authorize.net assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com sandbox-assets.secure.checkout.visa.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com *.googletagmanager.com tagmanager.google.com https://cdn-scripts.signifyd.com https://imgs.signifyd.com https://h64.online-metrix.net https://www.dwin1.com https://seal-centralohio.bbb.org *.bing.com *.quickspark.com *.doubleclick.net *.clarity.ms *.nr-data.net *.newrelic.com *.google.com *.networkmerchants.com *.milwaukeetool.com *.noibu.com *.cdn-btsg.com *.pricespider.com *.hotjar.com *.audioeye.com *.impactcdn.com *.online-metrix.net *.userway.org *.gstatic.com *.licdn.com https://cdn.cookielaw.org *.roeyecdn.com *.epigraph.cloud https://chimpstatic.com https://www.ohiopowertool.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com display.ugc.bazaarvoice.com webchat.dotdigital.com webchat.staging.dotdigital.com downloads.mailchimp.com *.fontawesome.com unsafe-inline assets.braintreegateway.com *.stripe.network *.stripecdn.com *.amazon.com tagmanager.google.com fonts.google.com *.mailchimp.com *.bootstrapcdn.com *.quickspark.com *.networkmerchants.com *.gstatic.com *.googleapis.com *.userway.org 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com www.apptrian.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com *.snplow.net commerce.adobedc.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.magento.com *.adobe.io performance.typekit.net commerce.adobe.io *.magento-datasolutions.com *.magento-ds.com *.sentry.io www.apptrian.com *.affirm.com *.affirm.ca api.bazaarvoice.com stg.api.bazaarvoice.com apps.bazaarvoice.com network.bazaarvoice.com network-stg.bazaarvoice.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com form-assets.mailchimp.com *.intuit.com *.amazonaws.com *.authorize.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com https://imgs.signifyd.com *.doubleclick.net *.clarity.ms *.nr-data.net *.networkmerchants.com *.bing.com *.noibu.com wss://*.noibu.com *.cdn-btsg.com *.hotjar.com *.hotjar.io wss://ws.hotjar.com *.audioeye.com *.sjv.io *.userway.org *.linkedin.com https://cdn.cookielaw.org 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com strict-dynamic http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self'; base-uri 'self'; object-src 'none'; frame-ancestors 'self'; frame-src 'self' https://customer-htr0575wlpdjwirn.cloudflarestream.com 1 font-src https://fonts.gstatic.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.sharethis.com *.weltpixel.com https://www.googletagmanager.com/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * www.xtento.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.sharethis.com https://www.facebook.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com https://bat.bing.com/ http://bat.bing.com/ www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.sharethis.com *.attn.tv events.attentivemobile.com https://www.dwin1.com https://widget.usersnap.com https://s.pinimg.com https://ct.pinterest.com https://connect.facebook.net https://analytics.tiktok.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ http://www.googletagmanager.com/ https://www.googletagmanager.com/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://bat.bing.com/ http://bat.bing.com/ www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.sharethis.com https://fonts.googleapis.com https://static.klaviyo.com unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.sharethis.com *.attn.tv events.attentivemobile.com https://www.facebook.com https://ct.pinterest.com https://analytics.tiktok.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com https://bat.bing.com/ http://bat.bing.com/ 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 script-src 'strict-dynamic' 'nonce-euxWtD9UwYUMUVPFpncVhQ==' 1 default-src 'self'; base-uri 'self'; frame-ancestors 'self'; script-src 'self' 'nonce-j4YHHkze7gxGzvsgeJUaSw==' https://www.googletagmanager.com https://www.google-analytics.com https://cdn.trustindex.io https://js.hs-scripts.com https://js.hsforms.net https://kit.fontawesome.com; connect-src 'self' https://www.google-analytics.com https://region1.google-analytics.com https://stats.g.doubleclick.net https://www.googletagmanager.com img-src 'self' data: blob: https: https://www.google-analytics.com https://stats.g.doubleclick.net; style-src 'self' 'unsafe-inline' https://kit.fontawesome.com https://ka-f.fontawesome.com; font-src 'self' data: https://ka-f.fontawesome.com; frame-src 'self' https://forms.hsforms.com https://*.trustindex.io https://www.youtube.com https://www.google.com https://*.doubleclick.net; worker-src 'self' blob:; media-src 'self' https:; object-src 'none'; manifest-src 'self'; upgrade-insecure-requests; 1 script-src 'none'; report-uri https://csp-reporting.cloudflare.com/cdn-cgi/script_monitor/report?m=8GxQYUiL.uB0bfJf2PTgCWzG52E2TokIY0BEp1h4C5A-1770427338-1.0.1.1-TXbXc0N1b6wGW_y9IjG6S8cohI3QRQBVXMDf8JEu9F.Lm8AOwJkKC0HBj9Qa8Wm3CiQcuCcPSYLKo_183Hex.dYLDhQYBHGYF3Ri..E__rB29txbm0j4BIv1XV6aQZsDzcs8H818F76q9E7sZFhsKH1DxoFSNY1sqEOaLDzmbyIyjG6O7Lhvo.Qr1I6pgvEY; report-to cf-csp-endpoint 1 font-src fonts.gstatic.com use.typekit.net *.afterpay.com/ *.afterpaycdn.com *.squarecdn.com *.cash.app *.cloudflare.com *.typekit.net *.trustedshops.com *.similarinc.com *.zipmoney.com.au *.zendesk.com *.bootstrapcdn.com p-a.io *.particularaudience.com *.digidirect.com.au images.latitudepayapps.com imageapi.magebinary.co.nz *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com * *.zipmoney.com.au *.digidirect.com.au *.images.latitudepayapps.com *.imageapi.magebinary.co.nz *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com https://plumrocket.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com https://www.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.afterpay.com *.afterpaycdn.com *.squarecdn.com *.cash.app * *.zipmoney.com.au *.digidirect.com.au *.google.com/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com https://plumrocket.com *.weltpixel.com zip.co static.zip.co sandbox.zip.co zipmoney.com.au sandbox.zipmoney.com.au checkout.gb.zip.co checkout.quadpay.com checkout-sandbox.quadpay.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com p.typekit.net *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net *.afterpay.com/ *.afterpaycdn.com *.squarecdn.com *.cash.app *.cloudflare.com cdn.klarna.com *.paypal.com s.ytimg.com *.google.com *.facebook.com *.adsrvr.org *.google.com.ph *.similarinc.com *.cloudfront.net digidirect.zendesk.com *.pinterest.com *.analytics.yahoo.com *.zendesk.com *.gstatic.com *.klarnacdn.net *.facebook.net *.doubleclick.net *.kayweb.com.au p-a.io *.particularaudience.com *.services.qantasloyalty.com *.adobedtm.com *.latitudepayapps.com zip.co bpi.zip.co *.latitudefinancial.com *.google.lk *.digidirect.com.au https://www.magezon.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com t.zip.co static.zipmoney.com.au static.zip.co data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com amcglobal.sc.omtrdc.net *.adobe.io use.typekit.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com *.magento-ds.com *.afterpay.com *.afterpaycdn.com *.squarecdn.com *.cash.app *.cloudflare.com maps.googleapis.com *.cloudfront.net *.testfreaks.com *.cfjump.com *.facebook.net *.benchplatform.com *.livechatinc.com *.g.doubleclick.net googletagmanager.com *.adsrvr.org *.studio19.com.au *.particularaudience.com *.srv.stackadapt.com cfjump.digidirect.com.au *.gstatic.com t.cfjump.com settings.luckyorange.net *.similarinc.com *.api.similarinc.com *.zipmoney.com.au *.zip.co *.zdassets.com assets.pinterest.com r3.dotdigital-pages.com api.smooch.io *.klarna.com *.klarnacdn.net *.google.com *.cardinalcommerce.com static.client.cardinaltrusted.com *.braintreegateway.com *.braintree-api.com *.paypal.com *.visitors.live *.wibmo.com *.paypal.cn *.paypalobjects.com *.googleadservices.com *.soreto.com *.kayweb.com.au p-a.io api-recs.particularaudience.com d10lpsik1i8c69.cloudfront.net gtm.js *.connect.studentbeans.com *.studentbeans.com *.instagram.com *.jquery.com *.adobedtm.com *.adobed.com *.latitudefinancial.com *.static.afterpay.com *.latitudepayapps.com *.clarity.ms *.zendesk.com *.digidirect.com utt.impactcdn.com *.google.com/ js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com https://www.googletagmanager.com tagmanager.google.com unpkg.com static.zipmoney.com.au static.zip.co zip.co 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com *.afterpay.com/ *.afterpaycdn.com *.squarecdn.com *.cash.app *.cloudflare.com *.typekit.net *.trustedshops.com *.usercentrics.eu tags.srv.stackadapt.com *.similarinc.com *.zipmoney.com.au *.gstatic.com *.google.com *.kayweb.com.au *.bootstrapcdn.com p-a.io *.particularaudience.com *.cloudfront.net *.zip.co *.digidirect.com images.latitudepayapps.com/ imageapi.magebinary.co.nz/ *.fontawesome.com unsafe-inline assets.braintreegateway.com https://fonts.googleapis.com tagmanager.google.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.cloudfront.net *.zendesk.com *.kayweb.com.au p-a.io *.particularaudience.com *.services.qantasloyalty.com *.zip.co *.zipmoney.com.au *.digidirect.com.au 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.magento.com *.adobe.io performance.typekit.net commerce.adobe.io *.magento-datasolutions.com *.magento-ds.com *.sentry.io *.afterpay.com *.afterpay-beta.com *.afterpaycdn.com *.squarecdn.com *.cash.app api.lab.amplitude.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io *.zendesk.com *.cloudflare.com *.paypal.com t.cfjump.com settings.luckyorange.net *.particularaudience.com stats.g.doubleclick.net *.google-analytics.com tags.srv.stackadapt.com secure.studio19.com.au secure.polygongroup.com.au bam-cell.nr-data.net *.similarinc.com *.api.similarinc.com *.zipmoney.com.au *.visitors.live *.googleapis.com *.zdassets.com digidirect.zendesk.com *.zip.co api.smooch.io *.gstatic.com *.google.com *.klarnacdn.net *.cardinalcommerce.com *.cardinaltrusted.com *.demdex.net *.braintree-api.com *.braintreegateway.com *.wibmo.com *.paypal.cn *.paypalobjects.com *.kayweb.com.au p-a.io *.qantasloyalty.com *.services.qantasloyalty.com api-recs.particularaudience.com d10lpsik1i8c69.cloudfront.net *.static.afterpay.com *.doubleclick.net *.clarity.ms wss://in.visitors.live visitors.live insight.adsrvr.org api-preview.luckyorange.com *.digidirect.com digidirect.pxf.io d.impct.site https://www.eventbriteapi.com https://corsproxy.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com google.com *.facebook.net 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.images.latitudepayapps.com *.imageapi.magebinary.co.nz 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 worker-src *.mczbf.com; font-src *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.fontawesome.com https://geowidget.easypack24.net *.cj.com maxcdn.bootstrapcdn.com *.cloudflare.com *.twitter.com *.typekit.net *.twimg.com *.trustedshops.com *.googleapis.com data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com *.googlesyndication.com facebook.com *.twitter.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com secure.authorize.net test.authorize.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com pay.google.com play.google.com *.autopay.eu *.packeta.com creativecdn.com ct.pinterest.com *.criteo.com *.criteo.net pudofinder.dpd.com.pl googletagmanager.com *.googletagmanager.com www.googletagmanager.com secure.payu.com merch-prod.snd.payu.com *.twitter.com *.wesupply.xyz https://wesupplylabs.com *.weltpixel.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net data: www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com validator.swagger.io *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.gstatic.com *.googlesyndication.com platnosci.bm.pl platnosci-accept.bm.pl www.gstatic.com *.autopay.eu https://geowidget.easypack24.net *.easypack24.net *.inpost.pl *.openstreetmap.org www.googleadservices.com www.google-analytics.com www.google.pl bat.bing.com mrtg.emailpartners.net pixel.wp.pl ct.pinterest.com scontent-waw1-1.cdninstagram.com adservice.google.pl c.clarity.ms c.bing.com *.mczbf.com *.kdukvh.com *.emjcd.com *.dotomi.com *.adnxs.com contextual.media.net pixel.rubiconproject.com match.sharethrough.com rtb-csync.smartadserver.com sync-t1.taboola.com criteo-sync.teads.tv eb2.3lift.com ups.analytics.yahoo.com visitor.omnitagjs.com id5-sync.com ad.360yield.com criteo-partners.tremorhub.com beacon.krxd.net gum.criteo.com s.thebrighttag.com ad.yieldlab.net *.seznam.cz *.bing.net duka.com *.duka.com *.criteo.net static.payu.com *.googleapis.com *.googleusercontent.com *.cloudflare.com *.klarna.com *.googleadservices.com *.google-analytics.com *.paypal.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.cloudfront.net data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com secure.authorize.net test.authorize.net www.paypalobjects.com js.braintreegateway.com www.paypal.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.gstatic.com *.googlesyndication.com *.autopay.eu pay.google.com *.packeta.com https://geowidget.easypack24.net *.easypack24.net *.inpost.pl *.openstreetmap.org www.googleadservices.com www.google-analytics.com static.hotjar.com bat.bing.com www.clarity.ms analytics.tiktok.com dsp-media.eskimi.com cdn.gdprcookiemanager.com cdn.tmtarget.com www.googleoptimize.com s.pinimg.com pixel.homebook.pl pixel.wp.pl js-agent.newrelic.com bam-cell.nr-data.net script.hotjar.com bam.nr-data.net *.mczbf.com *.cj.com *.criteo.net sslwidget.criteo.com googletagmanager.com *.clarity.ms *.seznam.cz paypalobjects.com secure.payu.com secure.snd.payu.com *.cloudflare.com *.twitter.com *.twimg.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com *.autopay.eu *.fontawesome.com https://geowidget.easypack24.net *.cj.com maxcdn.bootstrapcdn.com *.cloudflare.com *.twitter.com *.twimg.com *.typekit.net *.trustedshops.com *.usercentrics.eu 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com https://geowidget.easypack24.net 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.google-analytics.com *.facebook.com *.facebook.net *.google.com *.doubleclick.net *.googlesyndication.com *.packeta.com *.easypack24.net *.inpost.pl *.openstreetmap.org www.google-analytics.com cdn.gdprcookiemanager.com analytics.tiktok.com n.clarity.ms ct.pinterest.com stats.g.doubleclick.net bam.nr-data.net in.hotjar.com dsp-trk.eskimi.com dsp-ap.eskimi.com *.mczbf.com *.sjwoe.com p.clarity.ms google.com *.clarity.ms googletagmanager.com *.googletagmanager.com *.bing.net *.hotjar.io *.criteo.net *.criteo.com secure.payu.com merch-prod.snd.payu.com *.googleapis.com *.gstatic.com *.cloudflare.com *.twitter.com *.paypal.com *.twimg.com t.elasticsuite.io 'self' 'unsafe-inline'; child-src *.cj.com http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri http://csp-reporting-service.com/my-project/endpoint; report-to report-endpoint; 1 default-src * data: 'unsafe-eval' 'unsafe-inline' blob: 1 default-src 'self';base-uri 'self';frame-ancestors 'self';frame-src https://* 'self' epichttp: https://pay.instamed.com;script-src 'nonce-dd4df0a42022478aa393a14695bce6bd' https://az-mychart.franciscanalliance.org 'self';img-src https://* 'self' blob: data:;connect-src 'self' epichttp:;style-src https://az-mychart.franciscanalliance.org 'self' 'unsafe-inline';worker-src 'self' blob:;child-src 'self' blob:;form-action https://central.mychart.org/MyChart/ 'self';media-src https://* 'self' blob:; 1 base-uri 'self' ; connect-src https://*.ampproject.org https://*.appsflyer.com https://bat.bing.com https://*.clarity.ms https://*.cloudfront.net https://*.compare.com https://*.criteo.com https://*.criteo.net https://stats.g.doubleclick.net https://www.facebook.com https://app.five9.com https://*.google-analytics.com https://*.google.com https://*.googleapis.com https://www.googletagmanager.com https://*.insurify.com https://insurify.com https://insurifycdn.com https://*.klaviyo.com https://*.makestories.io https://*.mixpanel.com https://*.mxpnl.com https://*.pinterest.com wss://ws.pusherapp.com https://insurify.sjv.io https://*.snapchat.com https://lux.speedcurve.com https://analytics.tiktok.com https://widget.trustpilot.com https://*.usersnap.com https://ifrm.insurify.com https://browser-intake-datadoghq.com 'self' ; default-src 'self' ; font-src https://*.insurify.com https://fonts.gstatic.com https://*.bootstrapcdn.com https://insurifycdn.com https://widget.trustpilot.com https://ifrm.insurify.com 'self' data: ; form-action https://www.facebook.com https://tr.snapchat.com https://widget.trustpilot.com https://ifrm.insurify.com 'self' ; frame-ancestors 'self' ; frame-src https://insight.adsrvr.org https://match.adsrvr.org https://cj.dotomi.com https://*.doubleclick.net https://www.emjcd.com https://www.facebook.com https://*.pinterest.com https://www.quotelab.com https://tr.snapchat.com https://www.googletagmanager.com https://widget.trustpilot.com https://app.usecanopy.com https://ifrm.insurify.com 'self' ; img-src https://*.google.com https://*.googleapis.com https://www.google.bg https://www.google.com.pk https://www.googletagmanager.com https://maps.gstatic.com https://ib.adnxs.com https://*.appsflyer.com https://segment.prod.bidr.io https://*.bing.com https://*.clarity.ms https://*.cloudfront.net https://*.compare.com https://*.doubleclick.net https://www.facebook.com https://*.google-analytics.com https://www.gstatic.com https://insurifycdn.com *.makestories.io https://*.mediaalpha.com https://*.nextinsure.com https://*.pinterest.com https://www.shopperapproved.com https://*.snapchat.com https://lux.speedcurve.com https://*.storyblok.com https://cdn.transparent.ly https://widget.trustpilot.com https://*.usersnap.com 'self' data: ; media-src *.googlevideo.com 'self' ; script-src https://*.google.com https://*.googleapis.com https://www.google.bg https://www.google.com.pk https://maps.gstatic.com https://acdn.adnxs.com https://js.adsrvr.org *.ampproject.org https://*.appsflyer.com https://bat.bing.com https://*.bootstrapcdn.com https://*.clarity.ms https://*.cloudflare.com https://*.cloudfront.net https://*.compare.com https://*.criteo.com https://*.criteo.net https://googleads.g.doubleclick.net https://connect.facebook.net https://app.five9.com https://*.google-analytics.com https://www.googleadservices.com https://www.googletagmanager.com https://d.impactradius-event.com https://*.insurify.com https://insurifycdn.com https://*.jquery.com https://*.klaviyo.com https://insurance.mediaalpha.com https://*.mixpanel.com https://*.mxpnl.com https://s.pinimg.com https://*.pinterest.com https://sc-static.net https://www.shopperapproved.com https://cdn.speedcurve.com https://analytics.tiktok.com https://widget.trustpilot.com https://unpkg.com https://*.usersnap.com https://ifrm.insurify.com 'self' 'unsafe-inline' 'unsafe-eval' ; style-src https://fonts.googleapis.com https://*.bootstrapcdn.com https://*.googleapis.com https://*.ampproject.org https://widget.trustpilot.com https://ifrm.insurify.com 'self' 'unsafe-inline' ; worker-src 'self' blob: ; report-uri https://report-uri.insurify.com/json; 1 object-src 'none';base-uri 'self';script-src 'nonce-cCWCYZSZ330geZJ0JUUuHQ' 'strict-dynamic' 'report-sample' 'unsafe-eval' 'unsafe-inline' https: http:;report-uri https://csp.withgoogle.com/csp/gws/other-hp 1 default-src 'self';base-uri 'self';frame-ancestors 'self';frame-src https://* 'self' epichttp: https://UMHEALTHCAREEPICIFRAME-PP-PRTLTST.SPECTRUMRETAILNET.COM https://umhealthcareepiciframe-pp-prtl.spectrumretailnet.com;script-src 'nonce-416f8aee7ce94612820732eb2775472d' https://myuhealthchart.com 'self';img-src https://* 'self' blob: data:;connect-src 'self' epichttp:;style-src https://myuhealthchart.com 'self' 'unsafe-inline';worker-src 'self' blob:;child-src 'self' blob:;form-action https://central.mychart.org/MyChart/ 'self';media-src https://* 'self' blob:; 1 object-src 'none'; script-src 'self' https://fonts.googleapis.com cdn.jsdelivr.net https://api.mapbox.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://maps.googleapis.com https://unpkg.com unpkg.com; script-src-attr 'self'; script-src-elem 'self' cdn.jsdelivr.net https://api.mapbox.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://maps.googleapis.com https://unpkg.com unpkg.com; style-src 'self' https://api.mapbox.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://unpkg.com; style-src-attr 'self'; frame-ancestors 'self' 1 frame-ancestors 'self' *.preview.devprod.cloudflare.dev;frame-src 'self' www.youtube.com player.vimeo.com www.recaptcha.net www.google.com www.googletagmanager.com sgtm-cr.vistra.com *.hsforms.com td.doubleclick.net consentcdn.cookiebot.com s.company-target.com cdn.yoshki.com cdn.userway.org platform.twitter.com; report-uri https://vistragroup.com/csp-report 1 font-src fonts.gstatic.com use.typekit.net *.klevu.com *.ksearchnet.com *.fontawesome.com *.googleapis.com *.gstatic.com *.cloudflare.com *.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cybersource.com *.facebook.com *.cardinalcommerce.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.dotdigital-pages.com *.dotdigital.com webchat.dotdigital.com webchat.staging.dotdigital.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com *.cybersource.com https://www.google.com https://www.facebook.com *.doubleclick.net *.cardinalcommerce.com https://h.online-metrix.net 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com p.typekit.net *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net *.trackedlink.net *.klevu.com *.ksearchnet.com magefan.com cm.magefan.com *.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.online-metrix.net *.google.com *.google.co.in *.doubleclick.net *.hsforms.com *.hubspot.com *.googletagmanager.com *.nr-data.net https://trains.walthers.com/hubfs/Ma_yJuhneJoly2o2l-flyer_CONs-1.jpg https://cdnjs.cloudflare.com/ajax/libs/tinymce/4.9.6/skins/lightgray/img/trans.gif data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com amcglobal.sc.omtrdc.net *.adobe.io use.typekit.net s.ytimg.com www.googleapis.com *.vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-datasolutions.com *.magento-ds.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal webchat.dotdigital.com webchat.staging.dotdigital.com js.klevu.com *.ksearchnet.com *.fontawesome.com *.googleapis.com *.gstatic.com *.facebook.net connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com *.online-metrix.net *.googletagmanager.com *.google.com *.google.co.in *.hs-analytics.net *.hs-scripts.com *.hscollectedforms.net *.hs-banner.com *.hsleadflows.net *.hsadspixel.net *.doubleclick.net *.loyaltylion.net *.klevu.com https://cdn.equalweb.com http://assets.adobedtm.com https://h64.online-metrix.net *.hsforms.net https://js.klevu.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com webchat.dotdigital.com webchat.staging.dotdigital.com *.klevu.com *.ksearchnet.com *.fontawesome.com *.cloudflare.com *.bootstrapcdn.com *.loyaltylion.net https://statsjs.klevu.com https://js.klevu.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.amazonaws.com *.walthers.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com api.magento.com *.adobe.io performance.typekit.net commerce.adobe.io *.magento-datasolutions.com *.magento-ds.com *.sentry.io *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com *.klevu.com *.ksearchnet.com *.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.cardinalcommerce.com *.online-metrix.net *.google.com *.google-analytics.com *.doubleclick.net *.hubspot.com *.hubapi.com *.hs-banner.com *.walthers.com *.googleapis.com https://cdn.equalweb.com *.loyaltylion.net *.loyaltylion.com https://forms.hscollectedforms.net https://kg668dbov0.execute-api.us-east-1.amazonaws.com *.hsforms.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com https://fonts.gstatic.com https://www.google.com https://www.gstatic.com *.googleapis.com maxcdn.bootstrapcdn.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com 'self' 'unsafe-inline'; frame-ancestors *.certcapture.com self www.google.com *.stripe.com stripe.com *.link.com *.amazon.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.certcapture.com www.google.com www.gstatic.com apis.google.com accounts.google.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com landofcoder.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.certcapture.com flagpedia.net *.googleapis.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com commerce-payments-sdk.adobe.io www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.certcapture.com *.googleapis.com *.gstatic.com accounts.google.com *.fontawesome.com *.sharethis.com maps.googleapis.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com landofcoder.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.certcapture.com *.fontawesome.com *.googleapis.com *.google.com *.gstatic.com accounts.google.com maxcdn.bootstrapcdn.com *.stripe.network *.stripecdn.com *.amazon.com 'self' 'unsafe-inline'; object-src landofcoder.com 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.certcapture.com http://dpm.demdex.net https://www.google.com https://www.gstatic.com accounts.google.com *.sharethis.com www.gstatic.com maps.googleapis.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com landofcoder.com *.googleapis.com 'self' 'unsafe-inline'; child-src *.certcapture.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' *.itrustcapital.com; script-src *.itrustcapital.com https://www.googletagmanager.com 'unsafe-inline' 'self' ; style-src 'self' *.itrustcapital.com use.fontawesome.com 'unsafe-inline' https://www.google-analytics.com; font-src 'self' *.itrustcapital.com use.fontawesome.com 'unsafe-inline'; connect-src sdk.iad-05.braze.com api.amplitude.com dataschemasprodstorage.blob.core.windows.net *.alloy.co https://rum.browser-intake-us3-datadoghq.com https://www.googletagmanager.com 'self' *.itrustcapital.com https://www.google-analytics.com www.google-analytics.com https://stats.g.doubleclick.net wss:; img-src 'self' *.itrustcapital.com https://www.google-analytics.com www.google-analytics.com https://stats.g.doubleclick.net blob:; object-src 'none'; frame-src https://www.googletagmanager.com; report-uri https://csp-report.browser-intake-us3-datadoghq.com/api/v2/logs?dd-api-key=pubb464f8903d11bb4c37d5cbb555ed196a&dd-evp-origin=content-security-policy&ddsource=csp-report&ddtags=csp-report; report-to default 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com fonts.googleapis.com *.hotjar.com *.zopim.com *.fontawesome.com data: *.google.com https://fonts.bunny.net 'self' data: www.dufrio.com.br data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com *.pagar.me *.netsgroup.com *.sibs.pt *.seglan.com *.secureacs.com *.rsa3dsauth.com *.apata.io *.cardinalcommerce.com *.santander.com.br *.bradesco.com.br *.bradesco *.stone.com.br *.nubank.com.br *.itau.com.br *.bb.com.br *.caixa.gov.br *.inter.co *.bancointer.com.br *.c6bank.com.br *.bancobmg.com.br *.safra.com.br *.sicoob.com.br *.banrisul.com.br *.banrisul.b.br *.banorte.com *.xpi.com.br *.btgpactual.com *.btgpactualdigital.com *.mercadopago.com.br *.mercadopago.com *.picpay.com *.amedigital.com *.neon.tech *.neon.com.br *.wise.com *.revolut.com *.sandbox.3dsecure.io *.google.com www.dufrio.com.br 'self' 'unsafe-inline'; frame-ancestors www.dufrio.com.br 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com cdn.dnky.co *.hotjar.com *.facebook.com *.trustpilot.com *.criteo.com *.mercadopago.com *.mercadolibre.com *.pagar.me *.netsgroup.com *.sibs.pt *.seglan.com *.secureacs.com *.rsa3dsauth.com *.apata.io *.cardinalcommerce.com *.santander.com.br *.bradesco.com.br *.bradesco *.stone.com.br *.nubank.com.br *.itau.com.br *.bb.com.br *.caixa.gov.br *.inter.co *.bancointer.com.br *.c6bank.com.br *.bancobmg.com.br *.safra.com.br *.sicoob.com.br *.banrisul.com.br *.banrisul.b.br *.banorte.com *.xpi.com.br *.btgpactual.com *.btgpactualdigital.com *.mercadopago.com.br *.picpay.com *.amedigital.com *.neon.tech *.neon.com.br *.wise.com *.revolut.com *.sandbox.3dsecure.io www.dufrio.com.br *.voxus.tv *.btg360.com.br *.criteo.net *.awin1.com *.zenaps.com td.doubleclick.net *.yandex.ru *.orpen.com.br *.mainadv.com *.datalivemarketing.com.br www.googletagmanager.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.googleapis.com https://images.unsplash.com *.google.com *.google.nl connect.onlinesucces.nl px.ads.linkedin.com stats.g.doubleclick.net *.linkedin.com *.googletagmanager.com gallery.mailchimp.com *.trustedshops.com *.facebook.com *.zopim.com cdn.jsdelivr.net *.jmango360.com *.datatrics.com *.smaato.net *.google-analytics.com ssl.gstatic.com www.gstatic.com *.ebit.com.br *.ebitempresa.com.br *.mercadopago.com *.mlstatic.com *.mercadolibre.com *.mercadolivre.com.br *.mercadolibre.com.mx *.mercadolibre.com.ar *.mercadolivre.com cdn.mundipagg.com api.pagar.me *.caravelx.com https://firebasestorage.googleapis.com *.hsforms.net *.hsforms.com 'self' data: www.dufrio.com.br *.dufrio.com.br s3.amazonaws.com newimgebit-a.akamaihd.net *.bing.com *.google.com.br *.adnxs.com *.mercadopago.com.br *.btg360.com.br *.criteo.com *.mediavine.com *.bluekai.com *.adgrx.com *.casalemedia.com *.yahoo.com *.3lift.com *.teads.tv *.taboola.com *.smartadserver.com *.sharethrough.com *.rubiconproject.com *.media.net *.doubleclick.net *.bidswitch.net *.emxdgt.com *.yieldmo.com *.clmbtech.com *.socdm.com *.omnitagjs.com *.stickyadstv.com *.360yield.com *.ivitrack.com *.liadm.com *.outbrain.com *.pubmatic.com *.revcontent.com *.tremorhub.com *.awin1.com *.zenaps.com *.yahoo.net *.postrelease.com *.aralego.com *.aralego.net *.dmxleo.com *.clearsale.com.br *.yandex.ru *.clarity.ms *.microsoftonline.com *.caravel.store *.orpen.com.br *.unrulymedia.com *.live.sma.ia.br *.agkn.com sync.1rx.io dufrio-my.sharepoint.com *.syndigo.cloud *.syndigo.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.googleapis.com *.gstatic.com *.paypal.com *.googletagmanager.com *.googleadservices.com cdn.dnky.co api.comapi.com *.trackedlink.net snap.licdn.com chimpstatic.com checkout.buckaroo.nl *.adyen.com *.zopim.com *.hotjar.com *.zdassets.com *.sendcloud.sc *.mailchimp.com *.trustedshops.com *.fontawesome.com *.facebook.net *.feedbackcompany.com *.google-analytics.com *.trustpilot.com cdn.jsdelivr.net *.googleoptimize.com *.clarity.ms *.datatrics.com *.criteo.net *.criteo.com cdn.mouseflow.com tagmanager.google.com *.ebit.com.br *.mercadopago.com *.mlstatic.com 3ds2.pagar.me 3ds2-sdx.pagar.me connect.facebook.net js.huggy.chat *.avada.io *.hsforms.net *.hsforms.com www.dufrio.com.br self s3.amazonaws.com *.voxus.com.br *.bing.com *.btg360.com.br *.adcart.com.br *.dwin1.com *.afilio.com.br *.awin1.com *.zenaps.com *.sciencebehindecommerce.com *.clearsale.com.br *.cloudflareinsights.com *.k-analytix.com *.yandex.ru unsafe-inline *.dufrio.com.br *.cloudfront.net *.orpen.com.br *.tiktok.com *.datalivemarketing.com.br *.syndigo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com cdn.dnky.co checkout.buckaroo.nl *.fontawesome.com *.mailchimp.com *.trustpilot.com cdn.jsdelivr.net tagmanager.google.com fonts.google.com *.ebit.com.br *.mercadopago.com *.google.com webfonts.huggy.cloud https://fonts.bunny.net *.gstatic.com www.dufrio.com.br s3.amazonaws.com *.orpen.com.br 'self' 'unsafe-inline'; object-src www.dufrio.com.br 'self' 'unsafe-inline'; media-src *.adobe.com *.zopim.com www.dufrio.com.br *.syndigo.com 'self' 'unsafe-inline'; manifest-src www.dufrio.com.br 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net *.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.googleapis.com commerce.adobedc.net api.comapi.com stats.g.doubleclick.net *.zdassets.com *.hotjar.com *.hotjar.io *.zopim.com wss://*.zopim.com *.feedbackcompany.com *.zendesk.com *.clarity.ms *.facebook.com *.datatrics.com *.analytics.google.com *.googletagmanager.com https://hits-banner-cloud-function.azurewebsites.net *.mercadopago.com maps.googleapis.com *.mercadolibre.com api.mundipagg.com api.pagar.me brasilapi.com.br viacep.com.br servicodados.ibge.gov.br pay.sandbox.google.com wss://ct-socket.huggy.app widget.huggy.io https://get.geojs.io *.avada.io t.elasticsuite.io *.hsforms.net *.hsforms.com www.dufrio.com.br *.reclameaqui.com.br *.voxus.tv *.voxus.com.br *.loggly.com *.ipify.org *.google.com.br *.criteo.com *.bing.com *.us-east-2.on.aws *.sciencebehindecommerce.com *.wepowerconnections.com *.akamaihd.net *.konduto.com *.mailbiz.one *.cloudfront.net *.tiktok.com *.pangle-ads.com *.yandex.ru *.tiktokw.us *.datalivemarketing.com.br wss://mc.yandex.ru/solid.ws wss://socket.live.sma.ia.br/ws wss://socket.live.sma.ia.br/ws/ *.syndigo.com 'self' 'unsafe-inline'; child-src www.dufrio.com.br http: https: blob: 'self' 'unsafe-inline'; default-src *.googleapis.com www.dufrio.com.br *.google.com.br 'self' 'unsafe-inline' 'unsafe-eval'; base-uri www.dufrio.com.br 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.cloudflare.com *.twitter.com *.facebook.net *.twimg.com *.hotjar.com *.trustedshops.com *.googleapis.com *.magentocommerce.com *.paypal.com *.cardinalcommerce.com *.authorize.net *.fontawesome.com https://fonts.bunny.net *.mncdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.paypal.com *.twitter.com *.facebook.com 'self' 'unsafe-inline'; frame-ancestors *.google.com *.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com https://www.googletagmanager.com/ *.twitter.com *.gstatic.com *.hotjar.com *.google.com.tr *.veinteractive.com *.demdex.net *.solocpm.com *.facebook.com *.facebook.net *.addthis.com *.livechatinc.com *.yandex.ru *.adyen.com *.vimeo.com *.doubleclick.net *.bluekai.com *.useinsider.com *.asseco-see.com.tr *.param.com.tr *.modirum.com 'self' 'unsafe-inline'; img-src *.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net data: *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.swagger.io *.paypal.com *.typekit.net *.gstatic.com https://images.unsplash.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ *.cloudflare.com *.klarna.com *.googleadservices.com *.google-analytics.com *.paypalobjects.com *.hotjar.com *.twitter.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.magentocommerce.com *.cardinalcommerce.com *.authorize.net *.omtrdc.net *.newrelic.com *.doubleclick.net *.google.com *.google.com.tr *.facebook.com *.facebook.net *.demdex.net *.everesttech.net *.googleapis.com *.adis.ws *.livechatinc.com *.yandex.ru *.adyen.com *.setrowid.com *.setrow.com *.instagram.com *.useinsider.com *.googletagmanager.com https://firebasestorage.googleapis.com *.mncdn.com *.asseco-see.com.tr *.param.com.tr *.modirum.com *.mobilexpress.com.tr *.google.nl *.google.be *.segmentify.com *.sgmntfy.com *.vicco.com.tr *.yandex.com yandex.com *.yads.tech *.sharethis.com *.googlesyndication.com yandex.ru *.cloudflareinsights.com *.betweendigital.com *.bluevoox.com *.yandex.com.tr *.adkernel.com *.lunamedia.live *.bidswitch.net *.digital-services.solutions *.revotas.com *.quilljs.com *.yango.com *.opera.com vicco-middleware.mncdn.com pro.ip-api.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com commerce-payments-sdk.adobe.io s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://maps.googleapis.com https://player.vimeo.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ *.cloudflare.com *.twitter.com *.google-analytics.com *.twimg.com *.gstatic.com *.trustedshops.com *.usercentrics.eu *.fontawesome.com *.magentocommerce.com *.paypal.com *.hotjar.com *.cardinalcommerce.com *.authorize.net *.omtrdc.net *.instana.io *.google.com.tr *.googletagmanager.com *.veinteractive.com *.facebook.net *.supert.ag *.setrowid.com *.mainadv.com *.doubleclick.net *.googleapis.com *.addthis.com *.moatads.com *.addthisedge.com *.livechatinc.com *.yandex.ru *.adyen.com *.vimeo.com *.jsdelivr.net *.setrow.com *.instagram.com *.criteo.com *.criteo.net *.ciritizr.com *.bkrtx.com *.cloudfront.net *.useinsider.com *.critizr.com *.behance.net *.swagger.io *.avada.io *.shopify.com *.mncdn.com *.asseco-see.com.tr *.param.com.tr *.modirum.com *.mobilexpress.com.tr *.segmentify.com *.sgmntfy.com *.cookiespool.com *.vicco.com.tr *.yandex.com yandex.com *.yads.tech *.sharethis.com *.googlesyndication.com yandex.ru *.cloudflareinsights.com *.betweendigital.com *.bluevoox.com *.yandex.com.tr *.adkernel.com *.lunamedia.live *.bidswitch.net *.digital-services.solutions *.revotas.com *.quilljs.com *.jquery.com *.yango.com *.opera.com vicco-middleware.mncdn.com pro.ip-api.com *.adform.net s2.adform.net track.adform.net 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.facebook.net *.cloudflare.com *.googleapis.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.magentocommerce.com *.fontawesome.com *.paypal.com *.paypalobjects.com *.hotjar.com *.cardinalcommerce.com *.authorize.net *.omtrdc.net *.newrelic.com *.setrowid.com *.setrow.com *.critizr.com *.useinsider.com *.adobedtm.com *.google-analytics.com *.googletagmanager.com *.swagger.io https://fonts.bunny.net *.mncdn.com *.google.com *.jsdelivr.net *.segmentify.com *.sgmntfy.com *.vicco.com.tr *.yandex.com yandex.com *.yads.tech *.sharethis.com *.googlesyndication.com *.yandex.ru *.cloudflareinsights.com *.betweendigital.com *.bluevoox.com *.yandex.com.tr *.adkernel.com *.lunamedia.live *.bidswitch.net *.digital-services.solutions *.revotas.com *.quilljs.com *.yango.com *.opera.com vicco-middleware.mncdn.com pro.ip-api.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ *.google.com *.jsdelivr.net *.segmentify.com *.sgmntfy.com *.vicco.com.tr *.yandex.com yandex.com *.yads.tech *.sharethis.com *.googlesyndication.com *.yandex.ru yandex.ru *.cloudflareinsights.com *.betweendigital.com *.bluevoox.com *.yandex.com.tr *.adkernel.com *.lunamedia.live *.bidswitch.net *.digital-services.solutions *.revotas.com *.quilljs.com *.yango.com *.opera.com vicco-middleware.mncdn.com vicco-videos.lg.mncdn.com pro.ip-api.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net *.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com https://maps.googleapis.com https://player.vimeo.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ *.cloudflare.com *.google-analytics.com *.doubleclick.net *.twitter.com *.facebook.com *.facebook.net *.paypalobjects.com *.hotjar.com *.hotjar.io *.twimg.com *.magentocommerce.com *.cardinalcommerce.com *.cardinalcommerce.net *.veinteractive.com *.demdex.net *.yandex.ru *.vimeo.com *.setrowid.com *.setrow.com *.useinsider.com *.adobedtm.com *.swagger.io https://get.geojs.io *.avada.io *.segmentify.com *.sgmntfy.com *.googleapis.com *.cookiespool.com *.vicco.com.tr *.yandex.com yandex.com *.yads.tech *.sharethis.com *.googlesyndication.com yandex.ru *.cloudflareinsights.com *.betweendigital.com *.bluevoox.com *.yandex.com.tr *.adkernel.com *.lunamedia.live *.bidswitch.net *.digital-services.solutions *.revotas.com *.quilljs.com *.yango.com *.opera.com vicco-middleware.mncdn.com pro.ip-api.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.googleapis.com fonts.gstatic.com *.googleapis.com *.gstatic.com data: https://fonts.gstatic.com *.fontawesome.com maxcdn.bootstrapcdn.com https://geowidget.easypack24.net 'self' data: https://secure.tpay.com https://secure.sandbox.tpay.com https://tpay.com *.cloudflare.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com 'self' 'unsafe-inline'; frame-ancestors www.gstatic.com 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.google.com *.awin1.com *.zenaps.com *.fls.doubleclick.net c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * https://geowidget-app.inpost.pl/ *.weltpixel.com https://secure.tpay.com https://secure.sandbox.tpay.com https://tpay.com facebook.com *.cookiebot.com creativecdn.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io https://images.unsplash.com maps.googleapis.com maps.gstatic.com *.gstatic.com *.googleapis.com *.awin1.com *.zenaps.com *.salesmanago.pl *.salesmanago.es *.salesmanago.com magefan.com cm.magefan.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com https://geowidget.easypack24.net *.easypack24.net *.inpost.pl *.openstreetmap.org *.hsforms.net *.hsforms.com 'self' data: https://maps.gstatic.com https://maps.googleapis.com *.facebook.com https://secure.tpay.com https://secure.sandbox.tpay.com https://tpay.com *.bing.com garett.com.pl google.pl facebook.com trustmate.io www.google.pl *.clarity.ms blob: *.credit-agricole.pl lantern.roeye.com *.googlesyndication.com awin1.com google.com s3-eu-west-1.amazonaws.com salesmanago.s3-eu-west-1.amazonaws.com conversionlabs.net.pl *.cookiebot.com *.trustmate.io img.sct.eu1.usercentrics.eu data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.googleapis.com *.gstatic.com https://cdn.jsdelivr.net/npm/@ryangjchandler/spruce@2.x.x/dist/spruce.umd.js www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.awin1.com www.dwin1.com *.zenaps.com https://the.sciencebehindecommerce.com *.salesmanago.pl *.salesmanago.es *.salesmanago.com https://scripts.luigisbox.com https://cdn.luigisbox.com https://live.luigisbox.com https://api.luigisbox.com *.avada.io js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com https://geowidget.easypack24.net *.easypack24.net *.inpost.pl *.openstreetmap.org *.hsforms.net *.hsforms.com *.google.com https://maps.googleapis.com https://www.googletagmanager.com tagmanager.google.com *.facebook.net unpkg.com https://secure.tpay.com https://secure.sandbox.tpay.com https://tpay.com *.cookiebot.com rum.uptime.com *.buybox.click *.cloudflare.com *.hotjar.com bat.bing.com *.callpage.io trustmate.io analytics.tiktok.com *.clickonometrics.pl *.clarity.ms *.dwin1.com callpage.io *.roeyecdn.com *.googlesyndication.com awin1.com *.cookiebot.eu https://scripts.luigisbox.com https://cdn.luigisbox.com *.luigisbox.com https://scripts.luigisbox.tech https://cdn.luigisbox.tech *.luigisbox.tech *.facebook.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com https://scripts.luigisbox.com https://cdn.luigisbox.com https://live.luigisbox.com https://api.luigisbox.com https://fonts.googleapis.com *.gstatic.com *.googleapis.com *.fontawesome.com maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com https://geowidget.easypack24.net https://geowidget.inpost.pl tagmanager.google.com https://secure.tpay.com https://secure.sandbox.tpay.com https://tpay.com *.callpage.io *.cloudfront.net trustmate.io sandbox-easy-geowidget-sdk.easypack24.net *.luigisbox.com https://cdn.luigisbox.tech *.luigisbox.tech 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com https://geowidget.easypack24.net *.callpage.io 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com maps.googleapis.com maps.gstatic.com fonts.googleapis.com *.googleapis.com https://the.sciencebehindecommerce.com *.salesmanago.pl *.salesmanago.es *.salesmanago.com https://scripts.luigisbox.com https://cdn.luigisbox.com https://live.luigisbox.com https://api.luigisbox.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.easypack24.net *.inpost.pl *.openstreetmap.org t.elasticsuite.io *.hsforms.net *.hsforms.com *.google-analytics.com https://maps.googleapis.com *.facebook.net https://secure.tpay.com https://secure.sandbox.tpay.com https://tpay.com stats.g.doubleclick.net *.cookiebot.com *.googlesyndication.com stream.cloud.witbee.com *.cloudflare.com rum.uptime.com *.callpage.io vc-service.saleago.com googleads.g.doubleclick.net analytics.tiktok.com *.clarity.ms wss://*.salesmanago.com wss://*.hotjar.com *.hotjar.io delivery.clickonometrics.pl trustmate.io facebook.com *.cookiebot.eu https://api.luigisbox.com https://live.luigisbox.com https://app.luigisbox.com *.luigisbox.com analytics-ipv6.tiktokw.us https://api.luigisbox.tech https://live.luigisbox.tech https://app.luigisbox.tech *.luigisbox.tech 'self' 'unsafe-inline'; child-src *.awin1.com *.zenaps.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.salesmanago.pl *.salesmanago.es *.salesmanago.com *.googleapis.com *.google.com *.facebook.com *.cookiebot.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src blob: https://*.mhcache.com;font-src 'self' https://*.myheritage.com https://*.mhcache.com https://fonts.gstatic.com;frame-src 'self' https://*.mhcache.com https://portal.allyable.com https://mh-site-files-5c53d6a9947c.s3.amazonaws.com https://myheritage-container.com https://www.myheritage-partners.com https://www.myheritage.com https://*.mk-sense.com https://player.vimeo.com https://*.facebook.com https://*.googleapis.com https://*.google.com https://tpc.googlesyndication.com https://*.doubleclick.net https://accounts.google.com/gsi/;script-src https://accounts.google.com/gsi/client https://www.datadoghq-browser-agent.com https://*.googleapis.com https://appleid.cdn-apple.com *.myheritage.cz https://www.myheritage.cz 'unsafe-eval' 'nonce-6fdf40f91d62fa05e6c8dd1c566aa7a4' 'strict-dynamic';style-src data: blob: 'unsafe-inline' 'self' https://*.myheritage.com https://*.mhcache.com https://fonts.googleapis.com https://accounts.google.com/gsi/style;connect-src data: 'self' https://*.myheritage.com https://portal.allyable.com https://*.mhcache.com https://adservice.google.com https://*.logs.datadoghq.com https://*.browser-intake-datadoghq.com https://browser-intake-datadoghq.com https://sentry.io https://*.bing.com https://*.facebook.com https://*.doubleclick.net https://*.mk-sense.com https://*.filae.com https://accounts.google.com/gsi/ https://www.google.com/pagead/landing https://*.googleapis.com https://maps.googleapis.com/maps/api/mapsjs/gen_204 https://translate.googleapis.com https://www.google.com/ccm/collect https://cdn.builder.io *.myheritage.cz;media-src 'self' https://*.myheritage.com https://*.mhcache.com;frame-ancestors 'self' https://builder.io;img-src * data:;object-src 'none';base-uri 'self' https://*.mhcache.com;report-uri /FP/API/ContentSecurityPolicy/report-violation.php?report_mode=report&canonical_page_id=/company/home/ 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com cdn.jsdelivr.net cdn.almapay.com *.googleapis.com *.almapay.com localhost *.louispion.fr *.evermaps.io *.octipas.net https://cdnjs.cloudflare.com *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com localhost *.louispion.fr *.evermaps.io *.octipas.net *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com *.getalma.eu *.almapay.com/ *.stripe.com/ *.checkout.com/ *.adyen.com/ *.doubleclick.net *.facebook.com *.criteo.com *.leadplace.fr *.pinterest.com *.vimeo.com *.rolex.com localhost *.louispion.fr *.evermaps.io *.octipas.net c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * https://www.googletagmanager.com/ js.mollie.com payment.direct.worldline-solutions.com payment.preprod.direct.worldline-solutions.com payment.anzworldline-solutions.com.au payment.preprod.anzworldline-solutions.com.au payment.payone.com payment.preprod.payone.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.googleapis.com https://images.unsplash.com *.cookielaw.org *.stickyadstv.com *.bing.com *.facebook.com *.teads.tv *.rubiconproject.com *.dmxleo.com *.liadm.com *.outbrain.com *.taboola.com *.smartadserver.com *.3lift.com *.360yield.com *.pubmatic.com *.casalemedia.com *.media.net *.adform.net *.omnitagjs.com *.sharethrough.com *.ivitrack.com *.mediavine.com *.smaato.net *.doubleclick.net *.yahoo.com *.emxdgt.com *.tremorhub.com *.adnxs.com *.analytics.yahoo.com *.bidswitch.net *.criteo.com *.thebrighttag.com *.krxd.net *.yieldmo.com id5-sync.com *.yieldlab.net *.pinterest.com *.rolex.com *.googletagmanager.com *.doubleclick.net px.ads.linkedin.com *.bing.net localhost *.louispion.fr *.evermaps.io *.octipas.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ https://www.google.com/ https://www.mollie.com https://www.google.fr https://api.mapbox.com *.tile.openstreetmap.org https://maps.googleapis.com https://maps.gstatic.com data: 'self' 'unsafe-inline' 'strict-dynamic'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com https://rum.hlx.page cdn.jsdelivr.net *.googleapis.com *.gstatic.comm https://maps.googleapis.com player.vimeo.com maps.googleapis.com *.googletagmanager.com *.cookielaw.org *.early-birds.fr *.msecnd.net *.onetrust.com *.beeroot.io *.bing.com *.facebook.net *.facebook.com advgame.fr *.cloudfront.net *.teads.tv *.doubleclick.net *.clarity.ms *.criteo.net *.criteo.com *.adnxs.com *.leadplace.fr *.pinimg.com *.h1d3n0tsoo-staging-easiwebforms.net *.easiconnect.io *.adleadevent.com *.rolex.com *.booxi.eu *.naver.net payment.direct.worldline-solutions.com *.hotjar.com *.hotjar.io wisepops.net louispion.fr.bhglmag2.dnd.fr rqz-galerieslafayette.com.bhglmag2.dnd.fr *.louispion.fr *.rqz-galerieslafayette.com payment.preprod.direct.worldline-solutions.com rum.hlx.page localhost *.evermaps.io *.octipas.net https://cdnjs.cloudflare.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com http://www.googletagmanager.com/ https://www.googletagmanager.com/ js.mollie.com payment.anzworldline-solutions.com.au payment.preprod.anzworldline-solutions.com.au payment.payone.com payment.preprod.payone.com 'self' 'unsafe-inline' 'unsafe-eval' 'strict-dynamic'; style-src *.adobe.com fonts.googleapis.com cdn.jsdelivr.net *.googletagmanager.com localhost *.louispion.fr *.evermaps.io *.octipas.net https://fonts.googleapis.com https://cdnjs.cloudflare.com assets.braintreegateway.com *.fontawesome.com 'self' 'unsafe-inline'; object-src localhost *.louispion.fr *.evermaps.io 'self' 'unsafe-inline'; media-src *.adobe.com localhost *.louispion.fr *.evermaps.io *.youtube-nocookie.com *.octipas.net http://www.googleadservices.com/ http://www.google-analytics.com/ https://www.googleadservices.com/ https://www.google-analytics.com/ 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io insights.algolia.io *.getalma.eu *.almapay.com *.googleapis.com https://maps.googleapis.com https://player.vimeo.com ct.pinterest.com *.google.fr *.gstatic.comm *.cookielaw.org *.onetrust.com *.clarity.ms *.advalo.com *.teads.tv *.beeroot.io *.bing.com *.pinterest.com *.googlesyndication.com *.adleadevent.com *.abstractapi.com *.data.gouv.fr *.rolex.com *.adobedtm.com *.hotjar.com *.hotjar.io wss://ws.hotjar.com wisepops.com *.wisepops.com wisepops.net *.wisepops.net louispion.fr.bhglmag2.dnd.fr rqz-galerieslafayette.com.bhglmag2.dnd.fr *.louispion.fr *.rqz-galerieslafayette.com payment.preprod.direct.worldline-solutions.com payment.direct.worldline-solutions.com *.googletagmanager.com px.ads.linkedin.com *.bing.net *.adnxs.com *.adsrvr.org localhost *.evermaps.io *.octipas.net api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com http://stats.g.doubleclick.net/ https://stats.g.doubleclick.net/ http://www.google-analytics.com/ https://www.google-analytics.com/ https://nominatim.openstreetmap.org payment.anzworldline-solutions.com.au payment.preprod.anzworldline-solutions.com.au payment.payone.com payment.preprod.payone.com 'self' 'unsafe-inline' 'strict-dynamic'; child-src localhost *.louispion.fr *.evermaps.io assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 default-src 'self' 'unsafe-inline' 'unsafe-eval' lojavirus.com.br *.lojavirus.com.br wake-components.fbitsstatic.net lojavirus.fbitsstatic.net *.wake.tech fbits.net nr-data.net newrelic.com google.com googletagmanager.com google-analytics.com facebook.net facebook.com jquery.com bootstrapcdn.com googleadservices.com yapay.com.br googlesyndication.com cloudflare.com cnt.my clearsale.com.br zdassets.com ebit.com.br traycheckout.com.br doubleclick.net ecommercemail.com.br online-metrix.net hertzen.com k-analytix.com zendesk.com citydsp.com *.fbits.net *.nr-data.net *.newrelic.com *.google.com *.googletagmanager.com *.google-analytics.com *.facebook.net *.facebook.com *.jquery.com *.bootstrapcdn.com *.yapay.com.br *.googleadservices.com *.cloudflare.com *.googlesyndication.com *.cnt.my *.ebit.com.br *.traycheckout.com.br *.clearsale.com.br *.zdassets.com *.k-analytix.com *.hertzen.com *.doubleclick.net *.ecommercemail.com.br *.online-metrix.net *.zendesk.com *.citydsp.com wss://signalr.fbits.net k-analytix.com *.k-analytix.com i.konduto.com *.yapay.com.br *.traycheckout.com.br h.online-metrix.net *.clearsale.com.br *.btg360.com.br dzpxyxks1bfmb.cloudfront.net *.zopim.com *.gstatic.com *.gstatic.com *.koin.com.br *.soclminer.com.br *.btg360.com.br *.socialminer.com signalrcore.fbits.net wss://signalrcore.fbits.net *.cloudfront.net *.mlstatic.com *.mercadopago.com *.mercadolibre.com *.mercadopago.com.br *.paypal.com *.paypalobjects.com *.fbits.store *.adyen.com *.pagar.me *.mundipagg.com *.getnet.com.br *.braintree-api.com *.braintreegateway.com *.pagseguro.com.br *.yourviews.com.br *.pagbank.com *.vindi.com.br *.cieloecommerce.cielo.com.br *.braspag.com.br *.pagador.com.br *.online-metrix.net *.ucarecdn.com *.uploadcare.com *.yviews.com.br *.lojaconfiavel.com *.lightwidget.com bt-wake-connector.com.br lojavirus.fbitsstatic.net *.fbitsstatic.net *.pagaleve.com.br *.pagaleve.io wake-api.pagaleve.com.br securegtm.despegar.com api.ipify.org browser-intake-datadoghq.com *.datadoghq-browser-agent.com *.datadoghq.com wake.koin.com.br paypal-wake.s3.us-east-1.amazonaws.com *.cardinalcommerce.com *.secureacs.com api.globalgetnet.com *.globalgetnet.com *.sandbox.3dsecure.io gstatic.com *.3dsecure.io *.visa.com *.wake.tech *.appmax.com.br *.tunagateway.com *.pagoexpress.com.br ; img-src https: data:; style-src https: 'unsafe-inline'; font-src https: data:; frame-ancestors *.lojavirus.com.br lojavirus.com.br; report-uri https://pub-csp.fbits.net/checkout_sem_carrinho; report-to https://pub-csp.fbits.net/checkout_sem_carrinho; worker-src 'self' blob:; 1 base-uri 'self';connect-src https://*.go-mpulse.net https://*.akstat.io 'self' https: *.sentry.io *.amplitude.com *.care.com *.carezen.net *.signalfx.com *.google-analytics.com *.analytics.google.com *.googletagmanager.com *.g.doubleclick.net font.google.com analytics.google.com tagmanager.google.com www.google.com https://*.hotjar.com https://vc.hotjar.io https://content.hotjar.io https://events.hotjar.io https://surveystats.hotjar.io wss://*.hotjar.com https://geolocation.onetrust.com;default-src 'self' wss://*.care.com *.care.com *.careapis.com *.carezen.net *.cdn-care.com care.com cdn-care.com www.gstatic.com www.google.com *.googlesyndication.com tags.tiqcdn.com tags-eu.tiqcdn.com tk.getwork.com tr.snapchat.com shareasale.com *.doubleclick.net apps.rokt.com bid.g.doubleclick.net tags.w55c.net *.linkedin.com www.pinterest.com carecom.sjv.io staging-pt.ispot.tv ct.pinterest.com;font-src 'self' data: https://www.care.com https://www.dev.carezen.net https://www.stg.carezen.net fonts.gstatic.com https://script.hotjar.com;frame-ancestors 'self';img-src data: blob: *;object-src 'none';script-src https://*.go-mpulse.net 'nonce-a9bec56a35ca7ea1ec1a83353bcc7b39' 'self' *.akamaihd.net *.care.com *.careapis.com *.carezen.net *.cdn-care.com *.cloudfront.net *.googlesyndication.com *.sift.com *.monetate.net acsbapp.com analytics.tiktok.com apps.rokt.com bat.bing.com care.com cdn-care.com cdn.pdst.fm connect.facebook.net d.impactradius-event.com googleads.g.doubleclick.net maps.googleapis.com s.pinimg.com ssl.google-analytics.com tags-eu.tiqcdn.com tags.tiqcdn.com wss://*.care.com www.emjcd.com www.google-analytics.com www.google.com www.googleadservices.com *.googletagmanager.com www.gstatic.com tr.outbrain.com tags.w55c.net clarity.ms staging-pt.ispot.tv tracker.mnixdata.com *.mountain.com tagmanager.google.com s.go-mpulse.net collector-12308.tvsquared.com js.adsrvr.org https://static.hotjar.com https://script.hotjar.com https://cdn.cookielaw.org https://dev.visualwebsiteoptimizer.com 'nonce-164d1e853890f31eacf00f56663ee9df' 'strict-dynamic';frame-src 'self' alchemy.veriff.com www.google.com recaptcha.google.com bid.g.doubleclick.net 12355078.fls.doubleclick.net s.go-mpulse.net carecom.sjv.io apps.rokt.com tr.snapchat.com 3239339.fls.doubleclick.net https://vars.hotjar.com insight.adsrvr.org https://www.youtube.com/ https://ots2-qa.learningcaregroup.com/ScheduleATour/ https://ots2.learningcaregroup.com/ScheduleATour/ td.doubleclick.net;style-src 'self' 'unsafe-inline' tagmanager.google.com fonts.google.com https://static.hotjar.com https://script.hotjar.com https://cdn.cookielaw.org 'nonce-164d1e853890f31eacf00f56663ee9df';style-src-attr 'self' 'unsafe-inline' tags.tiqcdn.com tags-eu.tiqcdn.com bat.bing.com;upgrade-insecure-requests;report-uri https://o466311.ingest.sentry.io/api/6004104/security/?sentry_key=2c284ff228ac4d0e8b8ad9ea17497eee&sentry_release=hp-vhp-mfe%401.346.0&sentry_environment=prod 1 default-src 'self'; script-src 'report-sample' 'self' https://app-script.monsido.com/v2/monsido-script.js https://apps.usw2.pure.cloud/genesys-bootstrap/genesys.min.js https://connect.facebook.net/en_US/fbevents.js https://js.adsrvr.org/up_loader.1.1.0.js https://s.swiftypecdn.com/install/v2/st.js https://sc-static.net/scevent.min.js https://ssl.google-analytics.com/ga.js https://static.ads-twitter.com/uwt.js https://tr.snapchat.com/config/com/f46d0350-ae7f-4886-b620-b497a4d93c9f.js https://www.google-analytics.com/analytics.js https://www.googletagmanager.com/gtm.js; style-src 'report-sample' 'self'; object-src 'none'; base-uri 'self'; connect-src 'self' https://capidashboard.ialottery.com https://tr.snapchat.com https://tr6.snapchat.com https://www.google-analytics.com; font-src 'self'; frame-src 'self' https://10921257.fls.doubleclick.net https://apps.usw2.pure.cloud https://insight.adsrvr.org https://pixel-sync.sitescout.com https://tr.snapchat.com https://www.youtube.com; img-src 'self' https://analytics.twitter.com https://ssl.google-analytics.com https://t.co https://tracking.monsido.com https://www.facebook.com https://www.google.com; manifest-src 'self'; media-src 'self'; report-uri https://668597ef014602b312931fd2.endpoint.csper.io/?v=0; worker-src 'none'; 1 default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https:; style-src 'self' 'unsafe-inline' https:; img-src 'self' data: https:; font-src 'self' https:; connect-src 'self' https:; frame-src https:; object-src 'none'; base-uri 'self'; 1 font-src *.googleapis.com *.gstatic.com data: 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com *.stripe.com *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.sagepay.com *.opayo.eu.elavon.com maxcdn.bootstrapcdn.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.facebook.com *.googlesyndication.com *.stripe.com *.stripe.network *.google.com *.sagepay.com *.opayo.eu.elavon.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors *.stripe.com stripe.com *.stripe.network *.link.com *.amazon.com *.google.com pay.google.com 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.google.com *.doubleclick.net *.facebook.com *.googlesyndication.com www.xtento.com *.dotdigital-pages.com *.dotdigital.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.sagepay.com *.opayo.eu.elavon.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * *.googleapis.com *.trustpilot.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.gstatic.com *.googleapis.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net *.googletagmanager.com *.googlesyndication.com *.roeye.com www.xtento.com cdn.xtento.com *.trackedlink.net *.stripe.com *.stripe.network ebizmarts-website.s3.amazonaws.com *.sagepay.com *.paypal.com *.opayo.eu.elavon.com flagpedia.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com maps.googleapis.com maps.gstatic.com *.feefo.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com googleads.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ polyfill.io *.googleapis.com *.gstatic.com *.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net *.google-analytics.com *.googlesyndication.com *.jsdelivr.net www.xtento.com cdn.xtento.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com *.sagepay.com *.opayo.eu.elavon.com maps.googleapis.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com assets.shipperhq.com *.trustpilot.com *.feefo.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.googleapis.com *.doubleclick.net *.facebook.com *.gstatic.com *.googletagmanager.com *.googlesyndication.com cdn.dnky.co webchat.dotdigital.com webchat.staging.dotdigital.com *.stripe.network *.stripecdn.com *.amazon.com *.google.com *.sagepay.com *.opayo.eu.elavon.com maxcdn.bootstrapcdn.com unsafe-inline assets.braintreegateway.com assets.shipperhq.com *.trustpilot.com *.feefo.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.algolia.net *.algolia.com *.algolianet.com *.insights.algolia.io *.googleapis.com *.google-analytics.com *.facebook.com *.facebook.net *.google.com *.doubleclick.net *.googlesyndication.com *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.sagepay.com *.paypal.com *.opayo.eu.elavon.com www.gstatic.com maps.googleapis.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.cardinalcommerce.com google.com rms.shipperhq.com https://rms.shipperhq.com wss://rms.shipperhq.com ovs.shipperhq.com *.feefo.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; 1 font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.afterpay.com *.klevu.com *.yotpo.com *.livechatinc.com *.vimeo.com *.pixlee.com *.pxlecdn.com *.pixlee.co *.jst.ai *.jsdelivr.net *.klaviyo.com *.elev.io *.zdassets.com *.cartfulsolutions.com *.cloudmaestro.com *.freshchat.com *.visualwebsiteoptimizer.com *.cloudflare.com polyfill.io *.cartsave.io *.paypal.com *.braintree-api.com data: *.greatlakesskipper.com *.twitter.com *.twimg.com *.trustedshops.com *.googleapis.com *.ksearchnet.com *.fontawesome.com https://fonts.bunny.net maxcdn.bootstrapcdn.com fonts.googleapis.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.facebook.com *.cybersource.com *.freshchat.com *.visualwebsiteoptimizer.com *.cloudflare.com polyfill.io *.cartsave.io *.braintree-api.com 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.twitter.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * https://plumrocket.com 'self' 'unsafe-inline'; frame-ancestors 'self' 'unsafe-inline'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com www.google.com *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com *.criteo.net *.criteo.com *.livechatinc.com *.wufoo.com *.yotpo.com *.vimeo.com *.pixlee.com *.pxlecdn.com *.pixlee.co *.jst.ai *.jsdelivr.net getshogun.com *.klaviyo.com *.facebook.com *.cybersource.com insight.adsrvr.com insight.adsrvr.org *.frstre.com *.cloudfront.net *.g.doubleclick.net *.twitter.com *.cloudmaestro.com *.elev.io *.freshchat.com *.visualwebsiteoptimizer.com *.cloudflare.com polyfill.io *.cartsave.io *.braintree-api.com *.addthis.com *.recaptcha.net *.freshdesk.com airtable.com *.paypalobjects.com *.kaptcha.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com *.weltpixel.com *.googletagmanager.com *.doubleclick.net *.dotdigital-pages.com *.dotdigital.com webchat.dotdigital.com webchat.staging.dotdigital.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * https://plumrocket.com *.wesupply.xyz https://wesupplylabs.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com 'self' data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net data: landofcoder.com *.yotpo.com *.vimeo.com *.pixlee.com *.pixlee.co *.pxlecdn.co *.jst.ai *.jsdelivr.net *.pxlecdn.com *.klaviyo.com *.facebook.com *.facebook.net *.google.com *.bing.com *.choozle.com s3.amazon.com s3.amazonaws.com *.g.doubleclick.net *.adsrvr.org *.twitter.com *.swagger.io *.cloudfront.net *.godaddy.com *.cartfulsolutions.com *.cloudmaestro.com *.trustwave.com/ *.taboola.com *.media.net *.3lift.com *.rubiconproject.com *.adnxs.com *.outbrain.com *.adform.net *.360yield.com *.yieldmo.com *.bidswitch.net *.yahoo.com *.smartadserver.com *.advertising.com *.stickyadstv.com *.fwmrm.net *.adscale.de *.teads.tv *.postrelease.com *.sharethrough.com *.ivitrack.com *.casalemedia.com *.smaato.net *.pubmatic.com *.omnitagjs.com *.criteo.com *.mediawallahscript.com *.mgid.com *.addthis.com *.revcontent.com *.liadm.com *.rlcdn.com *.turn.com *.krxd.net *.google.com.ar *.freshchat.com *.visualwebsiteoptimizer.com *.cloudflare.com polyfill.io *.cartsave.io *.braintree-api.com *.bazaarvoice.com *.klevu.com *.greatlakesskipper.com *.clmbtech.com *.tapad.com *.openx.net *.dmxleo.com *.tremorhub.com *.kargo.com *.tpmn.co.kr *.agkn.com *.amanad.adtdp.com *.bluekai.com *.mathtag.com *.zemanta.com *.bnmla.com *.stackadapt.com *.simpli.fi *.admanmedia.com *.loopme.me *.digitaleast.mobi *.yieldlab.net *.lemmatechnologies.com *.avct.cloud *.deepintent.com *.dotomi.com *.creative-serving.com *.twiago.com *.amazon-adsystem.com *.mediavine.com *.socdm.com *.octillion.tv *.bidr.io.tv *.everesttech.net *.w55c.net *.emxdgt.com *.adgrx.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.klarna.com *.googleadservices.com *.google-analytics.com *.twimg.com *.ytimg.com *.lightemporium.com *.usercentrics.eu *.reddit.com *.googletagmanager.com *.doubleclick.net *.trackedlink.net https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.ksearchnet.com magefan.com cm.magefan.com *.disqus.com https://firebasestorage.googleapis.com quickchart.io img.youtube.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net amcglobal.sc.omtrdc.net *.adobe.io use.typekit.net *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.magento-ds.com https://www.gstatic.com/recaptcha/ www.google.com *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.magento-datasolutions.com https://rum.hlx.page *.klevu.com *.cloudflare.com *.klaviyo.com acsbapp.com *.acsbap.com acsbap.com *.online-metrix.net *.criteo.net *.criteo.com *.trustwave.com *.livechatinc.com *.wufoo.com *.fontawesome.com *.yotpo.com *.vimeo.com *.pixlee.com *.pxlecdn.com *.pixlee.co *.jst.ai *.gstatic.com *.jsdelivr.net *.justuno.com *.getshogun.com *.zdassets.com *.elev.io *.facebook.net *.zopim.com *.govx.com govxconnect.com *.pinimg.com *.bing.com *.tapfiliate.com *.cloudfront.net *.pepperjam.net *.pepperjam.com *.g.doubleclick.net *.ensighten.com *.bestworlds.com *.cartsave.io *.twitter.com *.swagger.io *.payments-amazon.com *.amazon.com *.godaddy.com *.cartfulsolutions.com *.cybersource.com *.cloudmaestro.com *.freshchat.com *.visualwebsiteoptimizer.com polyfill.io *.oribi.io *.paypal.com *.cloudflareinsights.com *.braintree-api.com *.greatlakesskipper.com *.trackedweb.net *.emxdgt.com *.uptrendsdata.com *.noibu.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.google-analytics.com *.twimg.com *.trustedshops.com *.usercentrics.eu *.googleapis.com *.googletagmanager.com *.googleadservices.com *.redditstatic.com *.reddit.com *.tiktok.com unpkg.com *.doubleclick.net *.trackedlink.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal webchat.dotdigital.com webchat.staging.dotdigital.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.ksearchnet.com *.disqus.com *.avada.io *.shopify.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com https://js.klevu.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com *.klevu.com *.fontawesome.com *.yotpo.com *.vimeo.com *.pixlee.com *.pxlecdn.com *.pixlee.co *.jst.ai *.jsdelivr.net *.klaviyo.com *.bestworlds.com *.cartsave.io *.cloudmaestro.com *.freshchat.com *.visualwebsiteoptimizer.com *.cloudflare.com polyfill.io *.paypal.com *.braintree-api.com apps.bazaarvoice.com *.greatlakesskipper.com *.googleapis.com *.twitter.com *.twimg.com *.gstatic.com *.typekit.net *.trustedshops.com *.usercentrics.eu *.tagmanager.google.com *.googletagmanager.com webchat.dotdigital.com webchat.staging.dotdigital.com https://static.klaviyo.com *.ksearchnet.com https://fonts.bunny.net maxcdn.bootstrapcdn.com fonts.gstatic.com assets.braintreegateway.com https://statsjs.klevu.com https://js.klevu.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.vimeo.com *.pixlee.com *.pxlecdn.com *.pixlee.co *.jst.ai *.jsdelivr.net *.klaviyo.com *.zdassets.com *.cloudmaestro.com agentcore.s3.amazonaws.com *.freshchat.com *.cloudflare.com polyfill.io *.cartsave.io *.paypal.com *.braintree-api.com *.livechatinc.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.magento-datasolutions.com *.magento-ds.com *.yotpo.com *.vimeo.com *.pixlee.com *.pxlecdn.com *.pixlee.co *.klaviyo.com *.jst.ai *.acsbapp.com acsbapp.com *.jsdelivr.net *.zdassets.com *.zendesk.com *.facebook.com *.elev.io *.zopim.com wss://*.zopim.com *.google-analytics.com *.g.doubleclick.net *.pinterest.com *.bestworlds.com *.cartsave.io *.bing.com *.amazon.com *.cartfulsolutions.com *.cloudmaestro.com adapter.aivo.co *.agentbot.net *.oribi.io *.hotjar.com *.freshchat.com *.visualwebsiteoptimizer.com *.cloudflare.com polyfill.io *.ksearchnet.com *.trackedweb.net *.googleadservices.com *.google.com.ar *.uptrendsdata.com *.noibu.com www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com *.twitter.com *.twimg.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.doubleclick.net *.run.app *.trackedlink.net *.dotdigital-pages.com webchat.dotdigital.com webchat.staging.dotdigital.com https://static.klaviyo.com https://static-forms.klaviyo.com https://fast.a.klaviyo.com https://static-tracking.klaviyo.com/ https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ *.klevu.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src *.klaviyo.com *.cloudmaestro.com *.visualwebsiteoptimizer.com *.cloudflare.com polyfill.io *.cartsave.io *.paypal.com *.braintree-api.com *.greatlakesskipper.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri http://csp-reporting-service.com/my-project/endpoint; report-to report-endpoint; 1 require-trusted-types-for 'script'; report-uri https://csp.withgoogle.com/csp/uxe-owners-acl/searchplayground_google 1 frame-src 'self'; frame-ancestors 'self'; object-src 'none' 1 default-src https: 'self' *.facebook.net *.googletagmanager.com *.bizibly.com *.doubleclick.net https://*.intercomcdn.com https://*.datadoghq-browser-agent.com; font-src 'self' https://*.intercomcdn.com *.fontawesome.com data:; base-uri 'none'; object-src data: 'unsafe-eval'; img-src 'self' data: * ; script-src https: 'self' 'unsafe-eval' 'unsafe-inline' http://*.google-analytics.com http://*.gstatic.com http://*.bing.com http://*.googleadservices.com http://*.hs-scripts.com http://*.bizible.com *.facebook.net *.googletagmanager.com http://*.fontawesome.com http://*.outbrain.com blob:; style-src https: 'self' *.fontawesome.com 'unsafe-inline'; report-to /rest/trackers/csp; 1 default-src 'self' stat.joomlapolis.com https: data ; script-src-attr 'self' 'unsafe-inline' stat.joomlapolis.com *.stripe.com *.stripe.network translate.google.com translate.googleapis.com www.googletagmanager.comi www.google-analytics.com connect.facebook.net blob data ; script-src 'self' 'unsafe-inline' 'unsafe-eval' stat.joomlapolis.com *.stripe.com *.stripe.network translate.google.com translate.googleapis.com www.googletagmanager.comi www.google-analytics.com connect.facebook.net blob data ; script-src-elem 'self' 'unsafe-inline' stat.joomlapolis.com *.stripe.com *.stripe.network translate.google.com translate.googleapis.com www.google-analytics.com gc.kis.v2.scr.kaspersky-labs.com me.kis.v2.scr.kaspersky-labs.com *.kaspersky-labs.com www.pagespeed-mod.com connect.facebook.net ; style-src 'self' 'unsafe-inline' translate.google.com translate.googleapis.com ; style-src-elem 'self' 'unsafe-inline' translate.googleapis.com www.gstatic.com fonts.googleapis.com gc.kis.v2.scr.kaspersky-labs.com me.kis.v2.scr.kaspersky-labs.com *.kaspersky-labs.com pwm-image.trendmicro.com adblockers.opera-mini.net ; img-src 'self' data: www.joomlapolis.com stat.joomlapolis.com forge.joomlapolis.com *.stripe.com *.stripe.network *.ytimg.com www.gstatic.com www.google.com translate.google.com translate.googleapis.com www.google.com/images fonts.gstatic.com yastatic.net i.imgur.com servimg.com tinypic.com www.google-analytics.com www.googleadservices.com www.facebook.com img391.imageshack.us blob data ; frame-src 'self' *.stripe.com *.stripe.network www.youtube.com www.youtube-nocookie.com www.slideshare.net mozbar.moz.com div.show pwm-image.trendmicro.com ; font-src 'self' data: fonts.gstatic.com use.typekit.net *.avast.com chrome-extension github.com/google/fonts/blob chrome-extension ; connect-src *.joomlapolis.com *.googleapis.com ; report-uri /report-csp-jp-c.php ; 1 object-src 'none'; connect-src 'self' *.dogfartnetwork.com *.dfxtra.com cognito-identity.us-east-1.amazonaws.com backend.getbeamer.com *.comm100.io *.algolia.net insights.algolia.io *.algolianet.com *.gammaapis.com *.gammacdn.com analytics.google.com *.google-analytics.com adservice.google.com *.analytics.google.com *.doubleclick.net *.pubnub.com *.lovense.com *.handyfeeling.com www.gammaentertainment.com *.tiypa.com *.recombee.us dasasoveekepl.cloudfront.net capture.trackjs.com ws: jlduihq7lrcdxgw4vrndhdfcsq.appsync-api.us-east-1.amazonaws.com tcs4u525zrg5hnnoe5kzndxuaq.appsync-api.us-east-1.amazonaws.com xtnzefcqrb.execute-api.us-east-1.amazonaws.com 2aed6ghjsb4436qtebuqk3gfzq0xeauy.lambda-url.us-east-1.on.aws lzzos7clo5.execute-api.us-east-1.amazonaws.com *.izooto.com www.idealgasm.com 3tt0xhv5u7.execute-api.us-east-1.amazonaws.com; form-action 'self' *.dogfartnetwork.com *.dfxtra.com join.gammasecure.com; script-src 'self' *.dogfartnetwork.com *.dfxtra.com app.getbeamer.com static.getbeamer.com blob: vue.comm100.com standby.comm100vue.com *.gammacdn.com www.google-analytics.com www.googletagmanager.com www.gstatic.com www.google.com code.jquery.com d3a3ewgd1iewwz.cloudfront.net cdn.izooto.com 'unsafe-eval' 'unsafe-inline'; frame-src 'self' *.dogfartnetwork.com *.dfxtra.com push.getbeamer.com app.getbeamer.com www.google.com *.doubleclick.net cdn.izooto.com *.banhq.com; report-uri https://csp-report.browser-intake-datadoghq.com/api/v2/logs?dd-api-key=pub787d5a6164b329b26f2e4f7956bbed10&dd-evp-origin=content-security-policy&ddsource=csp-prod&ddtags=CSP-Prod; 1 connect-src *.bundesregierung.de analytics.bundesregierung.de 'self' https://hls-hd.myrasec.de *.stage.bio ; style-src *.bundesregierung.de 'self' 'unsafe-inline' ; script-src *.bundesregierung.de 'self' ; script-src-elem 'self' *.bundesregierung.de 'nonce-PVdLFfewWP/SudZKYm2R4nnnmKua52KWM7wZYThQEPa4UeqpUNGNoN2XEqmyS1tl3BM5kBlS2s/kicsQfEIhlRpOWqtYXQXY1NS+XXMRqeqPSIjoopaXnVC496qzISwDZJVSV8YsMReulFsm92KClv+OmhjZOQF/q0ql4D/rE7Y=' *.stage.bio ; frame-src *.bundesregierung.de 'self' ; media-src *.bundesregierung.de 'self' http://video.bundesregierung.de https://zdf-hls-18.akamaized.net *.stage.bio ; frame-ancestors *.bundesregierung.de 'self' ; img-src 'self' *.bundesregierung.de https://*.tile.openstreetmap.de data: *.stage.bio ; default-src *.bundesregierung.de 'self' ; font-src *.bundesregierung.de 'self' ; report-uri https://www.bundeskanzler.de/service/csp-report ; 1 object-src 'none';base-uri 'self';script-src 'nonce-wEwcfpdeYKbmnNwzsoYtBw' 'strict-dynamic' 'report-sample' 'unsafe-eval' 'unsafe-inline' https: http:;report-uri https://csp.withgoogle.com/csp/gws/other-hp 1 report-uri /_/csp-reports 1 connect-src https://api.segment.io https://cdn.segment.com https://stats.g.doubleclick.net https://www.google-analytics.com https://via.intercom.io https://api.intercom.io https://api.au.intercom.io https://api.eu.intercom.io https://api-iam.intercom.io https://api-iam.eu.intercom.io https://api-iam.au.intercom.io https://api-ping.intercom.io https://nexus-websocket-a.intercom.io wss://nexus-websocket-a.intercom.io https://nexus-websocket-b.intercom.io wss://nexus-websocket-b.intercom.io https://nexus-europe-websocket.intercom.io wss://nexus-europe-websocket.intercom.io https://nexus-australia-websocket.intercom.io wss://nexus-australia-websocket.intercom.io https://uploads.intercomcdn.com https://uploads.intercomcdn.eu https://uploads.au.intercomcdn.com https://uploads.eu.intercomcdn.com https://uploads.intercomusercontent.com 'self' https://api.ipstack.com https://geoip-js.com https://*.launchdarkly.com https://*.aptrinsic.com https://sentry.pub.jamf.build https://api.services.jamfnow.com https://services-api.services.jamfnow.com https://jamfsw.okta.com/.well-known/openid-configuration https://jamfsw.okta.com/oauth2/v1/token; img-src https://*.google-analytics.com https://ssl.google-analytics.com https://www.google.ad https://www.google.ae https://www.google.al https://www.google.am https://www.google.as https://www.google.at https://www.google.az https://www.google.ba https://www.google.be https://www.google.bf https://www.google.bg https://www.google.bi https://www.google.bj https://www.google.bs https://www.google.bt https://www.google.by https://www.google.ca https://www.google.cat https://www.google.cd https://www.google.cf https://www.google.cg https://www.google.ch https://www.google.ci https://www.google.cl https://www.google.cm https://www.google.cn https://www.google.co.ao https://www.google.co.bw https://www.google.co.ck https://www.google.co.cr https://www.google.co.id https://www.google.co.il https://www.google.co.in https://www.google.co.jp https://www.google.co.ke https://www.google.co.kr https://www.google.co.ls https://www.google.co.ma https://www.google.co.mz https://www.google.co.nz https://www.google.co.th https://www.google.co.tz https://www.google.co.ug https://www.google.co.uk https://www.google.co.uz https://www.google.co.ve https://www.google.co.vi https://www.google.co.za https://www.google.co.zm https://www.google.co.zw https://www.google.com https://www.google.com.af https://www.google.com.ag https://www.google.com.ai https://www.google.com.ar https://www.google.com.au https://www.google.com.bd https://www.google.com.bh https://www.google.com.bn https://www.google.com.bo https://www.google.com.br https://www.google.com.bz https://www.google.com.co https://www.google.com.cu https://www.google.com.cy https://www.google.com.do https://www.google.com.ec https://www.google.com.eg https://www.google.com.et https://www.google.com.fj https://www.google.com.gh https://www.google.com.gi https://www.google.com.gt https://www.google.com.hk https://www.google.com.hz https://www.google.com.jm https://www.google.com.kh https://www.google.com.kw https://www.google.com.lb https://www.google.com.ly https://www.google.com.mm https://www.google.com.mt https://www.google.com.mx https://www.google.com.my https://www.google.com.na https://www.google.com.ng https://www.google.com.ni https://www.google.com.np https://www.google.com.om https://www.google.com.pa https://www.google.com.pe https://www.google.com.pg https://www.google.com.ph https://www.google.com.pk https://www.google.com.pr https://www.google.com.py https://www.google.com.qa https://www.google.com.sa https://www.google.com.sb https://www.google.com.sg https://www.google.com.sl https://www.google.com.sv https://www.google.com.tj https://www.google.com.tr https://www.google.com.tw https://www.google.com.ua https://www.google.com.uy https://www.google.com.vc https://www.google.com.vn https://www.google.cv https://www.google.cz https://www.google.de https://www.google.dj https://www.google.dk https://www.google.dm https://www.google.dz https://www.google.ee https://www.google.es https://www.google.fi https://www.google.fm https://www.google.fr https://www.google.ga https://www.google.ge https://www.google.gg https://www.google.gl https://www.google.gm https://www.google.gr https://www.google.gy https://www.google.hn https://www.google.hr https://www.google.ht https://www.google.hu https://www.google.ie https://www.google.im https://www.google.iq https://www.google.is https://www.google.it https://www.google.je https://www.google.jo https://www.google.kg https://www.google.ki https://www.google.kz https://www.google.la https://www.google.li https://www.google.lk https://www.google.lt https://www.google.lu https://www.google.lv https://www.google.md https://www.google.me https://www.google.mg https://www.google.mk https://www.google.ml https://www.google.mn https://www.google.ms https://www.google.mu https://www.google.mv https://www.google.mw https://www.google.ne https://www.google.nl https://www.google.no https://www.google.nr https://www.google.nu https://www.google.pk https://www.google.pl https://www.google.pn https://www.google.ps https://www.google.pt https://www.google.ro https://www.google.rs https://www.google.ru https://www.google.rw https://www.google.sc https://www.google.se https://www.google.sh https://www.google.si https://www.google.sk https://www.google.sm https://www.google.sn https://www.google.so https://www.google.sr https://www.google.st https://www.google.td https://www.google.tg https://www.google.tl https://www.google.tm https://www.google.tn https://www.google.to https://www.google.tt https://www.google.vg https://www.google.vu https://www.google.ws blob: data: https://js.intercomcdn.com https://static.intercomassets.com https://downloads.intercomcdn.com https://downloads.intercomcdn.eu https://downloads.au.intercomcdn.com https://uploads.intercomusercontent.com https://gifs.intercomcdn.com https://video-messages.intercomcdn.com https://messenger-apps.intercom.io https://messenger-apps.eu.intercom.io https://messenger-apps.au.intercom.io https://*.intercom-attachments-1.com https://*.intercom-attachments.eu https://*.au.intercom-attachments.com https://*.intercom-attachments-2.com https://*.intercom-attachments-3.com https://*.intercom-attachments-4.com https://*.intercom-attachments-5.com https://*.intercom-attachments-6.com https://*.intercom-attachments-7.com https://*.intercom-attachments-8.com https://*.intercom-attachments-9.com https://static.intercomassets.eu https://static.au.intercomassets.com https://appinstallers-packages.services.jamfcloud.com 'self' https://*.aptrinsic.com https://*.jamfnow.com https://*.services.jamfnow.com https://jamfnow-customapps.s3.amazonaws.com; script-src https://cdn.segment.com https://www.google-analytics.com https://www.googletagmanager.com https://app.intercom.io https://widget.intercom.io https://js.intercomcdn.com 'self' https://geoip-js.com/js/apis/geoip2/v2.1/geoip2.js https://*.aptrinsic.com https://www.youtube.com; child-src https://intercom-sheets.com https://www.intercom-reporting.com https://www.youtube.com https://player.vimeo.com https://fast.wistia.net; font-src https://js.intercomcdn.com https://fonts.intercomcdn.com 'self' https://fonts.gstatic.com; form-action https://intercom.help https://api-iam.intercom.io https://api-iam.eu.intercom.io https://api-iam.au.intercom.io; media-src https://js.intercomcdn.com https://downloads.intercomcdn.com https://downloads.intercomcdn.eu https://downloads.au.intercomcdn.com; style-src 'unsafe-inline' 'self' https://*.aptrinsic.com https://fonts.googleapis.com; base-uri 'self'; default-src 'self' https:; report-uri https://sentry.pub.jamf.build/api/266/security/?sentry_key=69c661b6de484d0285748b2206db8711&sentry_environment=production; 1 default-src 'self' https://www.googletagmanager.com/; 1 font-src fonts.gstatic.com use.typekit.net https://cdnjs.cloudflare.com https://ct.pinterest.com/ https://static.hotjar.com/ https://*.hotjar.com/ https://*.hotjar.io/ *.fontawesome.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com https://plumrocket.com 'self' 'unsafe-inline'; frame-ancestors https://h.online-metrix.net *.despegar.com/ 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.demdex.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ www.googletagmanager.com https://h.online-metrix.net *.cardinalcommerce.com *.online-metrix.net https://www.google.com/pagead/ https://www.google.com.br/pagead/ https://apps.mypurecloud.com https://td.doubleclick.net https://event.getblue.io https://app-indecx.com https://ct.pinterest.com/ https://web-modules-de-na1.niceincontact.com/ https://h.online-metrix.net/* *.despegar.com/ *.braintreepayments.com assets.braintreegateway.com *.paypal.com https://plumrocket.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net *.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com p.typekit.net *.telemetry-dev.adobe.io *.demdex.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io *.ftcdn.net *.behance.net https://h.online-metrix.net *.d.aa.online-metrix.net https://cdnjs.cloudflare.com https://res.cloudinary.com https://vlibras.gov.br https://www.vlibras.gov.br https://lumisfera.com.br https://cdn.cookielaw.org https://cdn.jsdelivr.net https://p.afilio.com.br https://bat.bing.com https://www.facebook.com/ https://static.hotjar.com/ https://*.hotjar.com/ https://*.hotjar.io/ *.adobedtm.com *.googleadservices.com *.google.com *.googletagmanager.com facebook.com.br/* https://connect.facebook.net/en_US/fbevents.js https://c.bing.com/ *.clarity.ms/ www.google.com/* www.google.com.br/* ct.pinterest.com/* *.despegar.com/ *.paypal.com data: 'self' 'unsafe-inline'; script-src *.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com beacon-qa.magento-datasolutions.com beacon-stage.magento-ds.com beacon.magento-ds.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com use.typekit.net *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com *.newrelic.com *.nr-data.net assets.adobedtm.com commerce.adobe.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.magento-ds.com https://h.online-metrix.net *.cardinalcommerce.com *.online-metrix.net https://cdn.cookielaw.org https://cdn.jsdelivr.net https://vlibras.gov.br https://www.vlibras.gov.br *.mypurecloud.com https://surveydynamix.com https://cdn.mouseflow.com https://bat.bing.com https://analytics.tiktok.com https://event.getblue.io https://widget.getblue.io https://www.clarity.ms https://js.braintreegateway.com https://static.hotjar.com/ https://*.hotjar.com/ https://*.hotjar.io/ https://viacep.com.br/* https://*.sc.omtrdc.net/ https://*.facebook.net/ facebook.com.br/* https://*.adobedtm.com/ www.googleadservices.com.br *.google.com *.google.com.br https://www.google.com/pagead/ https://www.google.com.br/pagead/ https://connect.facebook.net/en_US/fbevents.js https://s.pinimg.com https://ct.pinterest.com/* https://web-modules-de-na1.niceincontact.com https://cdnjs.cloudflare.com/ https://h.online-metrix.net/* *.despegar.com/ *.paypal.com *.pagseguro.com.br *.pagseguro.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com fonts.googleapis.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com https://cdnjs.cloudflare.com https://cdn-prod.securiti.ai https://cdn.cookielaw.org/* https://web-modules-de-na1.niceincontact.com *.fontawesome.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; manifest-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.snplow.net commerce.adobedc.net p13n.adobe.io www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.adobedc.net *.demdex.net *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io *.telemetry.adobe.io telemetry.adobe.io p13n-mr.adobe.io *.sentry.io *.sentry-cdn.com plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com livesearch-metrics-qa.magento-datasolutions.com livesearch-metrics.magento-ds.com commerce-int.adobe.io commerce.adobe.io *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.net qa-api.magedevteam.com https://h.online-metrix.net https://mpisandbox.braspag.com.br/v2/3ds/validate https://writer.cardinalcommerce.com/stag/log https://mpisandbox.braspag.com.br/v2/3ds/enroll https://centinelapistag.cardinalcommerce.com/V1/Order/JWT/Continue *.amazonaws.com *.braspag.com.br https://dev.visualwebsiteoptimizer.com https://cdn.cookielaw.org https://api-cdn.mypurecloud.com https://content.hotjar.io https://analytics.tiktok.com https://t.clarity.ms https://indecx.com https://geolocation.onetrust.com *.cardinalcommerce.com www.googleadservices.com.br *.google.com *.google.com.br www.googletagmanager.com.br wss://*.hotjar.com/ https://static.hotjar.com/ https://*.hotjar.com/ https://*.hotjar.io/ facebook.com.br/* https://connect.facebook.net/en_US/fbevents.js https://viacep.com.br https://stats.g.doubleclick.net/g/* *.clarity.ms/ https://ct.pinterest.com/* stats.g.doubleclick.net ct.pinterest.com https://vlibras.gov.br https://www.vlibras.gov.br *.despegar.com/ *.braintree-api.com *.pagseguro.com.br *.pagseguro.com 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src *.search-admin-ui-qa.magento-datasolutions.com search-admin-ui-qa.magento-datasolutions.com *.search-admin-ui.magento-ds.com search-admin-ui.magento-ds.com *.telemetry-dev.adobe.io telemetry-dev.adobe.io amcglobal.sc.omtrdc.net plp-widgets-ui-qa.magento-datasolutions.com plp-widgets-ui.magento.ds.com searchautocompleteqa.magento-datasolutions.com livesearch-autocomplete.magento-ds.com 'self' 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'self' 'unsafe-inline'; 1 default-src 'self' sunpower.okta.com login.mysunpower.com *.oktacdn.com; connect-src 'self' sunpower.okta.com sunpower-admin.okta.com login.mysunpower.com *.oktacdn.com *.mixpanel.com *.mapbox.com sunpower.kerberos.okta.com sunpower.mtls.okta.com https://oinmanager.okta.com data: login.mysunstrong.com *.ingest.sentry.io; script-src 'unsafe-inline' 'unsafe-eval' 'self' 'report-sample' sunpower.okta.com login.mysunpower.com *.oktacdn.com; style-src 'unsafe-inline' 'self' 'report-sample' sunpower.okta.com login.mysunpower.com *.oktacdn.com; frame-src 'self' sunpower.okta.com sunpower-admin.okta.com login.mysunpower.com login.okta.com *.vidyard.com; img-src 'self' sunpower.okta.com login.mysunpower.com *.oktacdn.com *.tiles.mapbox.com *.mapbox.com *.vidyard.com data: blob:; font-src 'self' sunpower.okta.com login.mysunpower.com data: *.oktacdn.com fonts.gstatic.com; frame-ancestors 'self' https://sds.mysunpower.com https://eddie.mysunpower.com 1 object-src 'none';base-uri 'self';script-src 'nonce-stFEqhu7CQGb4W5jiBCGzg' 'strict-dynamic' 'report-sample' 'unsafe-eval' 'unsafe-inline' https: http:;report-uri https://csp.withgoogle.com/csp/gws/other-hp 1 default-src 'self' 'unsafe-inline' 'unsafe-eval' blob: *.fontawesome.com *.googleapis.com *.cloudflare.com *.vimeo.com *.youtube.com *.googletagmanager.com *.ckeditor.com *.google-analytics.com *.newrelic.com *.nr-data.net *.livechatinc.com *.gstatic.com *.gtranslate.net *.google.com; object-src *; img-src * data: blob:; frame-src *; font-src * data: blob:; report-uri /report-csp-violation 1 base-uri 'self'; style-src https: 'self' 'unsafe-inline' *.googletagmanager.com *.tagmanager.google.com *.fonts.googleapis.com; script-src https: 'nonce-G+Gye4Mw3nDNOME8TYKmWWcmSi8=' 'strict-dynamic'; form-action 'self' ; frame-ancestors 'self' https://www.slipcase.com https://marketplace.marsh.com; frame-src 'self' view.ceros.com *.company-target.com *.google.com *.googletagmanager.com *.doubleclick.net *.g.doubleclick.net; report-to csp-endpoint; report-uri https://axaxl.com/api/CSP; font-src 'self' fonts.gstatic.com data:; img-src 'self' * data:; connect-src 'self' browser-intake-datadoghq.com *.googleadservices.com *.googletagmanager.com www.googletagmanager.com *.google-analytics.com *.analytics.google.com *.g.doubleclick.net www.google.com www.google.co.uk www.google.com.sg *.google.com *.googlesyndication.com *.company-target.com *.linkedin.com *.licdn.com *.brightcove.com *.brightcove.net *.brightcovecdn.com *.demandbase.com *.boltdns.net *.akamaihd.net *.nr-data.net *.en25.com; manifest-src 'self'; media-src blob: *.brightcovecdn.com *.boltdns.net *.media.brightcove.com *.akamaihd.net *.cf.brightcove.com; default-src 'self' mailto: tel: www.google.com www.google.co.uk *.google.com *.googletagmanager.com www.googletagmanager.com *.company-target.com *.linkedin.com *.licdn.com *.eloqua.com *.brightcove.com *.brightcove.net *.rlcdn.com *.boltdns.net *.demandbase.com *.akamaihd.net *.axaxl.com *.doubleclick.net *.en25.com www.google.com.sg; 1 report-uri https://csp.withgoogle.com/csp/youtube_main/strict;base-uri 'self';object-src 'none';script-src 'report-sample' 'nonce-EHBSXqwu01oz_WsAX8I2bw' 'unsafe-inline' 'strict-dynamic' https: http: 'unsafe-eval' 1 frame-ancestors 'none';object-src 'none';base-uri 'none';frame-src 'self' https://ct.pinterest.com https://cr.dm.ilmarinen.fi https://www.googletagmanager.com https://www.facebook.com https://www.google.com https://*.googlesyndication.com https://player.vimeo.com https://*.doubleclick.net https://*.surveypal.com https://www.youtube.com;default-src 'unsafe-eval' 'unsafe-inline' 'self' data: https: blob: 1 default-src 'self'; child-src 'self'; font-src 'none'; frame-ancestors 'self'; frame-src 'self'; manifest-src 'self'; media-src 'none'; object-src 'self'; worker-src 'self' blob: 0.0.0.0:3000; connect-src 'self' *.openhistoricalmap.org openhistoricalmap.github.io *.amazonaws.com http://127.0.0.1:8111 https://vector.openstreetmap.org https://api.maptiler.com https://tile.thunderforest.com https://render.openstreetmap.org https://nominatim.openhistoricalmap.org/ https://overpass-api.openhistoricalmap.org/api/interpreter https://routing.openstreetmap.de/ https://graphhopper.com/api/1/route https://valhalla1.openstreetmap.de/route https://www.wikidata.org/w/api.php; form-action 'self' render.openstreetmap.org tile.thunderforest.com; img-src 'self' data: www.gravatar.com *.wp.com tile.openstreetmap.org gps.tile.openstreetmap.org *.tile.thunderforest.com tile.tracestrack.com *.openstreetmap.fr https://commons.wikimedia.org/wiki/ upload.wikimedia.org; script-src 'self' openhistoricalmap.github.io 'wasm-unsafe-eval' 'nonce-1XfceDVSlwdqOkvU/4b3MTqeeUJd4lLn'; style-src 'self' openhistoricalmap.github.io 'unsafe-inline' 'nonce-1XfceDVSlwdqOkvU/4b3MTqeeUJd4lLn' 1 script-src 'self' 'unsafe-eval' chrome-extension: https://mc.yandex.ru 'unsafe-inline' 127.0.0.1:8182 127.0.0.1:8888 127.0.0.1:5005; frame-src 'self' https://mc.yandex.ru chrome-extension: https://mc.yandex.com; object-src 'self'; report-uri /cspreportonly; 1 font-src www.paypalobjects.com fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.googleapis.com data: *.lesandpit.org *.lowes-menswear.com.au *.lowes.com.au *.lowesleavers.com.au data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' www.facebook.com connect.facebook.net graph.facebook.com business.facebook.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net www.googletagmanager.com *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.dotdigital-pages.com *.dotdigital.com webchat.dotdigital.com webchat.staging.dotdigital.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.addressfinder.io *.adsrvr.org *.creativecdn.com gum.criteo.com *.doubleclick.net *.ezy-way.online www.facebook.com *.flowpaper.com *.freshchat.com *.google-analytics.com *.googleapis.com *.google.com.au *.googletagmanager.com *.gstatic.com *.impactcdn.com *.kaspersky-labs.com *.lesandpit.org *.lowes-menswear.com.au *.lowes.com.au *.lowesleavers.com.au *.newrelic.com *.paypalobjects.com *.pxf.io *.statsigapi.net *.stripe.com *.trackedweb.net *.typekit.net lowes.api.useinsider.com *.vimeo.com connect.facebook.net graph.facebook.com business.facebook.com www.commercepartnerhub.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.googleapis.com *.trackedlink.net *.ddlnk.net www.feedoptimise.com cdn.feedoptimise.com *.dycdn.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.addressfinder.io *.bing.com *.braintreegateway.com *.creativecdn.com *.dotdigital.com *.doubleclick.net *.ezy-way.online www.facebook.com *.freshchat.com *.google.com.au *.google.co.nz *.googletagmanager.com *.google.com *.impactcdn.com *.kaspersky-labs.com *.lesandpit.org *.lowes-menswear.com.au *.lowes.com.au *.lowesleavers.com.au *.newrelic.com *.paypalobjects.com *.pxf.io *.reddit.com *.statsigapi.net *.stripe.com *.trackedweb.net *.vimeo.com connect.facebook.net graph.facebook.com business.facebook.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com commerce-payments-sdk.adobe.io www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.addressfinder.io https://rum.hlx.page *.googleapis.com *.gstatic.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal webchat.dotdigital.com webchat.staging.dotdigital.com www.feedoptimise.com cdn.feedoptimise.com *.dycdn.net dn1i8v75r669j.cloudfront.net dkpklk99llpj0.cloudfront.net ds9p2a60lh6fp.cloudfront.net d1y9qtn9cuc3xw.cloudfront.net d81mfvml8p5ml.cloudfront.net *.freshrelevance.com *.dotdigital.com https://cdn.searchspring.net/intellisuggest/is.min.js js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com *.adsrvr.org *.amazonaws.com *.bing.com *.creativecdn.com *.criteo.com *.ezy-way.online www.facebook.com *.freshchat.com *.freshworksapi.com *.google-analytics.com *.googleadservices.com *.googletagmanager.com *.hotjar.com *.impactcdn.com *.kaspersky-labs.com *.lesandpit.org *.lowes-menswear.com.au *.lowes.com.au *.lowesleavers.com.au *.redditstatic.com *.searchspring.io *.tiktok.com *.useinsider.com connect.facebook.net graph.facebook.com business.facebook.com https://www.lowes.com.au 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.addressfinder.io webchat.dotdigital.com webchat.staging.dotdigital.com *.dycdn.net assets.braintreegateway.com *.bra