'self''none''unsafe-inline''unsafe-eval'data:blob:https:*
Content-Security-Policy: default-src 'self'
<meta http-equiv="Content-Security-Policy" content="default-src 'self'">
browserutils
CSP Header Generator