sources
The list of sources that may be loaded for the specified policy.
Please note that you may need to specify directives in your app's Content-Security-Policy as a element or as a HTTP header as well since those restrictions are inherited by child iframes used for rendering content-documents.
Examples:
domain.example.com Allows loading resources from the specified domain name.
*.example.com Allows loading resources from any subdomain under example.com.
https://cdn.com Allows loading resources only over HTTPS matching the given domain.
https: Allows loading resources only over HTTPS on any domain.
Allow any url.
Content copied to clipboard
For more examples see: https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Content-Security-Policy#Directives https://content-security-policy.com/