Content-Security-Policy: default-src 'none'; script-src 'unsafe-inline' 'unsafe-eval' 'nonce-Pb//gpAotDcMhI8o02X/tGP5eVE=' https://www.googletagmanager.com;