Content-Security-Policy: default-src 'none'; script-src 'unsafe-inline' 'unsafe-eval' 'nonce-UQEc+VKDNWD9JSscKElVmBn3V+8=' https://www.googletagmanager.com;