Pedidos ou recursos que ofendem as políticas de segurança
Violação
Tipo
Informação
Recurso
https://www.onderzoekdoen.nl/
Descrição
Refused to execute inline script because it violates the following Content Security Policy directive: "script-src-elem 'self' https://ajax.googleapis.com https://*.cloudfront.net https://*.googletagmanager.com https://www.google.com https://www.gstatic.com". Either the 'unsafe-inline' keyword, a hash ('sha256-bsEESS49bXtvNK+7wxIbAbdhC2COzQQU65Q5ubk4LVY='), or a nonce ('nonce-...') is required to enable inline execution.
Refused to execute inline script because it violates the following Content Security Policy directive: "script-src-elem 'self' https://ajax.googleapis.com https://*.cloudfront.net https://*.googletagmanager.com https://www.google.com https://www.gstatic.com". Either the 'unsafe-inline' keyword, a hash ('sha256-8L+IXgGICXGdVmCZxssE9Z6PVToHIPqC+SW5cAd4nE4='), or a nonce ('nonce-...') is required to enable inline execution.
Refused to apply inline style because it violates the following Content Security Policy directive: "style-src-elem 'self' https://*.googleapis.com". Either the 'unsafe-inline' keyword, a hash ('sha256-ZvkgNCQ890Zh4se4Vp0VgLLw5HulEYXldVDUPUsd20A='), or a nonce ('nonce-...') is required to enable inline execution.
Refused to execute inline script because it violates the following Content Security Policy directive: "script-src-elem 'self' https://ajax.googleapis.com https://*.cloudfront.net https://*.googletagmanager.com https://www.google.com https://www.gstatic.com". Either the 'unsafe-inline' keyword, a hash ('sha256-GDjJbyOYreMWYa4UD84PMTYtaAYPYuKBmwJrKhtOmtI='), or a nonce ('nonce-...') is required to enable inline execution.
Refused to load the script 'https://cdn.jsdelivr.net/npm/@flowbase-co/boosters-carousel-ticker@1/dist/carousel-ticker.min.js' because it violates the following Content Security Policy directive: "script-src-elem 'self' https://ajax.googleapis.com https://*.cloudfront.net https://*.googletagmanager.com https://www.google.com https://www.gstatic.com".
Refused to apply inline style because it violates the following Content Security Policy directive: "style-src-elem 'self' https://*.googleapis.com". Either the 'unsafe-inline' keyword, a hash ('sha256-7qNx19LxFRry6n2KdIyi91kR6M7Dmeeeull0GIkBdiw='), or a nonce ('nonce-...') is required to enable inline execution.
Refused to load the script 'https://cdn.jsdelivr.net/npm/[email protected]/dist/gsap.min.js' because it violates the following Content Security Policy directive: "script-src-elem 'self' https://ajax.googleapis.com https://*.cloudfront.net https://*.googletagmanager.com https://www.google.com https://www.gstatic.com".
Refused to load the script 'https://cdn.jsdelivr.net/npm/[email protected]/dist/ScrollTrigger.min.js' because it violates the following Content Security Policy directive: "script-src-elem 'self' https://ajax.googleapis.com https://*.cloudfront.net https://*.googletagmanager.com https://www.google.com https://www.gstatic.com".
Refused to apply inline style because it violates the following Content Security Policy directive: "style-src-elem 'self' https://*.googleapis.com". Either the 'unsafe-inline' keyword, a hash ('sha256-alQkhzRik30p4D42M4x52HUwzK1/HLrcDh9ydLkkoOI='), or a nonce ('nonce-...') is required to enable inline execution.
Refused to apply inline style because it violates the following Content Security Policy directive: "default-src 'self'". Either the 'unsafe-inline' keyword, a hash ('sha256-l32kuTgbhZFV7YL2q1Sv/65m8dy+QzAV1CjPDUML0hE='), or a nonce ('nonce-...') is required to enable inline execution. Note that hashes do not apply to event handlers, style attributes and javascript: navigations unless the 'unsafe-hashes' keyword is present. Note also that 'style-src' was not explicitly set, so 'default-src' is used as a fallback.