Refused to load the script 'https://www.googletagmanager.com/gtag/js?id=G-24XP4PG02H' because it violates the following Content Security Policy directive: "script-src 'sha256-1az3CiAdXAaMP3TFl5msfrDjNuSHMdg1ecAgxfZPR50=' 'unsafe-inline' 'strict-dynamic'". Note that 'script-src-elem' was not explicitly set, so 'script-src' is used as a fallback.
Refused to execute inline script because it violates the following Content Security Policy directive: "script-src 'sha256-1az3CiAdXAaMP3TFl5msfrDjNuSHMdg1ecAgxfZPR50=' 'unsafe-inline' 'strict-dynamic'". Note that 'unsafe-inline' is ignored if either a hash or nonce value is present in the source list.