# Styles (allow inline for now, tighten later if possible) style-src 'self' 'unsafe-inline'; # Images (allow CDN + FB/Google tracking pixels) img-src 'self' https://unc-mmio.b-cdn.net https://www.google-analytics.com https://www.googletagmanager.com https://connect.facebook.net https://www.facebook.com data:; # Fonts font-src 'self' data:; # Connections (AJAX, beacons, tracking) connect-src 'self' https://www.google-analytics.com https://www.googletagmanager.com https://connect.facebook.net https://www.facebook.com; # Frames (for GTM/FB iframes) frame-src 'self' https://www.googletagmanager.com https://connect.facebook.net https://www.facebook.com; # Disallow embedding by other sites frame-ancestors 'self'; X-Frame-Options: SAMEORIGIN X-Content-Type-Options: nosniff Referrer-Policy: strict-origin-when-cross-origin Permissions-Policy: geolocation=(), microphone=(), camera=() Strict-Transport-Security: max-age=31536000; includeSubDomains; preload Cross-Origin-Embedder-Policy: require-corp Cross-Origin-Opener-Policy: same-origin Cross-Origin-Resource-Policy: same-origin Content-Encoding: gzip Vo6Xiu)i<>@g Ej$e(ɯ