ø Content-Security-Policy: script-src 'self' 'unsafe-inline' 'unsafe-eval' https://www.google.com https://www.gstatic.com https://api.whatsapp.com https://www.diehardrecords.blogspot.com https://instagram.com https://www.youtube.com https://www.facebook.com https://twitter.com https://csp.withgoogle.com http://www.w3.org https://fonts.gstatic.com http://ws.correios.com.br https://superpay2.superpay.com.br http://www.atendesmart.com.br https://www.diehard.com.br https://ajax.googleapis.com https://code.jquery.com https://cieloecommerce.cielo.com.br/; style-src 'self' 'unsafe-inline' Strict-Transport-Security: max-age=31536000 Permissions-Policy: geolocation=(self),sync-xhr=(self),fullscreen=(self) X-XSS-Protection: 1; mode=block X-Content-Type-Options: nosniff Referrer-Policy: origin-when-cross-origin X-Frame-Options: SAMEORIGIN Access-Control-Allow-Origin: https://www.diehard.com.br Access-Control-Allow-Methods: OPTIONS Content-type: text/html; charset=UTF-8