$csp_rules = [ "default-src 'self' https: data: blob: 'unsafe-inline' 'unsafe-eval'", "script-src 'self' 'unsafe-inline' 'unsafe-eval' https://*.googletagmanager.com https://tagmanager.google.com https://*.google-analytics.com https://*.google.com https://*.gstatic.com https://ajax.googleapis.com https://connect.facebook.net https://*.facebook.com https://*.cloudfront.net", "connect-src 'self' https: data: blob: https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://*.g.doubleclick.net https://*.google.com https://www.facebook.com https://*.whatsapp.com wa.me", "img-src 'self' https: data: blob: https://*.google-analytics.com https://*.googletagmanager.com https://*.google.com https://*.g.doubleclick.net https://*.googleadservices.com https://www.facebook.com https://*.whatsapp.com", "style-src 'self' https: 'unsafe-inline' https://fonts.googleapis.com", "font-src 'self' https: data: https://fonts.gstatic.com", "frame-src 'self' https: *.whatsapp.com wa.me https://*.googletagmanager.com https://*.google.com https://www.facebook.com", "form-action 'self' https: *.whatsapp.com wa.me", // --- ADICIONE ESTAS DUAS LINHAS ABAIXO --- "worker-src 'self' blob:", "base-uri 'self'", // ----------------------------------------- "upgrade-insecure-requests", ];