qa.xtzbakers.com

Violation class: cross-origin subresource loading. Every violation here is a resource fetched from a different origin. Nothing is inline, so this page isolates the "remote fetch" half of default-src from the "inline code" half that qa.tubaluna.com covers.

Expected reports (5), each with blocked-uri pointing at https://example.com/…:

remote image:

remote video:

back to index