Violation class: cross-origin subresource loading.
Every violation here is a resource fetched from a different origin. Nothing is
inline, so this page isolates the "remote fetch" half of default-src
from the "inline code" half that qa.tubaluna.com covers.
Expected reports (5), each with blocked-uri pointing at
https://example.com/…:
style-src-elem — remote <link rel=stylesheet>font-src — remote @font-face sourcescript-src-elem — remote <script src>img-src — remote <img>media-src — remote <video>remote image: ![]()
remote video: