web application – HTTP header "Content-Security-Policy" with "default-src & # 39; self-script-src & # 39; self & # 39; not blocking the unspecified domain download

