查詢 「Strict-dynamic」的人也找了:
//=$keyword?>
- content-security-policy
- Strict-dynamic' is present, so host-based allowlisting is disabled
- Content-Security Policy: ignoring 'unsafe-inline''' within script-src: 'strict-dynamic' specified
- Refused to frame '' because it violates the following Content Security Policy directive: frame-src
- Script-src-elem
- CSP nonce
- Inline script
- Content Security Policy script-src