??? ?? ??????:
???? 'http:// ??? ??????.
*/js/track.js'? ?? ??? ?? ?? ??? ???? ?????: "default-src https: data: 'unsafe-inline' 'unsafe-eval' 'self' .qq.com .flzhan.com .gtimg.com .share.baidu.com .gtimg.cn .qlogo.cn img.hb.aicdn.com pub.idqqimg.com nsclick.baidu.com ajax.googleapis.com .qpic.cn ?? .jquery.com cdn.bootcss.com .sec.qq.com .sinaimg.cn wvjbscheme://* creativecommons.org www.w3.org purl.org tnm2.oa.com statics.dnspod.cn doksoft.com js.plus weixinping weixinpreinject weixin jsbridge". 'script-src'? ????? ???? ????? 'default-src'? ?? ???? ?????.
??? ??? ??? ?????
????HTML ??? ?????
????js ??? ???? ???? ???, ???? ??? js ????? ?? ??? ??????. ?????
Note that 'script-src' was not explicitly set, so 'default-src' is used as a fallback.
?? ???? ???? ??? ?? ??? ???? ?? ??? ???????.