default-src
'self'
script-src
'self''unsafe-inline'https://cdn.example.com
style-src
'self''unsafe-inline'
img-src
'self'data:https:
font-src
'self'https://fonts.gstatic.com
connect-src
'self'https://api.example.com
frame-src
'none'
object-src
'none'
base-uri
'self'