url:https://test.paperok.com/
// demo
Content-Security-Policy: default-src 'self';
  script-src 'self' 'nonce-6a29030c-1b1d-41' https://test.paperok.com/ 'strict-dynamic';
  style-src 'self' 'nonce-6a29030c-1b1d-41' https://test.paperok.com/;
  img-src 'self' https://test.paperok.com/;
  object-src 'none';
  base-uri 'self';
  report-uri /csp-violation-report-endpoint