Content-Security-Policy default-src 'self'; script-src 'self' https://assets.squarespace.com https://definitions.sqspcdn.com https://static1.squarespace.com https://connect.facebook.net; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://definitions.sqspcdn.com https://static1.squarespace.com https://assets.squarespace.com; img-src 'self' data: https://images.squarespace-cdn.com https://video.squarespace-cdn.com https://www.facebook.com; font-src 'self' data: https://fonts.gstatic.com https://static1.squarespace.com https://assets.squarespace.com; frame-src 'self' https://pepsiworcester.com; connect-src 'self' https://pepsiworcester.com https://video.squarespace-cdn.com https://featureassets.org https://prodregistryv2.org https://images.squarespace-cdn.com https://www.facebook.com; media-src 'self'; frame-ancestors 'none'; object-src 'none'; upgrade-insecure-requests; base-uri 'self'