Content Security Policy directive 'script-src 'self' *.cloudflare.com *.cloudflareinsights.com *.jsdelivr.net'. Either the 'unsafeinline' keyword, a hash ('sha256XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX='), or a nonce ('nonce-...') is required to enable inline execution. The action has been blocked.
Content Security Policy directive 'script-src 'self' *.cloudflare.com *.cloudflareinsights.com *.jsdelivr.net'. Either the 'unsafeinline' keyword, a hash ('sha256XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX='), or a nonce ('nonce-...') is required to enable inline execution. The action has been blocked. Cloudflare が自動で挿入する JS がブロックされているので、 ヘッダーで nonce を設定して許可してね、とのこと。