Slide 32
              Slide 32 text
              
                  3
Extending the
browser sandbox
Don’t allow unexpected domains
The browser will load scripts, fonts, videos, and all other
content from anywhere by default. 
Instead, an allow-list can be specified.
Content-Security-Policy: default-src 'self'
*.googleanalytics.com