{ "Content-Security-Policy": [ // The first format parameter {0} will be replaced by the nonce value. "default-src 'self'", "script-src 'self' 'nonce-{0}' 'unsafe-eval'", "style-src 'self' 'unsafe-inline' https://fonts.googleapis.com:*", "img-src 'self' data: https: blob:", "font-src 'self' https://fonts.gstatic.com:*", "connect-src 'self' https://nominatim.openstreetmap.org:* http://localhost:* https://localhost:* ws://localhost:* wss://localhost:* blob:", "frame-src 'self'", "media-src 'self'", "object-src 'self'" ], "AllowedOrigins": [ "https://localhost:7202", "https://digitale.unterschrift.wisag.de/" ], "TFARegParams": { "TimeLimit": "90.00:00:00" } }