@kirby @meso @nekofag It simply isn’t how CSP works. When you request /, you get the CSP then and there. It doesn’t matter what the CSP headers are on requests made from inside that page. Resources are either allowed or blocked before they’re requested, not after you have a response.