Set-Cookie: object-src-url-embed-allowed-img-src-none={{$id:uuid()}}; Path=/content-security-policy/object-src/ Content-Security-Policy: object-src 'self'; img-src 'none'; script-src 'self' 'unsafe-inline'; report-uri /reporting/resources/report.py?op=put&reportID={{$id}}