violates the following Content Security Policy directive: "default-src 'self'". 

Nginx 解决内容安全策略CSP(Content-Security-Policy)配置方式(漏洞修复) - 龙凌云端 -

add_header Content-Security-Policy "default-src 'self' sfa8.yashili.cn ynby.oss-cn-shenzhen.aliyuncs.com  webapi.amap.com  'unsafe-inline' 'unsafe-eval' blob: data: ;";

 

用一个例子来演示会更加清晰