I first encountered the Content Security Policy HTTP header earlier this year when one of our users reported the Instapaper bookmarklet wasnât working on GitHub. Triggering the bookmarklet, and inspecting element on the page revealed the problem: Refused to load the script âhttps://www.instapaper.com/j/redacted?u=https%3A%2F%2Fgithub.com%2Fcocoapods%2Fcocoapods&t=1414077850205' because it violates
{{#tags}}- {{label}}
{{/tags}}