default-src 'self' http://example.com http://example.net; connect-src 'none'