Refused to execute inline script because it violates the following Content Security Policy directive: "script-src…