{ admin off auto_https off } :8080 { file_server try_files {path} index.html header Access-Control-Allow-Methods "GET, PUT, POST, DELETE, OPTIONS" header Access-Control-Allow-Origin "*" header Content-Security-Policy " default-src 'self'; connect-src 'self' api.bitclout.com bitclout.com:* bithunt.bitclout.com pulse.bitclout.com api.bitpop.dev bitclout.me:* api.bitclout.me:* localhost:* explorer.bitclout.com:* https://api.blockchain.com/ticker https://api.blockchain.com/mempool/fees https://ka-f.fontawesome.com/ bitcoinfees.earn.com api.blockcypher.com amp.bitclout.com api.bitclout.green api.bitclout.blue api.bitclout.navy images.flickapp.com; script-src 'self' https://cdn.jsdelivr.net/npm/sweetalert2@10 https://kit.fontawesome.com/070ca4195b.js https://ka-f.fontawesome.com/; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; img-src 'self' data: i.imgur.com images.bitclout.com images.flickapp.com; font-src 'self' https://fonts.googleapis.com https://fonts.gstatic.com https://ka-f.fontawesome.com; frame-src 'self' localhost:* identity.bitclout.com identity.bitclout.blue identity.bitclout.green https://www.youtube.com https://player.vimeo.com https://www.tiktok.com https://giphy.com https://open.spotify.com https://w.soundcloud.com;" }