https-strict: behind-the-scene false noscript-spoof: * true * * * block * 1st-party css allow * 1st-party image allow