Vercel Page Integrity fixture

Variant: drift

This response emits monitored security headers, but it intentionally does not send an origin Content-Security-Policy header. Page Integrity's injected CSP should be the only CSP policy involved in script reporting.

Third-party scripts are loaded from js.stripe.com and cdn.jsdelivr.net so CSP reports include non-first-party resources.