Violates Content Security Privacy

I am trying to add an add-in to a form that can see the gift-type-change, and I get this error on the console.

Refused to frame 'https://d1o1p.cloudfront.net/' because it violates the following Content Security Policy directive: "frame-src *.blackbaud.com api-pte-bsp.sharedservices-dev.com dntcl.qualaroo.com doublethedonation.com doublethedonation.ngrok.io uk.smartthing.org www.google.com/recaptcha/ donatestock.com bloom-form-gen.web.app giveamply.com app.lifelegacy.io pllenty.com hope.fndrsng.com www.ucbcanada.com".

The cloudfront url it mentions is where I'm hosting my add-in. Surely that's not actually the issue. Any advice?

Comments