New Extensions policy for Content Security Policy (CSP) directives and timeline for enforcement

@Dist thanks for your reply but facebook pixel can’t be fixed in this way. It fetches script from https://connect.facebook.net/en_US/fbevents.js and we can’t add domain to CSP script-src. It would be great if twitch added that domain to CSP just like https://www.google-analytics.com