add_header Content-Security-Policy
"default-src 'self' data: *.adfox.ru *.edgefonts.net mc.yandex.ru www.youtube.com yastatic.net www.google-analytics.com;img-src 'self' unsafe-inline data: informer.yandex.ru stats.g.doubleclick.net www.google-analytics.com counter.yadro.ru mc.yandex.ru;script-src 'self' unsafe-inline unsafe-eval 'nonce-Xiojd98a8jd3s9kFiDi29UijwdX' *.edgefonts.net www.google-analytics.com mc.yandex.rustats.g.doubleclick.net;style-src 'self' unsafe-inline 'nonce-Xiojd98a8jd3s9kFiDi29UijwdX' *.edgefonts.net;";
<div nonce="Xiojd98a8jd3s9kFiDi29UijwdX" class="sidebox-weather" style="width: 100%;background-image: url('//openweathermap.org/img/w/{{ weather.icon }}.png');">
<span>Казань</span> <span class="temp">{{ weather.temp }} °C</span>
</div>