http
Content-Security-Policy: font-src 'self'; default-src 'self'
<style>
@font-face {
font-family: 'External';
src: url('https://cdn.example.com/font.woff2');
/* Blockiert: externe Domain */
}
body {
font-family: 'External', system-ui, sans-serif;
/* Fallback zu system-ui */
}
</style>