SecurityError: The operation is insecure. Content Security Policy directive: "default-src 'self'"

FWIW I prefer to host fonts locally…