Refused to load the font 'http://at.alicdn.com/t/font_1433401008_2229297.woff' because it violates the following Content Security Policy directive: "default-src 'self' data: gap: https://ssl.gstatic.com 'unsafe-eval'". Note that 'font-src' was not explicitly set, so 'default-src' is used as a fallback.