There are two things to fix here:
- Use https for the Google fonts link (
https://fonts.googleapis.com/css?family=Whatever
) - Authorize
https://fonts.googleapis.com
instyle-src
directive andhttps://fonts.gstatic.com
infont-src
directive:"style-src 'self' https://fonts.googleapis.com; font-src 'self' https://fonts.gstatic.com"