Content-Security-Policy: default-src 'self'; script-src 'self'; frame-ancestors 'none'; style-src 'self' ; img-src 'self'; upgrade-insecure-requests