Related Post: Header Set Content Security Policy Default Src Https Header Set Content-security-policy Default-src 'self' Content Security Policy Default-src *