Content security policy default src none header July 8, 2019 16 32 64 128 Header set content security policy default src none Content spoofing poc Nonce html Default content-security-policy