Content security policy header unsafe inline July 8, 2019 16 32 64 128 Nginx add_header content security policy unsafe inline Header set content security policy unsafe inline Header set content security policy default src self unsafe inline Content spoofing poc Broken link hijacking vulnerability