Content-Security-Policy: sandbox allow-scripts allow-same-origin