Content Security Policy (内容安全策略)
用于指定哪些内容可执行
HTTP头
child-src connect-src default-src
font-src frame-src img-src
manifest-src media-src object-src
script-src style-src worker-src
<host-source> <scheme-source> 'self'
'unsafe-inline' 'unsafe-eval' 'none'
'nonce-<base64-value>' <hash-source>
'strict-dynamic'