結果 : header set content security policy script src self