security: add csp
@@ -2,6 +2,9 @@
<html>
<head>
<meta charset="UTF-8">
+ <!-- https://developer.mozilla.org/en-US/docs/Web/HTTP/CSP -->
+ <meta http-equiv="Content-Security-Policy" content="default-src 'self'; script-src 'self'">
+ <meta http-equiv="X-Content-Security-Policy" content="default-src 'self'; script-src 'self'">
<title>Hello World!</title>
</head>
<body>