header("Content-Security-Policy: default-src 'self'; script-src 'self' https://apis.google.com; style-src 'self'; img-src 'self'");