Header add X-Frame-Options "SAMEORIGIN" Header add Content-Security-Policy "frame-ancestors 'self'"