/* - default-src: a fallback for all other directives. - 'self': Refers to the origin from which the protected document is being served, including the same URL scheme and port number. - script-src: specifies the valid sources of JS running either inside