Adding CSP header

Support for this was added in core: Mitigate XSS Attacks with Content Security Policy - #37 by Falco

「いいね!」 1