more_set_headers "Content-Security-Policy : default-src 'self'; object-src 'none';";