2 header("X-Content-Security-Policy: default-src localhost 'self';");
3 header("X-WebKit-CSP: script-src 'self'; style-src 'self' 'unsafe-inline'");
8 <meta http
-equiv
="Content-Type" content
="text/html; charset=utf-8" />
9 <title
>CSP Test Page
</title
>
11 <script src
="../dist/jquery.js"></script
>