http://www.jotoho.de header Content-Security-Policy "default-src 'self' https://jotoho.de https://*.jotoho.de; base-uri https://jotoho.de https://*.jotoho.de; object-src 'none'; frame-ancestors 'none'; upgrade-insecure-requests;" file_server { root /site/ }