Security Content security policy * APP_CSP_SRC='self' * local: self * development: *.domain.com * production: *.domain.com Example -> production = https://*.example.com