csp
default-src https://static.iconet-foundation.org/docs/iframe-example/embed-me.html; style-src 'unsafe-inline'; script-src 'unsafe-inline'; img-src data: blob:;