**Proposed header value** ``` "default-src 'self'; script-src 'self' code.jquery.com; connect-src 'self'; img-src 'self'; style-src 'self';" ``` This should be tested with a [report header](https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Content-Security-Policy-Report-Only) first - [x] Set up an endpoint that can accept security reports