b7f content-security-policy: default-src 'none'; navigate-to 'none'; form-action 'none'; img-src data:; x-content-type-options: nosniff X-Firefox-Spdy: h2