response.setHeader("Content-Security-Policy", "default-src *; style-src 'self' fonts.googleapis.com 'unsafe-inline'; script-src 'self' www.gstatic.com maps.googleapis.com api64.ipify.org 'unsafe-inline' 'unsafe-eval';frame-ancestors 'self';img-src * data: 'unsafe-inline' blob:; worker-src 'self' blob:;");