use Content-Security-Policy instead of old X-Frame-Options