I am adding Content Security Policy in Nginx for my website as:
example:
add_header Content-Security-Policy "default-src \'self\'; frame-src \'self\' http