<IfModule mod_headers.c> Header set Content-Security-Policy "○○-src 'self'; ○○-src https://foo.com;" </IfModule> <IfModule mod_headers.c> Header set Content-Security-Policy " \ default-src 'none'; \ script-src https://morisakimikiya.com/js/ \ https://ajax.googleapis.com/ajax/libs/jquery/ \ https://www.google.com/recaptcha/ \ 'sha256-*****'; \ font-src https://fonts.gstatic.com/; \ block-all-mixed-