feature/issue-41-csp-header
main
- Content-Security-Policy: strict CSP for static landingpage - X-Content-Type-Options: nosniff - X-Frame-Options: SAMEORIGIN - Referrer-Policy: strict-origin-when-cross-origin Fix #41