add_header Content-Security-Policy "frame-ancestors ‘self’ 网页地址 网页地址; add_header X-Frame-Options SAMEORIGIN;