Content-Security-Policy (CSP)限制页面资源加载来源示例: Content-Security-Policy: default-src 'self'X-Frame-Options防止点击劫持示例: X-Frame-Options: DENYX-Content-Type-Options禁用MIME类型嗅探示例: X-Content-Type-O