Content-security-policies on ste

atthe end of the code add

resp.Header.Set("Access-Control-Allow-Origin", "*")