add_header X-Frame-Options SAMEORIGIN;
add_header X-Frame-Options "allow-from https://*.xxx.cn/";
add_header Content-Security-Policy "connect-src *;frame-ancestors https://*.jobpi.cn/ https://*.schoolpi.net/; ";