get('web_config'); header('X-Frame-Options: DENY'); header("Content-Security-Policy: default-src 'self'"); ?>