Disallow iframes via X-Frame-Options and CSP by default