1. headers http header: content-security-policy: worker-src

  2. webapp: serviceworker: src