mastodon/app/controllers/concerns/api
..
content_security_policy.rb