Add Content-Type and CSP headers

Additionally force UTF-8 and allow only specific domains within CSP
header('Content-Type: text/html; Charset=UTF-8');
header('Content-Security-Policy: default-src \'self\' \'unsafe-inline\';');
// logout
if( isset($_GET["logout"]) && !empty($_SESSION["active"]) ){
