Nginx, seafile and Content-Security-Policy

A bit late my answer but check: Check security server