* [bugfix] Add s3 endpoint as image-src and media-src for CSP * use https if secure * reorder comment