Make Content-Security-Policy frame-ancestors directive configurable for New Universal Login

Disabled clickjacking protection for Classic Universal Login, however, the /login page still returned the Content-Security-Policy: frame-ancestors ‘none’ response header.