  1. I agree with requinix, it looks like something created for security, but most of the time i see this on WP installs (does WP exist on the server e.g. shared hosting) Maybe check the logs to see what scripts/processes are running, change the permissions on the file to see if you get an error in the error logs etc. Hope this helps
  2. Clearly you have something on the server generating this file for you. Perhaps cPanel? Is there some tool you should be using to modify this file instead of doing it yourself manually?
  3. I downloaded your code and added that attribute and it seemed to be working fine after that. You need to add it to both the CSP and the iframe's sandbox attribute.
