Defending Against Content Security Policy (CSP) Bypass: Best Practices for JavaScript Applications

You ship a Content Security Policy, see the header show up in DevTools, and feel safe. That feeling is the trap.