@sheogorath
Some CSP design guidelines here too
https://webcookies.org/articles/11/typical-content-security-policy-mistakes-and-omissions
There's also CSP checker https://webcookies.org/cookies/shivering-isles.com/30386338?531471#csp