Full threadwuyishan·Couldn't Content Security Policy (CSP) [1] be used to mitigate this attack?[1]: https://developer.mozilla.org/en-US/docs/Web/HTTP/CSPView on HN