wow. This is absolutely as insecure as `unsafe-inline` IMHO. I wonder why the spec doesn't mandate the `unsafe-` prefix for `data` too.
CSP really feels a bit half-baked between the various browsers. With the issue brought up here, all major browsers with CSP support have some annoying or even show-stopping bugs:
- Chrome treats responses with `content-type: application/pdf` as responses rendered with a plugin even though Chrome renders PDFs without the need for a plugin to be installed (the fact it's a plugin doing the rendering is an implementation detail). So if you want to even just link to PDFs, you have to enable `object-src`
- Firefox treats scripts running from bookmarklets as being scripts that are directly on the page. This means that unless you list `script-src: unsafe-inline`, your CSP policy can disable the user's ability to use bookmarklets. This is the single instance where a site owner has control over the user agent without the user having ultimate veto powers.