That would have been my first question as well.
It can work, if you specifically add the hash of that bit of JS to script-src or use the nonce based approach (I never figured that one out).
Otherwise it's unsafe-inline, at which point you may aswell not bother ;)