Conversation

Firefox/Safari don't support strict CSP in a reasonable way. They're missing several other important security features too, but it doesn't block deploying them for more modern/secure browsers. Trusted Types is easily the most impactful mitigation especially with 'none' policy...