https://sansec.io/research/skimming-google-defeats-csp