Review https://github.com/google/csp-evaluator for things that Google catches, that we don't. Also https://csp.withgoogle.com/docs/strict-csp.html