This page has a CSP: script-src 'none' script-src-attr 'unsafe-inline'