There’s some information in this post that may help: Mitigate XSS Attacks with Content Security Policy