Hi, I think CSP should be user configurable as there could be any domains which can be white listed. Currently I'm using secure.go locally to do so.