CSP
How to Roll Out a Strict CSP on a Legacy ASP.NET WebForms App (Without Breaking Everything)
Content-Security-Policy is one of those headers that sounds like a five-minute fix — add one line to your response, drop 'unsafe-inline', done. Then you point it at a legacy ASP.NET WebForms app and discover the framework itself is one of the worst-behaved CSP