Add too-strict Content-Security-Policy
Modern Web Security introduces a second line-of-defense against an attacker even on a vulnerable web page.
This is a 101, a discussion starter for the smallest project I can think of. However, it uses Auth.SCH, which makes configuration interesting.
WIP; probably breaks if merged as-is
Edited by Réthelyi Bálint