We have been using Mozilla observatory to nudge us to improve our webserver configurations; tighten them up. We can put a few headers in apache/nginx/IIS to bring our site up to level B but a sticking point is CSP – Content Security Policy. CSP is for controlling script origins and mitigating XSS (cross site scripting), …