Bsidessf 2018 - No More Xss: Deploying Csp With Nonces And Strict-Dynamic