BSides DC 2015 - Fixing XSS with Content Security Policy