Add a nonce to each script and style tags, sha256 hashes to inline events, and set them in CSP header.