How to break your site with a content security policy: an illustrated example