I recently added a CSP to my project but found that the I have to include 'unsafe-inline' for scripts for the Supertokens dashboard to work (https://supertokens.com/docs/post-authentication/dashboard/initial-setup). This basically defeats the purpose of having a CSP.