⚖ CSP: the 'nonce-value' allows external stylesheets from any sources and allows inline styles without 'unsafe-inline' in the style-src, but does not allow @import; 'nonce-value' is case-sensitive
⚖ Browsers support of style-src-attr directive of Content-Security-Policy; the style-src-attr directive allows inline styles in the style attribute of HTML elements and tags; the keys 'nonce-value' and 'hash-value' are not allowed in
Content Security Policy – A Pen Tester's Guide | Outpost24 blog
How to whitelist dynamically created scripts in a WebForms project using CSP (Content Security Policy)? - Stack Overflow
Content Security Policy: The Easy Way to Prevent Mixed Content | CSS-Tricks - CSS-Tricks
⚖ Browsers support of style-src-attr directive of Content-Security-Policy; the style-src-attr directive allows inline styles in the style attribute of HTML elements and tags; the keys 'nonce-value' and 'hash-value' are not allowed in
eCyLabs: Application Security Posture Management
A Refined Content Security Policy | WebKit
Secure Coding Guidelines for Content Security Policy | GnuDeveloper.com