We are using SmartClient v131p_2025-10-18_Enterprise. Currently in the CSP response header, we have script-src 'self' 'unsafe-inline' 'unsafe-eval',...