Interesting dive in to some HTML injection involving Mastodon.
https://portswigger.net/research/stealing-passwords-from-infosec-mastodon-without-bypassing-csp
https://portswigger.net/research/stealing-passwords-from-infosec-mastodon-without-bypassing-csp