http
HTTP/2 200 OK
Content-Type: text/html
Content-Security-Policy: script-src-attr 'none'; script-src 'self'
<!DOCTYPE html>
<html>
<body>
<button id="submit">Submit</button> <!-- OK -->
<button onclick="submitForm()">Submit</button> <!-- Blocked -->
<script src="/app.js"></script> <!-- OK durch script-src -->
<script>
document.getElementById('submit').addEventListener('click', submitForm);
</script>
</body>
</html>