>Banning inline script is the biggest security win CSP provides, and banning inline style likewise hardens your application.[1]
So which is it? Should we be moving away from inline scripts and CSS, and tightening it up with CSP, or is performance/fewer requests more desirable? Also, with HTTP2, the performance issue seems moot.
[1]http://www.html5rocks.com/en/tutorials/security/content-secu...