Content-Security-Policy: connect-src 'none' blocks every fetch, XHR, WebSocket, sendBeacon. Your browser will refuse to send data out.Subresource Integrity hashes pinned.Ctrl-S), disconnect from the network, and re-open it. It still works. Audit the source â ~300 lines.