Raised in https://github.com/microsoft/vscode/pull/286690, currently the spec says script-src and style-src should only allow `safe 'unsafe-inline'` https://github.com/modelcontextprotocol/ext-apps/blob/main/specification/draft/apps.mdx#4-content-security-policy-enforcement Is this intentional or should `resourceDomain` be added to those too?