@mdh I feel like there could definitely be some meaningful progress here. A form of #CSP and a `--no-eval` sound straightforward.
I'm not sure how #gRPCWeb factors into this though. From a security perspective, how is that different from a traditional #HTTP #REST service?