Mozilla Bug 671389 - Implement CSP sandbox directive

I am a top-level page sandboxed with "allow-scripts allow-forms allow-same-origin".