How to bypass CSP nonces with DOM XSS