rationale for setting `'unsafe-inline'` is that it cannot be more void than the lack of `script-src` but it still might add some benefits
Windmill API
The API server, exposing functionality to other components and the frontend
This crate exposes both a library as well as a binary target.