Our web application implements a Content Security Policy (CSP), but I’m concerned about potential bypasses through code injection. Additionally, attackers might try to access internal server resources by exploiting vulnerabilities. How can we strengthen our CSP and secure internal resources against such threats?