Use plain Javascript to prevent the use of window.eval(). Then
'unsafe-eval' won't be needed to be added to script-src CSP.
Also move the mathjax config to a separate file from the inline script so
that 'unsafe-inline can also be removed from script-src CSP.
<script src="{{ "js/mathjax-config.js" | absURL }}"></script>
<!-- -->
<script type="text/javascript" src=""></script>
<!-- <script type="text/javascript" src=""></script> -->