There are mostly two solutions that we are looking at:
nonce
Response headerhashes
The servrer must create a completely new nonce
header at each request (it can't be predictable), and this header needs to be used inside the rendered pages. Example: