Cross-Site Script Inclusion

unsafe-interpolation.py
@app.route('/js/bundle.js')
def javascript:
  """Don't ever do this!"""
  return render_template('js/bundle.js', INSERT_API_KEY_HERE=session.api_key)