Immediately after switching the page, it will work with CSR.
Please reload your browser to see how it works.
I don;t understand why it's a problem that the client (in principle) can handle values that the server will never send. Just don't send them, and you don;t have to worry about perplexing riddles like "but what would happen if I did?"
Try going to https://example.com/somepath and entering the following into the browser console:
I get