Drops 'unsafe-inline' + broad host sources from script-src; a per-request nonce is injected into
every <script> at render time and 'strict-dynamic' covers htmx-swapped + player-API scripts.
Testing on BETA only first — htmx nav / embeds may break under the strict policy; do NOT roll to
the fleet until validated.
(No files)
Note:
See TracChangeset
for help on using the changeset viewer.