From 173c843107931be9b74c63e644207bb6e88d3c5b Mon Sep 17 00:00:00 2001 From: rager306 Date: Sun, 22 Mar 2026 16:18:15 +0700 Subject: [PATCH] fix: replace unsafe-inline CSP with per-request nonce MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The dashboard CSP uses 'unsafe-inline' for script-src, which permits any inline \n", - "\n", - "\n", // App code - "\n", // Alpine.js MUST be last — it processes x-data and fires alpine:init - "\n", ""