"""Content Security Policy, and the migration away from 'unsafe-inline'. SEC-WEB-001 / OPS-010. script-src still carries 'unsafe-inline', which is why the stored XSS of SEC-XSS-001 executed instead of being blocked. Removing it is not a one-line change. A nonce authorises `