"""Content Security Policy. SEC-WEB-001 / OPS-010. script-src no longer carries 'unsafe-inline': the directive that let the stored XSS of SEC-XSS-001 execute instead of being blocked. Inline scripts are authorised by a per-request nonce, and every inline event handler has been replaced by a data-action attribute dispatched from main.js. Getting here took removing 82 handlers across 17 templates, because a nonce authorises `