fix: add 'unsafe-inline' to CSP script-src for token injection ce71ed6 tao-shen Claude Opus 4.6 commited on Feb 28
fix: use global variable for token injection (works in incognito iframe) 7b4c5b7 tao-shen Claude Opus 4.6 commited on Feb 28
fix: disable auth (mode:none) + patch CSP frame-ancestors for HF iframe embedding 331869d tao-shen commited on Feb 28