fix: add 'unsafe-inline' to CSP script-src for token injection 7636cf1 tao-shen Claude Opus 4.6 commited on Feb 28
fix: disable auth (mode:none) + patch CSP frame-ancestors for HF iframe embedding 1469692 tao-shen commited on Feb 28