| Age | Commit message (Collapse) | Author | |
|---|---|---|---|
| 2026-07-19 | Log CSP violations to their own file instead of relying on Rails.logger | erdgeist | |
| 2026-07-19 | Add a 500er logger and a trip wire in admin/boom to test it | erdgeist | |
| 2026-07-18 | Emit a report-only Content-Security-Policy with nonced inline scripts | erdgeist | |
| - dark-mode restore now travels nonced, the admin constants likewise - AUTH_TOKEN deleted in favour of the csrf meta tag - new report collector at /csp_reports | |||
