Two conflicting <meta> CSP tags in index.html (plus a separate _headers policy) meant the browser enforced their intersection, which blocked the Cloudflare Insights beacon script and its inline bootstrap. k5bss.html had the same gap in its own CSP. Consolidated to one consistent policy per surface that allows static.cloudflareinsights.com / cloudflareinsights.com, and moved index.html's inline script and onerror handler into js/main.js so script-src no longer needs 'unsafe-inline' there. Also added the missing fonts/ibm-plex-mono-400.woff2 that style.css has referenced since it was wired up, which was 404ing. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> |
||
|---|---|---|
| .. | ||
| css2@family=IBM+Plex+Mono%3Awght@300;400;500;600&family=IBM+Plex+Sans%3Awght@300;400;500&display=swap | ||
| ibm-plex-mono-400.woff2 | ||