← v2026.3.23

CSP Script Hashes

v2026.3.23 · Release notes

SHA-256 hashes for inline scripts in Control UI CSP directive.

CSP Script Hashes

Control UI now computes SHA-256 hashes for inline <script> blocks in the served index.html and includes them in the script-src CSP directive. Inline scripts remain blocked by default; only explicitly hashed bootstrap code is allowed.