The security headers test now expects script-src and style-src to allow only 'self', and checks that the policy carries no 'unsafe-inline' at all. It fails until the login and generator pages stop needing inline script and style. Model: opus-5-5