/**
* The cockpit's Content-Security-Policy, and the nonce injection into the page.
*
* Why a CSP here: the transcript renders **Markdown produced by the agent**,
* i.e. content derived from what the agent read (a file in a cloned repo, a web
* page, a Telegram message). `marked` lets raw HTML through. With no guard, an
* `
` planted in a README runs inside the cockpit — which can
* create a cron, hence run a shell command. Sanitising (DOMPurify, client-side)
* is the first barrier; the CSP is the one that still holds when the sanitiser
* has a hole.
*
* Everything here is pure; the wiring lives in server.ts.
*/
/**
* Marker hardcoded in `public/index.html`, replaced by the real nonce on every
* request.
*
* A literal string replacement, not a tag rewrite: we want neither to parse
* HTML nor to risk "nonce-ing" a `