807ae3d4fa
Serve uploaded SVGs (admin logos etc.) with a restrictive Content-Security-Policy (default-src 'none'; style-src 'unsafe-inline'; img-src 'self' data:) + X-Content-Type-Options: nosniff in secureStatic. The browser still renders the vector, but any embedded <script>/on* handler can't execute if the SVG is opened directly — keeps real SVGs (scalable) instead of rasterising them. Applies to all secureStatic mounts (uploads/photos/thumbnails/fonts); only SVGs get the header.