c75839d3ea
Every tile, the hero and the folder covers switched to a <canvas> when the per-event toggle was on or the protection level was `maximum`. A canvas pins a backing store of naturalWidth × naturalHeight × 4 bytes that the browser is not allowed to evict, and iOS Safari has a hard budget for canvas memory that fails silently when exceeded — blank tiles, no error, on exactly the browser the large-gallery report came from. A gallery is several hundred tiles and one lightbox image. What canvas buys on a thumbnail is a slightly harder right-click. What actually protects the images is server-side: the served file is watermarked and the download route refuses when downloads are off. The photographer who reported the large-gallery case, shipping to real clients, said the same and turned the global toggle off once it was about to reach their next gallery. So: tiles, hero and folder covers always render <img>. The lightbox keeps both the per-event toggle and the `maximum` implication — one image, where the calculus is different. The toggle is now wired to the lightbox for the first time; before this it reached only the tiles, so the label that said "canvas rendering" turned every grid into canvases and left the lightbox alone. Labels in all four locales now say where it applies. `protectionLevel` was destructured in seven tile components only to feed that OR; those props and their pass-throughs go with it. The shared layout props keep it, since the story layout still hands it to its lightbox. A source-level test pins that only PhotoLightbox passes useCanvasRendering to AuthenticatedImage or turns it on for `maximum`. Relates to issue 1287