frontend: fix CSP-dead modal close buttons, consolidate escapeHtml (audit Run 20 Phase 6)
audit Run 15 Phase 2: security fixes
ux: extract all executable inline JS from templates into static files