exorcise: template user-facing copy
Remediate audit Run 21 findings across server
audit Run 15 Phase 5: CSP script-src drops 'unsafe-inline'
ux: extract all executable inline JS from templates into static files