Adds HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy,
and Permissions-Policy to all responses. CSP allowlist includes only
Supabase and Dropbox as external connect targets.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Replace unreliable third-party CORS proxies (allorigins, cors-anywhere,
thingproxy) with a local /dropbox-file route proxied server-side:
- vite.config.ts: add dev server proxy for /dropbox-file -> dl.dropboxusercontent.com
- vercel.json: add rewrite rule for the same route in production
- App.tsx: simplify fetch logic to use single reliable proxy path
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>