// Diagnostic page for wallet sign-in failures. Reports what the page can // actually see, from the member's own device, instead of us guessing. // // It captures the one thing we cannot infer from the outside: whether a CSP // violation is firing when the wallet tries to inject its provider. Our // script-src is 'self' with no 'unsafe-inline', and wallet browsers that inject // via a