v1.4.8
Removed unsafe-inline scripts. If you previously customized the Headers__Security__ContentSecurity
setting, now feel free to rely on the default which does not allow unsafe-inline scripts.
Fixed the password login failed attempt lockout to show immediately rather than on a subsequent attempt.
Better support for OAuth pass-through to OIDC.