Congrats for doing this!
Regarding this:
> There should be no problems with running on a publicly-accessible server [...]
Looking at the https://github.com/jarmo/secrets-web source code, I don't see any place where it sets the `Content-Security-Policy` header. Or am I missing something?