Custom branding images now render
Fixed a bug where custom logo, favicon, and login-background images configured with external URLs were blocked by the content security policy and never displayed. The image policy now allows external HTTPS sources (images are display-only) and can be tightened or extended through the new CSP_IMG_SRC setting. The app also ships a default favicon.
No action required. Configured branding images render immediately after upgrade.