b51c055a12
Follow-ups on the cherry-picked handler: - a throwing observer can no longer change the decision; the handler returns an explicit deny regardless of logging failures - the denied-URL log carries origin only, so query tokens / signed URLs from attacker-controlled content never reach the persisted desktop log - the hidden link-title window (loads arbitrary user-linked pages on render, had no window-open handler at all) now denies too - tests trimmed to two invariants (proven red against the pre-fix shape)