* add unsafe-inline directive to style-src
* debugging - turn on csp reporting
* revert reporting only csp
* do not inline JS and CSS in build
* enable HTTPs only when in production mode
* remove debug printf
* fix clean target
* revert force_https removal