Build a safe URL from template, or null if it cannot be made safe.
Returns null rather than throwing: an unusable link is a no-op click, not an
error condition, and the caller has nothing useful to do with an exception.
The reason is returned separately by explainLinkRejection for the
one caller that wants to log it once at scene load.
Build a safe URL from
template, or null if it cannot be made safe.Returns null rather than throwing: an unusable link is a no-op click, not an error condition, and the caller has nothing useful to do with an exception. The reason is returned separately by explainLinkRejection for the one caller that wants to log it once at scene load.