diff --git a/README.md b/README.md index 99f7b9e..c6f3ae9 100644 --- a/README.md +++ b/README.md @@ -814,13 +814,15 @@ discoverable. on critical screens and when space is available to allow users to disambiguate addresses visually, as a security feature. - **Tailwind CSS**: Utility-first CSS via Tailwind. No custom CSS classes for - styling. Tailwind is configured with a minimal monochrome palette. This keeps - the styling co-located with the markup and eliminates CSS file management. The - handful of classes in `styles/main.css` are not styling: `.copy-flash-*` - carries the copy feedback animation, and `.am-address` carries the rule that - an address never wraps. Both are invariants that hold in every place they - appear, and spelling either out as repeated utilities is how one of those - places drifts away from the rest. + styling, and no `style="..."` attributes, which the + [Content Security Policy](#content-security-policy) refuses. Tailwind is + configured with a minimal monochrome palette. This keeps the styling + co-located with the markup and eliminates CSS file management. The handful of + classes in `styles/main.css` are not styling: `.copy-flash-*` carries the copy + feedback animation, and `.am-address` carries the rule that an address never + wraps. Both are invariants that hold in every place they appear, and spelling + either out as repeated utilities is how one of those places drifts away from + the rest. - **Vanilla JS**: No framework (React, Vue, Svelte, etc.). The popup UI is small enough that vanilla JS with simple view switching is sufficient. A framework would add bundle size, build complexity, and attack surface for no benefit at @@ -2213,7 +2215,7 @@ a bare string in `manifest/firefox.json` (MV2): ``` default-src 'self'; script-src 'self' 'wasm-unsafe-eval'; object-src 'self'; -style-src 'self' 'unsafe-inline'; img-src 'self' data:; +style-src 'self'; img-src 'self' data:; connect-src 'self' https: http:; frame-src 'none'; form-action 'none'; base-uri 'none' ``` @@ -2225,15 +2227,17 @@ wallet's own UI. Escaping is the primary fix for that (see `src/shared/html.js`); this is the second line, so an escape that does slip cannot reach the network. -Four directives are looser than `'self'`, each for a reason that does not +`style-src 'self'` admits the stylesheet and nothing inline: both browsers +refuse a `style="..."` attribute and a `