harden: drop 'unsafe-inline' from style-src (closes #328)
The popup's markup no longer carries style attributes. The 42 in index.html and in the HTML the view helpers build are now Tailwind classes, each computing to the value it replaced, so style-src is 'self' in both manifests, pinned in tests/manifest.test.js. The address dot's 16 colours are written out as whole classes, because Tailwind builds only the classes it finds in the source. The Settings debug well is shown and hidden with the hidden class, since clearing an inline display no longer uncovers it. Two tests that found the colour dot by its inline style now find it by its class. Script that sets element.style is unaffected. Model: opus-5-5
This commit was merged in pull request #467.
This commit is contained in:
@@ -45,6 +45,17 @@ but the review is broader than any of them.
|
||||
|
||||
# Completed Steps
|
||||
|
||||
- 2026-10-05: The popup's Content Security Policy no longer allows inline style
|
||||
([#328](https://git.eeqj.de/sneak/AutistMask/issues/328)): `style-src` is
|
||||
`'self'` in both manifests, pinned in `tests/manifest.test.js`. The 42
|
||||
`style="..."` attributes in `src/popup/index.html` and in the markup the view
|
||||
helpers build are now Tailwind classes, each computing to the value it
|
||||
replaced. The 16 address dot colours are written out as whole classes, because
|
||||
Tailwind builds only the classes it finds in the source. The Settings debug
|
||||
well is shown and hidden with the `hidden` class, since clearing an inline
|
||||
`display` no longer uncovers it. Script that sets `element.style` is
|
||||
unaffected.
|
||||
|
||||
- 2026-10-05: `.prettierignore` no longer lists an AI vendor's tool directory
|
||||
([#363](https://git.eeqj.de/sneak/AutistMask/issues/363)). The directory is
|
||||
not tracked, so the line ignored nothing.
|
||||
|
||||
Reference in New Issue
Block a user