harden: drop 'unsafe-inline' from style-src #467

Merged
clawbot merged 1 commits from issue-328-style-src-self into next 2026-10-05 15:26:07 +02:00
Collaborator

Implements #328.

style-src is now 'self' in both manifests, pinned in tests/manifest.test.js. Every style="..." attribute in src/popup/index.html and in the markup the view helpers build (42 in the current tree) is now Tailwind classes. Where a scale class would compute to a different value, an arbitrary value is used (rounded-[50%], w-[10ch], text-[#cc0000]). Script still writes element.style.visibility over the invisible class, unchanged.

Not visible in the diff:

  • The address dot's colour depends on the address, so its 16 colours are whole bg-[#...] classes; Tailwind builds only the classes it finds in the source.
  • tests/contractCreation.test.js and the Chrome suite found the colour dot by its inline style; they now find it by its class.

How I checked nothing moved: temporary code in the Chrome suite (not committed) recorded every element's computed style and on-screen box on each screen the suite visits, on next and on this branch. The two matched except for the address dots' colours, since each run generates its own addresses. A temporary probe inserting one inline style attribute was refused in both browsers and failed each suite, so Firefox applied the manifest's policy rather than discarding it; it logged nothing about the policy at install.

Deviation: the Settings debug well now starts with the hidden class and is shown by removing it, replacing two .style.display assignments the issue said need no change; clearing an inline display would no longer uncover the well.

Model: opus-5-5

Implements https://git.eeqj.de/sneak/AutistMask/issues/328. `style-src` is now `'self'` in both manifests, pinned in `tests/manifest.test.js`. Every `style="..."` attribute in `src/popup/index.html` and in the markup the view helpers build (42 in the current tree) is now Tailwind classes. Where a scale class would compute to a different value, an arbitrary value is used (`rounded-[50%]`, `w-[10ch]`, `text-[#cc0000]`). Script still writes `element.style.visibility` over the `invisible` class, unchanged. Not visible in the diff: - The address dot's colour depends on the address, so its 16 colours are whole `bg-[#...]` classes; Tailwind builds only the classes it finds in the source. - `tests/contractCreation.test.js` and the Chrome suite found the colour dot by its inline style; they now find it by its class. How I checked nothing moved: temporary code in the Chrome suite (not committed) recorded every element's computed style and on-screen box on each screen the suite visits, on `next` and on this branch. The two matched except for the address dots' colours, since each run generates its own addresses. A temporary probe inserting one inline style attribute was refused in both browsers and failed each suite, so Firefox applied the manifest's policy rather than discarding it; it logged nothing about the policy at install. Deviation: the Settings debug well now starts with the `hidden` class and is shown by removing it, replacing two `.style.display` assignments the issue said need no change; clearing an inline `display` would no longer uncover the well. Model: opus-5-5
clawbot added the needs-review label 2026-10-05 14:18:20 +02:00
clawbot self-assigned this 2026-10-05 14:18:20 +02:00
Author
Collaborator

FAIL

  1. TODO.md, Completed Steps, first entry (line 48 on next): the branch no longer applies cleanly to next, which has added its entry for #315 at the same place as this branch's entry for #328. Acceptable: rebase onto the current next, keeping both entries. Only the rebase is needed.

Model: opus-5-5

FAIL 1. `TODO.md`, Completed Steps, first entry (line 48 on `next`): the branch no longer applies cleanly to `next`, which has added its entry for https://git.eeqj.de/sneak/AutistMask/issues/315 at the same place as this branch's entry for https://git.eeqj.de/sneak/AutistMask/issues/328. Acceptable: rebase onto the current `next`, keeping both entries. Only the rebase is needed. Model: opus-5-5
clawbot added needs-rebase and removed needs-review labels 2026-10-05 14:39:03 +02:00
clawbot force-pushed issue-328-style-src-self from 6c005b7893 to 685af570cc 2026-10-05 14:46:07 +02:00 Compare
clawbot added needs-review and removed needs-rebase labels 2026-10-05 14:46:15 +02:00
Author
Collaborator

Rebased onto 9776f62; only TODO.md conflicted, resolved by keeping both entries (this one above the one from #315); nothing else changed.

Model: opus-5-5

Rebased onto `9776f62`; only `TODO.md` conflicted, resolved by keeping both entries (this one above the one from https://git.eeqj.de/sneak/AutistMask/issues/315); nothing else changed. Model: opus-5-5
clawbot added 1 commit 2026-10-05 15:01:44 +02:00
harden: drop 'unsafe-inline' from style-src (closes #328)
check / check (push) Waiting to run
e2e / e2e-chrome (push) Waiting to run
e2e / e2e-firefox (push) Waiting to run
f476e77732
The popup's markup no longer carries style attributes. The 42 in
index.html and in the HTML the view helpers build are now Tailwind
classes, each computing to the value it replaced, so style-src is 'self'
in both manifests, pinned in tests/manifest.test.js.

The address dot's 16 colours are written out as whole classes, because
Tailwind builds only the classes it finds in the source. The Settings
debug well is shown and hidden with the hidden class, since clearing an
inline display no longer uncovers it. Two tests that found the colour dot
by its inline style now find it by its class. Script that sets
element.style is unaffected.

Model: opus-5-5
clawbot force-pushed issue-328-style-src-self from 685af570cc to f476e77732 2026-10-05 15:01:44 +02:00 Compare
Author
Collaborator

Rebased onto a0360a7 (next, after #468); only TODO.md conflicted and both Completed Steps entries are kept, the #328 entry on top; nothing else changed.

Model: opus-5-5

Rebased onto `a0360a7` (`next`, after https://git.eeqj.de/sneak/AutistMask/pulls/468); only `TODO.md` conflicted and both Completed Steps entries are kept, the https://git.eeqj.de/sneak/AutistMask/issues/328 entry on top; nothing else changed. Model: opus-5-5
Author
Collaborator

PASS

Model: opus-5-5

PASS Model: opus-5-5
clawbot merged commit e590b83df0 into next 2026-10-05 15:26:07 +02:00
clawbot deleted branch issue-328-style-src-self 2026-10-05 15:26:08 +02:00
Sign in to join this conversation.
No Reviewers
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sneak/AutistMask#467