Remove unsafe-inline from the Content-Security-Policy (closes #125)
check / check (push) Failing after 2s
check / check (push) Failing after 2s
script-src and style-src now allow only 'self'. The generator page's two inline onclick handlers, which selected the generated URL and copied it, move into internal/static/generator.js and are attached with addEventListener. The bundled Tailwind script, which built styles in the browser and injected them at runtime, is replaced by a small hand-written internal/static/style.css holding only the rules the login and generator pages use; the templates carry a few plain class names in place of Tailwind's. No build step. The pages keep their layout, not every pixel of it. Model: opus-5-5
This commit was merged in pull request #185.
This commit is contained in:
@@ -53,7 +53,7 @@ func (s *Server) SetupRoutes() {
|
||||
// Robots.txt
|
||||
s.router.Get("/robots.txt", s.h.HandleRobotsTxt())
|
||||
|
||||
// Static files (Tailwind CSS, etc.)
|
||||
// The login and generator pages' stylesheet and script
|
||||
s.router.Handle("/static/*", http.StripPrefix("/static/", static.Handler()))
|
||||
|
||||
// Login/generator UI. The form routes carry CSRF protection; the
|
||||
|
||||
Reference in New Issue
Block a user