Remove unsafe-inline from the Content-Security-Policy (closes #125)
check / check (push) Failing after 2s
check / check (push) Failing after 2s
script-src and style-src now allow only 'self'. The generator page's two inline onclick handlers, which selected the generated URL and copied it, move into internal/static/generator.js and are attached with addEventListener. The bundled Tailwind script, which built styles in the browser and injected them at runtime, is replaced by a small hand-written internal/static/style.css holding only the rules the login and generator pages use; the templates carry a few plain class names in place of Tailwind's. No build step. The pages keep their layout, not every pixel of it. Model: opus-5-5
This commit is contained in:
@@ -0,0 +1,10 @@
|
||||
// Generator page: a click on the generated URL selects it, and the Copy
|
||||
// button copies it. Both are on the page only once a URL has been generated.
|
||||
const generatedURL = document.getElementById("generated-url");
|
||||
|
||||
if (generatedURL) {
|
||||
generatedURL.addEventListener("click", () => generatedURL.select());
|
||||
document.getElementById("copy-url").addEventListener("click", () => {
|
||||
navigator.clipboard.writeText(generatedURL.value);
|
||||
});
|
||||
}
|
||||
Reference in New Issue
Block a user