From c75e942da8e66bc6d93be8656cc2aefc162fd47b Mon Sep 17 00:00:00 2001 From: clawbot <35+clawbot@noreply.example.org> Date: Sun, 4 Oct 2026 13:00:12 +0000 Subject: [PATCH] Expect a Content-Security-Policy without unsafe-inline The security headers test now expects script-src and style-src to allow only 'self', and checks that the policy carries no 'unsafe-inline' at all. It fails until the login and generator pages stop needing inline script and style. Model: opus-5-5 --- internal/middleware/middleware_internal_test.go | 11 +++++++++-- 1 file changed, 9 insertions(+), 2 deletions(-) diff --git a/internal/middleware/middleware_internal_test.go b/internal/middleware/middleware_internal_test.go index d57d081..91ba3f3 100644 --- a/internal/middleware/middleware_internal_test.go +++ b/internal/middleware/middleware_internal_test.go @@ -325,6 +325,13 @@ func TestSecurityHeaders_PolicyHeaders(t *testing.T) { handler.ServeHTTP(rec, req) + // The login and generator pages load their script and stylesheet from + // /static, so the policy allows no inline script or style. + csp := rec.Header().Get("Content-Security-Policy") + if strings.Contains(csp, "unsafe-inline") { + t.Errorf("Content-Security-Policy allows unsafe-inline: %q", csp) + } + tests := []struct { header string want string @@ -333,8 +340,8 @@ func TestSecurityHeaders_PolicyHeaders(t *testing.T) { { "Content-Security-Policy", "default-src 'self'; " + - "script-src 'self' 'unsafe-inline'; " + - "style-src 'self' 'unsafe-inline'; " + + "script-src 'self'; " + + "style-src 'self'; " + "object-src 'none'; " + "base-uri 'self'; " + "form-action 'self'; " +