script-src and style-src now allow only 'self'; the comment explaining why they could not is gone.
The generator page's two inline onclick handlers (select the URL on click, copy it with the Copy button) move into internal/static/generator.js, loaded with a plain script tag at the end of the page and attached with addEventListener.
The 400 KB runtime Tailwind script, which built styles in the browser, is deleted. In its place internal/static/style.css is hand-written with only the rules the two pages use; the templates carry a few plain class names (login, card, page, error, result, columns, note) instead of Tailwind's utility classes. No build step.
internal/static now embeds *.css as well; the README.md line for /static/<file> says it serves the stylesheet and script.
The first commit changes only the security headers test, which fails without the second: it expects the new policy exactly and checks that it carries no unsafe-inline.
Checked by hand in a browser engine (headless Chrome against the image built from this branch), not only from served HTML: under the new policy the pages carry no inline script, style or handler, and login, URL generation and the Copy button work. The pages keep their layout, not every pixel of it.
Judgement call: an existing test is changed, as the issue's definition of done asks.
Not verified: browsers other than Chrome.
Model: opus-5-5
Implements https://git.eeqj.de/sneak/pixa/issues/125 per its plan (https://git.eeqj.de/sneak/pixa/issues/125#issuecomment-123541).
`script-src` and `style-src` now allow only `'self'`; the comment explaining why they could not is gone.
- The generator page's two inline `onclick` handlers (select the URL on click, copy it with the Copy button) move into `internal/static/generator.js`, loaded with a plain script tag at the end of the page and attached with `addEventListener`.
- The 400 KB runtime Tailwind script, which built styles in the browser, is deleted. In its place `internal/static/style.css` is hand-written with only the rules the two pages use; the templates carry a few plain class names (`login`, `card`, `page`, `error`, `result`, `columns`, `note`) instead of Tailwind's utility classes. No build step.
- `internal/static` now embeds `*.css` as well; the `README.md` line for `/static/<file>` says it serves the stylesheet and script.
The first commit changes only the security headers test, which fails without the second: it expects the new policy exactly and checks that it carries no `unsafe-inline`.
Checked by hand in a browser engine (headless Chrome against the image built from this branch), not only from served HTML: under the new policy the pages carry no inline script, style or handler, and login, URL generation and the Copy button work. The pages keep their layout, not every pixel of it.
Judgement call: an existing test is changed, as the issue's definition of done asks.
Not verified: browsers other than Chrome.
Model: opus-5-5
The security headers test now expects script-src and style-src to
allow only 'self', and checks that the policy carries no
'unsafe-inline' at all. It fails until the login and generator pages
stop needing inline script and style.
Model: opus-5-5
script-src and style-src now allow only 'self'. The generator page's
two inline onclick handlers, which selected the generated URL and
copied it, move into internal/static/generator.js and are attached
with addEventListener. The bundled Tailwind script, which built styles
in the browser and injected them at runtime, is replaced by a small
hand-written internal/static/style.css holding only the rules the
login and generator pages use; the templates carry a few plain class
names in place of Tailwind's. No build step. The pages keep their
layout, not every pixel of it.
Model: opus-5-5
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Implements #125 per its plan (#125 (comment)).
script-srcandstyle-srcnow allow only'self'; the comment explaining why they could not is gone.onclickhandlers (select the URL on click, copy it with the Copy button) move intointernal/static/generator.js, loaded with a plain script tag at the end of the page and attached withaddEventListener.internal/static/style.cssis hand-written with only the rules the two pages use; the templates carry a few plain class names (login,card,page,error,result,columns,note) instead of Tailwind's utility classes. No build step.internal/staticnow embeds*.cssas well; theREADME.mdline for/static/<file>says it serves the stylesheet and script.The first commit changes only the security headers test, which fails without the second: it expects the new policy exactly and checks that it carries no
unsafe-inline.Checked by hand in a browser engine (headless Chrome against the image built from this branch), not only from served HTML: under the new policy the pages carry no inline script, style or handler, and login, URL generation and the Copy button work. The pages keep their layout, not every pixel of it.
Judgement call: an existing test is changed, as the issue's definition of done asks.
Not verified: browsers other than Chrome.
Model: opus-5-5
PASS at
8d556472704fa5e2189a8dce5a81f4e7a834e4ff, rebased ontonextatbe6c715b36dfa7bb490dec41983477f37a9b4b6b.Model: opus-5-5
8d55647270tod268e3ac78clawbot referenced this pull request2026-10-04 18:46:51 +02:00
d268e3ac78to3d008b3017