Drop unsafe-inline from the Content-Security-Policy (closes #125) #185

Merged
clawbot merged 2 commits from issue-125-csp-no-unsafe-inline into next 2026-10-04 18:58:41 +02:00
Collaborator

Implements #125 per its plan (#125 (comment)).

script-src and style-src now allow only 'self'; the comment explaining why they could not is gone.

  • The generator page's two inline onclick handlers (select the URL on click, copy it with the Copy button) move into internal/static/generator.js, loaded with a plain script tag at the end of the page and attached with addEventListener.
  • The 400 KB runtime Tailwind script, which built styles in the browser, is deleted. In its place internal/static/style.css is hand-written with only the rules the two pages use; the templates carry a few plain class names (login, card, page, error, result, columns, note) instead of Tailwind's utility classes. No build step.
  • internal/static now embeds *.css as well; the README.md line for /static/<file> says it serves the stylesheet and script.

The first commit changes only the security headers test, which fails without the second: it expects the new policy exactly and checks that it carries no unsafe-inline.

Checked by hand in a browser engine (headless Chrome against the image built from this branch), not only from served HTML: under the new policy the pages carry no inline script, style or handler, and login, URL generation and the Copy button work. The pages keep their layout, not every pixel of it.

Judgement call: an existing test is changed, as the issue's definition of done asks.
Not verified: browsers other than Chrome.

Model: opus-5-5

Implements https://git.eeqj.de/sneak/pixa/issues/125 per its plan (https://git.eeqj.de/sneak/pixa/issues/125#issuecomment-123541). `script-src` and `style-src` now allow only `'self'`; the comment explaining why they could not is gone. - The generator page's two inline `onclick` handlers (select the URL on click, copy it with the Copy button) move into `internal/static/generator.js`, loaded with a plain script tag at the end of the page and attached with `addEventListener`. - The 400 KB runtime Tailwind script, which built styles in the browser, is deleted. In its place `internal/static/style.css` is hand-written with only the rules the two pages use; the templates carry a few plain class names (`login`, `card`, `page`, `error`, `result`, `columns`, `note`) instead of Tailwind's utility classes. No build step. - `internal/static` now embeds `*.css` as well; the `README.md` line for `/static/<file>` says it serves the stylesheet and script. The first commit changes only the security headers test, which fails without the second: it expects the new policy exactly and checks that it carries no `unsafe-inline`. Checked by hand in a browser engine (headless Chrome against the image built from this branch), not only from served HTML: under the new policy the pages carry no inline script, style or handler, and login, URL generation and the Copy button work. The pages keep their layout, not every pixel of it. Judgement call: an existing test is changed, as the issue's definition of done asks. Not verified: browsers other than Chrome. Model: opus-5-5
clawbot added the needs-review label 2026-10-04 15:27:04 +02:00
clawbot self-assigned this 2026-10-04 15:27:04 +02:00
Author
Collaborator

PASS at 8d556472704fa5e2189a8dce5a81f4e7a834e4ff, rebased onto next at be6c715b36dfa7bb490dec41983477f37a9b4b6b.

Model: opus-5-5

**PASS** at `8d556472704fa5e2189a8dce5a81f4e7a834e4ff`, rebased onto `next` at `be6c715b36dfa7bb490dec41983477f37a9b4b6b`. Model: opus-5-5
clawbot force-pushed issue-125-csp-no-unsafe-inline from 8d55647270 to d268e3ac78 2026-10-04 18:18:05 +02:00 Compare
clawbot added 2 commits 2026-10-04 18:49:17 +02:00
The security headers test now expects script-src and style-src to
allow only 'self', and checks that the policy carries no
'unsafe-inline' at all. It fails until the login and generator pages
stop needing inline script and style.

Model: opus-5-5
script-src and style-src now allow only 'self'. The generator page's
two inline onclick handlers, which selected the generated URL and
copied it, move into internal/static/generator.js and are attached
with addEventListener. The bundled Tailwind script, which built styles
in the browser and injected them at runtime, is replaced by a small
hand-written internal/static/style.css holding only the rules the
login and generator pages use; the templates carry a few plain class
names in place of Tailwind's. No build step. The pages keep their
layout, not every pixel of it.

Model: opus-5-5
clawbot force-pushed issue-125-csp-no-unsafe-inline from d268e3ac78 to 3d008b3017 2026-10-04 18:49:17 +02:00 Compare
clawbot merged commit 842372250f into next 2026-10-04 18:58:41 +02:00
clawbot deleted branch issue-125-csp-no-unsafe-inline 2026-10-04 18:58:41 +02:00
Sign in to join this conversation.
No Reviewers
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sneak/pixa#185