Drop unsafe-inline from the Content-Security-Policy (closes #125) #185

Merged
clawbot merged 2 commits from issue-125-csp-no-unsafe-inline into next 2026-10-04 18:58:41 +02:00
2 Commits
Author SHA1 Message Date
clawbot 3d008b3017 Remove unsafe-inline from the Content-Security-Policy (closes #125)
check / check (push) Failing after 3s
script-src and style-src now allow only 'self'. The generator page's
two inline onclick handlers, which selected the generated URL and
copied it, move into internal/static/generator.js and are attached
with addEventListener. The bundled Tailwind script, which built styles
in the browser and injected them at runtime, is replaced by a small
hand-written internal/static/style.css holding only the rules the
login and generator pages use; the templates carry a few plain class
names in place of Tailwind's. No build step. The pages keep their
layout, not every pixel of it.

Model: opus-5-5
2026-10-04 16:37:07 +00:00
clawbot c75e942da8 Expect a Content-Security-Policy without unsafe-inline
The security headers test now expects script-src and style-src to
allow only 'self', and checks that the policy carries no
'unsafe-inline' at all. It fails until the login and generator pages
stop needing inline script and style.

Model: opus-5-5
2026-10-04 16:37:07 +00:00