Files
pixa/internal/static/static.go
T
clawbot 3d008b3017
check / check (push) Failing after 3s
Remove unsafe-inline from the Content-Security-Policy (closes #125)
script-src and style-src now allow only 'self'. The generator page's
two inline onclick handlers, which selected the generated URL and
copied it, move into internal/static/generator.js and are attached
with addEventListener. The bundled Tailwind script, which built styles
in the browser and injected them at runtime, is replaced by a small
hand-written internal/static/style.css holding only the rules the
login and generator pages use; the templates carry a few plain class
names in place of Tailwind's. No build step. The pages keep their
layout, not every pixel of it.

Model: opus-5-5
2026-10-04 16:37:07 +00:00

22 lines
396 B
Go

// Package static provides embedded static files for the web UI.
package static
import (
"embed"
"io/fs"
"net/http"
)
//go:embed *.css *.js
var files embed.FS
// FS returns the embedded filesystem containing static files.
func FS() fs.FS {
return files
}
// Handler returns an http.Handler that serves static files.
func Handler() http.Handler {
return http.FileServer(http.FS(files))
}