Files
pixa/internal/templates/login.html
T
clawbot 842372250f
check / check (push) Failing after 2s
Remove unsafe-inline from the Content-Security-Policy (closes #125)
script-src and style-src now allow only 'self'. The generator page's
two inline onclick handlers, which selected the generated URL and
copied it, move into internal/static/generator.js and are attached
with addEventListener. The bundled Tailwind script, which built styles
in the browser and injected them at runtime, is replaced by a small
hand-written internal/static/style.css holding only the rules the
login and generator pages use; the templates carry a few plain class
names in place of Tailwind's. No build step. The pages keep their
layout, not every pixel of it.

Model: opus-5-5
2026-10-04 18:58:40 +02:00

42 lines
1014 B
HTML

<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="UTF-8">
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<title>Pixa - Login</title>
<link rel="stylesheet" href="/static/style.css">
</head>
<body class="login">
<div class="card">
<h1>Pixa Image Proxy</h1>
{{if .Error}}
<div class="error">
{{.Error}}
</div>
{{end}}
<form method="POST" action="/">
{{ .CSRFField }}
<div>
<label for="key">
Signing Key
</label>
<input
type="password"
id="key"
name="key"
required
autocomplete="current-password"
placeholder="Enter your signing key"
>
</div>
<button type="submit">
Login
</button>
</form>
</div>
</body>
</html>