Load Alpine's CSP build so the UI's directives run (closes #371)
check / check (push) Successful in 4m4s

The pages' Content-Security-Policy forbids eval, which the standard
Alpine.js build needs, so no directive ran: add forms showed open and
events never collapsed. 3p/ now holds the @alpinejs/csp 3.14.9 tarball
instead, and every directive in templates/ names a property or method
of a component registered in static/js/app.js, as that build requires.
The policy is unchanged.

A browser test in internal/server, built only with the browser tag,
loads the webhook page and the event log under the real headers.
make test-browser runs it in Docker, in a digest-pinned headless
browser image (Dockerfile.browser).

Model: opus-5-5
This commit is contained in:
2026-10-02 03:00:11 +00:00
parent bfdbc937c6
commit 383786b23a
15 changed files with 561 additions and 51 deletions
+3
View File
@@ -7,6 +7,9 @@ version: "2"
run:
timeout: 5m
modules-download-mode: readonly
# Lint the browser test too (make test-browser builds it with this tag).
build-tags:
- browser
linters:
default: all