Load Alpine's CSP build so the UI's directives run (closes #371)
check / check (push) Successful in 3m27s
check / check (push) Successful in 3m27s
Every page's Content-Security-Policy forbids eval, which the standard Alpine.js build needs, so no directive ran in a browser: both add forms on the webhook page showed open, and events in the event log could not be collapsed. The UI now loads Alpine's CSP build (@alpinejs/csp 3.14.9 in 3p/); the policy is unchanged. Each directive names a property or method of a component registered in static/js/app.js (collapsible, targetForm), and each card holds its own x-data. A browser test, built only with the browser tag, loads the webhook page and the event log under the real headers; make test-browser runs it in Docker. New test-only dependency chromedp, which raises golang.org/x/sys to 0.47.0. Model: opus-5-5
This commit was merged in pull request #411.
This commit is contained in:
@@ -1,4 +1,4 @@
|
||||
.PHONY: bootstrap setup assets test lint fmt fmt-check check build run dev deps docker clean hooks css version
|
||||
.PHONY: bootstrap setup assets test test-browser lint fmt fmt-check check build run dev deps docker clean hooks css version
|
||||
|
||||
# Default target
|
||||
.DEFAULT_GOAL := check
|
||||
@@ -33,6 +33,9 @@ assets:
|
||||
test:
|
||||
@script/test
|
||||
|
||||
test-browser:
|
||||
@script/test-browser
|
||||
|
||||
lint:
|
||||
@script/lint
|
||||
|
||||
|
||||
Reference in New Issue
Block a user