Load Alpine's CSP build so the UI's directives run (closes #371) #411

Open
clawbot wants to merge 1 commits from issue-371-alpine-csp-build into next
Collaborator

Every page's Content-Security-Policy forbids eval, and the standard Alpine.js build compiles each directive with the Function constructor, so in a browser no directive ran: both add forms on the webhook page showed open, and an event in the event log could not be collapsed.

The UI now loads Alpine's CSP build. The @alpinejs/csp 3.14.9 tarball replaces the alpinejs one in 3p/, and script/assets extracts it as before; the policy is unchanged. That build cannot run expressions, so each directive in templates/ now names a property or method of a component registered in static/js/app.js: collapsible for everything a click shows and hides, and targetForm for the add target form's per-type fields. Besides directive attributes, the only markup change is that each card on the webhook page holds its own x-data in place of the page-wide one, so open UI branches should rebase with small conflicts.

A new test in internal/server loads the webhook page and the event log in headless Chromium under the real headers. It checks that both add forms stay hidden until Add is clicked, that choosing Slack stops the HTTP fields from being submitted, that an event expands and collapses, and that the pages log no console warnings. It fails on the old tree.

  • Judgement call: the test skips without chromium on PATH. The Dockerfile's test stage installs Debian's chromium, unpinned like its other packages.
  • Deviation: the type select's x-model became @change; the 3.14.9 CSP build cannot assign through x-model.
  • New test-only dependency chromedp; it raises golang.org/x/sys to 0.47.0.
  • The registry publishes a sha512 integrity, not a sha256; the tarball matches it.

Model: opus-5-5

Every page's Content-Security-Policy forbids eval, and the standard Alpine.js build compiles each directive with the `Function` constructor, so in a browser no directive ran: both add forms on the webhook page showed open, and an event in the event log could not be collapsed. The UI now loads Alpine's CSP build. The `@alpinejs/csp` 3.14.9 tarball replaces the `alpinejs` one in `3p/`, and `script/assets` extracts it as before; the policy is unchanged. That build cannot run expressions, so each directive in `templates/` now names a property or method of a component registered in `static/js/app.js`: `collapsible` for everything a click shows and hides, and `targetForm` for the add target form's per-type fields. Besides directive attributes, the only markup change is that each card on the webhook page holds its own `x-data` in place of the page-wide one, so open UI branches should rebase with small conflicts. A new test in `internal/server` loads the webhook page and the event log in headless Chromium under the real headers. It checks that both add forms stay hidden until Add is clicked, that choosing Slack stops the HTTP fields from being submitted, that an event expands and collapses, and that the pages log no console warnings. It fails on the old tree. - Judgement call: the test skips without `chromium` on `PATH`. The Dockerfile's test stage installs Debian's `chromium`, unpinned like its other packages. - Deviation: the type select's `x-model` became `@change`; the 3.14.9 CSP build cannot assign through `x-model`. - New test-only dependency `chromedp`; it raises `golang.org/x/sys` to 0.47.0. - The registry publishes a sha512 integrity, not a sha256; the tarball matches it. Model: opus-5-5
clawbot self-assigned this 2026-10-02 00:23:07 +02:00
clawbot added 1 commit 2026-10-02 00:23:08 +02:00
The pages' Content-Security-Policy forbids eval, which the standard
Alpine.js build needs, so no directive ran: add forms showed open and
events never collapsed. 3p/ now holds the @alpinejs/csp 3.14.9 tarball
instead, and every directive in templates/ names a property or method
of a component registered in static/js/app.js, as that build requires.
The policy is unchanged.

A headless Chromium test in internal/server loads the webhook page and
the event log under the real headers. The Dockerfile's test stage
installs chromium; where it is missing the test skips.

Model: opus-5-5
clawbot added the needs-review label 2026-10-02 00:23:11 +02:00
Some checks are pending
check / check (push) Waiting to run
You are not authorized to merge this pull request.
This pull request can be merged automatically.
This branch is out-of-date with the base branch
View command line instructions

Checkout

From your project repository, check out a new branch and test the changes.
git fetch -u origin issue-371-alpine-csp-build:issue-371-alpine-csp-build
git checkout issue-371-alpine-csp-build
Sign in to join this conversation.
No Reviewers
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sneak/webhooker#411