Files
pad/internal
xarmian 204d63151f feat(server): strict-dynamic CSP + fail-fast missing index.html (TASK-375) (#172)
Completes the remaining items on the nonce-based CSP work:

1. Add 'strict-dynamic' to script-src. In CSP-L3 browsers this supersedes
   the 'self' host-list, so a future XSS that injects <script src="//evil">
   is blocked even though 'self' is still listed (kept as fallback for
   older browsers). The SvelteKit bootstrap script already dynamically
   imports the runtime chunks, which is exactly the pattern strict-dynamic
   is designed to permit.

2. Fail fast when the embedded index.html can't be read. The previous
   silent-swallow returned blank HTML to every SPA request, which is a
   broken build that the operator should notice immediately. Panic at
   startup so the server refuses to come up with a broken UI.

Parent: PLAN-643 (OSS Security Hardening).
2026-04-21 18:45:19 -04:00
..
2026-03-26 01:52:36 +00:00
2026-03-26 01:52:36 +00:00