Changeset f7d142f in Klonkt for src/views/pages/admin-updates.ejs


Ignore:
Timestamp:
06/28/2026 03:36:22 PM (2 months ago)
Author:
Robin Genis <roboburr@…>
Branches:
main
Children:
81bb9c5
Parents:
127f87e
Message:

chore(csp): drop the last script unsafe-inline + add Permissions-Policy

Move every inline on* handler to a shared delegated data-* handler, so script-src-attr
can be 'none' instead of 'unsafe-inline'. Add a Permissions-Policy header disabling
camera/microphone/geolocation/Topics (embed features left at default).

  • views/shell.ejs — shared delegated submit/change/click/error handler (data-confirm, data-autosubmit, data-lang-switch, data-selectall, data-back, data-fallback)
  • views/{pages,partials}/*.ejs — 18 inline on* handlers -> data-* attributes (14 files)
  • server.js — scriptSrcAttr 'unsafe-inline' -> 'none'; Permissions-Policy header
File:
1 edited

Legend:

Unmodified
Added
Removed
  • src/views/pages/admin-updates.ejs

    r127f87e rf7d142f  
    4040    <% if (canCheck && canSelfUpdate) { %>
    4141    <form method="post" action="/admin/updates/run" class="set-form"
    42           onsubmit="return confirm('<%= t('aupd.run_confirm') %>');">
     42          data-confirm="<%= t('aupd.run_confirm') %>">
    4343      <button type="submit" class="btn btn-primary">
    4444        <%= upToDate ? '↻ ' + t('aupd.redeploy') : '⬆ ' + t('aupd.update_now') %>
Note: See TracChangeset for help on using the changeset viewer.