Self-host front-end libraries, minimal sign-in header and CSP
- sign-in pages load only what they use (include_login_header.php, ajax_core.js) - every library, font and data file served from assets/vendor with pinned versions (VERSIONS.json); no CDN at runtime - Content-Security-Policy on app, sign-in and landing pages - remove httpbin Dropzone target and source-map references
This commit is contained in:
@@ -76,7 +76,7 @@
|
||||
</main>
|
||||
|
||||
<?php require '../include_ending.php'; ?>
|
||||
<script src="https://cdn.jsdelivr.net/npm/jsbarcode@3.11.6/dist/JsBarcode.all.min.js"></script>
|
||||
<script src="<?php echo $server_url?>assets/vendor/jsbarcode/3.11.6/JsBarcode.all.min.js"></script>
|
||||
<script>
|
||||
var advanced = false;
|
||||
var label_bin = 'Location';
|
||||
|
||||
@@ -155,7 +155,7 @@
|
||||
</div>
|
||||
|
||||
<?php require '../include_ending.php'; ?>
|
||||
<script src="https://cdn.jsdelivr.net/npm/jsbarcode@3.11.6/dist/JsBarcode.all.min.js"></script>
|
||||
<script src="<?php echo $server_url?>assets/vendor/jsbarcode/3.11.6/JsBarcode.all.min.js"></script>
|
||||
<script>
|
||||
var lots = [];
|
||||
var products = [];
|
||||
|
||||
Reference in New Issue
Block a user