Self-host front-end libraries, minimal sign-in header and CSP

- sign-in pages load only what they use (include_login_header.php, ajax_core.js)
- every library, font and data file served from assets/vendor with pinned
  versions (VERSIONS.json); no CDN at runtime
- Content-Security-Policy on app, sign-in and landing pages
- remove httpbin Dropzone target and source-map references
This commit is contained in:
Thanakorn
2026-09-24 14:53:41 +07:00
parent 8705be0d1b
commit f11af6e949
105 changed files with 3668 additions and 413 deletions
+3 -3
View File
@@ -13,7 +13,7 @@
// Reject if a user is already logged in — opening an invite link in an active
// session would bind invite state into the current session.
if (!empty($_SESSION['login_company_id'])) {
require '../include_header.php';
require __DIR__ . '/include_login_header.php';
?>
<body>
<div class="container py-5" style="max-width:480px;">
@@ -59,7 +59,7 @@
}
if ($invite_error) {
require '../include_header.php';
require __DIR__ . '/include_login_header.php';
$msg = $invite_error === 'expired'
? ['icon' => 'ti-clock-x', 'title' => 'Invitation Expired',
'body' => 'This invitation link has expired. Please contact the company administrator to resend your invitation.']
@@ -98,7 +98,7 @@
$invite_email = htmlspecialchars($row['email']);
$invite_role = htmlspecialchars(ucfirst($row['role']));
require '../include_header.php';
require __DIR__ . '/include_login_header.php';
?>
<body>