Self-host front-end libraries, minimal sign-in header and CSP
- sign-in pages load only what they use (include_login_header.php, ajax_core.js) - every library, font and data file served from assets/vendor with pinned versions (VERSIONS.json); no CDN at runtime - Content-Security-Policy on app, sign-in and landing pages - remove httpbin Dropzone target and source-map references
This commit is contained in:
@@ -0,0 +1,45 @@
|
||||
<?php
|
||||
// Minimal <head> for the sign-in, registration, password-reset and invitation
|
||||
// pages. Visitors here are not signed in, so they get only what these pages use:
|
||||
// jQuery, Bootstrap, bootbox, the loading overlay, the theme CSS and
|
||||
// ajax_core.js — not custom.js (every feature's API URLs), the template bundle,
|
||||
// charts, the scanner or the export libraries that include_header.php loads.
|
||||
|
||||
if (ob_get_level() === 0) {
|
||||
ob_start();
|
||||
}
|
||||
ini_set('display_errors', '0');
|
||||
ini_set('log_errors', '1');
|
||||
|
||||
require_once __DIR__ . '/../assets/utils/timezone.php';
|
||||
require_once __DIR__ . '/../assets/utils/page_headers.php';
|
||||
send_page_security_headers();
|
||||
|
||||
$vendor_url = $server_url . 'assets/vendor/';
|
||||
?>
|
||||
<!DOCTYPE html>
|
||||
<html lang="en">
|
||||
|
||||
<head>
|
||||
<meta charset="UTF-8" />
|
||||
<title>BRN WMS</title>
|
||||
<meta name="csrf-token" content="<?= htmlspecialchars($_SESSION['csrf_token'] ?? '') ?>">
|
||||
<meta name="viewport" content="width=device-width, initial-scale=1">
|
||||
<link rel="apple-touch-icon" sizes="180x180" href="<?php echo $server_url?>assets/images/favicon.png">
|
||||
<link rel="icon" type="image/png" sizes="32x32" href="<?php echo $server_url?>assets/images/favicon32.png">
|
||||
<link rel="icon" type="image/png" sizes="16x16" href="<?php echo $server_url?>assets/images/favicon32.png">
|
||||
<link rel="manifest" href="<?php echo $server_url?>assets/site.webmanifest">
|
||||
|
||||
<script src="<?php echo $vendor_url?>jquery/3.7.1/jquery.min.js"></script>
|
||||
<script src="<?php echo $vendor_url?>popper/2.11.8/popper.min.js"></script>
|
||||
<script src="<?php echo $vendor_url?>bootstrap/5.3.8/bootstrap.min.js"></script>
|
||||
<script src="<?php echo $vendor_url?>bootbox/4.4.0/bootbox.min.js"></script>
|
||||
<script src="<?php echo $vendor_url?>loadingoverlay/2.1.7/loadingoverlay.min.js"></script>
|
||||
|
||||
<link href="<?php echo $vendor_url?>bootstrap/5.3.8/bootstrap.min.css" rel="stylesheet">
|
||||
<link rel="stylesheet" href="<?php echo $server_url?>assets/css/main.css">
|
||||
<link rel="stylesheet" href="<?php echo $server_url?>assets/css/custom.css">
|
||||
|
||||
<script>var server_url = <?php echo json_encode($server_url); ?>;</script>
|
||||
<script src="<?php echo $server_url?>assets/js/ajax_core.js?v=<?php echo @filemtime(__DIR__ . '/../assets/js/ajax_core.js'); ?>"></script>
|
||||
</head>
|
||||
Reference in New Issue
Block a user