Self-host front-end libraries, minimal sign-in header and CSP
- sign-in pages load only what they use (include_login_header.php, ajax_core.js) - every library, font and data file served from assets/vendor with pinned versions (VERSIONS.json); no CDN at runtime - Content-Security-Policy on app, sign-in and landing pages - remove httpbin Dropzone target and source-map references
This commit is contained in:
@@ -13,7 +13,7 @@
|
||||
// Reject if a user is already logged in — opening an invite link in an active
|
||||
// session would bind a different account's identity into the current session.
|
||||
if (!empty($_SESSION['login_company_id'])) {
|
||||
require '../include_header.php';
|
||||
require __DIR__ . '/include_login_header.php';
|
||||
?>
|
||||
<body>
|
||||
<div class="container py-5" style="max-width:480px;">
|
||||
@@ -60,7 +60,7 @@
|
||||
}
|
||||
|
||||
if ($invite_error) {
|
||||
require '../include_header.php';
|
||||
require __DIR__ . '/include_login_header.php';
|
||||
$msg = $invite_error === 'expired'
|
||||
? ['icon' => 'ti-clock-x', 'title' => 'Invitation Expired',
|
||||
'body' => 'This invitation link has expired. Please contact your administrator to send a new invitation.']
|
||||
@@ -101,7 +101,7 @@
|
||||
$company_name = htmlspecialchars($row['company_name']);
|
||||
$invite_email = htmlspecialchars($row['email']);
|
||||
|
||||
require '../include_header.php';
|
||||
require __DIR__ . '/include_login_header.php';
|
||||
?>
|
||||
|
||||
<body>
|
||||
@@ -178,7 +178,7 @@
|
||||
|
||||
</div>
|
||||
|
||||
<script src="https://cdn.jsdelivr.net/npm/zxcvbn@4.4.2/dist/zxcvbn.js"></script>
|
||||
<script src="<?php echo $server_url?>assets/vendor/zxcvbn/4.4.2/zxcvbn.js"></script>
|
||||
<script>
|
||||
|
||||
const STRENGTH_LEVELS = [
|
||||
|
||||
Reference in New Issue
Block a user