Self-host front-end libraries, minimal sign-in header and CSP
- sign-in pages load only what they use (include_login_header.php, ajax_core.js) - every library, font and data file served from assets/vendor with pinned versions (VERSIONS.json); no CDN at runtime - Content-Security-Policy on app, sign-in and landing pages - remove httpbin Dropzone target and source-map references
This commit is contained in:
@@ -14,7 +14,7 @@
|
||||
$_SESSION['csrf_token'] = bin2hex(random_bytes(32));
|
||||
}
|
||||
|
||||
require '../include_header.php';
|
||||
require __DIR__ . '/include_login_header.php';
|
||||
|
||||
$user_name = htmlspecialchars($_SESSION['onboarding_name'] ?? 'there');
|
||||
?>
|
||||
|
||||
Reference in New Issue
Block a user