Self-host front-end libraries, minimal sign-in header and CSP
- sign-in pages load only what they use (include_login_header.php, ajax_core.js) - every library, font and data file served from assets/vendor with pinned versions (VERSIONS.json); no CDN at runtime - Content-Security-Policy on app, sign-in and landing pages - remove httpbin Dropzone target and source-map references
This commit is contained in:
@@ -7,7 +7,7 @@
|
||||
<body>
|
||||
|
||||
<!-- zxcvbn JS: client-side password strength scoring, no server round-trip -->
|
||||
<script src="https://cdn.jsdelivr.net/npm/zxcvbn@4.4.2/dist/zxcvbn.js"></script>
|
||||
<script src="<?php echo $server_url?>assets/vendor/zxcvbn/4.4.2/zxcvbn.js"></script>
|
||||
<?php require '../include_topbar.php'; ?>
|
||||
<?php require '../include_setting_sidebar.php'; ?>
|
||||
|
||||
@@ -350,7 +350,7 @@
|
||||
// ═══════════════════════════════════════════════════════
|
||||
function load_countries() {
|
||||
return $.getJSON(
|
||||
'https://cdn.jsdelivr.net/npm/world_countries_lists@latest/data/countries/en/countries.json'
|
||||
'<?php echo $server_url?>assets/vendor/world_countries_lists/3.3.0/countries.json'
|
||||
).then(function(data) {
|
||||
const $sel = $('#country');
|
||||
// Thailand first for convenience, then alphabetical
|
||||
|
||||
Reference in New Issue
Block a user