Self-host front-end libraries, minimal sign-in header and CSP
- sign-in pages load only what they use (include_login_header.php, ajax_core.js) - every library, font and data file served from assets/vendor with pinned versions (VERSIONS.json); no CDN at runtime - Content-Security-Policy on app, sign-in and landing pages - remove httpbin Dropzone target and source-map references
This commit is contained in:
Vendored
+1
-2
File diff suppressed because one or more lines are too long
@@ -44,6 +44,6 @@ $app_url = $app_url ?? '/app';
|
||||
<!-- end of copyright -->
|
||||
|
||||
<!-- Back To Top Button -->
|
||||
<button onclick="topFunction()" id="myBtn">
|
||||
<button id="myBtn">
|
||||
<img src="<?= $base ?>/images/up-arrow.png" alt="Back to top">
|
||||
</button>
|
||||
|
||||
@@ -12,7 +12,7 @@ $base = $base ?? '/landing';
|
||||
<title><?= htmlspecialchars($page_title) ?></title>
|
||||
|
||||
<!-- Styles -->
|
||||
<link href="https://fonts.googleapis.com/css2?family=Open+Sans:ital,wght@0,400;0,600;1,400&display=swap" rel="stylesheet">
|
||||
<link href="<?= $base ?>/webfonts/open-sans/open-sans.css" rel="stylesheet">
|
||||
<link href="<?= $base ?>/css/bootstrap.min.css" rel="stylesheet">
|
||||
<link href="<?= $base ?>/css/fontawesome-all.min.css" rel="stylesheet">
|
||||
<link href="<?= $base ?>/css/swiper.css" rel="stylesheet">
|
||||
|
||||
@@ -0,0 +1,12 @@
|
||||
<?php
|
||||
// Security headers for the public landing pages. Require this before any output.
|
||||
// Everything the landing pages load is self-hosted (css/, js/, webfonts/), and they
|
||||
// have no inline scripts, so scripts are limited to this origin.
|
||||
if (!headers_sent()) {
|
||||
header("Content-Security-Policy: default-src 'self'; script-src 'self'; style-src 'self' 'unsafe-inline'; "
|
||||
. "font-src 'self' data:; img-src 'self' data:; connect-src 'self'; object-src 'none'; "
|
||||
. "base-uri 'self'; form-action 'self'; frame-ancestors 'self'", true);
|
||||
header('X-Content-Type-Options: nosniff', true);
|
||||
header('X-Frame-Options: SAMEORIGIN', true);
|
||||
header('Referrer-Policy: strict-origin-when-cross-origin', true);
|
||||
}
|
||||
@@ -1,5 +1,6 @@
|
||||
<?php
|
||||
require __DIR__ . '/../app/config.php';
|
||||
require __DIR__ . '/includes/security_headers.php';
|
||||
$base = rtrim($base_url, '/') . '/landing';
|
||||
$app_url = rtrim($base_url, '/') . '/app';
|
||||
$active_nav = 'home';
|
||||
|
||||
Vendored
+1
-2
File diff suppressed because one or more lines are too long
@@ -133,4 +133,7 @@ function scrollFunctionBTT() {
|
||||
function topFunction() {
|
||||
document.body.scrollTop = 0; // for Safari
|
||||
document.documentElement.scrollTop = 0; // for Chrome, Firefox, IE and Opera
|
||||
}
|
||||
}
|
||||
|
||||
// Back-to-top button (was an inline onclick, which the landing CSP does not allow).
|
||||
if (myButton) myButton.addEventListener("click", topFunction);
|
||||
|
||||
Vendored
-1
File diff suppressed because one or more lines are too long
@@ -1,5 +1,6 @@
|
||||
<?php
|
||||
require __DIR__ . '/../app/config.php';
|
||||
require __DIR__ . '/includes/security_headers.php';
|
||||
$base = rtrim($base_url, '/') . '/landing';
|
||||
$app_url = rtrim($base_url, '/') . '/app';
|
||||
$page_title = 'Privacy Policy — BRN WMS';
|
||||
|
||||
@@ -1,5 +1,6 @@
|
||||
<?php
|
||||
require __DIR__ . '/../app/config.php';
|
||||
require __DIR__ . '/includes/security_headers.php';
|
||||
$base = rtrim($base_url, '/') . '/landing';
|
||||
$app_url = rtrim($base_url, '/') . '/app';
|
||||
$page_title = 'Terms of Service — BRN WMS';
|
||||
|
||||
BIN
Binary file not shown.
BIN
Binary file not shown.
Binary file not shown.
Binary file not shown.
@@ -0,0 +1,60 @@
|
||||
/* latin-ext */
|
||||
@font-face {
|
||||
font-family: 'Open Sans';
|
||||
font-style: italic;
|
||||
font-weight: 400;
|
||||
font-stretch: 100%;
|
||||
font-display: swap;
|
||||
src: url(memQYaGs126MiZpBA-UFUIcVXSCEkx2cmqvXlWq8tWZ0Pw86hd0Rk8ZkWV4ewJER.woff2) format('woff2');
|
||||
unicode-range: U+0100-02BA, U+02BD-02C5, U+02C7-02CC, U+02CE-02D7, U+02DD-02FF, U+0304, U+0308, U+0329, U+1D00-1DBF, U+1E00-1E9F, U+1EF2-1EFF, U+2020, U+20A0-20AB, U+20AD-20C0, U+2113, U+2C60-2C7F, U+A720-A7FF;
|
||||
}
|
||||
/* latin */
|
||||
@font-face {
|
||||
font-family: 'Open Sans';
|
||||
font-style: italic;
|
||||
font-weight: 400;
|
||||
font-stretch: 100%;
|
||||
font-display: swap;
|
||||
src: url(memQYaGs126MiZpBA-UFUIcVXSCEkx2cmqvXlWq8tWZ0Pw86hd0Rk8ZkWVAewA.woff2) format('woff2');
|
||||
unicode-range: U+0000-00FF, U+0131, U+0152-0153, U+02BB-02BC, U+02C6, U+02DA, U+02DC, U+0304, U+0308, U+0329, U+2000-206F, U+20AC, U+2122, U+2191, U+2193, U+2212, U+2215, U+FEFF, U+FFFD;
|
||||
}
|
||||
/* latin-ext */
|
||||
@font-face {
|
||||
font-family: 'Open Sans';
|
||||
font-style: normal;
|
||||
font-weight: 400;
|
||||
font-stretch: 100%;
|
||||
font-display: swap;
|
||||
src: url(memvYaGs126MiZpBA-UvWbX2vVnXBbObj2OVTSGmu1aB.woff2) format('woff2');
|
||||
unicode-range: U+0100-02BA, U+02BD-02C5, U+02C7-02CC, U+02CE-02D7, U+02DD-02FF, U+0304, U+0308, U+0329, U+1D00-1DBF, U+1E00-1E9F, U+1EF2-1EFF, U+2020, U+20A0-20AB, U+20AD-20C0, U+2113, U+2C60-2C7F, U+A720-A7FF;
|
||||
}
|
||||
/* latin */
|
||||
@font-face {
|
||||
font-family: 'Open Sans';
|
||||
font-style: normal;
|
||||
font-weight: 400;
|
||||
font-stretch: 100%;
|
||||
font-display: swap;
|
||||
src: url(memvYaGs126MiZpBA-UvWbX2vVnXBbObj2OVTS-muw.woff2) format('woff2');
|
||||
unicode-range: U+0000-00FF, U+0131, U+0152-0153, U+02BB-02BC, U+02C6, U+02DA, U+02DC, U+0304, U+0308, U+0329, U+2000-206F, U+20AC, U+2122, U+2191, U+2193, U+2212, U+2215, U+FEFF, U+FFFD;
|
||||
}
|
||||
/* latin-ext */
|
||||
@font-face {
|
||||
font-family: 'Open Sans';
|
||||
font-style: normal;
|
||||
font-weight: 600;
|
||||
font-stretch: 100%;
|
||||
font-display: swap;
|
||||
src: url(memvYaGs126MiZpBA-UvWbX2vVnXBbObj2OVTSGmu1aB.woff2) format('woff2');
|
||||
unicode-range: U+0100-02BA, U+02BD-02C5, U+02C7-02CC, U+02CE-02D7, U+02DD-02FF, U+0304, U+0308, U+0329, U+1D00-1DBF, U+1E00-1E9F, U+1EF2-1EFF, U+2020, U+20A0-20AB, U+20AD-20C0, U+2113, U+2C60-2C7F, U+A720-A7FF;
|
||||
}
|
||||
/* latin */
|
||||
@font-face {
|
||||
font-family: 'Open Sans';
|
||||
font-style: normal;
|
||||
font-weight: 600;
|
||||
font-stretch: 100%;
|
||||
font-display: swap;
|
||||
src: url(memvYaGs126MiZpBA-UvWbX2vVnXBbObj2OVTS-muw.woff2) format('woff2');
|
||||
unicode-range: U+0000-00FF, U+0131, U+0152-0153, U+02BB-02BC, U+02C6, U+02DA, U+02DC, U+0304, U+0308, U+0329, U+2000-206F, U+20AC, U+2122, U+2191, U+2193, U+2212, U+2215, U+FEFF, U+FFFD;
|
||||
}
|
||||
Reference in New Issue
Block a user