Self-host front-end libraries, minimal sign-in header and CSP

- sign-in pages load only what they use (include_login_header.php, ajax_core.js)
- every library, font and data file served from assets/vendor with pinned
  versions (VERSIONS.json); no CDN at runtime
- Content-Security-Policy on app, sign-in and landing pages
- remove httpbin Dropzone target and source-map references
This commit is contained in:
Thanakorn
2026-09-24 14:53:41 +07:00
parent 8705be0d1b
commit f11af6e949
105 changed files with 3668 additions and 413 deletions
+1 -1
View File
@@ -44,6 +44,6 @@ $app_url = $app_url ?? '/app';
<!-- end of copyright -->
<!-- Back To Top Button -->
<button onclick="topFunction()" id="myBtn">
<button id="myBtn">
<img src="<?= $base ?>/images/up-arrow.png" alt="Back to top">
</button>
+1 -1
View File
@@ -12,7 +12,7 @@ $base = $base ?? '/landing';
<title><?= htmlspecialchars($page_title) ?></title>
<!-- Styles -->
<link href="https://fonts.googleapis.com/css2?family=Open+Sans:ital,wght@0,400;0,600;1,400&display=swap" rel="stylesheet">
<link href="<?= $base ?>/webfonts/open-sans/open-sans.css" rel="stylesheet">
<link href="<?= $base ?>/css/bootstrap.min.css" rel="stylesheet">
<link href="<?= $base ?>/css/fontawesome-all.min.css" rel="stylesheet">
<link href="<?= $base ?>/css/swiper.css" rel="stylesheet">
+12
View File
@@ -0,0 +1,12 @@
<?php
// Security headers for the public landing pages. Require this before any output.
// Everything the landing pages load is self-hosted (css/, js/, webfonts/), and they
// have no inline scripts, so scripts are limited to this origin.
if (!headers_sent()) {
header("Content-Security-Policy: default-src 'self'; script-src 'self'; style-src 'self' 'unsafe-inline'; "
. "font-src 'self' data:; img-src 'self' data:; connect-src 'self'; object-src 'none'; "
. "base-uri 'self'; form-action 'self'; frame-ancestors 'self'", true);
header('X-Content-Type-Options: nosniff', true);
header('X-Frame-Options: SAMEORIGIN', true);
header('Referrer-Policy: strict-origin-when-cross-origin', true);
}