Self-host front-end libraries, minimal sign-in header and CSP
- sign-in pages load only what they use (include_login_header.php, ajax_core.js) - every library, font and data file served from assets/vendor with pinned versions (VERSIONS.json); no CDN at runtime - Content-Security-Policy on app, sign-in and landing pages - remove httpbin Dropzone target and source-map references
This commit is contained in:
@@ -44,6 +44,6 @@ $app_url = $app_url ?? '/app';
|
||||
<!-- end of copyright -->
|
||||
|
||||
<!-- Back To Top Button -->
|
||||
<button onclick="topFunction()" id="myBtn">
|
||||
<button id="myBtn">
|
||||
<img src="<?= $base ?>/images/up-arrow.png" alt="Back to top">
|
||||
</button>
|
||||
|
||||
Reference in New Issue
Block a user