Self-host front-end libraries, minimal sign-in header and CSP
- sign-in pages load only what they use (include_login_header.php, ajax_core.js) - every library, font and data file served from assets/vendor with pinned versions (VERSIONS.json); no CDN at runtime - Content-Security-Policy on app, sign-in and landing pages - remove httpbin Dropzone target and source-map references
This commit is contained in:
@@ -12,7 +12,7 @@ $base = $base ?? '/landing';
|
||||
<title><?= htmlspecialchars($page_title) ?></title>
|
||||
|
||||
<!-- Styles -->
|
||||
<link href="https://fonts.googleapis.com/css2?family=Open+Sans:ital,wght@0,400;0,600;1,400&display=swap" rel="stylesheet">
|
||||
<link href="<?= $base ?>/webfonts/open-sans/open-sans.css" rel="stylesheet">
|
||||
<link href="<?= $base ?>/css/bootstrap.min.css" rel="stylesheet">
|
||||
<link href="<?= $base ?>/css/fontawesome-all.min.css" rel="stylesheet">
|
||||
<link href="<?= $base ?>/css/swiper.css" rel="stylesheet">
|
||||
|
||||
Reference in New Issue
Block a user