Self-host front-end libraries, minimal sign-in header and CSP
- sign-in pages load only what they use (include_login_header.php, ajax_core.js) - every library, font and data file served from assets/vendor with pinned versions (VERSIONS.json); no CDN at runtime - Content-Security-Policy on app, sign-in and landing pages - remove httpbin Dropzone target and source-map references
This commit is contained in:
Vendored
+1
-2
File diff suppressed because one or more lines are too long
@@ -133,4 +133,7 @@ function scrollFunctionBTT() {
|
||||
function topFunction() {
|
||||
document.body.scrollTop = 0; // for Safari
|
||||
document.documentElement.scrollTop = 0; // for Chrome, Firefox, IE and Opera
|
||||
}
|
||||
}
|
||||
|
||||
// Back-to-top button (was an inline onclick, which the landing CSP does not allow).
|
||||
if (myButton) myButton.addEventListener("click", topFunction);
|
||||
|
||||
Vendored
-1
File diff suppressed because one or more lines are too long
Reference in New Issue
Block a user