Self-host front-end libraries, minimal sign-in header and CSP

- sign-in pages load only what they use (include_login_header.php, ajax_core.js)
- every library, font and data file served from assets/vendor with pinned
  versions (VERSIONS.json); no CDN at runtime
- Content-Security-Policy on app, sign-in and landing pages
- remove httpbin Dropzone target and source-map references
This commit is contained in:
Thanakorn
2026-09-24 14:53:41 +07:00
parent 8705be0d1b
commit f11af6e949
105 changed files with 3668 additions and 413 deletions
+1 -2
View File
File diff suppressed because one or more lines are too long
+4 -1
View File
@@ -133,4 +133,7 @@ function scrollFunctionBTT() {
function topFunction() {
document.body.scrollTop = 0; // for Safari
document.documentElement.scrollTop = 0; // for Chrome, Firefox, IE and Opera
}
}
// Back-to-top button (was an inline onclick, which the landing CSP does not allow).
if (myButton) myButton.addEventListener("click", topFunction);
-1
View File
File diff suppressed because one or more lines are too long