Self-host front-end libraries, minimal sign-in header and CSP
- sign-in pages load only what they use (include_login_header.php, ajax_core.js) - every library, font and data file served from assets/vendor with pinned versions (VERSIONS.json); no CDN at runtime - Content-Security-Policy on app, sign-in and landing pages - remove httpbin Dropzone target and source-map references
This commit is contained in:
@@ -1,5 +1,6 @@
|
||||
<?php
|
||||
require __DIR__ . '/../app/config.php';
|
||||
require __DIR__ . '/includes/security_headers.php';
|
||||
$base = rtrim($base_url, '/') . '/landing';
|
||||
$app_url = rtrim($base_url, '/') . '/app';
|
||||
$page_title = 'Terms of Service — BRN WMS';
|
||||
|
||||
Reference in New Issue
Block a user