fix(security): enforce browser headers for SPA and API#2016
Draft
bestony wants to merge 1 commit into
Draft
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #1541
Summary
script-srchas no unsafe inline/eval sources.nosniffsetter now that the header is global.Verification
pnpm checkpasses with the repository's existing warnings only.pnpm typecheckpasses (10/10 tasks).The formal Docker/browser pass from the new QA case was not run in this local turn; it remains the maintainer-run validation for login, chat, WebSocket updates, avatars, attachments, document preview, and browser-console CSP violations. The parallel root Turbo test run also hit a Vitest worker
onTaskUpdatetimeout in an unrelated CLI portable-S3 test; the same test passes in an isolated 12/12 run.The PR is intentionally draft for the GoF competition and must remain draft.