diff --git a/AGENTS.md b/AGENTS.md index 15fd99c..6b10a86 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -77,7 +77,20 @@ sign-up UI; users are created/managed by admins only (P0 hardening batch). | GET | `/tickets/new` | Client | Create Issue form | | GET | `/tickets/{id}` | Client | Issue detail with timeline | -Frontend: Alpine.js (CDN) + Tailwind CSS (CDN). Auth state in localStorage. Role-based nav routing in `base.html`. +Frontend: Alpine.js + Tailwind CSS vendored same-origin (no CDN) — see +"Frontend assets" below. Auth state in localStorage. Role-based nav routing in `base.html`. + +### Frontend assets (vendored, LAN-safe) +- Alpine.js 3.17.2 + Tailwind Play 3.4.17 are committed under `app/static/vendor/` + and served at `/static/vendor/…` (mounted in `app/main.py`, versioned + filenames → immutable cache `public, max-age=31536000, immutable`). Templates + must never reference a CDN; update `app/templates/base.html` when upgrading: + download `alpinejs@/dist/cdn.min.js` (jsDelivr) and the tailwind play + script (`cdn.tailwindcss.com/`), save as `app/static/vendor/-.min.js`, + bump the ` - + + +