diff --git a/AGENTS.md b/AGENTS.md index 15fd99c..b37beb2 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -77,7 +77,23 @@ sign-up UI; users are created/managed by admins only (P0 hardening batch). | GET | `/tickets/new` | Client | Create Issue form | | GET | `/tickets/{id}` | Client | Issue detail with timeline | -Frontend: Alpine.js (CDN) + Tailwind CSS (CDN). Auth state in localStorage. Role-based nav routing in `base.html`. +Frontend: Alpine.js + Tailwind CSS vendored same-origin (no CDN) — see +"Frontend assets" below. Auth state in localStorage. Role-based nav routing in `base.html`. + +### Frontend assets (vendored, LAN-safe) +- Alpine.js 3.17.2 + Tailwind Play 3.4.17 are committed under `app/static/vendor/` + and served at `/static/vendor/…` (mounted in `app/main.py`, versioned + filenames → immutable cache `public, max-age=31536000, immutable`). Templates + must never reference a CDN; update `app/templates/base.html` when upgrading: + download `alpinejs@/dist/cdn.min.js` (jsDelivr) and the tailwind play + script (`cdn.tailwindcss.com/`), save them under `app/static/vendor/` + mirroring the committed names (Alpine keeps `.min.js`, e.g. + `alpine-3.17.2.min.js`; the tailwind play file does not, e.g. + `tailwind-3.4.17.js`), then bump the ` - + + +