Fixes the login/app pages stuck on the loading overlay in real browsers. Root cause: CSP script-src lacked 'unsafe-eval', which Alpine.js 3.17.2 requires (expression evaluator uses new Function). Every Alpine expression threw a CSP violation, Alpine never initialized, and the loading overlay stayed visible forever. Verified by headless Chromium before/after: eval errors gone, overlay hidden. Regression test asserts the CSP header includes unsafe-eval.
Fixes the login/app pages stuck on the loading overlay in real browsers. Root cause: CSP script-src lacked 'unsafe-eval', which Alpine.js 3.17.2 requires (expression evaluator uses new Function). Every Alpine expression threw a CSP violation, Alpine never initialized, and the loading overlay stayed visible forever. Verified by headless Chromium before/after: eval errors gone, overlay hidden. Regression test asserts the CSP header includes unsafe-eval.
Alpine 3.17.2's CDN build compiles every x-data/x-show/x-text expression
with new Function(), which the strict P0 CSP (script-src 'self'
'unsafe-inline') blocked. Every Alpine directive threw "Evaluating a
string as JavaScript violates ... 'unsafe-eval' is not an allowed
source", Alpine never initialized, and the loading overlay
(x-show="loading" in base.html) stayed visible forever on /login and
every Alpine-driven page.
Add 'unsafe-eval' to script-src (Alpine's documented CSP requirement for
its runtime); everything else in the header is unchanged. Regression test
asserts the /login CSP header carries 'unsafe-eval' inside script-src.
Verified live: headless chromium (playwright build 1243) shows zero
CSP/eval console errors after the fix, with Alpine applying
style="display:none" to the loading overlay; the pre-fix header produces
the Alpine Expression Error spam and leaves the overlay visible.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Fixes the login/app pages stuck on the loading overlay in real browsers. Root cause: CSP script-src lacked 'unsafe-eval', which Alpine.js 3.17.2 requires (expression evaluator uses new Function). Every Alpine expression threw a CSP violation, Alpine never initialized, and the loading overlay stayed visible forever. Verified by headless Chromium before/after: eval errors gone, overlay hidden. Regression test asserts the CSP header includes unsafe-eval.