From 40f1c0ecf6d499668c2a2967510043eb88233ac8 Mon Sep 17 00:00:00 2001 From: root Date: Wed, 9 Sep 2026 15:45:52 +0000 Subject: [PATCH] fix(csp): add 'unsafe-eval' to script-src so Alpine.js initializes Alpine 3.17.2's CDN build compiles every x-data/x-show/x-text expression with new Function(), which the strict P0 CSP (script-src 'self' 'unsafe-inline') blocked. Every Alpine directive threw "Evaluating a string as JavaScript violates ... 'unsafe-eval' is not an allowed source", Alpine never initialized, and the loading overlay (x-show="loading" in base.html) stayed visible forever on /login and every Alpine-driven page. Add 'unsafe-eval' to script-src (Alpine's documented CSP requirement for its runtime); everything else in the header is unchanged. Regression test asserts the /login CSP header carries 'unsafe-eval' inside script-src. Verified live: headless chromium (playwright build 1243) shows zero CSP/eval console errors after the fix, with Alpine applying style="display:none" to the loading overlay; the pre-fix header produces the Alpine Expression Error spam and leaves the overlay visible. --- AGENTS.md | 15 +++++++++++---- app/main.py | 10 +++++++--- tests/test_frontend_vendoring.py | 30 ++++++++++++++++++++++++++++++ 3 files changed, 48 insertions(+), 7 deletions(-) diff --git a/AGENTS.md b/AGENTS.md index 17da210..08dac52 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -98,9 +98,15 @@ Frontend: Alpine.js + Tailwind CSS vendored same-origin (no CDN) — see `alpine-3.17.2.min.js`; the tailwind play file does not, e.g. `tailwind-3.4.17.js`), then bump the `