root 40f1c0ecf6 fix(csp): add 'unsafe-eval' to script-src so Alpine.js initializes
Alpine 3.17.2's CDN build compiles every x-data/x-show/x-text expression
with new Function(), which the strict P0 CSP (script-src 'self'
'unsafe-inline') blocked. Every Alpine directive threw "Evaluating a
string as JavaScript violates ... 'unsafe-eval' is not an allowed
source", Alpine never initialized, and the loading overlay
(x-show="loading" in base.html) stayed visible forever on /login and
every Alpine-driven page.

Add 'unsafe-eval' to script-src (Alpine's documented CSP requirement for
its runtime); everything else in the header is unchanged. Regression test
asserts the /login CSP header carries 'unsafe-eval' inside script-src.

Verified live: headless chromium (playwright build 1243) shows zero
CSP/eval console errors after the fix, with Alpine applying
style="display:none" to the loading overlay; the pre-fix header produces
the Alpine Expression Error spam and leaves the overlay visible.
2026-09-09 15:45:52 +00:00
2026-07-19 19:51:30 +00:00

denya-onecare

Denya OneCare - Centralized issue tracking for Pavilion Accra. FastAPI + SQLite + Alpine.js + Twilio.

S
Description
Denya OneCare - Centralized issue tracking for Pavilion Accra. FastAPI + SQLite + Alpine.js + Twilio.
Readme
759 KiB
2026-09-09 17:46:22 +00:00
Languages
Python 58.4%
HTML 41.3%
Mako 0.2%
Dockerfile 0.1%