40f1c0ecf6d499668c2a2967510043eb88233ac8
Alpine 3.17.2's CDN build compiles every x-data/x-show/x-text expression with new Function(), which the strict P0 CSP (script-src 'self' 'unsafe-inline') blocked. Every Alpine directive threw "Evaluating a string as JavaScript violates ... 'unsafe-eval' is not an allowed source", Alpine never initialized, and the loading overlay (x-show="loading" in base.html) stayed visible forever on /login and every Alpine-driven page. Add 'unsafe-eval' to script-src (Alpine's documented CSP requirement for its runtime); everything else in the header is unchanged. Regression test asserts the /login CSP header carries 'unsafe-eval' inside script-src. Verified live: headless chromium (playwright build 1243) shows zero CSP/eval console errors after the fix, with Alpine applying style="display:none" to the loading overlay; the pre-fix header produces the Alpine Expression Error spam and leaves the overlay visible.
fix: include Penthouse rows (PH1E-/PH1W-/PH2E-/PH2W-) in apartment mapping — parser had skipped them
denya-onecare
Denya OneCare - Centralized issue tracking for Pavilion Accra. FastAPI + SQLite + Alpine.js + Twilio.
Description
Denya OneCare - Centralized issue tracking for Pavilion Accra. FastAPI + SQLite + Alpine.js + Twilio.
759 KiB
Releases
1
Denya Logo Assets v1
Latest
Languages
Python
58.4%
HTML
41.3%
Mako
0.2%
Dockerfile
0.1%