docs(website): document the SPA Content-Security-Policy #26
Reference in New Issue
Block a user
No description provided.
Delete Branch "docs/csp-security-headers"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Companion to RunicGateway/website#84, which implements the CSP and related security-header changes. Per the repo rule that
docs/must reflect behavior/security-contract changes, this updates the security section.Change
website/BACKEND_DESIGN.md§6 (Auth & security): replaced the vague linewith the actual policy now shipped in
server/src/app.js:selfallowance (Google Fonts stylesheet + gstatic font files,'unsafe-inline'for React inline styles,data:/https:images for uploads + embedded body images +BRAND_*assets, same-originconnect-srcfor REST + SSE);upgrade-insecure-requestsis intentionally omitted;/api/docsSwagger UI route;X-Powered-Byhandling across the public app and the two internal-only listeners.AI disclosure
AI-assisted (Claude Code / Claude Opus 4.8). Commit carries a
Co-Authored-Bytrailer.🤖 Generated with Claude Code
https://claude.ai/code/session_01NgyHnrNa8WwG3doxvxjuCr