Skip to content

fix(console): keep public config within strict CSP - #340

Merged
Pigbibi merged 1 commit into
mainfrom
fix/console-csp-bootstrap
Aug 31, 2026
Merged

fix(console): keep public config within strict CSP#340
Pigbibi merged 1 commit into
mainfrom
fix/console-csp-bootstrap

Conversation

@Pigbibi

@Pigbibi Pigbibi commented Aug 31, 2026

Copy link
Copy Markdown
Contributor

Summary: replace the inline public configuration bootstrap with a same-origin bootstrap-config.js asset; retain a strict same-origin script policy without inline-script exceptions; add regression coverage that verifies the served page stays free of private routing metadata; document decision-first console principles derived from mature quant and operations consoles. Validation: worker and page-asset syntax checks, strategy-switch worker validation test, idempotent bootstrap injection and asset sync, and whitespace validation.

Co-Authored-By: Codex <noreply@openai.com>
@Pigbibi
Pigbibi merged commit 30586b1 into main Aug 31, 2026
6 checks passed
@Pigbibi
Pigbibi deleted the fix/console-csp-bootstrap branch August 31, 2026 14:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant