Skip to content

Commit 2df8bd7

Browse files
authored
Apply latest heavy updates cleanly (#41)
1 parent f2b9416 commit 2df8bd7

9 files changed

Lines changed: 20 additions & 23 deletions

File tree

‎static/css/dui.css‎

Lines changed: 1 addition & 1 deletion
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

‎static/css/main.css‎

Lines changed: 1 addition & 1 deletion
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

‎static/js/core/resource-loader.js‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -40,7 +40,7 @@ export function appendScriptOnce({
4040
}
4141

4242
const script = document.createElement("script");
43-
const policy = window.__staticLoaderPolicy;
43+
const policy = window.__defaultPolicy;
4444
script.src = policy ? policy.createScriptURL(src) : src;
4545
script.async = async;
4646
script.defer = defer;

‎static/js/data/taxonomy-playlist.js‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -51,7 +51,7 @@ function setButtonIcon(button, iconClass) {
5151
}
5252

5353
function makeSvgFromMarkup(markup) {
54-
const p = window.__staticLoaderPolicy;
54+
const p = window.__defaultPolicy;
5555
const safeString =
5656
p && typeof p.createHTML === "function" ? p.createHTML(markup) : markup;
5757
const doc = new DOMParser().parseFromString(safeString, "image/svg+xml");

‎static/js/features/search-loader.js‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -648,7 +648,7 @@ var ASK_AI_ICON_SVG =
648648
'<svg xmlns="http://www.w3.org/2000/svg" class="h-4 w-4 text-primary" fill="none" viewBox="0 0 24 24" stroke="currentColor"><path stroke-linecap="round" stroke-linejoin="round" stroke-width="2" d="M9.813 15.904L9 18l-1.813-2.096a5.5 5.5 0 117.626 0L13 18l-.813-2.096M12 8v4m0 3h.01" /></svg>';
649649

650650
function parseSvgString(svgString) {
651-
var p = window.__staticLoaderPolicy;
651+
var p = window.__defaultPolicy;
652652
var safeString =
653653
p && typeof p.createHTML === "function"
654654
? p.createHTML(svgString)
@@ -1285,7 +1285,7 @@ function loadSearchLibraries(callback) {
12851285
}
12861286

12871287
var script = document.createElement("script");
1288-
var p = window.__staticLoaderPolicy;
1288+
var p = window.__defaultPolicy;
12891289
script.src =
12901290
p && typeof p.createScriptURL === "function"
12911291
? p.createScriptURL(safeSrc)

‎static/js/shell.min.js‎

Lines changed: 1 addition & 1 deletion
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

‎static/js/system/service-worker.js‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -61,7 +61,7 @@ async function requestNotificationPermission() {
6161

6262
async function setupServiceWorker(swPath) {
6363
try {
64-
const policy = window.__staticLoaderPolicy;
64+
const policy = window.__defaultPolicy;
6565
const safePath = policy ? policy.createScriptURL(swPath) : swPath;
6666
await navigator.serviceWorker.register(safePath);
6767
const registration = await navigator.serviceWorker.ready;

‎templates/macros/head.html‎

Lines changed: 9 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -35,16 +35,15 @@
3535
{% endif %}
3636
<meta charset="utf-8">
3737
<meta name="viewport" content="width=device-width, initial-scale=1.0">
38-
3938
{% if nonce != "" %}
40-
<meta http-equiv="Content-Security-Policy" content="default-src 'self'; script-src 'nonce-{{ nonce }}' 'strict-dynamic' 'unsafe-inline' 'wasm-unsafe-eval' https://dhanur.me blob: https://*.dhanur.me https://www.googletagmanager.com https://www.google-analytics.com https://giscus.app https://utteranc.es https://static.cloudflareinsights.com https://gist.github.com https://asciinema.org https://challenges.cloudflare.com https://*.cloudflare.com https://*.sentry-cdn.com; style-src 'nonce-{{ nonce }}' data: https://*.dhanur.me https://fonts.googleapis.com https://giscus.app; style-src-attr 'unsafe-inline'; font-src 'self' data: https://*.dhanur.me https://fonts.gstatic.com; img-src 'self' data: https:; connect-src 'self' https://*.dhanur.me https://*.sentry.io https://browser.sentry-cdn.com https://www.google-analytics.com https://stats.g.doubleclick.net https://analytics.ahrefs.com; manifest-src 'self' https://*.dhanur.me; frame-src 'self' https://giscus.app https://utteranc.es https://www.youtube.com https://codepen.io https://www.openstreetmap.org https://asciinema.org https://challenges.cloudflare.com; worker-src 'self' blob: https://*.dhanur.me; object-src 'none'; base-uri 'self'; form-action 'self'; upgrade-insecure-requests; require-trusted-types-for 'script'; trusted-types static-loader dompurify giscus googletagmanager sentry 'allow-duplicates';">
39+
<meta http-equiv="Content-Security-Policy" content="default-src 'self'; script-src 'nonce-{{ nonce }}' 'strict-dynamic' 'unsafe-inline' 'wasm-unsafe-eval' blob: https://dhanur.me https://*.dhanur.me https://www.googletagmanager.com https://www.google-analytics.com https://giscus.app https://utteranc.es https://static.cloudflareinsights.com https://gist.github.com https://asciinema.org https://challenges.cloudflare.com https://*.cloudflare.com https://*.sentry-cdn.com; style-src 'nonce-{{ nonce }}' data: https://*.dhanur.me https://fonts.googleapis.com https://giscus.app; style-src-attr 'unsafe-inline'; font-src 'self' data: https://*.dhanur.me https://fonts.gstatic.com; img-src 'self' data: https:; connect-src 'self' https://*.dhanur.me https://*.sentry.io https://browser.sentry-cdn.com https://www.google-analytics.com https://stats.g.doubleclick.net https://analytics.ahrefs.com; manifest-src 'self' https://*.dhanur.me; frame-src 'self' https://giscus.app https://utteranc.es https://www.youtube.com https://codepen.io https://www.openstreetmap.org https://asciinema.org https://challenges.cloudflare.com; worker-src 'self' blob: https://*.dhanur.me; object-src 'none'; base-uri 'self'; form-action 'self'; upgrade-insecure-requests; require-trusted-types-for 'script'; trusted-types default dompurify giscus googletagmanager sentry 'allow-duplicates';">
4140
{% endif %}
4241
<meta name="referrer" content="strict-origin-when-cross-origin">
43-
<script nonce="">
42+
<script>
4443
(function(){
45-
if (window.trustedTypes && window.trustedTypes.createPolicy && !window.__staticLoaderPolicy) {
44+
if (window.trustedTypes && window.trustedTypes.createPolicy) {
4645
try {
47-
window.__staticLoaderPolicy = window.trustedTypes.createPolicy('static-loader', {
46+
window.__defaultPolicy = window.trustedTypes.createPolicy('default', {
4847
createScriptURL: function(s) { return s; },
4948
createHTML: function(s) { return s; }
5049
});
@@ -57,7 +56,7 @@
5756
<link rel="preconnect" href="https://auth.dhanur.me" crossorigin>
5857
{% set theme_colorset = self::get_theme_colorset(config=config) | trim %}
5958
{%- set cookie_domain = config.base_url | replace(from="https://", to="") | replace(from="http://", to="") -%}
60-
<script nonce="" data-cookie-domain="{{ cookie_domain }}"
59+
<script data-cookie-domain="{{ cookie_domain }}"
6160
data-default-colorset="{{ theme_colorset }}"
6261
data-webmcp-compat="1">
6362
{{ load_data(path="static/js/core/boot.js") | safe }}
@@ -137,12 +136,12 @@
137136
{# Google Analytics and Sentry are loaded client-side only after cookie consent. #}
138137
{# Ahrefs Analytics: lightweight site-analytics script, no consent gate required. #}
139138
{% if config.extra.ahrefs_analytics_key is defined and config.extra.ahrefs_analytics_key != "" %}
140-
<script data-telemetry="ahrefs" nonce="">
139+
<script data-telemetry="ahrefs">
141140
(function(){
142141
function load(){
143142
var s=document.createElement("script");
144143
var url = "https://analytics.ahrefs.com/analytics.js";
145-
var p = window.__staticLoaderPolicy;
144+
var p = window.__defaultPolicy;
146145
s.src = p ? p.createScriptURL(url) : url;
147146
s.async=true;
148147
s.setAttribute("data-key","{{ config.extra.ahrefs_analytics_key | safe }}");
@@ -202,10 +201,8 @@
202201

203202
<link rel="preload" href="{{ get_url(path="css/main.css") | safe }}" as="style">
204203
<link rel="stylesheet" href="{{ get_url(path="css/main.css") | safe }}">
205-
<link rel="preload" href="{{ get_url(path="css/lqip.css") | safe }}" as="style" onload="this.onload=null;this.rel='stylesheet'">
206-
<noscript><link rel="stylesheet" href="{{ get_url(path="css/lqip.css") | safe }}"></noscript>
207-
<link rel="preload" href="{{ get_url(path="css/font-awesome.subset.css") | safe }}" as="style" onload="this.onload=null;this.rel='stylesheet'">
208-
<noscript><link rel="stylesheet" href="{{ get_url(path="css/font-awesome.subset.css") | safe }}"></noscript>
204+
<link rel="stylesheet" href="{{ get_url(path="css/lqip.css") | safe }}">
205+
<link rel="stylesheet" href="{{ get_url(path="css/font-awesome.subset.css") | safe }}">
209206

210207
<meta name="js-modules"
211208
data-katex-css="{{ get_url(path="css/katex.min.css") | safe }}"

‎templates/macros/sidebar.html‎

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -22,8 +22,8 @@
2222
{% if config.build_search_index and not is_export %}
2323
<div class="px-2 pt-4 pb-0 flex flex-col items-center gap-2">
2424
<div class="w-full flex items-center gap-2">
25-
<label
26-
for="search-modal"
25+
<button
26+
type="button"
2727
class="sidebar-search-trigger input w-full flex items-center justify-between gap-3 text-left cursor-pointer transition"
2828
aria-label="Search"
2929
data-search-open="true"
@@ -38,7 +38,7 @@
3838
<kbd class="kbd kbd-xs">D</kbd>
3939
<kbd class="kbd kbd-xs">K</kbd>
4040
</span>
41-
</label>
41+
</button>
4242
</div>
4343
</div>
4444
{% endif %}

0 commit comments

Comments
 (0)