|
35 | 35 | {% endif %} |
36 | 36 | <meta charset="utf-8"> |
37 | 37 | <meta name="viewport" content="width=device-width, initial-scale=1.0"> |
38 | | - |
39 | 38 | {% if nonce != "" %} |
40 | | - <meta http-equiv="Content-Security-Policy" content="default-src 'self'; script-src 'nonce-{{ nonce }}' 'strict-dynamic' 'unsafe-inline' 'wasm-unsafe-eval' https://dhanur.me blob: https://*.dhanur.me https://www.googletagmanager.com https://www.google-analytics.com https://giscus.app https://utteranc.es https://static.cloudflareinsights.com https://gist.github.com https://asciinema.org https://challenges.cloudflare.com https://*.cloudflare.com https://*.sentry-cdn.com; style-src 'nonce-{{ nonce }}' data: https://*.dhanur.me https://fonts.googleapis.com https://giscus.app; style-src-attr 'unsafe-inline'; font-src 'self' data: https://*.dhanur.me https://fonts.gstatic.com; img-src 'self' data: https:; connect-src 'self' https://*.dhanur.me https://*.sentry.io https://browser.sentry-cdn.com https://www.google-analytics.com https://stats.g.doubleclick.net https://analytics.ahrefs.com; manifest-src 'self' https://*.dhanur.me; frame-src 'self' https://giscus.app https://utteranc.es https://www.youtube.com https://codepen.io https://www.openstreetmap.org https://asciinema.org https://challenges.cloudflare.com; worker-src 'self' blob: https://*.dhanur.me; object-src 'none'; base-uri 'self'; form-action 'self'; upgrade-insecure-requests; require-trusted-types-for 'script'; trusted-types static-loader dompurify giscus googletagmanager sentry 'allow-duplicates';"> |
| 39 | + <meta http-equiv="Content-Security-Policy" content="default-src 'self'; script-src 'nonce-{{ nonce }}' 'strict-dynamic' 'unsafe-inline' 'wasm-unsafe-eval' blob: https://dhanur.me https://*.dhanur.me https://www.googletagmanager.com https://www.google-analytics.com https://giscus.app https://utteranc.es https://static.cloudflareinsights.com https://gist.github.com https://asciinema.org https://challenges.cloudflare.com https://*.cloudflare.com https://*.sentry-cdn.com; style-src 'nonce-{{ nonce }}' data: https://*.dhanur.me https://fonts.googleapis.com https://giscus.app; style-src-attr 'unsafe-inline'; font-src 'self' data: https://*.dhanur.me https://fonts.gstatic.com; img-src 'self' data: https:; connect-src 'self' https://*.dhanur.me https://*.sentry.io https://browser.sentry-cdn.com https://www.google-analytics.com https://stats.g.doubleclick.net https://analytics.ahrefs.com; manifest-src 'self' https://*.dhanur.me; frame-src 'self' https://giscus.app https://utteranc.es https://www.youtube.com https://codepen.io https://www.openstreetmap.org https://asciinema.org https://challenges.cloudflare.com; worker-src 'self' blob: https://*.dhanur.me; object-src 'none'; base-uri 'self'; form-action 'self'; upgrade-insecure-requests; require-trusted-types-for 'script'; trusted-types default dompurify giscus googletagmanager sentry 'allow-duplicates';"> |
41 | 40 | {% endif %} |
42 | 41 | <meta name="referrer" content="strict-origin-when-cross-origin"> |
43 | | - <script nonce=""> |
| 42 | + <script> |
44 | 43 | (function(){ |
45 | | - if (window.trustedTypes && window.trustedTypes.createPolicy && !window.__staticLoaderPolicy) { |
| 44 | + if (window.trustedTypes && window.trustedTypes.createPolicy) { |
46 | 45 | try { |
47 | | - window.__staticLoaderPolicy = window.trustedTypes.createPolicy('static-loader', { |
| 46 | + window.__defaultPolicy = window.trustedTypes.createPolicy('default', { |
48 | 47 | createScriptURL: function(s) { return s; }, |
49 | 48 | createHTML: function(s) { return s; } |
50 | 49 | }); |
|
57 | 56 | <link rel="preconnect" href="https://auth.dhanur.me" crossorigin> |
58 | 57 | {% set theme_colorset = self::get_theme_colorset(config=config) | trim %} |
59 | 58 | {%- set cookie_domain = config.base_url | replace(from="https://", to="") | replace(from="http://", to="") -%} |
60 | | - <script nonce="" data-cookie-domain="{{ cookie_domain }}" |
| 59 | + <script data-cookie-domain="{{ cookie_domain }}" |
61 | 60 | data-default-colorset="{{ theme_colorset }}" |
62 | 61 | data-webmcp-compat="1"> |
63 | 62 | {{ load_data(path="static/js/core/boot.js") | safe }} |
|
137 | 136 | {# Google Analytics and Sentry are loaded client-side only after cookie consent. #} |
138 | 137 | {# Ahrefs Analytics: lightweight site-analytics script, no consent gate required. #} |
139 | 138 | {% if config.extra.ahrefs_analytics_key is defined and config.extra.ahrefs_analytics_key != "" %} |
140 | | - <script data-telemetry="ahrefs" nonce=""> |
| 139 | + <script data-telemetry="ahrefs"> |
141 | 140 | (function(){ |
142 | 141 | function load(){ |
143 | 142 | var s=document.createElement("script"); |
144 | 143 | var url = "https://analytics.ahrefs.com/analytics.js"; |
145 | | - var p = window.__staticLoaderPolicy; |
| 144 | + var p = window.__defaultPolicy; |
146 | 145 | s.src = p ? p.createScriptURL(url) : url; |
147 | 146 | s.async=true; |
148 | 147 | s.setAttribute("data-key","{{ config.extra.ahrefs_analytics_key | safe }}"); |
|
202 | 201 |
|
203 | 202 | <link rel="preload" href="{{ get_url(path="css/main.css") | safe }}" as="style"> |
204 | 203 | <link rel="stylesheet" href="{{ get_url(path="css/main.css") | safe }}"> |
205 | | - <link rel="preload" href="{{ get_url(path="css/lqip.css") | safe }}" as="style" onload="this.onload=null;this.rel='stylesheet'"> |
206 | | - <noscript><link rel="stylesheet" href="{{ get_url(path="css/lqip.css") | safe }}"></noscript> |
207 | | - <link rel="preload" href="{{ get_url(path="css/font-awesome.subset.css") | safe }}" as="style" onload="this.onload=null;this.rel='stylesheet'"> |
208 | | - <noscript><link rel="stylesheet" href="{{ get_url(path="css/font-awesome.subset.css") | safe }}"></noscript> |
| 204 | + <link rel="stylesheet" href="{{ get_url(path="css/lqip.css") | safe }}"> |
| 205 | + <link rel="stylesheet" href="{{ get_url(path="css/font-awesome.subset.css") | safe }}"> |
209 | 206 |
|
210 | 207 | <meta name="js-modules" |
211 | 208 | data-katex-css="{{ get_url(path="css/katex.min.css") | safe }}" |
|
0 commit comments