aboutsummaryrefslogtreecommitdiff
path: root/src/routes/+layout.svelte
diff options
context:
space:
mode:
authorFuwn <[email protected]>2026-06-01 13:09:56 +0000
committerFuwn <[email protected]>2026-06-01 13:09:56 +0000
commit571e8b7961660aa193f755f8e4bb71e0984486da (patch)
treea4819275b8cd8f8fb61bfac6310400eb3f081916 /src/routes/+layout.svelte
parentfix(security): mark auth cookies Secure outside localhost (diff)
downloaddue.moe-571e8b7961660aa193f755f8e4bb71e0984486da.tar.xz
due.moe-571e8b7961660aa193f755f8e4bb71e0984486da.zip
feat(security): add Content-Security-Policy
No CSP existed, leaving the app without defense-in-depth against XSS. Add a SvelteKit nonce-based policy (mode: auto): script-src limited to self + per-request nonce + the analytics/Vercel script hosts, object-src none, base-uri and frame-ancestors self. img/style/font/connect stay permissive (https:) so the image proxy, CDNs, fonts and the many cross-origin API calls keep working; the two inline app.html scripts carry %sveltekit.nonce%. Verified in-browser across routes (no violations, HMR and hydration intact) and via a production build.
Diffstat (limited to 'src/routes/+layout.svelte')
0 files changed, 0 insertions, 0 deletions