Commit Graph
48 Commits
Author SHA1 Message Date
David Barragán Merino 1e8acbb2db 🐳 Cover the inline scripts of the served pages with CSP hashes
The frontend build now emits the sha256 hashes of the inline scripts of every page it writes into resources/public, the image moves them out of the document root, and the entrypoint splices them into the default script-src. This removes one of the two reasons why enforcing mode was not usable.

The hashes are computed on the rendered output rather than on the mustache templates, since the digest covers the exact bytes served between the script tags. All four served pages contribute, not just index.html: challenge.html handles the redirect, render.html is loaded by the exporter in a headless browser, and rasterizer.html is initialised by the frontend itself, so leaving any of them out would have broken those paths under enforcing mode. The storybook previews are excluded because that container does not serve them.

A bundle predating this change yields no hashes and the policy stays as it was, so older bundles keep building.

The three external locations were also passing through the security headers of their upstreams. raw.githubusercontent.com returns its own Content-Security-Policy and both it and fonts.googleapis.com return Strict-Transport-Security. Browsers enforce the intersection of every policy they receive, so the upstream one takes precedence on those responses, and the HSTS one lands on our own host, meaning a deployment that deliberately disables HSTS would get it set anyway by a third party. Hide all three at the proxy.

Signed-off-by: David Barragán Merino <david.barragan@kaleidos.net>
2026-09-18 18:55:19 +02:00
Juan de la Cruzandalonso.torres cddbd8e897 ✨ Add font family preview in typography selector (#10411)
Co-authored-by: alonso.torres <alonso.torres@kaleidos.net>
2026-07-20 10:06:02 +02:00
Andrey Antukh 7135782e7d Merge remote-tracking branch 'origin/main-staging' into staging 2026-04-24 08:19:47 +02:00
Andrey Antukh 09637f9794 ✨ Allow render entrypoint load alternative config
The render entrypoint is used by exporter
2026-04-22 13:11:10 +02:00
Andrey Antukh 98e8160875 ♻️ Remove worker URI from global templates and compute from public URI
- Remove penpotWorkerURI from index.mustache and rasterizer.mustache templates
- Remove worker_main entry from the build manifest
- Construct worker URI in config.cljs by joining public-uri with worker path
- Fix global variable casing for plugins-list-uri and templates-uri
- Fix alignment in worker.cljs let bindings
2026-04-22 09:52:44 +02:00
Alexis Morin 05521a84d4 🌐 Add Canadian French 2026-02-26 10:26:10 +01:00
Andrey Antukh 5016b2a7bf Merge remote-tracking branch 'origin/staging-render' into develop 2026-01-23 11:18:33 +01:00
Andrey Antukh b8c70be9a2 ✨ Make frontend build and watch process more resilent to errors 2026-01-21 13:44:35 +01:00
Andrey Antukh 1ffa956251 ✨ Include timestamp on version tag 2026-01-20 12:26:39 +01:00
Andrey Antukh 52b8560b70 Merge branch 'staging-render' into develop 2025-12-30 15:30:56 +01:00
Andrey Antukh 824ca1bbca 🔧 Make devenv init yarn indpendent 2025-12-30 15:28:19 +01:00
Andrey Antukh 9eebc467ef ✨ Preload default translations 2025-12-23 13:10:58 +01:00
Andrey Antukh f478399ae0 Merge remote-tracking branch 'origin/staging-render' into develop 2025-12-22 17:28:18 +01:00
Andrey Antukh bb5568e15a 🎉 Enable hindi translations on the application 2025-12-22 16:57:00 +01:00
Andrey Antukh eb1eeb4750 Merge remote-tracking branch 'origin/staging-render' into niwinz-develop-merge 2025-12-10 13:53:15 +01:00
Andrey Antukh a4646373cf ♻️ Refactor wasm loading strategy on worker 2025-12-09 19:41:19 +01:00
Andrey Antukh d04fdb5fbd ✨ Make the dist bundle use consistent and cache-aware uris (#7911) 2025-12-09 08:05:28 +01:00
Andrey Antukh 416980f063 🐛 Fix issue on render template on dist bundle (#7899) 2025-12-03 20:48:02 +01:00
Andrey Antukh d1379c55f6 ✨ Make i18n translation files load on demand 2025-12-03 16:44:37 +01:00
Andrey Antukh 2f1b99fa53 ♻️ Use ESM target for build frontend 2025-12-01 09:30:21 +01:00
Andrey Antukh b03cfffb9e ⏪ Restore the dashboard thumbnail rendering using wasm (#7796)
* Revert "🐛 Rollback esm worker (#7792)"

This reverts commit 0120a5335b.

* 🐛 Fix incorrect manifest reading on building worker
2025-11-21 11:42:40 +01:00
Andrey Antukh dede2a8f8e 💄 Fix JS files formatting issues 2025-08-29 11:25:58 +02:00
Juanfran 0a7d6d98e1 ✨ Integrate plugin runtime as npm library (#6852) 2025-07-07 09:46:07 +02:00
Andrey Antukh f20032199a 🎉 Add Serbian lang 2025-06-16 13:42:22 +02:00
Andrey Antukh de2695682d ✨ Allow encode mailto and self target link in markdown
On translation files
2025-06-06 14:03:52 +02:00
Alejandro Alonso aae81b8a04 🎉 Add wasm playground environment 2025-05-05 09:45:59 +02:00
Andrey Antukh e1c9691567 ✨ Improve scss compilation error handling
Don't stop watch scss process on compilation error
2024-11-25 12:44:10 +01:00
Alejandro Alonso c89abf56ac 🐛 Fix translate files generations with markdown and links 2024-11-25 07:20:32 +01:00
Andrey Antukh 607deb31dc ♻️ Refactor bundle mechanism
Mainly leave shadow-cljs for build cljs stuff and use esbuild
for bundle all js dependencies, completly avoiding all possible
incompatibility issues between js libraries and google closure
compiler.
2024-11-01 10:04:03 +01:00
Andrey Antukh 28878caca9 🐛 Fix cache issues with plugin runtime import uri 2024-10-09 13:09:01 +02:00
Belén Albeza eb720b053a Merge pull request #5057 from penpot/eva-fix-css-compilation
🔧 Rearrange css files for compilation
2024-09-06 14:45:52 +02:00
Andrey Antukh d88f28f5c2 ✨ Add support for optional human challenge 2024-09-05 15:35:39 +02:00
Eva Marco 34cc211912 🔧 Rearrange css files for compilation 2024-09-05 09:39:43 +02:00
Belén Albeza 8aaa04b1f8 ✨ Add English translations to storybook template 2024-09-02 14:51:41 +02:00
Belén Albeza 457da6f23e ✨ Append timestamp to CSS import in storybook 2024-08-05 17:39:57 +02:00
Belén Albeza 8bcc2a4932 ✨ Compile storybook target in release and a separate DS stylesheet 2024-08-01 15:29:02 +02:00
Belén Albeza fb6ebcd074 🐛 Fix debug css being included in prod builds 2024-07-08 15:57:35 +02:00
Belén Albeza 44a2a63fb8 ✨ Ensure DS scss modules are compiled before the app css modules 2024-07-08 15:57:35 +02:00
Belén Albeza eae19e8252 📎 Remove leftover code 2024-07-08 15:57:35 +02:00
Belén Albeza 4ac18e2ef0 🐛 Fix cursors svg duplicating icons sprites 2024-07-04 09:20:18 +02:00
Belén Albeza f05e1354ff 🔧 Add assets svg sprite generation 2024-07-04 09:20:18 +02:00
Belén Albeza c6a7ad0520 🐛 Fix template generation for storybook 2024-07-03 15:25:30 +02:00
Belén Albeza ecbedf847f 💄 Reformat affected JS files 2024-07-01 10:29:57 +02:00
Belén Albeza e74ab949ba 🐛 Include debug css in local dev only 2024-05-17 16:48:03 +02:00
Belén Albeza d30eca016e 💄 Reformat JS file 2024-05-17 16:47:15 +02:00
alonso.torres d7324b2e98 ✨ Support development and production plugin runtime 2024-04-19 01:29:13 +02:00
Belén Albeza 6a0768b490 🐛 Fix helper to compile polyfills 2024-03-26 15:09:58 +01:00
Andrey Antukh ec9d67ae1e 🎉 Add node scripts based compile & watch alternative to gulp 2024-03-25 08:47:55 +01:00