Adopt Astro 7.1 finer-grained CSP directives to de-brittle the captcha CSP #64
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-web#64
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "%!s()"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
Severity: LOW/MEDIUM (robustness) — Astro 7.1 adoption, pre-onboarding audit (2026-07-19). Repo is already on astro 7.1.1, so this is adoption, not a version bump (no migration risk).
Astro 7.1 adds finer-grained CSP directives (
script-src-elem,script-src-attr,style-src-elem,style-src-attr). Todaysrc/lib/cap-widget-csp.ts:18-45string-scrapes the minified Cap widget source to hash its shadow-root inline<style>— brittle and fail-closed on any upstream restyle (captcha loses styling). The new directives let us allow inline styles precisely without weakeningscript-src, so the fragile hash extraction can be dropped.Ask
Add the finer-grained directives under
security.csp.directivesinastro.config.mjs; remove/simplifycap-widget-csp.ts; verify withbuild+preview(CSP is off in dev). Optionally adddeferRenderto theglobcontent loaders insrc/content.config.tsfor a small build-memory win. Effort M.