Derive the CSP script hashes from app.html

This commit is contained in:
Coracle-Bot 2026-09-15 07:14:24 +00:00
parent 7dffabd9d9
commit 241d2b3737

View file

@ -1,5 +1,16 @@
import adapter from "@sveltejs/adapter-static"
import {vitePreprocess} from "@sveltejs/vite-plugin-svelte"
import {createHash} from "node:crypto"
import {readFileSync} from "node:fs"
// Sveltekit hashes the scripts it injects itself, but not the ones app.html carries, so those
// have to be named in script-src by hand. Hashing them here rather than pasting a literal is
// what stops an edit to app.html silently violating the policy.
const appHtmlScripts = [
...readFileSync(new URL("./src/app.html", import.meta.url), "utf8").matchAll(
/<script(?![^>]*\bsrc=)[^>]*>([\s\S]*?)<\/script>/g,
),
].map(([, script]) => "sha256-" + createHash("sha256").update(script).digest("base64"))
/** @type {import('@sveltejs/kit').Config} */
export default {
@ -19,7 +30,7 @@ export default {
},
csp: {
directives: {
"script-src": ["self", "wasm-unsafe-eval", "https://plausible.coracle.social", "sha256-NpqGpeZTuPniNAucgyfqzWy9iIHwOswFzPzpigwvp/c="],
"script-src": ["self", "wasm-unsafe-eval", "https://plausible.coracle.social", ...appHtmlScripts],
"worker-src": ["self", "blob:"],
"style-src": ["self", "unsafe-inline"],
"frame-src": ["none"],