fix: allow inline styles in CSP so bar-chart widths actually apply

style-src 'self' (without unsafe-inline) silently blocks style="..."
attributes introduced via innerHTML — the CSS parses fine and the
attribute is present in the DOM, but the browser never applies it,
so every bar rendered at its track's full width regardless of its
real percentage. script-src stays locked down; this only loosens
CSS, and no untrusted external content is ever rendered into a
style attribute here.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
2026-08-06 10:57:56 -05:00
co-authored by Claude Sonnet 5
parent a077739e82
commit 812e81e220
+6 -1
View File
@@ -28,7 +28,12 @@ server {
add_header X-Frame-Options "SAMEORIGIN" always; add_header X-Frame-Options "SAMEORIGIN" always;
add_header Referrer-Policy "strict-origin-when-cross-origin" always; add_header Referrer-Policy "strict-origin-when-cross-origin" always;
add_header Permissions-Policy "geolocation=(), microphone=(), camera=()" always; add_header Permissions-Policy "geolocation=(), microphone=(), camera=()" always;
add_header Content-Security-Policy "default-src 'self'; script-src 'self'; style-src 'self'; connect-src 'self' https://newprod-api.bestcoastpairings.com; img-src 'self' data:;" always; # style-src needs 'unsafe-inline': the app sets bar-chart widths via
# inline style="width:X%" through innerHTML, which CSP's style-src
# blocks without it (script-src stays locked down — this only affects
# CSS, and nothing here renders untrusted external content into a
# style attribute).
add_header Content-Security-Policy "default-src 'self'; script-src 'self'; style-src 'self' 'unsafe-inline'; connect-src 'self' https://newprod-api.bestcoastpairings.com; img-src 'self' data:;" always;
location / { location / {
try_files $uri $uri/ =404; try_files $uri $uri/ =404;