fix: remove style-src 'unsafe-inline' from CSP (only needed for Skeleton's inline styles) - #1242
Open
wendyamoni-creator wants to merge 2 commits into
Conversation
…uccess
request() was invalidating NEWSLETTER/STATISTICS cache tags for any
POST/DELETE that returned HTTP 2xx, without inspecting the parsed
payload's success field. newsletterSubscribe / newsletterUnsubscribe
can return { success: false, message: '...' } with a 200 status, so a
rejected subscription was still busting the statistics cache — causing
an unnecessary refetch and a brief stale flicker for unrelated data.
Fix: in the mutation cache-invalidation block, derive 'succeeded' from
the response body:
- no success field present → treat as success (non-envelope endpoints)
- success: true → invalidate as before
- success: false → skip invalidation entirely
Tests added to 'Cache invalidation strategy' suite:
• success:false 200 response → cache NOT invalidated
• success:true 200 response → cache IS invalidated
• no success field present → cache IS invalidated (non-envelope)
Closes solutions-plug#1162
…ton's inline styles) Replace Skeleton component's inline style attribute with CSS classes and CSS utility classes in Statistics.css. Remove 'unsafe-inline' from style-src in both next.config.js and proxy.ts middleware CSP definitions. This eliminates the CSS-based data exfiltration risk that 'unsafe-inline' permits, since only one component (Skeleton.tsx) previously required it. Co-authored-by: automated
|
@wendyamoni-creator Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits. You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Test plan
✨ openapi-typescript 7.13.0
🚀 ../services/api/openapi.yaml → src/lib/api/schema.d.ts [86.4ms] passes with zero warnings
Closes #1163