fix(security): audit batch B — SPA CSP/security headers + vite upgrade
Implements AUDIT_REPORT.md M-2 and M-5: - M-2: CSP (script-src 'self'; frame-ancestors 'none'; object-src 'none'; ...), nosniff, X-Frame-Options DENY, Referrer-Policy on the SPA nginx, plus gzip for the bundle. The inline theme bootstrap moved to /theme-init.js so script-src 'self' holds with no inline scripts. - M-5: vite 5 -> 8 (+ plugin-react 6) — clears the dev-only esbuild advisories; npm audit now reports 0 vulnerabilities including dev deps. Build verified. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
Generated
+535
-1113
File diff suppressed because it is too large
Load Diff
Reference in New Issue
Block a user