Skip to content
This repository was archived by the owner on Aug 8, 2026. It is now read-only.
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 0 additions & 2 deletions handlers/csp.go
Original file line number Diff line number Diff line change
Expand Up @@ -39,8 +39,6 @@ func enforceContentSecurityPolicy(next http.Handler) http.Handler {
values: []string{
"'self'",
"'nonce-" + nonce + "'",
// for htmx 2.0.4 inline style
"'sha256-bsV5JivYxvGywDAZ22EZJKBFip65Ng9xoJVLbBg7bdo='",
},
},
{
Expand Down
38 changes: 14 additions & 24 deletions handlers/static/js/htmx-settings.js
Original file line number Diff line number Diff line change
@@ -1,26 +1,16 @@
/* global htmx */

// Tighten security.
htmx.config.selfRequestsOnly = true;
htmx.config.allowScriptTags = false;
htmx.config.allowEval = false;

// Don't let response-targets override isError.
htmx.config.responseTargetUnsetsError = false;

document.addEventListener("DOMContentLoaded", () => {
document.body.addEventListener("htmx:beforeSwap", function (evt) {
if (evt.detail.xhr.status === 204) {
evt.detail.shouldSwap = true;
}
if (evt.detail.xhr.status === 422) {
// allow 422 responses to swap as we are using this as a signal that
// a form was submitted with bad data and want to rerender with the
// errors
//
// set isError to false to avoid error logging in console
evt.detail.shouldSwap = true;
evt.detail.isError = false;
}
});
});
htmx.config.selfRequestsOnly = true; // Prevent hx-* from calling other origins.
htmx.config.allowScriptTags = false; // Server-rendered swaps don't need scripts.
htmx.config.allowEval = false; // Keep htmx from evaluating dynamic JS strings.
htmx.config.historyCacheSize = 0; // Avoid localStorage page-cache staleness/leaks.
htmx.config.historyRestoreAsHxRequest = false; // Restore history with full pages.
htmx.config.includeIndicatorStyles = false; // Indicator CSS lives in screenjournal.css.
htmx.config.timeout = 5000; // Fail stalled requests instead of disabling UI forever.
htmx.config.responseTargetUnsetsError = false; // Keep response-targets error state.
htmx.config.responseHandling = [
{ code: "204", swap: true }, // Empty 204 deletes clear the target element.
{ code: "422", swap: true, error: false }, // Validation errors swap normally.
{ code: "[23]..", swap: true }, // Successful non-empty responses swap normally.
{ code: "[45]..", swap: false, error: true }, // Error targets handle failures.
];
Loading