Commit graph

10 commits

Author SHA1 Message Date
Franciszek Stachura
9a27c7ae20 autocomplete: Submit form on item selection 2024-09-13 11:22:28 +02:00
Franciszek Stachura
b2c3ab73e9 web: Fix highlighting when second select is before first 2024-09-11 15:40:57 +02:00
Franciszek Stachura
30933fea6a web: Highlight whole lines of code 2024-09-11 11:48:27 +02:00
Franciszek Stachura
3b4bcd852a web: Add javascript based range links
Click line anchor and another line anchor holding shift to
make a link to a range.
2024-09-11 11:48:27 +02:00
Franciszek Stachura
0e9ff63c15 web: Save sidebar state in local storage 2024-09-11 11:13:16 +02:00
Franciszek Stachura
ec37680f04 web: Add ability to hide sidebar on desktop layout
The sidebar is hidden by default
2024-09-11 11:13:13 +02:00
Franciszek Stachura
f5c7c3c1ec templates: Remove png version of logo
Backwards compatibility for browsers without svg support (in this
version) causes the logo to unnecessarily flicker on navigation.

According to caniuse.com SVG in img elements is supported in browsers
used by 97.85% of users. https://caniuse.com/svg-img
Firefox introduced support in 2011, Chrome in 2013, Safari in 2015.
2024-09-09 16:33:12 +02:00
Franciszek Stachura
8c5e12fffd Add support for 'raw' parameter for source files
This parameter makes the server return a response with raw file
contents and headers that cause the browser to show a 'save as' dialog.

Regarding Content-Security-Policy:

https://www.w3.org/TR/CSP2/#sandbox-usage

> For example, a message board or email system might provide downloads of
> arbitrary attachments provided by other users. Attacks that rely on tricking
> a client into rendering one of these attachments could be mitigated by
> requesting that resources only be rendered in a very restrictive sandbox.
> Sending the sandbox directive with an empty value establishes such an
> environment:
>
> Content-Security-Policy: sandbox

https://www.w3.org/TR/CSP2/#directive-default-src

> Given this behavior, one good way of building a policy for a site would be to
> begin with a default-src of 'none', and to build up a policy from there that
> contains only those resource types which are actually in use for the page
> you’d like to protect. If you don’t use webfonts, for instance, there’s no
> reason to specify a source list for font-src; specifying only those resource
> types a page uses ensures that the possible attack surface for that page
> remains as small as possible.

https://cheatsheetseries.owasp.org/cheatsheets/Content_Security_Policy_Cheat_Sheet.html#defense-in-depth

> A strong CSP provides an effective second layer of protection against various
> types of vulnerabilities, especially XSS. Although CSP doesn't prevent web
> applications from containing vulnerabilities, it can make those
> vulnerabilities significantly more difficult for an attacker to exploit.

The idea is to prevent the browser from loading any external resources, if it
turned out it's possible to trick it into interpreting a file as HTML.
2024-09-05 14:12:53 +02:00
Théo Lebrun
ab9d776397 frontend: header: fix Bootlin logo paths and commit logo png+svg
Signed-off-by: Théo Lebrun <theo.lebrun@bootlin.com>
2024-08-27 15:50:08 +02:00
Franciszek Stachura
9e18f26aeb Restructure Elixir to avoid Python path hacks
* Move static files from http to a new directory
2024-08-27 11:33:18 +02:00