Inspector page: static SvelteKit site with /inspect (plan step 5)
A prerendered static site (adapter-static) with a landing page and
/inspect, which runs spec §63 steps 1 to 8 on a .dkc chosen with the file
picker, dropped anywhere on the page, or taken from the official fixtures
bundled at build time. It shows every step, the decoded header, the unlock
date in UTC and local time, and each extension's id, version, criticality,
length and hex, with a text view and an informative CBOR diagnostic view,
all escaped and labelled as unauthenticated before step 15. Copiar JSON
copies the exact "datekeys inspect -json" view.
No network: a hash-mode Content-Security-Policy with connect-src 'self'
is the first element of every page, and scripts/check-build.mjs verifies
it, the fixtures and the absence of external URLs after every build.
Large files are read only up to what steps 1 to 8 need.
Reviewed for design and accessibility (WCAG AA contrast, keyboard,
focus, live status, 360 px), security and correctness; 262 tests pass,
svelte-check has no warnings.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2 weeks ago
|
|
|
// SvelteKit configuration of the inspector page (plan §8, phase 1): a static
|
|
|
|
|
// site, every page prerendered, no server code, and a Content-Security-Policy
|
|
|
|
|
// that keeps the page on its own origin.
|
|
|
|
|
import adapter from '@sveltejs/adapter-static';
|
|
|
|
|
|
|
|
|
|
// The only inline style of the site: the style attribute of SvelteKit's route
|
|
|
|
|
// announcer (<div id="svelte-announcer">, written by `svelte-kit sync` into
|
|
|
|
|
// .svelte-kit/generated/root.svelte), allowed by its SHA-256 and nothing else.
|
|
|
|
|
// It is the hash of the attribute value for @sveltejs/kit 2.70.3; the build
|
|
|
|
|
// check (scripts/check-build.mjs) fails if the bundle holds any other inline
|
|
|
|
|
// style, and src/app.css hides the announcer anyway in browsers without
|
|
|
|
|
// style-src-attr.
|
|
|
|
|
const ANNOUNCER_STYLE_HASH = 'sha256-S8qMpvofolR8Mpjy4kQvEm7m1q8clzU4dfDH0AmvZjo=';
|
|
|
|
|
|
|
|
|
|
/** @type {import('@sveltejs/kit').Config} */
|
|
|
|
|
const config = {
|
|
|
|
|
compilerOptions: {
|
|
|
|
|
runes: true,
|
|
|
|
|
},
|
|
|
|
|
kit: {
|
|
|
|
|
// strict: the build fails if any route is not prerendered.
|
|
|
|
|
adapter: adapter({ strict: true }),
|
|
|
|
|
// Prerendered pages get the policy as <meta http-equiv>, the first element
|
|
|
|
|
// of <head>. In 'hash' mode SvelteKit adds the SHA-256 of each inline
|
|
|
|
|
// script it writes (the hydration bootstrap) to script-src; the styles are
|
|
|
|
|
// external files (inlineStyleThreshold stays 0), so style-src needs no
|
|
|
|
|
// hash, and style-src-attr allows the announcer's style attribute alone.
|
|
|
|
|
// Nonces cannot work in prerendered HTML. The fixtures are fetched
|
/inspect asks drand for the release when the person asks
The author found copying the release of the round tedious. A button,
"Pedir la firma a drand", fetches it from the three public relays of
the CLI of the reference, as its client does: raced, 6 s, at most
8 KiB an answer, no redirects, and the randomness checked against the
signature; step 10 still verifies the signature with the pinned key,
so a relay cannot make the page accept a false one. It is the only
connection the page makes to another site, and only on that click: the
CSP allows those three origins in connect-src, check-build.mjs
requires exactly them, and the footer says so. Pasting by hand still
works. Checked in Chromium: api2.drand.sh gave the release of round
32668196 and the capsule opened.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
7 days ago
|
|
|
// from the same origin; the only other origins the page may reach are
|
|
|
|
|
// the public relays of drand, when the person asks for the release of a
|
|
|
|
|
// round (src/lib/inspector/drand.ts, as the CLI of the reference).
|
Inspector page: static SvelteKit site with /inspect (plan step 5)
A prerendered static site (adapter-static) with a landing page and
/inspect, which runs spec §63 steps 1 to 8 on a .dkc chosen with the file
picker, dropped anywhere on the page, or taken from the official fixtures
bundled at build time. It shows every step, the decoded header, the unlock
date in UTC and local time, and each extension's id, version, criticality,
length and hex, with a text view and an informative CBOR diagnostic view,
all escaped and labelled as unauthenticated before step 15. Copiar JSON
copies the exact "datekeys inspect -json" view.
No network: a hash-mode Content-Security-Policy with connect-src 'self'
is the first element of every page, and scripts/check-build.mjs verifies
it, the fixtures and the absence of external URLs after every build.
Large files are read only up to what steps 1 to 8 need.
Reviewed for design and accessibility (WCAG AA contrast, keyboard,
focus, live status, 360 px), security and correctness; 262 tests pass,
svelte-check has no warnings.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2 weeks ago
|
|
|
csp: {
|
|
|
|
|
mode: 'hash',
|
|
|
|
|
directives: {
|
|
|
|
|
'default-src': ['self'],
|
|
|
|
|
'script-src': ['self'],
|
|
|
|
|
'style-src': ['self'],
|
|
|
|
|
'style-src-attr': ['unsafe-hashes', ANNOUNCER_STYLE_HASH],
|
|
|
|
|
'img-src': ['self'],
|
|
|
|
|
'font-src': ['self'],
|
/inspect asks drand for the release when the person asks
The author found copying the release of the round tedious. A button,
"Pedir la firma a drand", fetches it from the three public relays of
the CLI of the reference, as its client does: raced, 6 s, at most
8 KiB an answer, no redirects, and the randomness checked against the
signature; step 10 still verifies the signature with the pinned key,
so a relay cannot make the page accept a false one. It is the only
connection the page makes to another site, and only on that click: the
CSP allows those three origins in connect-src, check-build.mjs
requires exactly them, and the footer says so. Pasting by hand still
works. Checked in Chromium: api2.drand.sh gave the release of round
32668196 and the capsule opened.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
7 days ago
|
|
|
'connect-src': ['self', 'https://api.drand.sh', 'https://api2.drand.sh', 'https://api3.drand.sh'],
|
Inspector page: static SvelteKit site with /inspect (plan step 5)
A prerendered static site (adapter-static) with a landing page and
/inspect, which runs spec §63 steps 1 to 8 on a .dkc chosen with the file
picker, dropped anywhere on the page, or taken from the official fixtures
bundled at build time. It shows every step, the decoded header, the unlock
date in UTC and local time, and each extension's id, version, criticality,
length and hex, with a text view and an informative CBOR diagnostic view,
all escaped and labelled as unauthenticated before step 15. Copiar JSON
copies the exact "datekeys inspect -json" view.
No network: a hash-mode Content-Security-Policy with connect-src 'self'
is the first element of every page, and scripts/check-build.mjs verifies
it, the fixtures and the absence of external URLs after every build.
Large files are read only up to what steps 1 to 8 need.
Reviewed for design and accessibility (WCAG AA contrast, keyboard,
focus, live status, 360 px), security and correctness; 262 tests pass,
svelte-check has no warnings.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2 weeks ago
|
|
|
'manifest-src': ['self'],
|
|
|
|
|
'frame-src': ['none'],
|
|
|
|
|
'worker-src': ['none'],
|
|
|
|
|
'object-src': ['none'],
|
|
|
|
|
'base-uri': ['none'],
|
|
|
|
|
'form-action': ['none'],
|
|
|
|
|
},
|
|
|
|
|
},
|
|
|
|
|
prerender: {
|
|
|
|
|
handleHttpError: 'fail',
|
|
|
|
|
handleMissingId: 'fail',
|
|
|
|
|
handleUnseenRoutes: 'fail',
|
|
|
|
|
},
|
|
|
|
|
typescript: {
|
|
|
|
|
// The generated tsconfig covers src/ and vite.config.ts; the vitest
|
|
|
|
|
// configuration is type-checked as well.
|
|
|
|
|
config(tsconfig) {
|
|
|
|
|
tsconfig.include.push('../vitest.config.ts');
|
|
|
|
|
},
|
|
|
|
|
},
|
|
|
|
|
},
|
|
|
|
|
};
|
|
|
|
|
|
|
|
|
|
export default config;
|