trackslash
TRACK-6 P1

Self-host frontend assets instead of executing third-party CDN scripts

0
All issues

Description

Problem

Authenticated pages execute JavaScript directly from cdn.tailwindcss.com and unpkg.com without Subresource Integrity (internal/server/templates/shell.html:8-10). The Tailwind URL is not versioned. The login and signup pages load the same third-party scripts before rendering credential/passkey controls (internal/server/templates/login.html:8-13, :52-57).

These scripts execute with the full track-slash origin. Pinning a version in the URL does not protect against CDN, registry, account, or network-path compromise when no immutable local artifact or integrity hash is enforced.

Impact

A compromised or unexpectedly changed CDN asset can keylog passwords on the login page, interfere with passkey ceremonies, read project/issue data, and perform authenticated actions as the current user. This creates an avoidable third-party path to account and workspace compromise.

Acceptance criteria

  • Build and serve Tailwind CSS, HTMX, and Lucide assets from the application/release artifact.
  • Pin dependency versions and checksums in a lockfile or equivalent reproducible build input.
  • Remove production runtime requests to cdn.tailwindcss.com and unpkg.com.
  • Add a test that rendered login, signup, and authenticated shells contain no third-party executable assets.
  • Verify the UI works with a script-src 'self' / style-src 'self' CSP target (coordinate with the browser-security-header ticket).

Sub-issues

0

Linked issues

0

GitHub

0

No branches or pull requests linked.

Comments

0
No comments.