Description
Problem
Authenticated pages execute JavaScript directly from cdn.tailwindcss.com and unpkg.com without Subresource Integrity (internal/server/templates/shell.html:8-10). The Tailwind URL is not versioned. The login and signup pages load the same third-party scripts before rendering credential/passkey controls (internal/server/templates/login.html:8-13, :52-57).
These scripts execute with the full track-slash origin. Pinning a version in the URL does not protect against CDN, registry, account, or network-path compromise when no immutable local artifact or integrity hash is enforced.
Impact
A compromised or unexpectedly changed CDN asset can keylog passwords on the login page, interfere with passkey ceremonies, read project/issue data, and perform authenticated actions as the current user. This creates an avoidable third-party path to account and workspace compromise.
Acceptance criteria
- Build and serve Tailwind CSS, HTMX, and Lucide assets from the application/release artifact.
- Pin dependency versions and checksums in a lockfile or equivalent reproducible build input.
- Remove production runtime requests to
cdn.tailwindcss.comandunpkg.com. - Add a test that rendered login, signup, and authenticated shells contain no third-party executable assets.
- Verify the UI works with a
script-src 'self'/style-src 'self'CSP target (coordinate with the browser-security-header ticket).
Sub-issues
0Linked issues
0GitHub
0No branches or pull requests linked.