From c2e9190405260011abc979c99c67fbbf61478957 Mon Sep 17 00:00:00 2001 From: Jobin Kurian Date: Wed, 1 Apr 2026 09:23:05 +0530 Subject: [PATCH] fix(wiki): tighten CSP with nonce and stricter LLM error matching Address PR review feedback: replace 'unsafe-inline' script-src with a per-build nonce, and parse error JSON before matching max_tokens rejection to avoid false positives. --- gitnexus/src/core/wiki/html-viewer.ts | 11 ++++-- gitnexus/src/core/wiki/llm-client.ts | 9 ++++- gitnexus/test/unit/wiki-html-viewer.test.ts | 42 ++++++++++++++------- 3 files changed, 43 insertions(+), 19 deletions(-) diff --git a/gitnexus/src/core/wiki/html-viewer.ts b/gitnexus/src/core/wiki/html-viewer.ts index b8b9bb01e..a21b424dd 100644 --- a/gitnexus/src/core/wiki/html-viewer.ts +++ b/gitnexus/src/core/wiki/html-viewer.ts @@ -5,6 +5,7 @@ * module tree, and metadata — viewable offline in any browser. */ +import { randomBytes } from 'crypto'; import fs from 'fs/promises'; import path from 'path'; @@ -90,6 +91,8 @@ function buildHTML( const treeJSON = safeJSON(moduleTree); const metaJSON = safeJSON(meta); + const nonce = randomBytes(16).toString('base64'); + const parts: string[] = []; // ── Head ── @@ -98,11 +101,11 @@ function buildHTML( parts.push(''); parts.push(''); parts.push(''); - parts.push(''); + parts.push(``); parts.push('' + esc(projectName) + ' — Wiki'); - parts.push('