mirror of
https://github.com/delibae/claude-prism.git
synced 2026-10-08 03:08:10 +00:00
fix: Windows CI C++17 flag for ICU 78+ and add CSP validation tests
- Set CXXFLAGS=/std:c++17 on Windows CI (ICU 78+ requires C++17 features like nested-namespace-definition and auto in non-type template params) - Add Vitest tests validating tauri.conf.json CSP configuration to prevent regressions (dangerousDisableAssetCspModification, style-src, connect-src, font-src directives) Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
This commit is contained in:
parent
bc36383328
commit
5dc5e71c36
2 changed files with 42 additions and 2 deletions
4
.github/workflows/build-desktop.yml
vendored
4
.github/workflows/build-desktop.yml
vendored
|
|
@ -78,8 +78,8 @@ jobs:
|
|||
echo "VCPKGRS_TRIPLET=x64-windows-static-release" >> $GITHUB_ENV
|
||||
echo "VCPKG_DEFAULT_HOST_TRIPLET=x64-windows-static-release" >> $GITHUB_ENV
|
||||
echo "RUSTFLAGS=-Ctarget-feature=+crt-static" >> $GITHUB_ENV
|
||||
# Override macOS-specific flags from .cargo/config.toml
|
||||
echo "CXXFLAGS=" >> $GITHUB_ENV
|
||||
# Override macOS-specific paths from .cargo/config.toml; ICU 78+ requires C++17
|
||||
echo "CXXFLAGS=/std:c++17" >> $GITHUB_ENV
|
||||
echo "CFLAGS=" >> $GITHUB_ENV
|
||||
|
||||
- name: Setup Apple code signing
|
||||
|
|
|
|||
40
apps/desktop/src/__tests__/tauri-conf-csp.test.ts
Normal file
40
apps/desktop/src/__tests__/tauri-conf-csp.test.ts
Normal file
|
|
@ -0,0 +1,40 @@
|
|||
import { describe, it, expect } from "vitest";
|
||||
import { readFileSync } from "fs";
|
||||
import { resolve } from "path";
|
||||
|
||||
/**
|
||||
* Validates tauri.conf.json CSP (Content Security Policy) configuration.
|
||||
*
|
||||
* Background: Tauri 2 injects nonces into CSP directives at build time.
|
||||
* Per CSP spec, when a nonce is present, 'unsafe-inline' is ignored by the browser.
|
||||
* This means dynamically injected <style> tags (e.g., from CodeMirror's style-mod)
|
||||
* get blocked in production builds, causing invisible editor text.
|
||||
*
|
||||
* The fix: `dangerousDisableAssetCspModification` prevents Tauri from adding nonces,
|
||||
* so 'unsafe-inline' remains effective for runtime style injection.
|
||||
*/
|
||||
describe("tauri.conf.json CSP configuration", () => {
|
||||
const confPath = resolve(__dirname, "../../src-tauri/tauri.conf.json");
|
||||
const conf = JSON.parse(readFileSync(confPath, "utf-8"));
|
||||
const security = conf.app?.security;
|
||||
const csp = security?.csp ?? "";
|
||||
|
||||
it("should have dangerousDisableAssetCspModification enabled so runtime style injection works", () => {
|
||||
expect(security?.dangerousDisableAssetCspModification).toBe(true);
|
||||
});
|
||||
|
||||
it("should include 'unsafe-inline' in style-src for CodeMirror dynamic styles", () => {
|
||||
const styleSrc = csp.match(/style-src\s+([^;]+)/)?.[1] ?? "";
|
||||
expect(styleSrc).toContain("'unsafe-inline'");
|
||||
});
|
||||
|
||||
it("should include ipc: in connect-src for Tauri IPC in production", () => {
|
||||
const connectSrc = csp.match(/connect-src\s+([^;]+)/)?.[1] ?? "";
|
||||
expect(connectSrc).toContain("ipc:");
|
||||
});
|
||||
|
||||
it("should include data: in font-src for base64-encoded fonts", () => {
|
||||
const fontSrc = csp.match(/font-src\s+([^;]+)/)?.[1] ?? "";
|
||||
expect(fontSrc).toContain("data:");
|
||||
});
|
||||
});
|
||||
Loading…
Add table
Reference in a new issue