diff --git a/.github/workflows/build-desktop.yml b/.github/workflows/build-desktop.yml index ce45af6..4e48d1f 100644 --- a/.github/workflows/build-desktop.yml +++ b/.github/workflows/build-desktop.yml @@ -78,8 +78,8 @@ jobs: echo "VCPKGRS_TRIPLET=x64-windows-static-release" >> $GITHUB_ENV echo "VCPKG_DEFAULT_HOST_TRIPLET=x64-windows-static-release" >> $GITHUB_ENV echo "RUSTFLAGS=-Ctarget-feature=+crt-static" >> $GITHUB_ENV - # Override macOS-specific flags from .cargo/config.toml - echo "CXXFLAGS=" >> $GITHUB_ENV + # Override macOS-specific paths from .cargo/config.toml; ICU 78+ requires C++17 + echo "CXXFLAGS=/std:c++17" >> $GITHUB_ENV echo "CFLAGS=" >> $GITHUB_ENV - name: Setup Apple code signing diff --git a/apps/desktop/src/__tests__/tauri-conf-csp.test.ts b/apps/desktop/src/__tests__/tauri-conf-csp.test.ts new file mode 100644 index 0000000..f0fbbd6 --- /dev/null +++ b/apps/desktop/src/__tests__/tauri-conf-csp.test.ts @@ -0,0 +1,40 @@ +import { describe, it, expect } from "vitest"; +import { readFileSync } from "fs"; +import { resolve } from "path"; + +/** + * Validates tauri.conf.json CSP (Content Security Policy) configuration. + * + * Background: Tauri 2 injects nonces into CSP directives at build time. + * Per CSP spec, when a nonce is present, 'unsafe-inline' is ignored by the browser. + * This means dynamically injected