Address remaining safe security hardening

This commit is contained in:
BigBodyCobain
2026-06-02 13:34:11 -06:00
parent 10a8c7b5be
commit c3dd95f6a9
14 changed files with 94 additions and 47 deletions
@@ -147,18 +147,18 @@ describe('middleware matcher exclusions', () => {
});
// ---------------------------------------------------------------------------
// 5. Google Fonts domains are preserved in CSP
// 5. Runtime Google Fonts domains are not required in CSP
// ---------------------------------------------------------------------------
describe('Google Fonts domains in CSP', () => {
it('style-src includes https://fonts.googleapis.com', () => {
describe('local font CSP', () => {
it('style-src does not allow https://fonts.googleapis.com', () => {
const csp = getCsp();
expect(csp).toContain('https://fonts.googleapis.com');
expect(csp).not.toContain('https://fonts.googleapis.com');
});
it('font-src includes https://fonts.gstatic.com', () => {
it('font-src does not allow https://fonts.gstatic.com', () => {
const csp = getCsp();
expect(csp).toContain('https://fonts.gstatic.com');
expect(csp).not.toContain('https://fonts.gstatic.com');
});
});
@@ -178,9 +178,9 @@ describe('production CSP directive completeness', () => {
expect(csp).not.toMatch(/script-src [^;]*'nonce-/);
});
it('has style-src with unsafe-inline and fonts.googleapis.com', () => {
it('has style-src with hydration-compatible inline styles only', () => {
expect(csp).toMatch(/style-src [^;]*'unsafe-inline'/);
expect(csp).toMatch(/style-src [^;]*https:\/\/fonts\.googleapis\.com/);
expect(csp).not.toMatch(/style-src [^;]*https:\/\/fonts\.googleapis\.com/);
});
it('has worker-src self blob:', () => {
@@ -130,16 +130,17 @@ describe('unchanged directives in production', () => {
vi.unstubAllEnvs();
});
it('style-src preserves unsafe-inline and Google Fonts', () => {
it('style-src preserves unsafe-inline without runtime Google Fonts', () => {
const styleSrc = getDirective('style-src');
expect(styleSrc).toContain("'unsafe-inline'");
expect(styleSrc).toContain('https://fonts.googleapis.com');
expect(styleSrc).not.toContain('https://fonts.googleapis.com');
});
it('font-src preserves data: and fonts.gstatic.com', () => {
it('font-src preserves self and data without runtime Google Fonts', () => {
const fontSrc = getDirective('font-src');
expect(fontSrc).toContain("'self'");
expect(fontSrc).toContain('data:');
expect(fontSrc).toContain('https://fonts.gstatic.com');
expect(fontSrc).not.toContain('https://fonts.gstatic.com');
});
it('worker-src self blob:', () => {