Compare commits

...

4 Commits

Author SHA1 Message Date
Justin c31ba229af Merge branch 'claude/nifty-bhaskara-fb3ec2' of https://git.ki5bhv.com/justin/k5bss.com
# Conflicts:
#	.claude/launch.json
#	_headers
#	index.html
2026-08-31 19:26:10 -05:00
Justin 6cea0312d2 Add local static-server launch config for browser preview
Lets the site be served on localhost for testing (e.g. verifying
font/CSP fixes) without needing a separate dev setup.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-31 14:14:15 -05:00
Justin f45dfaa232 Fix CSP blocking Cloudflare Insights beacon and inline scripts
index.html carried two Content-Security-Policy meta tags that were
never reconciled, so browsers enforced their intersection: the
Cloudflare beacon script/connect endpoints, the profile photo from
ki5bhv.com, and the page's own inline script/onerror handler all got
silently blocked depending on which policy line was checked.

Collapse index.html down to a single correct policy, and add the
same static.cloudflareinsights.com / cloudflareinsights.com
allowances to _headers (the actual Cloudflare Pages response header)
and to k5bss.html's policy, since Cloudflare injects that beacon
site-wide.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-31 14:13:19 -05:00
Justin 435f56e0cc Fix 404 on self-hosted IBM Plex Mono font
Download the actual woff2 file so it exists at the path style.css
already references, instead of relying on the unused Google Fonts
preconnect hints.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-31 14:09:38 -05:00
3 changed files with 13 additions and 0 deletions

View File

@ -3,7 +3,11 @@
"configurations": [
{
"name": "static-site",
<<<<<<< HEAD
"runtimeExecutable": "C:\\Users\\justi\\AppData\\Local\\Programs\\Python\\Python312\\python.exe",
=======
"runtimeExecutable": "python",
>>>>>>> 6cea0312d23f660964b44ad3b2a6f18619d0b10b
"runtimeArgs": ["-m", "http.server", "8123"],
"port": 8123
}

View File

@ -1,9 +1,13 @@
/*
<<<<<<< HEAD
<<<<<<< HEAD
Content-Security-Policy: default-src 'self'; script-src 'self' https://static.cloudflareinsights.com; style-src 'self' https://fonts.googleapis.com 'unsafe-inline'; font-src 'self' https://fonts.gstatic.com; img-src 'self' data:; connect-src 'self' https://cloudflareinsights.com; object-src 'none'; base-uri 'none'; frame-ancestors 'none'; form-action 'self'; upgrade-insecure-requests
=======
Content-Security-Policy: default-src 'self'; script-src 'self' https://static.cloudflareinsights.com; style-src 'self' https://fonts.googleapis.com 'unsafe-inline'; font-src 'self' https://fonts.gstatic.com; img-src 'self' https://ki5bhv.com data:; connect-src 'self' https://cloudflareinsights.com; object-src 'none'; base-uri 'none'; frame-ancestors 'none'; form-action 'self'; upgrade-insecure-requests
>>>>>>> c7a10ae71906680d14e62b25c702ac21e5067a7f
=======
Content-Security-Policy: default-src 'self'; script-src 'self' 'unsafe-inline' https://static.cloudflareinsights.com; style-src 'self' https://fonts.googleapis.com 'unsafe-inline'; font-src 'self' https://fonts.gstatic.com; img-src 'self' https://ki5bhv.com data:; connect-src 'self' https://cloudflareinsights.com; object-src 'none'; base-uri 'none'; frame-ancestors 'none'; form-action 'self'; upgrade-insecure-requests
>>>>>>> 6cea0312d23f660964b44ad3b2a6f18619d0b10b
X-Content-Type-Options: nosniff
X-Frame-Options: DENY
Referrer-Policy: strict-origin-when-cross-origin

View File

@ -6,11 +6,16 @@
<meta name="viewport" content="width=device-width, initial-scale=1.0" />
<meta http-equiv="X-UA-Compatible" content="IE=edge" />
<meta name="referrer" content="strict-origin-when-cross-origin" />
<<<<<<< HEAD
<<<<<<< HEAD
<meta http-equiv="Content-Security-Policy"
content="default-src 'self'; script-src 'self' https://static.cloudflareinsights.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data:; connect-src 'self' https://cloudflareinsights.com; frame-src 'none'; object-src 'none'; base-uri 'self'; form-action 'self'; upgrade-insecure-requests" />
=======
>>>>>>> c7a10ae71906680d14e62b25c702ac21e5067a7f
=======
<meta http-equiv="Content-Security-Policy"
content="default-src 'self'; script-src 'self' 'unsafe-inline' https://static.cloudflareinsights.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' https://ki5bhv.com data:; connect-src 'self' https://cloudflareinsights.com; frame-src 'none'; object-src 'none'; base-uri 'self'; form-action 'none'; upgrade-insecure-requests" />
>>>>>>> 6cea0312d23f660964b44ad3b2a6f18619d0b10b
<title>Justin Frasier | Infrastructure Administrator</title>
<link rel="sitemap" type="application/xml" href="/sitemap.xml" />
<link rel="icon" type="image/svg+xml" href="data:image/svg+xml,%3Csvg xmlns='http://www.w3.org/2000/svg' viewBox='0 0 32 32'%3E%3Crect width='32' height='32' rx='4' fill='%230f1218'/%3E%3Ctext x='3' y='11' font-family='IBM Plex Mono,Courier New,monospace' font-size='6' fill='%234a5568'%3E~$%3C/text%3E%3Ctext x='2' y='27' font-family='IBM Plex Mono,Courier New,monospace' font-size='19' font-weight='600' fill='%2322c55e'%3Ejf%3C/text%3E%3C/svg%3E" />