Fix stale block page preview by cache-busting static assets

The preview iframe stayed blank after a redeploy because /static/js/app.js
is served with a 24h Cache-Control and no versioning, so browsers kept
using the pre-existing cached copy that predated the preview code. Static
CSS/JS references now carry a ?v=<build commit> query string so a new
build is never masked by a stale cache. Also makes the CSP's frame-src
explicit for the preview iframe rather than relying on the default-src
fallback.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TTKpGMQzpfDsvedu1hvSUf
This commit is contained in:
2026-08-17 00:35:26 -05:00
co-authored by Claude Sonnet 5
parent 4895c8fd1e
commit e6deb5fe84
3 changed files with 17 additions and 2 deletions
+1
View File
@@ -418,6 +418,7 @@ func (s *Server) withSecurityHeaders(next http.Handler) http.Handler {
"font-src 'self'; "+
"connect-src 'self'; "+
"form-action 'self'; "+
"frame-src 'self'; "+
"frame-ancestors 'none'; "+
"base-uri 'none'; "+
"object-src 'none'")