Fix stale block page preview by cache-busting static assets
The preview iframe stayed blank after a redeploy because /static/js/app.js is served with a 24h Cache-Control and no versioning, so browsers kept using the pre-existing cached copy that predated the preview code. Static CSS/JS references now carry a ?v=<build commit> query string so a new build is never masked by a stale cache. Also makes the CSP's frame-src explicit for the preview iframe rather than relying on the default-src fallback. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01TTKpGMQzpfDsvedu1hvSUf
This commit is contained in:
@@ -418,6 +418,7 @@ func (s *Server) withSecurityHeaders(next http.Handler) http.Handler {
|
||||
"font-src 'self'; "+
|
||||
"connect-src 'self'; "+
|
||||
"form-action 'self'; "+
|
||||
"frame-src 'self'; "+
|
||||
"frame-ancestors 'none'; "+
|
||||
"base-uri 'none'; "+
|
||||
"object-src 'none'")
|
||||
|
||||
Reference in New Issue
Block a user