The preview iframe stayed blank after a redeploy because /static/js/app.js
is served with a 24h Cache-Control and no versioning, so browsers kept
using the pre-existing cached copy that predated the preview code. Static
CSS/JS references now carry a ?v=<build commit> query string so a new
build is never masked by a stale cache. Also makes the CSP's frame-src
explicit for the preview iframe rather than relying on the default-src
fallback.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TTKpGMQzpfDsvedu1hvSUf
Serves a page explaining why a domain was blocked instead of leaving a
sinkholed client with a dead connection. Binds its own HTTP/HTTPS
listeners with self-signed, per-hostname TLS certs generated on the
fly, re-evaluates the requesting client against the policy engine per
request, and renders an HTML template editable from Settings with a
live preview.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TTKpGMQzpfDsvedu1hvSUf