refactor: split the Site's behaviour out of one 1,575-line inline script
dtf-site.html held commercial rules, the nesting engine, PDF analysis, the cart and every handler in a single inline script, 42% of the runtime code in one file, and the money logic lived in the middle of it. It is now nine files under local/static, cut at the section markers the original author left, so no function was split across a boundary: config, product modes, upload, sheet analysis, PDF, quality, packing, cart, flow. They load as classic scripts in the original order and share one global scope, so evaluation is exactly what it was; the extraction was checked byte-identical against the original before the tags replaced it. dtf-site.html is 1,394 lines of markup and style. With no inline script left anywhere, the policy no longer needs a hash allowlist: script-src is now 'self' alone, which is stronger than what it replaced and cannot drift as the page changes. Three things depended on the old shape and were updated rather than worked around. The pricing parity test read the ladder out of the HTML and now reads it from site-config.js, still proving the server agrees with what the customer is shown. The isolated artwork test served four hardcoded script paths and now serves any script that resolves inside local/static, so the next file added does not silently 404. The CSP assertion checked the whole policy for 'unsafe-inline' and now checks the script-src directive alone, since style-src legitimately carries it. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
22
ROADMAP.md
22
ROADMAP.md
@@ -410,10 +410,11 @@ charges. Fix as part of 1.1.
|
||||
`smoke_test` failed on `/session`, blocking the release. Browser tests skip with
|
||||
a warning when the runner has no Chrome — **install `google-chrome-stable` on the
|
||||
runner (or set `CHROME_BIN`) to make them gate as well.**
|
||||
- `[ ]` 5.2 — Remove or archive the dead prototypes `(F30)`: `portal/`, `kanban/`,
|
||||
`agente/`, root `schema.sql` (~1,500 lines describing an abandoned model). Several
|
||||
expose unauthenticated endpoints taking the acting user from the request body
|
||||
(`/api/puxar`, `/api/devolver`).
|
||||
- `[x]` 5.2 — `portal/`, `kanban/`, `agente/`, the root `schema.sql` and
|
||||
`.env.exemplo` removed: 2,283 lines implementing a model this system abandoned,
|
||||
referenced by nothing, with several endpoints taking the acting user from the
|
||||
request body. The documents describing them are archived under `docs/historico/`
|
||||
with a header saying they are background, not instructions.
|
||||
- `[x]` 5.3 — Root `requirements.txt` deleted. It pinned by wildcard, listed
|
||||
packages the system does not use, and sat next to the hash-locked
|
||||
`local/requirements.lock` inviting the wrong one to be installed. Only historical
|
||||
@@ -427,9 +428,16 @@ charges. Fix as part of 1.1.
|
||||
`SECURITY_REPORT.md` describe a MinIO localhost stack, an API with "no external
|
||||
network route", a `operator` / `local-operator-only` login the email-validated
|
||||
model rejects, and a release gate — none match the current tree.
|
||||
- `[ ]` 5.6 — `dtf-site.html` is 2,889 lines with commercial rules, the packing
|
||||
engine, PDF analysis, UI and checkout inline `(F29)`. Split at least the pricing
|
||||
table and the packer so 3.2 has somewhere to land.
|
||||
- `[x]` 5.6 — The Site's 1,575-line inline script is now nine files under
|
||||
`local/static/`, cut at the author's own section boundaries so no function was
|
||||
split: config, modes, upload, sheet analysis, PDF, quality, packing, cart, flow.
|
||||
`dtf-site.html` is 1,394 lines of markup and style. The extraction was verified
|
||||
byte-identical before the tags were swapped in, and they load as classic scripts
|
||||
in the original order, so evaluation semantics are unchanged.
|
||||
|
||||
A consequence worth having: with no inline script anywhere, the policy needs no
|
||||
hash allowlist and is now simply `script-src 'self'`. `site-packing.js` is also
|
||||
where a server-side packer (3.2) has to agree, which was the point of splitting.
|
||||
- `[ ]` 5.7 — Commercial rules duplicated between `FAIXAS` (JS) and `TIERS` (Python)
|
||||
`(F26)`. `test_pricing` guards parity; generate one from the other instead.
|
||||
- `[ ]` 5.11 — Nothing tests the schema against an empty database. The 4.1 indexes
|
||||
|
||||
Reference in New Issue
Block a user