test(opaque): fix playwright scenarios

This commit is contained in:
Edouard Vanbelle
2026-08-03 08:39:54 +02:00
parent 526903e0d5
commit 39ea00fff3
2 changed files with 35 additions and 4 deletions
+7 -1
View File
@@ -90,7 +90,13 @@ const config = {
mode: 'hash',
directives: {
'default-src': ['self'],
'script-src': ['self', themeInitHash],
// `'wasm-unsafe-eval'` (CSP Level 3) permits WebAssembly.compile()
// without allowing eval() for JavaScript. Required for the OPAQUE
// aPAKE client (`@serenity-kit/opaque`), lazy-loaded by the login
// path only when `OXICLOUD_OPAQUE_MODE != off`. Mirrors the Rust
// server's `content_security_policy` in `src/interfaces/web/mod.rs`
// so headers + this meta tag agree on the same posture.
'script-src': ['self', 'wasm-unsafe-eval', themeInitHash],
'worker-src': ['self'],
'style-src': ['self', 'unsafe-inline'],
'img-src': ['self', 'data:', 'blob:', 'https:'],