Skip to content

Generate hub embed font CSS safely - #8

Merged
iksteen merged 4 commits into
masterfrom
fix/hub-generated-font-css
Jul 31, 2026
Merged

Generate hub embed font CSS safely#8
iksteen merged 4 commits into
masterfrom
fix/hub-generated-font-css

Conversation

@iksteen

@iksteen iksteen commented Jul 29, 2026

Copy link
Copy Markdown
Owner

Scrutinize embed mode more. Font CSS is now hub generated and client CSS is not longer allowed. Normalize font family names.
Allow hub to force a template so clean a client can't inject anything besides content and fonts.

iksteen and others added 4 commits July 29, 2026 23:25
Add hub template fallback/override controls and ensure forced pages discard client-authored templates, CSS, and render configuration while retaining validated hash-keyed fonts through hub-generated presentation data. Protect hub-owned pages with nonce CSP and safe render JSON serialization.

Inspired by mrexodia's work in #7.

Co-authored-by: Duncan Ogilvie <mr.exodia.tpodt@gmail.com>
Carry over mrexodia's Windows-specific large-enum rationale from PR #7; the command enum is parsed once and immediately consumed, so boxing only shifts the size disparity.

Co-authored-by: Duncan Ogilvie <mr.exodia.tpodt@gmail.com>
Escape only the less-than sign needed to protect inline script JSON, and emit already-validated hash family keys directly.
@iksteen
iksteen merged commit 825c3ec into master Jul 31, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant