Merge manifest hygiene and reconcile runtime exclusions with CSP response capture

This commit is contained in:
Jonathan Sykes
2026-10-09 15:12:39 +08:00
14 changed files with 22494 additions and 15 deletions

View File

@@ -112,3 +112,11 @@ test('the last core script owns boot without an extra request or unsafe stale pa
assert.ok(html.includes("'sha256-__APP_SCRIPT_HASH__'"));
assert.ok(readFileSync(join(__dirname,'section-rail.js'),'utf8').includes('root.AppBootstrap={ready}'));
});
test('runtime exclusion rules never remove shell or declared dynamic assets', async () => {
const { isRuntimeAsset } = await import('../server/asset-manifest.js');
const definition = JSON.parse(readFileSync(join(__dirname, 'assets.json'), 'utf8'));
for (const asset of new Set([...shell.filter(p => p !== '/'), ...Object.values(definition.groups).flatMap(g => g.files)])) {
assert.ok(isRuntimeAsset(asset, definition), `${asset} remains a runtime asset`);
}
for (const asset of ['/app.test.js', '/nested/probe.test.mjs', '/README.md', '/fonts/font-OFL.txt', '/admin.html', '/perf/fixture.js']) assert.equal(isRuntimeAsset(asset, definition), false, asset);
});