style: format auth.ts to satisfy format:check (CI)

Wrap the two long CSP-builder lines in registerSecurityHeaders to the 120-col
Prettier limit. Formatting only — no behavior change. Fixes the failing
"Typecheck & Lint" check (prettier --check) on PR #103.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
Ark0N
2026-06-07 04:45:35 +02:00
co-authored by Claude Opus 4.8
parent afea6d6a1c
commit ceca85365c
+4 -2
View File
@@ -158,9 +158,11 @@ export function registerSecurityHeaders(app: FastifyInstance, https: boolean): v
// needs WebAssembly eval and must fetch its wasm/model from the pinned CDNs.
// Computed once; OFF by default so the production CSP is byte-for-byte unchanged.
const gesture = process.env.CODEMAN_GESTURE === '1';
const scriptSrc = "script-src 'self' 'unsafe-inline' https://cdn.jsdelivr.net" + (gesture ? " 'wasm-unsafe-eval'" : '');
const scriptSrc =
"script-src 'self' 'unsafe-inline' https://cdn.jsdelivr.net" + (gesture ? " 'wasm-unsafe-eval'" : '');
const connectSrc =
"connect-src 'self' wss://api.deepgram.com" + (gesture ? ' https://cdn.jsdelivr.net https://storage.googleapis.com' : '');
"connect-src 'self' wss://api.deepgram.com" +
(gesture ? ' https://cdn.jsdelivr.net https://storage.googleapis.com' : '');
const workerSrc = gesture ? "; worker-src 'self' blob:" : '';
const csp =
`default-src 'self'; ${scriptSrc}; style-src 'self' 'unsafe-inline' https://cdn.jsdelivr.net; ` +