From ceca85365c310593f5a8823030d4fe82272ef9fd Mon Sep 17 00:00:00 2001 From: Ark0N Date: Sun, 7 Jun 2026 04:45:35 +0200 Subject: [PATCH] style: format auth.ts to satisfy format:check (CI) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Wrap the two long CSP-builder lines in registerSecurityHeaders to the 120-col Prettier limit. Formatting only — no behavior change. Fixes the failing "Typecheck & Lint" check (prettier --check) on PR #103. Co-Authored-By: Claude Opus 4.8 (1M context) --- src/web/middleware/auth.ts | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-) diff --git a/src/web/middleware/auth.ts b/src/web/middleware/auth.ts index 7ae4a247..74416491 100644 --- a/src/web/middleware/auth.ts +++ b/src/web/middleware/auth.ts @@ -158,9 +158,11 @@ export function registerSecurityHeaders(app: FastifyInstance, https: boolean): v // needs WebAssembly eval and must fetch its wasm/model from the pinned CDNs. // Computed once; OFF by default so the production CSP is byte-for-byte unchanged. const gesture = process.env.CODEMAN_GESTURE === '1'; - const scriptSrc = "script-src 'self' 'unsafe-inline' https://cdn.jsdelivr.net" + (gesture ? " 'wasm-unsafe-eval'" : ''); + const scriptSrc = + "script-src 'self' 'unsafe-inline' https://cdn.jsdelivr.net" + (gesture ? " 'wasm-unsafe-eval'" : ''); const connectSrc = - "connect-src 'self' wss://api.deepgram.com" + (gesture ? ' https://cdn.jsdelivr.net https://storage.googleapis.com' : ''); + "connect-src 'self' wss://api.deepgram.com" + + (gesture ? ' https://cdn.jsdelivr.net https://storage.googleapis.com' : ''); const workerSrc = gesture ? "; worker-src 'self' blob:" : ''; const csp = `default-src 'self'; ${scriptSrc}; style-src 'self' 'unsafe-inline' https://cdn.jsdelivr.net; ` +