chore(api,docs): update unpkg libraries, specify SRI hash, add strict CSP - #916
Conversation
Codecov Report❌ Patch coverage is
Additional details and impacted files@@ Coverage Diff @@
## main #916 +/- ##
=======================================
Coverage 93.11% 93.11%
=======================================
Files 23 23
Lines 4736 4766 +30
=======================================
+ Hits 4410 4438 +28
- Misses 268 269 +1
- Partials 58 59 +1 ☔ View full report in Codecov by Sentry. 🚀 New features to boost your workflow:
|
7dad9ec to
d8507bb
Compare
d8507bb to
99c3246
Compare
|
Any reason not to share CSPs between the docs renderers? |
@wolveix they all need to have their own distinct CSP where only some directives are shared, while others depend on the UI framework being used. |
|
@wolveix can you have a look? :) This would be very nice to have included in an upcoming release so we can finally get rid ouf our custom doc handler and instead use one of Huma's default handlers 😃 |
|
ftr: Chrome just fixed a zero day use-after-free in its CSS handling: https://chromereleases.googleblog.com/2026/02/stable-channel-update-for-desktop_13.html, this change will prevent unpkg.com from exploiting it (which will most probably not happen, but still.) |
|
Sorry, was just going through the other issues :) Definitely keen to merge this before I create a new release; however, I'm not a fan of the current implementation (more on my side than yours). Reckon we could cut down on the duplicate code here, without making it an abstracted mess? Not a blocker by any means, but if you have ideas now before we merge, it'd be awesome to get them implemented 🙏🏻 |
dab0d36 to
509902a
Compare
|
@wolveix updated the docs to refer to the default docs implementation in |
| /> | ||
| </body> | ||
| </html>`)) | ||
| // Please refer to the "DocsRendererScalar" renderer code inside api.go on what to return here |
There was a problem hiding this comment.
Nice! Though for the first docs listed, I'd still include the raw HTML directly to show how it can be customized, per the existing docs :D
|
@leonklingele nicely done! One minor comment 🙏🏻 |
509902a to
24f86b9
Compare
There was a problem hiding this comment.
Pull request overview
This pull request updates the API documentation renderers by upgrading external library versions, adding Subresource Integrity (SRI) hashes for security, and implementing strict Content Security Policy (CSP) headers. It also fixes a typo in the test file and reorders documentation sections to prioritize Scalar over Stoplight Elements.
Changes:
- Updated unpkg library versions: @scalar/api-reference to 1.44.20, @stoplight/elements to 9.0.15, and swagger-ui-dist to 5.31.1
- Added SRI integrity hashes and crossorigin attributes to all external script and stylesheet resources
- Implemented strict CSP directives for all three documentation renderers with restrictive policies including sandbox, script-src, and style-src directives
- Fixed typo "Scalarin HTML" to "Scalar in HTML" in api.go and corresponding test
- Reordered documentation sections to present Scalar Docs before Stoplight Elements
- Changed Scalar renderer to use JSON format instead of YAML for OpenAPI spec
- Refactored SwaggerUI to use data attributes and dataset API for URL passing
- Changed referrer policy from "same-origin" to "no-referrer" for improved privacy
Reviewed changes
Copilot reviewed 2 out of 3 changed files in this pull request and generated 1 comment.
| File | Description |
|---|---|
| api.go | Updated library versions, added SRI hashes, implemented CSP headers, fixed typo, refactored HTML for all three renderers |
| api_test.go | Fixed test assertion from "Scalarin HTML" to "Scalar in HTML" |
| docs/docs/features/api-docs.md | Reordered sections to show Scalar first, updated examples to reference renderer code instead of inline HTML |
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
| <script src="https://unpkg.com/swagger-ui-dist@5.31.0/swagger-ui-bundle.js" crossorigin></script> | ||
| <script> | ||
| <script src="https://unpkg.com/swagger-ui-dist@5.31.1/swagger-ui-bundle.js" crossorigin integrity="sha384-o9idN8HE6/V6SAewgnr6/5nz7+Npt5J0Cb4tNyXK8pycsVmgl1ZNbRS7tlEGxd+J"></script> | ||
| <script data-url="` + openAPIPath + `.json> |
There was a problem hiding this comment.
Missing closing double quote in the data-url attribute. The line should be:
<script data-url="` + openAPIPath + `.json">
This will cause the HTML to be malformed and the script tag to not parse correctly.
| <script data-url="` + openAPIPath + `.json> | |
| <script data-url="` + openAPIPath + `.json"> |
There was a problem hiding this comment.
Please have another look.
24f86b9 to
26af2c1
Compare
26af2c1 to
b6a6507
Compare
|
@wolveix updated, ptal, again :) |
A last-minute, seemingly inconspicuous, addition[^0] was made to danielgtaylor#916 which resulted in changing the CSP hash for the inline script, effectively breaking Swagger Web UI spec rendering. This change updates to the correct hash. [^0]: https://github.com/danielgtaylor/huma/compare/26af2c17e8cc3fca088c4a878611627c0389711a..b6a65071f8f3206a654dd37dabf2766ffab3e883
See the individual commits for details.