Skip to content

chore(api,docs): update unpkg libraries, specify SRI hash, add strict CSP - #916

Merged
wolveix merged 3 commits into
danielgtaylor:mainfrom
leonklingele:chore/spec-docs-security
Feb 19, 2026
Merged

wolveix merged 3 commits into
danielgtaylor:mainfrom
leonklingele:chore/spec-docs-security

Conversation

@leonklingele

Copy link
Copy Markdown
Contributor

See the individual commits for details.

@codecov

codecov Bot commented Nov 17, 2025 •

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 96.15385% with 2 lines in your changes missing coverage. Please review.
✅ Project coverage is 93.11%. Comparing base (e31a819) to head (b6a6507).
⚠️ Report is 2 commits behind head on main.

Files with missing lines Patch % Lines
api.go 96.15% 1 Missing and 1 partial ⚠️
Additional details and impacted files
@@           Coverage Diff           @@
##             main     #916   +/-   ##
=======================================
  Coverage   93.11%   93.11%           
=======================================
  Files          23       23           
  Lines        4736     4766   +30     
=======================================
+ Hits         4410     4438   +28     
- Misses        268      269    +1     
- Partials       58       59    +1     

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@leonklingele
leonklingele force-pushed the chore/spec-docs-security branch 2 times, most recently from 7dad9ec to d8507bb Compare November 18, 2025 10:48
@leonklingele
leonklingele force-pushed the chore/spec-docs-security branch from d8507bb to 99c3246 Compare February 17, 2026 23:33
@wolveix

wolveix commented Feb 17, 2026

Copy link
Copy Markdown
Collaborator

Any reason not to share CSPs between the docs renderers?

@leonklingele

Copy link
Copy Markdown
Contributor Author

Any reason not to share CSPs between the docs renderers?

@wolveix they all need to have their own distinct CSP where only some directives are shared, while others depend on the UI framework being used.

@leonklingele

Copy link
Copy Markdown
Contributor Author

@wolveix can you have a look? :) This would be very nice to have included in an upcoming release so we can finally get rid ouf our custom doc handler and instead use one of Huma's default handlers 😃

@leonklingele

Copy link
Copy Markdown
Contributor Author

ftr: Chrome just fixed a zero day use-after-free in its CSS handling: https://chromereleases.googleblog.com/2026/02/stable-channel-update-for-desktop_13.html, this change will prevent unpkg.com from exploiting it (which will most probably not happen, but still.)

@wolveix

wolveix commented Feb 19, 2026

Copy link
Copy Markdown
Collaborator

Sorry, was just going through the other issues :)

Definitely keen to merge this before I create a new release; however, I'm not a fan of the current implementation (more on my side than yours). Reckon we could cut down on the duplicate code here, without making it an abstracted mess?

Not a blocker by any means, but if you have ideas now before we merge, it'd be awesome to get them implemented 🙏🏻

@leonklingele
leonklingele force-pushed the chore/spec-docs-security branch from dab0d36 to 509902a Compare February 19, 2026 02:15
@leonklingele

Copy link
Copy Markdown
Contributor Author

@wolveix updated the docs to refer to the default docs implementation in api.go. This will remove all code duplications. ptal :)

Comment thread docs/docs/features/api-docs.md Outdated
/>
</body>
</html>`))
// Please refer to the "DocsRendererScalar" renderer code inside api.go on what to return here

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Nice! Though for the first docs listed, I'd still include the raw HTML directly to show how it can be customized, per the existing docs :D

@wolveix

wolveix commented Feb 19, 2026

Copy link
Copy Markdown
Collaborator

@leonklingele nicely done! One minor comment 🙏🏻

@leonklingele
leonklingele force-pushed the chore/spec-docs-security branch from 509902a to 24f86b9 Compare February 19, 2026 02:32
Copilot AI review requested due to automatic review settings February 19, 2026 02:32

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This pull request updates the API documentation renderers by upgrading external library versions, adding Subresource Integrity (SRI) hashes for security, and implementing strict Content Security Policy (CSP) headers. It also fixes a typo in the test file and reorders documentation sections to prioritize Scalar over Stoplight Elements.

Changes:

  • Updated unpkg library versions: @scalar/api-reference to 1.44.20, @stoplight/elements to 9.0.15, and swagger-ui-dist to 5.31.1
  • Added SRI integrity hashes and crossorigin attributes to all external script and stylesheet resources
  • Implemented strict CSP directives for all three documentation renderers with restrictive policies including sandbox, script-src, and style-src directives
  • Fixed typo "Scalarin HTML" to "Scalar in HTML" in api.go and corresponding test
  • Reordered documentation sections to present Scalar Docs before Stoplight Elements
  • Changed Scalar renderer to use JSON format instead of YAML for OpenAPI spec
  • Refactored SwaggerUI to use data attributes and dataset API for URL passing
  • Changed referrer policy from "same-origin" to "no-referrer" for improved privacy

Reviewed changes

Copilot reviewed 2 out of 3 changed files in this pull request and generated 1 comment.

File Description
api.go Updated library versions, added SRI hashes, implemented CSP headers, fixed typo, refactored HTML for all three renderers
api_test.go Fixed test assertion from "Scalarin HTML" to "Scalar in HTML"
docs/docs/features/api-docs.md Reordered sections to show Scalar first, updated examples to reference renderer code instead of inline HTML

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread api.go Outdated
<script src="https://unpkg.com/swagger-ui-dist@5.31.0/swagger-ui-bundle.js" crossorigin></script>
<script>
<script src="https://unpkg.com/swagger-ui-dist@5.31.1/swagger-ui-bundle.js" crossorigin integrity="sha384-o9idN8HE6/V6SAewgnr6/5nz7+Npt5J0Cb4tNyXK8pycsVmgl1ZNbRS7tlEGxd+J"></script>
<script data-url="` + openAPIPath + `.json>

Copilot AI Feb 19, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Missing closing double quote in the data-url attribute. The line should be:

<script data-url="` + openAPIPath + `.json">

This will cause the HTML to be malformed and the script tag to not parse correctly.

Suggested change
<script data-url="` + openAPIPath + `.json>
<script data-url="` + openAPIPath + `.json">

Copilot uses AI. Check for mistakes.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Please have another look.

@leonklingele
leonklingele force-pushed the chore/spec-docs-security branch from 24f86b9 to 26af2c1 Compare February 19, 2026 02:39
@leonklingele
leonklingele force-pushed the chore/spec-docs-security branch from 26af2c1 to b6a6507 Compare February 19, 2026 02:40
@leonklingele

Copy link
Copy Markdown
Contributor Author

@wolveix updated, ptal, again :)

@wolveix
wolveix merged commit 6c29f67 into danielgtaylor:main Feb 19, 2026
4 checks passed
leonklingele added a commit to leonklingele/huma that referenced this pull request Feb 19, 2026
A last-minute, seemingly inconspicuous, addition[^0] was made to
danielgtaylor#916 which resulted in changing the
CSP hash for the inline script, effectively breaking Swagger Web UI spec
rendering. This change updates to the correct hash.

[^0]: https://github.com/danielgtaylor/huma/compare/26af2c17e8cc3fca088c4a878611627c0389711a..b6a65071f8f3206a654dd37dabf2766ffab3e883
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants