Add CookieYes for GDPR/CCPA compliance (#759)
* feat: add CookieYes for GDPR/CCPA compliance * refactor how cookieYes script is loaded
This commit is contained in:
@@ -1,6 +1,9 @@
|
||||
<!DOCTYPE html>
|
||||
<html lang="en" data-theme="system">
|
||||
<head>
|
||||
<!-- CookieYes banner -->
|
||||
<%- cookieYesScript %>
|
||||
<!-- End of CookieYes banner -->
|
||||
<meta charset="utf-8" />
|
||||
<link rel="icon" type="image/svg+xml" href="/icon.svg" />
|
||||
<link rel="icon" href="/favicon.ico" />
|
||||
|
||||
@@ -11,7 +11,6 @@
|
||||
"bugs": {
|
||||
"url": "https://github.com/meshtastic/web/issues"
|
||||
},
|
||||
|
||||
"homepage": "https://meshtastic.org",
|
||||
"scripts": {
|
||||
"build": "vite build",
|
||||
@@ -48,8 +47,8 @@
|
||||
"@radix-ui/react-tabs": "^1.1.12",
|
||||
"@radix-ui/react-toast": "^1.2.14",
|
||||
"@radix-ui/react-toggle-group": "^1.1.10",
|
||||
"@radix-ui/react-visually-hidden": "^1.2.3",
|
||||
"@radix-ui/react-tooltip": "^1.2.7",
|
||||
"@radix-ui/react-visually-hidden": "^1.2.3",
|
||||
"@tailwindcss/vite": "^4.1.11",
|
||||
"@tanstack/react-router": "^1.127.9",
|
||||
"@tanstack/react-router-devtools": "^1.127.9",
|
||||
@@ -79,6 +78,8 @@
|
||||
"react-map-gl": "8.0.4",
|
||||
"react-qrcode-logo": "^3.0.0",
|
||||
"rfc4648": "^1.5.4",
|
||||
"vite-plugin-html": "^3.2.2",
|
||||
"vite": "^7.0.4",
|
||||
"zod": "^4.0.5",
|
||||
"zustand": "5.0.6"
|
||||
},
|
||||
@@ -105,7 +106,6 @@
|
||||
"tar": "^7.4.3",
|
||||
"testing-library": "^0.0.2",
|
||||
"typescript": "^5.8.3",
|
||||
"vite": "^7.0.4",
|
||||
"vitest": "^3.2.4"
|
||||
}
|
||||
}
|
||||
|
||||
@@ -22,7 +22,7 @@
|
||||
"@layouts/*": ["./src/layouts/*"]
|
||||
}
|
||||
},
|
||||
"include": ["src", "./vite-env.d.ts"],
|
||||
"include": ["src", ".d.ts"],
|
||||
"exclude": [
|
||||
"routeTree.gen.ts",
|
||||
"node_modules",
|
||||
|
||||
@@ -10,13 +10,25 @@
|
||||
{
|
||||
"source": "/",
|
||||
"headers": [
|
||||
{
|
||||
"key": "Cross-Origin-Embedder-Policy",
|
||||
"value": "require-corp"
|
||||
},
|
||||
{
|
||||
"key": "Cross-Origin-Opener-Policy",
|
||||
"value": "same-origin"
|
||||
},
|
||||
{
|
||||
"key": "Cross-Origin-Embedder-Policy",
|
||||
"value": "credentialless"
|
||||
},
|
||||
{
|
||||
"key": "X-Content-Type-Options",
|
||||
"value": "nosniff"
|
||||
},
|
||||
{
|
||||
"key": "Strict-Transport-Security",
|
||||
"value": "max-age=63072000; includeSubDomains; preload"
|
||||
},
|
||||
{
|
||||
"key": "Referrer-Policy",
|
||||
"value": "strict-origin-when-cross-origin"
|
||||
}
|
||||
]
|
||||
}
|
||||
|
||||
Vendored
+6
-4
@@ -1,10 +1,12 @@
|
||||
/// <reference types="vite/client" />
|
||||
|
||||
interface ViteTypeOptions {
|
||||
strictImportMetaEnv: unknown;
|
||||
}
|
||||
|
||||
interface ImportMetaEnv {
|
||||
readonly env: {
|
||||
readonly VITE_COMMIT_HASH: string;
|
||||
readonly VITE_VERSION: string;
|
||||
};
|
||||
readonly VITE_COMMIT_HASH: string;
|
||||
readonly VITE_VERSION: string;
|
||||
}
|
||||
|
||||
interface ImportMeta {
|
||||
|
||||
+64
-44
@@ -3,7 +3,8 @@ import path from "node:path";
|
||||
import process from "node:process";
|
||||
import tailwindcss from "@tailwindcss/vite";
|
||||
import react from "@vitejs/plugin-react";
|
||||
import { defineConfig } from "vite";
|
||||
import { defineConfig, loadEnv } from "vite";
|
||||
import { createHtmlPlugin } from "vite-plugin-html";
|
||||
|
||||
let hash = "";
|
||||
let version = "v0.0.0";
|
||||
@@ -23,50 +24,69 @@ try {
|
||||
}
|
||||
|
||||
const CONTENT_SECURITY_POLICY =
|
||||
"script-src 'self' 'unsafe-inline' https://cdn.jsdelivr.net; style-src 'self' 'unsafe-inline' data: https://rsms.me https://cdn.jsdelivr.net; img-src 'self' data:; font-src 'self' data: https://rsms.me https://cdn.jsdelivr.net; worker-src 'self' blob:; object-src 'none'; base-uri 'self';";
|
||||
"script-src 'self' 'unsafe-inline' https://cdn.jsdelivr.net https://cdn-cookieyes.com; style-src 'self' 'unsafe-inline' data: https://rsms.me https://cdn.jsdelivr.net; img-src 'self' data:; font-src 'self' data: https://rsms.me https://cdn.jsdelivr.net; worker-src 'self' blob:; object-src 'none'; base-uri 'self';";
|
||||
|
||||
export default defineConfig({
|
||||
plugins: [
|
||||
react(),
|
||||
tailwindcss(),
|
||||
// VitePWA({
|
||||
// registerType: "autoUpdate",
|
||||
// strategies: "generateSW",
|
||||
// devOptions: {
|
||||
// enabled: true,
|
||||
// },
|
||||
// workbox: {
|
||||
// cleanupOutdatedCaches: true,
|
||||
// sourcemap: true,
|
||||
// },
|
||||
// }),
|
||||
],
|
||||
optimizeDeps: {
|
||||
include: ["react/jsx-runtime"],
|
||||
},
|
||||
define: {
|
||||
"import.meta.env.VITE_COMMIT_HASH": JSON.stringify(hash),
|
||||
"import.meta.env.VITE_VERSION": JSON.stringify(version),
|
||||
},
|
||||
build: {
|
||||
emptyOutDir: true,
|
||||
assetsDir: "./",
|
||||
},
|
||||
resolve: {
|
||||
alias: {
|
||||
"@app": path.resolve(process.cwd(), "./src"),
|
||||
"@pages": path.resolve(process.cwd(), "./src/pages"),
|
||||
"@components": path.resolve(process.cwd(), "./src/components"),
|
||||
"@core": path.resolve(process.cwd(), "./src/core"),
|
||||
"@layouts": path.resolve(process.cwd(), "./src/layouts"),
|
||||
export default defineConfig(({ mode }) => {
|
||||
const env = loadEnv(mode, process.cwd());
|
||||
|
||||
return {
|
||||
plugins: [
|
||||
react(),
|
||||
tailwindcss(),
|
||||
// This is for GDPR/CCPA compliance
|
||||
createHtmlPlugin({
|
||||
inject: {
|
||||
data: {
|
||||
cookieYesScript:
|
||||
mode === "production" && env.VITE_COOKIEYES_CLIENT_ID
|
||||
? `<script async src="https://cdn-cookieyes.com/client_data/${env.VITE_COOKIEYES_CLIENT_ID}/script.js"></script>`
|
||||
: "",
|
||||
},
|
||||
},
|
||||
}),
|
||||
// VitePWA({
|
||||
// registerType: "autoUpdate",
|
||||
// strategies: "generateSW",
|
||||
// devOptions: {
|
||||
// enabled: true,
|
||||
// },
|
||||
// workbox: {
|
||||
// cleanupOutdatedCaches: true,
|
||||
// sourcemap: true,
|
||||
// },
|
||||
// }),
|
||||
],
|
||||
optimizeDeps: {
|
||||
include: ["react/jsx-runtime"],
|
||||
},
|
||||
},
|
||||
server: {
|
||||
port: 3000,
|
||||
headers: {
|
||||
"content-security-policy": CONTENT_SECURITY_POLICY,
|
||||
"Cross-Origin-Opener-Policy": "same-origin",
|
||||
"Cross-Origin-Embedder-Policy": "require-corp",
|
||||
define: {
|
||||
"import.meta.env.VITE_COMMIT_HASH": JSON.stringify(hash),
|
||||
"import.meta.env.VITE_VERSION": JSON.stringify(version),
|
||||
},
|
||||
},
|
||||
build: {
|
||||
emptyOutDir: true,
|
||||
assetsDir: "./",
|
||||
},
|
||||
resolve: {
|
||||
alias: {
|
||||
"@app": path.resolve(process.cwd(), "./src"),
|
||||
"@pages": path.resolve(process.cwd(), "./src/pages"),
|
||||
"@components": path.resolve(process.cwd(), "./src/components"),
|
||||
"@core": path.resolve(process.cwd(), "./src/core"),
|
||||
"@layouts": path.resolve(process.cwd(), "./src/layouts"),
|
||||
},
|
||||
},
|
||||
server: {
|
||||
port: 3000,
|
||||
headers: {
|
||||
"content-security-policy": CONTENT_SECURITY_POLICY,
|
||||
"Cross-Origin-Opener-Policy": "same-origin",
|
||||
"Cross-Origin-Embedder-Policy": "credentialless",
|
||||
"X-Content-Type-Options": "nosniff",
|
||||
"Strict-Transport-Security":
|
||||
"max-age=63072000; includeSubDomains; preload",
|
||||
"Referrer-Policy": "strict-origin-when-cross-origin",
|
||||
},
|
||||
},
|
||||
};
|
||||
});
|
||||
|
||||
Reference in New Issue
Block a user