rdmbair15m5-changelog-20260830-1355-mermaid-execution-and-csp-exemption
rdmbair15m5-changelog-20260830-1355-mermaid-execution-and-csp-exemption
Exempted Mermaid chart execution across
dev.ecs0.net/issues/ and enabled explicit DOM runtime chart
rendering.
Summary
Updated Content-Security-Policy on Nginx gateway and refreshed the
HTML lifecycle templates to fully exempt and permit Mermaid chart
execution (unsafe-eval, unsafe-inline,
blob:, worker-src, child-src,
data:). Added automated renderMermaidCharts()
execution handlers to trigger rendering immediately upon page load.
Scope
- Host / Infrastructure:
rdmsm4x(Gateway Docker serviceecs0-dev-gateway-1& Wiki serviceecs0-dev-wiki-1) andrdmbair15m5. - Files Modified:
/Users/richh/dev/sites/dev.ecs0.net/infra/nginx/gateway.conf/Users/richh/dev/issues/bin/ticket/Users/richh/dev/sites/dev.ecs0.net/issues/index.html/Users/richh/dev/sites/dev.ecs0.net/wiki/index.html- All 341 rendered issue HTML files
Exact Changes
CSP Exemption (
gateway.conf):- Configured
script-srcto permit'self' 'unsafe-inline' 'unsafe-eval' https: data: blob:. - Configured
worker-srcandchild-srcto permit'self' blob: data:. - Permitted
'unsafe-inline' https: data: blob:for styles, images, and fonts.
- Configured
Explicit Mermaid Execution Handler:
- Added asynchronous
renderMermaidCharts()hook toHTML_DASHBOARD_TEMPLATEandHTML_TICKET_TEMPLATEinticketCLI. - Configured Mermaid initialization with
securityLevel: 'loose',startOnLoad: false, and explicitmermaid.run({ querySelector: '.mermaid' })withmermaid.initfallback.
- Added asynchronous
Re-Export & Origin Deployment:
- Ran
ticket reindexandticket export-html. - Re-synced files to
rdmsm4x:~/dev/sites/dev.ecs0.net/and restarted Docker gateway/wiki containers.
- Ran
Verification Evidence
- HTTP 200 response with updated CSP headers verified on
http://127.0.0.1:8788/issues/. - Local and CDN Mermaid assets loaded with active
renderMermaidCharts()trigger.
Outstanding Owner Actions
- None.