Fleet changelogs · dev.ecs0.net
rdmbair15m5-changelog-20260830-1355-mermaid-execution-and-csp-exemption

rdmbair15m5-changelog-20260830-1355-mermaid-execution-and-csp-exemption

Exempted Mermaid chart execution across dev.ecs0.net/issues/ and enabled explicit DOM runtime chart rendering.

Summary

Updated Content-Security-Policy on Nginx gateway and refreshed the HTML lifecycle templates to fully exempt and permit Mermaid chart execution (unsafe-eval, unsafe-inline, blob:, worker-src, child-src, data:). Added automated renderMermaidCharts() execution handlers to trigger rendering immediately upon page load.

Scope

Exact Changes

  1. CSP Exemption (gateway.conf):

    • Configured script-src to permit 'self' 'unsafe-inline' 'unsafe-eval' https: data: blob:.
    • Configured worker-src and child-src to permit 'self' blob: data:.
    • Permitted 'unsafe-inline' https: data: blob: for styles, images, and fonts.
  2. Explicit Mermaid Execution Handler:

    • Added asynchronous renderMermaidCharts() hook to HTML_DASHBOARD_TEMPLATE and HTML_TICKET_TEMPLATE in ticket CLI.
    • Configured Mermaid initialization with securityLevel: 'loose', startOnLoad: false, and explicit mermaid.run({ querySelector: '.mermaid' }) with mermaid.init fallback.
  3. Re-Export & Origin Deployment:

    • Ran ticket reindex and ticket export-html.
    • Re-synced files to rdmsm4x:~/dev/sites/dev.ecs0.net/ and restarted Docker gateway/wiki containers.

Verification Evidence

Outstanding Owner Actions