ui 0.5.1: RichTextEditor without injected TipTap style tag (CSP) - #10
Merged
Merged
Conversation
… in base.css (#9) TipTap appended a <style data-tiptap-style> at runtime, which a CSP with style-src 'self' blocks. Run the editor with injectCSS: false and ship the same ProseMirror base rules (verbatim from @tiptap/core style.ts, 3.31) unlayered in base.css, so Tailwind's purge cannot drop them. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…wind v4 note (#9) Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This was referenced Sep 30, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #9
Problem
RichTextEditorlet TipTap attach a<style data-tiptap-style>with the ProseMirror base rules to<head>at runtime. Under a Content-Security-Policy withstyle-src 'self'(no'unsafe-inline'), which Ausleihbar introduces in virtUOS/ausleihbar#44 and enforces in virtUOS/ausleihbar#45, the browser blocks that. The editor would then lose its base styles, including line wrapping.Change
useEditor({ injectCSS: false, … }).base.cssnow carries the ProseMirror rules. They are byte-for-byte identical to@tiptap/coresrc/style.ts, which is unchanged from 3.27.2 to 3.31.3, so the whole dependency range is covered. The rules are deliberately not in an@layer. TheProseMirror-*classes are only set at runtime by prosemirror-view, so Tailwind's content scan never finds them and would drop layered rules.@basicbar/uiinjects no inline styles or scripts, with a note onprePaintScript()under a strict CSP. The CHANGELOG gets theui 0.5.1entry, and the version is bumped to 0.5.1.Migration: none, as long as the tool imports
@basicbar/ui/base.css, which Ausleihbar and AbstimmBAR both do. AbstimmBAR still uses its own editor, so the new rules are harmless there.Tests
npm run buildpasses.break-spaces, gapcursor,cursor-blink,hideselection.<style>element and reports 0 CSP violations. This was the last remaining violation in Ausleihbar..ProseMirrorcomputes towhite-space: break-spacesandposition: relative, with ligatures off.ProseMirror-selectednodeandProseMirror-hideselection.Release after merge
Tag
ui/v0.5.1.🤖 Generated with Claude Code