Verified defect
Chrome Network records CSP blocks for the existing App Health tracker, newsletter capture and shared AI/feedback footer scripts. The document response policy matches next.config.ts securityHeaders. Local project-strip loads successfully. Newsletter has no shadow root and feedback/extension are absent.
Proposed bounded repair
Add exactly https://sassmaker.com and https://health.sassmaker.com to the existing script-src allowlist in next.config.ts. Preserve all other directives and headers. No credentials, dependencies, provider bindings, or wildcard hosts. These are the first-party producers already referenced by the product HTML.
Release gate
Owner approval required by Fleet production-config boundary. After approval use a clean managed writer; validate policy regression and normal build/CI; release exact main through existing guarded workflow; verify browser document CSP and loaded tracker/capture/feedback, including responsive dialog. Do not submit synthetic feedback or joins. Rollback is removal of the two explicit hosts.
Caveat
Source/header verification alone is insufficient: the first observation used HTTP headers lacking this CSP, whereas fresh Chrome Network exposes the effective response policy and blocked script IDs. Browser runtime is the acceptance source.
Recreated from original issue #83 (repo recreated 2026-10-04 to purge leaked personal data and a secret from git history).
Verified defect
Chrome Network records CSP blocks for the existing App Health tracker, newsletter capture and shared AI/feedback footer scripts. The document response policy matches
next.config.tssecurityHeaders. Local project-strip loads successfully. Newsletter has no shadow root and feedback/extension are absent.Proposed bounded repair
Add exactly
https://sassmaker.comandhttps://health.sassmaker.comto the existing script-src allowlist in next.config.ts. Preserve all other directives and headers. No credentials, dependencies, provider bindings, or wildcard hosts. These are the first-party producers already referenced by the product HTML.Release gate
Owner approval required by Fleet production-config boundary. After approval use a clean managed writer; validate policy regression and normal build/CI; release exact main through existing guarded workflow; verify browser document CSP and loaded tracker/capture/feedback, including responsive dialog. Do not submit synthetic feedback or joins. Rollback is removal of the two explicit hosts.
Caveat
Source/header verification alone is insufficient: the first observation used HTTP headers lacking this CSP, whereas fresh Chrome Network exposes the effective response policy and blocked script IDs. Browser runtime is the acceptance source.
Recreated from original issue #83 (repo recreated 2026-10-04 to purge leaked personal data and a secret from git history).