Mirror the openvidu.io hardening: heading outline, template escaping, Dependabot - #19
Merged
Merged
Conversation
"Understanding the code" stepped from H2 to H4 in seven server tutorials; the endpoint headings are H3 now, matching the Go tutorial and the openvidu.io copies. Heading text is unchanged.
Escape the frontmatter values rendered in the head and the footer's previous/next titles: MkDocs' theme environment does not autoescape. Declare the referrer policy in its meta form, the only one GitHub Pages allows, and record the frame buster's known limit next to the code. The newsletter input gains an accessible name, and the form drops the Mailchimp validation hooks that have no script behind them, so native validation applies.
Only github-actions was covered. The Python pins live inline in the workflow pip install lines, which Dependabot cannot read, so the Dockerfile is the part it can keep current.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Companion to OpenVidu/openvidu.io#127: the part of that work that applies to this repo. Merge together.
## Understanding the codeto H4 endpoint headings; they are H3 now, matching the Go tutorial and the openvidu.io copies. Heading text is unchanged, so anchors survive.page.meta.robotsin the head and the footer's previous/next titles now escape. The referrer policy is declared in its meta form, the only one GitHub Pages allows, and the frame buster's known limit (its<noscript>fallback re-opens the page inside a script-less sandboxed frame) is recorded next to the code.#mc-embedded-subscribeand#mce-EMAIL, both kept.pip installlines, which Dependabot cannot read, so the Dockerfile is the part it can keep current.Checked and not needed here
bundle.d7400e89.publish-webtakes noworkflow_dispatchinputs, and the lychee workflow already passes its exit code throughenv. Nothing to quote.header.htmlortabs.htmloverride, and this repo has no publish tool, so theovwebfixes, the hash-locked install and the Python floor do not apply. Its build hook is a separate, smaller file that imports nothing fromovweb.Verification:
mkdocs build --strictpasses with zero warnings, andtools/sync-check.py --openvidu-io ../openvidu.ioreports 43 tutorial pairs in sync against the openvidu.io branch.Still open, as in the other repo: this repository has no branch ruleset either.
🤖 Generated with Claude Code
Sobre el check
validateen rojoEs esperado y se resuelve solo. El job hace checkout de
OpenVidu/openvidu.iosinref:, es decir su rama por defecto, así que compara estos tutoriales contramain, donde el arreglo de encabezados todavía no está: de ahí las 28 líneas que reporta. Contra la rama del PR emparejado el check pasa (tools/sync-check.py --openvidu-io ../openvidu.io→ 43 pares en sintonía).Orden de integración: primero openvidu.io#127 en
main, y después este PR (o re-lanzar su check), que pasará a verde sin tocar nada.