Skip to content

docs: document CSP-safe styling convention for frontend - #1671

Merged
hman38705 merged 1 commit into
solutions-plug:mainfrom
brite-side0:drips/1670
Sep 30, 2026
Merged

hman38705 merged 1 commit into
solutions-plug:mainfrom
brite-side0:drips/1670

Conversation

@brite-side0

Copy link
Copy Markdown
Contributor

Summary

docs: document CSP-safe styling convention for frontend

What was solved

#1670 — docs(frontend): document CSP-safe styling conventions (no inline styles)

Document the CSP-safe styling convention for the frontend: explain that inline style props are stripped by the Content-Security-Policy (per commits 5bd5e51 and e80a15b), mandate CSS classes/CSS modules instead, note the current lack of automated enforcement and whether an ESLint rule (e.g. react/forbid-dom-props for style) should back it up, and add a short pointer from CONTRIBUTING.md to the rule.

Addressed:

  • Changed: frontend/README.md, frontend/docs/styling.md, CONTRIBUTING.md
  • Document the convention in frontend/README.md (per docs(frontend): add frontend/README.md for local dev onboarding #1668) or a dedicated frontend/docs/styling.md
  • Explain WHY (CSP strips/blocks inline styles) so the rule isn't silently reverted
  • State the required pattern: use CSS classes / CSS modules instead of style={{...}} props for anything affecting rendering

Changes

  • CONTRIBUTING.md (modify)
  • frontend/README.md (create)
  • frontend/docs/styling.md (create)

Approach

  1. Read frontend/README.md (or create frontend/docs/styling.md if README is absent) and CONTRIBUTING.md to match existing heading/link conventions.
  2. Add a 'Styling' section documenting the CSP-safe convention: explain that inline style props are stripped by the Content-Security-Policy (refs 5bd5e51, e80a15b), so rendering-affecting styles must use CSS classes / CSS modules instead of style={{...}}.
  3. Note the current lack of automated enforcement and recommend an ESLint rule (e.g. react/forbid-dom-props for style) as a future option, without adding tooling or dependencies.
  4. Add a short pointer from CONTRIBUTING.md to the styling rule.
  5. Keep changes documentation-only; do not refactor components or migrate existing inline styles.

Issues

Closes #1670

@hman38705
hman38705 merged commit e54fdd6 into solutions-plug:main Sep 30, 2026
15 of 62 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

docs(frontend): document CSP-safe styling conventions (no inline styles)

2 participants