Skip to content

fix: update swagger-ui to 5.29.1 and add SRI hashes - #1060

Merged
jmattheis merged 1 commit into
gotify:masterfrom
lbellows:docs-swagger-ui-sri
Sep 30, 2026
Merged

jmattheis merged 1 commit into
gotify:masterfrom
lbellows:docs-swagger-ui-sri

Conversation

@lbellows

Copy link
Copy Markdown
Contributor

Fixes #1053 (the SRI and version part; keeps the CDN as discussed there).

  • Bumps swagger-ui on /docs from 4.15.5 to 5.29.1, the newest release on cdnjs. npm has 5.33.0, but cdnjs has not published it yet.
  • Adds integrity (sha512), crossorigin="anonymous" and referrerpolicy="no-referrer" to the stylesheet and both scripts. cdnjs sends Access-Control-Allow-Origin: *, so the CORS-mode fetch SRI needs works.
  • Adds a test that fails if an external <script>/<link> in the page has no hash, so a later version bump can't drop it without anyone noticing.

The hashes match three sources: the cdnjs API, a local sha512 of the served files, and the swagger-ui-dist@5.29.1 npm tarball (byte-identical).

Regression check. I ran master and this branch side by side and loaded /docs in headless Chromium:

master (4.15.5) this PR (5.29.1)
operations rendered 42 42
tags application, message, auth, oidc, client, user, info, plugin same
security schemes in Authorize dialog 7 same 7
Basic auth → Try it out → GET /current/user 200, admin user 200, admin user
host from swagger?base= correct correct
console errors none (favicon 404s only, pre-existing) same
390px mobile viewport no horizontal scroll same

The Swagger 2.0 spec renders unchanged. 5.x only adds an "OAS 2.0" badge next to the version.

@codecov

codecov Bot commented Sep 30, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 76.09%. Comparing base (d02796b) to head (8492a2c).

Additional details and impacted files
@@           Coverage Diff           @@
##           master    #1060   +/-   ##
=======================================
  Coverage   76.09%   76.09%           
=======================================
  Files          67       67           
  Lines        3619     3619           
=======================================
  Hits         2754     2754           
  Misses        654      654           
  Partials      211      211           

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@jmattheis jmattheis left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks

@jmattheis
jmattheis added this pull request to the merge queue Sep 30, 2026
Merged via the queue into gotify:master with commit f77d8a0 Sep 30, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

/docs loads swagger-ui 4.15.5 from cdnjs without SRI

2 participants