#!/usr/bin/env bash # Assemble dist/ — the CSP-clean static build served at learn.bztmon.com. # # The artifact build inlines GSAP and the app JS because the artifact CSP blocks every # external request. nginx has no such constraint, so here they stay SEPARATE files: # `script-src 'self'` holds with no 'unsafe-inline' exception, and the two GSAP bundles # (116KB, unchanged between deploys) become independently cacheable. set -euo pipefail IFS=$'\n\t' trap 'printf "build failed at line %s\n" "$LINENO" >&2' ERR here="$(cd -- "$(dirname -- "${BASH_SOURCE[0]}")" && pwd)" cd -- "$here" dist="$here/dist" src_markup="ec2-part1.html" src_app="ec2-part2.html" for f in "$src_markup" "$src_app" gsap.min.js st.min.js; do [[ -f "$f" ]] || { printf 'missing source: %s\n' "$f" >&2; exit 1; } done rm -rf -- "$dist" mkdir -p -- "$dist" # --- app.js: strip the single block; served standalone it must be raw JS. sed -e '1{/^[[:space:]]* HTML } > "$dist/index.html" # No inline JS may survive into the served HTML, or the CSP silently kills the page. # Every