feat(themes): free-form community themes with a security floor (#1015)

* feat(themes): free-form community themes with a security floor

Community themes are no longer token-only. The in-app guard
(validateThemeCss) now enforces only a security floor — no network
(@import / non-data url()), no scripts (<style>/<script>/expression()/
javascript:/-moz-binding), no @property, @keyframes namespaced as <id>-,
and a 256 KB cap — and otherwise allows any selectors, structure and
animations. validateThemePackage checks the manifest plus that floor.

Themes can react to app state via same-element attributes set on the theme
root: data-playing, data-fullscreen, data-sidebar-collapsed, data-lyrics-open.

The local-import confirm dialog now notes that imported themes aren't
reviewed and are installed at the user's own risk. Removes the now-unused
bundled token whitelist.

* docs(themes): note free-form themes in the Theme Store entry

Add PR #1015 and a free-form bullet to the still-unreleased Theme Store
changelog and credits entry.
This commit is contained in:
Psychotoxical
2026-06-07 14:04:38 +02:00
committed by GitHub
parent aad1a6c3f0
commit 23f032b274
19 changed files with 170 additions and 335 deletions
@@ -132,7 +132,7 @@ export function ThemeImportSection() {
<ConfirmModal
open={pending !== null}
title={t('settings.themeImportConfirmTitle')}
message={pending ? t('settings.themeImportConfirmBody', { name: pending.name, author: pending.author }) : ''}
message={pending ? `${t('settings.themeImportConfirmBody', { name: pending.name, author: pending.author })} ${t('settings.themeImportConfirmRisk')}` : ''}
confirmLabel={t('settings.themeStoreInstall')}
cancelLabel={t('common.cancel')}
onConfirm={confirmInstall}