Lint / Shell (shellcheck) (push) Successful in 21s
Lint / JS (eslint) (push) Successful in 14s
Lint / No secrets in webhook configs (push) Successful in 6s
Lint / Landing page is rendered (matrix (push) Successful in 6s
Lint / Python (ruff) (push) Successful in 7s
Lint / Python deps (pip-audit) (push) Successful in 52s
Lint / Secret scan (gitleaks) (push) Successful in 8s
Lint / Shell (shellcheck) (pull_request) Successful in 17s
Lint / JS (eslint) (pull_request) Successful in 13s
Lint / No secrets in webhook configs (pull_request) Successful in 6s
Lint / Landing page is rendered (matrix (pull_request) Successful in 6s
Lint / Python (ruff) (pull_request) Successful in 8s
Lint / Python deps (pip-audit) (pull_request) Successful in 53s
Lint / Secret scan (gitleaks) (pull_request) Successful in 8s
- cinny/nginx.conf: a call.chat.lotusguild.org server block that serves ONLY /public/element-call/ (the same files chat.lotusguild.org already serves there) and 404s everything else, including source maps and dotfiles. - cinny/nginx-security-headers-call.conf (new snippet): frame-ancestors https://chat.lotusguild.org instead of X-Frame-Options SAMEORIGIN, which would block the now cross-origin parent. - cinny/nginx-security-headers.conf: the app's Permissions-Policy delegates autoplay/camera/display-capture/microphone to the call origin (without it the cross-origin frame's getUserMedia is refused). Outer quotes switched to single: the inner "origin" quotes broke nginx parsing. Nothing changes for users until config.json sets elementCallUrl (separate step). Snippets are installed by hand on LXC 106; nginx.conf deploys on merge. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01PPmy3tPq869XDW4njjVaKA