HTML injection and CSP
STATIC’s page-visible changes need code to run inside a browser document. The proxy inserts a reference to its locally served /__static/runtime.js asset and a profile configuration on eligible HTML responses. The injected script runs in the browser; the Rust proxy runs outside it.
Eligibility and insertion
An origin response must be successful and have a text/html content type. The body must be nonempty, decode as UTF-8, and not already contain known STATIC bootstrap markers. The injector supports gzip, deflate, Brotli, and Zstandard encodings subject to a configured decompressed-size limit; unsupported encodings skip injection. HTTP/2 additionally buffers HTML/XHTML candidates before the injector decides whether text/html qualifies.
The injector places a script element before the first existing script when it can, otherwise in or near the document head. Its data-static-config-b64 attribute carries the materialized browser-side profile config. STATIC serves the script asset locally rather than fetching it from the website. An x-static-injected: 1 response header marks a changed response; content length and encoding headers are updated after mutation.
Content Security Policy
An existing script-src or script-src-elem nonce can be reused. If a CSP header exists without one, STATIC generates a nonce and rewrites applicable policy directives after insertion. It also handles CSP meta tags encountered in HTML and can add blob: to worker policy where needed for its worker bootstrap. This changes the page’s security policy; it is not a transparent operation or a guarantee that every site’s policy and script ordering will work.
The order matters: the CSP stage finds or prepares a nonce, the JS stage inserts a script with that nonce, and CSP finalization rewrites the response policy only when injection occurred.
Caching and other responses
For eligible navigations and bootstrap assets, STATIC strips conditional request validators that could cause a 304 response with no body to modify. Script/bootstrap asset responses have validators removed and are marked no-cache. Alt-Svc is handled later so the browser is less likely to switch to an alternative transport that bypasses the intended path.
The HTML stage does not rewrite every page, existing service workers, or arbitrary binary responses. See the injection implementation, CSP stage, and runtime asset handler. Next: what the script does.