1/* 2 * Neutralizing service worker. 3 * 4 * The site used to ship a caching PWA service worker here (scope '/', network-first 5 * HTML caching). It was retired by removing its registration, but a deleted or blocked 6 * file does NOT remove a service worker: browsers that registered it keep it installed 7 * and active. Once security was tightened (rejectIfNoRule), /sw.js began returning a 8 * login redirect / 403, so those browsers' periodic update checks failed and the old 9 * worker could never be replaced. Its network-first fetch handler kept serving stale 10 * pages and cached login redirects, driving redirect loops. 11 * 12 * This replacement is a deliberate no-op: it has NO fetch handler, so every request 13 * goes straight to the network. On activation it takes control immediately and wipes 14 * the caches the old worker created. main.gsp calls navigator.serviceWorker 15 * .register('/sw.js') on load, which forces affected browsers to fetch this file and 16 * swap out the old worker on their very next visit (active healing). Clean browsers 17 * simply end up with this harmless passthrough worker. 18 * 19 * Do not add caching or a fetch handler here. If the PWA is ever revived, do it under 20 * a new, versioned worker file. 21 */ 22self.addEventListener('install', () => { 23 // Replace the retired worker right away instead of waiting for every tab to close. 24 self.skipWaiting(); 25}); 26 27self.addEventListener('activate', (event) => { 28 event.waitUntil((async () => { 29 // Drop every Cache Storage bucket the old worker filled (stale HTML, cached 30 // login pages, fingerprinted assets). Safe: this worker reads none of them. 31 try { 32 const keys = await caches.keys(); 33 await Promise.all(keys.map((k) => caches.delete(k))); 34 } catch (e) { 35 // Best effort; nothing to do if the Cache API is unavailable. 36 } 37 // Take control of already-open tabs so their next navigation is un-intercepted. 38 await self.clients.claim(); 39 })()); 40}); 41 42// No 'fetch' listener on purpose -> the browser handles all requests directly.
Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.