/** * The one page the worker renders itself. * * It is inline rather than a static asset because it is the only thing served * without a session — keeping it here means the asset directory can stay * entirely behind the gate, with no "is this file public?" judgement calls. */ function escapeHtml(value: string): string { return value .replace(/&/g, '&') .replace(//g, '>') .replace(/"/g, '"') .replace(/'/g, '''); } export interface LoginPageOptions { /** Path to return to after a successful sign-in. Already validated same-origin. */ next: string; /** Shown above the form when a previous attempt failed. */ error?: string; /** CSP nonce for the inline stylesheet. */ nonce: string; } export function renderLoginPage({ next, error, nonce }: LoginPageOptions): string { const errorBlock = error ? `\n ` : ''; return ` Sign in — codegraph telemetry

codegraph telemetry

This dashboard is private. Enter the shared password to continue.


${errorBlock}

You stay signed in on this browser for a year.

`; }