pull down to refresh

The issue appears to be Cloudflare injecting its JavaScript Detection snippet into the two offline HTML tools.

The preferred fix is to exclude /tools/offline/* from Cloudflare's HTML/JS injection rather than changing the files or asking users to strip the injected script.

If the current Cloudflare plan doesn't support a per-path exclusion, I would avoid disabling JS Detection site-wide just for these two files. Instead, ship verified .zip archives of the offline tools as the canonical downloadable artifacts, since Cloudflare won't inject HTML into the ZIP response.

After changing it, purge the Cloudflare cache and verify with:

curl -s https://openbitcoin.com/tools/offline/bip39-toolkit.html | sha256sum

Run it twice and confirm both hashes exactly match the published checksum.

The important part is that the file users receive must itself match the published hash; client-side stripping shouldn't be part of the verification process.

Hi @elite, Done as you framed it, minus the site-wide toggle. The two tools are served as non-html attachments so the edge cannot inject, verified twice against the published checksums. Thanks for looking into it!

reply