HashPort does not verify every type of web resource in exactly the same way
The resources that directly affect how a page executes need to be inside the strict verification boundary
This includes HTML JavaScript Workers
Service Workers WASM
Images fonts videos and JSON are not required to be treated as executable resources
One of the strictest rules is Same Origin
If a page loads executable JavaScript from another Origin, the verifier cannot continue treating the entire page as a fully verifiable frontend
Because you cannot verify your own HTML while ignoring the external code that actually executes
This is a deeper requirement for onchain frontends
Putting a few website files on chain is not the end of the process
The important question is which resources actually determine what the user sees and which resources actually determine what the user signs
Only when those execution boundaries can be verified does frontend verification become meaningful