1.4 KiB
1.4 KiB
TASKS
Current
feat/frontend-xss-hardening
Status: in_progress
DoD:
- API-derived data is not inserted into
innerHTMLwithout escaping - shared DOM-safe helpers are introduced for frontend rendering paths that still need markup
- known unsafe rendering paths from
__REVIEW_FRONT.mdare removed or hardened - the current UI behavior remains intact after the hardening pass
- targeted frontend smoke checks cover the touched pages
Next
feat/frontend-shell-unification
Backlog
feat/frontend-xss-hardeningfeat/frontend-login-simplificationfeat/frontend-settings-honesty-passfeat/frontend-command-palette-decisionfeat/frontend-plural-rulesfeat/frontend-template-safety-cleanupfeat/frontend-shell-unificationfeat/frontend-wizard-modularizationfeat/frontend-build-pipelinefeat/frontend-css-state-cleanupfeat/frontend-performance-polishfeat/frontend-observability-and-testabilityfeat/id-display-supportfeat/postgres-pool-configfeat/postgres-registry-modularizationfeat/sqlx-compile-time-verificationfeat/secret-crypto-hkdffeat/typed-timestampsfeat/error-structure-normalizationfeat/correlation-id-propagationfeat/runtime-rate-limiting-and-backpressurefeat/distributed-mcp-session-storefeat/websocket-test-run-polishfeat/live-authenticated-staging-entry