fix(security): harden public CV edges
This commit is contained in:
@@ -33,6 +33,8 @@ operator/external dependencies belong in `BLOCKERS.md`.
|
||||
the full npm high-severity audit to a blocking CI gate.
|
||||
- Corrected Chromium PDF export argument handling, bounded hung exports, and verified the returned
|
||||
public artifact is a real PDF in the browser smoke suite.
|
||||
- Sandboxed authenticated CV preview iframes without enabling scripts, isolated public-PDF request
|
||||
budgets by client and slug, and removed/ignored the tracked expired acceptance JWT artifact.
|
||||
- Removed unfinished Portfolio/Notes workspace navigation promises; existing project, attachment,
|
||||
and application-note surfaces remain authoritative, and stale section links fall back to Overview.
|
||||
|
||||
|
||||
Reference in New Issue
Block a user