docs: reorganize tree, restore architecture + research from archive, add Phase 0 reports
Active docs/ was stub scaffolding while the real docs sat in docs/_archive/. Restore and correct them, and record the Phase 0 work. - docs/architecture/current.md: verified system map (from archived SYSTEM_OVERVIEW, 9 corrections against code). - docs/research/competitors.md: sourced competitor analysis (from archived PRODUCT_RESEARCH, feature matrix corrected). - docs/decisions/ADR-002-job-application-model.md: the Job/JobApplication split. - docs/application-discovery-report.md, docs/implementation-roadmap.md, docs/phase-0-foundation-report.md, docs/career-workspace-branch-assessment.md. - Remove 10 zero-byte placeholder files that advertised content that never existed. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
@@ -0,0 +1,48 @@
|
||||
# Input Validation
|
||||
|
||||
## Purpose
|
||||
|
||||
Protect the application.
|
||||
|
||||
---
|
||||
|
||||
# Validate
|
||||
|
||||
All inputs:
|
||||
|
||||
- Forms.
|
||||
- APIs.
|
||||
- Imports.
|
||||
- Files.
|
||||
- AI outputs.
|
||||
|
||||
---
|
||||
|
||||
# Protection Against
|
||||
|
||||
Examples:
|
||||
|
||||
- SQL injection.
|
||||
- XSS.
|
||||
- HTML injection.
|
||||
- Malicious uploads.
|
||||
|
||||
---
|
||||
|
||||
# CV Builder
|
||||
|
||||
Special attention:
|
||||
|
||||
Users can create:
|
||||
|
||||
- Custom sections.
|
||||
- HTML-like content.
|
||||
- Formatting.
|
||||
|
||||
The renderer must sanitise content.
|
||||
|
||||
---
|
||||
|
||||
# Rule
|
||||
|
||||
Never render user content directly without validation.
|
||||
Reference in New Issue
Block a user