ce76046a29
- consolidate API ownership and remove dead vendor code - add Stripe billing, learning paths, and public CV hardening - add migration, recovery, security, audit, and browser gates
9 lines
519 B
Markdown
9 lines
519 B
Markdown
# validation
|
|
|
|
Validation happens at trust boundaries: controller request DTOs, file uploads, imported URLs, OAuth
|
|
state callbacks, AI sidecar authentication, and deployment configuration. Job import and IMAP targets
|
|
resolve through SSRF guards that reject private, loopback, link-local, and unsafe redirect targets.
|
|
|
|
Unhandled failures use Problem Details with a trace ID; expected validation failures retain their
|
|
specific 4xx responses. See `docs/security/input-validation.md` and `docs/security/api-security.md`.
|