b176a44627
Active docs/ was stub scaffolding while the real docs sat in docs/_archive/. Restore and correct them, and record the Phase 0 work. - docs/architecture/current.md: verified system map (from archived SYSTEM_OVERVIEW, 9 corrections against code). - docs/research/competitors.md: sourced competitor analysis (from archived PRODUCT_RESEARCH, feature matrix corrected). - docs/decisions/ADR-002-job-application-model.md: the Job/JobApplication split. - docs/application-discovery-report.md, docs/implementation-roadmap.md, docs/phase-0-foundation-report.md, docs/career-workspace-branch-assessment.md. - Remove 10 zero-byte placeholder files that advertised content that never existed. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
56 lines
523 B
Markdown
56 lines
523 B
Markdown
# File Security
|
|
|
|
## Purpose
|
|
|
|
Protect uploaded documents.
|
|
|
|
---
|
|
|
|
# File Types
|
|
|
|
Potential uploads:
|
|
|
|
- PDF.
|
|
- DOCX.
|
|
- Images.
|
|
- Portfolio files.
|
|
|
|
---
|
|
|
|
# Validation
|
|
|
|
Check:
|
|
|
|
- File type.
|
|
- File size.
|
|
- File contents.
|
|
|
|
Never trust extensions.
|
|
|
|
---
|
|
|
|
# Processing
|
|
|
|
Uploaded files may contain:
|
|
|
|
- Malicious content.
|
|
- Embedded scripts.
|
|
- AI prompt injection.
|
|
|
|
Treat as untrusted.
|
|
|
|
---
|
|
|
|
# Storage
|
|
|
|
Requirements:
|
|
|
|
- Secure naming.
|
|
- Access control.
|
|
- User ownership checks.
|
|
|
|
---
|
|
|
|
# PDF Processing
|
|
|
|
Never directly trust extracted text. |