Skip to main content

Review

Deterministic escaping pass

Adds emission-time escaping and the injection fixture suite.

Files changed
12
Additions
418
Deletions
96
Review cards
4

Changed files

Changed files
PathStatusAdditionsDeletions
src/escape.tsadded+88−0
src/emit.tsmodified+140−61
tests/security/injection.test.tsadded+190−0
docs/adr/0001-page-spec-compiler-boundary.mdmodified+0−35

Escaping strategy

Before

  • Escape applied while parsing
  • Context assumed safe after validation
  • Attribute values escaped once

After

  • Escape applied at emission per context
  • URL schemes allowlisted per action
  • Embedded JSON serialized for script context

Risk assessment

Risk by impact and likelihood
AreaImpactLikelihoodNote
Escaping regressionhighlowCovered by the injection fixture suite.
Output byte driftmediummediumExpected once; snapshots update in the same commit.
PerformancelowlowEscaping is linear in output size.

Review cards

  • good

    Emission-time escaping

    Context is explicit at the call site, which removes a whole class of ordering bugs.

  • concern

    Snapshot churn

    Every escaping change rewrites snapshots; keep the diff reviewable per block type.

  • question

    URL policy source

    Confirm the allowlist lives in one module and is reused by actions and widgets.