GODSIGH/js/layers
jing 0162ec0cdf pre-deploy: escape external feed strings in InfoBox HTML (ship-check)
Defense-in-depth for the public deploy: USGS/EONET place/title/category are now
HTML-escaped before interpolation into Cesium InfoBox descriptions, and the
USGS/EONET links are passed through lib.safeUrl (http(s)-only) so a hostile feed
can't inject markup or a javascript:/data: href. Entity names/labels stay raw
(Cesium renders those as text). Verified: escapeHtml neutralizes
<img onerror>, safeUrl drops javascript:/data:, 219 quakes + 500 fires still
render normally.

ship-check pass: no auth surface (dev-only history/snap not deployed); no
secrets in tree (AIS key empty, data/ gitignored); proxy upstreams are a fixed
dict (no SSRF); no money paths.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-13 20:55:42 +10:00
..
aircraft.js wave2: adversarial-review fixes (9 confirmed findings) 2026-07-13 17:16:24 +10:00
events.js phase 6: interaction polish + readability fixes 2026-07-13 12:32:04 +10:00
fires.js pre-deploy: escape external feed strings in InfoBox HTML (ship-check) 2026-07-13 20:55:42 +10:00
infra.js phases 2-5: satellite, aircraft, ship, infra & event layers 2026-07-13 12:25:51 +10:00
quakes.js pre-deploy: escape external feed strings in InfoBox HTML (ship-check) 2026-07-13 20:55:42 +10:00
satellites.js wave2: adversarial-review fixes (9 confirmed findings) 2026-07-13 17:16:24 +10:00
ships.js phase 7-8: adversarial-review fixes + README 2026-07-13 12:47:11 +10:00