aboutsummaryrefslogtreecommitdiffstats
path: root/AGENTS.md
diff options
context:
space:
mode:
Diffstat (limited to 'AGENTS.md')
-rw-r--r--AGENTS.md6
1 files changed, 5 insertions, 1 deletions
diff --git a/AGENTS.md b/AGENTS.md
index 5ffd8ba..5aec663 100644
--- a/AGENTS.md
+++ b/AGENTS.md
@@ -154,7 +154,11 @@ internal/web/ server.go (host router, middleware, render helpers)
as well as to `reservedPageSlugs`) also get `X-Frame-Options: DENY` and
a CSP of `frame-ancestors`/`base-uri`/`form-action`/`object-src` only —
no `script-src`, the dashboard's inline scripts are a product
- constraint. Public blog pages carry no framing rule (owner content). Flood
+ constraint. Public blog pages carry no framing rule (owner content).
+ Audited and left as is (2026-09): SQL is all parameterised (`likeEscape`
+ for ILIKE, `pgx.Identifier` for database names); templates are
+ `html/template` and the only `{{html}}` sinks are owner-authored content;
+ `/media` never renders a type a browser would script (`filetype.go`). Flood
control for everything else stays at the reverse proxy (`limit_req`).
- **Templates**: each page file is parsed together with its layout
(`layouts/dashboard.html` or `layouts/blog.html` for `blog/*`) and all