14 lines
584 B
Markdown
14 lines
584 B
Markdown
# Browser security boundary
|
|
|
|
The browser bundle is public. Secrets, token lifecycle, raw HTML injection,
|
|
dynamic code execution, untrusted script URLs, and public production source
|
|
maps are prohibited defaults.
|
|
|
|
`config/hosting/security-headers.json` is the declared header set. Hosting
|
|
verification compares that declaration with live responses. CSP deliberately
|
|
omits `unsafe-inline` and `unsafe-eval`; production code and built assets must
|
|
remain compatible with that baseline.
|
|
|
|
Route guards are UX hints and client validation does not replace backend
|
|
authorization or validation.
|