584 B
584 B
Browser security boundary
The browser bundle is public. Secrets, token lifecycle, raw HTML injection, dynamic code execution, untrusted script URLs, and public production source maps are prohibited defaults.
config/hosting/security-headers.json is the declared header set. Hosting
verification compares that declaration with live responses. CSP deliberately
omits unsafe-inline and unsafe-eval; production code and built assets must
remain compatible with that baseline.
Route guards are UX hints and client validation does not replace backend authorization or validation.