- Drive all approved tasks to completion with VERDICT.md - Fix state machine: IMPLEMENTATION.md was never checked in determine_task_state() - Fix state machine: DOC_REVIEW.md priority wrong (checked after BUG_REPORT) - Fix board display: approved planning tasks now advance to Design group - Fix board display: rejected planning tasks move to Blocked group - Fix path traversal: review API validated task names against ../ injection - Fix URL encoding: unquote() task names in API path parsing - Fix comment parsing: robust REVIEW.md read/write, handle falsy comments - Fix dead code: KanbanBoard class missing COLUMNS and __init__ - Fix inotify: explicit error messages and polling fallback - Fix review API: validate task names, prevent path traversal - Update CHANGELOG.md with all changes
413 B
413 B
Adversarial Bug Report: Inline Comment Textarea for Review
Deep Review
Textarea value is read with .value, sent as JSON, and stored directly in REVIEW.md.
Potential Issues
- No input sanitization: Comment text is stored raw. If REVIEW.md is later parsed by markdown renderer, injection possible. Acceptable risk — REVIEW.md is a structured data file, not a rendered document.