Target names, URLs and log lines reach the page as text (closes #29)
check / check (push) Successful in 3m29s

A host row escapes the name and URL it writes into its markup with a new
escapeHTML function, and the debug log builds each line as an element
whose text is set, so neither is read as HTML once targets can be
configured. A unit test builds the row of a target named <b>x</b>;
hostRowHTML is exported for it.

README.md stops calling CONFIG frozen: the interval menu changes
updateInterval. AppState declares _recoveryProbeId and
_recoveryProbeChecks, the sparkline axis functions drop the parameters
they never used, and HostState's history comment names both entry
shapes.

Model: opus-5-5
This commit is contained in:
2026-10-04 02:01:52 +00:00
parent 9b548da90d
commit 87a2305048
4 changed files with 61 additions and 16 deletions
+8
View File
@@ -23,6 +23,14 @@ latest run passes.
# Completed Steps
- 2026-10-04: a target's name and URL and a debug log message show as the
characters they are and are never read as HTML (issue #29): a host row escapes
the name and URL it writes into its markup, and the debug log sets each line
as text. A unit test checks a target named `<b>x</b>`. `README.md` no longer
calls `CONFIG` frozen; the interval menu changes its `updateInterval`.
`AppState` declares the recovery probe's two properties, the sparkline axis
functions lose the parameters they did not use, and the comment on a target's
history names both kinds of entry it holds. Nothing the page does changed
- 2026-10-04: a frontend build on Node 26 or newer, such as `make test` on a
host with Node 26, no longer prints Node's warning that `module.register()` is
deprecated (issue #32); the build in `Dockerfile` runs on Node 22, which never