Target names, URLs and log lines reach the page as text (closes #29) #105

Merged
clawbot merged 1 commits from issue-29-escape-target-text into next 2026-10-04 05:35:37 +02:00
1 Commits
Author SHA1 Message Date
clawbot 4091a3b41a Target names, URLs and log lines reach the page as text (closes #29)
check / check (push) Successful in 3m13s
A host row escapes the name and URL it writes into its markup with a new
escapeHTML function, and the debug log builds each line as an element
whose text is set, so neither is read as HTML once targets can be
configured. A unit test builds the row of a target whose name and URL
hold < > " & and ' and checks each comes out escaped; hostRowHTML is
exported for it.

README.md stops calling CONFIG frozen: the interval menu sets
updateInterval, and the timeouts, history span and axis ticks are
computed from it. AppState declares _recoveryProbeId and
_recoveryProbeChecks, the sparkline axis functions drop the parameters
they never used, and HostState's history comment names both entry
shapes.

Model: opus-5-5
2026-10-04 03:29:27 +00:00