docs(10.1): record D-18/D-19, resolve research questions, add pattern map
Plan checker iteration 1 flagged unresolved research questions and a missing decision note for golang.org/x/net/html. D-18 approves x/net/html for the partial sanitizer; D-19 fixes the Discogs widget fill to [year, format]. STATE marks the phase ready to execute.
This commit is contained in:
@@ -48,6 +48,10 @@ Not in scope: the real Discogs HTTP client and jobs (Phase 14); WASM (FW-06 / v2
|
||||
### Hygiene constraint (partial HTML in the SPA)
|
||||
- **D-17:** Phase 10 forbids unsanitized `v-html` / `innerHTML` (T-10-16, `--hygiene`). Partial HTML still has to appear in the list/form. Researcher/planner must pick a host that does not reopen that threat (dedicated sanitized slot, iframe under the admin prefix, or equivalent). Record data must not become executable HTML.
|
||||
|
||||
### Resolved at planning (2026-09-28)
|
||||
- **D-18:** `golang.org/x/net/html` becomes a direct dependency of the framework, used only by the cabana partial sanitizer (`html.ParseFragment` + tag/attribute allowlist). It is already in `go.sum` as an indirect dependency, so no new module enters the build. This is the decision note CLAUDE.md rule 4 asks for; `encoding/xml` was rejected as too weak on real HTML. — **Reversibility:** reversible
|
||||
- **D-19:** The Albums Discogs widget uses `fill: [year, format]`. A `year` field (`type: number`) is added to the Albums admin form; the model already has `Year *int`. The `format`-only option was rejected. — **Reversibility:** reversible
|
||||
|
||||
### Claude's Discretion
|
||||
- Exact YAML key names (`headerPartial` vs another spelling, widget `path` vs `tag`, action path convention).
|
||||
- JS/CSS capability interface name (must not reuse `pact.AdminAssets`).
|
||||
|
||||
Reference in New Issue
Block a user