procurement-ingest/lambdas/wo
Adam Moussa 78eb8de067 Escape HTML in both web UI dashboards to prevent XSS
Both Function URLs are public (auth_type=NONE) and render
email-derived content via f-strings. Attacker-crafted emails
could inject scripts. Added html.escape() on all interpolated
values in both PO and WO dashboards.
2026-05-12 14:32:01 -04:00
..
email_processor Merge workorder-ingest pipeline into unified repo 2026-05-12 14:12:17 -04:00
web_ui Escape HTML in both web UI dashboards to prevent XSS 2026-05-12 14:32:01 -04:00