asepharyana 05a3bc7471
CI / go test + web typecheck (push) Canceled after 0s
CI / build + deploy (Nix) — flowsight (push) Canceled after 0s
fix: audit round 4 — XSS in HTML report export, SSRF webhook guard, body limit
- ToHTML() now html.EscapeString on ticker, generated_at, section name/body, citations (stored/LLM content can't inject script into exported file)
- Discord destination webhook_url restricted to discord.com/discordapp.com hosts (SSRF guard: server POSTs alert cards; no private IPs or arbitrary hosts)
- Router middleware caps POST/PUT/PATCH bodies at 1 MiB (MaxBytesReader)
- TestDestinations updated: non-discord host must 422, uses realistic discord.com webhook URL
2026-09-16 14:43:56 +07:00
2026-09-16 01:27:43 +07:00

docs index

Spec-driven source of truth. Code follows these docs; docs change before code.

Doc Contents
PLAN.md Concept: Autopilot Routines, Verifiable AI, Accuracy Ledger; agents, features, architecture, data model, routes, pages, rules, timeline, verification, risks
API-REFERENCE.md All 70 Sectors v2 paths with params, costs, FlowSight usage, per-cycle credit budget
TECH-STACK.md Pinned versions, deps, why-chosen, declined alternatives, CI gates
ARCHITECTURE.md Backend/frontend layout, scheduler, agent contracts, citation pipeline, SSE design
ROUTINES.md 7 routine specs: schedule, inputs, detection logic, delivery format
AGENT-SPECS.md 7 agent contracts: inputs, processing steps, outputs, verification fixtures
DATA-MODEL.md Table schemas, indexes, retention, seed strategy
API.md Backend route specs: request/response shapes, errors, auth
DEMO-DECK.md Offline demo narrative: briefing → radar → report → interrogation
S
Description
No description provided
Readme
9.1 MiB
Languages
Go 73%
TypeScript 25.6%
Nix 0.6%
CSS 0.4%
Shell 0.3%