// Self-contained observability dashboard HTML (Phase 8). // A single static HTML string with zero build-time dependencies. The page // reads /metrics (same origin) and queries the MCP /mcp endpoint directly. // All KB-sourced fields are esc() escaped for defense-in-depth (data is // server-trusted, but we never pass unsanitized strings to innerHTML). // XSS note: this dashboard consumes only same-origin server data // (/metrics + MCP results). The esc() calls on slug/title/section/error are // defense-in-depth; no user-supplied free text reaches innerHTML. export const DASHBOARD_HTML = `