Review a private case page before release. It displays notes, loads a chart on one report route, and emits operational events when a case fails to open. Confirm that private pages cannot be framed by unrelated origins, that cross-site navigation does not disclose full case paths, and that browser capabilities the page does not need are denied. Render notes as text. Review a chart dependency update from a clean lockfile install and inspect browser requests. Finally, make failure telemetry useful without storing notes, tokens, session values, or full URLs. The deliverable is a small evidence packet, not a claim that headers alone secure the service.
Project: private page trust review
Build contract
- Capture actual browser policy headers on success, redirect, and error responses for private routes, plus the distinct public widget route.
- Save and reload HTML-looking note text through the full API path; review any raw-markup sink separately.
- Build from a clean dependency install, inspect changed packages and network traffic, and prove telemetry excludes private payloads with retention checks.
Implementation checkpoint
function caseFailureEvent(errorKind, requestId, releaseId) {
const accepted = ["route_failure", "permission_denied", "decode_failure"];
if (!accepted.includes(errorKind)) throw new Error("Unsupported category");
return { event: errorKind, routeClass: "case_detail", requestId, releaseId };
}Cost and boundaries
Policy headers are cheap on the wire; route-by-route testing and partner compatibility cost time. Text rendering is cheaper to maintain than an unnecessary rich-text sanitizer. Clean installs and dependency diffs take engineer attention, but reduce surprises from mutable packages. Narrow telemetry reduces storage and disclosure; if a rare incident needs extra context, add a time-limited diagnostic field with an owner rather than turning on whole-body logging.
Failure drill
Force a 403 response and inspect whether it lost the private route's frame policy. Enter a note that looks like markup, then reload and make sure it remains literal text. Simulate a chart-library update that sends a request to an unknown host and confirm the review catches it. Trigger an account recovery error and search the resulting logs for a test token and private note. If either appears, pause rollout, restrict affected logs, and fix the logging boundary before claiming the page is ready.
Acceptance checks
- Verify policy headers across successful and failed private responses, then test framing behavior.
- Render hostile-looking note input as text after save, reload, and live update.
- Inspect lockfile changes, built network traffic, and optional chart failure behavior.
- Search telemetry for seeded secrets and test the configured deletion period.
Common Mistakes
- Assuming policy headers replace server authorization.
- Treating a database note as safe HTML.
- Calling a lockfile or advisory scan a full dependency review.
- Logging entire failed requests for convenience.
Related lessons
Embedding and Browser Capability Headers; DOM Sinks and Trusted Content; Dependency Integrity and Update Window; Telemetry Minimization and Retention; Untrusted output: escape by context and constrain scripts.
