[dashboard-language] Security, privacy, accessibility: secret redaction validator slice

Daily Dashboard Language Renderer · pull request · closed

Filter2mode:review mode:live
All recorded Export JSON
github-actions[bot]

published Aug 29, 2026, 4:59 PM · updated Aug 29, 2026, 5:18 PM

Milestone

Security, privacy, accessibility

What shipped

  • Added a narrow validator increment for DLS-SAFE-005 and DLS-VAL-004 in pages/dashboard/src/validator.js.
  • data.source-metadata now conservatively rejects credential-like and PEM-like secret material in provenance metadata fields.
  • Error messages remain generic and path-specific, so rejected secret values are not echoed back in validation output.
  • Added unit coverage in pages/dashboard/test/unit/validator.test.js for rejected secret-bearing metadata and non-echoing error messages.
  • Updated pages/dashboard/PLAN.md with the completed slice and run log.

Specification coverage

  • Section 13: DLS-SAFE-005
  • Section 12: DLS-VAL-004

Quality gates

  • npm install
  • npm run typecheck
  • npm run lint
  • npm test
  • npm run test:e2e

Blockers

  • None in this increment.

Next milestone

Security, privacy, accessibility — next slice for DLS-SAFE-006 consuming-context authorization boundaries or additional screen-reader behavior.

Generated by 🧩 Daily Dashboard Language Renderer · pi · gpt54 · 34.5 AIC · ⌖ 9.11 AIC · ⊞ 5.8K ·