Problem
The web app has no Content Security Policy headers.
It is vulnerable to XSS and clickjacking.
What To Build
- Add security headers via vercel.json (CSP, XFO, etc)
- Sanitize all user-generated content with DOMPurify
- HTTPS enforcement
- Audit localStorage usage
- Subresource Integrity for CDN assets
Files To Touch
- vercel.json
- src/services/api.ts
- Any components rendering user content
Acceptance Criteria
Mandatory Checks Before PR
Problem
The web app has no Content Security Policy headers.
It is vulnerable to XSS and clickjacking.
What To Build
Files To Touch
Acceptance Criteria
Mandatory Checks Before PR