|
Some checks failed
Caterium QA / qa (push) Has been cancelled
Inline handlers built as onclick="fn('${esc(id)}')" were injectable:
esc() turns ' into ', which the browser decodes back to ' before
the JS runs, so an id like x');alert(1);// broke out of the string.
Ids can come from a restored backup file or a synced catalog. Add
SunSafe.jsArg (JSON.stringify + HTML escape) and use it in all 23
handlers in app-runtime.js and index.html. Verified in a browser: a
payload id is passed through as a plain string and nothing executes.
Also replace the Settings version label that still showed
v17.6.0 · 2026.09.07, and bump the cache-busting version of the two
changed scripts (sun-safe.js, app-runtime.js).
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
|
||
|---|---|---|
| .github/workflows | ||
| docs | ||
| ops | ||
| public | ||
| supabase | ||
| tests | ||
| .gitattributes | ||
| .gitignore | ||
| deploy-trigger.txt | ||
| GITHUB-CLOUDFLARE-SETUP.txt | ||
| package-lock.json | ||
| package.json | ||
| PUSH-TO-GITHUB.bat | ||
| README.md | ||
| TIMEWEB-APP-PLATFORM.md | ||
| UPDATE-FROM-REMOTE-AND-PUSH.bat | ||
| wrangler.jsonc | ||
Caterium
Caterium catering SaaS frontend with Supabase backend.
Production
Primary production URL: https://app.caterium.ru
Production frontend is hosted on Timeweb Cloud App Platform:
- repository:
pavlov346346-source/caterium-app - branch:
production - publish directory:
public - auto deploy: enabled for
production
main is the integration branch. GitHub Actions runs the full Caterium QA workflow for each push to main. Only a successful QA run may promote the verified commit to production.
The Cloudflare Worker ancient-sound-04ab is retained only as a fallback. It is not the primary production target and must not replace the Timeweb deployment unless an intentional fallback procedure is being used.
Deploy checks
npm ci
npm audit --audit-level=high
npm run check:deploy
npm run test:e2e
The QA workflow performs these checks automatically. High/critical npm audit findings block promotion.
Cloudflare fallback
Use Cloudflare only as a backup deployment target. Manual fallback deployment is available as:
npm run deploy:cloudflare-backup
When configuring Git-based Cloudflare fallback deployment, use the verified production branch rather than main so the fallback receives the same QA-approved commit as Timeweb.
Backend
Supabase Edge Functions are versioned under supabase/functions/.
SQL migration/history files live under ops/sql/.
Database DDL changes should be applied as migrations and kept in repository history.
See TIMEWEB-APP-PLATFORM.md for the production hosting checklist.