-
GO-30-CSP W2+W3: migrate all inline on* handlers to delegated dispatch
-
Harden email-body linkifier against href attribute breakout
-
Security: single-source escaping into js/escape.js, cover the compose window; bump ammonia
-
Frontend XSS: seal the unsafe attribute escaper (CHRONIC-XSS)
-
UX/security: encode attacker-controlled values for HTML attributes, guard URL schemes
-
email reader: detect any HTML tag for reader-mode strip, not a tag denylist
-
Security remediation: fix stored XSS in email labels, harden the URL opener
-
fix(ux): centralize natural-date parsing in Rust, fix cache-invalidate order, clamp pagination
-
theme: GoingsOn styles purely intent-specified (no brand aliases)
-
UX audit remediation, error handling, day planning, draft autosave
-
Email features: signatures, drafts, labels, notifications
-
UX audit: 11 usability improvements from audit findings
-
Audit Run 14: tests, security hardening, JSDoc, date_utils extraction
-
Theme import/export, weekly review improvements, mobile UX cleanup
-
Mobile UX improvements, monthly review, maintainability splits
-
Initial commit