fix: security hardening and cleanup from community PR cherry-picks

- Add HTML sanitizer for markdown rendering (XSS prevention)
- Switch service worker to network-first caching (deploys take effect immediately)
- Sanitize Content-Disposition filenames (header injection prevention)
- Expose session.muxName getter, replace unsafe `as any` cast
- Static import for execFile, update CLAUDE.md keyboard shortcuts

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
This commit is contained in:
arkon
2026-04-11 07:20:09 +02:00
co-authored by Claude Opus 4.6
parent f3cbe9bca6
commit b4a808adcf
6 changed files with 49 additions and 14 deletions
+5
View File
@@ -530,6 +530,11 @@ export class Session extends EventEmitter {
return this._claudeSessionId;
}
/** The tmux session name, if the session is running inside a mux */
get muxName(): string | null {
return this._muxSession?.muxName ?? null;
}
get totalCost(): number {
return this._totalCost;
}