mirror of
https://github.com/Ark0N/Codeman.git
synced 2026-10-01 13:09:42 +02:00
Expand docs/security-architecture.md: - Add a table-of-contents and an explicit "Trust model" section framing the security boundary as network-bind + auth (not a sandbox around --dangerously-skip-permissions), with an actor/granted matrix and out-of-scope notes. - Clarify the file-serving hardening: the octet-stream + attachment + nosniff combination (not the CSP, which allows 'unsafe-inline') is what blocks SVG/HTML execution. - Detail the actual transport security headers: enumerated CSP widenings (cdn.jsdelivr.net, deepgram wss, data:/blob: img-src, gesture wasm opt-in), HSTS, X-Frame-Options, localhost-only CORS. - Add a "Key source files" table and a dated maintenance note. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>