Complaint Management UI package — atomic React components that run on the parent app's auth and API
A caller can configure the API destination while the client automatically uses a stored token when no explicit token is supplied. No confirmed covert attack was identified.
Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
dist/complaint-app.jsView on unpkgThe package permits its API base URL to be replaced at runtime.
dist/complaint-app.jsView on unpkg · L3794Its request interceptor falls back to an existing token cookie and adds that token as a bearer credential.
dist/complaint-app.jsView on unpkg · L3816UI data operations send requests through that configured client.
dist/complaint-app.jsView on unpkg · L4110A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/style.cssView on unpkgThe manifest lists development scripts only and no install lifecycle hook.
package.jsonView on unpkg · L21This report applies to @attabot/complaint-app@1.0.24.
See version security history for other recorded verdicts.
Evidence last updated: .
The package permits its API base URL to be replaced at runtime.
dist/complaint-app.jsView on unpkg · L3794Its request interceptor falls back to an existing token cookie and adds that token as a bearer credential.
dist/complaint-app.jsView on unpkg · L3816Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
dist/complaint-app.jsView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/style.cssView on unpkgUI data operations send requests through that configured client.
dist/complaint-app.jsView on unpkg · L4110The manifest lists development scripts only and no install lifecycle hook.
package.jsonView on unpkg · L21