Complaint Management UI package — atomic React components that run on the parent app's auth and API
A consumer can configure an unrestricted API destination while the shared client forwards an available bearer token. No default hidden exfiltration recipient was identified.
Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
dist/complaint-app.jsView on unpkgThe provider accepts a caller-controlled API URL and authentication token.
dist/complaint-app.jsView on unpkg · L3841The shared HTTP client uses the configured base URL, reads a token cookie when no supplied token exists, and adds that token as a Bearer header.
dist/complaint-app.jsView on unpkg · L3800Complaint operations send requests through that shared client.
dist/complaint-app.jsView on unpkg · L4104A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/style.cssView on unpkgThis report applies to @attabot/complaint-app@1.0.27.
See version security history for other recorded verdicts.
Evidence last updated: .
The shared HTTP client uses the configured base URL, reads a token cookie when no supplied token exists, and adds that token as a Bearer header.
dist/complaint-app.jsView on unpkg · L3800Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
dist/complaint-app.jsView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/style.cssView on unpkgThe provider accepts a caller-controlled API URL and authentication token.
dist/complaint-app.jsView on unpkg · L3841Complaint operations send requests through that shared client.
dist/complaint-app.jsView on unpkg · L4104