Complaint Management UI package — atomic React components that run on the parent app's auth and API
A configurable API destination can receive existing browser authentication cookies as bearer credentials. This establishes conditional credential exposure, but no confirmed malicious attack.
Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
dist/complaint-app.jsView on unpkgThe API client accepts an unrestricted base URL and falls back to the browser token cookie when no caller token is supplied.
dist/complaint-app.jsView on unpkg · L3804The request interceptor forwards that token in the Authorization header.
dist/complaint-app.jsView on unpkg · L3815Authentication failures send the browser refreshToken cookie to the configured API URL.
dist/complaint-app.jsView on unpkg · L3825A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/style.cssView on unpkgThe manifest has no automatic installation lifecycle hooks.
package.jsonView on unpkg · L21This report applies to @attabot/complaint-app@1.0.29.
See version security history for other recorded verdicts.
Evidence last updated: .
The API client accepts an unrestricted base URL and falls back to the browser token cookie when no caller token is supplied.
dist/complaint-app.jsView on unpkg · L3804The request interceptor forwards that token in the Authorization header.
dist/complaint-app.jsView on unpkg · L3815Authentication failures send the browser refreshToken cookie to the configured API URL.
dist/complaint-app.jsView on unpkg · L3825Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
dist/complaint-app.jsView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/style.cssView on unpkgThe manifest has no automatic installation lifecycle hooks.
package.jsonView on unpkg · L21