Complaint Management UI package — atomic React components that run on the parent app's auth and API
Requests can carry a stored or explicitly supplied token to the configured API base URL. A caller who configures an unrelated endpoint could expose that token.
Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
dist/complaint-app.jsView on unpkgThe bundle allows the API base URL to come from VITE_API_URL and reads a token from an explicit setter or browser storage.
dist/complaint-app.jsView on unpkg · L3794Its request interceptor adds that token as a Bearer authorization header without checking the destination against an allowlist.
dist/complaint-app.jsView on unpkg · L3817A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/style.cssView on unpkgThe bundle allows the API base URL to come from VITE_API_URL and reads a token from an explicit setter or browser storage.
package.jsonView on unpkg · L21This report applies to @attabot/complaint-app@1.0.33.
See version security history for other recorded verdicts.
Evidence last updated: .
The bundle allows the API base URL to come from VITE_API_URL and reads a token from an explicit setter or browser storage.
dist/complaint-app.jsView on unpkg · L3794Its request interceptor adds that token as a Bearer authorization header without checking the destination against an allowlist.
dist/complaint-app.jsView on unpkg · L3817Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
dist/complaint-app.jsView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/style.cssView on unpkgThe bundle allows the API base URL to come from VITE_API_URL and reads a token from an explicit setter or browser storage.
package.jsonView on unpkg · L21