Complaint Management UI package — atomic React components that run on the parent app's auth and API
At runtime, the package has a default external API receiver. Requests made through its client carry parent authentication credentials, and a failed request can send a refresh credential to that receiver.
Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
dist/complaint-app.umd.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
dist/complaint-app.umd.jsView on unpkgThe bundled client defaults its API base URL to an external airaops host.
dist/complaint-app.jsView on unpkg · L3794Every request attaches the parent token or a token cookie as a bearer credential.
dist/complaint-app.jsView on unpkg · L3815On an authentication error, it sends the refresh-token cookie to that external host.
dist/complaint-app.jsView on unpkg · L3825This report applies to @attabot/complaint-app@1.0.8.
See version security history for other recorded verdicts.
Evidence last updated: .
Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
dist/complaint-app.umd.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
dist/complaint-app.umd.jsView on unpkgThe bundled client defaults its API base URL to an external airaops host.
dist/complaint-app.jsView on unpkg · L3794Every request attaches the parent token or a token cookie as a bearer credential.
dist/complaint-app.jsView on unpkg · L3815On an authentication error, it sends the refresh-token cookie to that external host.
dist/complaint-app.jsView on unpkg · L3825