43aacd9f60d7cdca937426fdbb2ac1914af12b38
Sina #5505 concern 1: doc.id and blockId are server-trusted today, but the path-interpolation pattern is repeated three times across the route and the autosave hook. Validate both ids against the standard UUID regex before any fetch fires so a future feature taking user-supplied ids cannot silently introduce a path-injection vector. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Description
No description provided
Languages
Python
73.1%
TypeScript
11.5%
Java
10.9%
Svelte
4.2%
Shell
0.1%