It is a real hole and we are shipping without fixing it, so it needs to be written down somewhere that outlives the conversation it came up in. Discipline names are rendered into inline handlers in the WP creator escaped with esc(), which maps ' to '. That is right for text and wrong here: the browser decodes entities in an attribute before the JS parser sees it, so the entity becomes a bare quote and closes the handler's string literal. Escaping for a handler argument has to go backslash, then quote, then HTML — esc() only does the last part. Same bug, same ordering, as the two fixed on 2026-08-05 (jsq() in admin.js, escHandlerArg() in work-package-suite-app.js); this one predates that work and sits in a file it did not touch. Left open rather than fixed because the suite is internal, behind a login, with named employee accounts and no anonymous input path — the likely cost is a discipline named "Owner's Equipment" silently breaking its own pill, not an attack. The entry records the conditions that change that judgement (exposure outside the corporate network, accounts for subcontractors or clients, self-registration), so the rating cannot go quietly stale if the deployment story changes. Neither CSP nor the CSRF gate mitigates it, and both are noted so nobody re-derives that hopefully. Also records the archived-project rough edge from the same day: the server refuses writes with 409, but the two big apps still present Save and Issue buttons, so the failure is safe but late. data-wp-archived is already on the document element for whoever closes it. Each entry says what closing it takes, and entries get deleted in the commit that fixes them — otherwise this file becomes a museum instead of a queue. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Description
No description provided
Languages
Python
49.3%
JavaScript
32.6%
CSS
8.9%
HTML
8.7%
Shell
0.4%