diff --git a/.gitignore b/.gitignore index fc4d342..e978658 100644 --- a/.gitignore +++ b/.gitignore @@ -19,6 +19,7 @@ node_modules/ # testing .coverage +_test_*.svg .coverage.* .fastest.coverage htmlcov/ diff --git a/CHANGELOG.md b/CHANGELOG.md index 1b98b58..0daf62f 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -19,6 +19,11 @@ reflects what actually animates, and deploys only ship from a green build. - **JSON validation errors:** `validate --json` returns `{valid, error}` for setup failures such as bad JSON, unknown presets, and missing files. - **Title in compose output:** the artifact's name now ships alongside the text roles. +- **POST body reaches every field:** `font_mode`, `pair`, `state_glyph_shape`, `data`, `format`, + `telemetry_data`, `receipt_display_name`, `connector_data`, `stats_username`, `chart_owner`, + `chart_repo`, `edge_motion`, and `motion_register` are `POST /v1/compose` body fields on every + response shape. An unknown key is reported in `warnings` (json, envelope, report) or the + `X-HW-Warning` header (svg) instead of being dropped. ### Security - **Markup injection via `genome_override`:** a hostile genome could inject `