noCV
READ-106 · Support richer reading

Render annotations safely and expose their controls

Practice briefBugAdvanced

Pasted annotation markup changes layout and introduces active links. Annotation actions are unnamed icons visible only on hover.

Focused work estimate
2h 15m + prerequisites
Priority in the scenario
High
Engineering practice
Untrusted content · Accessible controls · Draft state

Estimated field mix

  • Security40%
  • Accessibility30%
  • Frontend30%

Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.

Your next step

Review it, then add it to your workspace.

The board opens an editable draft; nothing is saved until you confirm it. Sign-in and workspace permissions apply, and Demo boards remain ephemeral.

Project context

The fictional Plainview handbook reader serves versioned HTML documents with headings, tables, footnotes, and annotations. Scope is accessible HTML rendering from a structured model; OCR and arbitrary PDF remediation are excluded.

Setup prerequisites

  • Versioned synthetic documents with stable section IDs
  • Annotation and document-access API contracts to stub

Preceding work

Complete these dependencies, or supply their agreed outputs before taking this ticket.

Acceptance criteria

  • Annotations use plain text or an explicit constrained format that removes disallowed content.
  • Edit, delete, and return-to-passage actions have accessible names and work without hover.
  • Failed saves preserve a draft distinct from confirmed comments.

Implementation constraints

  • Keep document source immutable and treat annotation content as untrusted.

Verification to include

  • Create a normal annotation and navigate every action by keyboard.
  • Paste script-like markup and a dangerous link, then reject save; no active content runs and the unsaved draft stays explicit.

Deliverables

  • Safe annotation renderer and keyboard/security regression cases

Rollout and recovery

Enable plain text first; disable rich formatting on sanitization regression while preserving stored source text.

Value of the work

For the engineer: Practice semantic structure, accessible navigation, safe annotations, and stable reading positions.

For the team: Inspect how an engineer makes information usable while protecting document integrity and access boundaries.

Evidence boundaries

Outcome Evidence: Tests, patches, and runbooks are requested deliverables. They become Outcome Evidence only through a qualified Mission and immutable Evidence IDs.

Ownership Evidence: Independent adaptation must be observed under a declared verification policy and cite immutable Evidence IDs. Completing a planning ticket establishes no Ownership Evidence.