Render annotations safely and expose their controls
Pasted annotation markup changes layout and introduces active links. Annotation actions are unnamed icons visible only on hover.
- Focused work estimate
- 2h 15m + prerequisites
- Priority in the scenario
- High
- Engineering practice
- Untrusted content · Accessible controls · Draft state
Estimated field mix
- Security40%
- Accessibility30%
- Frontend30%
Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.
Review it, then add it to your workspace.
The board opens an editable draft; nothing is saved until you confirm it. Sign-in and workspace permissions apply, and Demo boards remain ephemeral.
Project context
The fictional Plainview handbook reader serves versioned HTML documents with headings, tables, footnotes, and annotations. Scope is accessible HTML rendering from a structured model; OCR and arbitrary PDF remediation are excluded.
Setup prerequisites
- Versioned synthetic documents with stable section IDs
- Annotation and document-access API contracts to stub
Preceding work
Complete these dependencies, or supply their agreed outputs before taking this ticket.
Acceptance criteria
- Annotations use plain text or an explicit constrained format that removes disallowed content.
- Edit, delete, and return-to-passage actions have accessible names and work without hover.
- Failed saves preserve a draft distinct from confirmed comments.
Implementation constraints
- Keep document source immutable and treat annotation content as untrusted.
Verification to include
- Create a normal annotation and navigate every action by keyboard.
- Paste script-like markup and a dangerous link, then reject save; no active content runs and the unsaved draft stays explicit.
Deliverables
- Safe annotation renderer and keyboard/security regression cases
Rollout and recovery
Enable plain text first; disable rich formatting on sanitization regression while preserving stored source text.
Value of the work
For the engineer: Practice semantic structure, accessible navigation, safe annotations, and stable reading positions.
For the team: Inspect how an engineer makes information usable while protecting document integrity and access boundaries.
Evidence boundaries
Outcome Evidence: Tests, patches, and runbooks are requested deliverables. They become Outcome Evidence only through a qualified Mission and immutable Evidence IDs.
Ownership Evidence: Independent adaptation must be observed under a declared verification policy and cite immutable Evidence IDs. Completing a planning ticket establishes no Ownership Evidence.