# Dispatch for worker_chat_m2_fix_1

You are worker_chat_m2_fix_1 (remediation worker for Milestone M2: Client Chat Security & Verification Hardening).
Your working directory is: c:\Projects\FreeExile\.agents\teamwork\worker_chat_m2_fix_1

## Mandatory Inputs to Read First
1. `c:\Projects\FreeExile\.agents\teamwork\ORIGINAL_REQUEST.md` (section `## 2026-10-01T00:42:05Z`)
2. `c:\Projects\FreeExile\.agents\teamwork\orchestrator_8\plan.md`
3. Reviewer Findings: `c:\Projects\FreeExile\.agents\teamwork\reviewer_chat_m2_1\handoff.md`
4. Code files to remediate:
   - `client/webapp/js/ui/chat_ui.js`
   - `tests/unit/test_webapp_chat_ui.py`

## MANDATORY INTEGRITY WARNING
DO NOT CHEAT. All implementations must be genuine. DO NOT hardcode test results, create dummy/facade implementations, or circumvent the intended task. A auditor will independently verify your work. Integrity violations WILL be detected and your work WILL be rejected.

## File Ownership
You own EXCLUSIVELY:
- `client/webapp/js/ui/chat_ui.js`
- `tests/unit/test_webapp_chat_ui.py`

Do NOT touch `server/chat/` or `tools/stress/`.

## Remediation Tasks
1. In `client/webapp/js/ui/chat_ui.js`:
   - **Fix Stored XSS via Double-Quote Attribute Breakout**:
     In `renderMessageHtml`: escape double quotes `"` and single quotes `'` in addition to `&`, `<`, `>`:
     ```javascript
     const sanitized = String(content)
       .replace(/&/g, '&amp;')
       .replace(/</g, '&lt;')
       .replace(/>/g, '&gt;')
       .replace(/"/g, '&quot;')
       .replace(/'/g, '&#39;');
     ```
   - **Fix Stored XSS via Sender Name**:
     In `renderChatLog`: sanitize `msg.senderName` with the same HTML entity escaping before interpolating into `row.innerHTML`.
   - **Fix HMAC Badge Spoofing / Facade**:
     In `openItemTooltip` and link click handler:
     Track authentic verification (`snapshot.isVerified === true`).
     When an item link is unverified or fallback, display:
     ```javascript
     hmacBadge.textContent = '⚠ Chưa Xác Thực';
     hmacBadge.className = 'px-1.5 py-0.5 rounded text-[8px] font-mono font-bold bg-rose-950 text-rose-400 border border-rose-800/60';
     ```
     And render `'• Không có dữ liệu thuộc tính (Chưa xác thực)'` instead of fabricating fake default affixes.
     When `snapshot.isVerified === true`, display:
     ```javascript
     hmacBadge.textContent = '✓ HMAC Xác Thực';
     hmacBadge.className = 'px-1.5 py-0.5 rounded text-[8px] font-mono font-bold bg-emerald-950 text-emerald-400 border border-emerald-700/60';
     ```
   - **Bound Snapshot Cache**:
     Enforce a maximum size (e.g. 500 entries) on `snapshotCache` (`if (snapshotCache.size > 500) snapshotCache.delete(snapshotCache.keys().next().value);`).
   - **Maintain File Length Cap**:
     Ensure `client/webapp/js/ui/chat_ui.js` remains strictly <= 350 lines (Soft Cap).
2. In `tests/unit/test_webapp_chat_ui.py`:
   - Add automated test assertions verifying:
     - Quotes in item names are escaped as `&quot;` and do not break out of HTML attributes.
     - `msg.senderName` containing `<script>` or HTML tags is properly sanitized.
     - Unverified fallback item snapshots display `⚠ Chưa Xác Thực` and do not display fake affixes.
     - Authenticated item snapshots display `✓ HMAC Xác Thực`.
   - Run `python -m unittest tests/unit/test_webapp_chat_ui.py`.
3. Verify all existing tests pass:
   - `python -m unittest tests/unit/test_chat_service.py`
   - `python -m unittest tests/unit/test_chat_and_moderation.py`
   - `python -m unittest tests/e2e/test_chat_distributed_system_e2e.py`
4. Code Hygiene:
   - Run `python tools/lint/check_code_and_doc_hygiene.py --strict` to verify 0 hard cap violations.

Deliver your report in `c:\Projects\FreeExile\.agents\teamwork\worker_chat_m2_fix_1\handoff.md`.

## 2026-10-01T02:50:08Z
[Message] timestamp=2026-10-01T02:50:08Z sender=ea9d395f-60cc-4be9-a3ac-f706d683a6cd priority=MESSAGE_PRIORITY_HIGH
You are worker_chat_m2_fix_1 for FreeExile.
Working directory: c:\Projects\FreeExile\.agents\teamwork\worker_chat_m2_fix_1
Remediate Client Chat Security & Verification Hardening in client/webapp/js/ui/chat_ui.js and tests/unit/test_webapp_chat_ui.py.
