security(gate3): Security-Review-Haertung ueber 4 Pakete (luna-pro)
Phase 6 / Gate 3 — Security-Review auf den fertigen Code, 4 thematische Pakete:
- P1 Secrets+Injection (client/phraser/diagnostics): validate haertet URL/Entity/
Unicode-Umgehungen (// , &entity; , Cc/Cf/Zl/Zp); kein Key-Leak.
- P2 XSS+externe (card/ha_entity/frontend): kein XSS; DoS-Caps (Forecast 400, Karte 60).
- P3 Mutator+Startup (coordinator/__init__/const): nicht-blockierender Startup via
Background-Task, LLM-/Store-Ops defensiv, weather_entity_id-Guard, build_items
NaN/inf+Caps, Warn-Log ohne Secret.
- P4 Flows (config_flow): test_entity exception-frei, _clean_item defensiv, finite
Bandgrenzen + sanitized_options-Normalisierung, echte bool-Coercion, Typ-Log.
- 24 Findings, 14 uebernommen (mit Regressionstests), 10 verworfen mit Evidenz.
Suite gruen 188/188. Gate 3 BESTANDEN.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>