Skip to content

Emit spec-conformant signed sections from CMS integrations #4

Description

@jt55401

Implement the CMS cleanup from the spec review.

Tasks:

  • Emit signed sections that wrap the actual signed content, not detached signature metadata blocks.
  • Use canonical unpadded Base64 hashes and signatures.
  • Bind signatures to serialized origins rather than bare hostnames.
  • Emit and sign all direct child meta claims inside signed-section according to the finalized claims contract.
  • Include signed attribute coverage for href, src, alt, and aria-label where the CMS output contains those attributes.
  • Update WordPress and Hugo reference integration code and tests.
  • Keep legacy API usage only behind compatibility paths if needed.

Spec tracking issue: HTMLTrust/htmltrust-spec protocol cleanup after security review.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions