Skip to content

docs: add DApp security notes#99

Open
skyc1e wants to merge 2 commits into
circlefin:mainfrom
skyc1e:docs/safe-svg-tokenuri-rendering
Open

docs: add DApp security notes#99
skyc1e wants to merge 2 commits into
circlefin:mainfrom
skyc1e:docs/safe-svg-tokenuri-rendering

Conversation

@skyc1e
Copy link
Copy Markdown

@skyc1e skyc1e commented May 27, 2026

Adds a small DApp security page and links it from the README.

It covers two things Arc app developers can easily get wrong:

  • rendering on-chain SVG metadata from tokenURI() without injecting untrusted SVG into the page DOM
  • payment escrow contract basics: bounded release delays, a payee recovery path, fee snapshots at funding time, and two-step ownership transfers

Closes #85
Closes #86

Checked with git diff --check.

@skyc1e skyc1e marked this pull request as ready for review May 27, 2026 22:49
@skyc1e skyc1e changed the title docs: add safe SVG tokenURI rendering note docs: add DApp security notes May 27, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

1 participant