Allowed
Structured screen data, public component properties, safe inline styles, local resource URLs, and metadata needed for viewer rendering.
Public Boundary
XCON Viewer is viewer-only. It renders declarative UI documents without executing application behavior.
Structured screen data, public component properties, safe inline styles, local resource URLs, and metadata needed for viewer rendering.
JavaScript execution, event handlers, action references, backend/database sections, unsafe URLs, raw HTML injection by default, and runtime business logic.