Side A closes a significant security gap by sanitizing untrusted Reddit `body_html` with `ammonia` before passing it to `maud::PreEscaped`, adds a dedicated sanitizer module, and includes tests verifying scripts and event handlers are stripped while benign markup is preserved. Side B fixes an important browser-auth design bug by removing shared sentinel delegates, switching browser sessions to `None` delegates, and adding strong integration tests for multi-user voting, but its impact is narrower than preventing XSS in rendered content.
constitution · epochs · watch · epoch 3 · comparison · attempt
judgment
openai/gpt-chat-latest → A (3:2)
jud_9e4bd6a6e7f802 · raw event
Metadata
judgment_idjud_9e4bd6a6e7f8028f913844724874b4cde922abe2983ba57abf4dd0067c48a28e
model_idopenai/gpt-chat-latest
winnerA
ratio3:2
comparison_idcmp_9e39df70a69cc3045f6ec341026c25a06f348e8115726eea9531471f07d648cf
attempt_idatt_2a04e36915e4cdef73a5f294c7117f1e3ec64f6198eb15c90e57778aeb9ffa98