example_route():
...
```
## Security — Settings Sanitization
**NEVER send raw settings or configuration data to the frontend without sanitization.**
- Always use `sanitize_settings_for_user()` from `functions_settings.py` before passing settings to `render
remove components** and measure impact. Simplest solution first, complexity only when needed.
### Quality Criteria (Frontend)
- **Design Quality** -- coherence, not a collection of parts
- **Originality** -- penalize template layouts, library defaults
special non-versioned preview data (e.g., Potree octree viewer files) that the frontend reads directly from the auxiliary bucket.
- The `constructPipeline` lambda should prefer the appropriate output path when provided
files, and other visual content. It deploys as a CloudFormation/CDK stack with:
- **React frontend** (`web/`) — Cloudscape UI, many viewer plugins for 3D/media
- **Python Lambda backend** (`backend/`) — Casbin ABAC/RBAC auth, DynamoDB
container processing or special non-versioned viewer data (e.g., Potree octree files that the frontend reads directly). It should **not** be used for standard pipeline outputs that flow through
sandbox, and the boundary between **tracked core specs** and
> **untracked ad-hoc specs**. For frontend patterns see `web/CLAUDE.md`.
---
## What these tests are for
Playwright drives the **deployed** application
VAMS Viewer Plugin System
Auto-loaded when working within `web/src/visualizerPlugin/`. See `web/CLAUDE.md` for the frontend-wide steering.
---
## Architecture
The 3D/media viewer system uses a plugin-based architecture:
- **PluginRegistry** (`core/PluginRegistry.ts`) — Singleton
cross-platform AI programming orchestration app built with **Tauri 2** (React 18 frontend + pure Rust backend, no Python sidecar). It manages LLM-powered task execution with features like agent management
never ships code the repo hasn't typechecked, built, and tested.
**The stance is frontend-opinionated, backend-agnostic — preserve it.** The frontend
is one fixed, curated stack you *compose* from
A file Claude Code reads at the start of every session. It holds the commands, conventions and warnings the agent needs for this project.
Where does it go?
At the repository root. Claude Code also reads CLAUDE.md files in subdirectories when it works there.
What should it contain?
Build and test commands, the project's layout, conventions that aren't obvious from the code, and mistakes to avoid. Short files tend to work better than long ones.
CLAUDE.md or AGENTS.md?
Claude Code reads CLAUDE.md; most other agents read AGENTS.md. Many projects keep one and point the other at it.