Problem / motivation
The UI needs a small audited boundary around secure-metadata rather than coupling DOM code to vendor-native reports and exceptions.
Scope
Create a single vendor import adapter and a pure explicit model for input admission, inspection summaries, non-empty grouping, bounded value formatting, diagnostics, cleaning evidence, verification, MIME, and output names.
Non-goals
No generic metadata engine, recursive renderer, custom policy copy, pixel decode, Canvas, batch, ZIP, or vendor internals.
Acceptance criteria
- Only metadata.js directly imports the vendored artifact.
- The exact released public API and authoritative default policy export are used.
- 50 MiB application admission remains stricter than library limits.
- Rational, binary, opaque, duplicate, partial, diagnostic, and error semantics are deterministic and testable.
Problem / motivation
The UI needs a small audited boundary around secure-metadata rather than coupling DOM code to vendor-native reports and exceptions.
Scope
Create a single vendor import adapter and a pure explicit model for input admission, inspection summaries, non-empty grouping, bounded value formatting, diagnostics, cleaning evidence, verification, MIME, and output names.
Non-goals
No generic metadata engine, recursive renderer, custom policy copy, pixel decode, Canvas, batch, ZIP, or vendor internals.
Acceptance criteria