From 1ea63ef1ee8c95c7c04bf03e17c6e05fe4672ea5 Mon Sep 17 00:00:00 2001 From: Jakub Zych Date: Fri, 2 Oct 2026 17:08:31 +0200 Subject: [PATCH] docs(12): record code review disposition --- .../12-REVIEW-DISPOSITION.md | 78 +++++++++++++++++++ 1 file changed, 78 insertions(+) create mode 100644 .planning/phases/12-p-ytarium-api-collections-and-albums/12-REVIEW-DISPOSITION.md diff --git a/.planning/phases/12-p-ytarium-api-collections-and-albums/12-REVIEW-DISPOSITION.md b/.planning/phases/12-p-ytarium-api-collections-and-albums/12-REVIEW-DISPOSITION.md new file mode 100644 index 0000000..ba563a5 --- /dev/null +++ b/.planning/phases/12-p-ytarium-api-collections-and-albums/12-REVIEW-DISPOSITION.md @@ -0,0 +1,78 @@ +--- +phase: 12 +review: 12-REVIEW.md +titles: json +findings: + - id: CR-01 + severity: critical + disposition: open + title: "Client file extension outside `[a-z0-9]+` poisons every listing with a permanent 500 (T-12-16 bypass)" + - id: WR-01 + severity: warning + disposition: open + title: "Public originals keep the client extension, so a valid image can be served as HTML (stored XSS on the uploads origin)" + - id: WR-02 + severity: warning + disposition: open + title: "Lock-order inversion between AcceptInvitation and the resolver can deadlock on Postgres" + - id: WR-03 + severity: warning + disposition: open + title: "Artist names without Latin letters collapse into one global artist row (and genres into one empty-slug genre)" + - id: WR-04 + severity: warning + disposition: open + title: "Album writes answer 500 after their transaction has committed" + - id: WR-05 + severity: warning + disposition: open + title: "Bulk create runs up to 5 synchronous Discogs downloads per row, with no per-request cap" + - id: IN-01 + severity: info + disposition: open + title: "Two copies of the upload storage code" + - id: IN-02 + severity: info + disposition: open + title: "A pre-existing album write path and a no-op GORM callback remain" + - id: IN-03 + severity: info + disposition: open + title: "Accept writes the notification inside the accept transaction, unlike PHP and the doc comment" + - id: IN-04 + severity: info + disposition: open + title: "A collection name containing CR or LF silently breaks its invitation mails" + - id: IN-05 + severity: info + disposition: open + title: "The trim and numeric helpers are re-implemented in several places" + - id: IN-06 + severity: info + disposition: open + title: "Global mutable `models.MarketCurrencyFunc` is set at Boot without synchronization" +open: 12 +total: 12 +recorded: 2026-10-02T15:08:31.458Z +--- + +# Phase 12: Code Review Disposition + +| Finding | Severity | Disposition | Source | +|---------|----------|-------------|--------| +| CR-01 | critical | open | - | +| WR-01 | warning | open | - | +| WR-02 | warning | open | - | +| WR-03 | warning | open | - | +| WR-04 | warning | open | - | +| WR-05 | warning | open | - | +| IN-01 | info | open | - | +| IN-02 | info | open | - | +| IN-03 | info | open | - | +| IN-04 | info | open | - | +| IN-05 | info | open | - | +| IN-06 | info | open | - | + +Dispositions: `open` (recorded, not yet triaged), `fixed`, `skipped`, `deferred`. +Set `deferred` by hand and put the reason in the Source cell; both are preserved. A `|` in the reason is kept as prose and escaped on the next run. +Re-running the gate keeps every row it can. A row the current review no longer reports is kept and its Source cell flagged, so a finding does not leave this record silently. ONE exception: when a finding id is REUSED by a different finding, the earlier decision cannot keep a row — the id is taken — and it is dropped. A RECORDED decision (anything but `open`) is named on the console when that happens; a row still at `open` is replaced silently, because `open` records no decision to lose.