diff --git a/.planning/phases/12.2-admin-form-fields-date-file-upload-relation-editing-with-def/12.2-REVIEW-DISPOSITION.md b/.planning/phases/12.2-admin-form-fields-date-file-upload-relation-editing-with-def/12.2-REVIEW-DISPOSITION.md new file mode 100644 index 0000000..7d5275c --- /dev/null +++ b/.planning/phases/12.2-admin-form-fields-date-file-upload-relation-editing-with-def/12.2-REVIEW-DISPOSITION.md @@ -0,0 +1,53 @@ +--- +phase: 12.2 +review: 12.2-REVIEW.md +titles: json +findings: + - id: CR-01 + severity: critical + disposition: open + title: "Form saves can commit before an in-flight upload reaches the deferred session" + - id: CR-02 + severity: critical + disposition: open + title: "Aborted or network-failed uploads have no idempotency or reconciliation path" + - id: CR-03 + severity: critical + disposition: open + title: "Core CRUD, settings, and relation mutation JSON bodies are uncapped" + - id: WR-01 + severity: warning + disposition: open + title: "A field may advertise a maximum file size that its request cap cannot carry" + - id: WR-02 + severity: warning + disposition: open + title: "Datetime picker bounds use local days while the server validates UTC days" + - id: WR-03 + severity: warning + disposition: open + title: "Concurrent reorder requests can overwrite the latest order or create a mixed order" + - id: WR-04 + severity: warning + disposition: open + title: "Pending pivot hydration discards type-conversion errors" +open: 7 +total: 7 +recorded: 2026-10-02T19:20:13Z +--- + +# Phase 12.2: Code Review Disposition + +| Finding | Severity | Disposition | Source | +|---------|----------|-------------|--------| +| CR-01 | critical | open | - | +| CR-02 | critical | open | - | +| CR-03 | critical | open | - | +| WR-01 | warning | open | - | +| WR-02 | warning | open | - | +| WR-03 | warning | open | - | +| WR-04 | warning | open | - | + +Dispositions: `open` (recorded, not yet triaged), `fixed`, `skipped`, `deferred`. +Set `deferred` by hand and put the reason in the Source cell; both are preserved. A `|` in the reason is kept as prose and escaped on the next run. +Re-running the gate keeps every row it can. A row the current review no longer reports is kept and its Source cell flagged, so a finding does not leave this record silently. ONE exception: when a finding id is REUSED by a different finding, the earlier decision cannot keep a row — the id is taken — and it is dropped. A RECORDED decision (anything but `open`) is named on the console when that happens; a row still at `open` is replaced silently, because `open` records no decision to lose.