docs(10): add code review report and disposition

This commit is contained in:
Jakub Zych
2026-09-27 18:36:06 +02:00
parent 473a454c29
commit 6918ec5998
2 changed files with 321 additions and 0 deletions

View File

@@ -0,0 +1,25 @@
---
phase: 10-admin-vue-spa
source: 10-REVIEW.md
created: 2026-09-27T16:36:06Z
---
# Phase 10 review disposition
| Finding | Severity | Disposition | Note |
|---|---|---|---|
| CR-01 | critical | open | Refresh ignores the tokens_valid_after cutoff, so the SPA undoes session revocation (confirmed in bouncer/refresh.go; flaw from 09-01, exposed by the Phase 10 cookie auto-refresh) |
| WR-01 | warning | open | Logout does not expire the cookie when the token is rejected |
| WR-02 | warning | open | A belongsTo foreign key exposed as a scalar field skips the relation scope check |
| WR-03 | warning | open | Model rules run before relation values are assigned |
| WR-04 | warning | open | Scope filter choices cannot be scoped to the signed-in admin |
| WR-05 | warning | open | SPA loaders have no error handling, so network failures leave views stuck loading |
| WR-06 | warning | open | After a delete or unlink, the list can stay on a page past the last page |
| WR-07 | warning | open | Refresh re-mints iat, so the refresh window slides with no upper bound |
| IN-01 | info | open | A large access TTL makes the proactive refresh fire in a loop |
| IN-02 | info | open | Nothing enforces the CSRF design's "no preflight on the admin API" assumption |
| IN-03 | info | open | Choosing the transport by X-Requested-With is fragile for Bearer clients |
| IN-04 | info | open | Dead genre and style cases in the albums DropdownOptions |
| IN-05 | info | open | Relation id lists have no size cap |
| IN-06 | info | open | The gate's required-test check ignores the package |
| IN-07 | info | open | Logging out from a dirty form can leave the user on the form without a session |