docs(10): add code review report and disposition
This commit is contained in:
25
.planning/phases/10-admin-vue-spa/10-REVIEW-DISPOSITION.md
Normal file
25
.planning/phases/10-admin-vue-spa/10-REVIEW-DISPOSITION.md
Normal file
@@ -0,0 +1,25 @@
|
||||
---
|
||||
phase: 10-admin-vue-spa
|
||||
source: 10-REVIEW.md
|
||||
created: 2026-09-27T16:36:06Z
|
||||
---
|
||||
|
||||
# Phase 10 review disposition
|
||||
|
||||
| Finding | Severity | Disposition | Note |
|
||||
|---|---|---|---|
|
||||
| CR-01 | critical | open | Refresh ignores the tokens_valid_after cutoff, so the SPA undoes session revocation (confirmed in bouncer/refresh.go; flaw from 09-01, exposed by the Phase 10 cookie auto-refresh) |
|
||||
| WR-01 | warning | open | Logout does not expire the cookie when the token is rejected |
|
||||
| WR-02 | warning | open | A belongsTo foreign key exposed as a scalar field skips the relation scope check |
|
||||
| WR-03 | warning | open | Model rules run before relation values are assigned |
|
||||
| WR-04 | warning | open | Scope filter choices cannot be scoped to the signed-in admin |
|
||||
| WR-05 | warning | open | SPA loaders have no error handling, so network failures leave views stuck loading |
|
||||
| WR-06 | warning | open | After a delete or unlink, the list can stay on a page past the last page |
|
||||
| WR-07 | warning | open | Refresh re-mints iat, so the refresh window slides with no upper bound |
|
||||
| IN-01 | info | open | A large access TTL makes the proactive refresh fire in a loop |
|
||||
| IN-02 | info | open | Nothing enforces the CSRF design's "no preflight on the admin API" assumption |
|
||||
| IN-03 | info | open | Choosing the transport by X-Requested-With is fragile for Bearer clients |
|
||||
| IN-04 | info | open | Dead genre and style cases in the albums DropdownOptions |
|
||||
| IN-05 | info | open | Relation id lists have no size cap |
|
||||
| IN-06 | info | open | The gate's required-test check ignores the package |
|
||||
| IN-07 | info | open | Logging out from a dirty form can leave the user on the form without a session |
|
||||
Reference in New Issue
Block a user