docs(12.1-05): security review and validation sign-off for Phase 12.1
- 12.1-SECURITY-REVIEW.md: every threat T-12.1-01 to T-12.1-40 and T-12.1-SC with its mitigation, test and observed result; T-12-18 revisited; the D-30 guard and its boundary; the eleven handed-over items; five findings that need a decision - 12.1-VALIDATION.md: per-task map with real task ids and measured run times, signed off - deferred-items.md: older framework files that name an application
This commit is contained in:
@@ -20,3 +20,10 @@
|
||||
**Why not fixed here:** all of them are fixed lists or counts in the application repository (fonoteka.go). Plan 12.1-03 commits only inside the plugin checkout.
|
||||
**Effect on plan 12.1-03's own verify:** the command `go -C ../fonoteka.go test ./plugins/golem15/fonoteka -run '^(TestAdmin|TestPhase09|TestPhase10|TestPhase12Threats)'` cannot be green before plan 04: it matches `TestAdminMetadataFiltering` and the two tests of the entry above. Every other test that pattern selects passes.
|
||||
**Suggested owner:** plan 12.1-04, together with the entry above.
|
||||
|
||||
- Thirteen framework Go files outside Phase 12.1 name a consuming application
|
||||
status: open
|
||||
**Found:** plan 12.1-05 Task 3, 2026-10-05, when the hygiene stage of `scripts/check-phase12.1.sh` was first pointed at the whole `modules` tree.
|
||||
**What:** `grep -rlniE` for the two application names over `modules --include=*.go` lists 13 files, all tests or comments of older modules (for example `modules/tide/capture_test.go` and `modules/wristband/authorize_test.go`). None was added or changed by Phase 12.1.
|
||||
**Why not fixed here:** out of this phase's scope: the hygiene stage covers the files Phase 12.1 added or changed, the root README, every module README, `docs`, `admin/src` and `admin/tests`, and those are clean. Renaming fixtures in other modules' tests belongs to those modules.
|
||||
**Suggested owner:** a quick task, or the next phase that touches each module.
|
||||
|
||||
Reference in New Issue
Block a user