docs(12.1-05): security review and validation sign-off for Phase 12.1

- 12.1-SECURITY-REVIEW.md: every threat T-12.1-01 to T-12.1-40 and T-12.1-SC with its mitigation, test and observed result; T-12-18 revisited; the D-30 guard and its boundary; the eleven handed-over items; five findings that need a decision
- 12.1-VALIDATION.md: per-task map with real task ids and measured run times, signed off
- deferred-items.md: older framework files that name an application
This commit is contained in:
Jakub Zych
2026-10-05 16:13:50 +02:00
parent 83feeef9fa
commit 93f0171e9c
3 changed files with 281 additions and 46 deletions

View File

@@ -20,3 +20,10 @@
**Why not fixed here:** all of them are fixed lists or counts in the application repository (fonoteka.go). Plan 12.1-03 commits only inside the plugin checkout.
**Effect on plan 12.1-03's own verify:** the command `go -C ../fonoteka.go test ./plugins/golem15/fonoteka -run '^(TestAdmin|TestPhase09|TestPhase10|TestPhase12Threats)'` cannot be green before plan 04: it matches `TestAdminMetadataFiltering` and the two tests of the entry above. Every other test that pattern selects passes.
**Suggested owner:** plan 12.1-04, together with the entry above.
- Thirteen framework Go files outside Phase 12.1 name a consuming application
status: open
**Found:** plan 12.1-05 Task 3, 2026-10-05, when the hygiene stage of `scripts/check-phase12.1.sh` was first pointed at the whole `modules` tree.
**What:** `grep -rlniE` for the two application names over `modules --include=*.go` lists 13 files, all tests or comments of older modules (for example `modules/tide/capture_test.go` and `modules/wristband/authorize_test.go`). None was added or changed by Phase 12.1.
**Why not fixed here:** out of this phase's scope: the hygiene stage covers the files Phase 12.1 added or changed, the root README, every module README, `docs`, `admin/src` and `admin/tests`, and those are clean. Renaming fixtures in other modules' tests belongs to those modules.
**Suggested owner:** a quick task, or the next phase that touches each module.