docs(10): re-review CR-01 fix and record approved UAT

This commit is contained in:
Jakub Zych
2026-09-27 20:38:18 +02:00
parent 7e015638f7
commit c7487f6799
3 changed files with 95 additions and 23 deletions

View File

@@ -23,3 +23,7 @@ created: 2026-09-27T16:36:06Z
| IN-05 | info | open | Relation id lists have no size cap |
| IN-06 | info | open | The gate's required-test check ignores the package |
| IN-07 | info | open | Logging out from a dirty form can leave the user on the form without a session |
| WR-08 | warning | open | The frontend user refresh still ignores tokens_valid_after, so the CR-01 gap remains for site users (added by re-review 2026-09-27) |
| IN-08 | info | open | bouncer.Middleware still inlines the subject lookup that subjectPrincipal now owns (added by re-review 2026-09-27) |
| IN-09 | info | open | RefreshAudienceFor takes a request context but the blacklist calls ignore it (added by re-review 2026-09-27) |
| IN-10 | info | open | service.users is documented as the backend guard's provider, which is not guaranteed (added by re-review 2026-09-27) |