--- phase: 07-user-plugin-and-authentication reviewed: 2026-09-22T17:26:00Z depth: standard files_reviewed: 4 files_reviewed_list: - ../fonoteka.go/plugins/golem15/user/controllers/api_controller.go - ../fonoteka.go/parity/schema_diff_test.go - ../fonoteka.go/parity/manifest.yaml - bouncer/phase07_coverage_test.go findings: critical: 0 warning: 2 info: 0 total: 2 status: issues_found --- # Phase 7: Code Review Report **Reviewed:** 2026-09-22T17:26:00Z **Depth:** standard **Files Reviewed:** 4 **Status:** issues_found ## Summary The session, token, and lock tests match the handlers they name. Two response differences against the recorded PHP corpus are still in the Go handlers. Neither is a new crash or a secret leak. Both keep the user API routes pending. ## Warnings ### 1. Wrong activation code returns 200 `Activate` ignores the error from `VerifyActivationCode` and always writes the user payload at status 200. The isolated PHP app throws and returns the HTML error page at status 500 for `POST /_user/api/v1/activate` with `{"code":"wrong"}` and for `POST /_user/api/v1/activate-by-code` with `1!nope`. The fixtures record the HTML. The Go handler was left as-is in 07-05. ### 2. Logout blacklists a token PHP still accepts Go logout adds the presented jti to `jwt_blacklist`, so the next fetch is 401. PHP logout returns `{"message":"Logged out"}` and a following fetch with that bearer is still 200. `TestSessionSequence` locks in the Go behavior. The recorded fixtures lock in the PHP behavior. The routes stay `pending`. ## Info None.