# Phase 12.2 deferred items Things found during plan 12.2-05 that are outside this phase's scope. None of them was changed here. | Item | Where | Why deferred | Suggested follow-up | |------|-------|--------------|---------------------| | The public static handler sends no `X-Content-Type-Options: nosniff` | `modules/lagoon/attach/static.go` `servePublicBlobs` (Phase 5/12 code) | It predates this phase and is not in its threat register. The stored content type comes from the sniff, and the protected admin route already sends nosniff | Add `X-Content-Type-Options: nosniff` to `StaticHandler`/`StaticHandlerPublic` responses (one header, plus a test) | | `IsAllowedImage` checks the header only: a valid GIF header followed by HTML passes | `modules/lagoon/attach/guard.go` | Header-only by design (it gets the 1 MiB read-ahead). The content is served as `image/gif`, and browsers do not sniff images into HTML | Consider a full decode for small images, or re-encoding image uploads, if polyglots matter beyond content-type safety | | No unique index on a first bind | `deferred_bindings` (12.2-01) | Two concurrent first binds of the same slave can both insert. WinterCMS has the same gap. The duplicates are harmless (`TestDeferredConcurrentFirstBind`) | A user decision: keep it, or add a partial unique index on (session_key, backend_user_id, master_type, master_field, slave_type, slave_id, is_bind) in a new migration | | GORM reads a bare `type:time` tag as its own time type | Test models only | `AutoMigrate` with `gorm:"type:time"` creates `timestamptz`. Framework migrations are hand-written SQL, so production is unaffected | A docs note in `docs/database/casts-and-validation.md` that an AutoMigrate'd `lagoon.TimeOfDay` column needs `type:time without time zone` | | `lagoon.Date` accepts a timestamp string, `*lagoon.Date` does not | `modules/lagoon/fill.go` (Scan fallback only for non-pointer fields) | A plain Date falls back to `Date.Scan`, which accepts the driver's `YYYY-MM-DDT...` form. The SPA always sends `YYYY-MM-DD` | Make the two variants consistent, either way, if an API client ever sends timestamps to date fields |