--- phase: 10.1 review: 10.1-REVIEW.md titles: json findings: - id: CR-01 severity: critical disposition: fixed title: "A fractional, exponent or overflowing number for an integer column is a 500, not a validation error" - id: WR-01 severity: warning disposition: fixed title: "A late schema response re-activates the previous controller's stylesheets over the current view" - id: WR-02 severity: warning disposition: fixed title: "Plugin stylesheets stay enabled on views that are not controller views" - id: WR-03 severity: warning disposition: fixed title: "The partial view-model guard (T-10.1-09) is shallow and easy to bypass" - id: WR-04 severity: warning disposition: fixed title: "`isJSONScalar` trusts `reflect.Kind`, not the JSON the value encodes to" - id: WR-05 severity: warning disposition: fixed title: "Form schema shows widgets the admin is not allowed to run" - id: WR-06 severity: warning disposition: fixed title: "The widget action route ignores the field's `context`" - id: IN-01 severity: info disposition: open title: "The widget-tag collision mitigation (T-10.1-11) only checks YAML" - id: IN-02 severity: info disposition: open title: "A toolbar action accepts `{\"values\": null}`" - id: IN-03 severity: info disposition: open title: "The OpenAPI annotations omit the 500 responses the new routes return" - id: IN-04 severity: info disposition: open title: "The gate's partial-template hygiene only scans `*/controllers/*/_*.htm`" - id: IN-05 severity: info disposition: open title: "Plugin admin assets are served without authentication" - id: IN-06 severity: info disposition: open title: "A form partial `?id=` needs writable-model capabilities" - id: IN-07 severity: info disposition: open title: "The `compilePartials` escape check has false positives" open: 7 total: 14 recorded: 2026-09-29T08:10:44.662Z --- # Phase 10.1: Code Review Disposition | Finding | Severity | Disposition | Source | |---------|----------|-------------|--------| | CR-01 | critical | fixed | 10.1-REVIEW-FIX.md | | WR-01 | warning | fixed | 10.1-REVIEW-FIX.md | | WR-02 | warning | fixed | 10.1-REVIEW-FIX.md | | WR-03 | warning | fixed | 10.1-REVIEW-FIX.md | | WR-04 | warning | fixed | 10.1-REVIEW-FIX.md | | WR-05 | warning | fixed | 10.1-REVIEW-FIX.md | | WR-06 | warning | fixed | 10.1-REVIEW-FIX.md | | IN-01 | info | open | - | | IN-02 | info | open | - | | IN-03 | info | open | - | | IN-04 | info | open | - | | IN-05 | info | open | - | | IN-06 | info | open | - | | IN-07 | info | open | - | Dispositions: `open` (recorded, not yet triaged), `fixed`, `skipped`, `deferred`. Set `deferred` by hand and put the reason in the Source cell; both are preserved. A `|` in the reason is kept as prose and escaped on the next run. Re-running the gate keeps every row it can. A row the current review no longer reports is kept and its Source cell flagged, so a finding does not leave this record silently. ONE exception: when a finding id is REUSED by a different finding, the earlier decision cannot keep a row — the id is taken — and it is dropped. A RECORDED decision (anything but `open`) is named on the console when that happens; a row still at `open` is replaced silently, because `open` records no decision to lose.