Files
summercms/.planning/phases/10.1-runtime-admin-extension-point/10.1-REVIEW-DISPOSITION.md
2026-09-29 10:10:45 +02:00

3.4 KiB

phase, review, titles, findings, open, total, recorded
phase review titles findings open total recorded
10.1 10.1-REVIEW.md json
id severity disposition title
CR-01 critical fixed A fractional, exponent or overflowing number for an integer column is a 500, not a validation error
id severity disposition title
WR-01 warning fixed A late schema response re-activates the previous controller's stylesheets over the current view
id severity disposition title
WR-02 warning fixed Plugin stylesheets stay enabled on views that are not controller views
id severity disposition title
WR-03 warning fixed The partial view-model guard (T-10.1-09) is shallow and easy to bypass
id severity disposition title
WR-04 warning fixed `isJSONScalar` trusts `reflect.Kind`, not the JSON the value encodes to
id severity disposition title
WR-05 warning fixed Form schema shows widgets the admin is not allowed to run
id severity disposition title
WR-06 warning fixed The widget action route ignores the field's `context`
id severity disposition title
IN-01 info open The widget-tag collision mitigation (T-10.1-11) only checks YAML
id severity disposition title
IN-02 info open A toolbar action accepts `{"values": null}`
id severity disposition title
IN-03 info open The OpenAPI annotations omit the 500 responses the new routes return
id severity disposition title
IN-04 info open The gate's partial-template hygiene only scans `*/controllers/*/_*.htm`
id severity disposition title
IN-05 info open Plugin admin assets are served without authentication
id severity disposition title
IN-06 info open A form partial `?id=` needs writable-model capabilities
id severity disposition title
IN-07 info open The `compilePartials` escape check has false positives
7 14 2026-09-29T08:10:44.662Z

Phase 10.1: Code Review Disposition

Finding Severity Disposition Source
CR-01 critical fixed 10.1-REVIEW-FIX.md
WR-01 warning fixed 10.1-REVIEW-FIX.md
WR-02 warning fixed 10.1-REVIEW-FIX.md
WR-03 warning fixed 10.1-REVIEW-FIX.md
WR-04 warning fixed 10.1-REVIEW-FIX.md
WR-05 warning fixed 10.1-REVIEW-FIX.md
WR-06 warning fixed 10.1-REVIEW-FIX.md
IN-01 info open -
IN-02 info open -
IN-03 info open -
IN-04 info open -
IN-05 info open -
IN-06 info open -
IN-07 info open -

Dispositions: open (recorded, not yet triaged), fixed, skipped, deferred. Set deferred by hand and put the reason in the Source cell; both are preserved. A | in the reason is kept as prose and escaped on the next run. Re-running the gate keeps every row it can. A row the current review no longer reports is kept and its Source cell flagged, so a finding does not leave this record silently. ONE exception: when a finding id is REUSED by a different finding, the earlier decision cannot keep a row — the id is taken — and it is dropped. A RECORDED decision (anything but open) is named on the console when that happens; a row still at open is replaced silently, because open records no decision to lose.