Files
summercms/.planning/phases/02-api-parity-harness-bootstrap/02-REVIEW-FIX.md
2026-09-17 14:45:35 +02:00

4.0 KiB

phase, fixed_at, review_path, iteration, findings_in_scope, fixed, skipped, status
phase fixed_at review_path iteration findings_in_scope fixed skipped status
02-api-parity-harness-bootstrap 2026-09-17T12:55:00Z .planning/phases/02-api-parity-harness-bootstrap/02-REVIEW.md 1 8 8 0 all_fixed

Phase 02: Code Review Fix Report

Fixed at: 2026-09-17T12:55:00Z Source review: .planning/phases/02-api-parity-harness-bootstrap/02-REVIEW.md Iteration: 1

Summary:

  • Findings in scope: 8 (CR-01, WR-01 … WR-07)
  • Fixed: 8
  • Skipped: 0
  • Info (IN-01 … IN-04): not in scope

Fixed Issues

CR-01: Short captured IDs rewrite pagination and IPv4, hiding PHP/Go diffs

Files modified: tide/variables.go, tide/capture_test.go; ../fonoteka.go/parity/fixtures/** (38 YAML files) Commit: 5994e67 (framework), d6251e0 (fonoteka fixtures) Status: fixed: requires human verification Applied fix: Short numeric capture values (len < 8) are no longer substituted into request/response bodies. Path, query, and headers still isolate /albums/1. . is an identifier byte so IPv4 last octets stay literal. Added TestScrubShortIDsLeavePaginationAndIPv4Literal. Restored committed pagination keys (current_page, last_page, total, album_count, counts) and 127.0.0.{{id:*}} to literal 1 / 127.0.0.1. JSON id / *_id placeholders were left in place; normalizeJSON still masks those at compare time.

WR-01: Fixture save is neither exclusive nor all-or-nothing

Files modified: tide/fixture.go, tide/proxy.go, tide/proxy_test.go, tide/manifest.go, cmd/summer/parity.go Commit: 7e70afe Applied fix: Sessions stay in memory until Flush. SaveFlowExclusive claims the destination with O_EXCL. Failed sessions always os.Remove the session path. parity:proxy --update overwrites. Manifest route recording uses exclusive create unless --update.

WR-02: Redirect Location is recorded but never compared

Files modified: tide/diff.go, tide/headers_test.go Commit: 5cb2def Applied fix: Added Location to extraCompareHeaders. Set-Cookie stays off the compare list.

WR-03: JSON decoder stops after the first value

Files modified: tide/diff.go, tide/diff_test.go Commit: d3d202e Applied fix: decodeJSON errors when Decoder.More() is true after the first value.

WR-04: Secret scanners miss passwords and live mismatch text can print tokens

Files modified: tide/variables.go, tide/flow.go, tide/manifest.go, tide/capture_test.go; ../fonoteka.go/parity/check_corpus.go, ../fonoteka.go/parity/check_corpus_test.go Commit: 0ac9dc4 (framework), 1336d53 (fonoteka) Applied fix: After placeholder strip, leftover "password" / password= fail unless the value is the documented allow-list parity-alice-pass. Opaque "access_token" leftovers fail. MismatchError and coverage diff lines run through redactSecrets (JWT, inv_, client_secret, auth_token).

WR-05: php_parity.sh isolation is a basename substring

Files modified: ../fonoteka.go/parity/php_parity.sh Commit: d0f1b61 Applied fix: Basename must still contain parity, and the resolved path must live under $PARITY_ROOT (/tmp/summercms-parity by default). Any path inside $PHP_ROOT is refused.

WR-06: Parity Postgres container is leaked on os.Exit

Files modified: ../fonoteka.go/parity/synthetic_test.go Commit: fb64174 Applied fix: stopParityPostgres() is called explicitly before every os.Exit in TestMain. defer is no longer used for container cleanup.

Files modified: tide/variables.go, tide/flow.go, tide/manifest.go, tide/proxy_test.go Commit: f7b81b9 Applied fix: resolvePath uses EvalSymlinks on the path or its parent before prefix checks. Sidecar reads must stay inside the fixture root after symlink resolution. A vars symlink into fixtures/ is rejected.


Fixed: 2026-09-17T12:55:00Z Fixer: the agent (gsd-code-fixer) Iteration: 1