Files
summercms/.planning/phases/14.1-oauth-identities-and-fonoteka-me-routes/14.1-REVIEW-DISPOSITION.md
Jakub Zych eb84825724 docs(14.1): record code review and verification
WR-01 is fixed; WR-02 and the three info findings stay open. The phase
goal is 8/8 with corpus 175/175/0.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-10-05 21:48:08 +02:00

44 lines
1.8 KiB
Markdown

---
phase: 14.1
review: 14.1-REVIEW.md
titles: json
findings:
- id: WR-01
severity: warning
disposition: fixed
title: "Hidden profile_data is not json:\"-\"; DATA-07 registry test is red"
- id: WR-02
severity: warning
disposition: open
title: "Last-method 409 is a non-transactional count-then-delete"
- id: IN-01
severity: info
disposition: open
title: "Winter 404 unit tests inject a stub, not host WriteWinterHTTPError"
- id: IN-02
severity: info
disposition: open
title: "MeToken D-09 empty-but-Valid CollectionIDs is untested"
- id: IN-03
severity: info
disposition: open
title: "Index Find decrypts Encrypted token columns it never returns"
open: 4
total: 5
recorded: 2026-10-05T20:00:00Z
---
# Phase 14.1: Code Review Disposition
| Finding | Severity | Disposition | Source |
|---------|----------|-------------|--------|
| WR-01 | warning | fixed | sm-user-plugin cf5c6b9; fonoteka.go 7fc790d |
| WR-02 | warning | open | - |
| IN-01 | info | open | - |
| IN-02 | info | open | - |
| IN-03 | info | open | - |
Dispositions: `open` (recorded, not yet triaged), `fixed`, `skipped`, `deferred`.
Set `deferred` by hand and put the reason in the Source cell; both are preserved. A `|` in the reason is kept as prose and escaped on the next run.
Re-running the gate keeps every row it can. A row the current review no longer reports is kept and its Source cell flagged, so a finding does not leave this record silently. ONE exception: when a finding id is REUSED by a different finding, the earlier decision cannot keep a row — the id is taken — and it is dropped. A RECORDED decision (anything but `open`) is named on the console when that happens; a row still at `open` is replaced silently, because `open` records no decision to lose.