Files
summercms/.planning/phases/15-journal-plugin/15-REVIEW-DISPOSITION.md
2026-10-06 19:29:25 +02:00

79 lines
2.8 KiB
Markdown

---
phase: 15
review: 15-REVIEW.md
titles: json
findings:
- id: CR-01
severity: critical
disposition: open
title: "Admin toolbar import/export accepts unsandboxed filesystem paths"
- id: CR-02
severity: critical
disposition: open
title: "`translations.content_html` bypasses FormatHTML (stored XSS)"
- id: WR-01
severity: warning
disposition: open
title: "`rss_enabled` is ignored; disabling RSS still serves the feed"
- id: WR-02
severity: warning
disposition: open
title: "Typesense search double-paginates and reports the wrong total"
- id: WR-03
severity: warning
disposition: open
title: "Public search trusts a stale process-global gate instead of settings"
- id: WR-04
severity: warning
disposition: open
title: "Featured-image write routes skip `access_posts`"
- id: WR-05
severity: warning
disposition: open
title: "Post create/update persists the row before associations"
- id: WR-06
severity: warning
disposition: open
title: "`uniqueMediaKey` overwrites the original object after 999 collisions"
- id: IN-01
severity: info
disposition: open
title: "FormatHTML XSS tests do not require rejection"
- id: IN-02
severity: info
disposition: open
title: "`TestMediaFolderPatternRejectsDotDot` cannot fail if `../` is allowed"
- id: IN-03
severity: info
disposition: open
title: "Phrasebook still documents PHP artisan scout import"
- id: IN-04
severity: info
disposition: open
title: "RSS channel links fall back to the request Host header"
open: 12
total: 12
recorded: 2026-10-06T17:28:00Z
---
# Phase 15: Code Review Disposition
| Finding | Severity | Disposition | Source |
|---------|----------|-------------|--------|
| CR-01 | critical | open | - |
| CR-02 | critical | open | - |
| WR-01 | warning | open | - |
| WR-02 | warning | open | - |
| WR-03 | warning | open | - |
| WR-04 | warning | open | - |
| WR-05 | warning | open | - |
| WR-06 | warning | open | - |
| IN-01 | info | open | - |
| IN-02 | info | open | - |
| IN-03 | info | open | - |
| IN-04 | info | open | - |
Dispositions: `open` (recorded, not yet triaged), `fixed`, `skipped`, `deferred`.
Set `deferred` by hand and put the reason in the Source cell; both are preserved. A `|` in the reason is kept as prose and escaped on the next run.
Re-running the gate keeps every row it can. A row the current review no longer reports is kept and its Source cell flagged, so a finding does not leave this record silently. ONE exception: when a finding id is REUSED by a different finding, the earlier decision cannot keep a row — the id is taken — and it is dropped. A RECORDED decision (anything but `open`) is named on the console when that happens; a row still at `open` is replaced silently, because `open` records no decision to lose.