| CR-01 |
critical |
open |
Refresh ignores the tokens_valid_after cutoff, so the SPA undoes session revocation (confirmed in bouncer/refresh.go; flaw from 09-01, exposed by the Phase 10 cookie auto-refresh) |
| WR-01 |
warning |
open |
Logout does not expire the cookie when the token is rejected |
| WR-02 |
warning |
open |
A belongsTo foreign key exposed as a scalar field skips the relation scope check |
| WR-03 |
warning |
open |
Model rules run before relation values are assigned |
| WR-04 |
warning |
open |
Scope filter choices cannot be scoped to the signed-in admin |
| WR-05 |
warning |
open |
SPA loaders have no error handling, so network failures leave views stuck loading |
| WR-06 |
warning |
open |
After a delete or unlink, the list can stay on a page past the last page |
| WR-07 |
warning |
open |
Refresh re-mints iat, so the refresh window slides with no upper bound |
| IN-01 |
info |
open |
A large access TTL makes the proactive refresh fire in a loop |
| IN-02 |
info |
open |
Nothing enforces the CSRF design's "no preflight on the admin API" assumption |
| IN-03 |
info |
open |
Choosing the transport by X-Requested-With is fragile for Bearer clients |
| IN-04 |
info |
open |
Dead genre and style cases in the albums DropdownOptions |
| IN-05 |
info |
open |
Relation id lists have no size cap |
| IN-06 |
info |
open |
The gate's required-test check ignores the package |
| IN-07 |
info |
open |
Logging out from a dirty form can leave the user on the form without a session |