Files
summercms/.planning/phases/10-admin-vue-spa/10-REVIEW-DISPOSITION.md
2026-09-27 18:36:06 +02:00

1.6 KiB

phase, source, created
phase source created
10-admin-vue-spa 10-REVIEW.md 2026-09-27T16:36:06Z

Phase 10 review disposition

Finding Severity Disposition Note
CR-01 critical open Refresh ignores the tokens_valid_after cutoff, so the SPA undoes session revocation (confirmed in bouncer/refresh.go; flaw from 09-01, exposed by the Phase 10 cookie auto-refresh)
WR-01 warning open Logout does not expire the cookie when the token is rejected
WR-02 warning open A belongsTo foreign key exposed as a scalar field skips the relation scope check
WR-03 warning open Model rules run before relation values are assigned
WR-04 warning open Scope filter choices cannot be scoped to the signed-in admin
WR-05 warning open SPA loaders have no error handling, so network failures leave views stuck loading
WR-06 warning open After a delete or unlink, the list can stay on a page past the last page
WR-07 warning open Refresh re-mints iat, so the refresh window slides with no upper bound
IN-01 info open A large access TTL makes the proactive refresh fire in a loop
IN-02 info open Nothing enforces the CSRF design's "no preflight on the admin API" assumption
IN-03 info open Choosing the transport by X-Requested-With is fragile for Bearer clients
IN-04 info open Dead genre and style cases in the albums DropdownOptions
IN-05 info open Relation id lists have no size cap
IN-06 info open The gate's required-test check ignores the package
IN-07 info open Logging out from a dirty form can leave the user on the form without a session