Files
summercms/.planning/phases/12.2-admin-form-fields-date-file-upload-relation-editing-with-def/deferred-items.md
Jakub Zych 912a46603f docs(12.2-05): security review and validation map for phase 12.2
- 12.2-SECURITY-REVIEW.md maps T-12.2-01 to T-12.2-36 and the supply
  chain rows to the controls as built and their passing tests, with the
  parent-predicate removal check and the residual risks
- 12.2-VALIDATION.md: per-task map with real task ids, all green,
  nyquist_compliant and wave_0_complete set
- deferred-items.md: out-of-scope findings for follow-up
2026-10-02 20:54:14 +02:00

2.1 KiB

Phase 12.2 deferred items

Things found during plan 12.2-05 that are outside this phase's scope. None of them was changed here.

Item Where Why deferred Suggested follow-up
The public static handler sends no X-Content-Type-Options: nosniff modules/lagoon/attach/static.go servePublicBlobs (Phase 5/12 code) It predates this phase and is not in its threat register. The stored content type comes from the sniff, and the protected admin route already sends nosniff Add X-Content-Type-Options: nosniff to StaticHandler/StaticHandlerPublic responses (one header, plus a test)
IsAllowedImage checks the header only: a valid GIF header followed by HTML passes modules/lagoon/attach/guard.go Header-only by design (it gets the 1 MiB read-ahead). The content is served as image/gif, and browsers do not sniff images into HTML Consider a full decode for small images, or re-encoding image uploads, if polyglots matter beyond content-type safety
No unique index on a first bind deferred_bindings (12.2-01) Two concurrent first binds of the same slave can both insert. WinterCMS has the same gap. The duplicates are harmless (TestDeferredConcurrentFirstBind) A user decision: keep it, or add a partial unique index on (session_key, backend_user_id, master_type, master_field, slave_type, slave_id, is_bind) in a new migration
GORM reads a bare type:time tag as its own time type Test models only AutoMigrate with gorm:"type:time" creates timestamptz. Framework migrations are hand-written SQL, so production is unaffected A docs note in docs/database/casts-and-validation.md that an AutoMigrate'd lagoon.TimeOfDay column needs type:time without time zone
lagoon.Date accepts a timestamp string, *lagoon.Date does not modules/lagoon/fill.go (Scan fallback only for non-pointer fields) A plain Date falls back to Date.Scan, which accepts the driver's YYYY-MM-DDT... form. The SPA always sends YYYY-MM-DD Make the two variants consistent, either way, if an API client ever sends timestamps to date fields