Files
summercms/.planning/phases/10-admin-vue-spa/10-REVIEW-DISPOSITION.md

2.3 KiB

phase, source, created
phase source created
10-admin-vue-spa 10-REVIEW.md 2026-09-27T16:36:06Z

Phase 10 review disposition

Finding Severity Disposition Note
CR-01 critical fixed Fixed in be4a923 (tests a13a121), quick 260927-q23. Admin refresh now applies the backend guard's subject checks (activated, not deleted, iat not before tokens_valid_after) via bouncer.RefreshAudienceFor before minting, and a refused cookie refresh expires summer_admin.
WR-01 warning open Logout does not expire the cookie when the token is rejected
WR-02 warning open A belongsTo foreign key exposed as a scalar field skips the relation scope check
WR-03 warning open Model rules run before relation values are assigned
WR-04 warning open Scope filter choices cannot be scoped to the signed-in admin
WR-05 warning open SPA loaders have no error handling, so network failures leave views stuck loading
WR-06 warning open After a delete or unlink, the list can stay on a page past the last page
WR-07 warning open Refresh re-mints iat, so the refresh window slides with no upper bound
IN-01 info open A large access TTL makes the proactive refresh fire in a loop
IN-02 info open Nothing enforces the CSRF design's "no preflight on the admin API" assumption
IN-03 info open Choosing the transport by X-Requested-With is fragile for Bearer clients
IN-04 info open Dead genre and style cases in the albums DropdownOptions
IN-05 info open Relation id lists have no size cap
IN-06 info open The gate's required-test check ignores the package
IN-07 info open Logging out from a dirty form can leave the user on the form without a session
WR-08 warning open The frontend user refresh still ignores tokens_valid_after, so the CR-01 gap remains for site users (added by re-review 2026-09-27)
IN-08 info open bouncer.Middleware still inlines the subject lookup that subjectPrincipal now owns (added by re-review 2026-09-27)
IN-09 info open RefreshAudienceFor takes a request context but the blacklist calls ignore it (added by re-review 2026-09-27)
IN-10 info open service.users is documented as the backend guard's provider, which is not guaranteed (added by re-review 2026-09-27)