- 12.2-SECURITY-REVIEW.md maps T-12.2-01 to T-12.2-36 and the supply chain rows to the controls as built and their passing tests, with the parent-predicate removal check and the residual risks - 12.2-VALIDATION.md: per-task map with real task ids, all green, nyquist_compliant and wave_0_complete set - deferred-items.md: out-of-scope findings for follow-up
2.1 KiB
2.1 KiB
Phase 12.2 deferred items
Things found during plan 12.2-05 that are outside this phase's scope. None of them was changed here.
| Item | Where | Why deferred | Suggested follow-up |
|---|---|---|---|
The public static handler sends no X-Content-Type-Options: nosniff |
modules/lagoon/attach/static.go servePublicBlobs (Phase 5/12 code) |
It predates this phase and is not in its threat register. The stored content type comes from the sniff, and the protected admin route already sends nosniff | Add X-Content-Type-Options: nosniff to StaticHandler/StaticHandlerPublic responses (one header, plus a test) |
IsAllowedImage checks the header only: a valid GIF header followed by HTML passes |
modules/lagoon/attach/guard.go |
Header-only by design (it gets the 1 MiB read-ahead). The content is served as image/gif, and browsers do not sniff images into HTML |
Consider a full decode for small images, or re-encoding image uploads, if polyglots matter beyond content-type safety |
| No unique index on a first bind | deferred_bindings (12.2-01) |
Two concurrent first binds of the same slave can both insert. WinterCMS has the same gap. The duplicates are harmless (TestDeferredConcurrentFirstBind) |
A user decision: keep it, or add a partial unique index on (session_key, backend_user_id, master_type, master_field, slave_type, slave_id, is_bind) in a new migration |
GORM reads a bare type:time tag as its own time type |
Test models only | AutoMigrate with gorm:"type:time" creates timestamptz. Framework migrations are hand-written SQL, so production is unaffected |
A docs note in docs/database/casts-and-validation.md that an AutoMigrate'd lagoon.TimeOfDay column needs type:time without time zone |
lagoon.Date accepts a timestamp string, *lagoon.Date does not |
modules/lagoon/fill.go (Scan fallback only for non-pointer fields) |
A plain Date falls back to Date.Scan, which accepts the driver's YYYY-MM-DDT... form. The SPA always sends YYYY-MM-DD |
Make the two variants consistent, either way, if an API client ever sends timestamps to date fields |