Files
summercms/.planning/phases/11-jobs-realtime-and-search-infrastructure/11-REVIEW-DISPOSITION.md
2026-09-30 15:18:21 +02:00

4.1 KiB

phase, review, titles, findings, open, total, recorded
phase review titles findings open total recorded
11 11-REVIEW.md json
id severity disposition title
CR-01 critical open The search index syncs mid-transaction, before pivots are written, and diverges from committed data
id severity disposition title
WR-01 warning open Broadcast channel and payload callbacks get a handle that continues the write's statement after `WithContext`
id severity disposition title
WR-02 warning open Scheduled commands that open their own database fail inside a running worker
id severity disposition title
WR-03 warning open A nested `lagoon.Transaction` over the root handle is an independent transaction, but its callbacks wait on the parent
id severity disposition title
WR-04 warning open `websockets:generate-vapid-keys --update` writes the VAPID private key into the application's repository tree
id severity disposition title
WR-05 warning open Identifier connection tokens are authorized as user ids by the subscribe proxy
id severity disposition title
WR-06 warning open The default broadcast payload serializes the in-memory model: zero values on partial updates, and every exported field
id severity disposition title
WR-07 warning open The Centrifugo subscribe proxy shares an IP-keyed rate limit bucket with public traffic
id severity disposition title
IN-01 info open Parity tooling cannot detect key-order drift, and several payload maps are unordered
id severity disposition title
IN-02 info open The fallback to the in-memory album in `albumPayload` is unreachable
id severity disposition title
IN-03 info open The River scheduler and `schedule:run --once` disagree on DST days and sub-minute intervals
id severity disposition title
IN-04 info open `summer_jobs` rows can stay IN_PROGRESS forever
id severity disposition title
IN-05 info open The centrifugo and typesense `Config` structs do not redact their secrets
id severity disposition title
IN-06 info open `parity:broadcasts --api-key` puts a secret on the command line
id severity disposition title
IN-07 info open The removal harness leaves mutated security code behind on SIGTERM or SIGKILL
id severity disposition title
IN-08 info open `Service.Emit` drops the caller's context when `db` is nil
id severity disposition title
IN-09 info open The three modules detect a transaction in different ways
id severity disposition title
IN-10 info open `RecordBroadcasts` returns before the recorder has released its port
18 18 2026-09-30T13:18:20.607Z

Phase 11: Code Review Disposition

Finding Severity Disposition Source
CR-01 critical open -
WR-01 warning open -
WR-02 warning open -
WR-03 warning open -
WR-04 warning open -
WR-05 warning open -
WR-06 warning open -
WR-07 warning open -
IN-01 info open -
IN-02 info open -
IN-03 info open -
IN-04 info open -
IN-05 info open -
IN-06 info open -
IN-07 info open -
IN-08 info open -
IN-09 info open -
IN-10 info open -

Dispositions: open (recorded, not yet triaged), fixed, skipped, deferred. Set deferred by hand and put the reason in the Source cell; both are preserved. A | in the reason is kept as prose and escaped on the next run. Re-running the gate keeps every row it can. A row the current review no longer reports is kept and its Source cell flagged, so a finding does not leave this record silently. ONE exception: when a finding id is REUSED by a different finding, the earlier decision cannot keep a row — the id is taken — and it is dropped. A RECORDED decision (anything but open) is named on the console when that happens; a row still at open is replaced silently, because open records no decision to lose.