Files
summercms/.planning/phases/10-admin-vue-spa/10-REVIEW-DISPOSITION.md

30 lines
2.3 KiB
Markdown

---
phase: 10-admin-vue-spa
source: 10-REVIEW.md
created: 2026-09-27T16:36:06Z
---
# Phase 10 review disposition
| Finding | Severity | Disposition | Note |
|---|---|---|---|
| CR-01 | critical | fixed | Fixed in be4a923 (tests a13a121), quick 260927-q23. Admin refresh now applies the backend guard's subject checks (activated, not deleted, iat not before tokens_valid_after) via bouncer.RefreshAudienceFor before minting, and a refused cookie refresh expires summer_admin. |
| WR-01 | warning | open | Logout does not expire the cookie when the token is rejected |
| WR-02 | warning | open | A belongsTo foreign key exposed as a scalar field skips the relation scope check |
| WR-03 | warning | open | Model rules run before relation values are assigned |
| WR-04 | warning | open | Scope filter choices cannot be scoped to the signed-in admin |
| WR-05 | warning | open | SPA loaders have no error handling, so network failures leave views stuck loading |
| WR-06 | warning | open | After a delete or unlink, the list can stay on a page past the last page |
| WR-07 | warning | open | Refresh re-mints iat, so the refresh window slides with no upper bound |
| IN-01 | info | open | A large access TTL makes the proactive refresh fire in a loop |
| IN-02 | info | open | Nothing enforces the CSRF design's "no preflight on the admin API" assumption |
| IN-03 | info | open | Choosing the transport by X-Requested-With is fragile for Bearer clients |
| IN-04 | info | open | Dead genre and style cases in the albums DropdownOptions |
| IN-05 | info | open | Relation id lists have no size cap |
| IN-06 | info | open | The gate's required-test check ignores the package |
| IN-07 | info | open | Logging out from a dirty form can leave the user on the form without a session |
| WR-08 | warning | open | The frontend user refresh still ignores tokens_valid_after, so the CR-01 gap remains for site users (added by re-review 2026-09-27) |
| IN-08 | info | open | bouncer.Middleware still inlines the subject lookup that subjectPrincipal now owns (added by re-review 2026-09-27) |
| IN-09 | info | open | RefreshAudienceFor takes a request context but the blacklist calls ignore it (added by re-review 2026-09-27) |
| IN-10 | info | open | service.users is documented as the backend guard's provider, which is not guaranteed (added by re-review 2026-09-27) |