- 12.2-SECURITY-REVIEW.md maps T-12.2-01 to T-12.2-36 and the supply chain rows to the controls as built and their passing tests, with the parent-predicate removal check and the residual risks - 12.2-VALIDATION.md: per-task map with real task ids, all green, nyquist_compliant and wave_0_complete set - deferred-items.md: out-of-scope findings for follow-up
12 lines
2.1 KiB
Markdown
12 lines
2.1 KiB
Markdown
# Phase 12.2 deferred items
|
|
|
|
Things found during plan 12.2-05 that are outside this phase's scope. None of them was changed here.
|
|
|
|
| Item | Where | Why deferred | Suggested follow-up |
|
|
|------|-------|--------------|---------------------|
|
|
| The public static handler sends no `X-Content-Type-Options: nosniff` | `modules/lagoon/attach/static.go` `servePublicBlobs` (Phase 5/12 code) | It predates this phase and is not in its threat register. The stored content type comes from the sniff, and the protected admin route already sends nosniff | Add `X-Content-Type-Options: nosniff` to `StaticHandler`/`StaticHandlerPublic` responses (one header, plus a test) |
|
|
| `IsAllowedImage` checks the header only: a valid GIF header followed by HTML passes | `modules/lagoon/attach/guard.go` | Header-only by design (it gets the 1 MiB read-ahead). The content is served as `image/gif`, and browsers do not sniff images into HTML | Consider a full decode for small images, or re-encoding image uploads, if polyglots matter beyond content-type safety |
|
|
| No unique index on a first bind | `deferred_bindings` (12.2-01) | Two concurrent first binds of the same slave can both insert. WinterCMS has the same gap. The duplicates are harmless (`TestDeferredConcurrentFirstBind`) | A user decision: keep it, or add a partial unique index on (session_key, backend_user_id, master_type, master_field, slave_type, slave_id, is_bind) in a new migration |
|
|
| GORM reads a bare `type:time` tag as its own time type | Test models only | `AutoMigrate` with `gorm:"type:time"` creates `timestamptz`. Framework migrations are hand-written SQL, so production is unaffected | A docs note in `docs/database/casts-and-validation.md` that an AutoMigrate'd `lagoon.TimeOfDay` column needs `type:time without time zone` |
|
|
| `lagoon.Date` accepts a timestamp string, `*lagoon.Date` does not | `modules/lagoon/fill.go` (Scan fallback only for non-pointer fields) | A plain Date falls back to `Date.Scan`, which accepts the driver's `YYYY-MM-DDT...` form. The SPA always sends `YYYY-MM-DD` | Make the two variants consistent, either way, if an API client ever sends timestamps to date fields |
|