Files
summercms/.planning/phases/15-journal-plugin/15-REVIEW-DISPOSITION.md
2026-10-06 19:29:25 +02:00

2.8 KiB

phase, review, titles, findings, open, total, recorded
phase review titles findings open total recorded
15 15-REVIEW.md json
id severity disposition title
CR-01 critical open Admin toolbar import/export accepts unsandboxed filesystem paths
id severity disposition title
CR-02 critical open `translations.content_html` bypasses FormatHTML (stored XSS)
id severity disposition title
WR-01 warning open `rss_enabled` is ignored; disabling RSS still serves the feed
id severity disposition title
WR-02 warning open Typesense search double-paginates and reports the wrong total
id severity disposition title
WR-03 warning open Public search trusts a stale process-global gate instead of settings
id severity disposition title
WR-04 warning open Featured-image write routes skip `access_posts`
id severity disposition title
WR-05 warning open Post create/update persists the row before associations
id severity disposition title
WR-06 warning open `uniqueMediaKey` overwrites the original object after 999 collisions
id severity disposition title
IN-01 info open FormatHTML XSS tests do not require rejection
id severity disposition title
IN-02 info open `TestMediaFolderPatternRejectsDotDot` cannot fail if `../` is allowed
id severity disposition title
IN-03 info open Phrasebook still documents PHP artisan scout import
id severity disposition title
IN-04 info open RSS channel links fall back to the request Host header
12 12 2026-10-06T17:28:00Z

Phase 15: Code Review Disposition

Finding Severity Disposition Source
CR-01 critical open -
CR-02 critical open -
WR-01 warning open -
WR-02 warning open -
WR-03 warning open -
WR-04 warning open -
WR-05 warning open -
WR-06 warning open -
IN-01 info open -
IN-02 info open -
IN-03 info open -
IN-04 info open -

Dispositions: open (recorded, not yet triaged), fixed, skipped, deferred. Set deferred by hand and put the reason in the Source cell; both are preserved. A | in the reason is kept as prose and escaped on the next run. Re-running the gate keeps every row it can. A row the current review no longer reports is kept and its Source cell flagged, so a finding does not leave this record silently. ONE exception: when a finding id is REUSED by a different finding, the earlier decision cannot keep a row — the id is taken — and it is dropped. A RECORDED decision (anything but open) is named on the console when that happens; a row still at open is replaced silently, because open records no decision to lose.