| id |
severity |
disposition |
title |
| CR-01 |
critical |
open |
Writable numeric fields cannot be saved; bad field values return 500 instead of 422 |
|
| id |
severity |
disposition |
title |
| WR-01 |
warning |
open |
Required-permission wildcards never match, and multiple required codes use ALL rather than Winter's ANY |
|
| id |
severity |
disposition |
title |
| WR-02 |
warning |
open |
Navigation shows a denied parent item, including its label and target controller |
|
| id |
severity |
disposition |
title |
| WR-03 |
warning |
open |
Create, update and delete are not gated by the compiled list and form declarations |
|
| id |
severity |
disposition |
title |
| WR-04 |
warning |
open |
A form field that is `required` but limited by `context` makes every create fail |
|
| id |
severity |
disposition |
title |
| WR-05 |
warning |
open |
Relation link and unlink ignore the panel's toolbarButtons |
|
| id |
severity |
disposition |
title |
| WR-06 |
warning |
open |
A relation list without an explicit `sort` fails when the first column is not sortable |
|
| id |
severity |
disposition |
title |
| WR-07 |
warning |
open |
Relation column order depends on a fixed 16-space YAML indentation |
|
| id |
severity |
disposition |
title |
| WR-08 |
warning |
open |
List search returns 500 for non-text searchable columns, and the scaffold creates one |
|
| id |
severity |
disposition |
title |
| WR-09 |
warning |
open |
Scaffolded admin controllers have no permissions and no record source |
|
| id |
severity |
disposition |
title |
| WR-10 |
warning |
open |
Cabana silently reuses any guard already registered under the name "backend" |
|
| id |
severity |
disposition |
title |
| WR-11 |
warning |
open |
Login identifier can resolve to the wrong admin; admin:create does not prevent login/email collisions |
|
| id |
severity |
disposition |
title |
| WR-12 |
warning |
open |
The dummy hash cost is fixed at 10 while real hashes use the configured cost (timing oracle) |
|
| id |
severity |
disposition |
title |
| WR-13 |
warning |
open |
Admin passwords are passed as command-line flags |
|
| id |
severity |
disposition |
title |
| WR-14 |
warning |
open |
Logout cannot revoke a token whose access lifetime has expired but whose refresh window is still open |
|
| id |
severity |
disposition |
title |
| WR-15 |
warning |
open |
The editors pivot `granted_by` stores a backend_users id in a frontend-user column |
|
| id |
severity |
disposition |
title |
| WR-16 |
warning |
open |
Reflection helpers skip embedded structs and fall back to case-insensitive Go field names |
|
| id |
severity |
disposition |
title |
| WR-17 |
warning |
open |
User-level `backend_users.permissions` is ignored, so Winter denies are lost at cutover |
|
| id |
severity |
disposition |
title |
| WR-18 |
warning |
open |
The phase gate's zero-test check applies per invocation, not per package |
|
| id |
severity |
disposition |
title |
| WR-19 |
warning |
open |
Plugin hooks and scopes query outside the CRUD transaction |
|
| id |
severity |
disposition |
title |
| IN-01 |
info |
open |
A no-op relation mutation returns `{}` |
|
| id |
severity |
disposition |
title |
| IN-02 |
info |
open |
Relation search does not escape LIKE wildcards |
|
| id |
severity |
disposition |
title |
| IN-03 |
info |
open |
`last_page` is inconsistent between the list and relation endpoints |
|
| id |
severity |
disposition |
title |
| IN-04 |
info |
open |
Page parsing and the offset computation can overflow |
|
| id |
severity |
disposition |
title |
| IN-05 |
info |
open |
Controllers with unroutable IDs are accepted |
|
| id |
severity |
disposition |
title |
| IN-06 |
info |
open |
The bulk-delete decoder is looser than the relation decoder |
|
| id |
severity |
disposition |
title |
| IN-07 |
info |
open |
Dead dropdown branches and SQL built by string concatenation in the albums controller |
|
| id |
severity |
disposition |
title |
| IN-08 |
info |
open |
The password-reset cutoff also rejects logins made within about 1-2 seconds of the reset |
|
| id |
severity |
disposition |
title |
| IN-09 |
info |
open |
Album scoping hides database errors as an empty list |
|
| id |
severity |
disposition |
title |
| IN-10 |
info |
open |
Read-only GETs take row locks |
|
| id |
severity |
disposition |
title |
| IN-11 |
info |
open |
Logout reports success without revoking when no blacklist is configured |
|
| id |
severity |
disposition |
title |
| IN-12 |
info |
open |
The scaffold marks a file that must be edited as "DO NOT EDIT" |
|