docs(housekeeping): record authority review and remaining parity work
This commit is contained in:
1 parent
54f0345aac
commit
845666cf37
3 files changed
+42
No files matched your search
@@ -2,6 +2,12 @@
|
||||
|
||||
Baseline: 8e54cdbc. CI aggregate success verified remotely. This is an open-work inventory, not a completion report.
|
||||
|
||||
## Delivery checkpoints
|
||||
|
||||
- Task 1 room/room-furniture legacy convergence: implemented in 184052fb and d0190bc1, independently reviewed, pushed; CI passed. Post-commit refresh warnings are truthful response metadata, but shared UI display remains open.
|
||||
- Task 4 moderation authority and guarded legacy entrypoints: implemented in 8a894617; pool-starvation review finding fixed in 54f0345a with 112 focused tests passing. Independent scoped re-review clean. No live DB/RCON contention or emulator acknowledgment evidence.
|
||||
- All other findings below remain open until their implementation, tests and review are recorded. A baseline finding is retained here for traceability even after its corresponding checkpoint is delivered.
|
||||
|
||||
## Hotel / Studio / Operations
|
||||
|
||||
| Priority | Confirmed gap | Evidence | Execution |
|
||||
@@ -19,6 +25,8 @@ Baseline: 8e54cdbc. CI aggregate success verified remotely. This is an open-work
|
||||
|
||||
Also requiring explicit parity review: one-time radio API-key delivery; catalog audit/repair bridge versus a history-only screen; radio CRUD legacy convergence.
|
||||
|
||||
Radio follow-up confirmed: admin-radio-api-keys.ts, admin-radio-autodj.ts and admin-radio-moderation.ts still write directly and can audit absent targets or swallow failures. Canonical radio runtime checks existence but does not lock those rows before mutations. radio.api-key.create returns metadata without the generated key; the legacy API-key page only renders a masked prefix. Functional parity Task16 covers guarded convergence and a creation-only secret result separated from audit/list output.
|
||||
|
||||
Controller confirmed shared site-settings freshness defect: an expired memory cache is returned before attempting a database refresh whenever Redis has no value. Cache invalidation also resets inFlight without protecting against stale in-flight work repopulating the cache. Include regression coverage in the settings task.
|
||||
|
||||
Operations replacing legacy dashboard metrics is intentional in migration/operations.ts, not itself missing parity.
|
||||
@@ -38,8 +46,10 @@ Audit coverage: Hotel mutations, Studio service/runner/repository, Hotel query/s
|
||||
| System | Privileged configuration/external operations lack canonical audit | Task 6 |
|
||||
| System | Multi-key settings/maintenance writes are non-atomic | Task 6 |
|
||||
| System | Unknown permission slugs silently revoke grants; audit outside transaction | Task 6 |
|
||||
| System | Canonical ACL changes omit the permissions cache invalidation used by legacy actions | Task 6 |
|
||||
| System | Rank update accepts missing target and empty/unknown fields | Task 6 |
|
||||
| System | Logs fixed to flattened latest 50, no investigation filters/details | Task 12 |
|
||||
| System | Command-center query omits declared recent emulator-error/staff-activity feeds | Task 12 |
|
||||
| Content | Theme Builder operations absent despite verified migration row | Task 9 |
|
||||
| Content | CRUD synthetic snapshots/false success for absent records | Task 8 |
|
||||
| Content | Prefix settings silently skip invalid keys | Task 8 |
|
||||
@@ -55,3 +65,7 @@ Audit coverage: Hotel mutations, Studio service/runner/repository, Hotel query/s
|
||||
Read-only audit coverage included all declared commands and production query routing for Content/Economy, and People/System commands, services, query models and affected legacy entrypoints. Findings are mapped to implementation work; each needs focused regression evidence. Proposed badge slot uniqueness is NOT accepted without model verification: slot semantics may allow multiple unequipped badges.
|
||||
|
||||
No domain is declared complete by this document. UI-only omissions remain separately open even when their backend operation already exists.
|
||||
|
||||
Support follow-up confirmed in people/services/support-mutations.ts: ticket, Help Center, template and CFH reads lack FOR UPDATE; ticket-template delete audits success for a missing row; ticket.assign writes a supplied assignee without a user/eligibility lookup. Legacy CFH assign/state/close still write directly in actions/moderation.ts. Functional parity Task17 covers state integrity and active staff-action convergence, preserving separately scoped public ticket flows.
|
||||
|
||||
Acceptance infrastructure check: current e2e/smoke.spec.ts only checks health and homepage rendering; it does not exercise authenticated administration workflows. The supplied docker-compose.yml assumes existing host MariaDB/Redis/emulator services rather than provisioning an isolated test stack. No Docker/MySQL/MariaDB executable was found on the current PATH. These are live-acceptance limitations, not reasons to defer locally testable implementation or to use production data as fixtures.
|
||||
Reference in new issue
Block a user