Files
EpicNext-Cms/docs/superpowers/evidence/2026-09-05-housekeeping-parity-gaps.md
T
Simo 845666cf37
CI / check (pull_request) Successful in 1m41s
CI / deploy (pull_request) Skipped
CI / e2e (pull_request) Skipped
docs(housekeeping): record authority review and remaining parity work
2026-09-05 11:29:57 +02:00

7.0 KiB

Housekeeping functional parity audit

Baseline: 8e54cdbc. CI aggregate success verified remotely. This is an open-work inventory, not a completion report.

Delivery checkpoints

  • Task 1 room/room-furniture legacy convergence: implemented in 184052fb and d0190bc1, independently reviewed, pushed; CI passed. Post-commit refresh warnings are truthful response metadata, but shared UI display remains open.
  • Task 4 moderation authority and guarded legacy entrypoints: implemented in 8a894617; pool-starvation review finding fixed in 54f0345a with 112 focused tests passing. Independent scoped re-review clean. No live DB/RCON contention or emulator acknowledgment evidence.
  • All other findings below remain open until their implementation, tests and review are recorded. A baseline finding is retained here for traceability even after its corresponding checkpoint is delivered.

Hotel / Studio / Operations

Priority Confirmed gap Evidence Execution
P1 Legacy radio editor can write unrelated site setting keys src/actions/admin-radio-extra.ts saveRadioSetting Functional parity Task 2
P1 Legacy room items allow arbitrary fields and wrong-room update/delete src/actions/rooms.ts Task 1
P1 Studio final persistence/readback failure reclassifies successful runner as failed hotel/commands/studio-commands.ts createStudioOperationService Task 3
P1 Hotel radio writes omit runtime cache invalidation hotel/services/mutations-production.ts Task 2
P1 Studio furniture import omits selected source and finalization studio-commands.ts furni branch vs src/app/api/admin/import/furni/route.ts Open orchestration task
P2 Studio command reason is discarded studio-commands.ts / hotel/queries/studio.ts Task 3
P2 Production Studio get/list only reads process memory hotel/queries/studio.ts Open durable repository task
P2 Clone ignores false catalog/items refresh delivery studio-commands.ts consolidate Task 3
P2 Repair ignores nested Nitro failure and error events studio-commands.ts repair-icons branch Task 3
P2 Hotel HAVING filters only final UNION branch hotel/queries/hotel-production.ts Open query task

Also requiring explicit parity review: one-time radio API-key delivery; catalog audit/repair bridge versus a history-only screen; radio CRUD legacy convergence.

Radio follow-up confirmed: admin-radio-api-keys.ts, admin-radio-autodj.ts and admin-radio-moderation.ts still write directly and can audit absent targets or swallow failures. Canonical radio runtime checks existence but does not lock those rows before mutations. radio.api-key.create returns metadata without the generated key; the legacy API-key page only renders a masked prefix. Functional parity Task16 covers guarded convergence and a creation-only secret result separated from audit/list output.

Controller confirmed shared site-settings freshness defect: an expired memory cache is returned before attempting a database refresh whenever Redis has no value. Cache invalidation also resets inFlight without protecting against stale in-flight work repopulating the cache. Include regression coverage in the settings task.

Operations replacing legacy dashboard metrics is intentional in migration/operations.ts, not itself missing parity.

Audit coverage: Hotel mutations, Studio service/runner/repository, Hotel query/search/inbox/widgets, legacy room/radio actions, furniture import API; Operations composition and migration contract. Auditors performed read-only code comparison, not service-backed acceptance.

Other domains

Domain Gap Execution
People Ban/moderation/CFH bypass target hierarchy or existence; CFH accepts unrelated user Task 4
People Alert/trade-lock bypass established target guard Task 4
People Commands lose audit reason Task 5
People Missing IP/word-filter delete reports success Task 5
People Missing canonical user creation and individual badge grant/removal Task 7
People User detail omits legacy account/relations/investigation fields Task 12
System Privileged configuration/external operations lack canonical audit Task 6
System Multi-key settings/maintenance writes are non-atomic Task 6
System Unknown permission slugs silently revoke grants; audit outside transaction Task 6
System Canonical ACL changes omit the permissions cache invalidation used by legacy actions Task 6
System Rank update accepts missing target and empty/unknown fields Task 6
System Logs fixed to flattened latest 50, no investigation filters/details Task 12
System Command-center query omits declared recent emulator-error/staff-activity feeds Task 12
Content Theme Builder operations absent despite verified migration row Task 9
Content CRUD synthetic snapshots/false success for absent records Task 8
Content Prefix settings silently skip invalid keys Task 8
Content Edit query payloads incomplete across banners/prefixes/help/writeables/email Task 8
Economy Missing file-upload soundtrack responsibility Task 11
Economy Catalog bulk-create catches row failures and audits success Task 10
Economy Badge grant race and inconsistent code bounds Task 7
Economy Voucher update omits editable code Task 10
Economy Marketplace/transactions filtering and user identity projections incomplete Task 12
Economy Expired active subscriptions included Task 12
Economy Calendar/rare-values editable/grouped projections incomplete Task 12

Read-only audit coverage included all declared commands and production query routing for Content/Economy, and People/System commands, services, query models and affected legacy entrypoints. Findings are mapped to implementation work; each needs focused regression evidence. Proposed badge slot uniqueness is NOT accepted without model verification: slot semantics may allow multiple unequipped badges.

No domain is declared complete by this document. UI-only omissions remain separately open even when their backend operation already exists.

Support follow-up confirmed in people/services/support-mutations.ts: ticket, Help Center, template and CFH reads lack FOR UPDATE; ticket-template delete audits success for a missing row; ticket.assign writes a supplied assignee without a user/eligibility lookup. Legacy CFH assign/state/close still write directly in actions/moderation.ts. Functional parity Task17 covers state integrity and active staff-action convergence, preserving separately scoped public ticket flows.

Acceptance infrastructure check: current e2e/smoke.spec.ts only checks health and homepage rendering; it does not exercise authenticated administration workflows. The supplied docker-compose.yml assumes existing host MariaDB/Redis/emulator services rather than provisioning an isolated test stack. No Docker/MySQL/MariaDB executable was found on the current PATH. These are live-acceptance limitations, not reasons to defer locally testable implementation or to use production data as fixtures.