Commit f2c5e7302d

f2c5e7302d8cbac97d2ace0ba73b562a9be36da5

parent: abdeafa214

Verified · cmc ci/build: success ci/test: success

cmc <hello@cleberg.net> · 2026-09-29 04:41 UTC

wiki: #261 rows in step with the code

Ref #261

Layout: unified · split

.gitbay/wiki/Architecture/04-Trust-Boundaries.org +2 −2
@@ -93,8 +93,8 @@ no HTTP write path (=internal/httpd/smart.go=,
93 decode the JSON result into the template (=internal/httpd/control.go=). 93 decode the JSON result into the template (=internal/httpd/control.go=).
943. Form posts pass =checkOrigin= (=accounts.go=), dispatch the 943. Form posts pass =checkOrigin= (=accounts.go=), dispatch the
95 matching command, and map the exit code to a redirect or an error on 95 matching command, and map the exit code to a redirect or an error on
96 the page. Three toggles (pin, watch, mark read) write the store 96 the page. The pin, watch and mark-read toggles dispatch =repo pin=,
97 directly instead (#261). 97 =repo watch=/=mute=/=unwatch= and =notifications read= the same way.
98 98
99** E. JSON API 99** E. JSON API
100 100
.gitbay/wiki/Architecture/09-Controls.org +2 −2
@@ -9,7 +9,7 @@ chapter names of OWASP ASVS 4.0 where one fits.
9 9
10| Control | Status | Evidence | 10| Control | Status | Evidence |
11|---------------------------------------------+----------+------------------------------------------------------------------| 11|---------------------------------------------+----------+------------------------------------------------------------------|
12| One authorization path for every surface | partial | all surfaces call =control.Dispatch= (=internal/control/control.go=); three web toggles write the store directly (#261) | 12| One authorization path for every surface | in place | all surfaces call =control.Dispatch= (=internal/control/control.go=); web form handlers, including the pin, watch and mark-read toggles, dispatch commands; login and session bookkeeping are not commands |
13| No server-side signing key | in place | =internal/sig= verifies only | 13| No server-side signing key | in place | =internal/sig= verifies only |
14| Least functionality by default | in place | API, web accounts, git://, push and registration default off (=internal/config/config.go=) | 14| Least functionality by default | in place | API, web accounts, git://, push and registration default off (=internal/config/config.go=) |
15| No git library; git runs as a subprocess with built argv | in place | =internal/gitutil= | 15| No git library; git runs as a subprocess with built argv | in place | =internal/gitutil= |
@@ -100,5 +100,5 @@ chapter names of OWASP ASVS 4.0 where one fits.
100| Service hardening | in place | systemd sandboxing ([[file:03-Deployment.org][3]]) | 100| Service hardening | in place | systemd sandboxing ([[file:03-Deployment.org][3]]) |
101| Backups offsite and append-only | in place | restic with append-only credentials (documented) | 101| Backups offsite and append-only | in place | restic with append-only credentials (documented) |
102| Restore tested | gap | tooling in place (=admin restore-drill=, Admin wiki "Restore drill"); clean-host drill pending (#259) | 102| Restore tested | gap | tooling in place (=admin restore-drill=, Admin wiki "Restore drill"); clean-host drill pending (#259) |
103| Migrations validated before commit | gap | foreign-key check runs after commit (#261) | 103| Migrations validated before commit | in place | =PRAGMA foreign_key_check= runs inside the migration transaction, before commit (=internal/store/store.go=) |
104| Signed, reviewed changes to production | in place | signed commits, =require-mr=, ff-only merges, clean-tree deploys | 104| Signed, reviewed changes to production | in place | signed commits, =require-mr=, ff-only merges, clean-tree deploys |
.gitbay/wiki/Architecture/10-Known-Gaps.org −1
@@ -11,7 +11,6 @@ what the 2026-09-27 review found; remove a row when its issue closes.
11| Issue | Area | Gap | Severity | 11| Issue | Area | Gap | Severity |
12|-------+------------------+-----------------------------------------------------------------------+----------| 12|-------+------------------+-----------------------------------------------------------------------+----------|
13| #259 | Recovery | No restore has been exercised; the procedure and tooling (=admin restore-drill=, =backup --verify=) are in place, the clean-host drill is pending | high | 13| #259 | Recovery | No restore has been exercised; the procedure and tooling (=admin restore-drill=, =backup --verify=) are in place, the clean-host drill is pending | high |
14| #261 | Various | Migration foreign-key check after commit; three web writes bypass dispatch; documentation drift | medium |
15 14
16* Not filed 15* Not filed
17 16