Small fixes from the architecture review.
- Migrations with
-- foreign_keys: offcommit, then runPRAGMA foreign_key_check(internal/store/store.go:237). A violation is reported after the schema anduser_versionare persisted. Run the check inside the transaction before commit;foreign_key_checkworks with enforcement off. pinToggle(internal/httpd/accounts.go:241), the watch toggle and mark-read (internal/httpd/notifyweb.go) call the store directly and ignore errors, skipping the dispatch write budget and audit. Route them through their commands.- API.org says tokens are minted on the API (line 16) and that token commands are refused by name (line 55); the code allows them. The 401 in internal/httpd/api.go:131 says "mint one over SSH".
- Parity says batched review is not built;
mr comment --pendingand publication exist and the web uses them. - Threat-Model says secrets never appear in URLs; login links carry
?token=. Document the exception, sendCache-Control: no-storeon the login flow, and note that proxies must strip the query from logs.
referenced in commit 7a6343d02d by cmc: wiki: architecture and security pages
2026-09-28 04:30 UTC