internal/httpd/accounts.go calls the store directly instead of dispatching a command at :165 (repo create), :301 (issue create), :346 (issue edit), :387 (MR edit), :410 (issue comment), :434 (MR comment). Everything the command layer guards is skipped from the browser:
checkRepoQuota(internal/control/repo.go:190): the quota is enforced only over SSH and the API.refuseArchived(repo.go:117): archived repositories accept issues and comments from the web.notifyUsers: nobody is mailed for web-created issues or comments.--format: web comments hardcodemd.- The audit entry
Dispatchwrites for every mutating command (control.go:115).
issueactions.go and mractions.go already use issueArgs/mrArgs + runControl. Convert the six handlers to runControlStdin, delete the duplicated author-or-write checks at accounts.go:341 and :381, and add a test that greps httpd for s.store.(Create|Add|Update) and fails on a hit outside session and token code.
closed by commit 01ced7ef9e by cmc: web: repo create, issue and MR create, edit and comment dispatch the command
2026-09-03 15:59 UTC