Commit 073fca4510
Unsigned
Layout: unified · split
ROADMAP.md +58
| @@ -169,6 +169,64 @@ implies. | ||
| 169 | 169 | Labels and hints appear in 17 of 89 view files. Mechanical and low-risk, but it |
| 170 | 170 | cannot be verified from a build — it needs VoiceOver driven on a device. |
| 171 | 171 | |
| 172 | ### SonarCloud backlog | |
| 173 | ||
| 174 | 51 open issues: **0 bugs, 0 vulnerabilities, 51 code smells**, plus 3 security | |
| 175 | hotspots. The headline number is misleading, so trust the breakdown before | |
| 176 | budgeting: | |
| 177 | ||
| 178 | - **35× `swift:S1075` (hardcoded URI)** — 28 of them in | |
| 179 | `SourceHutWebDeepLinkMapperTests`, 5 in `Shared/HutchDeepLinkURLs`. A deep-link | |
| 180 | mapper's tests exist precisely to assert against literal URLs, and a client for | |
| 181 | one forge has fixed endpoints by definition. These want triaging as *Won't | |
| 182 | Fix* in SonarCloud, not refactoring. "Fixing" them would make the code worse. | |
| 183 | - **5× `swift:S1135`** — TODO comments. Two are in `HutchIntents` and name real | |
| 184 | gaps. | |
| 185 | - **3× `swift:S1186` (empty closure)** — all three CRITICAL, all three trivial: | |
| 186 | `Button("Cancel", role: .cancel) {}` needs no body. A comment settles it. | |
| 187 | - **2× `javascript:S4624`** in the Safari extension; **2× `swift:S1172`** unused | |
| 188 | parameters. | |
| 189 | ||
| 190 | The 3 hotspots are the part actually worth thought: | |
| 191 | ||
| 192 | - `KeychainHelper:33` and `:80` (**HIGH**) — the token is stored | |
| 193 | `kSecAttrAccessibleWhenUnlockedThisDeviceOnly` with no | |
| 194 | `SecAccessControl`, so it does not require biometric or passcode | |
| 195 | authentication to read. That is a genuine product decision — should a stolen, | |
| 196 | unlocked phone hand over a sr.ht token? — not a lint nit. | |
| 197 | - `ReadmeView:1922` (**LOW**) — unrestricted WebView navigation. Probably a false | |
| 198 | positive: `isAllowedReadmeNavigationURL` enforces a scheme allowlist. Verify, | |
| 199 | then annotate. | |
| 200 | ||
| 201 | Query it with: | |
| 202 | `https://sonarcloud.io/api/issues/search?componentKeys=zerolabsco_hutch&resolved=false` | |
| 203 | ||
| 204 | ### Ingest "What's cooking on SourceHut?" | |
| 205 | ||
| 206 | sr.ht posts a quarterly update to `~sircmpwn/sr.ht-announce`, mirrored at | |
| 207 | <https://sourcehut.org/blog/>. Nothing in Hutch tracks it, so the API grows and | |
| 208 | this repo's assumptions quietly rot. Read each quarter's post, diff it against | |
| 209 | `Docs/API`, `SCOPE.md`, and the call sites, and file what changed. | |
| 210 | ||
| 211 | That this is worth doing is already proven: **`SCOPE.md` claims pronouns are | |
| 212 | "not in GraphQL schema", while `AppState` queries `pronouns` and | |
| 213 | `UserProfileView` displays them.** sr.ht shipped it, the doc never caught up, | |
| 214 | and it has been discouraging work that is in fact already done. | |
| 215 | ||
| 216 | [Q2 2026](https://sourcehut.org/blog/2026-05-28-whats-cooking-q2-2026/) alone | |
| 217 | flags two openings: | |
| 218 | ||
| 219 | - **hub.sr.ht gained a writable GraphQL API** for managing projects and project | |
| 220 | resources. Hutch's projects are read-only, and `SCOPE.md` still rules out | |
| 221 | discovery on the grounds that hub has no public API. Both claims need | |
| 222 | rechecking — this may also unblock `mailingListSubscribe`, which Phase 1 left | |
| 223 | out for exactly that reason. | |
| 224 | - **git.sr.ht deploy keys are complete** (`createDeployKey` / `deleteDeployKey` | |
| 225 | are in the SDL). Hutch never calls them. | |
| 226 | ||
| 227 | Start from Q1 2026 forward — that is roughly when the current `Docs/API` dumps | |
| 228 | were captured. | |
| 229 | ||
| 172 | 230 | ### Swift 6 language mode |
| 173 | 231 | |
| 174 | 232 | The project builds in Swift 5 language mode with |
SCOPE.md +5 −1
| @@ -5,7 +5,11 @@ | ||
| 5 | 5 | - Push notifications for builds and tickets (requires a backend relay server) |
| 6 | 6 | - ref: https://git.sr.ht/~ccleberg/hutch-notify |
| 7 | 7 | - Explore / search (hub.sr.ht) (no public discovery API) |
| 8 | - Pronouns on profile (not in GraphQL schema) | |
| 8 | - ~~Pronouns on profile (not in GraphQL schema)~~ — **stale**. sr.ht added | |
| 9 | pronouns (see the Q1 2026 "What's cooking"), and Hutch already queries them in | |
| 10 | `AppState` and shows them in `UserProfileView`. Left here struck through as | |
| 11 | evidence for the ingestion task in ROADMAP.md: this entry spent months telling | |
| 12 | people not to build something that was already built. | |
| 9 | 13 | - Revoke personal access tokens (`@internal` in schema, inaccessible) |
| 10 | 14 | - Archive a message to a list (`archiveMessage` is `@internal`, inaccessible) |
| 11 | 15 | - Ticket activity feed (todo.sr.ht's root `events` query is broken upstream and |