Commit 073fca4510

073fca45103b2cecc6039d3448023d481f5f495b

parent: 2dc1ba46f2

Unsigned

cmc <hello@cleberg.net> · 2026-07-16 06:31 UTC

docs: record the SonarCloud backlog and the What's cooking task

Two additions to Phase 3.

SonarCloud, with the breakdown rather than the headline: 51 open issues are 0
bugs, 0 vulnerabilities and 51 code smells, and 35 of those are hardcoded-URI
warnings against a deep-link mapper's test fixtures and a one-forge client's
endpoint constants. Those want triaging as Won't Fix, not refactoring. The part
worth real thought is the 3 hotspots — the sr.ht token is stored without a
SecAccessControl, so an unlocked phone hands it over, which is a product
decision rather than a lint nit.

Ingesting sr.ht's quarterly "What's cooking" posts, because nothing here tracks
the API's evolution and this repo's assumptions rot silently. Already proven
worthwhile: SCOPE.md claimed pronouns were not in the schema while AppState
queries them and UserProfileView displays them. That entry is struck through and
kept as evidence. Q2 2026 also reports a writable hub.sr.ht API and finished
deploy keys, both of which contradict what is written here.

Layout: unified · split

ROADMAP.md +58
@@ -169,6 +169,64 @@ implies.
169169Labels and hints appear in 17 of 89 view files. Mechanical and low-risk, but it
170170cannot be verified from a build — it needs VoiceOver driven on a device.
171171
172### SonarCloud backlog
173
17451 open issues: **0 bugs, 0 vulnerabilities, 51 code smells**, plus 3 security
175hotspots. The headline number is misleading, so trust the breakdown before
176budgeting:
177
178- **35× `swift:S1075` (hardcoded URI)** — 28 of them in
179 `SourceHutWebDeepLinkMapperTests`, 5 in `Shared/HutchDeepLinkURLs`. A deep-link
180 mapper's tests exist precisely to assert against literal URLs, and a client for
181 one forge has fixed endpoints by definition. These want triaging as *Won't
182 Fix* in SonarCloud, not refactoring. "Fixing" them would make the code worse.
183- **5× `swift:S1135`** — TODO comments. Two are in `HutchIntents` and name real
184 gaps.
185- **3× `swift:S1186` (empty closure)** — all three CRITICAL, all three trivial:
186 `Button("Cancel", role: .cancel) {}` needs no body. A comment settles it.
187- **2× `javascript:S4624`** in the Safari extension; **2× `swift:S1172`** unused
188 parameters.
189
190The 3 hotspots are the part actually worth thought:
191
192- `KeychainHelper:33` and `:80` (**HIGH**) — the token is stored
193 `kSecAttrAccessibleWhenUnlockedThisDeviceOnly` with no
194 `SecAccessControl`, so it does not require biometric or passcode
195 authentication to read. That is a genuine product decision — should a stolen,
196 unlocked phone hand over a sr.ht token? — not a lint nit.
197- `ReadmeView:1922` (**LOW**) — unrestricted WebView navigation. Probably a false
198 positive: `isAllowedReadmeNavigationURL` enforces a scheme allowlist. Verify,
199 then annotate.
200
201Query it with:
202`https://sonarcloud.io/api/issues/search?componentKeys=zerolabsco_hutch&resolved=false`
203
204### Ingest "What's cooking on SourceHut?"
205
206sr.ht posts a quarterly update to `~sircmpwn/sr.ht-announce`, mirrored at
207<https://sourcehut.org/blog/>. Nothing in Hutch tracks it, so the API grows and
208this repo's assumptions quietly rot. Read each quarter's post, diff it against
209`Docs/API`, `SCOPE.md`, and the call sites, and file what changed.
210
211That this is worth doing is already proven: **`SCOPE.md` claims pronouns are
212"not in GraphQL schema", while `AppState` queries `pronouns` and
213`UserProfileView` displays them.** sr.ht shipped it, the doc never caught up,
214and it has been discouraging work that is in fact already done.
215
216[Q2 2026](https://sourcehut.org/blog/2026-05-28-whats-cooking-q2-2026/) alone
217flags two openings:
218
219- **hub.sr.ht gained a writable GraphQL API** for managing projects and project
220 resources. Hutch's projects are read-only, and `SCOPE.md` still rules out
221 discovery on the grounds that hub has no public API. Both claims need
222 rechecking — this may also unblock `mailingListSubscribe`, which Phase 1 left
223 out for exactly that reason.
224- **git.sr.ht deploy keys are complete** (`createDeployKey` / `deleteDeployKey`
225 are in the SDL). Hutch never calls them.
226
227Start from Q1 2026 forward — that is roughly when the current `Docs/API` dumps
228were captured.
229
172230### Swift 6 language mode
173231
174232The project builds in Swift 5 language mode with
SCOPE.md +5 −1
@@ -5,7 +5,11 @@
55- Push notifications for builds and tickets (requires a backend relay server)
66 - ref: https://git.sr.ht/~ccleberg/hutch-notify
77- Explore / search (hub.sr.ht) (no public discovery API)
8- Pronouns on profile (not in GraphQL schema)
8- ~~Pronouns on profile (not in GraphQL schema)~~ — **stale**. sr.ht added
9 pronouns (see the Q1 2026 "What's cooking"), and Hutch already queries them in
10 `AppState` and shows them in `UserProfileView`. Left here struck through as
11 evidence for the ingestion task in ROADMAP.md: this entry spent months telling
12 people not to build something that was already built.
913- Revoke personal access tokens (`@internal` in schema, inaccessible)
1014- Archive a message to a list (`archiveMessage` is `@internal`, inaccessible)
1115- Ticket activity feed (todo.sr.ht's root `events` query is broken upstream and