Commit 073fca4510
Unsigned
Layout: unified · split
ROADMAP.md +58
| @@ -169,6 +169,64 @@ implies. | |||
| 169 | Labels and hints appear in 17 of 89 view files. Mechanical and low-risk, but it | 169 | Labels and hints appear in 17 of 89 view files. Mechanical and low-risk, but it |
| 170 | cannot be verified from a build — it needs VoiceOver driven on a device. | 170 | cannot be verified from a build — it needs VoiceOver driven on a device. |
| 171 | 171 | ||
| 172 | ### SonarCloud backlog | ||
| 173 | |||
| 174 | 51 open issues: **0 bugs, 0 vulnerabilities, 51 code smells**, plus 3 security | ||
| 175 | hotspots. The headline number is misleading, so trust the breakdown before | ||
| 176 | budgeting: | ||
| 177 | |||
| 178 | - **35× `swift:S1075` (hardcoded URI)** — 28 of them in | ||
| 179 | `SourceHutWebDeepLinkMapperTests`, 5 in `Shared/HutchDeepLinkURLs`. A deep-link | ||
| 180 | mapper's tests exist precisely to assert against literal URLs, and a client for | ||
| 181 | one forge has fixed endpoints by definition. These want triaging as *Won't | ||
| 182 | Fix* in SonarCloud, not refactoring. "Fixing" them would make the code worse. | ||
| 183 | - **5× `swift:S1135`** — TODO comments. Two are in `HutchIntents` and name real | ||
| 184 | gaps. | ||
| 185 | - **3× `swift:S1186` (empty closure)** — all three CRITICAL, all three trivial: | ||
| 186 | `Button("Cancel", role: .cancel) {}` needs no body. A comment settles it. | ||
| 187 | - **2× `javascript:S4624`** in the Safari extension; **2× `swift:S1172`** unused | ||
| 188 | parameters. | ||
| 189 | |||
| 190 | The 3 hotspots are the part actually worth thought: | ||
| 191 | |||
| 192 | - `KeychainHelper:33` and `:80` (**HIGH**) — the token is stored | ||
| 193 | `kSecAttrAccessibleWhenUnlockedThisDeviceOnly` with no | ||
| 194 | `SecAccessControl`, so it does not require biometric or passcode | ||
| 195 | authentication to read. That is a genuine product decision — should a stolen, | ||
| 196 | unlocked phone hand over a sr.ht token? — not a lint nit. | ||
| 197 | - `ReadmeView:1922` (**LOW**) — unrestricted WebView navigation. Probably a false | ||
| 198 | positive: `isAllowedReadmeNavigationURL` enforces a scheme allowlist. Verify, | ||
| 199 | then annotate. | ||
| 200 | |||
| 201 | Query it with: | ||
| 202 | `https://sonarcloud.io/api/issues/search?componentKeys=zerolabsco_hutch&resolved=false` | ||
| 203 | |||
| 204 | ### Ingest "What's cooking on SourceHut?" | ||
| 205 | |||
| 206 | sr.ht posts a quarterly update to `~sircmpwn/sr.ht-announce`, mirrored at | ||
| 207 | <https://sourcehut.org/blog/>. Nothing in Hutch tracks it, so the API grows and | ||
| 208 | this repo's assumptions quietly rot. Read each quarter's post, diff it against | ||
| 209 | `Docs/API`, `SCOPE.md`, and the call sites, and file what changed. | ||
| 210 | |||
| 211 | That this is worth doing is already proven: **`SCOPE.md` claims pronouns are | ||
| 212 | "not in GraphQL schema", while `AppState` queries `pronouns` and | ||
| 213 | `UserProfileView` displays them.** sr.ht shipped it, the doc never caught up, | ||
| 214 | and it has been discouraging work that is in fact already done. | ||
| 215 | |||
| 216 | [Q2 2026](https://sourcehut.org/blog/2026-05-28-whats-cooking-q2-2026/) alone | ||
| 217 | flags two openings: | ||
| 218 | |||
| 219 | - **hub.sr.ht gained a writable GraphQL API** for managing projects and project | ||
| 220 | resources. Hutch's projects are read-only, and `SCOPE.md` still rules out | ||
| 221 | discovery on the grounds that hub has no public API. Both claims need | ||
| 222 | rechecking — this may also unblock `mailingListSubscribe`, which Phase 1 left | ||
| 223 | out for exactly that reason. | ||
| 224 | - **git.sr.ht deploy keys are complete** (`createDeployKey` / `deleteDeployKey` | ||
| 225 | are in the SDL). Hutch never calls them. | ||
| 226 | |||
| 227 | Start from Q1 2026 forward — that is roughly when the current `Docs/API` dumps | ||
| 228 | were captured. | ||
| 229 | |||
| 172 | ### Swift 6 language mode | 230 | ### Swift 6 language mode |
| 173 | 231 | ||
| 174 | The project builds in Swift 5 language mode with | 232 | The project builds in Swift 5 language mode with |
SCOPE.md +5 −1
| @@ -5,7 +5,11 @@ | |||
| 5 | - Push notifications for builds and tickets (requires a backend relay server) | 5 | - Push notifications for builds and tickets (requires a backend relay server) |
| 6 | - ref: https://git.sr.ht/~ccleberg/hutch-notify | 6 | - ref: https://git.sr.ht/~ccleberg/hutch-notify |
| 7 | - Explore / search (hub.sr.ht) (no public discovery API) | 7 | - Explore / search (hub.sr.ht) (no public discovery API) |
| 8 | - Pronouns on profile (not in GraphQL schema) | 8 | - ~~Pronouns on profile (not in GraphQL schema)~~ — **stale**. sr.ht added |
| 9 | pronouns (see the Q1 2026 "What's cooking"), and Hutch already queries them in | ||
| 10 | `AppState` and shows them in `UserProfileView`. Left here struck through as | ||
| 11 | evidence for the ingestion task in ROADMAP.md: this entry spent months telling | ||
| 12 | people not to build something that was already built. | ||
| 9 | - Revoke personal access tokens (`@internal` in schema, inaccessible) | 13 | - Revoke personal access tokens (`@internal` in schema, inaccessible) |
| 10 | - Archive a message to a list (`archiveMessage` is `@internal`, inaccessible) | 14 | - Archive a message to a list (`archiveMessage` is `@internal`, inaccessible) |
| 11 | - Ticket activity feed (todo.sr.ht's root `events` query is broken upstream and | 15 | - Ticket activity feed (todo.sr.ht's root `events` query is broken upstream and |