2026-04-02 - 2026-10-02
Overview
50 Pull requests merged by 2 users
Merged
#411 [E01-S01-T05] ADR: Kysely containment
Merged
#412 [E01-S01-T06] ADR: React SSR
Merged
#413 [E01-S01-T07] ADR: React/Vite admin
Merged
#407 [E01-S01-T02] ADR: Node/TypeScript
Merged
#410 [E01-S01-T03] ADR: Fastify
Merged
#408 [E01-S01-T04] ADR: PostgreSQL
Merged
#406 [E01-S01-T01] ADR: Modular monolith
Merged
#405 [E00-S05-T01] Implement CI quality baseline (required PR stages)
Merged
#404 [E00-S04-T05] .env.example contains placeholders only
Merged
#403 [E00-S04-T04] No module reads process.env except configuration adapter
Merged
#402 [E00-S04-T03] Secrets automatically redact from logs
Merged
#397 [E00-S04-T02] Missing required setting gives field-specific startup error
Merged
#396 [E00-S04-T01] TypeBox/Ajv schema
Merged
#395 [E00-S03-T06] App does not report ready before migrations complete
Merged
#394 [E00-S03-T05] Migration failure produces structured diagnostic
Merged
#393 [E00-S03-T04] Advisory lock prevents concurrent migration runners
Merged
#392 [E00-S03-T03] Migration ledger created
Merged
#391 [E00-S03-T02] pg/Kysely imports isolated to database-postgres
Merged
#390 [E00-S03-T01] PostgreSQL 18.6 container
Merged
#389 [E00-S02-T08] Secrets are not embedded in image
Merged
#388 [E00-S02-T07] amd64 and arm64 are build targets
Merged
#387 [E00-S02-T06] App root filesystem read-only except mounts/tmpfs
Merged
#386 [E00-S02-T05] App runs non-root
Merged
#385 [E00-S02-T04] DB volume persists across restart/recreate
Merged
#384 [E00-S02-T03] App health endpoint succeeds
Merged
#383 [E00-S02-T02] PostgreSQL health gates app start
Merged
#382 [E00-S02-T01] docker compose up -d starts DB + app
Merged
#381 [E00-S01-T14] No core package imports a concrete extension
Merged
#380 [E00-S01-T13] Clean clone installs with frozen lockfile
Merged
#379 [E00-S01-T12] Root commands exist for build/test/typecheck
Merged
#378 [E00-S01-T11] apps/packages/extensions separated
Merged
#377 [E00-S01-T10] Strict base tsconfig committed
Merged
#376 [E00-S01-T09] TypeScript 6.0.3 exact dependency
Merged
#375 [E00-S01-T08] Node engine restricted to 24.x
Merged
#374 [E00-S01-T07] Commit and lock in pnpm 11.23.0 workspace
Merged
#373 [E00-S01-T06] Document local non-container developer path
Merged
#372 [E00-S01-T05] Add root build/test scripts
Merged
#371 [E00-S01-T04] Add dependency-boundary rule/test
Merged
#370 [E00-S01-T03] Configure ESM package boundaries
Merged
#369 [E00-S01-T02] Implement tsconfig.base.json
Merged
#368 [E00-S01-T01] Create workspace/package manifests
Merged
#20 [Story] Git-ignore local secrets and environment files
Merged
#18 Update .gitea/workflows/ci.yml
Merged
#17 Update .gitea/workflows/ci.yml
Merged
#16 Update .gitea/workflows/ci.yml
Merged
#15 [Story] Newsletter signup (serverless)
Merged
#13 [Story] Update home page intro copy
Merged
#11 [Story] Reading list page
Merged
#9 [Story] Reading list page
Merged
#7 feature/5
51 Issues closed from 3 users
Closed
#193 [E01-S01-T06] ADR: React SSR
Closed
#189 [E01-S01-T02] ADR: Node/TypeScript
Closed
#401 Final Review Assessment for PR #397
Closed
#399 PR Review
Closed
#400 PR #397 Review for Issue #183
Closed
#398 PR Review Comment
Closed
#190 [E01-S01-T03] ADR: Fastify
Closed
#191 [E01-S01-T04] ADR: PostgreSQL
Closed
#409 [security] Review of PR #408 — in progress
Closed
#188 [E01-S01-T01] ADR: Modular monolith
Closed
#187 [E00-S05-T01] Implement CI quality baseline (required PR stages)
Closed
#186 [E00-S04-T05] .env.example contains placeholders only
Closed
#185 [E00-S04-T04] No module reads process.env except configuration adapter
Closed
#184 [E00-S04-T03] Secrets automatically redact from logs
Closed
#183 [E00-S04-T02] Missing required setting gives field-specific startup error
Closed
#182 [E00-S04-T01] TypeBox/Ajv schema
Closed
#181 [E00-S03-T06] App does not report ready before migrations complete
Closed
#180 [E00-S03-T05] Migration failure produces structured diagnostic
Closed
#179 [E00-S03-T04] Advisory lock prevents concurrent migration runners
Closed
#178 [E00-S03-T03] Migration ledger created
Closed
#177 [E00-S03-T02] pg/Kysely imports isolated to database-postgres
Closed
#176 [E00-S03-T01] PostgreSQL 18.6 container
Closed
#175 [E00-S02-T08] Secrets are not embedded in image
Closed
#174 [E00-S02-T07] amd64 and arm64 are build targets
Closed
#173 [E00-S02-T06] App root filesystem read-only except mounts/tmpfs
Closed
#172 [E00-S02-T05] App runs non-root
Closed
#171 [E00-S02-T04] DB volume persists across restart/recreate
Closed
#170 [E00-S02-T03] App health endpoint succeeds
Closed
#169 [E00-S02-T02] PostgreSQL health gates app start
Closed
#168 [E00-S02-T01] docker compose up -d starts DB + app
Closed
#167 [E00-S01-T14] No core package imports a concrete extension
Closed
#166 [E00-S01-T13] Clean clone installs with frozen lockfile
Closed
#165 [E00-S01-T12] Root commands exist for build/test/typecheck
Closed
#164 [E00-S01-T11] apps/packages/extensions separated
Closed
#163 [E00-S01-T10] Strict base tsconfig committed
Closed
#162 [E00-S01-T09] TypeScript 6.0.3 exact dependency
Closed
#161 [E00-S01-T08] Node engine restricted to 24.x
Closed
#160 [E00-S01-T07] pnpm 11.23.0 workspace committed
Closed
#159 [E00-S01-T06] Document local non-container developer path
Closed
#158 [E00-S01-T05] Add root build/test scripts
Closed
#157 [E00-S01-T04] Add dependency-boundary rule/test
Closed
#156 [E00-S01-T03] Configure ESM package boundaries
Closed
#155 [E00-S01-T02] Implement tsconfig.base.json
Closed
#154 [E00-S01-T01] Create workspace/package manifests
Closed
#19 [Story] Git-ignore local secrets and environment files
Closed
#21 security-review-started: PR #20 (feature/19)
Closed
#14 [Story] Newsletter signup (serverless)
Closed
#12 Change content
Closed
#10 [Story] Reading list page
Closed
#8 [Story] Reading list page
Closed
#5 [Story] Contact page
356 Issues created by 1 user
Opened
#5 [Story] Contact page
Opened
#8 [Story] Reading list page
Opened
#10 [Story] Reading list page
Opened
#12 Change content
Opened
#14 [Story] Newsletter signup (serverless)
Opened
#19 [Story] Git-ignore local secrets and environment files
Opened
#21 security-review-started: PR #20 (feature/19)
Opened
#23 [I-02] Extensibility Platform
Opened
#22 [I-01] Publishing Core
Opened
#25 [I-04] Visitor Personalisation
Opened
#24 [I-03] Administration
Opened
#26 [I-05] Operational Simplicity
Opened
#27 [I-06] Extension Ecosystem
Opened
#29 [E01] Architecture governance
Opened
#28 [E00] Repository and runtime foundation
Opened
#31 [E03] Site model
Opened
#30 [E02] Minimal extension runtime
Opened
#33 [E05] Administrator security
Opened
#32 [E04] Blog content
Opened
#34 [E06] Minimal authoring
Opened
#35 [E07] Amber theme and public SSR
Opened
#37 [E09] Home administration
Opened
#36 [E08] Home composition
Opened
#38 [E10] Site identity/navigation/footer
Opened
#40 [E12] Schema-driven extension settings
Opened
#39 [E11] Extension API v1
Opened
#42 [E14] Disable/re-enable safety
Opened
#41 [E13] Extension migrations
Opened
#43 [E15] Theme runtime
Opened
#44 [E16] Theme contract verification
Opened
#46 [E18] Public theme selector
Opened
#45 [E17] Generic visitor preferences
Opened
#47 [E19] First-run setup
Opened
#48 [E20] Backup/restore
Opened
#49 [E21] Export/import
Opened
#51 [E23] Accessibility
Opened
#50 [E22] Upgrade safety
Opened
#53 [E25] Performance
Opened
#52 [E24] Security
Opened
#55 [E29] Media pipeline
Opened
#54 [E26] Failure-mode verification
Opened
#56 [E30] Embeds
Opened
#57 [E31] Native charts and diagrams
Opened
#58 [E00-S01] Workspace bootstrap
Opened
#60 [E00-S03] PostgreSQL adapter and migration runner
Opened
#59 [E00-S02] Docker Compose baseline
Opened
#62 [E00-S05] CI quality baseline
Opened
#61 [E00-S04] Configuration service
Opened
#63 [E01-S01] ADR baseline
Opened
#64 [E02-S01] Extension manifest loader
Opened
#66 [E02-S03] Minimum registries
Opened
#65 [E02-S02] Extension registry
Opened
#67 [E03-S01] Site configuration persistence
Opened
#68 [E04-S01] core.post content-type contribution
Opened
#69 [E04-S02] Content repository/application commands
Opened
#70 [E04-S03] Immutable revisions
Opened
#72 [E05-S01] Administrator bootstrap
Opened
#71 [E04-S04] Initial blocks
Opened
#73 [E05-S02] Opaque DB-backed session
Opened
#75 [E06-S01] Admin application shell
Opened
#74 [E05-S03] CSRF protection
Opened
#76 [E06-S02] Draft editor
Opened
#78 [E07-S01] Theme API v1 minimum
Opened
#77 [E06-S03] Publish action
Opened
#79 [E07-S02] Amber extension (was Node)
Opened
#80 [E07-S03] Article SSR
Opened
#81 [E08-S01] PageComposition persistence
Opened
#82 [E08-S02] Section registry
Opened
#83 [E08-S03] Site intro section
Opened
#84 [E08-S04] Post list section
Opened
#85 [E08-S05] Home SSR
Opened
#86 [E09-S01] Section list/editor
Opened
#88 [E09-S03] Enable/disable
Opened
#87 [E09-S02] Reorder
Opened
#89 [E09-S04] Generic section settings form
Opened
#90 [E10-S01] Edit site identity
Opened
#91 [E10-S02] Navigation CRUD
Opened
#92 [E10-S03] Footer configuration
Opened
#93 [E11-S01] Publish manifest contract
Opened
#94 [E11-S02] Publish extension context
Opened
#95 [E11-S03] Compatibility validator
Opened
#96 [E11-S04] Persist extension state
Opened
#98 [E12-S02] Generic settings admin renderer
Opened
#97 [E12-S01] Persist settings by extension ID
Opened
#99 [E12-S03] Server validation
Opened
#100 [E13-S01] Register migrations
Opened
#101 [E13-S02] Migration lock/transaction
Opened
#102 [E13-S03] Error state
Opened
#103 [E14-S01] Disable extension
Opened
#104 [E14-S02] Missing block fallback
Opened
#105 [E14-S03] Re-enable
Opened
#106 [E15-S01] Complete ThemeRegistry
Opened
#107 [E15-S02] Amber extraction audit (was Node)
Opened
#108 [E15-S03] Theme settings
Opened
#110 [E16-S02] Test Light theme
Opened
#109 [E16-S01] Theme component gallery
Opened
#111 [E16-S03] Theme failure scenarios
Opened
#112 [E29-S01] Upload endpoint and validation
Opened
#114 [E29-S03] core.image end to end
Opened
#113 [E29-S02] Image processing job
Opened
#115 [E29-S04] Video upload and core.video
Opened
#116 [E30-S01] Hardened fetch service (core)
Opened
#117 [E30-S02] Provider allowlist and admin page
Opened
#118 [E30-S03] oEmbed resolution, snapshot cache, click-to-load island
Opened
#119 [E30-S04] CSP frame-src generation from the provider table
Opened
#121 [E31-S02] core.diagram Mermaid server-side rendering
Opened
#120 [E31-S01] core.chart renderers (line, bar, area, scatter)
Opened
#122 [E31-S03] Accessibility contract
Opened
#124 [E17-S02] Preference service
Opened
#123 [E17-S01] Anonymous preference identity
Opened
#125 [E17-S03] Owner theme policy
Opened
#126 [E18-S01] Client island
Opened
#127 [E18-S02] Preference mutation endpoint
Opened
#129 [E18-S04] Disable fallback
Opened
#128 [E18-S03] SSR resolution
Opened
#130 [E19-S01] Detect uninitialised installation
Opened
#132 [E19-S03] Initial site wizard
Opened
#131 [E19-S02] Create administrator
Opened
#133 [E20-S01] Backup procedure/command
Opened
#134 [E20-S02] Restore procedure
Opened
#135 [E20-S03] Automated restore smoke
Opened
#137 [E21-S02] Content/config export
Opened
#136 [E21-S01] Export format v1
Opened
#139 [E21-S04] Missing dependency report
Opened
#138 [E21-S03] Import validation
Opened
#140 [E22-S01] Release manifest
Opened
#141 [E22-S02] Pre-upgrade check
Opened
#142 [E22-S03] Migration recovery documentation
Opened
#143 [E23-S01] Keyboard journey suite
Opened
#146 [E23-S04] Extension accessibility checklist
Opened
#145 [E23-S03] Focus/semantic audit
Opened
#144 [E23-S02] Reduced motion
Opened
#147 [E24-S01] Threat model
Opened
#148 [E24-S02] Rate limits
Opened
#150 [E24-S04] Dependency/security response process
Opened
#149 [E24-S03] CSP/security headers
Opened
#151 [E25-S01] Zero-JS public assertion
Opened
#152 [E25-S02] Query-count regression
Opened
#153 [E25-S03] Reference benchmark
Opened
#154 [E00-S01-T01] Create workspace/package manifests
Opened
#155 [E00-S01-T02] Implement tsconfig.base.json
Opened
#157 [E00-S01-T04] Add dependency-boundary rule/test
Opened
#156 [E00-S01-T03] Configure ESM package boundaries
Opened
#158 [E00-S01-T05] Add root build/test scripts
Opened
#159 [E00-S01-T06] Document local non-container developer path
Opened
#160 [E00-S01-T07] pnpm 11.23.0 workspace committed
Opened
#162 [E00-S01-T09] TypeScript 6.0.3 exact dependency
Opened
#161 [E00-S01-T08] Node engine restricted to 24.x
Opened
#163 [E00-S01-T10] Strict base tsconfig committed
Opened
#164 [E00-S01-T11] apps/packages/extensions separated
Opened
#165 [E00-S01-T12] Root commands exist for build/test/typecheck
Opened
#166 [E00-S01-T13] Clean clone installs with frozen lockfile
Opened
#167 [E00-S01-T14] No core package imports a concrete extension
Opened
#168 [E00-S02-T01] docker compose up -d starts DB + app
Opened
#169 [E00-S02-T02] PostgreSQL health gates app start
Opened
#170 [E00-S02-T03] App health endpoint succeeds
Opened
#171 [E00-S02-T04] DB volume persists across restart/recreate
Opened
#172 [E00-S02-T05] App runs non-root
Opened
#173 [E00-S02-T06] App root filesystem read-only except mounts/tmpfs
Opened
#174 [E00-S02-T07] amd64 and arm64 are build targets
Opened
#175 [E00-S02-T08] Secrets are not embedded in image
Opened
#176 [E00-S03-T01] PostgreSQL 18.6 container
Opened
#177 [E00-S03-T02] pg/Kysely imports isolated to database-postgres
Opened
#178 [E00-S03-T03] Migration ledger created
Opened
#179 [E00-S03-T04] Advisory lock prevents concurrent migration runners
Opened
#180 [E00-S03-T05] Migration failure produces structured diagnostic
Opened
#181 [E00-S03-T06] App does not report ready before migrations complete
Opened
#182 [E00-S04-T01] TypeBox/Ajv schema
Opened
#184 [E00-S04-T03] Secrets automatically redact from logs
Opened
#183 [E00-S04-T02] Missing required setting gives field-specific startup error
Opened
#185 [E00-S04-T04] No module reads process.env except configuration adapter
Opened
#186 [E00-S04-T05] .env.example contains placeholders only
Opened
#187 [E00-S05-T01] Implement CI quality baseline (required PR stages)
Opened
#188 [E01-S01-T01] ADR: Modular monolith
Opened
#190 [E01-S01-T03] ADR: Fastify
Opened
#189 [E01-S01-T02] ADR: Node/TypeScript
Opened
#191 [E01-S01-T04] ADR: PostgreSQL
Opened
#192 [E01-S01-T05] ADR: Kysely containment
Opened
#193 [E01-S01-T06] ADR: React SSR
Opened
#194 [E01-S01-T07] ADR: React/Vite admin
Opened
#196 [E01-S01-T09] ADR: Theme contract
Opened
#195 [E01-S01-T08] ADR: Extension API ownership
Opened
#197 [E01-S01-T10] ADR: Page composition
Opened
#198 [E01-S01-T11] ADR: Visitor preferences
Opened
#199 [E01-S01-T12] ADR: Build-time trusted extensions
Opened
#200 [E01-S01-T13] ADR: Docker Compose
Opened
#201 [E01-S01-T14] ADR: Version/support policy
Opened
#203 [E02-S01-T02] Validates manifest JSON Schema
Opened
#202 [E02-S01-T01] Discovers built-in manifests
Opened
#204 [E02-S01-T03] Globally unique extension IDs
Opened
#205 [E02-S01-T04] Unsupported Extension API rejected
Opened
#206 [E02-S01-T05] Duplicate ID is deterministic startup/activation error
Opened
#207 [E02-S01-T06] Diagnostic identifies package and constraint
Opened
#208 [E02-S02-T01] Implement ExtensionRegistry API
Opened
#209 [E02-S03-T01] Implement minimum registries
Opened
#210 [E03-S01-T01] Values stored and runtime validated
Opened
#212 [E03-S01-T03] Invalid canonical URL rejected
Opened
#211 [E03-S01-T02] Public rendering reads service interface
Opened
#213 [E03-S01-T04] Bootstrap defaults only in bootstrap/config code
Opened
#215 [E04-S01-T02] Core persistence stores registered type without blog branch
Opened
#216 [E04-S01-T03] Unknown/unregistered type cannot be created/published
Opened
#214 [E04-S01-T01] core-blog registers core.post
Opened
#217 [E04-S01-T04] Ownership by extension recorded
Opened
#219 [E04-S02-T02] Slug uniqueness enforced at DB and application layers
Opened
#218 [E04-S02-T01] Implement content commands
Opened
#220 [E04-S02-T03] Public query never returns draft/deleted entry
Opened
#221 [E04-S02-T04] Publish state transition validated
Opened
#222 [E04-S02-T05] Timestamps UTC/TIMESTAMPTZ
Opened
#223 [E04-S03-T01] Edit creates revision
Opened
#225 [E04-S03-T03] Entry points to current revision
Opened
#224 [E04-S03-T02] Revision number unique per content item
Opened
#226 [E04-S03-T04] Transaction prevents orphan/inconsistent current revision
Opened
#228 [E04-S04-T01] Invalid props rejected
Opened
#227 [E04-S03-T05] Prior revision remains readable to admin service
Opened
#229 [E04-S04-T02] Unknown block renders controlled fallback
Opened
#230 [E04-S04-T03] HTML injection attempts remain text
Opened
#231 [E04-S04-T04] Add core.markdown block (v1.1)
Opened
#232 [E05-S01-T01] No universal/default password
Opened
#233 [E05-S01-T02] Password hashed with Argon2id
Opened
#235 [E05-S01-T04] Secret/password never appears in logs
Opened
#234 [E05-S01-T03] Bootstrap per documented first-run path
Opened
#236 [E05-S02-T01] >=256-bit random raw token
Opened
#237 [E05-S02-T02] Only lookup hash stored
Opened
#238 [E05-S02-T03] Secure/HttpOnly/SameSite attributes in production
Opened
#239 [E05-S02-T04] Logout revokes server session
Opened
#240 [E05-S02-T05] Expiration enforced server-side
Opened
#241 [E05-S02-T06] Admin API returns 401 to anonymous caller
Opened
#242 [E05-S03-T01] CSRF protection with test coverage
Opened
#243 [E06-S01-T01] Admin application shell screens
Opened
#244 [E06-S02-T01] Server is source of validation truth
Opened
#245 [E06-S02-T02] Failed validation preserves editor state
Opened
#246 [E06-S02-T03] Successful save can be re-opened
Opened
#247 [E06-S03-T01] Invalid block prevents publish
Opened
#249 [E06-S03-T03] Draft public URL returns 404
Opened
#248 [E06-S03-T02] Duplicate slug returns conflict
Opened
#250 [E06-S03-T04] Publish makes article visible atomically
Opened
#251 [E07-S01-T01] Amber registers via ThemeDefinitionV1
Opened
#252 [E07-S02-T01] Amber tokens live only in theme extension
Opened
#253 [E07-S02-T02] Core renderer contains no Amber branch
Opened
#254 [E07-S02-T03] Amber approximates source design language
Opened
#255 [E07-S03-T01] Server returns article HTML
Opened
#256 [E07-S03-T02] Works with JS disabled
Opened
#257 [E07-S03-T03] Title + metadata + blocks render semantically
Opened
#259 [E07-S03-T05] Missing/draft is 404
Opened
#258 [E07-S03-T04] Canonical URL derived from site/post
Opened
#260 [E07-S03-T06] Quote/code overflow/focus behaviours covered
Opened
#261 [E08-S01-T01] Persist ordered versioned section instances
Opened
#262 [E08-S02-T01] Register core.site-intro and core.post-list
Opened
#265 [E08-S04-T02] Stable newest-first default
Opened
#263 [E08-S03-T01] Site intro section settings
Opened
#264 [E08-S04-T01] Published only
Opened
#266 [E08-S04-T03] Empty state
Opened
#267 [E08-S04-T04] Section uses content query service, not direct DB
Opened
#268 [E08-S05-T01] Home renderer knows section contracts
Opened
#269 [E09-S01-T01] Section list/editor
Opened
#270 [E09-S02-T01] Section reorder
Opened
#271 [E09-S03-T01] Section enable/disable
Opened
#272 [E09-S04-T01] Generic section settings form
Opened
#273 [E10-S01-T01] Edit site identity
Opened
#274 [E10-S02-T01] Navigation CRUD
Opened
#275 [E10-S03-T01] Footer configuration
Opened
#277 [E11-S02-T01] Publish extension context
Opened
#276 [E11-S01-T01] Publish manifest contract
Opened
#280 [E12-S01-T01] Persist settings by extension ID
Opened
#279 [E11-S04-T01] Persist extension state
Opened
#278 [E11-S03-T01] Compatibility validator
Opened
#282 [E12-S03-T01] Server validation
Opened
#281 [E12-S02-T01] Generic settings admin renderer
Opened
#283 [E13-S01-T01] Register migrations
Opened
#284 [E13-S02-T01] Migration lock/transaction
Opened
#285 [E13-S03-T01] Extension migration error state
Opened
#286 [E14-S01-T01] Disable extension
Opened
#287 [E14-S02-T01] Missing block fallback
Opened
#288 [E14-S03-T01] Re-enable extension
Opened
#289 [E15-S01-T01] Complete ThemeRegistry
Opened
#291 [E15-S02-T02] Core packages cannot import Amber extension
Opened
#290 [E15-S02-T01] Amber tokens exist only in theme-amber
Opened
#292 [E15-S02-T03] Bootstrap references Amber ID as initial config only
Opened
#293 [E15-S02-T04] Theme removal/invalid config has fallback
Opened
#294 [E15-S03-T01] Theme settings
Opened
#295 [E16-S01-T01] Theme component gallery
Opened
#296 [E16-S02-T01] Test theme requires no core changes
Opened
#297 [E16-S02-T02] Different body/UI fonts can be used
Opened
#298 [E16-S02-T03] Light background/contrast works
Opened
#299 [E16-S02-T04] Theme selector/resolution recognises both
Opened
#300 [E16-S02-T05] All component-gallery states remain usable
Opened
#301 [E16-S03-T01] Theme failure scenarios fall back safely
Opened
#302 [E29-S01-T01] Reject oversized uploads and forged MIME types
Opened
#303 [E29-S01-T02] Duplicate checksum returns existing record
Opened
#305 [E29-S02-T01] Strip EXIF/GPS from public objects
Opened
#304 [E29-S01-T03] Object keys never contain original filename
Opened
#306 [E29-S02-T02] Derivatives at all applicable widths
Opened
#308 [E29-S03-T01] core.image end to end
Opened
#307 [E29-S02-T03] Original upload bytes never publicly served
Opened
#310 [E29-S04-T02] Non-compliant file rejected with guidance message
Opened
#309 [E29-S04-T01] Compliant MP4 publishes with poster frame
Opened
#312 [E30-S02-T01] Provider allowlist and admin page
Opened
#311 [E30-S01-T01] Hardened fetch service (core)
Opened
#313 [E30-S03-T01] oEmbed resolution, snapshot cache, click-to-load
Opened
#315 [E31-S01-T01] core.chart renderers
Opened
#314 [E30-S04-T01] CSP frame-src from provider table
Opened
#317 [E31-S03-T01] Chart accessibility contract
Opened
#316 [E31-S02-T01] core.diagram Mermaid SSR
Opened
#318 [E17-S01-T01] Created lazily only when preference is set
Opened
#319 [E17-S01-T02] >=256-bit random token
Opened
#320 [E17-S01-T03] One-way lookup hash at rest
Opened
#321 [E17-S01-T04] Expiration supported
Opened
#323 [E17-S01-T06] Corrupt/unknown token ignored safely
Opened
#322 [E17-S01-T05] Cookie contains no personal/theme data
Opened
#324 [E17-S02-T01] Namespaced key validation
Opened
#325 [E17-S02-T02] Schema/policy validation supplied by feature
Opened
#326 [E17-S02-T03] No theme-specific persistence
Opened
#327 [E17-S03-T01] Owner theme policy
Opened
#329 [E18-S02-T01] Preference mutation endpoint
Opened
#328 [E18-S01-T01] Theme selector client island
Opened
#330 [E18-S03-T01] SSR theme resolution
Opened
#331 [E18-S04-T01] Disable fallback
Opened
#332 [E19-S01-T01] Detect uninitialised installation
Opened
#333 [E19-S02-T01] Create administrator (no default credentials)
Opened
#334 [E19-S03-T01] Initial site wizard
Opened
#335 [E20-S01-T01] Backup procedure/command
Opened
#337 [E20-S03-T01] Automated restore smoke
Opened
#336 [E20-S02-T01] Restore procedure
Opened
#339 [E21-S02-T01] Content/config export
Opened
#338 [E21-S01-T01] Export format v1
Opened
#340 [E21-S03-T01] Import validation
Opened
#341 [E21-S04-T01] Missing dependency report
Opened
#342 [E22-S01-T01] Release manifest
Opened
#344 [E22-S03-T01] Migration recovery documentation
Opened
#343 [E22-S02-T01] Pre-upgrade check
Opened
#346 [E23-S02-T01] Reduced motion
Opened
#345 [E23-S01-T01] Keyboard journey suite
Opened
#348 [E23-S04-T01] Extension accessibility checklist
Opened
#347 [E23-S03-T01] Focus/semantic audit
Opened
#349 [E24-S01-T01] Threat model
Opened
#351 [E24-S03-T01] CSP/security headers
Opened
#350 [E24-S02-T01] Rate limits
Opened
#353 [E25-S01-T01] Zero-JS public assertion
Opened
#352 [E24-S04-T01] Dependency/security response process
Opened
#354 [E25-S02-T01] Query-count regression
Opened
#355 [E25-S03-T01] Reference benchmark
Opened
#356 [E26-T01] PostgreSQL unavailable
Opened
#358 [E26-T03] Extension migration failure
Opened
#357 [E26-T02] Core migration failure
Opened
#359 [E26-T04] Duplicate extension ID
Opened
#360 [E26-T05] Invalid settings
Opened
#361 [E26-T06] Missing theme
Opened
#362 [E26-T07] Corrupt visitor cookie
Opened
#363 [E26-T08] Missing block extension
Opened
#365 [E26-T10] Extension activation exception
Opened
#364 [E26-T09] Missing media
Opened
#398 PR Review Comment
Opened
#399 PR Review
Opened
#400 PR #397 Review for Issue #183
Opened
#401 Final Review Assessment for PR #397
Opened
#409 [security] Review of PR #408 — in progress