Study/audit-results/REJECTED_FINDINGS.md

3.6 KiB

Rejected Findings

Findings that were investigated and disproven, or removed as duplicate/stylistic/insignificant, with the reason.

ID Original claim Rejection reason
FE-06 "All /api/* routes are unauthenticated (no middleware, no per-route checks) — curl without a session cookie returns data" Refuted by adversarial review + parent verification. src/proxy.ts IS the compiled Next.js 16 middleware (verified in .next/server/functions-config-manifest.json, middleware.js, and the compiled chunk; build output shows "ƒ Proxy (Middleware)"). It decrypts the iron-session cookie and enforces isAuthenticated + sessionGeneration on every path except /login, /api/auth, /shared, /_next*, /favicon*, and paths containing .. The auditor searched for middleware.ts (the Next 15 name) and missed proxy.ts. The residual truth is the dot-bypass (FIN-09). The claim that "no frontend code handles 401s because there is no auth" is also wrong — there is no 401 because the proxy redirects to /login.
QUIZ-06 (standalone) "Quiz resume with stale question ids crashes the viewer" Merged into FIN-04. The quiz-side path is currently unreachable (no question editing/deletion exists in the app; quiz deletion cascades progress), so it is a latent variant of the same root cause (dead filterAndClampOrder), not a separate live defect.
OPS-02 (original framing) "Fresh-volume deployment crash-loops because migrate deploy fails" Weakened by adversarial review. On a fresh volume prisma migrate deploy succeeds (verified against a temp DB); the fresh-volume failure is FIN-01 (schema drift → app 500s while the container runs). The crash loop requires a secondary trigger (db-push DB, tampering, lock). Reframed as FIN-22 with the crash-loop path demoted.
FE-01 (original severity) Optimistic drag-drop reorder without rollback rated High Severity downgraded to Medium by adversarial review. Mechanics confirmed (fire-and-forget fetch, in-place mutation, origin group omitted from cross-group payload) but impact analysis: sortOrder gaps only, silent divergence self-heals on reload, no visible break for a single user. Merged into FIN-18.
AUTH-06 (standalone) "Cross-class group membership via reorder API exposes another class's content" Merged into FIN-19 (same root cause: groupId/sortOrder never validated server-side). The sharing-exposure angle is recorded as impact of FIN-19.
DBAUD-04 "Relative SQLite path resolution may cause dev dual-DB split-brain" Disproven. CLI (prisma.config.ts) and app adapter both resolve file:./dev.db cwd-relative; predev and the app run from the project root → same file. Docker uses absolute file:/app/data/study.db. Recorded as verified-safe in UNVERIFIED_RISKS.md.
DBAUD-05/06/07, QUIZ-08-verdicts, GRP-01-verdicts (various) "Cascades broken / transactions partial / StudyProgress duplicates via NULL tricks / id regeneration on card edit / XSS via markdown / client-server boundary violations" Disproven by the respective auditors with evidence: FKs enforced by compile default; nested creates implicit-transactional; service-level guards block duplicates; PATCH edits in place (ids preserved); no rehype-raw; no server-module imports in client components. Recorded as verified-safe.
FE-11 (as bug) "Collapsed-groups expand flash" Retained only as Observation (FIN-51) — cosmetic, no data impact.
Various Style preferences, harmless duplication, generic best practices, speculative micro-optimizations, Arcade-only issues Excluded per audit scope rules.