Skip to content

chore(docs): delete the findings inbox, audit every tripwire, and drop stale allowlist headroom - #142

Merged
kilianmc merged 1 commit into
devfrom
chore/triage-findings-inbox
Sep 9, 2026
Merged

kilianmc merged 1 commit into
devfrom
chore/triage-findings-inbox

Conversation

@kilianmc

@kilianmc kilianmc commented Sep 9, 2026

Copy link
Copy Markdown
Owner

What this does

Three things Kilian asked for, plus the triage the first one implied.

1. The ## Findings inbox is deleted

It staged a finding until the next promotion to main — which ties triage to an event weeks away while nothing re-checks a staged line, so it accumulates claims that have stopped being true. One of the five lines it held described a gap that the PR which surfaced it had already closed: #141 stripped 1,657 comment lines from the stylesheets and shipped the .scss budget guard in the same commit, while the line above it still said .scss was unguarded.

The rule is now one line in the header, next to "To add a line here, archive one": a finding is triaged the moment it is found — GUARD, TRIPWIRE, ARCHIVE or DELETE — and there is nowhere to stage one.

The five staged findings, each routed to exactly one destination:

Finding Disposition
/api/sessions/completion discards its last session when the row count lands exactly on the cap filed as a register issue (confirmed real)
blanked-dev-server recovery needs Vite restarted with .vite deleted tripwire, folded into the existing line as a clause — no new bullet
.scss outside the prose budget deleted — stale, already guarded by #141
JournalResponse.trends has no client reader added to the unused-columns sweep as a wire field (no migration)
the web suite's settle() races any second read filed as a register issue, 40 call sites

2. Tripwires audited: 104 → 103 bullets

Only one bullet was genuinely deletable — the gitleaks line. Its digest clause duplicated the stronger openapi-sha256 phrasing that survives at CLAUDE.md:42, and its useDefault clause is asserted at tests/test_gitleaks_config.py:32 with a failure message that states the rule in words.

Three further clauses were trimmed because a test already enforces them. In each case the test was rewritten to own the rule rather than cite the prose being deleted — pwaContract.test.ts opened "Four PWA properties CLAUDE.md records", which the trim would have turned into a lie, so its four reasons moved into the it() names (code, and uncapped) and ABSENT_PATHS now carries its own reason.

Four false claims repaired in lines that stayed:

  • set_index meant two different things. The line described the whole logged session's 1..N ordinal — true of logged_set, and not of prescribed_set, which is block-scoped by UniqueConstraint("session_block_id", "set_index"). A reader editing prescribed_set would have been wrong.
  • A diagnostics header allowlist was asserted in the present tense and does not exist. x-vercel-oidc-token appears nowhere in source; the only header reads are authorization and x-forwarded-for, neither reflected back. The prohibition stays, now as a conditional obligation.
  • _sizes.scss was cited for px-to-rem arithmetic that c95e03a stripped.
  • One archive pointer did not grep-resolve, so the header's "grep the archive by the heading named on the tripwire line" instruction dead-ended. All 96 pointers across 87 bullets now resolve as literal substrings of real headings.

Seven bullets were tempting and deliberately kept — three restatements of the position: fixed ban are setups for different prohibitions, and the CORS and maxDuration pairs are one invariant stated from both ends, in two files an agent would never read together.

3. Allowlist: no row was stale, but the limit field was

No row is deletable, and that is provable rather than a judgement. The arm at test_comment_budget.py:511 fails on any entry covering a comment now within its cap, and it is green — so every one of the rows is load-bearing. Exact duplicates: 0. Dead anchors: 0. Rows naming a deleted file: 0.

What was stale is limit, which no arm checks. The file's convention is limit == span, and 41 rows deviated, carrying headroom that licensed silent regrowth — three useSessionRun.ts blocks of 3, 5 and 9 lines were all pinned at limit = 26, a ceiling copied from the largest. All lowered to their measured span.

One further row was orphaned by the PWA trim and deleted: 1,279 → 1,278 entries. BASELINE stays 972 and BASELINE_RATCHET needs no move, because no backlog row was removed — slack is unchanged at 10 against the arm's cap of 25.

Verification

npm run check green — 1430 server (ruff clean, mypy clean on 114 files) and 1502 web across 62 files.

The .scss guard was shown to bite: a 3-line comment injected into _diary.scss produced slash_run (style tier) 3 lines > cap 0, then restored.

Notes

🤖 Generated with Claude Code

…p stale allowlist headroom

The `## Findings inbox` section is gone (Kilian). It staged a finding until the next
promotion to `main`, which ties triage to an event weeks away while nothing re-checks a
staged line — so it accumulates claims that have stopped being true. One of the five lines
it held described a gap that the very PR which surfaced it had already closed: #141 stripped
1,657 comment lines from the stylesheets *and* shipped the `.scss` budget guard in the same
commit. The rule is now one line in the header: a finding is triaged the moment it is found.

The five staged findings, each routed:
- the `/api/sessions/completion` off-by-one at the row cap -> filed as a register issue
- the blanked-dev-server recovery -> folded into the existing tripwire as a clause
- `.scss` outside the prose budget -> DELETED, already guarded by #141
- `JournalResponse.trends` having no reader -> added to the unused-columns sweep
- the web suite's `settle()` race -> filed as a register issue

Tripwires audited, 104 -> 103 bullets. One deletion: the gitleaks bullet, whose digest
clause duplicated the stronger `openapi-sha256` phrasing and whose `useDefault` clause is
asserted by `tests/test_gitleaks_config.py`. Three further clauses trimmed because a test
already enforces them, and in each case the test was rewritten to own the rule rather than
cite the prose being deleted — `pwaContract.test.ts` opened "Four PWA properties CLAUDE.md
records", which the trim would have made false, so its four reasons moved into the `it()`
names and `ABSENT_PATHS` now carries its own.

Four false claims repaired in lines that stayed. `set_index` was described as the whole
logged session's ordinal, which is true of `logged_set` and NOT of `prescribed_set`, where
it is block-scoped by `UniqueConstraint("session_block_id", "set_index")`. A diagnostics
header allowlist was asserted in the present tense and does not exist. `_sizes.scss` was
cited for arithmetic that c95e03a stripped. One archive pointer did not grep-resolve.

The allowlist had no deletable row, and that is provable rather than a judgement: the arm at
`test_comment_budget.py:511` fails on any entry covering a comment now within its cap, and
it is green, so all rows are load-bearing. What was stale is the `limit` field, which no arm
checks — 41 rows carried headroom above their measured span, licensing silent regrowth
(three `useSessionRun.ts` blocks of 3, 5 and 9 lines were all pinned at 26). Lowered to
span. One further row was orphaned by the PWA trim and deleted, so 1,279 -> 1,278 entries.
BASELINE stays 972 and `BASELINE_RATCHET` needs no move: no backlog row was removed.

`npm run check` green: 1430 server, 1502 web across 62 files.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@vercel

vercel Bot commented Sep 9, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
climb-trainer Ready Ready Preview Sep 9, 2026 4:39pm UTC

@kilianmc
kilianmc merged commit b7da079 into dev Sep 9, 2026
5 checks passed
@kilianmc
kilianmc deleted the chore/triage-findings-inbox branch September 9, 2026 16:41

This branch was successfully deployed

1 active deployment
Preview — 17ded2df Deployed Sep 9, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant