Skip to content

audit: cora scan v0.9.0 — 26 MAJOR findings triaged as backlog #237

Description

@ajianaz

What

Full cora scan on develop @ e9706b7 (pre-tag v0.9.0): 213 files, 292 findings (26 MAJOR, rest MINOR/INFO). Per release policy, MAJORs that are not v0.9.0 regressions and not broken-by-default regressions are triaged to this tracking issue instead of blocking the release.

Verified false positive (removed from blocker list)

  • Dockerfile:38 "ENTRYPOINT references index.js but adapter-node emits server/index.js" — bun run index.js resolves /app/index.js, which exists at the root of the copied build/ dir and is the adapter-node entry shim that imports ./server/index.js. This exact Dockerfile produced the working v0.7.x/v0.8.0 GHCR images.

MAJOR backlog

Docs accuracy

  • README MCP section claims 17 tools (changelog ships 30–34); missing ?confirm=true on account delete; schema section outdated (8 tables / 4 migrations); missing newer endpoints (/ready, /metrics, /api/health, trends)
  • docs/deployment.md: shell substitution in .env example; Caddyfile header_up outside reverse_proxy; backup scripts target named volume vs bind mount mismatch
  • DESIGN.md: stale schema/limits descriptions (plaintext tokens, no CASCADE, mixed timestamps — several already fixed in code by fix(core): canonicalize mention/comment timestamps to RFC3339 UTC #229)

Security hardening

  • OAuth callback does not validate state parameter (web/src/routes/auth/callback); auth-flow docs omit state/PKCE
  • TITEN_COOKIE_SECURE defaults to false + token encryption off by default in docker-compose (documented dev default; consider deriving from APP_URL scheme, rungu pattern)
  • /metrics registered outside auth middleware (always public)
  • API key accepted via ?api_key= query string (docs + README)
  • install.sh: binaries installed without checksum verification; PATH fallback writes .bashrc unread by zsh

Correctness

  • web/src/routes/admin/mentions: reply posted from currently selected account, not the mention's account
  • web/src/routes/admin/settings: form shows defaults while loading; save can overwrite server config
  • web/src/routes/admin/schedules: loadMore lacks stale-response guard; triple initial fetch from loaded flag
  • web/src/routes/admin/accounts: empty Expires At crashes with Invalid Date; avatar placeholder crashes without username
  • docker-compose: web port always published to host (bypasses Traefik TLS when fronted)
  • titen-cli: URL query/path interpolation without percent-encoding; response parsed before HTTP status check; pre-restore backup misses WAL

Why

Full scan output kept at release time; items are real but none is a v0.9.0 regression. Each PR merged into v0.9.0 passed the per-PR Cora Review check cleanly.

Testing

  • Triage per-item when picked up; verify against current develop before fixing (some may already be fixed)

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions