Skip to content

docs: land the 2026-08-05 codebase audit report - #401

Merged
arzafran merged 2 commits into
mainfrom
docs/audit-2026-08-05
Aug 5, 2026
Merged

arzafran merged 2 commits into
mainfrom
docs/audit-2026-08-05

Conversation

@arzafran

@arzafran arzafran commented Aug 5, 2026

Copy link
Copy Markdown
Member

What this does

Lands the adversarial codebase audit run on 2026-08-05, plus the changelog entry for it and for #372.

The report found 8 high, 13 medium, 11 low and one info finding, now filed as #373-#400. Seven area auditors read their surfaces in full, a cross-model pass verified the finding list, and team-knowledge reconciliation ran after the findings existed so a documented decision could reclassify a finding's severity without silently deleting it.

It also carries a correction about itself: the draft-mode surface the report listed as sound was not, and #372 fixed a real bug there hours later. Section 10 says so and names why the pass missed it — every auditor asked what a route handler does when called, none asked who else can call it.

Summary

Test Plan

  • bun run check, expect exit 0 (473 tests pass) — docs-only change, no code touched

Copilot AI review requested due to automatic review settings August 5, 2026 15:24
@vercel

vercel Bot commented Aug 5, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
satus Ready Ready Preview Aug 5, 2026 4:23pm

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Adds the 2026-08-05 adversarial codebase audit report to the repo and records both the audit and the related draft-mode prefetch fix (#372) in the changelog.

Changes:

  • Added the full audit report at docs/audits/codebase-audit-2026-08-05.md (including post-publication corrections in §10).
  • Updated CHANGELOG.md with a Fixed entry for #372 and a Documentation entry referencing the new audit.

Reviewed changes

Copilot reviewed 2 out of 2 changed files in this pull request and generated 1 comment.

File Description
docs/audits/codebase-audit-2026-08-05.md New audit report document (findings + system map + corrections).
CHANGELOG.md Changelog entries for #372 and for the 2026-08-05 audit report.
Suppressed comments (2)

docs/audits/codebase-audit-2026-08-05.md:25

  • In the summary table, sanity/env.ts:29-32 appears to be a shortened path, but other entries use full paths (e.g. lib/integrations/sanity/...). Using the real path (lib/integrations/sanity/env.ts) improves consistency and avoids confusion.
| H4  | High   | Sanity     | `SANITY_STUDIO_PROJECT_ID`-only config breaks frontend AND `/studio` (hydration 404)               | `lib/utils/validation.ts:22-29`, `sanity/env.ts:29-32`                      | CONFIRMED (scenario corrected by Codex) |

docs/audits/codebase-audit-2026-08-05.md:52

  • The summary table references sanity/queries.ts:39, but the file lives at lib/integrations/sanity/queries.ts. Using the correct path makes this finding easier to locate.
| L10 | Low    | SEO        | Dead exports: `articleSchema`/`breadcrumbSchema`/`articleQuery` have zero callers                  | `lib/seo/schemas.ts:55-93`, `sanity/queries.ts:39`                          | CONFIRMED                               |

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread docs/audits/codebase-audit-2026-08-05.md Outdated

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 2 out of 2 changed files in this pull request and generated no new comments.

Suppressed comments (2)

CHANGELOG.md:120

  • This line says the audit findings were "filed as #373–#400". That issue range contains 28 issues, but the same sentence also states the audit has 33 findings (8+13+11+1). If multiple findings are grouped into single issues, rephrase to avoid implying a 1:1 mapping between finding count and issue count.
- Adversarial codebase audit, 2026-08-05 (`docs/audits/codebase-audit-2026-08-05.md`): 8 high, 13 medium, 11 low, one info, filed as #373–#400. Seven parallel area auditors read their surfaces in full with a bounded cross-model verify pass over the finding list; team-knowledge reconciliation ran after the findings existed so documented decisions could reclassify severity without suppressing anything. The report carries a post-publication correction: the draft-mode surface it listed as sound was not, and #372 fixed it hours later — the audit asked what each route handler does when called, never who else can call it.

CHANGELOG.md:116

  • This new changelog bullet is a single very long line. The surrounding entries wrap long bullets across multiple indented lines, which is easier to review and reduces noisy diffs when future edits happen. Consider wrapping this bullet to match the existing style (continuation lines indented by two spaces).
- Draft-mode previews stop losing their session to a prefetch. The "Disable Draft Mode" pill was a prefetching `Link`, so the router's speculative fetch of `/api/draft-mode/disable` ran the handler and deleted the draft cookies out from under an open preview; reloads only sometimes recovered because it was a race. The route now answers prefetch/RSC fetches with 204 and disables only on a real document navigation (the cross-site 403 guard runs first, so a cross-site request still gets 403 whatever headers it carries), the pill renders only in a conclusively standalone context — the visual-editing hook falls back to `standalone` after 1s when the Presentation handshake is slow, so iframe and popup contexts stay hidden regardless — and the pill is a plain anchor rather than the prefetching primitive. (#372)

@arzafran
arzafran merged commit d9d9f30 into main Aug 5, 2026
13 checks passed
@arzafran
arzafran deleted the docs/audit-2026-08-05 branch August 5, 2026 16:31

This branch was successfully deployed

1 active deployment
Preview — e9d39fec Deployed Aug 5, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants