Audit: one action = one route (DESIGN §41) across web, CLI, WebMCP; MCP later #175

Open
opened 2026-09-26 14:05:52 +00:00 by kayg · 2 comments
Owner

Owner rule 2026-09-26 (DESIGN §41). Inventory every user action (create/edit/move/delete log entry, note, task, file, folder, share, tag, settings, search...) and every server route. For each action there must be exactly one route; the web UI, the calternal CLI (crates/calternal-cli), and WebMCP tools (apps/web/src/lib/webmcp, #160) must call it. Find duplicates (two endpoints writing the same thing, a CLI-only or UI-only write path, permission checks done in an adapter instead of the route), merge them into one route, move all authorization/validation/rate limits onto the route, and delete the extra paths with their tests moved over. Add a test that lists the OpenAPI operations and fails if a write operation has no single owner action (table in code). The MCP server itself is not in scope (later); leave a note of which routes it will call. Security: every merged route gets adversarial probe coverage. Report a before/after action→route table.

Owner rule 2026-09-26 (DESIGN §41). Inventory every user action (create/edit/move/delete log entry, note, task, file, folder, share, tag, settings, search...) and every server route. For each action there must be exactly one route; the web UI, the calternal CLI (crates/calternal-cli), and WebMCP tools (apps/web/src/lib/webmcp, #160) must call it. Find duplicates (two endpoints writing the same thing, a CLI-only or UI-only write path, permission checks done in an adapter instead of the route), merge them into one route, move all authorization/validation/rate limits onto the route, and delete the extra paths with their tests moved over. Add a test that lists the OpenAPI operations and fails if a write operation has no single owner action (table in code). The MCP server itself is not in scope (later); leave a note of which routes it will call. Security: every merged route gets adversarial probe coverage. Report a before/after action→route table.
Author
Owner

Starting route audit on branch job/route-audit. Base SHA: 6e1e565603. I have read CLAUDE.md, CONTEXT.md, and DESIGN.md §41 plus the auth scope rules in §21. I am inventorying the action-to-route mappings before code changes.

Starting route audit on branch job/route-audit. Base SHA: 6e1e5656036eaeb060df3089043519aab2066376. I have read CLAUDE.md, CONTEXT.md, and DESIGN.md §41 plus the auth scope rules in §21. I am inventorying the action-to-route mappings before code changes.
Author
Owner

Finding: sign-out has two routes for one action. Web calls DELETE /api/v1/auth/session from apps/web/src/routes/+layout.svelte; CLI calls DELETE /api/v1/auth/cli/session from crates/calternal-cli/src/remote_commands.rs. Both handlers revoke only the calling session in crates/calternal-auth/src/api.rs. The baseline action-to-route catalog is committed as 048d05de.

Finding: sign-out has two routes for one action. Web calls DELETE /api/v1/auth/session from apps/web/src/routes/+layout.svelte; CLI calls DELETE /api/v1/auth/cli/session from crates/calternal-cli/src/remote_commands.rs. Both handlers revoke only the calling session in crates/calternal-auth/src/api.rs. The baseline action-to-route catalog is committed as 048d05de.
Sign in to join this conversation.
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
kayg/calternal#175
No description provided.