Files
ScadaBridge/code-reviews
Joseph Doherty d39089f4ed docs(code-review): full review at 4307c381 — 18 modules, 67 findings recorded + remediation tracked
Full per-module re-review of the 16 stale modules (last seen 1eb6e97 / 2026-05-28)
plus first-ever reviews of KpiHistory (#26) and ScriptAnalysis (#25), at HEAD 4307c381.

67 new findings (0 Critical, 6 High, 27 Medium, 34 Low). Remediation in commit
fd618cf1 closed 5 of the 6 Highs and ~33 Medium/Low; the rest are Deferred/Won't Fix
with rationale. Remaining pending (4) are all InboundAPI's Database-helper findings
(IA-026 High .. IA-029), left to the active feat/ipsen-movein effort per owner decision.

Highlights: caught a central-only-delivery security drift (SMTP creds broadcast to
sites — DM-025/SR-031), a never-committed 'Resolved' fix (SiteEventLogging-016 → -024),
an unguarded KPI recorder tick (KH-001), a trust-analyzer fallback weakening (SA-001),
and a native-alarm subscribe-path leak (DCL-023). ScriptAnalysis verdict: trust boundary
is semantically sound (symbol-based) in the production cluster config.

README regenerated; regen-readme.py --check passes (4 pending / 567 total).
2026-06-20 18:02:32 -04:00
..

Code Reviews

Comprehensive, per-module code reviews of the ScadaBridge codebase. Each module (one buildable project under src/) has its own folder containing a findings.md. This README is the aggregated index — the single place to see all outstanding work.

Generated by regen-readme.py from the per-module findings.md files. Do not edit by hand — edit the findings files and re-run the script.

How it works

  • Reviews are performed one module at a time against a fixed checklist.
  • Every finding is recorded in the module's findings.md with a severity and status.
  • Findings are never deleted — they are closed by changing their status, keeping a full audit trail.
  • This README aggregates every pending finding (Open / In Progress) across all modules.

See REVIEW-PROCESS.md for the full procedure: the review checklist, severity definitions, finding format, and how to mark items resolved.

Layout

code-reviews/
├── README.md            # this file — process overview + pending findings
├── REVIEW-PROCESS.md     # how to perform a review and track findings
├── regen-readme.py       # regenerates this README from the findings files
├── _template/findings.md # copy-this template for a module review
└── <Module>/findings.md  # one folder per src/ project

Baseline review — 2026-05-16

All 19 modules were reviewed at commit 9c60592 (241 findings: 6 Critical, 46 High, 100 Medium, 89 Low). The tables below track what remains open as findings are resolved and re-triaged; findings discovered after the baseline are appended to their module file and counted in Total.

Severity Open findings
Critical 0
High 1
Medium 1
Low 2
Total 4

Module Status

Module Last reviewed Commit Open (C/H/M/L) Open Total
AuditLog 2026-06-20 4307c381 0/0/0/0 0 16
CLI 2026-06-19 d6ead8ae 0/0/0/0 0 24
CentralUI 2026-06-19 d6ead8ae 0/0/0/0 0 36
ClusterInfrastructure 2026-06-20 4307c381 0/0/0/0 0 15
Commons 2026-06-19 d6ead8ae 0/0/0/0 0 26
Communication 2026-06-20 4307c381 0/0/0/0 0 24
ConfigurationDatabase 2026-06-19 d6ead8ae 0/0/0/0 0 27
DataConnectionLayer 2026-06-20 4307c381 0/0/0/0 0 26
DeploymentManager 2026-06-20 4307c381 0/0/0/0 0 27
ExternalSystemGateway 2026-06-20 4307c381 0/0/0/0 0 26
HealthMonitoring 2026-06-20 4307c381 0/0/0/0 0 25
Host 2026-06-20 4307c381 0/0/0/0 0 26
InboundAPI 2026-06-20 4307c381 0/1/1/2 4 29
KpiHistory 2026-06-20 4307c381 0/0/0/0 0 6
ManagementService 2026-06-19 d6ead8ae 0/0/0/0 0 26
NotificationOutbox 2026-06-19 d6ead8ae 0/0/0/0 0 13
NotificationService 2026-06-20 4307c381 0/0/0/0 0 28
ScriptAnalysis 2026-06-20 4307c381 0/0/0/0 0 8
Security 2026-06-20 4307c381 0/0/0/0 0 25
SiteCallAudit 2026-06-20 4307c381 0/0/0/0 0 9
SiteEventLogging 2026-06-20 4307c381 0/0/0/0 0 27
SiteRuntime 2026-06-20 4307c381 0/0/0/0 0 31
StoreAndForward 2026-06-20 4307c381 0/0/0/0 0 27
TemplateEngine 2026-06-20 4307c381 0/0/0/0 0 25
Transport 2026-06-19 d6ead8ae 0/0/0/0 0 15

Pending Findings

Every Open / In Progress finding across all modules, highest severity first. Resolved findings drop off this list but remain recorded in their module's findings.md (see REVIEW-PROCESS.md §4–§5). Full detail — description, location, recommendation — lives in the module's findings.md.

Critical (0)

None open.

High (1)

ID Module Title
InboundAPI-026 InboundAPI InboundDatabaseHelper gives inbound scripts arbitrary raw SQL (not read-only); contradicts the design doc's "No direct database access" decision and regresses InboundAPI-007

Medium (1)

ID Module Title
InboundAPI-027 InboundAPI InboundDatabaseHelper is sync-over-async and ignores the method-deadline token — thread-pool starvation and an unbounded slow query

Low (2)

ID Module Title
InboundAPI-028 InboundAPI InboundDatabaseHelper has no negative-path tests; Database/WaitForAttribute are not exercised end-to-end through the endpoint
InboundAPI-029 InboundAPI Routed WaitForAttribute is cancelled by the method-level deadline, contradicting spec §6 (wait bounded by the wait timeout, not the method timeout)