docs: complete XML-doc coverage and strip internal tracking IDs from code comments
Resolve all CommentChecker findings across the gateway server, worker, tests, and .NET client (314 -> 0 real issues): add missing <returns>/<summary>/<param> on public and test members, convert Stream/interface overrides to <inheritdoc/>, and remove internal task/issue tracking IDs (SEC-*, IPC-*, WRK-*, GWC-*, TST-*, Client.Dotnet-*) from shipped code documentation while preserving the design rationale prose. Shipped comments should not carry internal bookkeeping, and complete XML docs keep the analyzer/TreatWarningsAsErrors gate and generated API docs clean. The 6 remaining flags are heuristic false positives (MD5, UTC-4, capacity-1, near-1601) left intact so real documentation is not corrupted. Claude-Session: https://claude.ai/code/session_01DMXXvNuPekkkrTEyPNxEkW
This commit is contained in:
@@ -41,7 +41,7 @@ public static class GatewayApplication
|
||||
app.UseStaticFiles();
|
||||
app.UseAuthentication();
|
||||
app.UseAuthorization();
|
||||
// SEC-11: the rate limiter must run after routing has selected the endpoint (so its
|
||||
// The rate limiter must run after routing has selected the endpoint (so its
|
||||
// RequireRateLimiting policy metadata is visible) and before the endpoint executes.
|
||||
app.UseRateLimiter();
|
||||
app.UseAntiforgery();
|
||||
@@ -105,7 +105,7 @@ public static class GatewayApplication
|
||||
return builder;
|
||||
}
|
||||
|
||||
// SEC-11: register the named fixed-window rate-limiter policy applied to POST /auth/login. The
|
||||
// Registers the named fixed-window rate-limiter policy applied to POST /auth/login. The
|
||||
// limit knobs are read from MxGateway:Security at startup; the per-request partition is keyed on
|
||||
// the remote IP (see DashboardEndpointRouteBuilderExtensions.GetLoginRateLimitPartition).
|
||||
private static void AddLoginRateLimiter(WebApplicationBuilder builder)
|
||||
|
||||
Reference in New Issue
Block a user