Files
dtf-system/docs/REMEDIATION-2026-09-22.md
2026-09-23 10:40:18 -03:00

12 KiB
Raw Permalink Blame History

DTF remediation register — 2026-09-22

This is the action list for all 37 findings in the September 21 review. That review contains the evidence and severity for each ID. This register includes the September 22 payment review. It is a plan, not evidence that a finding has been closed in production.

Current position: We are in Week 2. The local fixes for foreign-quote order disclosure and approval without a verified amount are implemented and tested, but are not committed or deployed. The first order-correctness slice now covers parts of findings 2, 5–8, and 11; see the progress note below. The remaining work and production verification stay open. Payment webhook work is partial progress on finding 31, not completion of real payments.

Local progress, 2026-09-22: Browser and API regressions covered stale editor items, DPI refusal and warning acknowledgement, changed-cart quote actions, oversized width, and finals invalidated by a later correction. A versioned per-file source specification survived quote review into the order snapshot. At that point exact placement coordinates and a generated print file were still missing. None of these changes is a production release.

Local progress, 2026-09-23: Specification v2 adds per-copy film coordinates, validates every copy and the quote height, and keeps a downloadable layout manifest in the approved order. The board now pages pending and approved unpaid quotes; a local regression reached all 105 pending and 22 approved fixture quotes. Final print-file generation, completed-order search, and quote cancellation/expiry lifecycle remain open.

Operational progress, 2026-09-23: Finding 23's entrypoints are repaired locally. The staging gate passed in a network-disabled image with non-secret fixture data; ops.security_status ran in the API image and correctly reported stale local signatures; ops.backup create-and-verify restored database counts and 78 clean objects in isolated temporary targets; the production API image built and imported ops. This verifies the commands, not production offsite recovery (finding 30) or a fresh scanner (finding 17).

Quality progress, 2026-09-23: Findings 9 and 10 are partly repaired: failed image decoding blocks checkout, mixed analyzed/manual sheets stay at table price, and rotated DPI uses the correct pixel axis. PDF measurement now uses the PDF.js page model with effective crop, rotation, UserUnit and page count; invalid or multi-page files block quoting. The same-origin PDF worker and isolated browser checks pass. Unsupported image operators, representative print-file evidence and final printability remain open.

Upload progress, 2026-09-23: The API and customer picker now reject files above the effective ClamAV stream limit before transfer, and the session advertises that limit. Unfinished reservations have a one-hour lease and a customer/operator cancel endpoint; owner-scoped cancellation has an integration check. Quota remains reserved until the object is actually purged, so a failed cleanup cannot admit unaccounted storage. PDF rendering now destroys the parser job when its timeout fires, covered by a browser check. This closes the misleading upload-then-quarantine path locally but does not satisfy the agreed large-file capability in finding 3. A tested large-file scan/release design, stronger anonymous admission controls (finding 16), and remaining browser resource bounds (finding 12) are still required.

Gates

Gate Meaning
W2 Fix during Week 2 before calling the corresponding client workflow complete. These defects can be worked on while provider contracts are clarified.
Upload Resolve before inviting the public to upload customer artwork.
Paid Resolve before enabling live checkout or accepting a real paid order.
Release Resolve before declaring the deployed production system ready.
Incremental Improve alongside feature work; it does not justify a standalone rewrite.

The gates are cumulative: a live release must pass W2, Upload, Paid, and Release checks. Decisions labelled business require an agreed product rule; engineering can build and test the surrounding flow in parallel. Where a deployment risk is conditional, verify the actual topology and document the result before closing it.

Complete finding-to-action map

Review ID Gate Required action and closure evidence
1 Paid Implement real payment, freight, ERP, and notification adapters with sandbox acceptance and reconciliation; remove fake adapters from the live path.
2 W2 Store a versioned per-file production specification and approved layout on quote and order; prove the factory can reproduce the purchased job.
3 Upload; business Agree the advertised maximum and implement a scan/release path that actually supports it; reject unsupported sizes before transfer.
4 W2 Give quotes an explicit lifecycle and paginated/searchable operator view; verify the 101st actionable quote remains visible.
5 W2 Invalidate or revision-bind finals when a new correction arrives; test a correction submitted after a final was uploaded.
6 W2 Make quality eligibility a checkout gate and store any required acknowledgement against the artwork revision.
7 W2 Clear the current cart item immediately when artwork is removed or becomes invalid; test the submitted payload.
8 W2 Bind checkout to an immutable quoted cart snapshot; require re-quote after any material edit, including same-price edits.
9 W2 Measure PDF pages through the parser's page model; handle every supported page or reject multi-page/unsupported geometry explicitly.
10 W2 Require quality evidence per billable source; make undecodable/unknown sources explicit and correct rotation-sensitive DPI calculations.
11 W2 Validate physical dimensions before packing; never silently scale a requested print size.
12 Upload Bound browser decoding, copy count, PDF work, and preview size; cancel obsolete work and test representative large inputs.
13 Paid Capture and validate a full delivery-address snapshot, then connect it to freight quote and order fulfilment.
14 Paid; business Set written auto-approval rules and manual-exception criteria; prove eligible orders can complete after hours without an operator.
15 W2; business Define accepted print output, generate it from the approved versioned layout, and compare produced geometry/metres with the quote. If scope changes, update the client commitment and site claims explicitly.
16 Upload Limit anonymous reservation capacity and lifetime; add cancellation and cleanup, then test quota-exhaustion behavior.
17 Upload Update ClamAV signatures on a controlled schedule; surface signature age and fail the intake gate when stale.
18 Release Trust only the actual proxy hop, restrict origin access, and test real client IP/rate limits through the deployed Swarm topology.
19 Release Wire file-backed secrets into the active stack; give each service only necessary credentials and remove unused bootstrap secrets.
20 Release Recheck operator active atomically when issuing and using sessions; test disable-versus-login concurrency and document password-change session policy.
21 Paid Provide email verification and customer recovery/guest continuity, and make checkout's account-creation claim match reality.
22 Release; business Agree retention/export/deletion rules for profiles, quotes, orders, payloads, artwork, and backups; implement and verify them.
23 W2 Repair staging, backup, and security commands after the directory move; smoke-test them in the images and Compose files actually shipped.
24 Release Set and test PostgreSQL node placement/persistence for the intended Swarm size, plus recovery after host failure.
25 Release Scan before promotion, publish immutable paired API/web image identities, and deploy exactly the scanned release.
26 Release Make preflight enforce the active stack contract and provider behavior; verify Portainer/deployment convergence after promotion.
27 Release Run browser tests in a network where signed storage URLs work; fail CI when Chrome or the test endpoint is unavailable.
28 Release Isolate each CI Compose project, ports, networks, and volumes; serialize release promotion and test overlapping runs.
29 Release Separate liveness/readiness, monitor provider backlog, cleanup, scanner freshness and backup age; test alert routing and rollback acceptance.
30 Release; business Set recovery objectives, make consistent encrypted offsite backups, and rehearse restore of database plus required live artwork.
31 Paid Finish durable payment intent, idempotent webhook handling, status/refund rules, reconciliation, and ordered outbox/dead-letter recovery; test provider-success/database-failure cases. Signed event work is only partial progress.
32 Upload Bound upload concurrency, decouple upload from scan waiting, measure queue latency, and distinguish transient scan errors from rejected content.
33 Release Introduce ordered schema migrations and core constraints/relationships; test both clean install and upgrade from the existing schema.
34 Incremental Replace shared mutable browser cart state as part of IDs 2/7/8; then extract reusable business operations from routes and add bounded DB connection management where load measurements warrant it.
35 Release Add representative artwork, real PDF, failure/retry, migration, operational-command, and exact-release acceptance tests.
36 W2 Correct executable setup/Portainer/security instructions and PDF generator paths; check generated output against current scope.
37 Release Inventory and scan every deployed image and vendored asset, pin release dependencies, and set a controlled refresh process. Do not describe the existing PDF.js advisory as a proven exploit.

Execution order

  1. Correct the customer/order model now: IDs 2, 4–11, 23, and 36. Keep an immutable quote revision through payment, production output, and correction approval. Close each defect with a focused regression test and a real artwork example where geometry matters.
  2. Set the missing product rules while coding continues: IDs 3, 14, 15, 22, and 30. Obtain representative files, accepted print format, auto-approval thresholds, retention rules, recovery objectives, and provider sandbox access. Do not collect credentials in this document.
  3. Make public intake safe: IDs 3, 12, 16, 17, and 32. Test the declared upload size end to end, including scan, release, quota, browser memory, and timeout behavior.
  4. Complete live commerce: IDs 1, 13, 14, 15, 21, and 31. Build freight/address, payment/reconciliation, ERP, and notification flows; test duplicates, outages, refunds, and human exceptions in provider sandboxes.
  5. Prove the deployed system: IDs 18–20, 22, 24–30, 33, 35, and 37. Run the exact images and stack, exercise migration, backup/restore, monitoring, secrets, CI and release rollback. Improve ID 34 as the affected areas are changed.

Who supplies what

  • Engineering: implement and test the code, schema, operational commands, CI gates, provider adapters, and recovery runbooks; gather evidence for each closure. This work can start with the order/cart defects without waiting for provider access.
  • Business/client: approve unattended-pricing exceptions, final print-file format and samples, the real maximum file size, shipping services and policy, privacy retention, and recovery objectives. The detailed worksheet is production inputs.
  • Provider/operations owners: supply sandbox accounts and configuration through the approved secret channel, plus the real deployment topology, backup destination, alert recipients, and release/rollback ownership. No credentials belong in this register or the repository.

Closure rule: A checkbox or passing mocked flow is insufficient. For each ID, keep the original evidence, record the implemented change and test, then verify in the environment that carries the risk. The working roadmap tracks Week 2 delivery status; this register tracks the full defect disposition.