Files
dashcaddy/DC-PRODUCTION-GRADE-BACKLOG.md
T
Hermes f9eaa324dd
CI / Test & Lint (push) Has been cancelled
CI / Security audit (push) Has been cancelled
DC-059: mark done in BACKLOG + DC-PRODUCTION-GRADE-BACKLOG
2026-08-08 15:40:18 -07:00

5.3 KiB

DashCaddy Production-Grade Repair Backlog

Autonomous agent: work through these IN ORDER. Mark each [ ] as [x] when shipped. If an item is too big for one tick, implement a sub-part, push that, and note progress.

P0 — Security & Correctness

  • P0-1: npm audit fix — Done (commit 3a0a5bc, grade A). Resolved 3 high CVEs via minimatch 9.0.9 in webdav transitive. 4 remaining vulns are semver-major-only (sharp→0.35.3, dockerode→5.0.1, nodemailer→9.0.5, uuid→11.1.1) — deferred per backlog note. All 1498 jest tests pass. URN urn:ump:hlju4hixg3tijbghncigm5gesoemupuczrzmkykumh7xbgkq3d2q.
  • P0-2: Command injection in ca.js:210 — Done (commit 66e4460, grade A). Replaced execSync(\openssl pkcs12 ... -password "pass:${password}"`)withexecFileSync('openssl', [..., '-password', `pass:${password}`])`. No shell parsing. All 1498 tests pass.
  • P0-3: Unvalidated req.body in backup config — Done (commit b3488f1, grade A). POST /backups/config now destructures only {backups, defaultRetention} instead of passing req.body wholesale. All 1498 tests pass.
  • P0-4: Asset upload buffer size check — Done (commit 57ed09f, grade A). POST /assets/upload now uses decodeImageData(data) helper which enforces MIME whitelist (png/jpeg/jpg/svg+xml/webp/ico/x-icon) and 5 MB cap. (Prior partial fix had the helper but never wired it.) All 1498 tests pass.
  • P0-5: Error message leaking internals — Done (commit 609ccd3, grade A). apps-revert catch now logs err.message+stack via log.error server-side and returns generic Revert failed to client. All 1498 tests pass.

P1 — Architecture & Input Validation

  • P1-1: Add Joi validation library — Done in commit a667de7 (DC-059, codex-graded B). npm install joi@^18, src/utilities/validate.js exporting validateBody(schema, opts) middleware + 9 schemas (backupConfigUpdate, backupScheduleCreate, backupRestore, backupRestoreFile, appDeploy, appRestore, appRevert, assetUpload, logoUpload). Every exported schema has direct unit tests (41 total in __tests__/unit/validate.test.js) covering middleware semantics — not just schema.validate. Applied to 8 destructive routes: backups (schedule/restore/config), apps (deploy/restore/revert), assets (upload/logo). Used Joi's authoritative CIDR validator (rejects malformed IPv6 like ::::/64 that the previous hex/colon regex would have accepted). 1539/1539 Jest tests pass (was 1498, +41 new). ESLint warnings unchanged (416 total, all pre-existing — zero new introduced).
  • P1-2: Console→logger sweep (update-manager.js) — Replace all 49 console.* calls in src/managers/update-manager.js with structured logger calls. const log = require('../utils/logging') then log.info/warn/error(tag, msg, meta).
  • P1-3: Console→logger sweep (backup-manager.js) — Replace all 36 console.* calls in src/utilities/backup-manager.js with structured logger.
  • P1-4: Console→logger sweep (resource-monitor.js) — Replace all 32 console.* calls in src/managers/resource-monitor.js with structured logger.
  • P1-5: Console→logger sweep (credential-manager.js) — Replace all 20 console.* calls in src/managers/credential-manager.js with structured logger.
  • P1-6: Console→logger sweep (auth-manager.js) — Replace all 20 console.* calls in src/managers/auth-manager.js with structured logger.
  • P1-7: Console→logger sweep (bundled-workflows.js) — Replace all 18 console.* calls in src/recipes/bundled-workflows.js with structured logger.
  • P1-8: Console→logger sweep (remaining files) — Sweep remaining files with < 20 console calls each: crypto-utils.js (16), docker-security.js (15), port-lock-manager.js (16), self-updater.js (10), event-workers.js (5), keychain-manager.js (4), log-digest.js (3), csrf-protection.js (3). One commit for all small files.

P2 — Code Quality & Technical Debt

  • P2-1: Version drift fix — Update VERSION file from 1.14.9 to 1.15.0. Update CLAUDE.md line 247 from 1.13.4 to 1.15.0.
  • P2-2: Delete dead legacy filesgit rm dashcaddy-api/scripts/legacy/comprehensive-test.js dashcaddy-api/scripts/legacy/test-security-fixes.js status/api/test-api.js. Verify zero references first.
  • P2-3: ESLint no-empty fix — Add { allow: 'catch' } to the no-empty rule in .eslintrc.js, OR add // intentionally ignored comments. Goal: npx eslint src/ routes/ exits 0 errors.
  • P2-4: Fix no-useless-escaperoutes/auth/session-handlers.js:39\- inside character class → - (at end of class to avoid range).
  • P2-5: Test handle leaks — Run npx jest --detectOpenHandles --silent 2>&1 | grep -i leak and add teardown (afterEach(() => clearInterval/clearTimeout)) to tests that leave open handles. Focus on totp.routes.test.js (22s) and containers.routes.test.js (28s).
  • P2-6: Refactor config-schema.js validateConfig — Complexity 44 → extract sub-validators for each config section. Behavior-preserving refactor only.
  • P2-7: Refactor middleware.js auth function — Complexity 24, nesting depth 6 → extract auth-logic branches into named helper functions.

Completion Criteria

When all items above are [x], report "All backlog items complete" and stop.