September 23 review disposition

This records Lako's review against the candidate release, not a claim that production has changed. The original feedback was a Slack DM to Adam on September 23, 2026. No merge/deploy follows from local verification alone.

FeedbackDispositionEvidence / limitation
Very large PR; normally splitIntentionally not splitting the architectural rewrite retroactivelySeparate coherent remediation commits and this disposition make review tractable. Lako accepted the large breaking change; independent app ownership remains an architectural boundary.
Three reported vulnerabilitiesRuntime dependency fixes implemented; residual dev findings disclosedNext/React and compatible dependencies updated. Recorded production audit: zero. Full audit retains nine development-only Solana reference-test findings (three high, six moderate); not described as all vulnerabilities patched.
Persist organization/tenant isolationImplemented with the corrected ownership modelEvery process has explicit deployment-owner/app scope. Required policy on Main, backend and worker; no opt-in/legacy authorization branch. Participant Auth0 organizations are affiliations, not data owners. The private access policy has been reviewed; apply the explicit ownership map at cutover.
Enforce limits while streaming uploadImplementedIncoming bytes counted/cancelled before multipart buffering, including absent/lying Content-Length; Blob size checked before arrayBuffer. Configured file maximum plus bounded multipart overhead.
Check file ownership before deletionImplemented for stamped attachments; legacy deletes fail closedActivity/uploader metadata is server-owned. Process/activity/field permissions, readonly state and other-activity references are checked. Legacy reads are preserved without backfilling guessed ownership; deletion remains denied until evidence-based reconciliation. No claim of transactional filesystem/process deletion under concurrency.
Browser-bound OAuth stateImplementedPer-flow nonce cookie bound to signed state, checked before exchange/retry; secure host-only cookies outside loopback; terminal cleanup; synthetic cross-browser/concurrent-flow tests. Live mounted-origin acceptance remains.
Authorized uncertain-effect recovery workflowIntentionally separate follow-upUnknown external outcomes remain held for reconciliation, not auto-retried. No general admin resolution endpoint/UI is added in this release. Needs explicit capability design, evidence and audit semantics before enabling recovery.

Additional review corrections

App permissions are rederived for each target, not borrowed from the union of a person's other apps. Scoped identity fixes cover renderer fields/past steps and the private-notes probe; document exports require explicit app asset ownership. Owner claims cover canonical/document/file resources. Operator status/export reads do not seed the runtime, and backfill assigns explicit policy ownership before writes.

Template publication remains an explicit operator capability, not an app-grantable permission. Membership editing UI, general app-management API credentials and email-change/account-linking machinery are not included. These are deliberate scope choices, not alternate authorization modes.

Remaining activation gates

  • Use the reviewed private access policy and explicit template ownership map. Admin-only authoring, departed/test-account exclusions and no link-only access are intentional decisions.
  • Reserve merge for the coordinated deployment window, or hold activation if merging earlier. The worker must stay held until web acceptance, including across a merge-triggered redeployment.
  • Use the manual release gate while Actions billing remains unavailable; retain the failed checks honestly and record exact-candidate local/staging evidence plus reviewer approval.
  • Provision consistent protected-effect keys and the required access policy on every web host/worker.
  • Take final quiesced data and attachment-byte backups; reconcile every attachment and ownership sidecar.
  • Import/read back into the owner-aware stores before traffic/readiness seeding, then perform actual Auth0, mount, permission, file and controlled-worker acceptance. Preserve rollback evidence.

See cutover for ordering. Read-only production discovery is not authority to change provider accounts, share policy files, mutate production or deploy.

Verification record

The local Node22 verification matrix covered all27 stages: package boundaries/typechecks/tests, Main's625 tests, production builds and HTTP/browser journeys, and isolated packed installations of Main, Spell, Allocation Risk, Generic and Backend. The last Backend stage was rerun successfully after correcting scoped-identity denial concealment (unreadable processes return404); its app-extension probe verifies private notes never enter core reads or exports. Backend86 and Storage45 tests pass.

The owner-aware offline rehearsal converted all122 source processes and13 latest templates into both file and authenticated loopback Mongo stores. Restart readback hashes, identical re-import and foreign owner rejection passed, with zero external effects. A separate real-Mongo scope-filter proof passes. Production dependency audit is zero; the nine disclosed development findings remain. These are local proofs, not hosted CI success, live identity-provider acceptance or approval of the private policy.

Attachment rehearsal and reviewed access policy

All30 attachments and30 original sidecars were privately backed up and hash-checked. A fresh122-process read found10 referenced files: six current-context and four historical audit references in one completed process. All10 remain in the converted aggregate; no referenced file is missing. The other20 files have no current process/reference and are retained unresolved, not deleted. The new filesystem adapter reads every restored file with matching hashes. Final quiesced backup and hosted restoration remain cutover steps, not consequences of this rehearsal.

The reviewed policy restricts authoring to11 current admins, includes impersonation in that admin set, excludes departed members and a historical test alias, and requires verified app membership even for existing sharing links. No new invitations are requested. Personal identities and full policy remain in private operator evidence, not this repository. None of these reviews changed production.