Skip to content

Feat security#102

Draft
dominikletica wants to merge 247 commits into
dev-latestfrom
feat-security
Draft

Feat security#102
dominikletica wants to merge 247 commits into
dev-latestfrom
feat-security

Conversation

@dominikletica

@dominikletica dominikletica commented Jun 15, 2026

Copy link
Copy Markdown
Member

Summary

This is an aggregation PR for the feat-security branch tree and consists of the following child-branches:

  • feat-security-planning
  • feat-security-policy-docs
  • feat-security-geoip-observability
  • feat-security-abuse-foundation
  • feat-security-admin-acl-enforcement
  • feat-security-rate-enforcement
  • feat-security-auto-ban
  • feat-security-captcha-contract
  • feat-security-icon-captcha
  • feat-security-remember-me

*) feat-mailer-account-delivery deferred to the future feat-mailer-branch.

Testing

(Note: Will be updated when this PR is marked ready-for-review.)

  • bin/phpunit: [RESULT]
  • bin/jstest: [RESULT]
  • bin/lint: [RESULT]
  • Other (if not already covered by the full suites above):

Progress

Progress will be captured in separate follow-up review comments to this PR. Use those to determine whether or not a change has already been reviewed.

Review Notes

Since merge commits were already reviewed before being merged into this branch, a light follow-up pass is sufficient: focus on obvious code-quality issues, security or privacy regressions, behavior changes, stale planning assumptions, and side/cross effects caused by the combination with other merged changes.

For newly not-yet-reviewed commits (e.g. review fixes or small additions pushed directly to this branch after the last merge commit has landed), perform a normal review and cover code quality, security/privacy considerations, behavioral correctness, tests, documentation consistency, branch boundaries, and worklog accuracy.

No runtime behavior is intended to change inside this aggregation PR aside from changes implemented through PR merges into this branch.

@dominikletica dominikletica self-assigned this Jun 15, 2026
@dominikletica dominikletica added enhancement New feature or request security Something is affecting security or data safety labels Jun 15, 2026

@dominikletica dominikletica left a comment

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Progress

  • feat-security-planning merged
  • Documentation-only planning branch
  • No runtime code changed
  • No tests required beyond Markdown linting
  • Codex Cloud Review reported no issues

@dominikletica
dominikletica marked this pull request as ready for review June 15, 2026 20:13
@dominikletica
dominikletica marked this pull request as draft June 15, 2026 20:14

@dominikletica dominikletica left a comment

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Progress

  • feat-security-policy-docs merged
  • Documentation-only planning branch
  • No runtime code changed
  • No tests required beyond Markdown linting
  • Codex Cloud Review reported no issues

@dominikletica dominikletica left a comment

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Progress

  • feat-security-captcha-contract splitter, part 1 merged
  • Feature implementation branch
  • Branch split justified by huge rename-diff (packages->extensions)
  • Checks passed: bin/phpunit OK, bin/jstest OK, bin/lint OK
  • Codex Cloud Review reported 37 issues: 35 resolved, 2 handled as explicit decisions/follow-ups
  • Local Review reported 7 additional issues: 7 resolved
  • Spark reported 3 additional issues: 2 resolved, 1 rejected as invalid after validation but led to a related hardening fix

@dominikletica dominikletica left a comment

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Progress

  • Addressed CI test failures
  • Checks passed: bin/phpunit, bin/jstest, bin/lint

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request security Something is affecting security or data safety

Projects

None yet

Development

Successfully merging this pull request may close these issues.

feat-security

1 participant