Technical debt
Known gaps, each with its status and the evidence behind it. A gap closes with evidence, never by assertion.
TD-001 · Verify rulesets wait on a package-read token
Status: open. The catalog’s prettier, eslint and tsc jobs need
@fridai/quality-rulesets; the registry token available to the executor has
only the read_registry scope (container images), so npm answers 403
insufficient_scope. Needs a read_package_registry token, then experiment
plan task T0.6. Evidence: kb/plans/redline-experiment/BLOCKERS.md.
TD-002 · No block ids on kb-package pages
Status: open. YYZ child pages are HTML fragments rendered at publish by
@fridai/kb-harvester with @fridai/design-markdown-renderer; YYZ’s root pages
go through its own processor. Neither runs Redline’s remark plugin, so inline
redline, changed-since and anchored comments have nothing to attach to. The
harvester already walks each page’s syntax tree to add heading ids; block ids
belong there, using parseDocumentBlocks. Blocks Stage 2.
TD-003 · History comes from the build checkout, not the package
Status: open. The build-time index reads the git repository the site builds
in. YYZ’s content now arrives from kb-packages, each carrying its own
history.bundle, so the index finds no history for those pages. The index
needs a bundle source (one git log per package). Blocks Stage 2.
TD-004 · A service site maps to one GitLab project
Status: open. SITES_JSON registers one project and content roots per site.
A composed knowledge base spans several source projects, and neither the
kb-package manifest nor its provenance records the source content directory, so
a page cannot be traced back to its project and file. Blocks Stage 2.
TD-005 · Anonymous state is publicly cacheable
Status: open, mitigated. /documents/state for an anonymous reader answers
Cache-Control: public, max-age=15, so a browser reused the pre-login answer
right after a reader connected GitLab. The client store requests with
cache: 'no-store'; other clients of the API can still be misled. Evidence:
26164e9.
TD-006 · Browser specs run on one worker
Status: open. Every Playwright spec shares one mock GitLab and one service,
and some switch GitLab down, so specs run serially (workers: 1). Per-worker
mocks would restore parallelism if the suite grows slow. Evidence: 26164e9.
TD-007 · npm latest bypasses the release gate
Status: open. package-npm-publish tags every candidate latest, so
npm i @fridai/fio-redline installs builds nobody promoted, while the container
image only reaches hosts through the verified and released channels.
TD-008 · Scoped styles miss elements created at runtime
Status: open. Astro scopes a component’s CSS to the elements in its template, so elements its script creates later (GitRedline’s layer buttons, GitComments’ threads and reply forms, GitTrackChanges’ operations) do not get those rules. GitTimeline hit this as markers that could not be clicked and now uses prefixed global styles; the older components need the same change, and a browser check that their created elements are styled.