08 — Normalized stabilization backlog¶
Scope note (2026-09-04): register ini mempertahankan temuan, keputusan, dan evidence historis. Status tanggal lama tidak boleh dibaca sebagai kondisi runtime terkini. Untuk program documentation-first, hanya item yang membuat instruksi tidak benar atau tidak aman yang menahan artikel; gunakan Documentation Confidence Gates. Semua item tetap berlaku untuk sertifikasi release sampai ditutup melalui QG yang sesuai.
Status dan aturan penggunaan¶
Backlog ini adalah program stabilisasi untuk Scola V1 Production Baseline, bukan persetujuan product scope dan bukan user documentation. Audit dilakukan dalam server-development mode dari /home/scola/odoo, dengan frontend develop@68b77d88f78b3d32f0ede3a54b665e067b014062 dan backend main@2ff6ac7cb41810bbc3b66821cdad004b52d1658a pada 2026-08-08. Delta hardening e749832/2ff6ac7 telah direview secara statis, tetapi belum menutup item STAB/CTRL tanpa acceptance dan regression evidence terkait.
Pedoman yang dibaca sebelum penyusunan: root dan frontend AGENTS.md, docs/ai-guidelines/AI_AGENT_MASTER_GUIDE.md, docs/ai-guidelines/development-guide.md, docs/ai-guidelines/workspace-governance.md, docs/ai-guidelines/architecture-api.md, docs/ai-guidelines/ui-design-pattern.md, docs/ai-guidelines/menu-architecture.md, docs/ai-guidelines/datetime-timezone.md, docs/ai-guidelines/rbac-user-management.md, docs/ai-guidelines/DOCUMENTATION_GOVERNANCE.md, dan docs/qa/testing-guidelines.md. Sumber temuan: seluruh docs/recon/, docs/documentation-planning/, serta audit release-readiness 01–04 dan 09.
Status produk/package di kolom berikut mengikuti proposed contract, bukan commercial approval (docs/release-readiness/01-product-contract.md:21-43). Defect optional/pilot tidak membuat package supported; bila package dikeluarkan dari V1, acceptance yang benar adalah menghapus/hide route/menu/API dari supported surface, bukan mempertahankan defect sebagai limitation.
Execution note — T0-A (2026-08-08)¶
Cross-cutting implementation started for STAB-005 / STAB-007 / STAB-008 (see docs/release-readiness/execution/T0-A-result.md). Status for those three items: Code fixed, runtime verification pending — not Closed. Do not treat source change alone as release evidence.
Execution note — T0-A.1 (2026-08-08)¶
Platform authorization closure for AUTH-004 fail-closed + method/action foundation + inventory dimensional correction (see docs/release-readiness/execution/T0-A1-result.md). STAB-005 / STAB-007 / STAB-008 remain Code fixed, runtime verification pending — not Closed until T0-B. STAB-008 additionally gains method/action-aware rules and extractor CI gate (still runtime-pending).
Execution note — T0-B1 (2026-08-08)¶
DEC-002 session-scoped active role + Golden Tenant fixture foundation (see T0-B1-result.md). STAB-005/007/008 still not Closed pending T0-B2 runtime matrix.
Execution note — T6A.1 SPMB ops (2026-08-20)¶
Usage-felt operasional slice on certified W03 engine — not a new T6A COMPLETE claim. See docs/release-readiness/execution/T6A.1-SPMB-ops-plan.md and T6A.1-SPMB-ops-residuals.md. Staff queue, portal, and public quota surfaces align to w03_state; waitlist/ranking-as-decision/enrolled-reversal/fees/CBT remain out of scope.
Execution note — W02.1 / STAB-013 docs sync (2026-08-26)¶
Phase 3 docs sync only (plan Tutup Gap SPMB). See execution/W02.1-post-enrollment-archive-result.md, W02.1-post-enrollment-archive-residuals.md, and updated T6A.1-SPMB-ops-residuals.md. Does not rewrite auditor verdicts. Distinguishes historical snapshot vs current-tip engineering vs served-dev vs deferred product.
- W02.1 (bounded): post-enrollment archive is admission-scoped (
/archive-student-record) with reason, idempotency, immutable audit; FE usesarchiveEnrolledStudentRecord(not genericsetAdminStudentsActivefor SPMB);enrolledremains terminal; quota unchanged.RT-W03-REC-01= partial bounded closure, not full reversal. - STAB-013: original backlog row (view/config collapse) is a historical defect statement. On current-tip engineering,
admission_config_api.pyexposes distinctMUTATION_CAPABILITIES, unit negatives cover viewer / flag-off / cross-company / foreign FK / idempotency / archive-not-hard-delete (test_admission_config_api_unit.py), and legacy/admin/spmb/test|complaints|rankingdeep links are fail-closed viaproductStatus+RC1_FAIL_CLOSED_ROUTE_PREFIXES. Status: Code hardened + unit negatives present — not Closed / not CERTIFIED for demo or production. Independent runtime matrix / DEC-008 product gate remains separate. Do not invent CERTIFIED claims. - Clamscan (W03): residual “missing full clamscan” in older T6A.1 text is outdated for W03 documents — source has quarantine + fail-closed
w03_documents.scan_payload. T4.1 attendance proof residual (size/magic only) is a different surface. - Phase 5 leftovers (residual, non-blocker): principal/VP ranking routes still live outside
/admin/spmbscope; this note is the STAB backlog docs sync for Phase 3.
Execution note — T4.1 W05 hardening (2026-08-19)¶
Usage-felt follow-on after T4-W05 / independent W05-A. See docs/release-readiness/execution/T4.1-W05-hardening-plan.md and T4.1-W05-hardening-residuals.md. This is not W05 CERTIFIED.
- STAB-017 / STAB-018 / STAB-020 remain closed by T4 independent audit (regression only).
- STAB-019 is PARTIAL: path A (mandatory correction reason + before/after audit). Formal DEC-006 draft/complete/correct/cancel is still open. Evidence:
attendance_api_mixin.py_correction_reason_error/_record_sheet_correction; faculty/admin sheet CTA Koreksi. - STAB-021 residual
T4W05-R-004is CLOSED (bounded) at size/type/magic bytes (no malware scanner). Evidence:scola_attendance/utils/proof_file.py. - STAB-044 is CLOSED (bounded Core) — central jenjang resolver (
src/config/schoolJenjang.js), menu/route guard parity for teacher attendance surfaces, RT-PROFILE-JENJANG-01 negative matrix (tests/menu/teacherAttendanceReportScope.spec.js). Full DEC-013 signed profile matrix remains PRE_OPTIONAL_EXPOSURE. - STAB-022 usage-closed on listed W05 surfaces:
AttendanceSheetNew.vue,AttendanceSheetList.vue,WeeklyStudentReport.vue,ClassDailyReport.vueusegetTodayDateInTimezone/getMondayOfDateInTimezone. Evidence:tests/unit/utils/timezone.spec.js23:30/00:30 WIB/WITA/WIT. - STAB-027 usage-closed on listed W05 surfaces:
canMutatePerLessonAttendancedeny-list +denyRoleson/attendance/sheets/create; BE_admin_access_errorand faculty save role check return 403 without DB write. Overview/insight stay onstudents.attendance.view. - Daily-gate 404/nodb is a host reliability track, OUT OF W05 (
T4W05-R-002). Sheet save/create does not blindly re-POST after 404 (reconcile GET).
Execution note — W05-B DEC-006/007 (2026-08-29)¶
Bounded Core V1 manual attendance extended: daily gate + pickup registry (CORE_SUPPORTED). Student RFID/face remain V2 SC-ATTEND+. See execution/T4-DEC-006-007-attendance-v1-matrix.md and audit/RC1-W05B-attendance-boundary-reaudit.md.
- STAB-019 daily path: cancel/adjust require reason; audit log via
scola.attendance.daily.cancel.log; optionalnotify_parenton cancel (default off). - STAB-029:
notify_parentwired when explicitly requested; no UI checkbox in V1. - RT-W05-DAILY- matrix rows moved to IN V1 baseline* — runtime PASS still pending on exact served pair.
1. Severity dan triage rules¶
| Severity | Definisi operasional |
|---|---|
| S0 Critical | Confirmed code path dapat memberi akses/mutasi data sensitif tanpa domain authority, kebocoran membership/tenant boundary, atau perubahan ledger/master kritis melalui authority yang secara material salah. Stop release dan batasi/hide surface segera sambil melakukan runtime exploit validation. |
| S1 High | Core/approved workflow tidak dapat diselesaikan dengan benar, authorization/data-integrity boundary materially gagal, atau release evidence dapat memberi false-green pada product/package. Selalu Release Blocker. |
| S2 Medium | Bounded functional/consistency/recovery failure dengan containment/workaround aman; normally Must Fix. Tidak boleh diturunkan menjadi limitation bila menyentuh security, privacy, integrity, atau core completion. |
| S3 Low | Polish atau maintainability debt yang tidak mengubah authority, data, task completion, recovery, atau safety. |
Severity menyatakan impact, bukan kepastian exploit atau priority by component size. Temuan Requires runtime verification tetap diberi severity berdasarkan worst credible impact yang didukung code; downgrade hanya melalui evidence yang menutup kondisi tersebut. S0/S1 tidak boleh open pada baseline (docs/release-readiness/09-release-quality-gate.md:181-198). Product/business decisions berada di §7 tanpa S-severity. Missing runtime evidence berada di §8 dan tidak disamarkan sebagai bug.
2. Executive backlog summary¶
| Severity | Count | IDs | Release treatment |
|---|---|---|---|
| S0 | 6 | STAB-001–STAB-006 | Release Blocker; containment + fix + security/DPO regression |
| S1 | 23 | STAB-007–STAB-028, STAB-044 | Release Blocker; close or remove affected surface |
| S2 | 13 | STAB-029–STAB-041 | Must Fix by default; explicit bounded limitation only under QG policy |
| S3 | 2 | STAB-042–STAB-043 | Must Fix or post-release only after supported contract is unaffected |
| Decisions | 14 | DEC-001–DEC-014 | No bug severity; owner decision must precede implementation where linked |
| Readiness controls | 6 | CTRL-001–CTRL-006 | No bug severity; required evidence/control work |
3. S0 Critical defects¶
| ID | Affected workflow / roles / package | Root-cause category | Required fix | Owner / dependencies | Proposed acceptance criteria | Required regression tests | Evidence / trace |
|---|---|---|---|---|---|---|---|
| STAB-001 | W17 complaint; anonymous submitter, complaint operator; package Requires Product Decision | Authorization + attachment/privacy | Register public/internal actions explicitly; case/company assignment; strict anti-bot; server file allowlist/size/signature/scan; redaction/retention; safe download. Hide internal operator surface until fixed. | Complaint Owner + Security + DPO; DEC-001/004/006/009 | Only named operator can see/act on assigned company cases; public abuse and invalid files rejected; response/list minimal; audit/retention approved. | Anonymous abuse/rate/Turnstile fail, viewer/unassigned/cross-company, MIME/size/signature, attachment download, redaction/audit. | ../custom_addons_scola/gcgscola/scola_public_complaint/controllers/public_complaint_api.py:107-120,140-155,223-231,351-405,440-478; BLK-A04; AUTH-002/004/005/008/009/011. |
| STAB-002 | W15 counseling; counselor, student-affairs viewer, student/parent; SC-STUDENT | Authorization + sensitive data | Split view/create/respond/refer/close/export; counselor/case/company/child scope; purpose projection; audited break-glass only. | Counseling Owner + Security + DPO; DEC-003/004/006/009 | View-only cannot mutate; only assigned counselor/case actors receive approved fields; all sensitive accesses audited. | Cross-counselor/company/student/parent, viewer mutation, export/download, reassignment/closed case, break-glass expiry. | ../custom_addons_scola/gcgscola/scola_counseling/controllers/counseling_domain_api.py:39-59,81,171-174,233-236,314-338; BLK-A06; AUTH-002/005/006/008–011. |
| STAB-003 | W11 accounting; treasurer/viewer/approver; SC-FIN | Authorization + cross-company financial integrity | Split view/create/edit/post/reconcile/approve; scoped domain service before elevation; company/foreign-key validation; maker-checker and immutable audit. | Finance Controller + Security; DEC-003/004/006/007 | Viewer cannot mutate; no cross-company browse/write; self-post/reconcile and invalid state denied; one audited financial effect. | Direct API, cross-company guessed/mixed IDs, maker-self approval, post/reconcile/reverse, concurrent/retry, before/after ledger. | ../custom_addons_scola/gcgscola/scola_account/controllers/accounting_modules_api.py:20-59,69-167,212-300; BLK-A09; AUTH-002/005/009–011. |
| STAB-004 | W19 Dapodik; Dapodik operator/admin; SC-DAP Controlled Pilot | Authorization + tenant identity/master integrity | Split view/configure/preview/execute/delete; tenant-scoped stable identifiers; mandatory exact diff; idempotent sync and rollback/recovery. Keep pilot disabled until certified. | Dapodik/Integration Owner + Security + Data Steward; DEC-003/004/008 | Viewer cannot sync/configure; cross-tenant identifiers never match; preview equals write set; rerun one effect; recovery/audit approved. | NISN/NUPTK/rombel collision, flag off, viewer mutation, dry-run/write parity, concurrent/retry, partial failure/rollback. | ../custom_addons_scola/gcgscola/scola_dapodik_connector/controllers/dapodik_api.py:22-95,214-313,327-435,474-571; BLK-A11; AUTH-002/005/006/009–011/014. |
| STAB-005 | Core contextual tracking; any authenticated user; SC-CORE | Generic elevated endpoint / object authorization | Remove generic user surface or enforce model/action allowlist, native rights/rules, company/domain ownership and record purpose before elevation. | Core Platform Security; DEC-003/009 | Arbitrary model rejected; inaccessible ID returns 403 without existence leak; only allowlisted record/action succeeds and is audited. | Model/res_id fuzzing, cross-company/record, disallowed field/action, inaccessible/existing ID indistinguishability, audit. | ../custom_addons_scola/gcgscola/scola_core/controllers/core_reference_api.py:42-49; BLK-A12; AUTH-004/005/008/009/011. |
| STAB-006 | W18 messaging; student/parent/teacher/staff; product decision pending within portal | Membership authorization + attachment privacy | Membership-filter every batch item; attachment linked to accessible message/channel; safe field allowlist; tenant/retention/access audit. | Messaging Owner + Security + DPO; DEC-001/003/009/010 | Arbitrary or mixed unauthorized channel IDs reveal no preview/count; unrelated attachment inaccessible; revoked member loses access. | Non-member/mixed batch, guessed attachment, revoked membership, cross-company, list projection, read/download audit. | ../custom_addons_scola/gcgscola/scola_portal/controllers/general_messaging_api.py:439-482,520-550,945-982; BLK-A15; AUTH-005/007–009/011. |
4. S1 High defects¶
| ID | Affected workflow / roles / package | Root-cause category | Required fix | Owner / dependencies | Proposed acceptance criteria | Required regression tests | Evidence / trace |
|---|---|---|---|---|---|---|---|
| STAB-007 | W00 and all workflows; every multi-role user; platform/SC-CORE | Active-role semantics / SoD | Active role becomes server-side enforcement context; assigned roles are eligibility only; conflict/delegation/break-glass and acting-role audit. | Security + Product + Auth Owner; DEC-002/006 | Capability unique to role A becomes 403 after switch to B; forged role rejected; audit records acting role. | Single/multi/conflict role, switch/refresh/concurrent tabs, direct API, delegation expiry, provisioning migration. | ../custom_addons_scola/gcgscola/scola_core/controllers/auth.py:485-518; ../custom_addons_scola/gcgscola/scola_core/services/auth_capabilities.py:676-771; BLK-A02; AUTH-001/011/013. |
| STAB-008 | All protected APIs; all roles/packages | Route authorization resolver / deny-default | Exact/longest-prefix registry; action capability split; collision detector; every protected API registered and unknown protected denied; controller scope remains mandatory. | Platform Security/Auth; DEC-003 | Zero unintended overlap; specific library/fees/LMS rules resolve correctly; unregistered protected fixture denied. | Prefix permutations, exact/action routes, public allowlist, FE/BE registry parity, route extraction count. | ../custom_addons_scola/gcgscola/scola_platform_support/api_route_access.py:60,226,254,289,294,458,482-528; BLK-A03; AUTH-002–004/012/014. |
| STAB-009 | W08 promotion; academic admin/approver; SC-REPORT | Broken guard / missing implementation | Define/import correct guard, action capability, owner/approval/state/reversal; hide promotion until happy and negative paths pass. | Report Card Owner; DEC-004/006/007 | Controller loads; authorized flow completes; unauthorized/self/invalid transition denied; supported rollback works. | Startup/import, list/candidate/action, viewer, cross-company, self-approval, retry/reversal. | ../custom_addons_scola/gcgscola/scola_report_card/controllers/promotion_admin_api.py:21-24,63-172; BLK-A05; AUTH-002/004/010/014. |
| STAB-010 | W09 payroll; payroll viewer/operator/reviewer/approver/employee; SC-PEOPLE | View/mutation capability collapse + sensitive finance | Separate self/operator/reviewer/approver/auditor; employee/company scope, maker-checker, field projection, audit. | Payroll/HR + Finance + Security/DPO; DEC-003/004/006/009 | Viewer cannot confirm/cancel/draft/refund/input/batch; self sees own only; cross-company denied; salary projection approved. | Every state action, self/peer, company, maker-checker, export, audit/field snapshot. | ../custom_addons_scola/gcgscola/scola_payroll/controllers/payslip_admin_api.py:33-66,391-558; ../custom_addons_scola/gcgscola/scola_payroll/controllers/payroll_api.py:37-149,274-354; BLK-A07; AUTH-002/005/008/010/011. |
| STAB-011 | W15 kesiswaan; viewer/operator/approver/student-affairs; SC-STUDENT | View/mutation capability collapse + record ownership | Separate achievement/permit/discipline read/create/edit/delete/approve/reject; class/case/company scope and SoD/audit. | Student Affairs + Security; DEC-003/004/006 | Viewer mutation 403; other class/case/company denied; maker cannot self-approve unless signed policy. | Direct API per action, class/case/company, transition, self-approval/delegation, audit. | ../custom_addons_scola/gcgscola/scola_student_activity/controllers/kesiswaan_domain_api.py:42-54,78-84,165-221,1032-1077; BLK-A08; AUTH-002/005/006/008/010/011. |
| STAB-012 | W12 BOS/RKAS procurement; maker/approver; SC-BOS Pilot | Idempotency/state + authorization + attachment ownership | State/action guard, idempotency/constraint, SoD, company scope, attachment ownership/type/size/scan, compensating recovery. | BOS/RKAS + Finance + Security; DEC-004/006/007/009 | Repeated/concurrent approval creates one commitment; invalid state/viewer/foreign attachment rejected; one audit trail and approved recovery. | Double/concurrent action, viewer, self-approval, cross-company/model attachment, file validation, partial failure/reversal. | ../custom_addons_scola/gcgscola/scola_bos_rkas_procurement/models/purchase_request.py:142-164; ../custom_addons_scola/gcgscola/scola_bos_rkas_procurement/controllers/procurement_admin_api.py:35-62,355-384; BLK-A10; AUTH-002/005/009–011/014. |
| STAB-013 | W03 config; admissions viewer/manager; SC-ADM | (historical) View/config mutation collapse + package entitlement — current-tip engineering note 2026-08-26: mutation caps split + unit negatives present; not Closed / not CERTIFIED demo/prod (see Execution note W02.1 / STAB-013) | Split view/configure/delete, protect referenced/effective-dated company masters, audit; gate SC-ADM. | Admissions + Security; DEC-001/003/004/008 | Viewer/flag-off/cross-company save/delete denied; referenced delete safe; manager change audited and rollbackable. | Route/direct API, entitlement off/on, company, referenced record, effective date, rollback/audit. | Current tip: admission_config_api.py MUTATION_CAPABILITIES + test_admission_config_api_unit.py; FE fail-closed /admin/spmb/test|complaints|ranking. Historical lines BLK-A13; AUTH-002/005/010–012. |
| STAB-014 | W10 fee enrollment; billing operator/student; SC-FEES | Missing explicit tenant ownership on elevated IDs/FKs | Validate enrollment/student/course/batch/schedule company ownership before read/write; atomic scoped service. | Fees + Security; DEC-003/008 | Every lookup/detail/save filters active company; cross-company target/mixed FK rejected atomically. | Guessed detail, mixed student/course/batch, list totals, active-company switch, mutation rollback. | ../custom_addons_scola/gcgscola/scola_fees/controllers/fee_enrollment_api.py:135-175,180-235,263-267; BLK-A14; AUTH-005/006/009/014. |
| STAB-015 | Calendar communication; admin/owner/attendee; SC-CORE | Elevated event/user browse without proved owner/company scope | Action manage capability, event owner/company policy, attendee scope, notification/cancel audit. | Communications + Security; DEC-003/004/010 | Viewer cannot save; guessed event/user and cross-company attendee denied; owner transitions and notifications audited. | View/save direct API, other owner/company, attendee injection, invite/cancel propagation, audit. | ../custom_addons_scola/gcgscola/scola_portal/controllers/calendar_admin_api.py:23-83; BLK-A16; AUTH-002/005/006/009–012. |
| STAB-016 | Company/notification settings; school admin/platform role; SC-CORE + optional settings | View/config authority and tenant/global drift | Distinct configure capabilities; explicit tenant vs global owner; secret handling, effective date, rollback and audit; route/menu parity. | Platform Ops + Communications + Security; DEC-003/004/008/010 | Viewer cannot write; tenant change cannot affect another tenant; global only named platform role; secrets never returned/logged. | View/config direct API, tenant/global, feature off, secret redaction, rollback/audit, UI parity. | src/router/settingsRoutes.js:34-39; ../custom_addons_scola/gcgscola/scola_core/controllers/company_settings_api.py:119-125,205-249; ../custom_addons_scola/gcgscola/scola_portal/controllers/notification_config_api.py:25-57; BLK-A17; IA-011; AUTH-002/005/010–012. |
| STAB-017 | W05 first save; fresh teacher/homeroom; SC-CORE Controlled Pilot workflow | ACL/provisioning mismatch | Canonical scoped create/write boundary for sheet/line; no unrelated legacy attendance group and no broad sudo. | Attendance Backend + Identity/RBAC; DEC-002/003/012 | Fresh teacher with canonical groups first-saves atomically; unassigned teacher denied. | Fresh vs legacy user, create/write/read ACL, assigned/unassigned session, company, retry. | ../custom_addons_scola/gcgscola/scola_attendance/controllers/attendance_api_mixin.py:4304-4332; ../custom_addons_scola/gcgscola/scola_attendance/security/ir.model.access.csv:4,8; BLK-A19; AUTH-001/006/013/014. |
| STAB-018 | W05 faculty/admin save; teacher/admin; SC-CORE Controlled Pilot workflow | Roster/tenant validation and atomicity | Exact event-date roster, duplicate/membership/company/completeness validation on every save path. | Attendance Backend + School Ops; DEC-003/008 | Duplicate/missing/out-of-batch/zero/cross-company IDs all rejected with zero partial writes; exact roster succeeds. | Faculty/admin, single/combined session, all invalid roster variants, transaction rollback, concurrent update. | ../custom_addons_scola/gcgscola/scola_attendance/controllers/attendance_api_mixin.py:3335,3398-3422,4238-4275,4307-4334; BLK-A20; AUTH-005/006/009/014. |
| STAB-019 | W05 complete/correct; teacher/admin/leadership; SC-CORE Controlled Pilot workflow | State machine / correction ownership / audit | Distinct draft/complete/correct actions per approved PO-01/AM-02/SG-01; reason/cutoff/approval/recovery and immutable before/after audit. | Attendance PO + School SME + Security; DEC-006/007 | Only approved transitions/actors; late/invalid correction rejected; correction carries actor/time/reason/before-after and propagates downstream. | Role/state table, same/late day, self/approval, retry/concurrency, audit, student/parent update. | ../custom_addons_scola/gcgscola/scola_attendance/controllers/attendance_api_mixin.py:3398-3422,4307-4334; src/views/AttendanceManagement/Faculty/AttendanceSheet.vue:667-671,733-772; BLK-A21; UX-003; AUTH-002/010/011/014. |
| STAB-020 | W05 statuses and aggregates; all W05 actors; SC-CORE Controlled Pilot workflow | FE/BE state-model mismatch | Implement approved SG-02 canonical status/subtype across input, serializer, aggregate, migration and labels. | Attendance PO + SME + Analytics; DEC-006/007 | Every approved value round-trips and aggregates deterministically; invalid/legacy values handled by approved rule. | Create/read/update, period aggregate, parent/student, correction, legacy migration, invalid enum. | src/i18n/attendanceStatus.js:33-54; ../custom_addons_scola/gcgscola/scola_attendance/controllers/attendance_api_mixin.py:63-73,2855-2875,4313-4324; BLK-A22; UX-004/016; AUTH-002/010/014. |
| STAB-021 | W05 proof; teacher, student/parent viewers; SC-CORE Controlled Pilot workflow | Server file validation + privacy projection | Server size/type/signature/scan; opaque authorized download; no raw proof in list payload; viewer/retention/delete policy and audit. | Security + DPO + Attendance + Storage; DEC-006/009 | Invalid/oversize rejected; raw bytes absent from list; only approved child/company viewer downloads; retention/audit signed. | File matrix, spoofed MIME, payload size, child/company, download URL, retention/delete, audit. | src/views/AttendanceManagement/Faculty/AttendanceSheet.vue:315-319,592-603,749-750; ../custom_addons_scola/gcgscola/scola_attendance/controllers/attendance_api_mixin.py:2795-2796,2816-2833,4323-4324; BLK-A23; UX-005; AUTH-005/007–009/011/014. |
| STAB-022 | W05 create/pending and date-effective reports; teacher/admin; SC-CORE | Timezone/day-boundary defect | Replace raw UTC date selection with school-timezone facade for school-day defaults/math. | FE Attendance/Academic; timezone decision/runtime config | Around UTC boundary, UI default, API date, persisted day and downstream view all equal school local date. | UTC± offsets, 23:30/00:30 school local, reload/navigation, weekly Monday, daily report. | src/views/AttendanceManagement/Admin/AttendanceSheetNew.vue:196,405; src/views/AttendanceManagement/Admin/AttendanceSheetList.vue:184; src/views/FacultyViews/WeeklyStudentReport.vue:590,628; src/views/FacultyViews/ClassDailyReport.vue:313; UX-001; SSOT docs/ai-guidelines/datetime-timezone.md:3-16,55-58. |
| STAB-023 | W02 student create/import; viewer/identity admin; SC-CORE | Route/action/API guard drift | Route and CTA require students manage/import; retrace async-job state/error/retry; direct API same capability/scope. | Identity Admin FE/BE + Security; DEC-003/008 | Viewer cannot enter/call mutation; manager completes deterministic import with safe retry/error report. | Route/menu/direct API, file/validation, async timeout/retry/idempotency, company, job error download. | src/router/studentDataAdminRoutes.js:14-20,37-43; src/views/AdminViews/StudentDatabase/StudentList.vue:18,303; src/views/AdminViews/StudentDatabase/UploadSiswa.vue:769-778,835; BLK-B03; IA-024; AUTH-002/012/014. |
| STAB-024 | W00 navigation/package entry and package installation; all roles; SC-CORE + all optional/pilot packages | Declared-vs-actual package topology and product-gate leakage | Generate the exact fresh-database dependency/auto-install closure for every bundle; remove/split undeclared peer-SKU hard dependencies or implement the Product-approved composition. Derive shell/group/leaf visibility from approved package + installed addon + entitlement + capability; installed module never implies entitled user surface; optional off means no menu/route/API authority. | Product/Commercial + Backend Packaging + Platform + FE Navigation; DEC-001/011/012 | Approved package dependencies match the exact installed closure. SC-CORE may technically install only approved internal dependencies; every peer-SKU addon that remains installed is explicitly classified and its menu/route/capability/API surface denied when unentitled. Each optional/pilot package has a truthful independent or explicitly composite installer. | Empty-DB install/module-closure snapshot per bundle; unexpected transitive diff; entitlement/flag off/on; role/menu crawl; direct route/API; auto-install bridge; mixed shell; upgrade/uninstall compatibility. | Static contradictions: 01 §8; manifests ../custom_addons_scola/gcgscola/scola_attendance/__manifest__.py:24-36, ../custom_addons_scola/gcgscola/scola_admission/__manifest__.py:22-31, ../custom_addons_scola/gcgscola/scola_report_card/__manifest__.py:23-34, ../custom_addons_scola/gcgscola/scola_lms/__manifest__.py:20-31, ../custom_addons_scola/gcgscola/scola_cbt/__manifest__.py:20-28, ../custom_addons_scola/gcgscola/scola_bundle_enterprise/__manifest__.py:10-33; IA-001/011–014/023; BLK-B01; AUTH-012–014. |
| STAB-025 | W00 role entry/home; cashier/admin/head-admin/principal/VP/teacher and other roles; mixed packages | Role catalog/home/visible-forbidden authority drift | One canonical role/app/home contract mirrored by backend; remove orphan/invalid homes; reconcile admin vs school_admin, head-admin, VP scopes; zero visible-forbidden leaves. |
Product + Identity/RBAC + FE Navigation; DEC-001/002/004/011 | Every fresh supported role lands on valid authorized home; all visible leaves load; unauthorized direct routes/API deny; no orphan role/app. | Role×app×leaf crawl, fresh login/home, switch role, direct route/API, backend catalog parity. | src/config/apps/roleApps.js:1-679; ../custom_addons_scola/gcgscola/scola_core/services/role_catalog.py:7-40; IA-002–005/008/015–018; AUTH-001/012–014. |
| STAB-026 | W00 unsupported surface; normal roles/public; lab and registration | Placeholder/incomplete product exposure | Remove/hide/deprecate lab placeholder leaves and /register stub until complete product/API/owner/tests exist. |
Product + owning FE/module engineer; DEC-001/011 | Zero supported menu/search/home link to placeholder; direct route removed/explicitly unavailable; no API/product promise. | Role crawl, direct route, public route, search/deep link, feature off. | docs/recon/open-questions.md:41-50; BLK-A18; IA-006/007; AUTH-004/012–014. |
| STAB-027 | W05 monitor/correct UI; principal/VP/admin; SC-CORE Controlled Pilot | CTA/route/API authority contradiction | Default leadership read-only; hide mutation CTA/routes unless PO explicitly grants and backend enforces dedicated capability. | Attendance PO + FE/BE RBAC; DEC-006 | Principal/VP can read only approved scope, never see mutation CTA, and direct mutation returns 403/no data change; admin policy exact. | Menu/list/detail/create/pending/direct API per role and active-role switch. | src/views/AttendanceManagement/Admin/AttendanceSheetList.vue:9-20,192; ../custom_addons_scola/gcgscola/scola_attendance/controllers/attendance_api_mixin.py:146-199,3335-3337; BLK-B04; UX-002; IA-025; AUTH-012. |
| STAB-028 | Release regression; QA/release owner; SC-CORE and every package/composite bridge | Test/package-boundary false-green | Derive one suite manifest from the approved product contract and exact installed closure. Keep SC-CORE, each independent SKU, and every composite bridge result separate; installed-but-unentitled peer modules receive denial tests and never make a parent package green. | QA/Release + Package Owners; DEC-001/012; STAB-024 | Core smoke selects only Core journeys; each package result names exact module closure, entitlement/flags, independent/composite status, prerequisite results, and package denominator. SC-ADM/SPMB and all other optional/pilot suites are distinct. | Script/manifest contract, suite list snapshot, empty-DB closure, Core with all peer entitlements off, package off/on, composite-bridge profile, CI/manual parity. | package.json:36-39; docs/modular/product-tier-and-feature-flags.md:37-83; docs/ai-guidelines/development-guide.md:283-306; 07 §10; QG-14 docs/release-readiness/09-release-quality-gate.md:145. |
| STAB-044 | W00 and teacher attendance/report entry; teacher with missing, unknown, unsupported, or unassigned jenjang; SC-CORE | School-profile menu/route guard fail-open drift | Centralize a recognized-and-assigned jenjang predicate. Missing/unknown/unsupported codes deny or route to a safe unsupported state; only explicitly retained early/non-early codes enter their branch. Menu, route guard, backend record scope, and profile resolver use the same contract. | FE Navigation + Identity/RBAC + Academic Scope; DEC-003/013 | Empty, malformed, unsupported, expired/unassigned, and other-company jenjang never enter either teacher attendance branch or subject-report route; every retained code reaches exactly its approved branch; denial leaks no records. | Fresh teacher profile matrix; menu visibility; direct URL/deep link; role switch; missing/unknown code; other-company/level assignment; backend direct API; retained early/non-early positive cases. | CLOSED (bounded Core, 2026-08-26): resolveRecognizedJenjangProfile + isJenjangAllowedForUser in src/config/schoolJenjang.js; route guards in src/router/teacherRouteFragments/attendance.js; menu parity in src/config/apps/appFragments/teacherPortalApp.js; evidence tests/menu/teacherAttendanceReportScope.spec.js (RT-PROFILE-JENJANG-01 negatives). Full DEC-013 signed matrix = PRE_OPTIONAL_EXPOSURE. |
5. S2 Medium defects¶
| ID | Affected workflow / roles / package | Root-cause category | Required fix | Owner / dependencies | Proposed acceptance criteria | Required regression tests | Evidence / trace |
|---|---|---|---|---|---|---|---|
| STAB-029 | Daily attendance cancellation; operator/parent; SC-CORE/SC-ATTEND+ boundary | Parameter/side-effect contradiction | Implement and observe notify_parent, or remove the control/claim and expose approved manual recovery; dedupe delivery. |
Attendance + Notification; DEC-010 | Requested behavior equals delivered/audited state; failure visible with safe recovery. | true/false, delivery failure/retry/dedupe, parent visibility, cancellation audit. | ../custom_addons_scola/gcgscola/scola_attendance/controllers/attendance_api_mixin.py:1261-1320; BLK-B06. |
| STAB-030 | W20 RFID; device/operator; SC-ATTEND+ | View/mutation capability + retry state ambiguity | Manage capability for config/retry; explicit event state machine, idempotent reset/retry, dead-letter owner/monitoring. | Smart Attendance + Security/Ops; DEC-003/004/010 | Viewer cannot mutate/retry; failed event has one supported retry path and one attendance effect. | State/action matrix, processed error, repeated/concurrent retry, device/company, config route, dead-letter alert. | ../custom_addons_scola/gcgscola/scola_smart_attendance/controllers/rfid_events_api.py:450-478,657-672; ../custom_addons_scola/gcgscola/scola_smart_attendance/models/rfid_event.py:147-168; BLK-B07. |
| STAB-031 | W14 library queue; librarian/member; SC-LIB | Concurrency integrity (static inference) | Database lock/constraint or serialized assignment with deterministic priority and conflict recovery. | Library Engineering + SME | Concurrent attempts never assign one copy twice; deterministic winner and recovery audit. | Parallel transactions, same priority tie, cancellation/expiry/retry, inventory reconciliation. | ../custom_addons_scola/gcgscola/scola_library/controllers/library_queue_return_api.py:161-180; ../custom_addons_scola/gcgscola/scola_library/models/library_queue_auto.py:112-169; BLK-B08. |
| STAB-032 | Library settings; viewer/manager; SC-LIB | FE route vs API capability drift | Gate page/load/save consistently: either read GET for viewer + manage save, or manage-only page; match menu/route/API. | Library + FE RBAC; DEC-003/008 | Viewer behavior intentional and consistent; manager load/save succeeds; direct mutation secured. | Menu/route/load/save/direct API, flag off/on, company, role switch. | src/router/libraryManagementRoutes.js:146-152; src/services/library/library.service.js:759-795; ../custom_addons_scola/gcgscola/scola_library/controllers/library_portal_reading_api.py:63-72; BLK-B10. |
| STAB-033 | W16 communication; publisher/readers; SC-CORE | Duplicate canonical/legacy publication | Make scola.news sole writable source; legacy announcement read-only/migrated/removed; preserve history and audience/notification mapping. |
Communications + Platform; DEC-011 | One canonical create/publish route; legacy write impossible; migration report and no duplicate delivery. | Canonical publish, legacy direct API, history migration, audience/read receipt/notification parity. | ../custom_addons_scola/gcgscola/scola_news/models/scola_news.py:96-198,571-634; ../custom_addons_scola/gcgscola/scola_portal/models/announcement.py:15-27,146-212,262-325; BLK-B11; IA-010. |
| STAB-034 | Mutation feedback across supported pages; all roles/packages | Multiple notification taxonomies/renderers | One provider/renderer per shell; canonical error type/style/ARIA; mount on mobile/desktop; Indonesian close/default copy; prevent duplicate render. | FE Design System | Exactly one correctly styled/announced notification for each type on mobile/desktop. | Component types, AppLayout branches, local+global renderer, timeout/persistent, keyboard dismiss. | src/composables/useAlerts.js:47-52; src/components/AlertStack.vue:30-59,66-87; src/layouts/AppLayout.vue:18-29,37-75; UX-006. |
| STAB-035 | Save/cancel/destructive actions; all operators/packages | Modal lifecycle + native confirmation inconsistency | Loading/dirty close guard, localized defaults, one consequence-aware confirm component; remove native confirm on supported routes. |
FE Design System + domain owners; DEC-007 | Loading mutation cannot backdrop/Escape close; dirty cancel warns; destructive confirmation names effect/recovery; cancel performs no request. | Escape/backdrop/loading, dirty form, double submit, delete/post/approve/cancel, focus return/i18n. | src/components/ui/AppModal.vue:6-12,51-68,144-175; src/components/ui/AppConfirmDialog.vue:61-91; native examples src/views/AdminViews/AcademicConfig/AcademicCalendar/AcademicCalendarList.vue:802; UX-007/015. |
| STAB-036 | Server-paginated student/academic tables; admins; SC-CORE | Local sort over one server page | Add server sort contract/event or disable sorting for server-paged columns; preserve total/page/filter semantics. | FE Data Table + API owners | Dataset >2 pages sorts globally or UI shows non-sortable; page traversal deterministic. | Asc/desc each type, page traversal, filter+sort, reload, selection/bulk action. | src/components/ui/AppTable.vue:61-103,294,423-471; src/views/AdminViews/StudentDatabase/StudentList.vue:115-118; src/views/AdminViews/AcademicConfig/AcademicYear/AcademicYearList.vue:61-62; UX-009. |
| STAB-037 | Mobile shell and attendance summary tables; all portal/admin roles | Missing topbar + inconsistent responsive/a11y semantics | Require mobile topbar/header; canonical accessible tabs/table overflow/card alternative; route viewport inventory. | FE Shell/Design System | Every supported task at 320/360/390/768 px has title/navigation, no clipped action, keyboard/ARIA path and no page overflow. | Route viewport crawl, keyboard/focus/screen reader, bottom-bar overlap, student/parent parity. | src/layouts/AppLayout.vue:18-29; src/views/AdminViews/AcademicConfig/AcademicYear/AcademicYearList.vue:2-9; src/views/AttendanceManagement/Student/AttendanceList.vue:1-88; src/views/AttendanceManagement/Parent/AttendanceList.vue:1-104; UX-010/017. |
| STAB-038 | Forms/tabs/filters/search; all supported roles/packages | Component/validation/query-state inconsistency | Canonical controls; required/backend parity; inline error/focus; labelled filters; debounce cancellation/reset/page-1/URL state. | FE Design System + API owners | Required UI matches backend; invalid request atomic; tabs keyboard-safe; search/filter reload/back deterministic. | Missing/invalid/cross-scope, focus/ARIA, debounce race, reset, page state, empty-filter vs empty-data. | src/components/ui/AppInput.vue:5-10,57,81-94; src/views/AdminViews/StudentDatabase/StudentList.vue:63-118,441,534; src/views/AdminViews/AcademicConfig/StudyGroup/StudyGroupList.vue:96-125,1672-1678; UX-012/013. |
| STAB-039 | Loading/empty/error/retry; all supported pages | Non-normalized UI and HTTP error states | Canonical state blocks and safe 401/403/404/409/422/429/5xx/offline mapping; no raw backend error; retry only for safe/idempotent action. | FE Platform + API owners | No blank/infinite loading; 403 not empty; conflict offers reconcile; internal detail not rendered; safe retry deterministic. | Forced response matrix, offline/timeout/stale, retry/idempotency, correlation reference, screen-reader announcement. | src/components/ui/AppTable.vue:118-180; src/views/AttendanceManagement/Parent/Attendance.vue:344-366,419-427; src/views/AttendanceManagement/Admin/AttendanceSheetNew.vue:285-287,323-326,408-410; UX-014/018. |
| STAB-040 | Attendance navigation/status labels; all attendance actors; SC-CORE/ATTEND+ | Terminology collision | Approve and implement glossary/page taxonomy for Kehadiran/Absensi/Presensi, daily/per-session/smart/pickup; aliases searchable but not competing labels. |
Attendance PO + Product Design; DEC-006/007/011 | One canonical term per concept/locale; label maps to correct page/package; state meaning unchanged across roles. | Menu/page/breadcrumb/i18n snapshot, cross-role route, search alias, state round-trip. | src/i18n/locales/id.json:644,819,842,1079,1165,1199-1202,1516-1579,1881-1985; UX-016; IA-012. |
| STAB-041 | W00 navigation; all roles/packages | Duplicate leaf routes, aliases, breadcrumb gaps, validator drift | One canonical page/route owner; duplicate leaves consolidate; alias registry has owner/sunset/telemetry; breadcrumbs resolve canonical; audit validator matches runtime policy. | FE Navigation + Platform QA; DEC-011 | No unexplained duplicate route key; all aliases redirect to canonical with lifecycle; hidden/detail route breadcrumb valid; validator zero false positive for approved contract. | Route/menu graph, alias deep link, role crawl, breadcrumb chain, validator fixtures/runtime parity. | BLK-B02; IA-009/019–022; source inventories docs/recon/route-inventory.md and docs/recon/open-questions.md:30-37. |
6. S3 Low defects¶
| ID | Affected workflow / roles / package | Root-cause category | Required fix | Owner / dependencies | Proposed acceptance criteria | Required regression tests | Evidence / trace |
|---|---|---|---|---|---|---|---|
| STAB-042 | Supported UI primitives; all roles/packages | Duplicate component implementations | Deprecate root primitives; migrate supported imports to components/ui; maintain explicit temporary allowlist. |
FE Design System | Zero deprecated primitive import on supported surface, or each allowlist entry has owner/removal version. | Static import inventory, component smoke/visual snapshot for migrated pages. | src/components/AppButton.vue:1-40; src/components/ui/AppButton.vue:1-111; residual src/views/AdminViews/Infrastructure/Maintenance.vue:28-30; UX-008. |
| STAB-043 | Page headers/spacing; all roles/packages | Visual hierarchy drift | Standardize title/subtitle/breadcrumb/CTA zone and container spacing without changing domain workflow. | FE Design System | Supported page inventory uses approved shell/header contract; no duplicate/missing title. | Mobile/desktop visual snapshots, heading hierarchy, focus/landmark audit. | src/views/AdminViews/AcademicConfig/AcademicYear/AcademicYearList.vue:4-9; src/views/AdminViews/AcademicConfig/GradeLevel/GradeLevelList.vue:4-9; docs/ai-guidelines/ui-design-pattern.md:31-33; UX-011. |
7. Decision register — explicitly not bugs¶
No row in this section may receive S0–S3. A decision selects the intended product contract; only a divergence from the selected contract becomes a defect.
| Decision ID | Existing decision IDs | Decision required | Affected defects/workflows | Recommended owner | Unblock condition |
|---|---|---|---|---|---|
| DEC-001 | SM-01–SM-03 | Approve V1 packages, workflow/support status, mixed-shell boundary, and pilot entry/exit. | STAB-001/004/006/013/024–026/028; all workflows | Product + Commercial + Operations | Signed 01 catalog, tenant package profiles, owner and review date. |
| DEC-002 | RP-01 | Active role enforcement vs union/separate-account model. | STAB-007/017/025; W00/all sensitive | Security + Product | Chosen semantics, migration, conflict-role rules and tests approved. |
| DEC-003 | RP-02/RP-03, PR-03 | Capability taxonomy and tenant/company/school/class/assignment/self/child/cross-company policy. | STAB-001–008,010–018,023–025,027/030/032 | Security + DPO + domain owners | Action/scope matrix signed and machine-readable acceptance updated. |
| DEC-004 | PO-02, AM-01/AM-03 | Process owner, maker-checker, delegation and conflict-of-interest. | STAB-001–004,009–016 | Product + Finance/HR/Academic/Operations/Security | Named accountable owner and approval/delegation matrix per domain. |
| DEC-005 | PO-03, ER-01–ER-03 | Exception, recovery, escalation and irreversible-action ownership. | STAB-009/012/019/029–031/035/039 | Operations + Support + domain owners | L1/L2/L3, recovery/compensating path, prohibited retries and SLA signed. |
| DEC-006 | PO-01, AM-02, SG-02, ATT-D01–D17 | W05 actors, completion/correction, status model, notification, privacy and exceptions. | STAB-017–022/027/040; W05 | Attendance PO + School SME + Security/DPO | Complete W05 transition/role/field/privacy matrix and pilot exit criteria signed. |
| DEC-007 | SG-01–SG-03 | Canonical state glossary, irreversibility and correction/reversal semantics. | STAB-003/009/012/019/020/030/033/035/040 | Product Design + domain owners | State/action/entry/exit/downstream/recovery table approved. |
| DEC-008 | MD-01–MD-03 | Master-data source/owner, matching/deletion and config effective dates. | STAB-004/013/014/016/018/023/032 | Data Steward + Integration/domain owners | Field/record ownership, conflict and deletion/config policy approved. |
| DEC-009 | PR-01/PR-02 | Sensitive field, attachment/proof viewer, validation, retention/download/delete. | STAB-001/002/005/006/010/012/021 | DPO + Security + Storage/domain owners | Purpose/field/viewer/retention matrix and threat controls approved. |
| DEC-010 | NT-01–NT-03 | Notification events, recipients, channel, dedupe, failure/retry and authoritative record. | STAB-015/016/029/033 | Communications + Operations + DPO | Event-recipient-channel matrix, failure visibility and SLA approved. |
| DEC-011 | LD-01–LD-03, CH-01–CH-03 | Legacy/alias/deprecation and contextual-help delivery boundary. | STAB-024–026/033/040/041 | Product + Platform + Documentation | Canonical IDs, sunset/redirect telemetry and hidden-surface rule approved. |
| DEC-012 | RB-01–RB-03 | Named runtime baseline, role fixtures and evidence threshold. | STAB-007/017/024–028; CTRL-001–004 | Operations + QA + Identity/RBAC | Golden Tenant/versioned manifest/accounts and evidence policy approved. |
| DEC-013 | No normalized prior workshop ID; exposed by current jenjang/timezone branch audit | Approve the V1 certified school-profile set: jenjang/equivalence branches, supported IANA school timezones, and any profile-specific menu/workflow differences. | W00 and every certified date-sensitive workflow/leaf mapped by CTRL-005; W01/W05/W06/W20 are the minimum known set; STAB-022/037/040; QG-01/04/05/12/17 | Product + Operations + School SME + QA | Signed profile matrix; one deterministic Golden profile per retained branch/timezone class; navigation, authorization, and date-boundary cases bound to the release manifest. No package inherits WIB or non-early-years proof without an approved equivalence mapping. |
| DEC-014 | No normalized prior workshop ID; exposed by W00 exception-surface audit | Approve the V1 credential lifecycle and recovery boundary: account activation, forced-password change, self/admin reset, unlock, expiry, concurrent-session revocation, recovery-channel ownership, break-glass eligibility, and audit/notification. Explicitly remove or hide every excluded surface. | W00/W02 identity activation; STAB-007; E2E-GAP-12; QG-03/06/08/09/11/16 | Product + Identity/RBAC + Security + Operations/Support + DPO for recovery data | Signed state/action/actor/channel/token/session/audit matrix; fresh-role fixtures; retained paths have positive/negative/replay/expiry/revocation tests; excluded routes/actions are absent or denied. |
Workshop source: docs/documentation-planning/decision-workshop.md:31-127. Recommended defaults remain proposals, not hidden engineering decisions.
8. Readiness controls and verification-only findings — no bug severity¶
| Control | Source finding | Required work | Owner | Completion evidence |
|---|---|---|---|---|
| CTRL-001 | BLK-A01, IA-026, RB-01/RB-02 | Establish exact served runtime/product/role baseline and repeatable Golden Tenant; this is missing release evidence, not an application defect by itself. | Release + Operations + QA | Three deterministic seed/reset runs, exact FE/BE/DB/module/entitlement manifest, fresh-role login/menu/API snapshots. |
| CTRL-002 | BLK-B05 | Quarantine/supersede existing W05 user-guide claims until STAB-017–022/027 and DEC-006 pass. No final user documentation is produced in this task. | Documentation Owner + Attendance PO | Artifact inventory points to freeze status; no guide is treated as product contract. Evidence docs/documentation-planning/documentation-blockers.md:405-416. |
| CTRL-003 | NB-01 | Runtime-certify current weekly approval guards/company scope; static code improvement is not an open defect absent failing evidence. | LMS Owner + QA | Authorized approver, unrelated teacher/company, self-approval policy and audit/state tests tied to release build. Evidence docs/documentation-planning/documentation-blockers.md:480-491. |
| CTRL-004 | NB-02 | Runtime-certify LMS assignment idempotency, including concurrency where field uniqueness is not statically proved. | LMS Owner + QA | Same/concurrent token produces one record/side effect; timeout retry deterministic. Evidence docs/documentation-planning/documentation-blockers.md:492-502. |
| CTRL-005 | E2E-GAP-01–E2E-GAP-12 | Establish a truthful package denominator: map every retained canonical leaf/page to a named workflow/subflow and required release-test parameters, or narrow/remove it from the product contract. This is missing certification coverage, not proof of an application defect. | Product + Package Owners + QA/Release | Signed leaf→workflow→test manifest; all RT-PKG-GAP-* controls closed; package result denominator cannot omit an enabled surface or use a combined bridge as a standalone SKU certificate. Evidence 05 §8.1 and 07 §10.2. |
| CTRL-006 | E2E-GAP-12; W00 credential exception surface | Bound the credential lifecycle before release: retain only approved activation/change/reset/unlock/expiry/session-revocation/break-glass paths, assign recovery ownership, and create deterministic fresh-account/token/session fixtures. This is a decision/evidence gate, not a claim that every current path is defective. | Product + Identity/RBAC + Security + Operations/Support + QA | DEC-014 signed; route/action inventory maps every retained surface to W00 cases; excluded surface hidden/denied; RT-W00-REC-01 and RT-PKG-GAP-12 pass with token replay/expiry, session revocation, least privilege, safe notification and audit evidence. Code leads: src/router/adminShellRoutes.js:61-68, src/components/ChangePassword.vue:187-203, ../custom_addons_scola/gcgscola/scola_core/controllers/auth.py:367-400. |
9. Trace reconciliation¶
9.1 Existing blocker register coverage¶
| Source | Normalized destination |
|---|---|
| BLK-A01 | CTRL-001 |
| BLK-A02–A04 | STAB-007, STAB-008, STAB-001 |
| BLK-A05–A17 | STAB-009, STAB-002, STAB-010, STAB-011, STAB-003, STAB-012, STAB-004, STAB-005, STAB-013, STAB-014, STAB-006, STAB-015, STAB-016 |
| BLK-A18 | STAB-026 |
| BLK-A19–A23 | STAB-017–STAB-021 |
| BLK-B01–B04 | STAB-024/DEC-001, STAB-025/STAB-041, STAB-023, STAB-027 |
| BLK-B05–B08 | CTRL-002, STAB-029, STAB-030, STAB-031 |
| BLK-B09 | DEC-004/005/007 — auto-post behavior is confirmed, but desired approval/reversal is a product/finance decision until selected |
| BLK-B10–B11 | STAB-032, STAB-033 |
| NB-01/NB-02 | CTRL-003/CTRL-004 |
Source index: docs/documentation-planning/documentation-blockers.md:41-76,78-502.
9.2 UX, authorization and IA audit coverage¶
| Audit source | Normalized destination |
|---|---|
| UX-001–UX-005 | STAB-022, STAB-027, STAB-019, STAB-020, STAB-021 |
| UX-006–UX-010 | STAB-034, STAB-035, STAB-042, STAB-036, STAB-037 |
| UX-011–UX-018 | STAB-043, STAB-038, STAB-038, STAB-039, STAB-035, STAB-040, STAB-037, STAB-039 |
| UX-019/UX-020 | No defect; intentional differences remain gated by IC-01–IC-14 in docs/release-readiness/03-ux-consistency-audit.md. |
| AUTH-001–AUTH-004 | STAB-007/STAB-008 |
| AUTH-005–AUTH-012 | Cross-cutting acceptance on STAB-001–STAB-027; exact BLK mapping is in docs/release-readiness/04-authorization-readiness.md. |
| AUTH-013/AUTH-014 | STAB-007/017/023–028 plus CTRL-001–004 |
| IA-001 | STAB-024 |
| IA-002–IA-005 | STAB-025 |
| IA-006/IA-007 | STAB-026 |
| IA-008 | STAB-025 |
| IA-009/IA-010 | STAB-041/STAB-033 |
| IA-011–IA-014 | STAB-016/STAB-024/STAB-040 |
| IA-015–IA-018 | STAB-025 |
| IA-019–IA-022 | STAB-041 |
| IA-023 | STAB-024 |
| IA-024 | STAB-023 |
| IA-025 | STAB-027 |
| IA-026 | CTRL-001 |
IA evidence is defined in docs/release-readiness/02-information-architecture.md:169-194 under the exact IA IDs; no additional IA ID is invented here.
10. Backlog execution and closure contract¶
- Contain before repair: S0 and any directly exposed unsupported/placeholder surface is hidden/disabled for normal roles until fixed and tested. Containment is not closure.
- Decide before encoding: close linked DEC rows before implementing actor/state/approval/privacy semantics. Security deny-default and data-minimization do not wait for a permissive business decision.
- Fix by dependency: platform AUTH/package/IA defects (STAB-007/008/024/025/028) precede domain fixes; W01/W02 prerequisites precede W05; optional packages certify separately.
- One closure record: each defect records root cause, code/config/schema references, exact tests, before/after Golden Tenant result, owner review, and release manifest.
- No evidence-free downgrade: S0/S1 can only be downgraded after tests disprove the impact or scope is removed from product surface. A warning cannot close an authorization/privacy/data-integrity issue.
- Regression is mandatory: every row’s listed positive and negative tests join
07-release-test-matrix.md; required skipped/not-run cases fail the gate. - Reconcile after decisions: selected DEC outcome must create explicit implementation/test deltas; decisions never auto-close linked defects.
Definition of backlog-ready for implementation¶
This backlog is ready to drive tranches when:
- Product approves the relevant package/workflow boundary and every item has a named person/team owner;
- DEC dependencies for the tranche have dated decisions;
- each implementation unit is small enough to fix one root cause and carries the listed acceptance/regression IDs;
- Golden Tenant prerequisites and second-tenant fixtures exist;
- containment is active for open S0 and unsupported/incomplete surfaces;
- no duplicate issue is implemented twice: BLK/UX/AUTH/IA references resolve to the single STAB row above; and
- closure is judged by QG-01–QG-18 on one exact build, not by merging code alone.