Epic: Production readiness review
メンテナーはふだん 1 日以内に返信
まだ誰も着手していません。
評価
- 難易度
- 5/5
- 見積もり時間
- 1週間以上
- 初心者へのやさしさ
- 25/100
調査の方向性
LearnStack.Core のサービスとエンティティ、Blazor Server アプリ、38 件のユニットテスト、Azure のデプロイワークフローを確認し、段階別の調査結果をレビュー用チェックリストとして使用します。まず、エピックを独立して検証可能なサブ Issue に分割します。完了とは、各運用上のリスクについて、根拠があり、合意されたスコープと明確な検証経路があることを意味します。
索引モデルが issue の本文から書いたものです。
説明
Overview
Full static review of the solution — LearnStack.Core (7 entities, 5 services), the Blazor Server app (14 pages, Identity + passkeys, 5 languages), 38 unit tests, and the Azure deployment workflow — to identify what is needed before opening the app to real users.
[!NOTE]
This review is static analysis only: the code was read, not built or executed. Each sub-issue records the evidence (file + line) it is based on so it can be verified independently.
Verdict: the product surface is in good shape (resources, content ideas, friends, shared collections, Pulse, PWA, i18n). What is missing is almost entirely the operational layer — transactional email, data-protection key persistence, observability, database indexes, rate limiting and CI gates. Roughly five items will cause real problems on the first day of real traffic.
Nothing here is committed work — this epic is a backlog to triage.
Tier 1 — Release blockers
| Area | Problem |
|---|---|
| Auth / email | Email sender is a no-op: password reset and email confirmation silently do nothing |
| Data Protection | No key persistence — every restart or scale-out logs every user out |
| Migrations | MigrateAsync() on startup rethrows and races across instances |
| CI | Tests never gate the deploy; no PR build workflow exists |
| Deploy | No staging slot, smoke test or rollback; publish-profile secret instead of OIDC |
| Observability | No health checks, no telemetry, no structured logging |
Tier 2 — Scale, security and cost
| Area | Problem |
|---|---|
| Thumbnails | Up to 5 MB blobs on the resource row, base64-inlined into every render |
| Indexes | No index on UserId on any user-owned table |
| Pagination | Whole library loaded into memory, then filtered and paged in the component |
| Rate limiting | Nothing throttled — auth, public share pages, or the metadata fetcher |
| SSRF | Redirects bypass the private-IP check; unbounded response body |
| Edge hardening | No security headers, AllowedHosts: "*", no forwarded headers |
| Config | LocalDB connection string committed as the production default |
| Concurrency | No RowVersion; concurrent edits overwrite each other silently |
Tier 3 — Correctness and polish
| Area | Problem |
|---|---|
| Account deletion | Likely FK failure for users with linked ideas or shared collections (GDPR-facing) |
DisplayName |
Settable but never displayed; email local-part shown instead |
| Dead code | CultureMiddleware never registered |
| Localization | ro offered but has no resource file; ~56 strings untranslated in de/es/fr/it |
| Timezones | Everything UTC — relative dates and Pulse charts are wrong outside UTC |
| Repo hygiene | build_err.txt committed, leaking local paths |
| Tests | 38 tests, Core services only — no authorization-boundary or component tests |
| Supply chain | No Dependabot, CodeQL or secret scanning |
Tier 4 — Feature ideas
Categories/tags as first-class entities, browser extension and PWA share target, import from Pocket/Raindrop/bookmarks, digest email, AI assist on resources, full-text search, offline PWA, public profile pages, share analytics, admin dashboard, streaks and goals on Pulse.
Suggested sequencing
- Week 1 — cannot launch without: real email sender + confirmed accounts, Data Protection keys, migrations out of startup, PR CI that actually gates, health checks + telemetry.
- Week 2 — survives users: thumbnails out of SQL, indexes + server-side pagination, rate limiting, security headers, redirect-aware SSRF fix.
- Week 3 — trust: fix account deletion, authorization-boundary tests, staging slot + swap, Dependabot/CodeQL, finish the translations.
- Then features: browser extension / share target and import first — they address the biggest friction in the current flow.
- 主要言語
- HTML
- スター
- 10
- フォーク
- 0
- 平均マージ
- 2時間 35分
- マージ済み PR(30日)
- 21
環境構築
- Dockerfile・Docker Compose ファイルなし
- プルリクエストのテンプレートなし
- コントリビューションガイドを読む
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
kasuken/LearnStack のほかの issue
-
enhancement
難易度 1/5 1時間未満 初心者へのやさしさ 91/100
kasuken/LearnStack#59 ·
メンテナーはふだん 1 日以内に返信
-
enhancement
難易度 5/5 1週間以上 初心者へのやさしさ 35/100
kasuken/LearnStack#72 ·
メンテナーはふだん 1 日以内に返信
-
enhancement
難易度 5/5 1週間以上 初心者へのやさしさ 30/100
kasuken/LearnStack#71 ·
メンテナーはふだん 1 日以内に返信
-
enhancement
難易度 5/5 1週間以上 初心者へのやさしさ 35/100
kasuken/LearnStack#70 ·
メンテナーはふだん 1 日以内に返信
-
enhancement
難易度 5/5 1週間以上 初心者へのやさしさ 45/100
kasuken/LearnStack#69 ·
メンテナーはふだん 1 日以内に返信
kasuken/LearnStack の issue をすべて見る
似ている issue
-
[Bug][Python SDK] RecallMemory drops RFC-3339 created_at write-time timestamp returned by relayerオープン
難易度 2/5 1〜3時間 初心者へのやさしさ 82/100
MystenLabs/MemWal#1160 · コメント 2 件 ·
メンテナーはふだん 1 日以内に返信
-
Idle compaction monitors LIST the replica every tick when the newest destination file spans more than one TXID対応中かも @pishuv が今日担当しました。 オープン
難易度 2/5 1〜3時間 初心者へのやさしさ 72/100
benbjohnson/litestream#1563 ·
メンテナーはふだん 2 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 75/100
メンテナーはふだん 1 日以内に返信
-
Fix Math.ceilDiv wrong result for exact positive divisions対応中かも @pamod-madubashana が今日担当しました。 オープン
難易度 2/5 1〜3時間 初心者へのやさしさ 88/100
scala-native/scala-native#5094 ·
メンテナーはふだん 1 日以内に返信
-
難易度 1/5 1時間未満 初心者へのやさしさ 88/100
メンテナーはふだん 1 日以内に返信