Hacktoberfest 2026:维护者为十月标记出来的 issue,仍然开放、适合新手。 浏览 Hacktoberfest issue

Epic: Production readiness review

未关闭
#38 0 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看

维护者通常 1 天内回复

还没有人认领这个 Issue。

评估

难度
5/5
预计耗时
一周以上
新手友好度
25/100
Issue 类型
重构
描述清晰度
需要澄清
活跃度
活跃
技术栈
azure

调研方向

阅读 LearnStack.Core 的服务和实体、Blazor Server 应用、38 个单元测试以及 Azure 部署工作流,并将分层发现作为审查清单。首先将 epic 拆分为可独立验证的子 issue;完成意味着每个运营风险都有证据、已达成一致的范围以及明确的验证路径。

由索引模型根据 Issue 内容生成。

描述

enhancement

Overview

Full static review of the solution — LearnStack.Core (7 entities, 5 services), the Blazor Server app (14 pages, Identity + passkeys, 5 languages), 38 unit tests, and the Azure deployment workflow — to identify what is needed before opening the app to real users.

[!NOTE]
This review is static analysis only: the code was read, not built or executed. Each sub-issue records the evidence (file + line) it is based on so it can be verified independently.

Verdict: the product surface is in good shape (resources, content ideas, friends, shared collections, Pulse, PWA, i18n). What is missing is almost entirely the operational layer — transactional email, data-protection key persistence, observability, database indexes, rate limiting and CI gates. Roughly five items will cause real problems on the first day of real traffic.

Nothing here is committed work — this epic is a backlog to triage.

Tier 1 — Release blockers
Area Problem
Auth / email Email sender is a no-op: password reset and email confirmation silently do nothing
Data Protection No key persistence — every restart or scale-out logs every user out
Migrations MigrateAsync() on startup rethrows and races across instances
CI Tests never gate the deploy; no PR build workflow exists
Deploy No staging slot, smoke test or rollback; publish-profile secret instead of OIDC
Observability No health checks, no telemetry, no structured logging
Tier 2 — Scale, security and cost
Area Problem
Thumbnails Up to 5 MB blobs on the resource row, base64-inlined into every render
Indexes No index on UserId on any user-owned table
Pagination Whole library loaded into memory, then filtered and paged in the component
Rate limiting Nothing throttled — auth, public share pages, or the metadata fetcher
SSRF Redirects bypass the private-IP check; unbounded response body
Edge hardening No security headers, AllowedHosts: "*", no forwarded headers
Config LocalDB connection string committed as the production default
Concurrency No RowVersion; concurrent edits overwrite each other silently
Tier 3 — Correctness and polish
Area Problem
Account deletion Likely FK failure for users with linked ideas or shared collections (GDPR-facing)
DisplayName Settable but never displayed; email local-part shown instead
Dead code CultureMiddleware never registered
Localization ro offered but has no resource file; ~56 strings untranslated in de/es/fr/it
Timezones Everything UTC — relative dates and Pulse charts are wrong outside UTC
Repo hygiene build_err.txt committed, leaking local paths
Tests 38 tests, Core services only — no authorization-boundary or component tests
Supply chain No Dependabot, CodeQL or secret scanning
Tier 4 — Feature ideas

Categories/tags as first-class entities, browser extension and PWA share target, import from Pocket/Raindrop/bookmarks, digest email, AI assist on resources, full-text search, offline PWA, public profile pages, share analytics, admin dashboard, streaks and goals on Pulse.

Suggested sequencing
  1. Week 1 — cannot launch without: real email sender + confirmed accounts, Data Protection keys, migrations out of startup, PR CI that actually gates, health checks + telemetry.
  2. Week 2 — survives users: thumbnails out of SQL, indexes + server-side pagination, rate limiting, security headers, redirect-aware SSRF fix.
  3. Week 3 — trust: fix account deletion, authorization-boundary tests, staging slot + swap, Dependabot/CodeQL, finish the translations.
  4. Then features: browser extension / share target and import first — they address the biggest friction in the current flow.
主要语言
HTML
星标
10
派生
0
平均合并
2 小时 35 分钟
30 天内合并 PR
21

环境准备

  • 没有 Dockerfile 或 Docker Compose 文件
  • 没有 Pull Request 模板
  • 阅读贡献指南

从这里开始

  1. 先读完整个 Issue,再读项目的贡献指南。
  2. 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
  3. Fork 仓库,在一个分支上完成修改。
  4. 提交 Pull Request,并在描述里引用这个 Issue 编号。

kasuken/LearnStack 的其他 Issue

查看 kasuken/LearnStack 的全部 Issue

相似的 Issue

更多 Backend & API Design Issue

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。