Epic: Production readiness review
维护者通常 1 天内回复
还没有人认领这个 Issue。
评估
- 难度
- 5/5
- 预计耗时
- 一周以上
- 新手友好度
- 25/100
调研方向
阅读 LearnStack.Core 的服务和实体、Blazor Server 应用、38 个单元测试以及 Azure 部署工作流,并将分层发现作为审查清单。首先将 epic 拆分为可独立验证的子 issue;完成意味着每个运营风险都有证据、已达成一致的范围以及明确的验证路径。
由索引模型根据 Issue 内容生成。
描述
Overview
Full static review of the solution — LearnStack.Core (7 entities, 5 services), the Blazor Server app (14 pages, Identity + passkeys, 5 languages), 38 unit tests, and the Azure deployment workflow — to identify what is needed before opening the app to real users.
[!NOTE]
This review is static analysis only: the code was read, not built or executed. Each sub-issue records the evidence (file + line) it is based on so it can be verified independently.
Verdict: the product surface is in good shape (resources, content ideas, friends, shared collections, Pulse, PWA, i18n). What is missing is almost entirely the operational layer — transactional email, data-protection key persistence, observability, database indexes, rate limiting and CI gates. Roughly five items will cause real problems on the first day of real traffic.
Nothing here is committed work — this epic is a backlog to triage.
Tier 1 — Release blockers
| Area | Problem |
|---|---|
| Auth / email | Email sender is a no-op: password reset and email confirmation silently do nothing |
| Data Protection | No key persistence — every restart or scale-out logs every user out |
| Migrations | MigrateAsync() on startup rethrows and races across instances |
| CI | Tests never gate the deploy; no PR build workflow exists |
| Deploy | No staging slot, smoke test or rollback; publish-profile secret instead of OIDC |
| Observability | No health checks, no telemetry, no structured logging |
Tier 2 — Scale, security and cost
| Area | Problem |
|---|---|
| Thumbnails | Up to 5 MB blobs on the resource row, base64-inlined into every render |
| Indexes | No index on UserId on any user-owned table |
| Pagination | Whole library loaded into memory, then filtered and paged in the component |
| Rate limiting | Nothing throttled — auth, public share pages, or the metadata fetcher |
| SSRF | Redirects bypass the private-IP check; unbounded response body |
| Edge hardening | No security headers, AllowedHosts: "*", no forwarded headers |
| Config | LocalDB connection string committed as the production default |
| Concurrency | No RowVersion; concurrent edits overwrite each other silently |
Tier 3 — Correctness and polish
| Area | Problem |
|---|---|
| Account deletion | Likely FK failure for users with linked ideas or shared collections (GDPR-facing) |
DisplayName |
Settable but never displayed; email local-part shown instead |
| Dead code | CultureMiddleware never registered |
| Localization | ro offered but has no resource file; ~56 strings untranslated in de/es/fr/it |
| Timezones | Everything UTC — relative dates and Pulse charts are wrong outside UTC |
| Repo hygiene | build_err.txt committed, leaking local paths |
| Tests | 38 tests, Core services only — no authorization-boundary or component tests |
| Supply chain | No Dependabot, CodeQL or secret scanning |
Tier 4 — Feature ideas
Categories/tags as first-class entities, browser extension and PWA share target, import from Pocket/Raindrop/bookmarks, digest email, AI assist on resources, full-text search, offline PWA, public profile pages, share analytics, admin dashboard, streaks and goals on Pulse.
Suggested sequencing
- Week 1 — cannot launch without: real email sender + confirmed accounts, Data Protection keys, migrations out of startup, PR CI that actually gates, health checks + telemetry.
- Week 2 — survives users: thumbnails out of SQL, indexes + server-side pagination, rate limiting, security headers, redirect-aware SSRF fix.
- Week 3 — trust: fix account deletion, authorization-boundary tests, staging slot + swap, Dependabot/CodeQL, finish the translations.
- Then features: browser extension / share target and import first — they address the biggest friction in the current flow.
- 主要语言
- HTML
- 星标
- 10
- 派生
- 0
- 平均合并
- 2 小时 35 分钟
- 30 天内合并 PR
- 21
环境准备
- 没有 Dockerfile 或 Docker Compose 文件
- 没有 Pull Request 模板
- 阅读贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
kasuken/LearnStack 的其他 Issue
-
enhancement
难度 1/5 1 小时以内 新手友好度 91/100
kasuken/LearnStack#59 ·
维护者通常 1 天内回复
-
enhancement
难度 5/5 一周以上 新手友好度 35/100
kasuken/LearnStack#72 ·
维护者通常 1 天内回复
-
enhancement
难度 5/5 一周以上 新手友好度 30/100
kasuken/LearnStack#71 ·
维护者通常 1 天内回复
-
enhancement
难度 5/5 一周以上 新手友好度 35/100
kasuken/LearnStack#70 ·
维护者通常 1 天内回复
-
enhancement
难度 5/5 一周以上 新手友好度 45/100
kasuken/LearnStack#69 ·
维护者通常 1 天内回复
查看 kasuken/LearnStack 的全部 Issue
相似的 Issue
-
难度 1/5 1-3 小时 新手友好度 84/100
维护者通常 1 天内回复
-
enhancement pkg:sdk
难度 2/5 1-3 小时 新手友好度 80/100
aws/aws-durable-execution-sdk-go#144 ·
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 62/100
glpi-project/glpi#25883 ·
维护者通常 1 天内回复
-
beginner friendly community contributions-welcome enhancement good first issue hacktoberfest help wanted up-for-grabs
难度 2/5 1-3 小时 新手友好度 88/100
维护者通常 1 天内回复
-
HTML: <template> content is extracted as document text可能已有人在做 @ryanmeowy 今天认领。 未关闭bug html
难度 1/5 1 小时以内 新手友好度 82/100
docling-project/docling#4714 · 2 条评论 ·
维护者通常 1 天内回复