You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
These are the leftovers from #8352, #8367 and #8369. All three issues were checked on 2026-09-24, finding by finding, against main at 952db28. Most findings had landed through separate per-finding PRs. The items below are what is still open on main. Their parent issues are being closed with a comment that maps each finding to the PR that fixed it.
Dashboard DebugBear still holds live objects.src/bootstrap/debugbear-rum.ts stores live Event objects, not primitive snapshots. Its error/unhandledrejection listeners stay attached after the vendor script loads.
Theme "Auto" with nothing stored does not follow the OS. Settings shows Auto, but applyStoredTheme attaches the prefers-color-scheme listener only when 'auto' is stored, so the page never follows OS changes. getStoredTheme() also still turns 'auto' into dark.
Live Channels page ignores Auto. The pre-paint script in live-channels.html ignores Auto and the OS theme, and src/live-channels-main.ts never calls applyStoredTheme().
webmcp docs show the old pattern.docs/webmcp.mdx:132 and docs/zh/webmcp.mdx:132 still document the lowercase-only set_panel_enabled pattern; the code has accepted mixed case since fix: accept mixed-case dashboard catalog IDs #8255.
Happy-variant GDELT panels are empty (Browser service-layer defects outside the shared root causes (7 findings) #8367). Happy-variant positive GDELT topics (src/services/gdelt-intel.ts:321-353) still send the old DOC-API query strings. The handler matches only seeded topic ids, and the positive topics aren't seeded, so those panels come back empty. toneFilter and sort are also not implemented on the server.
Also audit api/invalidate-user-api-key-cache.ts, api/referral/me.ts and api/{discord,slack}/oauth/start.ts.
Empty key headers can hide a real key (Entitlement and auth checks enforced on one route are absent on equivalent routes (7 sites) #8352 bug class, audit). ??-based header resolution is still used in api/widget-agent.ts, api/mcp-proxy.ts, api/embed/{session,entitlement}.ts and scenario-job.ts, so an empty X-WorldMonitor-Key hides X-Api-Key. Check which way each one fails. premium-check.ts denies access in that case (the safe direction).
Product decision, not a bug
sanctions:pressure:v1 is still served anonymously through /api/bootstrap (shared/bootstrap-tier-keys.js), and the client reads it for non-premium users on purpose. Only sanctions:entities is Pro-only in practice. Decide whether this is intended.
These are the leftovers from #8352, #8367 and #8369. All three issues were checked on 2026-09-24, finding by finding, against main at 952db28. Most findings had landed through separate per-finding PRs. The items below are what is still open on main. Their parent issues are being closed with a comment that maps each finding to the PR that fixed it.
Being ported from the closed #8379 (follow-up PR)
/pro DebugBear queue has no size limit.
pro-test/src/debugbear-rum.ts:52-60still has the original Browser bootstrap, config and utility defects (5 findings) #8369 bug:Eventobjects;The dashboard copy was fixed in fix: bound DebugBear error buffering and preserve live forwarding #8249; this one was not.
Dashboard DebugBear still holds live objects.
src/bootstrap/debugbear-rum.tsstores liveEventobjects, not primitive snapshots. Itserror/unhandledrejectionlisteners stay attached after the vendor script loads.Theme "Auto" with nothing stored does not follow the OS. Settings shows Auto, but
applyStoredThemeattaches theprefers-color-schemelistener only when'auto'is stored, so the page never follows OS changes.getStoredTheme()also still turns'auto'into dark.Live Channels page ignores Auto. The pre-paint script in
live-channels.htmlignores Auto and the OS theme, andsrc/live-channels-main.tsnever callsapplyStoredTheme().webmcp docs show the old pattern.
docs/webmcp.mdx:132anddocs/zh/webmcp.mdx:132still document the lowercase-onlyset_panel_enabledpattern; the code has accepted mixed case since fix: accept mixed-case dashboard catalog IDs #8255.Still open, not in that PR
Pinned webcams panel goes stale (Browser service-layer defects outside the shared root causes (7 findings) #8367).
src/services/webcams/pinned-store.tsnever listens forstorageorwm:cloud-prefs-applied, so an openPinnedWebcamsPanelstays stale after a settings import, a cloud sign-in, or a change in another tab. Validation itself was fixed in fix(webcams): validate pinned records and player destinations #8219/fix: normalize pinned webcams across preference persistence #8220.Happy-variant GDELT panels are empty (Browser service-layer defects outside the shared root causes (7 findings) #8367). Happy-variant positive GDELT topics (
src/services/gdelt-intel.ts:321-353) still send the old DOC-API query strings. The handler matches only seeded topic ids, and the positive topics aren't seeded, so those panels come back empty.toneFilterandsortare also not implemented on the server.Hotspot "Live Intel" is not about the hotspot (Browser service-layer defects outside the shared root causes (7 findings) #8367, low). It shows generic articles for the hotspot's topic. A
country:XXquery, vianameToCountryCode, would make it about the hotspot.Merged news clusters keep the primary's velocity (Browser service-layer defects outside the shared root causes (7 findings) #8367, low). On the data-loader hybrid path, a semantic cluster merge keeps
primary.velocityinstead of recomputing it over the merged items.Session-verification outages return 401, not 503 (Entitlement and auth checks enforced on one route are absent on equivalent routes (7 sites) #8352 bug class). These endpoints call
validateBearerTokendirectly and return 401 when the session cannot be verified (a JWKS outage), instead of 503 + Retry-After:api/me/entitlement.ts:60api/customer-portal.ts:67api/latest-brief.ts:197api/brief/share-url.ts:94Also audit
api/invalidate-user-api-key-cache.ts,api/referral/me.tsandapi/{discord,slack}/oauth/start.ts.Empty key headers can hide a real key (Entitlement and auth checks enforced on one route are absent on equivalent routes (7 sites) #8352 bug class, audit).
??-based header resolution is still used inapi/widget-agent.ts,api/mcp-proxy.ts,api/embed/{session,entitlement}.tsandscenario-job.ts, so an emptyX-WorldMonitor-KeyhidesX-Api-Key. Check which way each one fails.premium-check.tsdenies access in that case (the safe direction).Product decision, not a bug
sanctions:pressure:v1is still served anonymously through/api/bootstrap(shared/bootstrap-tier-keys.js), and the client reads it for non-premium users on purpose. Onlysanctions:entitiesis Pro-only in practice. Decide whether this is intended.