The review of #35 (merged for #16, the spec following milestones 1 and 2) and its worker noticed points the spec leaves open. None blocked it.
The header size and the idle time are settings in SPEC.md (SWWAF_CLIENT_REQUEST_HEADER_MAX_BYTES, SWWAF_CLIENT_IDLE_TIMEOUT), but milestone 1 fixes them at their defaults and no later stage in the build order makes them settings.
With the size limits, the PR removed "of two matching limits the lower one acts first". That still applies to the paired client and app timeouts: a slow upload also slows the send to the app, and the spec no longer says whether it then gets 408 or 504.
README.md still lists the GeoJS answers among what the state files keep "so a restart loses nothing", without the "milestone 3 or later" its lookup section now has.
README.md says "milestone 3 or later" without saying what the milestones are; a pointer to the build order in SPEC.md would settle it.
Milestone 2 skips clients on private addresses in the country lists, while the full design has the allow-only list refuse them; the spec does not say which stage brings the full behaviour.
Model: opus-5-5
The review of https://git.eeqj.de/sneak/smallwebwaf/pulls/35 (merged for https://git.eeqj.de/sneak/smallwebwaf/issues/16, the spec following milestones 1 and 2) and its worker noticed points the spec leaves open. None blocked it.
- The header size and the idle time are settings in `SPEC.md` (`SWWAF_CLIENT_REQUEST_HEADER_MAX_BYTES`, `SWWAF_CLIENT_IDLE_TIMEOUT`), but milestone 1 fixes them at their defaults and no later stage in the build order makes them settings.
- With the size limits, the PR removed "of two matching limits the lower one acts first". That still applies to the paired client and app timeouts: a slow upload also slows the send to the app, and the spec no longer says whether it then gets `408` or `504`.
- `README.md` still lists the GeoJS answers among what the state files keep "so a restart loses nothing", without the "milestone 3 or later" its lookup section now has.
- `README.md` says "milestone 3 or later" without saying what the milestones are; a pointer to the build order in `SPEC.md` would settle it.
- Milestone 2 skips clients on private addresses in the country lists, while the full design has the allow-only list refuse them; the spec does not say which stage brings the full behaviour.
Model: opus-5-5
clawbot
self-assigned this 2026-09-29 02:10:49 +02:00
Plan. Docs only, one PR to next changing SPEC.md and README.md. Each point, decided:
Header size and idle time: they stay settings in the full design, fixed at their defaults in milestones 1 and 2. The build order lists them in the first stage after milestone 2.
Paired request timeouts: when the request body is still streaming and a request timeout runs out, the answer names the side smallwebwaf was waiting on at that moment: 408 if it was waiting for the client to send more, 504 if it was waiting for the app to take what it had. Milestone 1 (#13) builds the same rule.
README.md's list of what the state files keep marks the GeoJS answers as written to disk from milestone 3 or later, as its lookup section already says.
README.md points "milestone 3 or later" at the build order in SPEC.md.
Private addresses and the allow-only country list: the full behaviour (refused unless listed in SWWAF_ALLOW_NETS) comes in the first stage after milestone 2, together with the static lists that bring SWWAF_ALLOW_NETS. The build order says so.
Model: opus-5-5
Plan. Docs only, one PR to `next` changing `SPEC.md` and `README.md`. Each point, decided:
- Header size and idle time: they stay settings in the full design, fixed at their defaults in milestones 1 and 2. The build order lists them in the first stage after milestone 2.
- Paired request timeouts: when the request body is still streaming and a request timeout runs out, the answer names the side smallwebwaf was waiting on at that moment: `408` if it was waiting for the client to send more, `504` if it was waiting for the app to take what it had. Milestone 1 (https://git.eeqj.de/sneak/smallwebwaf/issues/13) builds the same rule.
- `README.md`'s list of what the state files keep marks the GeoJS answers as written to disk from milestone 3 or later, as its lookup section already says.
- `README.md` points "milestone 3 or later" at the build order in `SPEC.md`.
- Private addresses and the allow-only country list: the full behaviour (refused unless listed in `SWWAF_ALLOW_NETS`) comes in the first stage after milestone 2, together with the static lists that bring `SWWAF_ALLOW_NETS`. The build order says so.
Model: opus-5-5
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
The review of #35 (merged for #16, the spec following milestones 1 and 2) and its worker noticed points the spec leaves open. None blocked it.
SPEC.md(SWWAF_CLIENT_REQUEST_HEADER_MAX_BYTES,SWWAF_CLIENT_IDLE_TIMEOUT), but milestone 1 fixes them at their defaults and no later stage in the build order makes them settings.408or504.README.mdstill lists the GeoJS answers among what the state files keep "so a restart loses nothing", without the "milestone 3 or later" its lookup section now has.README.mdsays "milestone 3 or later" without saying what the milestones are; a pointer to the build order inSPEC.mdwould settle it.Model: opus-5-5
Plan. Docs only, one PR to
nextchangingSPEC.mdandREADME.md. Each point, decided:408if it was waiting for the client to send more,504if it was waiting for the app to take what it had. Milestone 1 (#13) builds the same rule.README.md's list of what the state files keep marks the GeoJS answers as written to disk from milestone 3 or later, as its lookup section already says.README.mdpoints "milestone 3 or later" at the build order inSPEC.md.SWWAF_ALLOW_NETS) comes in the first stage after milestone 2, together with the static lists that bringSWWAF_ALLOW_NETS. The build order says so.Model: opus-5-5
Opened #46 for this.
Model: opus-5-5
clawbot referenced this issue2026-10-04 02:58:02 +02:00