Skip to content

docs: Apache-2.0 licence and public-repository kit - #54

Merged
ovander merged 1 commit into
mainfrom
claude/socrate-suite-audit-3wqcnp
Sep 29, 2026
Merged

ovander merged 1 commit into
mainfrom
claude/socrate-suite-audit-3wqcnp

Conversation

@ovander

@ovander ovander commented Sep 29, 2026

Copy link
Copy Markdown
Owner

What and why

This prepares backendkit to be made public. It follows the same kit and conventions as ascenda-backend, ascenda-frontend and ha-vigie.

Licence and contributor kit

  • LICENSE: Apache-2.0, byte-identical to ha-vigie's.
  • CONTRIBUTING.md: setup, design rules, the exact CI checks, the pull-request flow and releases.
  • SECURITY.md: private vulnerability reporting, scope (the Socrate server itself is out of scope and goes to go-oauth2), supported versions, and past reviews.
  • CLAUDE.md: standing instructions in the same shape as ascenda-backend's.
  • .github/: CODEOWNERS, issue forms (bug.yml with a package dropdown, feature.yml, and config.yml linking to private reporting and go-oauth2) and a pull-request template.

README

  • bff and ailang had no package reference at all. They now have sections, with examples that I compiled and vetted against the module. bff also gets a "safe by default" table. Every row in that table was checked against the code:
    • no session → 401, and a bad CSRF token → 403 (gateway.go);
    • SanitizeReturnTo turns //host, absolute URLs, backslash and control-character inputs into /. I ran these inputs to confirm.
  • Both are added to the package tables, the "which package do I need" table and the contents.
  • New Security and License sections.

Fixes

  • The Socrate link in README.md:7 and docs/CLIENT-INTEGRATION.md:4 pointed to github.com/ovander/socrate, which does not exist. It now points to ovander/go-oauth2.
  • README contributing guideline 6 said that only ctxutil/apierror may be imported across packages, but the code also has bff/pep → socrate and aigateway → ailang. The rule now matches the code.

Removed from the public tree

  • CTO-ARCHITECTURE-REVIEW.md, FRAMEWORK-EVOLUTION.md, SECURITY-ARCHITECTURE.md and SECURITY-AUDIT.md. The two audits still carry "open" markers and a status table last updated at v1.9.0, so they shouldn't be published as they are. The files are archived privately. CHANGELOG.md still lists the fixes with their finding IDs.

How it was tested

  • go build ./..., go vet ./... and go test -race -count=1 ./... pass (14 packages). The PR changes no Go code.
  • The README bff and ailang examples compile and pass go vet against this module.
  • The issue forms parse as YAML, and every README anchor resolves.
  • A line is added under ## [Unreleased] in CHANGELOG.md.

A gitleaks scan of the full history (all branches and tags) found no secrets. It raised 0 findings on backendkit, and 4 false positives across the suite.

Compatibility

  • Exported API: none changed.
  • After merging, enable private vulnerability reporting in Settings → Code security, since SECURITY.md and the issue config point to it.

🤖 Generated with Claude Code

https://claude.ai/code/session_01GKRxaeYxyDhmt42cehLsGA


Generated by Claude Code

Prepare the repository for public visibility, following the conventions of
ovander/ascenda-backend and ovander/ha-vigie.

- LICENSE: Apache-2.0 (the same text as ha-vigie).
- CONTRIBUTING.md, SECURITY.md (private vulnerability reporting, scope,
  supported versions), CLAUDE.md, .github/CODEOWNERS, issue forms (bug,
  feature, config) and a pull-request template.
- README: package reference sections for bff and ailang, which had none,
  with examples compiled and vetted against the module; package and
  "which package" table rows; Security and License sections.
- Fix the Socrate link in README and docs/CLIENT-INTEGRATION.md, which
  pointed to a repository that does not exist (now ovander/go-oauth2).
- Fix the README contributing rule on cross-package imports to match the
  code (bff/pep -> socrate, aigateway -> ailang).
- Move the internal review documents out of the public tree (kept
  privately); CHANGELOG still lists the fixes with their finding IDs.

No Go code changes.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GKRxaeYxyDhmt42cehLsGA
@ovander
ovander merged commit 70337ae into main Sep 29, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants