From 7e3f97f052d56f11d789deeb49f412ec878d5583 Mon Sep 17 00:00:00 2001 From: Tomas Dvorak Date: Fri, 18 Sep 2026 19:55:04 +0200 Subject: [PATCH] docs(roadmap): mark WebDAV ranged-PUT and trash-walk fixes done --- ROADMAP.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/ROADMAP.md b/ROADMAP.md index 60e0420e..652df88b 100644 --- a/ROADMAP.md +++ b/ROADMAP.md @@ -136,7 +136,7 @@ Order = user-visible value first; each ships with backend + UI + tests. ## 5. Phase C — security + quality - Own security review on top of upstream fixes: session/token entropy audit, SSRF guard re-test (NAT64 class), rate limiting on auth endpoints -- Fix upstream bug backlog by impact: #3574 OOM (trash_bin_collect streaming), #3118/#3005 WebDAV large-file, ~~#3375 SMTP auth discovery~~ (done — `smtp_auth` setting) +- Fix upstream bug backlog by impact: ~~#3574 OOM~~ (done — paged tree walk + batched delete), ~~#3118/#3005 WebDAV large-file~~ (done — Content-Range assembly into one session; non-local policies get honest 501; single-PUT giant-file 500s are proxy/client timeouts, not fixable server-side), ~~#3375 SMTP auth discovery~~ (done — `smtp_auth` setting) - #3454 (PG FK on upload) is **Pro-only** — `audit_logs` doesn't exist in this codebase. When B.5 adds our own audit log: insert the audit row in the same tx *after* the file row, never before. - `desloppify` + `security-reviewer` passes; scorecard appended to README