# Changelog

## Score

- CAI 58 → 60 (+2.7)
- Rubric changed (rubric-2026.09.9 → rubric-2026.09.17) — scores are not directly comparable.

## Lenses

- Code Health 49 → 49 (-0.0)
- Architecture 67 → 69 (+2.2)
- Maturity 61 → 65 (+3.9)
- Readiness 62 → 79 (+17.2)
- Security 64 → 68 (+3.6)
- Domain Modelling 100 → 100 (+0.0)
- Event Sourcing 100 → 100 (+0.0)

## Resolved (43)

- Boundary-crossing change coupling: Parameters.rs ↔ lib.rs (warpgate-db-entities/src/Parameters.rs)
- Change coupling: lib.rs ↔ Parameters.svelte (warpgate-db-migrations/src/lib.rs)
- ClassTooLong: RemoteClient (warpgate-protocol-ssh/src/client/mod.rs)
- Documentation: no installation or build instructions (README.md)
- Documentation: no licence statement (README.md)
- Documentation: no usage examples (README.md)
- Duplicated block (13 lines × 2) (warpgate-protocol-mysql/src/client.rs)
- Duplicated block (14 lines × 4) (warpgate-common/src/audit.rs)
- High IaC: KSV-0014 (helm/warpgate/templates/setup-job.yaml)
- Hotspot: vendor/ironrdp-session/src/fast_path.rs (vendor/ironrdp-session/src/fast_path.rs)
- Hotspot: vendor/vnc-rs/src/codec/trle.rs (vendor/vnc-rs/src/codec/trle.rs)
- Hotspot: vendor/vnc-rs/src/codec/zrle.rs (vendor/vnc-rs/src/codec/zrle.rs)
- Hotspot: warpgate-common/src/config/mod.rs (warpgate-common/src/config/mod.rs)
- Hotspot: warpgate-desktop-auth/src/hold_screen.rs (warpgate-desktop-auth/src/hold_screen.rs)
- Hotspot: warpgate-protocol-rdp/src/client/input.rs (warpgate-protocol-rdp/src/client/input.rs)
- Hotspot: warpgate-protocol-rdp/src/server/rdp.rs (warpgate-protocol-rdp/src/server/rdp.rs)
- Hotspot: warpgate-protocol-ssh/src/client/channel_session.rs (warpgate-protocol-ssh/src/client/channel_session.rs)
- Hotspot: warpgate-protocol-ssh/src/server/target_menu.rs (warpgate-protocol-ssh/src/server/target_menu.rs)
- Hotspot: warpgate-protocol-vnc/src/server/protocol.rs (warpgate-protocol-vnc/src/server/protocol.rs)
- Hotspot: warpgate-web/src/admin/log-viewer/LogViewer.svelte (warpgate-web/src/admin/log-viewer/LogViewer.svelte)
- …and 23 more

## New (42)

- ClassTooLong: AuditEvent (warpgate-common/src/audit.rs)
- Connector::_handle_auth_result (cognitive 19) (warpgate-protocol-ssh/src/client/mod.rs)
- Connector::authenticate_session (cognitive 24) (warpgate-protocol-ssh/src/client/mod.rs)
- Duplicated block (13 lines × 2) (warpgate-protocol-mysql/src/client.rs)
- Duplicated block (14 lines × 2) (warpgate-common/src/audit.rs)
- Duplicated block (8 lines × 6) (warpgate-common/src/audit.rs)
- Duplicated block (9 lines × 2) (warpgate-common/src/audit.rs)
- Duplicated block (9 lines × 2) (warpgate-common/src/audit.rs)
- End-of-life runtime: .NET net6.0
- FileTooLong: src/audit.rs (warpgate-common/src/audit.rs)
- FunctionTooLong: warpgate_protocol_http::proxy::proxy_ws_inner (warpgate-protocol-http/src/proxy.rs)
- FunctionTooLong: warpgate_protocol_kubernetes::server::handlers::_handle_websocket_request_inner (warpgate-protocol-kubernetes/src/server/handlers.rs)
- Hotspot: warpgate-common/src/error.rs (warpgate-common/src/error.rs)
- Hotspot: warpgate-core/src/credential_encryption.rs (warpgate-core/src/credential_encryption.rs)
- Inconsistent abbreviation for 'User'. The type and property are named 'Usr', while other credentials use 'User' (e.g., 'AADJoin.Creds.UserCreds', 'AADJoin.Messages.JoinDeviceRequest.User' is not present but 'UserCreds' is). 'Usr' is a non-standard abbreviation.
- Inconsistent abbreviation for the same concept. 'MembershipChgs' is used as a nested type name for specific SIDs, while 'MembershipChanges' is used as the property name for the collection. 'Chgs' is a non-standard abbreviation for 'Changes'.
- Inconsistent casing for factory/parse methods. 'AuthResponse.fromString' uses lowercase 'f', while 'JoinDeviceResponse.FromString', 'TenantAuthResponse.FromString', and 'P2PCertificatesResponse.FromString' use PascalCase 'F'.
- Inconsistent constructor patterns for wrapping streams. `StreamWrapper` uses a static factory method `from_inner`, while `Framed` uses `new` and `new_with_leftover`. This forces users to remember different instantiation patterns for similar wrapper types.
- Inconsistent naming for standard I/O operations. `FramedRead` uses `read` (standard Rust `Read` trait name), while `FramedWrite` uses `write_all` (standard Rust `Write` trait method for full buffer writes). This creates asymmetry in the API surface.
- Inconsistent return types for `get_inner`/`get_inner_mut`. `StreamWrapper` returns the inner stream directly, while `Framed` returns a tuple of references. This inconsistency requires different handling code depending on which wrapper type is being used.
- …and 22 more

## Changes since last survey

- 47 commits — 37 feature/other, 10 fixes

## By area

- (root) — 8 commits
- warpgate-web/src — 7 commits
- warpgate-admin/src — 5 commits
- (repo) — 4 commits
- warpgate-protocol-kubernetes/src — 3 commits
- warpgate-protocol-ssh/src — 3 commits
- tests/conftest.py — 2 commits
- warpgate-common-http/src — 2 commits
- .github/workflows — 1 commit
- helm/warpgate — 1 commit
- tests/test_cluster_failover.py — 1 commit
- tests/test_util_wait_port.py — 1 commit
- vendor/ironrdp-connector — 1 commit
- vendor/ironrdp-server — 1 commit
- warpgate-common/src — 1 commit
- warpgate-core/src — 1 commit
- warpgate-db-entities/src — 1 commit
- warpgate-db-migrations/src — 1 commit
- warpgate-desktop-auth/src — 1 commit
- warpgate-protocol-http/src — 1 commit

## Notable commits

- fix: SSH - #2598 recording gap fix
- fix: fix(deps): bump cryptoki to 0.12.1 to resolve RUSTSEC-2026-0286 (#2604)
- fix: fixed #2585 - RDP CPU spin (#2591)
- fix: fixed #2590 - run migrations in a transaction (#2595)
- fix: fixed #2594 - generate TOTP with a CSPRNG
- fix: fixed #2597 - reject changing PK/SSO credential ownership
- fix: fixed #2605 - displaying expired role memberships for user
- fix: fixed #2613 - cannot remember approval if the only cred is web approval
- fix: fixed #2614 - show "waiting" UI on RDP while waiting for admin approval (#2615)
- fix: vendor ironrdp-server and and patch to potentially fix #2606
- change: Add scope clarifications to SECURITY.md (#2509)
- change: Audit Kubernetes exec, attach, port-forward and debug containers (#2558)
- change: Bump the actions-updates group across 1 directory with 9 updates (#2610)
- change: Cluster notifications (#2587)
- change: Detangle SSH session <> RC wait (#2603)
- change: Forward test_direct_tcpip to a local server instead of github.com (#2625)
- change: HashiCorp Vault / OpenBao integration for secret management (#2185)
- change: Helm chart updates
- change: Implement Kubernetes access tickets (#2562)
- change: Let go of a client that stopped reading when its target dies (#2520) (#2549)
- …and 27 more
