السلام عليكم يا أبطال رتق،
قمنا بمراجعة شاملة ومعمّقة لكامل مشروع رتق هذا الأسبوع - كل سطر تقريبا، من قاعدة البيانات إلى واجهة المستخدم - وطلعنا بـ 8 مهام جديدة حقيقية، كل واحدة موثقة بدقة (أين المشكلة بالضبط، ولماذا هي مهمة، وما هو الحل المتوقع). هذه ليست أفكارا عامة، بل مهام جاهزة للعمل عليها الآن.
المشروع يحتاج أبطاله. إليكم القائمة:
🔴 #227 - عاجلة: جدول الإشعارات في قاعدة البيانات غير موجود فعليا رغم أن الكود يحاول الكتابة فيه - أول رد على تعليق أو تقرير سيفشل. إصلاح صغير وسريع لكن أثره كبير.
🦸 #228 - الأكبر: التعليقات، الإبلاغ، طلبات الوصول، الموارد ذات الصلة... كلها مبنية بالكامل في الكود لكنها غير ظاهرة لأي مستخدم! مهمة متوسطة الحجم، تفتح ميزات كثيرة دفعة واحدة.
🔐 #229 - أمنية: رمز الجلسة (session token) يمر عبر رابط URL بعد تسجيل الدخول عبر GitHub - يجب ألا يظهر في السجلات أو تاريخ المتصفح أبدا.
✅ #230: أهم مجموعتين بيانات في المشروع (المستخدمون والموارد) بلا اختبارات كافية تحمي صلاحيات الوصول. فرصة ممتازة لمن يحب كتابة الاختبارات.
🛡️ #231: ثلاث ثغرات صغيرة في التحقق من الصلاحيات على مستوى الحقول - كل واحدة بسيطة ومستقلة عن الأخرى.
♿ #232: مربع البحث في الكتالوج وتلميح "موثوق من قبل" غير قابلين للوصول عبر لوحة المفاتيح أو قارئ الشاشة - نفس نوع الإصلاح الذي أنجزه #211 سابقا.
🔑 #233: لا توجد وسيلة لاستعادة كلمة مرور منسية! الأساس موجود في قاعدة البيانات لكن لم يُبنَ من فوقه شيء بعد.
👀 #234: لا يمكن لصاحب المورد رؤية من يملك صلاحية الوصول إليه أو إلغاءها.
كل مهمة موثقة بالكامل (السياق، النطاق، ما هو خارج النطاق، ومعايير القبول) - افتحوا أي رقم يعجبكم وابدأوا. القائمة الكاملة للمهام المفتوحة دائما هنا: https://github.com/Itqan-community/RATQ/issues
لا حاجة لخبرة سابقة في المشروع - فقط اختاروا مهمة تناسب مستواكم واطلبوا التكليف بتعليق على المهمة. جزاكم الله خيرا مقدما على كل من سينضم!
Assalamu alaikum, RATQ heroes,
We just finished a deep, full audit of the entire RATQ codebase this week - almost every line, from the database up to the UI - and came out with 8 real, concrete issues. Each one is fully scoped: exactly where the problem is, why it matters, and what the fix should look like. These aren't vague ideas, they're ready to pick up right now.
The project needs its heroes. Here's the lineup:
🔴 #227 - Urgent: the notifications table doesn't actually exist in the database even though the code tries to write to it - the first comment reply or report will fail. Small fix, big impact.
🦸 #228 - The big one: comments, reporting, access requests, related resources - all fully built in code, none of it visible to a real user. Medium-sized task that unlocks a whole layer of the product at once.
🔐 #229 - Security: the session token travels through the URL after GitHub login - it should never end up in logs or browser history.
✅ #230: the two most sensitive data collections in the project (Users and Resources) have almost no tests protecting their access rules. Great pick for anyone who enjoys writing tests.
🛡️ #231: three small, independent field-level permission gaps - each one simple and self-contained.
♿ #232: the catalog search box and the "Trusted By" tooltip aren't reachable by keyboard or screen reader - same class of fix as #211.
🔑 #233: there's no way to recover a forgotten password! The database groundwork is there, nothing's been built on top of it yet.
👀 #234: a resource owner can't see or revoke who has access to their own resource.
Every issue is fully documented (background, scope, out-of-scope, acceptance criteria) - open whichever number speaks to you and dive in. The full always-open queue is here: https://github.com/Itqan-community/RATQ/issues
No prior experience with the project needed - just pick something that matches your level and ask to be assigned in a comment. Jazak Allah khayran in advance to whoever picks one of these up!