Soju06/codex-lb

0 errors, 141 warningsmain

141 issues need attention.

141 warnings in the paths between 185 routes and 68 tables.

ROUTE FINDINGS77 of 185 · 7/7 rules
ROUTES
185
TABLES
68
FILES READ
120
RULES RUN
7/7

141 findings

  • GET /api/audit-logs has no validator or rate limiter attached.

    public-entry-guarded

  • GET /api/reports has no validator or rate limiter attached.

    public-entry-guarded

  • GET /api/reports/thread-identity has no validator or rate limiter attached.

    public-entry-guarded

  • GET /api/reports/options has no validator or rate limiter attached.

    public-entry-guarded

  • GET /api/usage/summary has no validator or rate limiter attached.

    public-entry-guarded

  • GET /api/usage/history has no validator or rate limiter attached.

    public-entry-guarded

  • GET /api/usage/window has no validator or rate limiter attached.

    public-entry-guarded

  • GET /api/firewall/ips has no validator or rate limiter attached.

    public-entry-guarded

  • GET /health has no validator or rate limiter attached.

    public-entry-guarded

  • GET /health/live has no validator or rate limiter attached.

    public-entry-guarded

  • GET /health/ready has no validator or rate limiter attached.

    public-entry-guarded

  • POST /internal/drain/start has no validator or rate limiter attached.

    public-entry-guarded

  • POST /internal/drain/stop has no validator or rate limiter attached.

    public-entry-guarded

  • GET /internal/drain/status has no validator or rate limiter attached.

    public-entry-guarded

  • GET /health/startup has no validator or rate limiter attached.

    public-entry-guarded

  • GET /api/fleet/summary has no validator or rate limiter attached.

    public-entry-guarded

  • GET /api/fleet/observability has no validator or rate limiter attached.

    public-entry-guarded

  • POST /api/fleet/refresh has no validator or rate limiter attached.

    public-entry-guarded

  • GET /api/runtime/version has no validator or rate limiter attached.

    public-entry-guarded

  • GET /api/api-keys has no validator or rate limiter attached.

    public-entry-guarded

  • GET /api/api-keys/{key_id}/trends has no validator or rate limiter attached.

    public-entry-guarded

  • GET /api/api-keys/{key_id}/usage-7d has no validator or rate limiter attached.

    public-entry-guarded

  • GET /api/accounts/{account_id}/trends has no validator or rate limiter attached.

    public-entry-guarded

  • GET /api/accounts/{account_id}/usage-reset-credits has no validator or rate limiter attached.

    public-entry-guarded

  • GET / has no validator or rate limiter attached.

    public-entry-guarded

  • GET /{path:path} has no validator or rate limiter attached.

    public-entry-guarded

  • GET /backend-api/codex/thread/goal/get has no validator or rate limiter attached.

    public-entry-guarded

  • POST /backend-api/codex/thread/goal/get has no validator or rate limiter attached.

    public-entry-guarded

  • POST /backend-api/codex/thread/goal/set has no validator or rate limiter attached.

    public-entry-guarded

  • POST /backend-api/codex/thread/goal/clear has no validator or rate limiter attached.

    public-entry-guarded

  • POST /backend-api/codex/analytics-events/events has no validator or rate limiter attached.

    public-entry-guarded

  • POST /backend-api/codex/memories/trace_summarize has no validator or rate limiter attached.

    public-entry-guarded

  • POST /backend-api/codex/safety/arc has no validator or rate limiter attached.

    public-entry-guarded

  • POST /backend-api/codex/alpha/search has no validator or rate limiter attached.

    public-entry-guarded

  • GET /backend-api/codex/agent-identities/jwks has no validator or rate limiter attached.

    public-entry-guarded

  • GET /backend-api/wham/agent-identities/jwks has no validator or rate limiter attached.

    public-entry-guarded

  • POST /backend-api/codex/responses has no validator or rate limiter attached.

    public-entry-guarded

  • GET /backend-api/codex/opportunistic/admission has no validator or rate limiter attached.

    public-entry-guarded

  • POST /v1/responses has no validator or rate limiter attached.

    public-entry-guarded

  • POST /internal/bridge/responses has no validator or rate limiter attached.

    public-entry-guarded

  • GET /backend-api/codex/models has no validator or rate limiter attached.

    public-entry-guarded

  • GET /v1/models has no validator or rate limiter attached.

    public-entry-guarded

  • GET /v1/usage has no validator or rate limiter attached.

    public-entry-guarded

  • GET /v1/reset-credit has no validator or rate limiter attached.

    public-entry-guarded

  • POST /v1/reset-credit has no validator or rate limiter attached.

    public-entry-guarded

  • POST /v1/warmup has no validator or rate limiter attached.

    public-entry-guarded

  • POST /v1/warmup/{mode} has no validator or rate limiter attached.

    public-entry-guarded

  • POST /backend-api/transcribe has no validator or rate limiter attached.

    public-entry-guarded

  • POST /backend-api/files has no validator or rate limiter attached.

    public-entry-guarded

  • POST /backend-api/files/{file_id}/uploaded has no validator or rate limiter attached.

    public-entry-guarded

  • POST /v1/audio/transcriptions has no validator or rate limiter attached.

    public-entry-guarded

  • POST /v1/embeddings has no validator or rate limiter attached.

    public-entry-guarded

  • POST /backend-api/codex/images/generations has no validator or rate limiter attached.

    public-entry-guarded

  • POST /v1/images/generations has no validator or rate limiter attached.

    public-entry-guarded

  • POST /v1/images/edits has no validator or rate limiter attached.

    public-entry-guarded

  • POST /backend-api/codex/images/edits has no validator or rate limiter attached.

    public-entry-guarded

  • POST /v1/images/variations has no validator or rate limiter attached.

    public-entry-guarded

  • POST /v1/chat/completions has no validator or rate limiter attached.

    public-entry-guarded

  • POST /backend-api/codex/responses/compact has no validator or rate limiter attached.

    public-entry-guarded

  • POST /v1/responses/compact has no validator or rate limiter attached.

    public-entry-guarded

  • GET /api/conversations has no validator or rate limiter attached.

    public-entry-guarded

  • GET /api/conversations/{conversation_id:path} has no validator or rate limiter attached.

    public-entry-guarded

  • GET /api/model-sources has no validator or rate limiter attached.

    public-entry-guarded

  • GET /api/quota-planner/settings has no validator or rate limiter attached.

    public-entry-guarded

  • GET /api/quota-planner/decisions has no validator or rate limiter attached.

    public-entry-guarded

  • GET /api/quota-planner/forecast has no validator or rate limiter attached.

    public-entry-guarded

  • GET /api/automations has no validator or rate limiter attached.

    public-entry-guarded

  • GET /api/automations/options has no validator or rate limiter attached.

    public-entry-guarded

  • GET /api/automations/runs has no validator or rate limiter attached.

    public-entry-guarded

  • GET /api/automations/runs/options has no validator or rate limiter attached.

    public-entry-guarded

  • GET /api/automations/runs/{run_id}/details has no validator or rate limiter attached.

    public-entry-guarded

  • GET /api/automations/{automation_id}/runs has no validator or rate limiter attached.

    public-entry-guarded

  • GET /api/dashboard-users has no validator or rate limiter attached.

    public-entry-guarded

  • GET /api/dashboard-users/invites has no validator or rate limiter attached.

    public-entry-guarded

  • GET /api/dashboard-roles/permissions has no validator or rate limiter attached.

    public-entry-guarded

  • GET /api/conversation-archive/records has no validator or rate limiter attached.

    public-entry-guarded

  • GET /api/accounts/{account_id}/rate-limit-reset-credits has no validator or rate limiter attached.

    public-entry-guarded

  • file_account_pins is not connected to anything.

    no-orphan-datastore

  • accounts is not connected to anything.

    no-orphan-datastore

  • usage_history is not connected to anything.

    no-orphan-datastore

  • account_usage_rollups is not connected to anything.

    no-orphan-datastore

  • api_key_usage_rollups is not connected to anything.

    no-orphan-datastore

  • account_usage_rollup_state is not connected to anything.

    no-orphan-datastore

  • request_report_hourly_rollups is not connected to anything.

    no-orphan-datastore

  • request_usage_hourly_rollups is not connected to anything.

    no-orphan-datastore

  • request_usage_hourly_error_rollups is not connected to anything.

    no-orphan-datastore

  • request_demand_quarter_rollups is not connected to anything.

    no-orphan-datastore

  • request_conversation_hourly_rollups is not connected to anything.

    no-orphan-datastore

  • additional_usage_history is not connected to anything.

    no-orphan-datastore

  • request_logs is not connected to anything.

    no-orphan-datastore

  • account_limit_warmups is not connected to anything.

    no-orphan-datastore

  • audit_logs is not connected to anything.

    no-orphan-datastore

  • scheduler_leader is not connected to anything.

    no-orphan-datastore

  • reset_credit_redeem_requests is not connected to anything.

    no-orphan-datastore

  • reset_credit_redeem_claims is not connected to anything.

    no-orphan-datastore

  • oauth_flow_states is not connected to anything.

    no-orphan-datastore

  • oauth_device_flow_slots is not connected to anything.

    no-orphan-datastore

  • sticky_sessions is not connected to anything.

    no-orphan-datastore

  • capability_lineage_markers is not connected to anything.

    no-orphan-datastore

  • dashboard_users is not connected to anything.

    no-orphan-datastore

  • dashboard_identities is not connected to anything.

    no-orphan-datastore

  • dashboard_user_invites is not connected to anything.

    no-orphan-datastore

  • dashboard_auth_providers is not connected to anything.

    no-orphan-datastore

  • dashboard_oidc_login_flows is not connected to anything.

    no-orphan-datastore

  • dashboard_scim_tokens is not connected to anything.

    no-orphan-datastore

  • dashboard_role_mappings is not connected to anything.

    no-orphan-datastore

  • dashboard_roles is not connected to anything.

    no-orphan-datastore

  • dashboard_role_grants is not connected to anything.

    no-orphan-datastore

  • dashboard_settings is not connected to anything.

    no-orphan-datastore

  • model_context_window_overrides is not connected to anything.

    no-orphan-datastore

  • runtime_sentinels is not connected to anything.

    no-orphan-datastore

  • api_firewall_allowlist is not connected to anything.

    no-orphan-datastore

  • api_keys is not connected to anything.

    no-orphan-datastore

  • api_key_accounts is not connected to anything.

    no-orphan-datastore

  • model_sources is not connected to anything.

    no-orphan-datastore

  • model_source_models is not connected to anything.

    no-orphan-datastore

  • api_key_model_sources is not connected to anything.

    no-orphan-datastore

  • api_key_limits is not connected to anything.

    no-orphan-datastore

  • api_key_usage_reservations is not connected to anything.

    no-orphan-datastore

  • api_key_usage_reservation_items is not connected to anything.

    no-orphan-datastore

  • automation_jobs is not connected to anything.

    no-orphan-datastore

  • automation_job_accounts is not connected to anything.

    no-orphan-datastore

  • automation_runs is not connected to anything.

    no-orphan-datastore

  • automation_run_cycles is not connected to anything.

    no-orphan-datastore

  • automation_run_cycle_accounts is not connected to anything.

    no-orphan-datastore

  • rate_limit_attempts is not connected to anything.

    no-orphan-datastore

  • quota_planner_settings is not connected to anything.

    no-orphan-datastore

  • quota_planner_decisions is not connected to anything.

    no-orphan-datastore

  • quota_window_observations is not connected to anything.

    no-orphan-datastore

  • cache_invalidation is not connected to anything.

    no-orphan-datastore

  • model_registry_snapshot is not connected to anything.

    no-orphan-datastore

  • account_refresh_claims is not connected to anything.

    no-orphan-datastore

  • account_plan_downgrade_observations is not connected to anything.

    no-orphan-datastore

  • bridge_ring_members is not connected to anything.

    no-orphan-datastore

  • http_bridge_sessions is not connected to anything.

    no-orphan-datastore

  • http_bridge_recovery_attempts is not connected to anything.

    no-orphan-datastore

  • http_bridge_operations is not connected to anything.

    no-orphan-datastore

  • http_bridge_operation_events is not connected to anything.

    no-orphan-datastore

  • http_bridge_operation_event_chunks is not connected to anything.

    no-orphan-datastore

  • http_bridge_session_aliases is not connected to anything.

    no-orphan-datastore

  • http_bridge_retry_circuits is not connected to anything.

    no-orphan-datastore

Part of this repository was not read, so this report is incomplete. Read 120 of 817 files, schemas and routes first. Point Wyro at a single service directory to read one in full. Unread: app/db/models.py, app/modules/settings/api.py, app/modules/settings/api.py.

Free account, no card. The repository opens as an editable graph.

Add this check to the README

wyro architecture badge
[![wyro architecture](https://wyro.in/api/badge/Soju06/codex-lb)](https://wyro.in/scan/Soju06/codex-lb)

It updates itself whenever the repository changes and links back to this report.

What this is

Wyro reads the repository’s routes and data models and checks the paths between them: whether a route can reach a table without passing a guard, whether a datastore holding personal data is exposed to a public read, whether an endpoint that issues credentials requires the credentials it issues.

It is rule-based, not a model. The same commit produces the same result every time, and it does not guess at business rules it cannot see. A rule with nothing to look at is reported as not having run — never as a pass.

This check runs on public source through GitHub’s own API and needs no account. A free account adds the editable architecture canvas, private repositories on paid plans, and a CI gate. No card required.