crafter-station/petdex

2 errors, 24 warningsmain

26 issues need attention.

2 errors and 24 warnings in the paths between 61 routes and 24 tables.

ROUTE FINDINGS16 of 61 · 7/7 rules
ROUTES
61
TABLES
24
FILES READ
120
RULES RUN
7/7

26 findings

  • POST /api/telemetry/event can reach telemetry_events without authenticating.

    auth-before-dataPOST /api/telemetry/event → telemetry_events

  • GET /api/pets/[slug]/codex-theme can reach submitted_pets without authenticating.

    auth-before-dataGET /api/pets/[slug]/codex-theme → submitted_pets

  • GET /api/og has no validator or rate limiter attached.

    public-entry-guarded

  • GET /api/manifest has no validator or rate limiter attached.

    public-entry-guarded

  • GET /api/wechat-qr has no validator or rate limiter attached.

    public-entry-guarded

  • GET /api/pets/random has no validator or rate limiter attached.

    public-entry-guarded

  • GET /api/manifest/v2 has no validator or rate limiter attached.

    public-entry-guarded

  • GET /api/pets/search has no validator or rate limiter attached.

    public-entry-guarded

  • GET /[locale]/install/[slug] has no validator or rate limiter attached.

    public-entry-guarded

  • GET /api/pets/[slug]/sticker has no validator or rate limiter attached.

    public-entry-guarded

  • GET /api/cli/auth-config has no validator or rate limiter attached.

    public-entry-guarded

  • GET /api/install-pet/[slug] has no validator or rate limiter attached.

    public-entry-guarded

  • POST /api/telemetry/event has no validator or rate limiter attached.

    public-entry-guarded

  • GET /api/pets/[slug]/thumb has no validator or rate limiter attached.

    public-entry-guarded

  • GET /api/pets/[slug]/variants has no validator or rate limiter attached.

    public-entry-guarded

  • GET /api/pets/[slug]/wastickers has no validator or rate limiter attached.

    public-entry-guarded

  • GET /api/pets/[slug]/codex-theme has no validator or rate limiter attached.

    public-entry-guarded

  • GET /api/desktop/latest-release has no validator or rate limiter attached.

    public-entry-guarded

  • pending_asset_gc_claims is not connected to anything.

    no-orphan-datastore

  • submission_reviews is not connected to anything.

    no-orphan-datastore

  • pet_export_approvals is not connected to anything.

    no-orphan-datastore

  • pet_sticker_publications is not connected to anything.

    no-orphan-datastore

  • manifest_fetches is not connected to anything.

    no-orphan-datastore

  • pet_request_candidates is not connected to anything.

    no-orphan-datastore

  • email_preferences is not connected to anything.

    no-orphan-datastore

  • wechat_qr_uploads is not connected to anything.

    no-orphan-datastore

Part of this repository was not read, so this report is incomplete. Read 120 of 469 files, schemas and routes first. Point Wyro at a single service directory to read one in full. Unread: src/lib/db/schema.ts, src/lib/db/schema.ts, src/lib/db/schema.ts.

Free account, no card. The repository opens as an editable graph.

Add this check to the README

wyro architecture badge
[![wyro architecture](https://wyro.in/api/badge/crafter-station/petdex)](https://wyro.in/scan/crafter-station/petdex)

It updates itself whenever the repository changes and links back to this report.

What this is

Wyro reads the repository’s routes and data models and checks the paths between them: whether a route can reach a table without passing a guard, whether a datastore holding personal data is exposed to a public read, whether an endpoint that issues credentials requires the credentials it issues.

It is rule-based, not a model. The same commit produces the same result every time, and it does not guess at business rules it cannot see. A rule with nothing to look at is reported as not having run — never as a pass.

This check runs on public source through GitHub’s own API and needs no account. A free account adds the editable architecture canvas, private repositories on paid plans, and a CI gate. No card required.