{"version": "2.1.0", "$schema": "https://json.schemastore.org/sarif-2.1.0.json", "runs": [{"tool": {"driver": {"name": "Repobility", "informationUri": "https://repobility.com", "rules": [{"id": "scanner-fb6b678288f233b8", "name": "Stray `console.log` in TS/JS \u2014 backend/src/index.ts:137", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend/src/index.ts:137"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-818c135d68311989", "name": "Stray `console.log` in TS/JS \u2014 backend/src/utils/email.ts:12", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend/src/utils/email.ts:12"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e9d5905da2c2865e", "name": "Stray `console.log` in TS/JS \u2014 backend/src/routes/castAuth.ts:1249", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend/src/routes/castAuth.ts:1249"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8e57ee118213a9d6", "name": "Stray `console.log` in TS/JS \u2014 backend/src/routes/reports.ts:54", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend/src/routes/reports.ts:54"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-812e4022c888eb77", "name": "Stray `console.log` in TS/JS \u2014 backend/src/routes/staff.ts:174", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend/src/routes/staff.ts:174"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-542a7fe88ec56b2b", "name": "Stray `console.log` in TS/JS \u2014 backend/src/routes/adminReports.ts:141", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend/src/routes/adminReports.ts:141"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6343e8b0516b32bd", "name": "Stray `console.log` in TS/JS \u2014 backend/src/services/notifications.ts:36", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend/src/services/notifications.ts:36"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-feb2637ca091618e", "name": "Stray `console.log` in TS/JS \u2014 backend/src/services/dailyReminderService.ts:102", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend/src/services/dailyReminderService.ts:102"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-12288bb5a1117d17", "name": "Stray `console.log` in TS/JS \u2014 backend/src/services/dataUploadMonitor.ts:104", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend/src/services/dataUploadMonitor.ts:104"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-db7b8714d741ce4e", "name": "Stray `console.log` in TS/JS \u2014 backend/src/services/emailSender.ts:102", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend/src/services/emailSender.ts:102"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8ff4393bf25ec8cc", "name": "Stray `console.log` in TS/JS \u2014 backend/src/db/pool.ts:14", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend/src/db/pool.ts:14"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-aa5acaa49eb8315b", "name": "Containers defined but no K8s/orchestration manifest found", "shortDescription": {"text": "Containers defined but no K8s/orchestration manifest found"}, "fullDescription": {"text": "Repo has Dockerfiles/compose but no Kubernetes/Nomad manifests. If the target deployment is K8s, the manifests may live in a separate ops repo."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "low", "confidence": 1.0}}, {"id": "scanner-728626a9ec3794ba", "name": "Insecure pattern 'local_storage_auth_token' in frontend/src/pages/CastMailHelp.tsx:70", "shortDescription": {"text": "Insecure pattern 'local_storage_auth_token' in frontend/src/pages/CastMailHelp.tsx:70"}, "fullDescription": {"text": "Found a known-risky pattern (local_storage_auth_token). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-3f5cb7ba5b722260", "name": "Insecure pattern 'local_storage_auth_token' in frontend/src/pages/CastResetPin.tsx:90", "shortDescription": {"text": "Insecure pattern 'local_storage_auth_token' in frontend/src/pages/CastResetPin.tsx:90"}, "fullDescription": {"text": "Found a known-risky pattern (local_storage_auth_token). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-8ca0677ecdcee7fe", "name": "Insecure pattern 'local_storage_auth_token' in frontend/src/pages/CastVerify.tsx:167", "shortDescription": {"text": "Insecure pattern 'local_storage_auth_token' in frontend/src/pages/CastVerify.tsx:167"}, "fullDescription": {"text": "Found a known-risky pattern (local_storage_auth_token). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b3ff9f7dafb73401", "name": "Insecure pattern 'local_storage_auth_token' in frontend/src/pages/CastMagic.tsx:31", "shortDescription": {"text": "Insecure pattern 'local_storage_auth_token' in frontend/src/pages/CastMagic.tsx:31"}, "fullDescription": {"text": "Found a known-risky pattern (local_storage_auth_token). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-5989edf37b2c6400", "name": "Insecure pattern 'local_storage_auth_token' in frontend/src/pages/CastLogin.tsx:80", "shortDescription": {"text": "Insecure pattern 'local_storage_auth_token' in frontend/src/pages/CastLogin.tsx:80"}, "fullDescription": {"text": "Found a known-risky pattern (local_storage_auth_token). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e62902694165b224", "name": "GitHub Actions workflow grants broad write permissions", "shortDescription": {"text": "GitHub Actions workflow grants broad write permissions"}, "fullDescription": {"text": "CI tokens with write permissions increase blast radius when an action, dependency, or PR workflow is compromised. Prefer job-level least-privilege permissions."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9783f351166036a8", "name": "Very large file: frontend/src/App.tsx (1688 lines)", "shortDescription": {"text": "Very large file: frontend/src/App.tsx (1688 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4e2675545eedba43", "name": "Very large file: frontend/src/pages/FieldReport.tsx (1966 lines)", "shortDescription": {"text": "Very large file: frontend/src/pages/FieldReport.tsx (1966 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-89fdba6eae88579a", "name": "Very large file: backend/src/routes/admin.ts (1848 lines)", "shortDescription": {"text": "Very large file: backend/src/routes/admin.ts (1848 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ea3b5e389d8c9c0f", "name": "Low test-to-source ratio", "shortDescription": {"text": "Low test-to-source ratio"}, "fullDescription": {"text": "15 tests / 115 src (ratio 0.13)."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-141b30a41e03817b", "name": "No license file detected", "shortDescription": {"text": "No license file detected"}, "fullDescription": {"text": "No LICENSE/COPYING/NOTICE file was found. Generated repositories often omit licensing, which blocks reuse and automated intake."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3ab5d313dda8e5f9", "name": "Debug logging residue appears in source files", "shortDescription": {"text": "Debug logging residue appears in source files"}, "fullDescription": {"text": "Found 101 console/debugger/print-style debug statements in non-test source. This is a common fast-generation residue before production cleanup."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-72b2a6250083a784", "name": "Placeholder or mock-heavy implementation detected", "shortDescription": {"text": "Placeholder or mock-heavy implementation detected"}, "fullDescription": {"text": "Found 44 placeholder/mock markers across 13 source files. This often means the repo looks complete while core flows still use generated scaffolding or fake data."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2d0c7b7ab8f8aacf", "name": "Critical user flow still appears backed by mock or placeholder data", "shortDescription": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "fullDescription": {"text": "A payment/auth/admin/order/billing-style flow contains mock, fake, TODO, dummy, or placeholder markers in runtime source. In the Fable corpus this is a high-leverage completeness smell: the app can look finished while the money, identity, or tenant flow is still scaffolded."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ea8f3013f588db25", "name": "Shallow git history limits provenance confidence", "shortDescription": {"text": "Shallow git history limits provenance confidence"}, "fullDescription": {"text": "The repository is a shallow clone. Origin/evolution analysis cannot distinguish fresh generation, imported legacy code, or long-lived human code with high confidence."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8424db9c75e04ba4", "name": "Very short observed git history", "shortDescription": {"text": "Very short observed git history"}, "fullDescription": {"text": "The repo has multiple source files but two or fewer visible commits. This is not a failure by itself, but it lowers confidence in evolution-based diagnosis."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-16f0e832826e9cd5", "name": "`fetch()` without try/.catch or AbortSignal \u2014 frontend/src/App.tsx:295", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 frontend/src/App.tsx:295"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-874e8a1e55c96de7", "name": "`fetch()` without try/.catch or AbortSignal \u2014 frontend/src/pages/CastToday.tsx:49", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 frontend/src/pages/CastToday.tsx:49"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2c880565cb488178", "name": "`fetch()` without try/.catch or AbortSignal \u2014 frontend/src/pages/CastVerify.tsx:53", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 frontend/src/pages/CastVerify.tsx:53"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-154f48d3a135729e", "name": "`fetch()` without try/.catch or AbortSignal \u2014 frontend/src/pages/CastMagic.tsx:23", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 frontend/src/pages/CastMagic.tsx:23"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-be2e59161314388c", "name": "Commented-code block (5 lines) in backend/migrations/1781300000000_drop-legacy-name-unique-index.js:1", "shortDescription": {"text": "Commented-code block (5 lines) in backend/migrations/1781300000000_drop-legacy-name-unique-index.js:1"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-fc85c3443c01a30e", "name": "Commented-code block (6 lines) in backend/migrations/1781100000000_add-procast-staff-no.js:1", "shortDescription": {"text": "Commented-code block (6 lines) in backend/migrations/1781100000000_add-procast-staff-no.js:1"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-813932da4ce7fb22", "name": "Legacy-named symbol `plan_v2` in backend/src/index.ts:107", "shortDescription": {"text": "Legacy-named symbol `plan_v2` in backend/src/index.ts:107"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1c6b3eeb23090645", "name": "`fetch()` without try/.catch or AbortSignal \u2014 backend/src/routes/admin.staff-create.test.ts:53", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 backend/src/routes/admin.staff-create.test.ts:53"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-003ec6b8aee378fc", "name": "Commented-code block (9 lines) in backend/src/services/staffResolver.ts:1", "shortDescription": {"text": "Commented-code block (9 lines) in backend/src/services/staffResolver.ts:1"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-3fc74e7bb1fcbbc8", "name": "`fetch()` without try/.catch or AbortSignal \u2014 backend/src/services/notifications.ts:172", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 backend/src/services/notifications.ts:172"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a70971173d037fe6", "name": "`fetch()` without try/.catch or AbortSignal \u2014 backend/src/services/dataUploadMonitor.ts:127", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 backend/src/services/dataUploadMonitor.ts:127"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9a82cf7d16234d20", "name": "21 env vars used in code but missing from .env.example", "shortDescription": {"text": "21 env vars used in code but missing from .env.example"}, "fullDescription": {"text": "Drift between code and config docs. The first few: `ADMIN_NOTIFICATION_EMAILS`, `BASE_URL`, `CSRF_ALLOWED_ORIGINS`, `CSRF_PROTECTION_DISABLED`, `DB_POOL_CONNECTION_TIMEOUT`, `DB_POOL_IDLE_TIMEOUT`, `DB_POOL_MAX`, `HOUKO_API_KEY` + 13 more. Add them (with a placeholder/comment) to .env.example so onboarding doesn't break."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b45d19fa5723c207", "name": "Frontend route `/report/:uniqueUrl` has no Link/navigate to it \u2014 frontend/src/main.tsx", "shortDescription": {"text": "Frontend route `/report/:uniqueUrl` has no Link/navigate to it \u2014 frontend/src/main.tsx"}, "fullDescription": {"text": "The route is registered but no `<Link to=\u2026>` or `navigate(\u2026)` in the codebase navigates here. Either it's reachable only via direct URL (intentional), it's dead, or the link broke during a refactor."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-5840221e26f51957", "name": "Frontend route `/cast/verify` has no Link/navigate to it \u2014 frontend/src/main.tsx", "shortDescription": {"text": "Frontend route `/cast/verify` has no Link/navigate to it \u2014 frontend/src/main.tsx"}, "fullDescription": {"text": "The route is registered but no `<Link to=\u2026>` or `navigate(\u2026)` in the codebase navigates here. Either it's reachable only via direct URL (intentional), it's dead, or the link broke during a refactor."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d3cf1093b9c14808", "name": "Frontend route `/cast/magic` has no Link/navigate to it \u2014 frontend/src/main.tsx", "shortDescription": {"text": "Frontend route `/cast/magic` has no Link/navigate to it \u2014 frontend/src/main.tsx"}, "fullDescription": {"text": "The route is registered but no `<Link to=\u2026>` or `navigate(\u2026)` in the codebase navigates here. Either it's reachable only via direct URL (intentional), it's dead, or the link broke during a refactor."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-505f2d783a177827", "name": "Frontend route `/*` has no Link/navigate to it \u2014 frontend/src/main.tsx", "shortDescription": {"text": "Frontend route `/*` has no Link/navigate to it \u2014 frontend/src/main.tsx"}, "fullDescription": {"text": "The route is registered but no `<Link to=\u2026>` or `navigate(\u2026)` in the codebase navigates here. Either it's reachable only via direct URL (intentional), it's dead, or the link broke during a refactor."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-27826dcf3cc718cc", "name": "Dangling fetch: GET /api/admin/me (frontend/src/App.tsx:150)", "shortDescription": {"text": "Dangling fetch: GET /api/admin/me (frontend/src/App.tsx:150)"}, "fullDescription": {"text": "`frontend/src/App.tsx:150` calls `GET /api/admin/me` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/admin/me`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-4016b064bef78b2f", "name": "Dangling fetch: POST /api/admin/auth/logout (frontend/src/App.tsx:172)", "shortDescription": {"text": "Dangling fetch: POST /api/admin/auth/logout (frontend/src/App.tsx:172)"}, "fullDescription": {"text": "`frontend/src/App.tsx:172` calls `POST /api/admin/auth/logout` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/admin/auth/logout`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-dbd68a304c582251", "name": "Dangling fetch: POST /api/admin/auth/request-access (frontend/src/App.tsx:186)", "shortDescription": {"text": "Dangling fetch: POST /api/admin/auth/request-access (frontend/src/App.tsx:186)"}, "fullDescription": {"text": "`frontend/src/App.tsx:186` calls `POST /api/admin/auth/request-access` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/admin/auth/request-access`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-a44d78eed6adfe6d", "name": "Dangling fetch: GET /api/admin/auth/access-requests (frontend/src/App.tsx:202)", "shortDescription": {"text": "Dangling fetch: GET /api/admin/auth/access-requests (frontend/src/App.tsx:202)"}, "fullDescription": {"text": "`frontend/src/App.tsx:202` calls `GET /api/admin/auth/access-requests` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/admin/auth/access-requests`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-e39d08bc437e02d3", "name": "Dangling fetch: GET /api/admin/auth/admins (frontend/src/App.tsx:213)", "shortDescription": {"text": "Dangling fetch: GET /api/admin/auth/admins (frontend/src/App.tsx:213)"}, "fullDescription": {"text": "`frontend/src/App.tsx:213` calls `GET /api/admin/auth/admins` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/admin/auth/admins`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-c8f01982628346f0", "name": "Dangling fetch: POST /api/admin/auth/access-requests/${requestId}/approve (frontend/src/App.tsx:224)", "shortDescription": {"text": "Dangling fetch: POST /api/admin/auth/access-requests/${requestId}/approve (frontend/src/App.tsx:224)"}, "fullDescription": {"text": "`frontend/src/App.tsx:224` calls `POST /api/admin/auth/access-requests/${requestId}/approve` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/admin/auth/access-requests/<p>/approve`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-9b56d0af9c60fa5c", "name": "Dangling fetch: POST /api/admin/auth/access-requests/${requestId}/reject (frontend/src/App.tsx:246)", "shortDescription": {"text": "Dangling fetch: POST /api/admin/auth/access-requests/${requestId}/reject (frontend/src/App.tsx:246)"}, "fullDescription": {"text": "`frontend/src/App.tsx:246` calls `POST /api/admin/auth/access-requests/${requestId}/reject` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/admin/auth/access-requests/<p>/reject`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-fcf6028e035d2aac", "name": "Dangling fetch: PUT /api/admin/auth/admins/${adminId}/role (frontend/src/App.tsx:258)", "shortDescription": {"text": "Dangling fetch: PUT /api/admin/auth/admins/${adminId}/role (frontend/src/App.tsx:258)"}, "fullDescription": {"text": "`frontend/src/App.tsx:258` calls `PUT /api/admin/auth/admins/${adminId}/role` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/admin/auth/admins/<p>/role`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-dba0b6b9d57526db", "name": "Dangling fetch: DELETE /api/admin/auth/admins/${adminId} (frontend/src/App.tsx:275)", "shortDescription": {"text": "Dangling fetch: DELETE /api/admin/auth/admins/${adminId} (frontend/src/App.tsx:275)"}, "fullDescription": {"text": "`frontend/src/App.tsx:275` calls `DELETE /api/admin/auth/admins/${adminId}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/admin/auth/admins/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-3836fe348841352a", "name": "Dangling fetch: GET /api/admin/projects?date=${dateStr} (frontend/src/App.tsx:338)", "shortDescription": {"text": "Dangling fetch: GET /api/admin/projects?date=${dateStr} (frontend/src/App.tsx:338)"}, "fullDescription": {"text": "`frontend/src/App.tsx:338` calls `GET /api/admin/projects?date=${dateStr}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/admin/projects`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-b8d68641a40abe1a", "name": "Dangling fetch: POST /api/admin/projects/${cancelModalProject.id}/cancel (frontend/src/App.tsx:361)", "shortDescription": {"text": "Dangling fetch: POST /api/admin/projects/${cancelModalProject.id}/cancel (frontend/src/App.tsx:361)"}, "fullDescription": {"text": "`frontend/src/App.tsx:361` calls `POST /api/admin/projects/${cancelModalProject.id}/cancel` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/admin/projects/<p>/cancel`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-d3fd22d87f3645cd", "name": "Dangling fetch: POST /api/admin/projects/${project.id}/restore (frontend/src/App.tsx:399)", "shortDescription": {"text": "Dangling fetch: POST /api/admin/projects/${project.id}/restore (frontend/src/App.tsx:399)"}, "fullDescription": {"text": "`frontend/src/App.tsx:399` calls `POST /api/admin/projects/${project.id}/restore` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/admin/projects/<p>/restore`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-29a53a49c650c13e", "name": "Dangling fetch: POST /api/admin/projects/${project.id}/cancel/resend (frontend/src/App.tsx:418)", "shortDescription": {"text": "Dangling fetch: POST /api/admin/projects/${project.id}/cancel/resend (frontend/src/App.tsx:418)"}, "fullDescription": {"text": "`frontend/src/App.tsx:418` calls `POST /api/admin/projects/${project.id}/cancel/resend` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/admin/projects/<p>/cancel/resend`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-24bf26116c551310", "name": "Dangling fetch: GET /api/admin/staff (frontend/src/App.tsx:462)", "shortDescription": {"text": "Dangling fetch: GET /api/admin/staff (frontend/src/App.tsx:462)"}, "fullDescription": {"text": "`frontend/src/App.tsx:462` calls `GET /api/admin/staff` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/admin/staff`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-27096412a7e1908b", "name": "Dangling fetch: GET /api/admin/csv/imports (frontend/src/App.tsx:484)", "shortDescription": {"text": "Dangling fetch: GET /api/admin/csv/imports (frontend/src/App.tsx:484)"}, "fullDescription": {"text": "`frontend/src/App.tsx:484` calls `GET /api/admin/csv/imports` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/admin/csv/imports`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-8ec613e947d6d10e", "name": "Dangling fetch: GET /api/admin/csv/imports/${importId}/projects (frontend/src/App.tsx:504)", "shortDescription": {"text": "Dangling fetch: GET /api/admin/csv/imports/${importId}/projects (frontend/src/App.tsx:504)"}, "fullDescription": {"text": "`frontend/src/App.tsx:504` calls `GET /api/admin/csv/imports/${importId}/projects` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/admin/csv/imports/<p>/projects`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-8d4d8be264b78a37", "name": "Dangling fetch: GET /api/admin/clients (frontend/src/App.tsx:527)", "shortDescription": {"text": "Dangling fetch: GET /api/admin/clients (frontend/src/App.tsx:527)"}, "fullDescription": {"text": "`frontend/src/App.tsx:527` calls `GET /api/admin/clients` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/admin/clients`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-3a28183c20abc761", "name": "Dangling fetch: PUT /api/admin/clients/${editingClient.id} (frontend/src/App.tsx:561)", "shortDescription": {"text": "Dangling fetch: PUT /api/admin/clients/${editingClient.id} (frontend/src/App.tsx:561)"}, "fullDescription": {"text": "`frontend/src/App.tsx:561` calls `PUT /api/admin/clients/${editingClient.id}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/admin/clients/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-cee7becf44956a44", "name": "Dangling fetch: POST /api/admin/clients (frontend/src/App.tsx:596)", "shortDescription": {"text": "Dangling fetch: POST /api/admin/clients (frontend/src/App.tsx:596)"}, "fullDescription": {"text": "`frontend/src/App.tsx:596` calls `POST /api/admin/clients` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/admin/clients`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-fe12db00d658955a", "name": "Dangling fetch: DELETE /api/admin/clients/${clientId} (frontend/src/App.tsx:624)", "shortDescription": {"text": "Dangling fetch: DELETE /api/admin/clients/${clientId} (frontend/src/App.tsx:624)"}, "fullDescription": {"text": "`frontend/src/App.tsx:624` calls `DELETE /api/admin/clients/${clientId}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/admin/clients/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-9b0892f5a589e399", "name": "Dangling fetch: DELETE /api/admin/projects/without-casts (frontend/src/App.tsx:642)", "shortDescription": {"text": "Dangling fetch: DELETE /api/admin/projects/without-casts (frontend/src/App.tsx:642)"}, "fullDescription": {"text": "`frontend/src/App.tsx:642` calls `DELETE /api/admin/projects/without-casts` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/admin/projects/without-casts`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-d8856fa9ad2764c3", "name": "Dangling fetch: POST /api/admin/staff (frontend/src/App.tsx:667)", "shortDescription": {"text": "Dangling fetch: POST /api/admin/staff (frontend/src/App.tsx:667)"}, "fullDescription": {"text": "`frontend/src/App.tsx:667` calls `POST /api/admin/staff` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/admin/staff`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-95a7575f5472b510", "name": "Dangling fetch: PUT /api/admin/staff/${editingStaff.id} (frontend/src/App.tsx:697)", "shortDescription": {"text": "Dangling fetch: PUT /api/admin/staff/${editingStaff.id} (frontend/src/App.tsx:697)"}, "fullDescription": {"text": "`frontend/src/App.tsx:697` calls `PUT /api/admin/staff/${editingStaff.id}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/admin/staff/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-9c2159cbedf83b1f", "name": "Dangling fetch: DELETE /api/admin/staff/${staffId} (frontend/src/App.tsx:724)", "shortDescription": {"text": "Dangling fetch: DELETE /api/admin/staff/${staffId} (frontend/src/App.tsx:724)"}, "fullDescription": {"text": "`frontend/src/App.tsx:724` calls `DELETE /api/admin/staff/${staffId}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/admin/staff/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-362f6c1f763a3890", "name": "Dangling fetch: POST /api/admin/staff/${staffId}/clear-pin (frontend/src/App.tsx:744)", "shortDescription": {"text": "Dangling fetch: POST /api/admin/staff/${staffId}/clear-pin (frontend/src/App.tsx:744)"}, "fullDescription": {"text": "`frontend/src/App.tsx:744` calls `POST /api/admin/staff/${staffId}/clear-pin` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/admin/staff/<p>/clear-pin`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-28a9c46e3f292c0f", "name": "Dangling fetch: POST /api/admin/staff/bulk-clear-pins (frontend/src/App.tsx:769)", "shortDescription": {"text": "Dangling fetch: POST /api/admin/staff/bulk-clear-pins (frontend/src/App.tsx:769)"}, "fullDescription": {"text": "`frontend/src/App.tsx:769` calls `POST /api/admin/staff/bulk-clear-pins` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/admin/staff/bulk-clear-pins`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-c1942279d3a61a35", "name": "Dangling fetch: POST /api/admin/staff/import (frontend/src/App.tsx:795)", "shortDescription": {"text": "Dangling fetch: POST /api/admin/staff/import (frontend/src/App.tsx:795)"}, "fullDescription": {"text": "`frontend/src/App.tsx:795` calls `POST /api/admin/staff/import` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/admin/staff/import`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-77abdea97783e071", "name": "Dangling fetch: POST /api/admin/csv/import (frontend/src/App.tsx:825)", "shortDescription": {"text": "Dangling fetch: POST /api/admin/csv/import (frontend/src/App.tsx:825)"}, "fullDescription": {"text": "`frontend/src/App.tsx:825` calls `POST /api/admin/csv/import` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/admin/csv/import`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-c0172878b1451a86", "name": "Dangling fetch: GET /api/admin/reports/${reportId}/detail (frontend/src/App.tsx:909)", "shortDescription": {"text": "Dangling fetch: GET /api/admin/reports/${reportId}/detail (frontend/src/App.tsx:909)"}, "fullDescription": {"text": "`frontend/src/App.tsx:909` calls `GET /api/admin/reports/${reportId}/detail` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/admin/reports/<p>/detail`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-95290fee3664c200", "name": "Dangling fetch: DELETE /api/admin/reports/${reportId} (frontend/src/App.tsx:930)", "shortDescription": {"text": "Dangling fetch: DELETE /api/admin/reports/${reportId} (frontend/src/App.tsx:930)"}, "fullDescription": {"text": "`frontend/src/App.tsx:930` calls `DELETE /api/admin/reports/${reportId}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/admin/reports/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-8969fad462e82140", "name": "Dangling fetch: POST /api/admin/reports/bulk-delete (frontend/src/App.tsx:954)", "shortDescription": {"text": "Dangling fetch: POST /api/admin/reports/bulk-delete (frontend/src/App.tsx:954)"}, "fullDescription": {"text": "`frontend/src/App.tsx:954` calls `POST /api/admin/reports/bulk-delete` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/admin/reports/bulk-delete`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-3984c5558e6b44e4", "name": "Dangling fetch: POST /api/admin/reports/${reportId}/resend (frontend/src/App.tsx:980)", "shortDescription": {"text": "Dangling fetch: POST /api/admin/reports/${reportId}/resend (frontend/src/App.tsx:980)"}, "fullDescription": {"text": "`frontend/src/App.tsx:980` calls `POST /api/admin/reports/${reportId}/resend` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/admin/reports/<p>/resend`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-b64e85babd1e310e", "name": "Dangling fetch: GET /api/admin/companies/${companyId}/emails (frontend/src/components/CompanyEmailManager.tsx:43)", "shortDescription": {"text": "Dangling fetch: GET /api/admin/companies/${companyId}/emails (frontend/src/components/CompanyEmailManager.tsx:43)"}, "fullDescription": {"text": "`frontend/src/components/CompanyEmailManager.tsx:43` calls `GET /api/admin/companies/${companyId}/emails` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/admin/companies/<p>/emails`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-a7a6a579a62fe804", "name": "Dangling fetch: POST /api/admin/companies/${companyId}/emails (frontend/src/components/CompanyEmailManager.tsx:74)", "shortDescription": {"text": "Dangling fetch: POST /api/admin/companies/${companyId}/emails (frontend/src/components/CompanyEmailManager.tsx:74)"}, "fullDescription": {"text": "`frontend/src/components/CompanyEmailManager.tsx:74` calls `POST /api/admin/companies/${companyId}/emails` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/admin/companies/<p>/emails`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-70b4f608bc12e7c2", "name": "Dangling fetch: DELETE /api/admin/companies/${companyId}/emails/${emailId} (frontend/src/components/CompanyEmailManager.", "shortDescription": {"text": "Dangling fetch: DELETE /api/admin/companies/${companyId}/emails/${emailId} (frontend/src/components/CompanyEmailManager.tsx:101)"}, "fullDescription": {"text": "`frontend/src/components/CompanyEmailManager.tsx:101` calls `DELETE /api/admin/companies/${companyId}/emails/${emailId}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/admin/companies/<p>/emails/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-a6c2f306d2a3e8d4", "name": "Dangling fetch: GET /api/projects/${uniqueUrl} (frontend/src/pages/FieldReport.tsx:127)", "shortDescription": {"text": "Dangling fetch: GET /api/projects/${uniqueUrl} (frontend/src/pages/FieldReport.tsx:127)"}, "fullDescription": {"text": "`frontend/src/pages/FieldReport.tsx:127` calls `GET /api/projects/${uniqueUrl}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/projects/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-b5a8661b034d7a8b", "name": "Dangling fetch: POST /api/cast/exchange-cast-token (frontend/src/pages/FieldReport.tsx:215)", "shortDescription": {"text": "Dangling fetch: POST /api/cast/exchange-cast-token (frontend/src/pages/FieldReport.tsx:215)"}, "fullDescription": {"text": "`frontend/src/pages/FieldReport.tsx:215` calls `POST /api/cast/exchange-cast-token` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/cast/exchange-cast-token`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-917099b157adfa35", "name": "Dangling fetch: GET /api/drafts/${uniqueUrl} (frontend/src/pages/FieldReport.tsx:331)", "shortDescription": {"text": "Dangling fetch: GET /api/drafts/${uniqueUrl} (frontend/src/pages/FieldReport.tsx:331)"}, "fullDescription": {"text": "`frontend/src/pages/FieldReport.tsx:331` calls `GET /api/drafts/${uniqueUrl}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/drafts/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-d86d70d71c9bcaf1", "name": "Dangling fetch: PUT /api/drafts/${uniqueUrl} (frontend/src/pages/FieldReport.tsx:382)", "shortDescription": {"text": "Dangling fetch: PUT /api/drafts/${uniqueUrl} (frontend/src/pages/FieldReport.tsx:382)"}, "fullDescription": {"text": "`frontend/src/pages/FieldReport.tsx:382` calls `PUT /api/drafts/${uniqueUrl}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/drafts/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-d6c587c3fd8585ea", "name": "Dangling fetch: POST /api/reports/approve (frontend/src/pages/FieldReport.tsx:435)", "shortDescription": {"text": "Dangling fetch: POST /api/reports/approve (frontend/src/pages/FieldReport.tsx:435)"}, "fullDescription": {"text": "`frontend/src/pages/FieldReport.tsx:435` calls `POST /api/reports/approve` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/reports/approve`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-81c01dd8dcdda43b", "name": "Dangling fetch: GET /api/staff/search?q=${encodeURIComponent(query)} (frontend/src/pages/FieldReport.tsx:494)", "shortDescription": {"text": "Dangling fetch: GET /api/staff/search?q=${encodeURIComponent(query)} (frontend/src/pages/FieldReport.tsx:494)"}, "fullDescription": {"text": "`frontend/src/pages/FieldReport.tsx:494` calls `GET /api/staff/search?q=${encodeURIComponent(query)}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/staff/search`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-b16c40ba93b9a2cc", "name": "Dangling fetch: POST /api/staff/select (frontend/src/pages/FieldReport.tsx:518)", "shortDescription": {"text": "Dangling fetch: POST /api/staff/select (frontend/src/pages/FieldReport.tsx:518)"}, "fullDescription": {"text": "`frontend/src/pages/FieldReport.tsx:518` calls `POST /api/staff/select` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/staff/select`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-65dc217cb5c4ce00", "name": "Dangling fetch: GET /api/staff/search?q=${encodeURIComponent(q)} (frontend/src/pages/FieldReport.tsx:1026)", "shortDescription": {"text": "Dangling fetch: GET /api/staff/search?q=${encodeURIComponent(q)} (frontend/src/pages/FieldReport.tsx:1026)"}, "fullDescription": {"text": "`frontend/src/pages/FieldReport.tsx:1026` calls `GET /api/staff/search?q=${encodeURIComponent(q)}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/staff/search`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-a6176fe4bca1eae2", "name": "Dangling fetch: POST /api/staff/register (frontend/src/pages/FieldReport.tsx:1107)", "shortDescription": {"text": "Dangling fetch: POST /api/staff/register (frontend/src/pages/FieldReport.tsx:1107)"}, "fullDescription": {"text": "`frontend/src/pages/FieldReport.tsx:1107` calls `POST /api/staff/register` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/staff/register`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-fa50afa19f4fe45d", "name": "Dangling fetch: GET /api/admin/me (frontend/src/pages/RootRedirect.tsx:16)", "shortDescription": {"text": "Dangling fetch: GET /api/admin/me (frontend/src/pages/RootRedirect.tsx:16)"}, "fullDescription": {"text": "`frontend/src/pages/RootRedirect.tsx:16` calls `GET /api/admin/me` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/admin/me`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-b5f8f79010d74625", "name": "Dangling fetch: GET /api/admin/control-board?date=${encodeURIComponent(date)} (frontend/src/pages/admin/ControlBoardPage", "shortDescription": {"text": "Dangling fetch: GET /api/admin/control-board?date=${encodeURIComponent(date)} (frontend/src/pages/admin/ControlBoardPage.tsx:50)"}, "fullDescription": {"text": "`frontend/src/pages/admin/ControlBoardPage.tsx:50` calls `GET /api/admin/control-board?date=${encodeURIComponent(date)}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/admin/control-board`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-c9ba7498facf99d6", "name": "Dangling fetch: GET /api/admin/email-logs?${params} (frontend/src/pages/admin/EmailLogsPage.tsx:42)", "shortDescription": {"text": "Dangling fetch: GET /api/admin/email-logs?${params} (frontend/src/pages/admin/EmailLogsPage.tsx:42)"}, "fullDescription": {"text": "`frontend/src/pages/admin/EmailLogsPage.tsx:42` calls `GET /api/admin/email-logs?${params}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/admin/email-logs`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-4864e67c6e241046", "name": "Dangling fetch: POST /api/admin/email-logs/${logId}/resend (frontend/src/pages/admin/EmailLogsPage.tsx:70)", "shortDescription": {"text": "Dangling fetch: POST /api/admin/email-logs/${logId}/resend (frontend/src/pages/admin/EmailLogsPage.tsx:70)"}, "fullDescription": {"text": "`frontend/src/pages/admin/EmailLogsPage.tsx:70` calls `POST /api/admin/email-logs/${logId}/resend` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/admin/email-logs/<p>/resend`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-fb025c2538eff02f", "name": "Dangling fetch: POST /api/admin/send-login-url (frontend/src/pages/admin/SendLoginUrlPage.tsx:50)", "shortDescription": {"text": "Dangling fetch: POST /api/admin/send-login-url (frontend/src/pages/admin/SendLoginUrlPage.tsx:50)"}, "fullDescription": {"text": "`frontend/src/pages/admin/SendLoginUrlPage.tsx:50` calls `POST /api/admin/send-login-url` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/admin/send-login-url`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-8f1bbeffc6140950", "name": "Dangling fetch: POST /api/admin/send-login-url (frontend/src/pages/admin/SendLoginUrlPage.tsx:78)", "shortDescription": {"text": "Dangling fetch: POST /api/admin/send-login-url (frontend/src/pages/admin/SendLoginUrlPage.tsx:78)"}, "fullDescription": {"text": "`frontend/src/pages/admin/SendLoginUrlPage.tsx:78` calls `POST /api/admin/send-login-url` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/admin/send-login-url`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-dae8959e36c4ca36", "name": "Dangling fetch: GET /api/admin/settings/email-notification (frontend/src/pages/admin/DashboardPage.tsx:16)", "shortDescription": {"text": "Dangling fetch: GET /api/admin/settings/email-notification (frontend/src/pages/admin/DashboardPage.tsx:16)"}, "fullDescription": {"text": "`frontend/src/pages/admin/DashboardPage.tsx:16` calls `GET /api/admin/settings/email-notification` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/admin/settings/email-notification`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-446e610a948dc0e1", "name": "Dangling fetch: PUT /api/admin/settings/email-notification (frontend/src/pages/admin/DashboardPage.tsx:46)", "shortDescription": {"text": "Dangling fetch: PUT /api/admin/settings/email-notification (frontend/src/pages/admin/DashboardPage.tsx:46)"}, "fullDescription": {"text": "`frontend/src/pages/admin/DashboardPage.tsx:46` calls `PUT /api/admin/settings/email-notification` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/admin/settings/email-notification`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-e709b17144729356", "name": "Dangling fetch: GET /api/admin/inquiries (frontend/src/pages/admin/InquiriesPage.tsx:48)", "shortDescription": {"text": "Dangling fetch: GET /api/admin/inquiries (frontend/src/pages/admin/InquiriesPage.tsx:48)"}, "fullDescription": {"text": "`frontend/src/pages/admin/InquiriesPage.tsx:48` calls `GET /api/admin/inquiries` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/admin/inquiries`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-7e2c064d04b8f624", "name": "Dangling fetch: PUT /api/admin/inquiries/${id}/status (frontend/src/pages/admin/InquiriesPage.tsx:66)", "shortDescription": {"text": "Dangling fetch: PUT /api/admin/inquiries/${id}/status (frontend/src/pages/admin/InquiriesPage.tsx:66)"}, "fullDescription": {"text": "`frontend/src/pages/admin/InquiriesPage.tsx:66` calls `PUT /api/admin/inquiries/${id}/status` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/admin/inquiries/<p>/status`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-c6211ee0fa911535", "name": "Dangling fetch: POST https://slack.com/api/files.getUploadURLExternal (backend/src/services/notifications.ts:154)", "shortDescription": {"text": "Dangling fetch: POST https://slack.com/api/files.getUploadURLExternal (backend/src/services/notifications.ts:154)"}, "fullDescription": {"text": "`backend/src/services/notifications.ts:154` calls `POST https://slack.com/api/files.getUploadURLExternal` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/slack.com/api/files.getuploadurlexternal`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-6f016b3c20f32019", "name": "Dangling fetch: POST https://slack.com/api/files.completeUploadExternal (backend/src/services/notifications.ts:183)", "shortDescription": {"text": "Dangling fetch: POST https://slack.com/api/files.completeUploadExternal (backend/src/services/notifications.ts:183)"}, "fullDescription": {"text": "`backend/src/services/notifications.ts:183` calls `POST https://slack.com/api/files.completeUploadExternal` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/slack.com/api/files.completeuploadexternal`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-dde3adb27bf7eebe", "name": "Unused endpoint: USE /api", "shortDescription": {"text": "Unused endpoint: USE /api"}, "fullDescription": {"text": "`backend/src/index.ts` declares `USE /api` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-fb249c271605d179", "name": "Unused endpoint: USE /api/admin/auth", "shortDescription": {"text": "Unused endpoint: USE /api/admin/auth"}, "fullDescription": {"text": "`backend/src/index.ts` declares `USE /api/admin/auth` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d65e041f6f8fecef", "name": "Unused endpoint: USE /api/admin/projects", "shortDescription": {"text": "Unused endpoint: USE /api/admin/projects"}, "fullDescription": {"text": "`backend/src/index.ts` declares `USE /api/admin/projects` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a91704d91a01e0de", "name": "Unused endpoint: USE /api/admin/control-board", "shortDescription": {"text": "Unused endpoint: USE /api/admin/control-board"}, "fullDescription": {"text": "`backend/src/index.ts` declares `USE /api/admin/control-board` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d93a530ce10d47d9", "name": "Unused endpoint: USE /api/admin", "shortDescription": {"text": "Unused endpoint: USE /api/admin"}, "fullDescription": {"text": "`backend/src/index.ts` declares `USE /api/admin` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-23bb1fec573b0241", "name": "Unused endpoint: USE /api/admin/reports", "shortDescription": {"text": "Unused endpoint: USE /api/admin/reports"}, "fullDescription": {"text": "`backend/src/index.ts` declares `USE /api/admin/reports` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ee6cce5de8114795", "name": "Unused endpoint: USE /api/admin/recipients", "shortDescription": {"text": "Unused endpoint: USE /api/admin/recipients"}, "fullDescription": {"text": "`backend/src/index.ts` declares `USE /api/admin/recipients` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c511a641229413ec", "name": "Unused endpoint: USE /api/admin/companies", "shortDescription": {"text": "Unused endpoint: USE /api/admin/companies"}, "fullDescription": {"text": "`backend/src/index.ts` declares `USE /api/admin/companies` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-23f8c45942243bc5", "name": "Unused endpoint: USE /api/admin/email-logs", "shortDescription": {"text": "Unused endpoint: USE /api/admin/email-logs"}, "fullDescription": {"text": "`backend/src/index.ts` declares `USE /api/admin/email-logs` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-728e92394c568abf", "name": "Unused endpoint: USE /api/projects", "shortDescription": {"text": "Unused endpoint: USE /api/projects"}, "fullDescription": {"text": "`backend/src/index.ts` declares `USE /api/projects` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-375cbbc5a3cc2d4a", "name": "Unused endpoint: USE /api/drafts", "shortDescription": {"text": "Unused endpoint: USE /api/drafts"}, "fullDescription": {"text": "`backend/src/index.ts` declares `USE /api/drafts` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2a06e6d401449b82", "name": "Unused endpoint: USE /api/reports", "shortDescription": {"text": "Unused endpoint: USE /api/reports"}, "fullDescription": {"text": "`backend/src/index.ts` declares `USE /api/reports` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-fd91a9955302e09b", "name": "Unused endpoint: USE /api/admin/csv", "shortDescription": {"text": "Unused endpoint: USE /api/admin/csv"}, "fullDescription": {"text": "`backend/src/index.ts` declares `USE /api/admin/csv` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5397f3c1b60808f0", "name": "Unused endpoint: USE /api/staff", "shortDescription": {"text": "Unused endpoint: USE /api/staff"}, "fullDescription": {"text": "`backend/src/index.ts` declares `USE /api/staff` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-63704095ac5e52ca", "name": "Unused endpoint: USE /api/cast", "shortDescription": {"text": "Unused endpoint: USE /api/cast"}, "fullDescription": {"text": "`backend/src/index.ts` declares `USE /api/cast` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-67e21a50a1402fd9", "name": "Unused endpoint: GET /report/:uniqueUrl", "shortDescription": {"text": "Unused endpoint: GET /report/:uniqueUrl"}, "fullDescription": {"text": "`backend/src/index.ts` declares `GET /report/:uniqueUrl` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-71aa93ab7d18b6ba", "name": "Unused endpoint: POST /api/test/admin-login", "shortDescription": {"text": "Unused endpoint: POST /api/test/admin-login"}, "fullDescription": {"text": "`backend/src/index.ts` declares `POST /api/test/admin-login` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-304b6f2b403d93f7", "name": "Unused endpoint: POST /register", "shortDescription": {"text": "Unused endpoint: POST /register"}, "fullDescription": {"text": "`backend/src/routes/castAuth.ts` declares `POST /register` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-aee9168e964a3822", "name": "Unused endpoint: POST /verify", "shortDescription": {"text": "Unused endpoint: POST /verify"}, "fullDescription": {"text": "`backend/src/routes/castAuth.ts` declares `POST /verify` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-618721b912bad1c2", "name": "Unused endpoint: POST /login", "shortDescription": {"text": "Unused endpoint: POST /login"}, "fullDescription": {"text": "`backend/src/routes/castAuth.ts` declares `POST /login` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2ee4be5d71be34a5", "name": "Unused endpoint: POST /magic-link", "shortDescription": {"text": "Unused endpoint: POST /magic-link"}, "fullDescription": {"text": "`backend/src/routes/castAuth.ts` declares `POST /magic-link` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ca0d5b3c4a96f12d", "name": "Unused endpoint: POST /magic", "shortDescription": {"text": "Unused endpoint: POST /magic"}, "fullDescription": {"text": "`backend/src/routes/castAuth.ts` declares `POST /magic` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-fd1dc91abf32142d", "name": "Unused endpoint: GET /me", "shortDescription": {"text": "Unused endpoint: GET /me"}, "fullDescription": {"text": "`backend/src/routes/castAuth.ts` declares `GET /me` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b9c041dc087ff77f", "name": "Unused endpoint: GET /today", "shortDescription": {"text": "Unused endpoint: GET /today"}, "fullDescription": {"text": "`backend/src/routes/castAuth.ts` declares `GET /today` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-60cee4315f4a8aca", "name": "Unused endpoint: GET /search-staff", "shortDescription": {"text": "Unused endpoint: GET /search-staff"}, "fullDescription": {"text": "`backend/src/routes/castAuth.ts` declares `GET /search-staff` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a68e62ee9a79b6e5", "name": "Unused endpoint: POST /reset-pin", "shortDescription": {"text": "Unused endpoint: POST /reset-pin"}, "fullDescription": {"text": "`backend/src/routes/castAuth.ts` declares `POST /reset-pin` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ff2f60a712955bca", "name": "Unused endpoint: GET /reset-pin/verify", "shortDescription": {"text": "Unused endpoint: GET /reset-pin/verify"}, "fullDescription": {"text": "`backend/src/routes/castAuth.ts` declares `GET /reset-pin/verify` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c9221f863ded2a52", "name": "Unused endpoint: POST /reset-pin/confirm", "shortDescription": {"text": "Unused endpoint: POST /reset-pin/confirm"}, "fullDescription": {"text": "`backend/src/routes/castAuth.ts` declares `POST /reset-pin/confirm` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-99fc36db98c134ce", "name": "Unused endpoint: POST /logout", "shortDescription": {"text": "Unused endpoint: POST /logout"}, "fullDescription": {"text": "`backend/src/routes/castAuth.ts` declares `POST /logout` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-92cf0af164564f78", "name": "Unused endpoint: POST /field-login", "shortDescription": {"text": "Unused endpoint: POST /field-login"}, "fullDescription": {"text": "`backend/src/routes/castAuth.ts` declares `POST /field-login` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4adba6f22dc99c78", "name": "Unused endpoint: POST /field-register", "shortDescription": {"text": "Unused endpoint: POST /field-register"}, "fullDescription": {"text": "`backend/src/routes/castAuth.ts` declares `POST /field-register` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f3634afb5d4bb2b3", "name": "Unused endpoint: POST /exchange-cast-token", "shortDescription": {"text": "Unused endpoint: POST /exchange-cast-token"}, "fullDescription": {"text": "`backend/src/routes/castAuth.ts` declares `POST /exchange-cast-token` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-02e20206f838a31f", "name": "Unused endpoint: POST /mail-help", "shortDescription": {"text": "Unused endpoint: POST /mail-help"}, "fullDescription": {"text": "`backend/src/routes/castAuth.ts` declares `POST /mail-help` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b4d6029703668a6e", "name": "Unused endpoint: POST /inquiry", "shortDescription": {"text": "Unused endpoint: POST /inquiry"}, "fullDescription": {"text": "`backend/src/routes/castAuth.ts` declares `POST /inquiry` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a009857a541ee10f", "name": "Unused endpoint: POST /:projectId/cancel", "shortDescription": {"text": "Unused endpoint: POST /:projectId/cancel"}, "fullDescription": {"text": "`backend/src/routes/adminProjectCancel.ts` declares `POST /:projectId/cancel` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c161bb41799c8001", "name": "Unused endpoint: POST /:projectId/cancel/resend", "shortDescription": {"text": "Unused endpoint: POST /:projectId/cancel/resend"}, "fullDescription": {"text": "`backend/src/routes/adminProjectCancel.ts` declares `POST /:projectId/cancel/resend` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a52dcc25c9521ef8", "name": "Unused endpoint: POST /:projectId/restore", "shortDescription": {"text": "Unused endpoint: POST /:projectId/restore"}, "fullDescription": {"text": "`backend/src/routes/adminProjectCancel.ts` declares `POST /:projectId/restore` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-be4cb5e3cabcce80", "name": "Unused endpoint: POST /import", "shortDescription": {"text": "Unused endpoint: POST /import"}, "fullDescription": {"text": "`backend/src/routes/adminCsvImport.ts` declares `POST /import` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0e1d335441f7165d", "name": "Unused endpoint: GET /imports", "shortDescription": {"text": "Unused endpoint: GET /imports"}, "fullDescription": {"text": "`backend/src/routes/adminCsvImport.ts` declares `GET /imports` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6ac0762ab69fcd7e", "name": "Unused endpoint: GET /imports/:id/projects", "shortDescription": {"text": "Unused endpoint: GET /imports/:id/projects"}, "fullDescription": {"text": "`backend/src/routes/adminCsvImport.ts` declares `GET /imports/:id/projects` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0b8f4adbf3e396d1", "name": "Unused endpoint: PUT /:project_unique_url", "shortDescription": {"text": "Unused endpoint: PUT /:project_unique_url"}, "fullDescription": {"text": "`backend/src/routes/drafts.ts` declares `PUT /:project_unique_url` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-674ede333826b6ad", "name": "Unused endpoint: GET /:project_unique_url", "shortDescription": {"text": "Unused endpoint: GET /:project_unique_url"}, "fullDescription": {"text": "`backend/src/routes/drafts.ts` declares `GET /:project_unique_url` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b78488ca426bf6de", "name": "Unused endpoint: POST /approve", "shortDescription": {"text": "Unused endpoint: POST /approve"}, "fullDescription": {"text": "`backend/src/routes/reports.ts` declares `POST /approve` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ee24e2aa1a2a8bef", "name": "Unused endpoint: GET /:reportId/pdf", "shortDescription": {"text": "Unused endpoint: GET /:reportId/pdf"}, "fullDescription": {"text": "`backend/src/routes/reports.ts` declares `GET /:reportId/pdf` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5baa8971ebe192a1", "name": "Unused endpoint: GET /", "shortDescription": {"text": "Unused endpoint: GET /"}, "fullDescription": {"text": "`backend/src/routes/adminControlBoard.ts` declares `GET /` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c55647ab565775a3", "name": "Unused endpoint: GET /:companyId/emails", "shortDescription": {"text": "Unused endpoint: GET /:companyId/emails"}, "fullDescription": {"text": "`backend/src/routes/adminCompanyEmails.ts` declares `GET /:companyId/emails` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1387ee53639bff45", "name": "Unused endpoint: POST /:companyId/emails", "shortDescription": {"text": "Unused endpoint: POST /:companyId/emails"}, "fullDescription": {"text": "`backend/src/routes/adminCompanyEmails.ts` declares `POST /:companyId/emails` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-02dd33e8afbe6618", "name": "Unused endpoint: PATCH /:companyId/emails/:emailId", "shortDescription": {"text": "Unused endpoint: PATCH /:companyId/emails/:emailId"}, "fullDescription": {"text": "`backend/src/routes/adminCompanyEmails.ts` declares `PATCH /:companyId/emails/:emailId` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d3e6dd92b30d502c", "name": "Unused endpoint: DELETE /:companyId/emails/:id", "shortDescription": {"text": "Unused endpoint: DELETE /:companyId/emails/:id"}, "fullDescription": {"text": "`backend/src/routes/adminCompanyEmails.ts` declares `DELETE /:companyId/emails/:id` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3d3bb7b8a4e0c87f", "name": "Unused endpoint: GET /google/start", "shortDescription": {"text": "Unused endpoint: GET /google/start"}, "fullDescription": {"text": "`backend/src/routes/adminAuth.ts` declares `GET /google/start` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}]}}, "automationDetails": {"id": "repobility/21364"}, "properties": {"repository": "tkgathr2/security-report-system", "repoUrl": "https://github.com/tkgathr2/security-report-system", "branch": "main"}, "results": [{"ruleId": "scanner-fb6b678288f233b8", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend/src/index.ts:137"}, "properties": {"repobilityId": "db2171a39601fa41", "scanner": "scanner-primary", "fingerprint": "fb6b678288f233b8", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-818c135d68311989", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend/src/utils/email.ts:12"}, "properties": {"repobilityId": "ac482d3f453aa043", "scanner": "scanner-primary", "fingerprint": "818c135d68311989", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-e9d5905da2c2865e", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend/src/routes/castAuth.ts:1249"}, "properties": {"repobilityId": "dda3ba6615eb32c0", "scanner": "scanner-primary", "fingerprint": "e9d5905da2c2865e", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-8e57ee118213a9d6", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend/src/routes/reports.ts:54"}, "properties": {"repobilityId": "d2291c7f1df0153c", "scanner": "scanner-primary", "fingerprint": "8e57ee118213a9d6", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-812e4022c888eb77", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend/src/routes/staff.ts:174"}, "properties": {"repobilityId": "c79219b37ba55ff6", "scanner": "scanner-primary", "fingerprint": "812e4022c888eb77", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-542a7fe88ec56b2b", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend/src/routes/adminReports.ts:141"}, "properties": {"repobilityId": "f70f0d0646a2eff5", "scanner": "scanner-primary", "fingerprint": "542a7fe88ec56b2b", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-6343e8b0516b32bd", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend/src/services/notifications.ts:36"}, "properties": {"repobilityId": "dc102fcd1440e871", "scanner": "scanner-primary", "fingerprint": "6343e8b0516b32bd", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-feb2637ca091618e", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend/src/services/dailyReminderService.ts:102"}, "properties": {"repobilityId": "fdf99925a1951047", "scanner": "scanner-primary", "fingerprint": "feb2637ca091618e", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-12288bb5a1117d17", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend/src/services/dataUploadMonitor.ts:104"}, "properties": {"repobilityId": "0127a30ee7bef1ff", "scanner": "scanner-primary", "fingerprint": "12288bb5a1117d17", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-db7b8714d741ce4e", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend/src/services/emailSender.ts:102"}, "properties": {"repobilityId": "032333cb26671c6e", "scanner": "scanner-primary", "fingerprint": "db7b8714d741ce4e", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-8ff4393bf25ec8cc", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend/src/db/pool.ts:14"}, "properties": {"repobilityId": "c1e476750c9fac36", "scanner": "scanner-primary", "fingerprint": "8ff4393bf25ec8cc", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-aa5acaa49eb8315b", "level": "note", "message": {"text": "Containers defined but no K8s/orchestration manifest found"}, "properties": {"repobilityId": "b230ea9b68736081", "scanner": "scanner-primary", "fingerprint": "aa5acaa49eb8315b", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["coverage", "deployment"]}}, {"ruleId": "scanner-728626a9ec3794ba", "level": "warning", "message": {"text": "Insecure pattern 'local_storage_auth_token' in frontend/src/pages/CastMailHelp.tsx:70"}, "properties": {"repobilityId": "9fed7384fe562b3e", "scanner": "scanner-primary", "fingerprint": "728626a9ec3794ba", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "local_storage_auth_token"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "frontend/src/pages/CastMailHelp.tsx"}, "region": {"startLine": 70}}}]}, {"ruleId": "scanner-3f5cb7ba5b722260", "level": "warning", "message": {"text": "Insecure pattern 'local_storage_auth_token' in frontend/src/pages/CastResetPin.tsx:90"}, "properties": {"repobilityId": "be2956964105cc56", "scanner": "scanner-primary", "fingerprint": "3f5cb7ba5b722260", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "local_storage_auth_token"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "frontend/src/pages/CastResetPin.tsx"}, "region": {"startLine": 90}}}]}, {"ruleId": "scanner-8ca0677ecdcee7fe", "level": "warning", "message": {"text": "Insecure pattern 'local_storage_auth_token' in frontend/src/pages/CastVerify.tsx:167"}, "properties": {"repobilityId": "940d5ee3deb70369", "scanner": "scanner-primary", "fingerprint": "8ca0677ecdcee7fe", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "local_storage_auth_token"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "frontend/src/pages/CastVerify.tsx"}, "region": {"startLine": 167}}}]}, {"ruleId": "scanner-b3ff9f7dafb73401", "level": "warning", "message": {"text": "Insecure pattern 'local_storage_auth_token' in frontend/src/pages/CastMagic.tsx:31"}, "properties": {"repobilityId": "09ebbd5c6101f711", "scanner": "scanner-primary", "fingerprint": "b3ff9f7dafb73401", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "local_storage_auth_token"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "frontend/src/pages/CastMagic.tsx"}, "region": {"startLine": 31}}}]}, {"ruleId": "scanner-5989edf37b2c6400", "level": "warning", "message": {"text": "Insecure pattern 'local_storage_auth_token' in frontend/src/pages/CastLogin.tsx:80"}, "properties": {"repobilityId": "8559473639d1cbe5", "scanner": "scanner-primary", "fingerprint": "5989edf37b2c6400", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "local_storage_auth_token"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "frontend/src/pages/CastLogin.tsx"}, "region": {"startLine": 80}}}]}, {"ruleId": "scanner-e62902694165b224", "level": "warning", "message": {"text": "GitHub Actions workflow grants broad write permissions"}, "properties": {"repobilityId": "1f6c5a7a5d239cdc", "scanner": "scanner-primary", "fingerprint": "e62902694165b224", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "least-privilege"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/auto-merge-devin.yml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-9783f351166036a8", "level": "note", "message": {"text": "Very large file: frontend/src/App.tsx (1688 lines)"}, "properties": {"repobilityId": "eae82fec6aab8d47", "scanner": "scanner-primary", "fingerprint": "9783f351166036a8", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-4e2675545eedba43", "level": "note", "message": {"text": "Very large file: frontend/src/pages/FieldReport.tsx (1966 lines)"}, "properties": {"repobilityId": "9aaf93a38cb831df", "scanner": "scanner-primary", "fingerprint": "4e2675545eedba43", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-89fdba6eae88579a", "level": "note", "message": {"text": "Very large file: backend/src/routes/admin.ts (1848 lines)"}, "properties": {"repobilityId": "385fd3fbf85b6f6a", "scanner": "scanner-primary", "fingerprint": "89fdba6eae88579a", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-ea3b5e389d8c9c0f", "level": "note", "message": {"text": "Low test-to-source ratio"}, "properties": {"repobilityId": "ef7b2552cc00a375", "scanner": "scanner-primary", "fingerprint": "ea3b5e389d8c9c0f", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["tests"]}}, {"ruleId": "scanner-141b30a41e03817b", "level": "note", "message": {"text": "No license file detected"}, "properties": {"repobilityId": "92e2d295cac60dc7", "scanner": "scanner-primary", "fingerprint": "141b30a41e03817b", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["license", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-3ab5d313dda8e5f9", "level": "note", "message": {"text": "Debug logging residue appears in source files"}, "properties": {"repobilityId": "f531dde902359314", "scanner": "scanner-primary", "fingerprint": "3ab5d313dda8e5f9", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["debug", "cleanup", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-72b2a6250083a784", "level": "warning", "message": {"text": "Placeholder or mock-heavy implementation detected"}, "properties": {"repobilityId": "0b71230457ae2de5", "scanner": "scanner-primary", "fingerprint": "72b2a6250083a784", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "incomplete", "generated-repo-pattern"]}}, {"ruleId": "scanner-2d0c7b7ab8f8aacf", "level": "warning", "message": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "properties": {"repobilityId": "715ba701e1c8da65", "scanner": "scanner-primary", "fingerprint": "2d0c7b7ab8f8aacf", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "critical-flow", "generated-repo-pattern"]}}, {"ruleId": "scanner-ea8f3013f588db25", "level": "note", "message": {"text": "Shallow git history limits provenance confidence"}, "properties": {"repobilityId": "b7ca189f5077ac81", "scanner": "scanner-primary", "fingerprint": "ea8f3013f588db25", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-8424db9c75e04ba4", "level": "none", "message": {"text": "Very short observed git history"}, "properties": {"repobilityId": "30031c4bb097192f", "scanner": "scanner-primary", "fingerprint": "8424db9c75e04ba4", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-16f0e832826e9cd5", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 frontend/src/App.tsx:295"}, "properties": {"repobilityId": "88bea393176658c9", "scanner": "scanner-primary", "fingerprint": "16f0e832826e9cd5", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-874e8a1e55c96de7", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 frontend/src/pages/CastToday.tsx:49"}, "properties": {"repobilityId": "73be4a20220ec5ff", "scanner": "scanner-primary", "fingerprint": "874e8a1e55c96de7", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-2c880565cb488178", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 frontend/src/pages/CastVerify.tsx:53"}, "properties": {"repobilityId": "4fd382a86d926f65", "scanner": "scanner-primary", "fingerprint": "2c880565cb488178", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-154f48d3a135729e", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 frontend/src/pages/CastMagic.tsx:23"}, "properties": {"repobilityId": "5649b1c5655b3382", "scanner": "scanner-primary", "fingerprint": "154f48d3a135729e", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-be2e59161314388c", "level": "none", "message": {"text": "Commented-code block (5 lines) in backend/migrations/1781300000000_drop-legacy-name-unique-index.js:1"}, "properties": {"repobilityId": "3c09c93df2c0d0af", "scanner": "scanner-primary", "fingerprint": "be2e59161314388c", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-fc85c3443c01a30e", "level": "none", "message": {"text": "Commented-code block (6 lines) in backend/migrations/1781100000000_add-procast-staff-no.js:1"}, "properties": {"repobilityId": "df353400101af29e", "scanner": "scanner-primary", "fingerprint": "fc85c3443c01a30e", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-813932da4ce7fb22", "level": "note", "message": {"text": "Legacy-named symbol `plan_v2` in backend/src/index.ts:107"}, "properties": {"repobilityId": "3896ae6b3a58bac4", "scanner": "scanner-primary", "fingerprint": "813932da4ce7fb22", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-1c6b3eeb23090645", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 backend/src/routes/admin.staff-create.test.ts:53"}, "properties": {"repobilityId": "a78238449ba08479", "scanner": "scanner-primary", "fingerprint": "1c6b3eeb23090645", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-003ec6b8aee378fc", "level": "none", "message": {"text": "Commented-code block (9 lines) in backend/src/services/staffResolver.ts:1"}, "properties": {"repobilityId": "75e0c4ad6280107f", "scanner": "scanner-primary", "fingerprint": "003ec6b8aee378fc", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-3fc74e7bb1fcbbc8", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 backend/src/services/notifications.ts:172"}, "properties": {"repobilityId": "26d493ba85ca8094", "scanner": "scanner-primary", "fingerprint": "3fc74e7bb1fcbbc8", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-a70971173d037fe6", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 backend/src/services/dataUploadMonitor.ts:127"}, "properties": {"repobilityId": "5a42e3e353cd102c", "scanner": "scanner-primary", "fingerprint": "a70971173d037fe6", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-9a82cf7d16234d20", "level": "note", "message": {"text": "21 env vars used in code but missing from .env.example"}, "properties": {"repobilityId": "2fad2cbef136ee78", "scanner": "scanner-primary", "fingerprint": "9a82cf7d16234d20", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "config-drift"]}}, {"ruleId": "scanner-b45d19fa5723c207", "level": "warning", "message": {"text": "Frontend route `/report/:uniqueUrl` has no Link/navigate to it \u2014 frontend/src/main.tsx"}, "properties": {"repobilityId": "e6abc2e1feb9b2ed", "scanner": "scanner-primary", "fingerprint": "b45d19fa5723c207", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "orphan-page", "wiring"]}}, {"ruleId": "scanner-5840221e26f51957", "level": "warning", "message": {"text": "Frontend route `/cast/verify` has no Link/navigate to it \u2014 frontend/src/main.tsx"}, "properties": {"repobilityId": "a6db2125f6ca5a34", "scanner": "scanner-primary", "fingerprint": "5840221e26f51957", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "orphan-page", "wiring"]}}, {"ruleId": "scanner-d3cf1093b9c14808", "level": "warning", "message": {"text": "Frontend route `/cast/magic` has no Link/navigate to it \u2014 frontend/src/main.tsx"}, "properties": {"repobilityId": "965b93f9edc16a76", "scanner": "scanner-primary", "fingerprint": "d3cf1093b9c14808", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "orphan-page", "wiring"]}}, {"ruleId": "scanner-505f2d783a177827", "level": "warning", "message": {"text": "Frontend route `/*` has no Link/navigate to it \u2014 frontend/src/main.tsx"}, "properties": {"repobilityId": "d43b7e0b45ccb7a3", "scanner": "scanner-primary", "fingerprint": "505f2d783a177827", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "orphan-page", "wiring"]}}, {"ruleId": "scanner-27826dcf3cc718cc", "level": "error", "message": {"text": "Dangling fetch: GET /api/admin/me (frontend/src/App.tsx:150)"}, "properties": {"repobilityId": "17faa58aae70e3dc", "scanner": "scanner-primary", "fingerprint": "27826dcf3cc718cc", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-4016b064bef78b2f", "level": "error", "message": {"text": "Dangling fetch: POST /api/admin/auth/logout (frontend/src/App.tsx:172)"}, "properties": {"repobilityId": "da7ce643f9aa9087", "scanner": "scanner-primary", "fingerprint": "4016b064bef78b2f", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-dbd68a304c582251", "level": "error", "message": {"text": "Dangling fetch: POST /api/admin/auth/request-access (frontend/src/App.tsx:186)"}, "properties": {"repobilityId": "e89a5a98731cd8b4", "scanner": "scanner-primary", "fingerprint": "dbd68a304c582251", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-a44d78eed6adfe6d", "level": "error", "message": {"text": "Dangling fetch: GET /api/admin/auth/access-requests (frontend/src/App.tsx:202)"}, "properties": {"repobilityId": "df323d0eeaca5a8c", "scanner": "scanner-primary", "fingerprint": "a44d78eed6adfe6d", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-e39d08bc437e02d3", "level": "error", "message": {"text": "Dangling fetch: GET /api/admin/auth/admins (frontend/src/App.tsx:213)"}, "properties": {"repobilityId": "8bd3f8990e32e9b3", "scanner": "scanner-primary", "fingerprint": "e39d08bc437e02d3", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-c8f01982628346f0", "level": "error", "message": {"text": "Dangling fetch: POST /api/admin/auth/access-requests/${requestId}/approve (frontend/src/App.tsx:224)"}, "properties": {"repobilityId": "a45df6c6dca333f4", "scanner": "scanner-primary", "fingerprint": "c8f01982628346f0", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-9b56d0af9c60fa5c", "level": "error", "message": {"text": "Dangling fetch: POST /api/admin/auth/access-requests/${requestId}/reject (frontend/src/App.tsx:246)"}, "properties": {"repobilityId": "f2228c511f854b87", "scanner": "scanner-primary", "fingerprint": "9b56d0af9c60fa5c", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-fcf6028e035d2aac", "level": "error", "message": {"text": "Dangling fetch: PUT /api/admin/auth/admins/${adminId}/role (frontend/src/App.tsx:258)"}, "properties": {"repobilityId": "233697d08eb73abd", "scanner": "scanner-primary", "fingerprint": "fcf6028e035d2aac", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-dba0b6b9d57526db", "level": "error", "message": {"text": "Dangling fetch: DELETE /api/admin/auth/admins/${adminId} (frontend/src/App.tsx:275)"}, "properties": {"repobilityId": "f0cc13bcea0a9de2", "scanner": "scanner-primary", "fingerprint": "dba0b6b9d57526db", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-3836fe348841352a", "level": "error", "message": {"text": "Dangling fetch: GET /api/admin/projects?date=${dateStr} (frontend/src/App.tsx:338)"}, "properties": {"repobilityId": "c42c3234dea5d164", "scanner": "scanner-primary", "fingerprint": "3836fe348841352a", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-b8d68641a40abe1a", "level": "error", "message": {"text": "Dangling fetch: POST /api/admin/projects/${cancelModalProject.id}/cancel (frontend/src/App.tsx:361)"}, "properties": {"repobilityId": "9e93600ffcfae9a5", "scanner": "scanner-primary", "fingerprint": "b8d68641a40abe1a", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-d3fd22d87f3645cd", "level": "error", "message": {"text": "Dangling fetch: POST /api/admin/projects/${project.id}/restore (frontend/src/App.tsx:399)"}, "properties": {"repobilityId": "7c35e4298c051a05", "scanner": "scanner-primary", "fingerprint": "d3fd22d87f3645cd", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-29a53a49c650c13e", "level": "error", "message": {"text": "Dangling fetch: POST /api/admin/projects/${project.id}/cancel/resend (frontend/src/App.tsx:418)"}, "properties": {"repobilityId": "f0697024f8a7a72e", "scanner": "scanner-primary", "fingerprint": "29a53a49c650c13e", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-24bf26116c551310", "level": "error", "message": {"text": "Dangling fetch: GET /api/admin/staff (frontend/src/App.tsx:462)"}, "properties": {"repobilityId": "8d3c32f9316dd032", "scanner": "scanner-primary", "fingerprint": "24bf26116c551310", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-27096412a7e1908b", "level": "error", "message": {"text": "Dangling fetch: GET /api/admin/csv/imports (frontend/src/App.tsx:484)"}, "properties": {"repobilityId": "adf0a71c389098c8", "scanner": "scanner-primary", "fingerprint": "27096412a7e1908b", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-8ec613e947d6d10e", "level": "error", "message": {"text": "Dangling fetch: GET /api/admin/csv/imports/${importId}/projects (frontend/src/App.tsx:504)"}, "properties": {"repobilityId": "1c65ca1d116c51f8", "scanner": "scanner-primary", "fingerprint": "8ec613e947d6d10e", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-8d4d8be264b78a37", "level": "error", "message": {"text": "Dangling fetch: GET /api/admin/clients (frontend/src/App.tsx:527)"}, "properties": {"repobilityId": "d839803efef1645d", "scanner": "scanner-primary", "fingerprint": "8d4d8be264b78a37", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-3a28183c20abc761", "level": "error", "message": {"text": "Dangling fetch: PUT /api/admin/clients/${editingClient.id} (frontend/src/App.tsx:561)"}, "properties": {"repobilityId": "e87b75560be66157", "scanner": "scanner-primary", "fingerprint": "3a28183c20abc761", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-cee7becf44956a44", "level": "error", "message": {"text": "Dangling fetch: POST /api/admin/clients (frontend/src/App.tsx:596)"}, "properties": {"repobilityId": "15c6d3a98be3a863", "scanner": "scanner-primary", "fingerprint": "cee7becf44956a44", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-fe12db00d658955a", "level": "error", "message": {"text": "Dangling fetch: DELETE /api/admin/clients/${clientId} (frontend/src/App.tsx:624)"}, "properties": {"repobilityId": "21d2a4094c49f162", "scanner": "scanner-primary", "fingerprint": "fe12db00d658955a", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-9b0892f5a589e399", "level": "error", "message": {"text": "Dangling fetch: DELETE /api/admin/projects/without-casts (frontend/src/App.tsx:642)"}, "properties": {"repobilityId": "8044d655252a1f76", "scanner": "scanner-primary", "fingerprint": "9b0892f5a589e399", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-d8856fa9ad2764c3", "level": "error", "message": {"text": "Dangling fetch: POST /api/admin/staff (frontend/src/App.tsx:667)"}, "properties": {"repobilityId": "3290b6eb7ff3a4f1", "scanner": "scanner-primary", "fingerprint": "d8856fa9ad2764c3", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-95a7575f5472b510", "level": "error", "message": {"text": "Dangling fetch: PUT /api/admin/staff/${editingStaff.id} (frontend/src/App.tsx:697)"}, "properties": {"repobilityId": "a1f232b73c16f053", "scanner": "scanner-primary", "fingerprint": "95a7575f5472b510", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-9c2159cbedf83b1f", "level": "error", "message": {"text": "Dangling fetch: DELETE /api/admin/staff/${staffId} (frontend/src/App.tsx:724)"}, "properties": {"repobilityId": "a4d0616df02e6900", "scanner": "scanner-primary", "fingerprint": "9c2159cbedf83b1f", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-362f6c1f763a3890", "level": "error", "message": {"text": "Dangling fetch: POST /api/admin/staff/${staffId}/clear-pin (frontend/src/App.tsx:744)"}, "properties": {"repobilityId": "3cc5c9f7b1af68b1", "scanner": "scanner-primary", "fingerprint": "362f6c1f763a3890", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-28a9c46e3f292c0f", "level": "error", "message": {"text": "Dangling fetch: POST /api/admin/staff/bulk-clear-pins (frontend/src/App.tsx:769)"}, "properties": {"repobilityId": "6010dd526921acae", "scanner": "scanner-primary", "fingerprint": "28a9c46e3f292c0f", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-c1942279d3a61a35", "level": "error", "message": {"text": "Dangling fetch: POST /api/admin/staff/import (frontend/src/App.tsx:795)"}, "properties": {"repobilityId": "051d3651a4dc3e91", "scanner": "scanner-primary", "fingerprint": "c1942279d3a61a35", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-77abdea97783e071", "level": "error", "message": {"text": "Dangling fetch: POST /api/admin/csv/import (frontend/src/App.tsx:825)"}, "properties": {"repobilityId": "6826050f2125809b", "scanner": "scanner-primary", "fingerprint": "77abdea97783e071", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-c0172878b1451a86", "level": "error", "message": {"text": "Dangling fetch: GET /api/admin/reports/${reportId}/detail (frontend/src/App.tsx:909)"}, "properties": {"repobilityId": "bee630042ce379b8", "scanner": "scanner-primary", "fingerprint": "c0172878b1451a86", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-95290fee3664c200", "level": "error", "message": {"text": "Dangling fetch: DELETE /api/admin/reports/${reportId} (frontend/src/App.tsx:930)"}, "properties": {"repobilityId": "8df096e96e11d12c", "scanner": "scanner-primary", "fingerprint": "95290fee3664c200", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-8969fad462e82140", "level": "error", "message": {"text": "Dangling fetch: POST /api/admin/reports/bulk-delete (frontend/src/App.tsx:954)"}, "properties": {"repobilityId": "769504a8a7e61cfc", "scanner": "scanner-primary", "fingerprint": "8969fad462e82140", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-3984c5558e6b44e4", "level": "error", "message": {"text": "Dangling fetch: POST /api/admin/reports/${reportId}/resend (frontend/src/App.tsx:980)"}, "properties": {"repobilityId": "5e165deb92f078e8", "scanner": "scanner-primary", "fingerprint": "3984c5558e6b44e4", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-b64e85babd1e310e", "level": "error", "message": {"text": "Dangling fetch: GET /api/admin/companies/${companyId}/emails (frontend/src/components/CompanyEmailManager.tsx:43)"}, "properties": {"repobilityId": "0bd66341a8873f2d", "scanner": "scanner-primary", "fingerprint": "b64e85babd1e310e", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-a7a6a579a62fe804", "level": "error", "message": {"text": "Dangling fetch: POST /api/admin/companies/${companyId}/emails (frontend/src/components/CompanyEmailManager.tsx:74)"}, "properties": {"repobilityId": "52b9febd12cf3aeb", "scanner": "scanner-primary", "fingerprint": "a7a6a579a62fe804", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-70b4f608bc12e7c2", "level": "error", "message": {"text": "Dangling fetch: DELETE /api/admin/companies/${companyId}/emails/${emailId} (frontend/src/components/CompanyEmailManager.tsx:101)"}, "properties": {"repobilityId": "ca800840f1f1a1e6", "scanner": "scanner-primary", "fingerprint": "70b4f608bc12e7c2", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-a6c2f306d2a3e8d4", "level": "error", "message": {"text": "Dangling fetch: GET /api/projects/${uniqueUrl} (frontend/src/pages/FieldReport.tsx:127)"}, "properties": {"repobilityId": "f676c3401aee960d", "scanner": "scanner-primary", "fingerprint": "a6c2f306d2a3e8d4", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-b5a8661b034d7a8b", "level": "error", "message": {"text": "Dangling fetch: POST /api/cast/exchange-cast-token (frontend/src/pages/FieldReport.tsx:215)"}, "properties": {"repobilityId": "c84666fbf462a3b4", "scanner": "scanner-primary", "fingerprint": "b5a8661b034d7a8b", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-917099b157adfa35", "level": "error", "message": {"text": "Dangling fetch: GET /api/drafts/${uniqueUrl} (frontend/src/pages/FieldReport.tsx:331)"}, "properties": {"repobilityId": "2632b9b923843d76", "scanner": "scanner-primary", "fingerprint": "917099b157adfa35", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-d86d70d71c9bcaf1", "level": "error", "message": {"text": "Dangling fetch: PUT /api/drafts/${uniqueUrl} (frontend/src/pages/FieldReport.tsx:382)"}, "properties": {"repobilityId": "924a1574a51628ba", "scanner": "scanner-primary", "fingerprint": "d86d70d71c9bcaf1", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-d6c587c3fd8585ea", "level": "error", "message": {"text": "Dangling fetch: POST /api/reports/approve (frontend/src/pages/FieldReport.tsx:435)"}, "properties": {"repobilityId": "a0e30b612bc319c6", "scanner": "scanner-primary", "fingerprint": "d6c587c3fd8585ea", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-81c01dd8dcdda43b", "level": "error", "message": {"text": "Dangling fetch: GET /api/staff/search?q=${encodeURIComponent(query)} (frontend/src/pages/FieldReport.tsx:494)"}, "properties": {"repobilityId": "7e5dd56cecf314d8", "scanner": "scanner-primary", "fingerprint": "81c01dd8dcdda43b", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-b16c40ba93b9a2cc", "level": "error", "message": {"text": "Dangling fetch: POST /api/staff/select (frontend/src/pages/FieldReport.tsx:518)"}, "properties": {"repobilityId": "823aabff98099eae", "scanner": "scanner-primary", "fingerprint": "b16c40ba93b9a2cc", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-65dc217cb5c4ce00", "level": "error", "message": {"text": "Dangling fetch: GET /api/staff/search?q=${encodeURIComponent(q)} (frontend/src/pages/FieldReport.tsx:1026)"}, "properties": {"repobilityId": "6fb0300f449f6f98", "scanner": "scanner-primary", "fingerprint": "65dc217cb5c4ce00", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-a6176fe4bca1eae2", "level": "error", "message": {"text": "Dangling fetch: POST /api/staff/register (frontend/src/pages/FieldReport.tsx:1107)"}, "properties": {"repobilityId": "597d54d8a4d70478", "scanner": "scanner-primary", "fingerprint": "a6176fe4bca1eae2", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-fa50afa19f4fe45d", "level": "error", "message": {"text": "Dangling fetch: GET /api/admin/me (frontend/src/pages/RootRedirect.tsx:16)"}, "properties": {"repobilityId": "eecc6d347008abc0", "scanner": "scanner-primary", "fingerprint": "fa50afa19f4fe45d", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-b5f8f79010d74625", "level": "error", "message": {"text": "Dangling fetch: GET /api/admin/control-board?date=${encodeURIComponent(date)} (frontend/src/pages/admin/ControlBoardPage.tsx:50)"}, "properties": {"repobilityId": "b328128c5befa407", "scanner": "scanner-primary", "fingerprint": "b5f8f79010d74625", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-c9ba7498facf99d6", "level": "error", "message": {"text": "Dangling fetch: GET /api/admin/email-logs?${params} (frontend/src/pages/admin/EmailLogsPage.tsx:42)"}, "properties": {"repobilityId": "1187f3674fecdc72", "scanner": "scanner-primary", "fingerprint": "c9ba7498facf99d6", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-4864e67c6e241046", "level": "error", "message": {"text": "Dangling fetch: POST /api/admin/email-logs/${logId}/resend (frontend/src/pages/admin/EmailLogsPage.tsx:70)"}, "properties": {"repobilityId": "664238ed97127967", "scanner": "scanner-primary", "fingerprint": "4864e67c6e241046", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-fb025c2538eff02f", "level": "error", "message": {"text": "Dangling fetch: POST /api/admin/send-login-url (frontend/src/pages/admin/SendLoginUrlPage.tsx:50)"}, "properties": {"repobilityId": "bbe07662d5d8dbb2", "scanner": "scanner-primary", "fingerprint": "fb025c2538eff02f", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-8f1bbeffc6140950", "level": "error", "message": {"text": "Dangling fetch: POST /api/admin/send-login-url (frontend/src/pages/admin/SendLoginUrlPage.tsx:78)"}, "properties": {"repobilityId": "80935ce69bba9ff9", "scanner": "scanner-primary", "fingerprint": "8f1bbeffc6140950", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-dae8959e36c4ca36", "level": "error", "message": {"text": "Dangling fetch: GET /api/admin/settings/email-notification (frontend/src/pages/admin/DashboardPage.tsx:16)"}, "properties": {"repobilityId": "532689e0e618feb0", "scanner": "scanner-primary", "fingerprint": "dae8959e36c4ca36", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-446e610a948dc0e1", "level": "error", "message": {"text": "Dangling fetch: PUT /api/admin/settings/email-notification (frontend/src/pages/admin/DashboardPage.tsx:46)"}, "properties": {"repobilityId": "cb9326959964151d", "scanner": "scanner-primary", "fingerprint": "446e610a948dc0e1", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-e709b17144729356", "level": "error", "message": {"text": "Dangling fetch: GET /api/admin/inquiries (frontend/src/pages/admin/InquiriesPage.tsx:48)"}, "properties": {"repobilityId": "7c2b01b6a8f79c37", "scanner": "scanner-primary", "fingerprint": "e709b17144729356", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-7e2c064d04b8f624", "level": "error", "message": {"text": "Dangling fetch: PUT /api/admin/inquiries/${id}/status (frontend/src/pages/admin/InquiriesPage.tsx:66)"}, "properties": {"repobilityId": "d62d954e6ba2d72e", "scanner": "scanner-primary", "fingerprint": "7e2c064d04b8f624", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-c6211ee0fa911535", "level": "error", "message": {"text": "Dangling fetch: POST https://slack.com/api/files.getUploadURLExternal (backend/src/services/notifications.ts:154)"}, "properties": {"repobilityId": "4a06ac3e8a60f138", "scanner": "scanner-primary", "fingerprint": "c6211ee0fa911535", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-6f016b3c20f32019", "level": "error", "message": {"text": "Dangling fetch: POST https://slack.com/api/files.completeUploadExternal (backend/src/services/notifications.ts:183)"}, "properties": {"repobilityId": "638434518140558a", "scanner": "scanner-primary", "fingerprint": "6f016b3c20f32019", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-dde3adb27bf7eebe", "level": "note", "message": {"text": "Unused endpoint: USE /api"}, "properties": {"repobilityId": "e065f5f9c943f94a", "scanner": "scanner-primary", "fingerprint": "dde3adb27bf7eebe", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-fb249c271605d179", "level": "note", "message": {"text": "Unused endpoint: USE /api/admin/auth"}, "properties": {"repobilityId": "40fcde0be8da6d59", "scanner": "scanner-primary", "fingerprint": "fb249c271605d179", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-d65e041f6f8fecef", "level": "note", "message": {"text": "Unused endpoint: USE /api/admin/projects"}, "properties": {"repobilityId": "2c5442e5c338c41b", "scanner": "scanner-primary", "fingerprint": "d65e041f6f8fecef", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-a91704d91a01e0de", "level": "note", "message": {"text": "Unused endpoint: USE /api/admin/control-board"}, "properties": {"repobilityId": "baeb4e8d0c950a70", "scanner": "scanner-primary", "fingerprint": "a91704d91a01e0de", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-d93a530ce10d47d9", "level": "note", "message": {"text": "Unused endpoint: USE /api/admin"}, "properties": {"repobilityId": "0fd7b508ffe65f2b", "scanner": "scanner-primary", "fingerprint": "d93a530ce10d47d9", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-23bb1fec573b0241", "level": "note", "message": {"text": "Unused endpoint: USE /api/admin/reports"}, "properties": {"repobilityId": "8c657af3f7234dc0", "scanner": "scanner-primary", "fingerprint": "23bb1fec573b0241", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-ee6cce5de8114795", "level": "note", "message": {"text": "Unused endpoint: USE /api/admin/recipients"}, "properties": {"repobilityId": "2624145cad4cdf55", "scanner": "scanner-primary", "fingerprint": "ee6cce5de8114795", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-c511a641229413ec", "level": "note", "message": {"text": "Unused endpoint: USE /api/admin/companies"}, "properties": {"repobilityId": "61234d8ed4097d50", "scanner": "scanner-primary", "fingerprint": "c511a641229413ec", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-23f8c45942243bc5", "level": "note", "message": {"text": "Unused endpoint: USE /api/admin/email-logs"}, "properties": {"repobilityId": "41ea21ce7f1d779a", "scanner": "scanner-primary", "fingerprint": "23f8c45942243bc5", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-728e92394c568abf", "level": "note", "message": {"text": "Unused endpoint: USE /api/projects"}, "properties": {"repobilityId": "0f0194e6df39539f", "scanner": "scanner-primary", "fingerprint": "728e92394c568abf", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-375cbbc5a3cc2d4a", "level": "note", "message": {"text": "Unused endpoint: USE /api/drafts"}, "properties": {"repobilityId": "312e43b56a70e76b", "scanner": "scanner-primary", "fingerprint": "375cbbc5a3cc2d4a", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-2a06e6d401449b82", "level": "note", "message": {"text": "Unused endpoint: USE /api/reports"}, "properties": {"repobilityId": "14c1ccd732e151c9", "scanner": "scanner-primary", "fingerprint": "2a06e6d401449b82", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-fd91a9955302e09b", "level": "note", "message": {"text": "Unused endpoint: USE /api/admin/csv"}, "properties": {"repobilityId": "6181502751ffc953", "scanner": "scanner-primary", "fingerprint": "fd91a9955302e09b", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-5397f3c1b60808f0", "level": "note", "message": {"text": "Unused endpoint: USE /api/staff"}, "properties": {"repobilityId": "79470c8d3edde27e", "scanner": "scanner-primary", "fingerprint": "5397f3c1b60808f0", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-63704095ac5e52ca", "level": "note", "message": {"text": "Unused endpoint: USE /api/cast"}, "properties": {"repobilityId": "2dab96975fcdffb5", "scanner": "scanner-primary", "fingerprint": "63704095ac5e52ca", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-67e21a50a1402fd9", "level": "note", "message": {"text": "Unused endpoint: GET /report/:uniqueUrl"}, "properties": {"repobilityId": "d8275ed2e48f478d", "scanner": "scanner-primary", "fingerprint": "67e21a50a1402fd9", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-71aa93ab7d18b6ba", "level": "note", "message": {"text": "Unused endpoint: POST /api/test/admin-login"}, "properties": {"repobilityId": "dd214e97259739e6", "scanner": "scanner-primary", "fingerprint": "71aa93ab7d18b6ba", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-304b6f2b403d93f7", "level": "note", "message": {"text": "Unused endpoint: POST /register"}, "properties": {"repobilityId": "c340e1cfb6396b9f", "scanner": "scanner-primary", "fingerprint": "304b6f2b403d93f7", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-aee9168e964a3822", "level": "note", "message": {"text": "Unused endpoint: POST /verify"}, "properties": {"repobilityId": "3e6ec93042f7fcf5", "scanner": "scanner-primary", "fingerprint": "aee9168e964a3822", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-618721b912bad1c2", "level": "note", "message": {"text": "Unused endpoint: POST /login"}, "properties": {"repobilityId": "5d2473226cbdb15e", "scanner": "scanner-primary", "fingerprint": "618721b912bad1c2", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-2ee4be5d71be34a5", "level": "note", "message": {"text": "Unused endpoint: POST /magic-link"}, "properties": {"repobilityId": "055f2129940b52a4", "scanner": "scanner-primary", "fingerprint": "2ee4be5d71be34a5", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-ca0d5b3c4a96f12d", "level": "note", "message": {"text": "Unused endpoint: POST /magic"}, "properties": {"repobilityId": "efb17ef9d5bcc6cc", "scanner": "scanner-primary", "fingerprint": "ca0d5b3c4a96f12d", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-fd1dc91abf32142d", "level": "note", "message": {"text": "Unused endpoint: GET /me"}, "properties": {"repobilityId": "99fa72ccb5f86c51", "scanner": "scanner-primary", "fingerprint": "fd1dc91abf32142d", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-b9c041dc087ff77f", "level": "note", "message": {"text": "Unused endpoint: GET /today"}, "properties": {"repobilityId": "443083900acc2791", "scanner": "scanner-primary", "fingerprint": "b9c041dc087ff77f", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-60cee4315f4a8aca", "level": "note", "message": {"text": "Unused endpoint: GET /search-staff"}, "properties": {"repobilityId": "9f50b3093d77a081", "scanner": "scanner-primary", "fingerprint": "60cee4315f4a8aca", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-a68e62ee9a79b6e5", "level": "note", "message": {"text": "Unused endpoint: POST /reset-pin"}, "properties": {"repobilityId": "da04872188d9c452", "scanner": "scanner-primary", "fingerprint": "a68e62ee9a79b6e5", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-ff2f60a712955bca", "level": "note", "message": {"text": "Unused endpoint: GET /reset-pin/verify"}, "properties": {"repobilityId": "7f1d38b1e7091dd0", "scanner": "scanner-primary", "fingerprint": "ff2f60a712955bca", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-c9221f863ded2a52", "level": "note", "message": {"text": "Unused endpoint: POST /reset-pin/confirm"}, "properties": {"repobilityId": "f4df3fbf6e551bdc", "scanner": "scanner-primary", "fingerprint": "c9221f863ded2a52", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-99fc36db98c134ce", "level": "note", "message": {"text": "Unused endpoint: POST /logout"}, "properties": {"repobilityId": "a6a8ce4e0a2b5448", "scanner": "scanner-primary", "fingerprint": "99fc36db98c134ce", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-92cf0af164564f78", "level": "note", "message": {"text": "Unused endpoint: POST /field-login"}, "properties": {"repobilityId": "f75688508e4cfbbd", "scanner": "scanner-primary", "fingerprint": "92cf0af164564f78", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-4adba6f22dc99c78", "level": "note", "message": {"text": "Unused endpoint: POST /field-register"}, "properties": {"repobilityId": "f2ea7f87ce328dec", "scanner": "scanner-primary", "fingerprint": "4adba6f22dc99c78", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-f3634afb5d4bb2b3", "level": "note", "message": {"text": "Unused endpoint: POST /exchange-cast-token"}, "properties": {"repobilityId": "d801606f99840837", "scanner": "scanner-primary", "fingerprint": "f3634afb5d4bb2b3", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-02e20206f838a31f", "level": "note", "message": {"text": "Unused endpoint: POST /mail-help"}, "properties": {"repobilityId": "8723c7e351123cf7", "scanner": "scanner-primary", "fingerprint": "02e20206f838a31f", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-b4d6029703668a6e", "level": "note", "message": {"text": "Unused endpoint: POST /inquiry"}, "properties": {"repobilityId": "29b8767a39c3b696", "scanner": "scanner-primary", "fingerprint": "b4d6029703668a6e", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-a009857a541ee10f", "level": "note", "message": {"text": "Unused endpoint: POST /:projectId/cancel"}, "properties": {"repobilityId": "76f0409b0fa01c67", "scanner": "scanner-primary", "fingerprint": "a009857a541ee10f", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-c161bb41799c8001", "level": "note", "message": {"text": "Unused endpoint: POST /:projectId/cancel/resend"}, "properties": {"repobilityId": "4cd4d1f98d6fb2cc", "scanner": "scanner-primary", "fingerprint": "c161bb41799c8001", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-a52dcc25c9521ef8", "level": "note", "message": {"text": "Unused endpoint: POST /:projectId/restore"}, "properties": {"repobilityId": "786ad017b014a468", "scanner": "scanner-primary", "fingerprint": "a52dcc25c9521ef8", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-be4cb5e3cabcce80", "level": "note", "message": {"text": "Unused endpoint: POST /import"}, "properties": {"repobilityId": "83593e4ac77f2611", "scanner": "scanner-primary", "fingerprint": "be4cb5e3cabcce80", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-0e1d335441f7165d", "level": "note", "message": {"text": "Unused endpoint: GET /imports"}, "properties": {"repobilityId": "76b6c835980cd38a", "scanner": "scanner-primary", "fingerprint": "0e1d335441f7165d", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-6ac0762ab69fcd7e", "level": "note", "message": {"text": "Unused endpoint: GET /imports/:id/projects"}, "properties": {"repobilityId": "6171b2b862814d90", "scanner": "scanner-primary", "fingerprint": "6ac0762ab69fcd7e", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-0b8f4adbf3e396d1", "level": "note", "message": {"text": "Unused endpoint: PUT /:project_unique_url"}, "properties": {"repobilityId": "07625dca7b9f391f", "scanner": "scanner-primary", "fingerprint": "0b8f4adbf3e396d1", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-674ede333826b6ad", "level": "note", "message": {"text": "Unused endpoint: GET /:project_unique_url"}, "properties": {"repobilityId": "5425da889b2fc9f6", "scanner": "scanner-primary", "fingerprint": "674ede333826b6ad", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-b78488ca426bf6de", "level": "note", "message": {"text": "Unused endpoint: POST /approve"}, "properties": {"repobilityId": "b289808add3742ae", "scanner": "scanner-primary", "fingerprint": "b78488ca426bf6de", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-ee24e2aa1a2a8bef", "level": "note", "message": {"text": "Unused endpoint: GET /:reportId/pdf"}, "properties": {"repobilityId": "28ac89b6dbc2f52c", "scanner": "scanner-primary", "fingerprint": "ee24e2aa1a2a8bef", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-5baa8971ebe192a1", "level": "note", "message": {"text": "Unused endpoint: GET /"}, "properties": {"repobilityId": "5538efc69c9a9fdd", "scanner": "scanner-primary", "fingerprint": "5baa8971ebe192a1", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-c55647ab565775a3", "level": "note", "message": {"text": "Unused endpoint: GET /:companyId/emails"}, "properties": {"repobilityId": "89650139ba869471", "scanner": "scanner-primary", "fingerprint": "c55647ab565775a3", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-1387ee53639bff45", "level": "note", "message": {"text": "Unused endpoint: POST /:companyId/emails"}, "properties": {"repobilityId": "1f3ebe74fb4cdc07", "scanner": "scanner-primary", "fingerprint": "1387ee53639bff45", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-02dd33e8afbe6618", "level": "note", "message": {"text": "Unused endpoint: PATCH /:companyId/emails/:emailId"}, "properties": {"repobilityId": "99d468ecdfd245c1", "scanner": "scanner-primary", "fingerprint": "02dd33e8afbe6618", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-d3e6dd92b30d502c", "level": "note", "message": {"text": "Unused endpoint: DELETE /:companyId/emails/:id"}, "properties": {"repobilityId": "f6a8a6298887aabd", "scanner": "scanner-primary", "fingerprint": "d3e6dd92b30d502c", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-3d3bb7b8a4e0c87f", "level": "note", "message": {"text": "Unused endpoint: GET /google/start"}, "properties": {"repobilityId": "bd4e79f4e8e70d75", "scanner": "scanner-primary", "fingerprint": "3d3bb7b8a4e0c87f", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}]}]}