# Gaps and inconsistencies (cross-cutting audit) **Last reviewed:** 2026-03-23 Most previously tracked gaps are **implemented**. This file lists only **long-horizon** or **compliance** items. --- ## Implemented (recent) | Topic | Where | |-------|--------| | Shared OkHttp + Retrofit refresh | `SyncRetrofitHolder`, `NetworkModule`, `BackendSyncAPI` / `BackendPullAPI` lambdas | | Non-blocking hosted config | `ClientConfigRefreshCoordinator.scheduleNonBlockingInitialLoad` | | Browser VPN policy flag | `BuildConfig.SMOA_BROWSER_VPN_ENFORCED` / `-Psmoa.browser.vpnEnforced=true`, `VPNManager.setBrowserVpnEnforced` | | Room credential cache | `credential_cache` + `CredentialCacheDatabaseModule` | | OpenAPI drift process | `docs/development/OPENAPI-SYNCHRONIZATION.md`, `scripts/export-openapi-local.sh` | --- ## Remaining (long-term) | Topic | Notes | |-------|--------| | **Strong multi-tenant isolation** | API key + `X-Unit` are not RLS; see `docs/security/TENANT-THREAT-MODEL.md`. | | **AAMVA / ICAO production compliance** | Encoders need jurisdiction QA and official test vectors. | | **Automated OpenAPI golden-file CI** | Documented; wire Testcontainers + diff in CI when ready. | | **Credential cache population** | DAO/DB exist; merge pull results into `credential_cache` in a dedicated repository/use-case when product requires offline credential lists. | --- ## Related - `docs/reference/IDENTITY-TEMPLATE-ALIGNMENT.md` - `docs/schemas/` - `backend/docs/BACKEND-GAPS-AND-ROADMAP.md`