Security and trust-boundary notes for issuetracker.
reporter_user_id and reporter_email are stripped from client input and re-injected from the resolved server-side identity — a request body can never spoof who reported or commented on an issue.
Status transitions are validated against an explicit allow-list on the server; a client can request a transition, but only a legal one is ever applied.
Soft delete keeps historical data — comments, attachments, audit trail — intact and queryable via all_objects, while the default manager keeps deleted records out of every normal query.
The API ships permissive by default (AllowAny) so it's usable out of the box — DEFAULT_PERMISSION_CLASSES is a host-project setting specifically so production deployments are expected to tighten it.
Create is open to anonymous callers only when ALLOW_ANONYMOUS_REPORTING is on, and even then a reporter_email is mandatory — update and delete always require an authenticated identity.