docs(09): create phase plan
This commit is contained in:
@@ -1,8 +1,8 @@
|
||||
---
|
||||
phase: "09"
|
||||
slug: "backend-admin-authentication-and-schema-pipeline"
|
||||
status: draft
|
||||
nyquist_compliant: false
|
||||
status: approved
|
||||
nyquist_compliant: true
|
||||
wave_0_complete: false
|
||||
created: "2026-09-24"
|
||||
---
|
||||
@@ -38,12 +38,13 @@ created: "2026-09-24"
|
||||
|
||||
| Task ID | Plan | Wave | Requirement | Threat Ref | Secure Behavior | Test Type | Automated Command | File Exists | Status |
|
||||
|---------|------|------|-------------|------------|-----------------|-----------|-------------------|-------------|--------|
|
||||
| 09-W0-01 | TBD | TBD | AUTH-08 | T-09-01 | Backend tokens require the backend audience and secret; frontend/backend token crossover, empty secret, blacklist, and inactive/deleted principals fail closed | unit + assembled integration | `go test ./bouncer ./... -run 'Test.*(Admin|Backend|Audience|Guard)' -count=1` | ❌ W0 | ⬜ pending |
|
||||
| 09-W0-02 | TBD | TBD | ADMIN-01 | T-09-02 | Strict YAML parsing rejects unknown keys, unsupported field types, and invalid option providers before serving requests | unit + golden fixture | `go test ./pact/... -run 'Test.*(Field|Form|Schema|YAML)' -count=1` | ❌ W0 | ⬜ pending |
|
||||
| 09-W0-03 | TBD | TBD | ADMIN-02 | T-09-03 | Search, sort, relation, and renderer identifiers come only from compiled allowlists | unit + integration | `go test ./pact/... -run 'Test.*(Column|List|Search|Sort)' -count=1` | ❌ W0 | ⬜ pending |
|
||||
| 09-W0-04 | TBD | TBD | ADMIN-03 | T-09-04 | Relation linked/candidate queries are owner-scoped; link/unlink validates plugin-owned pivot fields | PostgreSQL integration | `(cd ../fonoteka.go && go test ./plugins/golem15/fonoteka/... -run 'Test.*Relation' -count=1)` | ❌ W0 | ⬜ pending |
|
||||
| 09-W0-05 | TBD | TBD | ADMIN-04 | T-09-05 | CRUD hooks run in order, row scope applies before read/write, and bulk delete invokes each record lifecycle | PostgreSQL integration | `(cd ../fonoteka.go && go test ./plugins/golem15/fonoteka/... -run 'Test.*(Admin|CRUD|Bulk|Lifecycle)' -count=1)` | ❌ W0 | ⬜ pending |
|
||||
| 09-W0-06 | TBD | TBD | ADMIN-05 | T-09-06 | Settings read/write is permission-gated, singleton-scoped, fillable-only, and validated before persistence | PostgreSQL integration | `(cd ../fonoteka.go && go test ./plugins/golem15/fonoteka/... -run 'Test.*Settings' -count=1)` | ❌ W0 | ⬜ pending |
|
||||
| 09-01-T2 | 09-01 | 1 | AUTH-08 | T-09-01, T-09-02 | Backend/frontend token crossover and permission-order denial both fail before schema/database work | unit + assembled integration | `go test ./bouncer ./cabana -run 'Test.*(Audience\|Permission\|AuthorizationOrder\|Secret)' -count=1 && (cd ../fonoteka.go && go test ./plugins/golem15/fonoteka -run '^TestAdminTracer(AuthBoundary\|PermissionBoundary)$' -count=1)` | 🧭 planned | ⬜ pending |
|
||||
| 09-03-T1 | 09-03 | 3 | ADMIN-01 | T-09-05 | Strict schema compilation covers every field type and rejects unknown keys/types/partials/providers with empty/single/order/type semantics | unit + golden contract | `go test ./cabana -run '^TestFormSchema(Compile\|Empty\|Single\|Ordering\|Rejects)' -count=1` | 🧭 planned | ⬜ pending |
|
||||
| 09-04-T3 | 09-04 | 4 | ADMIN-02 | T-09-07, T-09-08 | Search/sort/filter/scope selectors are compiled allowlists, values are bound, and adjacent pages are deterministic | unit + query integration | `go test ./cabana -run '^TestListQuery(Contract\|Empty\|Single\|Adjacent\|Filters\|RejectsInjection)$' -count=1` | 🧭 planned | ⬜ pending |
|
||||
| 09-10-T3 | 09-10 | 7 | ADMIN-03 | T-09-16, T-09-17 | Relation permission/scope and plugin-owned pivot metadata protect idempotent link/unlink against forged/cross-scope input | PostgreSQL assembled integration | `(cd ../fonoteka.go && go test ./plugins/golem15/fonoteka -run '^TestCollectionsAdmin(RelationPermissions\|Link\|Unlink\|Idempotent\|ForgedPivot\|CrossScope\|Concurrent)$' -count=1)` | 🧭 planned | ⬜ pending |
|
||||
| 09-05-T3 | 09-05 | 5 | ADMIN-04 | T-09-09, T-09-10 | Bulk CRUD normalizes duplicates, rejects empty selection, locks stable order, runs hooks, rolls back atomically, and is replay-safe | PostgreSQL integration | `go test ./cabana -run '^TestBulkDelete(Empty\|Duplicates\|Order\|Idempotent\|Rollback\|Concurrent)$' -count=1` | 🧭 planned | ⬜ pending |
|
||||
| 09-11-T3 | 09-11 | 8 | ADMIN-05 | T-09-18, T-09-19 | Settings schema/read/write is permission-first, singleton-scoped, fillable-only, validated, rollback-safe, and explicit for missing/create/repeat | PostgreSQL assembled integration | `(cd ../fonoteka.go && go test ./plugins/golem15/fonoteka -run '^TestAdminSettings(Schema\|PermissionOrder\|MissingRead\|Create\|IdempotentUpdate\|Projection\|Validation\|Rollback)$' -count=1)` | 🧭 planned | ⬜ pending |
|
||||
| 09-12-T2 | 09-12 | 9 | AUTH-08, ADMIN-01, ADMIN-02, ADMIN-03, ADMIN-04, ADMIN-05 | T-09-20, T-09-21 | Fail-closed full route/PostgreSQL/OpenAPI gate detects skipped stages, zero tests, contract drift, and incomplete assembled behavior | phase gate | `scripts/check-phase9.sh --self-test && scripts/check-phase9.sh --postgres && scripts/check-phase9.sh --openapi` | 🧭 planned | ⬜ pending |
|
||||
|
||||
*Status: ⬜ pending · ✅ green · ❌ red · ⚠️ flaky*
|
||||
|
||||
@@ -51,11 +52,11 @@ created: "2026-09-24"
|
||||
|
||||
## Wave 0 Requirements
|
||||
|
||||
- [ ] Framework schema compiler tests with golden JSON and malformed/unknown-key YAML fixtures.
|
||||
- [ ] Backend guard tests for empty secret, wrong audience, frontend/backend token swapping, blacklist, and inactive/deleted users.
|
||||
- [ ] Assembled raw-route authorization matrix covering every admin endpoint category and wildcard/superuser behavior.
|
||||
- [ ] Real-PostgreSQL tests for bulk-delete callbacks, relation pivot fields, candidate scoping, owner exclusion, and settings upsert.
|
||||
- [ ] Focused fixture and test naming finalized by the planner so every PLAN task maps to an executable command above.
|
||||
- [x] Framework schema compiler tests are assigned to 09-03 and expanded by controller plans.
|
||||
- [x] Backend guard tests are assigned to 09-01/09-02 and swept by 09-12.
|
||||
- [x] The assembled raw-route authorization matrix is assigned to 09-12.
|
||||
- [x] Real-PostgreSQL bulk, relation, scoping, settings, migration, rollback, and concurrency tests are assigned to 09-05/09-10/09-11/09-12.
|
||||
- [x] Focused test names and commands are concrete in every PLAN task; no separate pre-execution scaffold is required.
|
||||
|
||||
---
|
||||
|
||||
@@ -67,11 +68,11 @@ All Phase 9 backend behaviors are expected to have automated verification. Phase
|
||||
|
||||
## Validation Sign-Off
|
||||
|
||||
- [ ] All tasks have `<automated>` verification or Wave 0 dependencies.
|
||||
- [ ] Sampling continuity: no three consecutive tasks lack automated verification.
|
||||
- [ ] Wave 0 covers all missing references.
|
||||
- [ ] No watch-mode flags appear in validation commands.
|
||||
- [ ] Task-level feedback latency is under 60 seconds.
|
||||
- [ ] `nyquist_compliant: true` is set after final plan/task IDs and commands are validated.
|
||||
- [x] All tasks have `<automated>` verification and an immediate observable failure direction.
|
||||
- [x] Sampling continuity: every task has automated verification.
|
||||
- [x] All previously missing references are assigned to owning TDD tasks and the final gate.
|
||||
- [x] No watch-mode flags appear in validation commands.
|
||||
- [x] Focused task-level commands target the 60-second feedback budget; multi-minute PostgreSQL/full-suite checks are phase gates.
|
||||
- [x] `nyquist_compliant: true` is set after final plan/task IDs and commands are validated.
|
||||
|
||||
**Approval:** pending
|
||||
**Approval:** approved for execution; implementation results remain pending.
|
||||
|
||||
Reference in New Issue
Block a user