docs(06): add rate-limit middleware gap plan
This commit is contained in:
@@ -223,7 +223,7 @@ Plans:
|
||||
4. The guarded outbound fetch helper rejects a non-allow-listed host and enforces a byte cap and timeout on a user-supplied cover URL fetch (manual cover URL, Discogs cover).
|
||||
5. OpenAPI is generated from swaggo/swag annotations on handlers and `openapi-typescript` produces valid TypeScript types from it; CORS and JSON body-size limits match the PHP deployment.
|
||||
|
||||
**Plans**: 5 plans
|
||||
**Plans**: 6 plans
|
||||
|
||||
Plans:
|
||||
**Wave 1** *(parallel)*
|
||||
@@ -243,6 +243,10 @@ Plans:
|
||||
|
||||
- [x] 06-05-PLAN.md — Full unit coverage across both repos, full route-table mutual-exclusivity test, 06-SECURITY-REVIEW.md
|
||||
|
||||
**Wave 5** *(gap closure; blocked on 06-05)*
|
||||
|
||||
- [ ] 06-06-PLAN.md — Repair personal-token middleware order and prove unauthenticated request 61 is rate-limited
|
||||
|
||||
### Phase 7: User plugin and authentication
|
||||
|
||||
**Goal**: The user plugin is ported with registration, login, JWT issue/refresh, organizations, personal API tokens and the must-change-password lock. Security-load-bearing — password auth, token scope ceilings and the session lock all live here; apply the security-review agent.
|
||||
|
||||
Reference in New Issue
Block a user