docs(06): add rate-limit middleware gap plan

This commit is contained in:
Jakub Zych
2026-09-19 23:07:43 +02:00
parent cb34de4203
commit 2f90fef830
2 changed files with 164 additions and 1 deletions

View File

@@ -223,7 +223,7 @@ Plans:
4. The guarded outbound fetch helper rejects a non-allow-listed host and enforces a byte cap and timeout on a user-supplied cover URL fetch (manual cover URL, Discogs cover).
5. OpenAPI is generated from swaggo/swag annotations on handlers and `openapi-typescript` produces valid TypeScript types from it; CORS and JSON body-size limits match the PHP deployment.
**Plans**: 5 plans
**Plans**: 6 plans
Plans:
**Wave 1** *(parallel)*
@@ -243,6 +243,10 @@ Plans:
- [x] 06-05-PLAN.md — Full unit coverage across both repos, full route-table mutual-exclusivity test, 06-SECURITY-REVIEW.md
**Wave 5** *(gap closure; blocked on 06-05)*
- [ ] 06-06-PLAN.md — Repair personal-token middleware order and prove unauthenticated request 61 is rate-limited
### Phase 7: User plugin and authentication
**Goal**: The user plugin is ported with registration, login, JWT issue/refresh, organizations, personal API tokens and the must-change-password lock. Security-load-bearing — password auth, token scope ceilings and the session lock all live here; apply the security-review agent.