docs(12.1): verification, UAT, and code-review close-out

This commit is contained in:
Jakub Zych
2026-10-05 16:53:16 +02:00
parent 4e4ce40dbb
commit 30336e44c6
4 changed files with 166 additions and 0 deletions

View File

@@ -0,0 +1,13 @@
---
phase: 12.1
review: 12.1-REVIEW.md
titles: json
findings: []
open: 0
total: 0
recorded: 2026-10-05T15:10:00Z
---
# Phase 12.1: Code Review Disposition
Quick review of the plan-05 production surface. No findings. Owner decisions FD-1 to FD-5 stay in `12.1-SECURITY-REVIEW.md`, not here.

View File

@@ -0,0 +1,47 @@
---
phase: 12.1-user-plugin-admin-screens
reviewed: 2026-10-05T15:10:00Z
depth: quick
files_reviewed: 6
files_reviewed_list:
- ../fonoteka.go/plugins/golem15/user/classes/admin_actions.go
- ../fonoteka.go/plugins/golem15/user/classes/privileged.go
- ../fonoteka.go/plugins/golem15/user/models/user.go
- ../fonoteka.go/plugins/golem15/user/controllers/users_admin_controller.go
- scripts/check-phase12.1.sh
- .planning/phases/12.1-user-plugin-admin-screens/12.1-SECURITY-REVIEW.md
findings:
critical: 0
warning: 0
info: 0
total: 0
status: clean
---
# Phase 12.1: Code Review Report
**Reviewed:** 2026-10-05T15:10:00Z
**Depth:** quick (resume close-out; gsd-code-reviewer was not spawned — typed GSD agents are unavailable in this runtime)
**Files Reviewed:** 6 production/guard files that plan 05 actually changed or relies on
**Status:** clean
Plan 05 is tests, the gate, docs, and two plugin production fixes already recorded in `12.1-SECURITY-REVIEW.md` (FX-1, FX-2). Framework `modules`, `cmd`, and `admin/src` did not change after `v0.1.3`. This pass read the two fixes and the D-30 guards instead of re-reading every test file.
## Production fixes (already gated)
| Fix | File | What was checked | Verdict |
|-----|------|------------------|---------|
| FX-1 | `classes/admin_actions.go` `fresh` | `NewDB` session, `Clauses()` first, then a second `NewDB` session so `IsPrivilegedMember` cannot inherit caller WHERE clauses | Correct; pinned by RC-25 |
| FX-2 | `models/user.go` `FilterScope` / `groupFilterID` | non-numeric filter values become `WHERE 1 = 0` instead of a 500 | Correct; pinned by RC-26 |
## D-30 guards
`guardCredentials` is called from `FormBeforeUpdate`; `guardPrivilegedMember` from `FormBeforeDelete`. Removal rows RC-23 and RC-24 name those exact calls. No new issue.
## Not treated as review findings
FD-1 to FD-5 in the security review are owner decisions (unlink role, lock vs manager, boolean JSON, host JWT secret, deactivate/ban). They are not defects introduced by plan 05.
## Findings
None.

View File

@@ -0,0 +1,36 @@
---
status: testing
phase: 12.1-user-plugin-admin-screens
source: [12.1-VERIFICATION.md]
started: 2026-10-05T15:10:00Z
updated: 2026-10-05T15:10:00Z
---
## Current Test
number: 1
name: Walk Users, User Groups and Organisations in light and dark mode as an admin holding golem15.users.access_users and golem15.users.access_groups but not golem15.users.manage_privileged_groups
expected: |
Screens match the UI-SPEC (row-state badges with text, one status callout on preview, record actions before the primary edit button, segmented permission control, locked admin group with its note). Filter and search Users; open a banned and a deactivated user's preview; run Activate, Unban and a bulk Ban; create a user with an invitation; open Permissions; try to add the admin group; edit a group's permissions; add and remove an organisation member.
awaiting: user response
## Tests
### 1. Walk Users, User Groups and Organisations in light and dark mode as an admin holding golem15.users.access_users and golem15.users.access_groups but not golem15.users.manage_privileged_groups
expected: Screens match the UI-SPEC (row-state badges with text, one status callout on preview, record actions before the primary edit button, segmented permission control, locked admin group with its note). Filter and search Users; open a banned and a deactivated user's preview; run Activate, Unban and a bulk Ban; create a user with an invitation; open Permissions; try to add the admin group; edit a group's permissions; add and remove an organisation member.
result: [pending]
### 2. D-30 on a user in the admin group: name-only save; email save; password save; Delete; bulk delete with another user
expected: Name-only save succeeds. Email and password each show the forbidden banner with the marked field, keep what was typed, save nothing. Delete and bulk delete each show a danger toast and delete nobody.
result: [pending]
## Summary
total: 2
passed: 0
issues: 0
pending: 2
skipped: 0
blocked: 0
## Gaps

View File

@@ -0,0 +1,70 @@
---
phase: 12.1-user-plugin-admin-screens
verified: 2026-10-05T15:10:00Z
status: human_needed
score: 5/5 roadmap success criteria verified against code; SC-5 gate --all recorded PASS on production HEAD 93f0171
overrides_applied: 0
human_verification:
- test: "Walk Users, User Groups and Organisations in light and dark mode as an admin holding golem15.users.access_users and golem15.users.access_groups but not golem15.users.manage_privileged_groups"
expected: "Screens match the UI-SPEC (row-state badges with text, one status callout on preview, record actions before the primary edit button, segmented permission control, locked admin group with its note). Filter and search Users; open a banned and a deactivated user's preview; run Activate, Unban and a bulk Ban; create a user with an invitation; open Permissions; try to add the admin group; edit a group's permissions; add and remove an organisation member."
why_human: "Visual fit with the design system in both themes cannot be asserted by unit tests (plan 12.1-05 Task 3 human-check)."
- test: "D-30 on a user in the admin group: name-only save; email save; password save; Delete; bulk delete with another user"
expected: "Name-only save succeeds. Email and password each show the forbidden banner with the marked field, keep what was typed, save nothing. Delete and bulk delete each show a danger toast and delete nobody."
why_human: "End-to-end feel of the forbidden banner and toasts is a browser check."
covered_files:
- ".planning/phases/12.1-user-plugin-admin-screens/12.1-01-PLAN.md"
- ".planning/phases/12.1-user-plugin-admin-screens/12.1-01-SUMMARY.md"
- ".planning/phases/12.1-user-plugin-admin-screens/12.1-02-PLAN.md"
- ".planning/phases/12.1-user-plugin-admin-screens/12.1-02-SUMMARY.md"
- ".planning/phases/12.1-user-plugin-admin-screens/12.1-03-PLAN.md"
- ".planning/phases/12.1-user-plugin-admin-screens/12.1-03-SUMMARY.md"
- ".planning/phases/12.1-user-plugin-admin-screens/12.1-04-PLAN.md"
- ".planning/phases/12.1-user-plugin-admin-screens/12.1-04-SUMMARY.md"
- ".planning/phases/12.1-user-plugin-admin-screens/12.1-05-PLAN.md"
- ".planning/phases/12.1-user-plugin-admin-screens/12.1-05-SUMMARY.md"
- ".planning/phases/12.1-user-plugin-admin-screens/12.1-SECURITY-REVIEW.md"
- ".planning/phases/12.1-user-plugin-admin-screens/12.1-VALIDATION.md"
- "scripts/check-phase12.1.sh"
- "modules/cabana/phase121_threats_test.go"
- "modules/cabana/crud.go"
- "modules/cabana/actions.go"
- "modules/cabana/http.go"
---
# Phase 12.1: User plugin admin screens Verification Report
**Phase Goal:** Backend admins manage frontend users, user groups and organisations in the admin SPA without SQL, so the PHP backend is not needed for user administration after cutover. The Users, User Groups and Organisations screens of the PHP user plugin are ported to `golem15.user`, driven by its `fields.yaml`/`columns.yaml`.
**Verified:** 2026-10-05T15:10:00Z
**Status:** human_needed
**Re-verification:** No, initial verification
Plan 05 production commits were already on `master` (`c076b4c`..`93f0171`); this run only wrote the missing SUMMARY and the phase-gate artifacts. The verifier checked code and ran the fast gate stages. It did not re-run the 12-minute `--all` (already PASS on the same production HEAD).
## Goal Achievement
| # | Success criterion | Status | Evidence |
| --- | --- | --- | --- |
| SC1 | Users, User Groups and Organisations each have a list and a create/update form from PHP YAML, in admin navigation, permission-gated | ✓ VERIFIED | Controllers `users_admin_controller.go`, `usergroups_admin_controller.go`, `organisations_admin_controller.go`; YAML under `models/user`, `usergroup`, `organisation`; three side items in `admin_navigation.go` (`users`, `usergroups`, `organisations`). Plugin subtest `T-12.1-18` requires the matching permission on every route |
| SC2 | A user's groups via a relation field; an organisation's members via a relation manager | ✓ VERIFIED | `AdminRelationLocks` on the users controller (line 380); `controllers/organisations/config_relation.yaml`; plugin tests `TestAdminUserGroupsField`, `TestAdminOrganisationMembers` |
| SC3 | activate, unban, unsuspend, delete and list bulk actions as in PHP Users.php | ✓ VERIFIED | Plugin tests `TestAdminUserActions`, `TestAdminUserForceDelete`; threat subtests T-12.1-23, T-12.1-30, T-12.1-39 |
| SC4 | T-12-18 revisited: the admin form is the first writer of `users_groups`; privileged membership needs the extra permission | ✓ VERIFIED | `AdminRelationLocks` + `checkRelationLocks`; plugin `T-12.1-28` comment cites T-12-18 by that id; `T-12.1-30` asserts no other writer; removal RC-19 |
| SC5 | The new code has unit tests, delivered in the last plan | ✓ VERIFIED | `TestPhase121Threats` in cabana (T-12.1-01..15) and plugin (18-25, 27-31, 34, 38, 39). Coverage recorded: pact 100%, cabana 86.6%, plugin packages 83–95.7%. `scripts/check-phase12.1.sh --all` PASS 2026-10-05. This session: `--self-test`, `--evidence` (41 threats, 27 removal rows), `--hygiene` all exit 0 |
## Artifacts
| Artifact | Status |
| --- | --- |
| Five plan SUMMARYs | ✓ |
| `scripts/check-phase12.1.sh` executable | ✓ |
| `12.1-SECURITY-REVIEW.md` threats_open 0 | ✓ (`--evidence` this session) |
| `12.1-VALIDATION.md` nyquist_compliant true | ✓ no TBD row |
| `12.1-REVIEW.md` + disposition | ✓ 0 findings |
| Plugin push | pending: `v0.1.3` is not on origin |
## Gaps
None that falsify a success criterion.
Status is `human_needed`, not `passed`, because the plan-05 visual walk and D-30 browser check are still outstanding, and because sm-user-plugin is unpublished until the framework tag is on origin. Those are not code gaps.
_Verifier: orchestrator inline on resume close-out. Did not spawn gsd-verifier (typed GSD agents unavailable). Did not re-run `--all` or `--removal`._