docs(06-07): update plan tracking

This commit is contained in:
Jakub Zych
2026-09-20 17:11:59 +02:00
parent bc43e9eabd
commit 3601a0ab09
3 changed files with 17 additions and 14 deletions

View File

@@ -53,7 +53,7 @@ Requirements for v1 (the Płytarium port). Each maps to roadmap phases. "User" b
- [x] **HTTP-01**: Plugins register route groups on net/http ServeMux with typed params and regex constraints; unknown and malformed ids both return 404 on ownership-scoped resources
- [x] **HTTP-02**: Plugins register named middleware that other plugins reference by name; the pipeline order is recover, CORS, locale, auth group, must-change-password, org context, rate limit, handler
- [x] **HTTP-03**: Three mutually exclusive auth groups share the same handlers with different route subsets: JWT under /_fonoteka/api/v1, personal scoped token under /api/v1/fonoteka, and public groups (onboarding, public/{token}, public-wishlist/{token}, invitation inspection)
- [ ] **HTTP-04**: A rate limiter supports named buckets keyed by a resolver (token id, IP, route param), stacking two limiters on one route, and ports Płytarium's five named buckets and inline throttles 1:1
- [x] **HTTP-04**: A rate limiter supports named buckets keyed by a resolver (token id, IP, route param), stacking two limiters on one route, and ports Płytarium's five named buckets and inline throttles 1:1
- [x] **HTTP-05**: An auth guard registry lets plugins add guards (JWT, personal token, OAuth bearer) that all resolve to the same current-user accessor
- [ ] **HTTP-06**: Response conventions are preserved: empty arrays serialize as [], timestamps as +00:00, tri-state booleans keep null, conditional keys are omitted not nulled, and no blanket envelope or error middleware wraps OAuth routes
- [ ] **HTTP-07**: A guarded outbound fetch helper enforces host allow-lists, byte caps and timeouts for user-supplied URLs (manual cover URL, Discogs cover)

View File

@@ -249,7 +249,7 @@ Plans:
**Wave 6** *(gap closure; parallel, blocked on 06-06)*
- [ ] 06-07-PLAN.md — Make limiter admission atomic and remove attacker-controlled Host from inline keys
- [x] 06-07-PLAN.md — Make limiter admission atomic and remove attacker-controlled Host from inline keys
- [ ] 06-08-PLAN.md — Reject private IPv4 embedded in NAT64 and 6to4 dial addresses
- [ ] 06-09-PLAN.md — Buffer route responses so partial-write panics yield clean raw/house 500s
- [ ] 06-10-PLAN.md — Restore exact no-newline InvScope 401/403 wire bodies
@@ -425,7 +425,7 @@ Phases execute in numeric order: 1 → 2 → 3 → 4 → 5 → 6 → 7 → 8 →
| 3. First vertical slice — genres end to end | 4/4 | Complete | 2026-09-17 |
| 4. CLI scaffolding, i18n and mail | 4/4 | Complete | 2026-09-18 |
| 5. Data layer full fidelity | 6/6 | Complete | 2026-09-18 |
| 6. HTTP routing, auth groups and rate limiting | 6/6 | Gaps found | - |
| 6. HTTP routing, auth groups and rate limiting | 7/11 | In Progress| |
| 7. User plugin and authentication | 0/TBD | Not started | - |
| 8. OAuth2.1 authorization server | 0/TBD | Not started | - |
| 9. Backend admin authentication and schema pipeline | 0/TBD | Not started | - |

View File

@@ -3,15 +3,15 @@ gsd_state_version: 1.0
milestone: v1.0
milestone_name: milestone
status: executing
stopped_at: Completed 06-06-PLAN.md
last_updated: "2026-09-20T14:14:04.240Z"
last_activity: 2026-09-20 -- Phase 6 planning complete
stopped_at: Completed 06-07-PLAN.md
last_updated: "2026-09-20T15:11:34.217Z"
last_activity: 2026-09-20
progress:
total_phases: 15
completed_phases: 5
total_plans: 34
completed_plans: 29
percent: 33
completed_plans: 30
percent: 88
---
# Project State
@@ -26,17 +26,17 @@ See: .planning/PROJECT.md (updated 2026-09-16)
## Current Position
Phase: 06 (http-routing-auth-groups-and-rate-limiting) — EXECUTING
Plan: 6 of 6
Plan: 2 of 11
Status: Ready to execute
Last activity: 2026-09-20 -- Phase 6 planning complete
Last activity: 2026-09-20
Progress: [██████████] 100%
Progress: [█████████░] 88%
## Performance Metrics
**Velocity:**
- Total plans completed: 29
- Total plans completed: 30
- Average duration: 21 min
- Total execution time: 104 min
@@ -75,6 +75,7 @@ Progress: [██████████] 100%
| Phase 06 P03 | 20 min | 3 tasks | 24 files |
| Phase 06 P05 | 13 min | 3 tasks | 13 files |
| Phase 06 P06 | 1h 29m | 2 tasks | 3 files |
| Phase 06 P07 | 12 min | 1 tasks | 4 files |
## Accumulated Context
@@ -174,6 +175,8 @@ Recent decisions affecting current work:
- [Phase 06]: PublicOnlyMode any-host-when-public is proven via skipReservedCheck httptest, not a live public IP dial — Unit tests must not require outbound network
- [Phase 06]: Keep inv_token outermost so valid credentials populate bouncer.Credential before the limiter selects tok:<id>. — The named bucket must retain per-token isolation for valid credentials instead of collapsing them onto the IP fallback.
- [Phase 06]: Place throttle:fonoteka-api-token before inv.scope:read in the personal-token middleware declaration. — Missing and invalid credentials must consume the 60/minute per-IP deny-path budget before InvScope returns its PHP-compatible 401 response.
- [Phase 06]: Replace the split limiter store protocol with one atomic Attempt operation. — Expiry, threshold comparison, admitted increment, and retry duration must share one mutex critical section so concurrent callers cannot bypass Max.
- [Phase 06]: Use one inline:domainless namespace plus trusted-proxy ClientIP for every anonymous inline throttle. — Host and inline throttle text must not let anonymous callers rotate rate-limit buckets; authenticated requests retain u:<principal id> isolation.
### Pending Todos
@@ -195,6 +198,6 @@ Items acknowledged and carried forward from previous milestone close:
## Session Continuity
Last session: 2026-09-20T11:32:06.433Z
Stopped at: Completed 06-06-PLAN.md
Last session: 2026-09-20T15:11:34.184Z
Stopped at: Completed 06-07-PLAN.md
Resume file: None