docs(state): record 07-08 completion and tracking
All eight Phase 7 plans have summaries. Avatar bucket publish is the UAT gap close; phase verification still has to run. Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
@@ -272,7 +272,7 @@ Plans:
|
|||||||
3. A personal API token is created with a read|write|ai scope ceiling, listed, and revoked; a scope-checking middleware rejects an out-of-scope request.
|
3. A personal API token is created with a read|write|ai scope ceiling, listed, and revoked; a scope-checking middleware rejects an out-of-scope request.
|
||||||
4. The must-change-password flag returns 423 on the authenticated surface except the locale and password-change routes, and locale resolves per request from the user's persisted `preferred_locale` with header fallback even while the lock is active.
|
4. The must-change-password flag returns 423 on the authenticated surface except the locale and password-change routes, and locale resolves per request from the user's persisted `preferred_locale` with header fallback even while the lock is active.
|
||||||
|
|
||||||
**Plans**: 7 plans
|
**Plans**: 8 plans
|
||||||
|
|
||||||
Plans:
|
Plans:
|
||||||
**Wave 1**
|
**Wave 1**
|
||||||
@@ -300,6 +300,10 @@ Plans:
|
|||||||
|
|
||||||
- [x] 07-07-PLAN.md — Re-record the logout blacklist under a persistent PHP cache, fix the already-activated HTML-500 quirk, and flip all 15 /_user/api/v1 routes plus both nuxt flows to ported
|
- [x] 07-07-PLAN.md — Re-record the logout blacklist under a persistent PHP cache, fix the already-activated HTML-500 quirk, and flip all 15 /_user/api/v1 routes plus both nuxt flows to ported
|
||||||
|
|
||||||
|
**Wave 7** *(gap closure; blocked on 07-07 UAT)*
|
||||||
|
|
||||||
|
- [x] 07-08-PLAN.md — Publish the uploads bucket on serve and Handler so assembled avatar POST is 200
|
||||||
|
|
||||||
### Phase 8: OAuth2.1 authorization server
|
### Phase 8: OAuth2.1 authorization server
|
||||||
|
|
||||||
**Goal**: An RFC 8414/6749/7591-compliant OAuth2.1 server on zitadel/oidc serves fonoteka-mcp and the ChatGPT connector unchanged, including exact `WWW-Authenticate` and protected-resource-metadata headers. Security-load-bearing — bearer tokens, PKCE and constant-time secret comparison all live here; apply the security-review agent.
|
**Goal**: An RFC 8414/6749/7591-compliant OAuth2.1 server on zitadel/oidc serves fonoteka-mcp and the ChatGPT connector unchanged, including exact `WWW-Authenticate` and protected-resource-metadata headers. Security-load-bearing — bearer tokens, PKCE and constant-time secret comparison all live here; apply the security-review agent.
|
||||||
@@ -452,7 +456,7 @@ Phases execute in numeric order: 1 → 2 → 3 → 4 → 5 → 6 → 7 → 8 →
|
|||||||
| 4. CLI scaffolding, i18n and mail | 4/4 | Complete | 2026-09-18 |
|
| 4. CLI scaffolding, i18n and mail | 4/4 | Complete | 2026-09-18 |
|
||||||
| 5. Data layer full fidelity | 6/6 | Complete | 2026-09-18 |
|
| 5. Data layer full fidelity | 6/6 | Complete | 2026-09-18 |
|
||||||
| 6. HTTP routing, auth groups and rate limiting | 14/14 | Complete | 2026-09-21 |
|
| 6. HTTP routing, auth groups and rate limiting | 14/14 | Complete | 2026-09-21 |
|
||||||
| 7. User plugin and authentication | 7/7 | Complete | 2026-09-22 |
|
| 7. User plugin and authentication | 8/8 | Complete | 2026-09-23 |
|
||||||
| 8. OAuth2.1 authorization server | 0/TBD | Not started | - |
|
| 8. OAuth2.1 authorization server | 0/TBD | Not started | - |
|
||||||
| 9. Backend admin authentication and schema pipeline | 0/TBD | Not started | - |
|
| 9. Backend admin authentication and schema pipeline | 0/TBD | Not started | - |
|
||||||
| 10. Admin Vue SPA | 0/TBD | Not started | - |
|
| 10. Admin Vue SPA | 0/TBD | Not started | - |
|
||||||
|
|||||||
@@ -3,14 +3,14 @@ gsd_state_version: 1.0
|
|||||||
milestone: v1.0
|
milestone: v1.0
|
||||||
milestone_name: milestone
|
milestone_name: milestone
|
||||||
status: verifying
|
status: verifying
|
||||||
stopped_at: Phase 9 context gathered
|
stopped_at: Completed 07-08-PLAN.md
|
||||||
last_updated: "2026-09-23T08:24:37.424Z"
|
last_updated: "2026-09-23T08:51:11.470Z"
|
||||||
last_activity: 2026-09-22 -- Completed 07-07-PLAN.md
|
last_activity: 2026-09-23 -- Completed 07-08-PLAN.md
|
||||||
progress:
|
progress:
|
||||||
total_phases: 15
|
total_phases: 15
|
||||||
completed_phases: 7
|
completed_phases: 7
|
||||||
total_plans: 44
|
total_plans: 45
|
||||||
completed_plans: 44
|
completed_plans: 45
|
||||||
percent: 47
|
percent: 47
|
||||||
---
|
---
|
||||||
|
|
||||||
@@ -25,10 +25,10 @@ See: .planning/PROJECT.md (updated 2026-09-16)
|
|||||||
|
|
||||||
## Current Position
|
## Current Position
|
||||||
|
|
||||||
Phase: 07 (user-plugin-and-authentication) — PLANS COMPLETE
|
Phase: 07 (user-plugin-and-authentication) — EXECUTING
|
||||||
Plan: 7 of 7
|
Plan: 8 of 8
|
||||||
Status: All 7 plans have SUMMARYs. Ready for `$gsd-verify-work 7` — do not auto-advance.
|
Status: All 8 plans have SUMMARYs. Ready for phase verification — do not auto-advance.
|
||||||
Last activity: 2026-09-22 -- Completed 07-07-PLAN.md
|
Last activity: 2026-09-23 -- Completed 07-08-PLAN.md
|
||||||
|
|
||||||
Progress: [██████████] 100%
|
Progress: [██████████] 100%
|
||||||
|
|
||||||
@@ -89,6 +89,7 @@ Progress: [██████████] 100%
|
|||||||
| Phase 07 P06 | 40 min | 3 tasks | 8 files |
|
| Phase 07 P06 | 40 min | 3 tasks | 8 files |
|
||||||
| Phase 07 P07 | 3h 15m | 3 tasks | 28 files |
|
| Phase 07 P07 | 3h 15m | 3 tasks | 28 files |
|
||||||
| Phase 07-user-plugin-and-authentication P07 | 3h 15m | 3 tasks | 28 files |
|
| Phase 07-user-plugin-and-authentication P07 | 3h 15m | 3 tasks | 28 files |
|
||||||
|
| Phase 07-user-plugin-and-authentication P08 | 25min | 3 tasks | 6 files |
|
||||||
|
|
||||||
## Accumulated Context
|
## Accumulated Context
|
||||||
|
|
||||||
@@ -203,6 +204,8 @@ Recent decisions affecting current work:
|
|||||||
- [Phase 07]: user_throttle and jwt_blacklist are allowed schema diffs — The frozen PHP snapshot predates the user plugin. jwt_blacklist is also the production PHP path: logout calls JWTAuth::invalidate(true) and blacklist_enabled defaults true. The earlier "PHP does not blacklist" note was a harness artifact of CACHE_DRIVER=array.
|
- [Phase 07]: user_throttle and jwt_blacklist are allowed schema diffs — The frozen PHP snapshot predates the user plugin. jwt_blacklist is also the production PHP path: logout calls JWTAuth::invalidate(true) and blacklist_enabled defaults true. The earlier "PHP does not blacklist" note was a harness artifact of CACHE_DRIVER=array.
|
||||||
- [Phase 07]: Fetch after logout stays 401 in Go — Re-recorded PHP with file cache still returned 200 on a reused token (show_black_list_exception default 0). That case is kept on disk but is not a ported corpus case.
|
- [Phase 07]: Fetch after logout stays 401 in Go — Re-recorded PHP with file cache still returned 200 on a reused token (show_black_list_exception default 0). That case is kept on disk but is not a ported corpus case.
|
||||||
- [Phase 07]: Already-activated activate/activate-by-code is Winter 500 HTML — User::attemptActivation throws when the user is already active; Go keys that path on IsAlreadyActivated, not wrong-code.
|
- [Phase 07]: Already-activated activate/activate-by-code is Winter 500 HTML — User::attemptActivation throws when the user is already active; Go keys that path on IsAlreadyActivated, not wrong-code.
|
||||||
|
- [Phase 07]: Both CLI serve and in-process Handler must publish *blob.Bucket; unit tests that call attach.Publish themselves cannot stand in for boot — Phase 5 shipped OpenBucket/Publish but never wired them. Phase 7 added HTTP avatar. UAT and corpus replay boot via Handler, so serve-only publish would leave the same 500.
|
||||||
|
- [Phase 07]: Assembled Handler avatar coverage lives in parity/ next to newConfiguredTarget, not in the user plugin package — The user plugin cannot import app.Handler without a reverse import. newConfiguredTarget is the same boot as replay.
|
||||||
|
|
||||||
### Pending Todos
|
### Pending Todos
|
||||||
|
|
||||||
@@ -224,6 +227,6 @@ Items acknowledged and carried forward from previous milestone close:
|
|||||||
|
|
||||||
## Session Continuity
|
## Session Continuity
|
||||||
|
|
||||||
Last session: 2026-09-23T08:24:37.406Z
|
Last session: 2026-09-23T08:50:56.663Z
|
||||||
Stopped at: Phase 9 context gathered
|
Stopped at: Completed 07-08-PLAN.md
|
||||||
Resume file: .planning/phases/09-backend-admin-authentication-and-schema-pipeline/09-CONTEXT.md
|
Resume file: None
|
||||||
|
|||||||
Reference in New Issue
Block a user