docs(06): create gap closure plans
This commit is contained in:
@@ -184,7 +184,7 @@ Plans:
|
||||
4. The money cast round-trips the PHP ceiling and blank-string cases as a fixed 4-decimal JSON string (never `float64`), and an encrypted-at-rest credential column is AES-GCM encrypted at rest and hidden from serialization.
|
||||
5. Paginated responses use the exact `{data, meta{current_page,last_page,per_page,total}}` envelope with no `links` key; another plugin extends a model's lifecycle through the GORM callback registry and a companion migration without editing the owning plugin's file; soft-deletable + uniquely-keyed tables pass a delete-then-recreate test.
|
||||
|
||||
**Plans**: 6 plans
|
||||
**Plans**: 11 plans
|
||||
|
||||
Plans:
|
||||
**Wave 1**
|
||||
@@ -247,6 +247,17 @@ Plans:
|
||||
|
||||
- [x] 06-06-PLAN.md — Repair personal-token middleware order and prove unauthenticated request 61 is rate-limited
|
||||
|
||||
**Wave 6** *(gap closure; parallel, blocked on 06-06)*
|
||||
|
||||
- [ ] 06-07-PLAN.md — Make limiter admission atomic and remove attacker-controlled Host from inline keys
|
||||
- [ ] 06-08-PLAN.md — Reject private IPv4 embedded in NAT64 and 6to4 dial addresses
|
||||
- [ ] 06-09-PLAN.md — Buffer route responses so partial-write panics yield clean raw/house 500s
|
||||
- [ ] 06-10-PLAN.md — Restore exact no-newline InvScope 401/403 wire bodies
|
||||
|
||||
**Wave 7** *(gap closure; blocked on 06-07..06-10)*
|
||||
|
||||
- [ ] 06-11-PLAN.md — Re-run Phase 6 security gates and refresh the stale threat verdict
|
||||
|
||||
### Phase 7: User plugin and authentication
|
||||
|
||||
**Goal**: The user plugin is ported with registration, login, JWT issue/refresh, organizations, personal API tokens and the must-change-password lock. Security-load-bearing — password auth, token scope ceilings and the session lock all live here; apply the security-review agent.
|
||||
|
||||
Reference in New Issue
Block a user