docs(06): create gap closure plans

This commit is contained in:
Jakub Zych
2026-09-20 16:14:21 +02:00
parent c187d6f735
commit 47e9c44b2a
7 changed files with 719 additions and 6 deletions

View File

@@ -184,7 +184,7 @@ Plans:
4. The money cast round-trips the PHP ceiling and blank-string cases as a fixed 4-decimal JSON string (never `float64`), and an encrypted-at-rest credential column is AES-GCM encrypted at rest and hidden from serialization.
5. Paginated responses use the exact `{data, meta{current_page,last_page,per_page,total}}` envelope with no `links` key; another plugin extends a model's lifecycle through the GORM callback registry and a companion migration without editing the owning plugin's file; soft-deletable + uniquely-keyed tables pass a delete-then-recreate test.
**Plans**: 6 plans
**Plans**: 11 plans
Plans:
**Wave 1**
@@ -247,6 +247,17 @@ Plans:
- [x] 06-06-PLAN.md — Repair personal-token middleware order and prove unauthenticated request 61 is rate-limited
**Wave 6** *(gap closure; parallel, blocked on 06-06)*
- [ ] 06-07-PLAN.md — Make limiter admission atomic and remove attacker-controlled Host from inline keys
- [ ] 06-08-PLAN.md — Reject private IPv4 embedded in NAT64 and 6to4 dial addresses
- [ ] 06-09-PLAN.md — Buffer route responses so partial-write panics yield clean raw/house 500s
- [ ] 06-10-PLAN.md — Restore exact no-newline InvScope 401/403 wire bodies
**Wave 7** *(gap closure; blocked on 06-07..06-10)*
- [ ] 06-11-PLAN.md — Re-run Phase 6 security gates and refresh the stale threat verdict
### Phase 7: User plugin and authentication
**Goal**: The user plugin is ported with registration, login, JWT issue/refresh, organizations, personal API tokens and the must-change-password lock. Security-load-bearing — password auth, token scope ceilings and the session lock all live here; apply the security-review agent.