docs(06-12): complete surf/bouncer gap-closure plan

This commit is contained in:
Jakub Zych
2026-09-21 19:43:51 +02:00
parent 8a9449df63
commit 4bad1a43a2
3 changed files with 37 additions and 9 deletions

View File

@@ -425,7 +425,7 @@ Phases execute in numeric order: 1 → 2 → 3 → 4 → 5 → 6 → 7 → 8 →
| 3. First vertical slice — genres end to end | 4/4 | Complete | 2026-09-17 |
| 4. CLI scaffolding, i18n and mail | 4/4 | Complete | 2026-09-18 |
| 5. Data layer full fidelity | 6/6 | Complete | 2026-09-18 |
| 6. HTTP routing, auth groups and rate limiting | 11/11 | Complete | 2026-09-21 |
| 6. HTTP routing, auth groups and rate limiting | 12/14 | In Progress| |
| 7. User plugin and authentication | 0/TBD | Not started | - |
| 8. OAuth2.1 authorization server | 0/TBD | Not started | - |
| 9. Backend admin authentication and schema pipeline | 0/TBD | Not started | - |

View File

@@ -2,15 +2,15 @@
gsd_state_version: 1.0
milestone: v1.0
milestone_name: milestone
status: executing
status: verifying
stopped_at: Completed 06-11-PLAN.md
last_updated: "2026-09-21T17:30:49.586Z"
last_activity: 2026-09-21 -- Phase 06 planning complete
last_updated: "2026-09-21T17:43:47.082Z"
last_activity: 2026-09-21
progress:
total_phases: 15
completed_phases: 5
total_plans: 37
completed_plans: 34
completed_plans: 35
percent: 33
---
@@ -27,10 +27,10 @@ See: .planning/PROJECT.md (updated 2026-09-16)
Phase: 06 (http-routing-auth-groups-and-rate-limiting) — EXECUTING
Plan: 11 of 11
Status: Ready to execute
Last activity: 2026-09-21 -- Phase 06 planning complete
Status: Phase complete — ready for verification
Last activity: 2026-09-21
Progress: [██████████] 100%
Progress: [██████████] 95%
## Performance Metrics
@@ -211,6 +211,6 @@ Items acknowledged and carried forward from previous milestone close:
## Session Continuity
Last session: 2026-09-21T11:04:05.263Z
Last session: 2026-09-21T17:43:47.062Z
Stopped at: Completed 06-11-PLAN.md
Resume file: None

View File

@@ -0,0 +1,28 @@
---
phase: 06-http-routing-auth-groups-and-rate-limiting
plan: 12
subsystem: surf, bouncer
tags: [gap-closure, body-limit, rate-limit, jwt, fail-closed]
requirements: [HTTP-04, HTTP-09, HTTP-05, HTTP-06]
key-files:
modified: [surf/router.go, surf/limiter.go, bouncer/registry.go, bouncer/jwt.go, surf/bodylimit_test.go, surf/limiter_test.go, surf/cors_test.go, bouncer/registry_test.go, bouncer/jwt_test.go]
metrics:
tasks: 3
completed: 2026-09-21
---
# Phase 6 Plan 12: surf/bouncer fail-closed gap closure Summary
Body cap now bounds every named middleware (inside recovery), limiter definitions and body config fail boot instead of failing open, mux conflicts return errors, and bouncer rejects typed-nil guards and fractional JWT subjects.
## Commits
- a50e09b: router ordering, factory cache, body-config validation, mux conflict error
- 4ad2ad2: fail-closed limiter definitions
- 8a9449d: typed-nil guard and integer-only JWT subject
## Deviations from Plan
- [Rule 3] surf/cors_test.go TestCORSAssembleUsesConfig lacked body_limits keys; added them (stricter validation legitimately requires them).
- Plan verification said fonoteka.go buckets must satisfy validation: `go test ./... -short` there is green.
## Self-Check: PASSED
go vet and go test ./... -race -short green in summercms.go; fonoteka.go tests green.