docs(07): create phase plan

Six plans for the user plugin and authentication phase:
- 07-01: bouncer JWT lifecycle, password hashing, I18N-02 locale
  override, lagoon.Validate extensions (summercms.go)
- 07-02: User/Throttle schema, core session loop (login/logout/
  fetch/refresh/register) (fonoteka.go)
- 07-03: account management (forgot/reset, activation, update,
  change-password, avatar, mail) (fonoteka.go)
- 07-04: personal API tokens, me/locale, 423-exempt route-table
  proof (fonoteka.go)
- 07-05: parity evidence recording against the isolated PHP
  instance (fonoteka.go)
- 07-06: full unit coverage and validation sign-off (both repos)

Plan count and scope confirmed at the plan-count checkpoint.
This commit is contained in:
Jakub Zych
2026-09-22 12:21:15 +02:00
parent 0c41151863
commit 57745e32a2
7 changed files with 1533 additions and 1 deletions

View File

@@ -272,7 +272,29 @@ Plans:
3. A personal API token is created with a read|write|ai scope ceiling, listed, and revoked; a scope-checking middleware rejects an out-of-scope request.
4. The must-change-password flag returns 423 on the authenticated surface except the locale and password-change routes, and locale resolves per request from the user's persisted `preferred_locale` with header fallback even while the lock is active.
**Plans**: TBD
**Plans**: 6 plans
Plans:
**Wave 1**
- [ ] 07-01-PLAN.md — bouncer JWT lifecycle, password hashing, I18N-02 locale-from-principal, lagoon.Validate extensions
**Wave 2** *(blocked on 07-01)*
- [ ] 07-02-PLAN.md — User/Throttle schema and the core session loop: login/logout/fetch/refresh/register
**Wave 3** *(blocked on 07-02)*
- [ ] 07-03-PLAN.md — Account management: forgot/reset password, activation, update, change-password, avatar, mail
- [ ] 07-04-PLAN.md — Personal API tokens (mint/list/revoke), me/locale, 423-exempt route-table proof
**Wave 4** *(blocked on 07-03, 07-04)*
- [ ] 07-05-PLAN.md — Parity evidence: record and replay the 15 /_user/api/v1 routes and the nuxt-auth flow
**Wave 5** *(blocked on 07-05)*
- [ ] 07-06-PLAN.md — Full unit coverage, 07-VALIDATION.md sign-off
### Phase 8: OAuth2.1 authorization server