diff --git a/.planning/phases/12.2-admin-form-fields-date-file-upload-relation-editing-with-def/12.2-REVIEW-DISPOSITION.md b/.planning/phases/12.2-admin-form-fields-date-file-upload-relation-editing-with-def/12.2-REVIEW-DISPOSITION.md index 7d5275c..b535b89 100644 --- a/.planning/phases/12.2-admin-form-fields-date-file-upload-relation-editing-with-def/12.2-REVIEW-DISPOSITION.md +++ b/.planning/phases/12.2-admin-form-fields-date-file-upload-relation-editing-with-def/12.2-REVIEW-DISPOSITION.md @@ -5,48 +5,48 @@ titles: json findings: - id: CR-01 severity: critical - disposition: open + disposition: fixed title: "Form saves can commit before an in-flight upload reaches the deferred session" - id: CR-02 severity: critical - disposition: open + disposition: fixed title: "Aborted or network-failed uploads have no idempotency or reconciliation path" - id: CR-03 severity: critical - disposition: open + disposition: fixed title: "Core CRUD, settings, and relation mutation JSON bodies are uncapped" - id: WR-01 severity: warning - disposition: open + disposition: fixed title: "A field may advertise a maximum file size that its request cap cannot carry" - id: WR-02 severity: warning - disposition: open + disposition: fixed title: "Datetime picker bounds use local days while the server validates UTC days" - id: WR-03 severity: warning - disposition: open + disposition: fixed title: "Concurrent reorder requests can overwrite the latest order or create a mixed order" - id: WR-04 severity: warning - disposition: open + disposition: fixed title: "Pending pivot hydration discards type-conversion errors" -open: 7 +open: 0 total: 7 -recorded: 2026-10-02T19:20:13Z +recorded: 2026-10-02T21:15:00Z --- # Phase 12.2: Code Review Disposition | Finding | Severity | Disposition | Source | |---------|----------|-------------|--------| -| CR-01 | critical | open | - | -| CR-02 | critical | open | - | -| CR-03 | critical | open | - | -| WR-01 | warning | open | - | -| WR-02 | warning | open | - | -| WR-03 | warning | open | - | -| WR-04 | warning | open | - | +| CR-01 | critical | fixed | 516f9c9 — FormSession.beginUpload / activeUploads; FormView and RelationChildModal refuse save while uploads are in flight | +| CR-02 | critical | fixed | 516f9c9 — X-Upload-Id stored on DeferredEnvelope.UploadID; abort deletes a stored file; network loss adopts a single pending extra | +| CR-03 | critical | fixed | 516f9c9 — decodeCappedObject / decodeCappedRelationMutation / decodeCappedBulk + writeCRUDError maps MaxBytesError to 413 | +| WR-01 | warning | fixed | 516f9c9 — boot rejects maxBytes + 64 KiB multipart overhead above upload_bytes | +| WR-02 | warning | fixed | 516f9c9 — datetime bounds are UTC-day instants projected into the local zone | +| WR-03 | warning | fixed | 516f9c9 — client serializes reorder (latest snapshot only); server locks visible files with FOR UPDATE | +| WR-04 | warning | fixed | 516f9c9 — ShowPivot and updatePendingPivot return lifecycleFailure on lagoon.Fill errors | Dispositions: `open` (recorded, not yet triaged), `fixed`, `skipped`, `deferred`. Set `deferred` by hand and put the reason in the Source cell; both are preserved. A `|` in the reason is kept as prose and escaped on the next run. diff --git a/.planning/phases/12.2-admin-form-fields-date-file-upload-relation-editing-with-def/12.2-UAT.md b/.planning/phases/12.2-admin-form-fields-date-file-upload-relation-editing-with-def/12.2-UAT.md new file mode 100644 index 0000000..928e37a --- /dev/null +++ b/.planning/phases/12.2-admin-form-fields-date-file-upload-relation-editing-with-def/12.2-UAT.md @@ -0,0 +1,44 @@ +--- +status: testing +phase: 12.2-admin-form-fields-date-file-upload-relation-editing-with-def +source: [12.2-VERIFICATION.md] +started: 2026-10-02T21:15:00Z +updated: 2026-10-02T21:15:00Z +--- + +## Current Test + +number: 1 +name: Calendar keyboard and visual fit (UI-SPEC backstop + Direction C) +expected: | + Esc returns focus to the datepicker trigger; a disabled day cannot be selected; the popover fits the existing control height and calendar cell size +awaiting: user response + +## Tests + +### 1. Calendar keyboard and visual fit (UI-SPEC backstop + Direction C) +expected: Esc returns focus to the datepicker trigger; a disabled day cannot be selected; the popover fits the existing control height and calendar cell size +result: [pending] + +### 2. Drag reorder and upload progress on a fileupload field +expected: Tiles and rows show queued/uploading/done; Save stays disabled while an upload is in flight; drag or keyboard reorder keeps the latest order +result: [pending] + +### 3. Child create/edit/delete and pivot edit on an unsaved parent +expected: Create-screen relation managers with deferrable: true work at record id 0; the pending note shows; the first parent save commits children, pivots and files +result: [pending] + +### 4. Create and push the v0.1.1 tag (12.2-05 Task 4) +expected: git tag -a v0.1.1 on the phase head, then git push origin master v0.1.1; downstream TODO items for date, file upload and related-record editing can resolve on that tag +result: [pending] + +## Summary + +total: 4 +passed: 0 +issues: 0 +pending: 4 +skipped: 0 +blocked: 0 + +## Gaps diff --git a/.planning/phases/12.2-admin-form-fields-date-file-upload-relation-editing-with-def/12.2-UI-REVIEW.md b/.planning/phases/12.2-admin-form-fields-date-file-upload-relation-editing-with-def/12.2-UI-REVIEW.md new file mode 100644 index 0000000..b15a8b8 --- /dev/null +++ b/.planning/phases/12.2-admin-form-fields-date-file-upload-relation-editing-with-def/12.2-UI-REVIEW.md @@ -0,0 +1,56 @@ +# Phase 12.2 — UI Review + +**Audited:** 2026-10-02 +**Baseline:** `12.2-UI-SPEC.md` (approved) +**Screenshots:** Not captured — no live admin session was driven in this pass +**Interaction captures:** off + +--- + +## Scope Decision + +UI audit of the three new controls (`DatepickerField`, `FileuploadField`, relation child/pivot modals) against the existing Direction C system. No new tokens. This pass used the committed SPA tests and a code read of the review-fix commit `516f9c9`; it did not open a browser. + +--- + +## Pillar Scores + +| Pillar | Score | Finding | +|--------|-------|---------| +| 1. Copywriting | 4 | All new strings go through `t` / phrasebook keys. No new literal UI copy in the review-fix commit. | +| 2. Visuals | 3 | Components reuse Button, FormGrid, ConfirmDialog, Reka DatePicker/Dialog/Progress. Visual fit of the calendar popover and file tiles is a human check. | +| 3. Color | 4 | Danger/soft/skel/muted tokens only; no new palette. | +| 4. Typography | 4 | DM Sans / tabular-nums for dates, times, sizes as specified. | +| 5. Spacing | 4 | Existing control heights and 4px scale; no new spacing tokens. | +| 6. Experience Design | 4 | Save blocked while uploads are in flight (CR-01). Abort deletes a stored file (CR-02). Reorder keeps the latest snapshot (WR-03). Dirty includes active uploads. | + +**Overall: 4** — automated backstops pass; browser visual UAT still required. + +--- + +## UI-SPEC backstops + +| Backstop | Automated evidence | Status | +|----------|--------------------|--------| +| Esc returns focus; disabled day cannot be selected | `admin/tests/form/DatepickerField.test.ts` | pass | +| Datetime local wall clock / UTC emit; ignoreTimezone | `admin/tests/app/dateFormat.test.ts` | pass | +| Protected thumbs use X-Session-Key, object URL, revoke | `admin/tests/form/FileuploadField.test.ts` | pass | +| Keyboard reorder, focus, announce, one request | `admin/tests/form/FileuploadField.test.ts` | pass | + +--- + +## Priority Fixes + +None blocking. Human items live in `12.2-UAT.md`. + +## Files Audited + +- `admin/src/views/FormView.vue` +- `admin/src/components/form/fields/FileuploadField.vue` +- `admin/src/components/form/fields/DatepickerField.vue` (via tests) +- `admin/src/components/form/formContext.ts` +- `admin/src/components/relation/RelationChildModal.vue` +- `admin/src/app/dateFormat.ts` +- `admin/tests/form/FileuploadField.test.ts` +- `admin/tests/app/dateFormat.test.ts` +- `admin/tests/smoke/deferred.smoke.test.ts` diff --git a/.planning/phases/12.2-admin-form-fields-date-file-upload-relation-editing-with-def/12.2-VERIFICATION.md b/.planning/phases/12.2-admin-form-fields-date-file-upload-relation-editing-with-def/12.2-VERIFICATION.md new file mode 100644 index 0000000..f15a206 --- /dev/null +++ b/.planning/phases/12.2-admin-form-fields-date-file-upload-relation-editing-with-def/12.2-VERIFICATION.md @@ -0,0 +1,71 @@ +--- +phase: 12.2-admin-form-fields-date-file-upload-relation-editing-with-def +verified: 2026-10-02T21:15:00Z +status: human_needed +score: 5/5 roadmap success criteria verified; 4 UI-SPEC backstops verified by SPA tests; browser UAT and the v0.1.1 tag remain human +overrides_applied: 0 +human_verification: + - test: "Calendar keyboard and visual fit (UI-SPEC backstop + Direction C)" + expected: "Esc returns focus to the datepicker trigger; a disabled day cannot be selected; the popover fits the existing control height and calendar cell size" + why_human: "Unit tests cover Esc and disabled days; visual fit against Direction C needs a browser" + - test: "Drag reorder and upload progress on a fileupload field" + expected: "Tiles and rows show queued/uploading/done; Save stays disabled while an upload is in flight; drag or keyboard reorder keeps the latest order" + why_human: "XHR progress and pointer drag are mocked in vitest; live feel is a human check" + - test: "Child create/edit/delete and pivot edit on an unsaved parent" + expected: "Create-screen relation managers with deferrable: true work at record id 0; the pending note shows; the first parent save commits children, pivots and files" + why_human: "The deferred smoke test is mocked; the assembled admin UI against a real plugin is a human check" + - test: "Create and push the v0.1.1 tag (12.2-05 Task 4)" + expected: "git tag -a v0.1.1 on the phase head, then git push origin master v0.1.1; downstream TODO items for date, file upload and related-record editing can resolve on that tag" + why_human: "The executor must not tag or push" +--- + +# Phase 12.2: Admin form fields Verification Report + +**Phase Goal:** A plugin's admin forms cover date/datetime, file upload, and related-record create/edit/delete with Winter-like deferred binding. +**Verified:** 2026-10-02T21:15:00Z +**Status:** human_needed +**Re-verification:** No — first verification after the review-fix commit. + +All five plans have SUMMARYs. The prior Codex run already passed the nine-stage `scripts/check-phase12.2.sh` suite, Nyquist validation, and the 41-threat security ledger (`12.2-SECURITY.md` `threats_open: 0`). This pass closed the seven code-review findings instead of re-running that 137-file review. + +## Goal Achievement + +| # | Success criterion | Status | Evidence | +| --- | --- | --- | --- | +| SC1 | `type: datepicker` with Winter modes stores date, timestamp and time | ✓ | `modules/cabana/datepicker_test.go`, `modules/lagoon/date_test.go`, `admin/tests/form/DatepickerField.test.ts`, `admin/tests/app/dateFormat.test.ts` (UTC-day bounds after 516f9c9) | +| SC2 | `type: fileupload` on attachOne/attachMany, saved and unsaved | ✓ | `modules/cabana/fileupload_test.go` including `TestFileuploadUploadID` and WR-01 boot headroom; SPA `FileuploadField.test.ts` (18 tests) | +| SC3 | Relation child CRUD scoped to the parent | ✓ | `modules/cabana/relation_child_test.go`, `relation_child_scope_test.go` (D-15); `TestPendingPivotFillError` after 516f9c9 | +| SC4 | Deferred bind/commit/purge | ✓ | `modules/lagoon/deferred_test.go` (envelope now stores `upload_id`), `purge_test.go`, `modules/cabana/deferred_commit_test.go`, deferred smoke | +| SC5 | Unit tests in the last plan; docs checker passes | ✓ | `12.2-05-SUMMARY.md`; this session `go test ./cmd/summer -run TestDocsTree` and `go run ./cmd/summer docs:build --check` exit 0 | + +## Review findings (516f9c9) + +| ID | Status | Check run this session | +| --- | --- | --- | +| CR-01 | fixed | `admin/tests/smoke/deferred.smoke.test.ts` "does not save while an upload is still in flight"; FormView/RelationChildModal disable Save | +| CR-02 | fixed | `TestFileuploadUploadID`; FileuploadField abort-delete and network-adopt tests; `TestDeferred/envelope` stores `upload_id` | +| CR-03 | fixed | `TestJSONBodyCaps` (create, update, link, unlink, settings → 413) | +| WR-01 | fixed | `TestFileuploadCompile` equality and 64 KiB headroom | +| WR-02 | fixed | `admin/tests/app/dateFormat.test.ts` UTC-day bounds | +| WR-03 | fixed | FileuploadField "sends only the latest order"; `visibleFilesLocked(..., true)` | +| WR-04 | fixed | `TestPendingPivotFillError` | + +`12.2-REVIEW-DISPOSITION.md` records all 7 as `fixed`. The 137-file review was not re-run. + +## Artifacts + +| Artifact | Status | +| --- | --- | +| Five plan SUMMARYs | ✓ | +| `12.2-SECURITY.md` threats_open 0 | ✓ (prior run) | +| `12.2-VALIDATION.md` nyquist_compliant | ✓ (prior run) | +| `12.2-REVIEW.md` + disposition | ✓ disposition updated | +| Docs checker | ✓ this session | +| Admin `vue-tsc --noEmit` | ✓ this session | +| v0.1.1 tag | pending (user) | + +## Gaps + +None in automated must-haves. Remaining work is the four human items above. + +_Verifier: the agent (inline, targeted; did not re-run the nine-stage gate or 137-file review)_