docs(06-08): update plan tracking
- Advance phase progress to 8 of 11 plans - Record transition-address security decisions and execution metrics - Mark HTTP-07 complete in requirements tracking
This commit is contained in:
@@ -56,7 +56,7 @@ Requirements for v1 (the Płytarium port). Each maps to roadmap phases. "User" b
|
|||||||
- [x] **HTTP-04**: A rate limiter supports named buckets keyed by a resolver (token id, IP, route param), stacking two limiters on one route, and ports Płytarium's five named buckets and inline throttles 1:1
|
- [x] **HTTP-04**: A rate limiter supports named buckets keyed by a resolver (token id, IP, route param), stacking two limiters on one route, and ports Płytarium's five named buckets and inline throttles 1:1
|
||||||
- [x] **HTTP-05**: An auth guard registry lets plugins add guards (JWT, personal token, OAuth bearer) that all resolve to the same current-user accessor
|
- [x] **HTTP-05**: An auth guard registry lets plugins add guards (JWT, personal token, OAuth bearer) that all resolve to the same current-user accessor
|
||||||
- [ ] **HTTP-06**: Response conventions are preserved: empty arrays serialize as [], timestamps as +00:00, tri-state booleans keep null, conditional keys are omitted not nulled, and no blanket envelope or error middleware wraps OAuth routes
|
- [ ] **HTTP-06**: Response conventions are preserved: empty arrays serialize as [], timestamps as +00:00, tri-state booleans keep null, conditional keys are omitted not nulled, and no blanket envelope or error middleware wraps OAuth routes
|
||||||
- [ ] **HTTP-07**: A guarded outbound fetch helper enforces host allow-lists, byte caps and timeouts for user-supplied URLs (manual cover URL, Discogs cover)
|
- [x] **HTTP-07**: A guarded outbound fetch helper enforces host allow-lists, byte caps and timeouts for user-supplied URLs (manual cover URL, Discogs cover)
|
||||||
- [x] **HTTP-08**: OpenAPI is generated from swaggo/swag annotations on handlers and openapi-typescript produces the admin SPA's types
|
- [x] **HTTP-08**: OpenAPI is generated from swaggo/swag annotations on handlers and openapi-typescript produces the admin SPA's types
|
||||||
- [x] **HTTP-09**: CORS and JSON body size limits match the PHP deployment
|
- [x] **HTTP-09**: CORS and JSON body size limits match the PHP deployment
|
||||||
|
|
||||||
@@ -189,7 +189,7 @@ Which phases cover which requirements. Updated during roadmap creation.
|
|||||||
| HTTP-04 | Phase 6 | In Progress |
|
| HTTP-04 | Phase 6 | In Progress |
|
||||||
| HTTP-05 | Phase 6 | Complete |
|
| HTTP-05 | Phase 6 | Complete |
|
||||||
| HTTP-06 | Phase 6 | In Progress |
|
| HTTP-06 | Phase 6 | In Progress |
|
||||||
| HTTP-07 | Phase 6 | In Progress |
|
| HTTP-07 | Phase 6 | Complete |
|
||||||
| HTTP-08 | Phase 6 | Complete |
|
| HTTP-08 | Phase 6 | Complete |
|
||||||
| HTTP-09 | Phase 6 | Complete |
|
| HTTP-09 | Phase 6 | Complete |
|
||||||
| AUTH-01 | Phase 7 | Pending |
|
| AUTH-01 | Phase 7 | Pending |
|
||||||
|
|||||||
@@ -250,7 +250,7 @@ Plans:
|
|||||||
**Wave 6** *(gap closure; parallel, blocked on 06-06)*
|
**Wave 6** *(gap closure; parallel, blocked on 06-06)*
|
||||||
|
|
||||||
- [x] 06-07-PLAN.md — Make limiter admission atomic and remove attacker-controlled Host from inline keys
|
- [x] 06-07-PLAN.md — Make limiter admission atomic and remove attacker-controlled Host from inline keys
|
||||||
- [ ] 06-08-PLAN.md — Reject private IPv4 embedded in NAT64 and 6to4 dial addresses
|
- [x] 06-08-PLAN.md — Reject private IPv4 embedded in NAT64 and 6to4 dial addresses
|
||||||
- [ ] 06-09-PLAN.md — Buffer route responses so partial-write panics yield clean raw/house 500s
|
- [ ] 06-09-PLAN.md — Buffer route responses so partial-write panics yield clean raw/house 500s
|
||||||
- [ ] 06-10-PLAN.md — Restore exact no-newline InvScope 401/403 wire bodies
|
- [ ] 06-10-PLAN.md — Restore exact no-newline InvScope 401/403 wire bodies
|
||||||
|
|
||||||
@@ -425,7 +425,7 @@ Phases execute in numeric order: 1 → 2 → 3 → 4 → 5 → 6 → 7 → 8 →
|
|||||||
| 3. First vertical slice — genres end to end | 4/4 | Complete | 2026-09-17 |
|
| 3. First vertical slice — genres end to end | 4/4 | Complete | 2026-09-17 |
|
||||||
| 4. CLI scaffolding, i18n and mail | 4/4 | Complete | 2026-09-18 |
|
| 4. CLI scaffolding, i18n and mail | 4/4 | Complete | 2026-09-18 |
|
||||||
| 5. Data layer full fidelity | 6/6 | Complete | 2026-09-18 |
|
| 5. Data layer full fidelity | 6/6 | Complete | 2026-09-18 |
|
||||||
| 6. HTTP routing, auth groups and rate limiting | 7/11 | In Progress| |
|
| 6. HTTP routing, auth groups and rate limiting | 8/11 | In Progress| |
|
||||||
| 7. User plugin and authentication | 0/TBD | Not started | - |
|
| 7. User plugin and authentication | 0/TBD | Not started | - |
|
||||||
| 8. OAuth2.1 authorization server | 0/TBD | Not started | - |
|
| 8. OAuth2.1 authorization server | 0/TBD | Not started | - |
|
||||||
| 9. Backend admin authentication and schema pipeline | 0/TBD | Not started | - |
|
| 9. Backend admin authentication and schema pipeline | 0/TBD | Not started | - |
|
||||||
|
|||||||
@@ -3,15 +3,15 @@ gsd_state_version: 1.0
|
|||||||
milestone: v1.0
|
milestone: v1.0
|
||||||
milestone_name: milestone
|
milestone_name: milestone
|
||||||
status: executing
|
status: executing
|
||||||
stopped_at: Completed 06-07-PLAN.md
|
stopped_at: Completed 06-08-PLAN.md
|
||||||
last_updated: "2026-09-20T15:11:34.217Z"
|
last_updated: "2026-09-20T18:59:52.988Z"
|
||||||
last_activity: 2026-09-20
|
last_activity: 2026-09-20
|
||||||
progress:
|
progress:
|
||||||
total_phases: 15
|
total_phases: 15
|
||||||
completed_phases: 5
|
completed_phases: 5
|
||||||
total_plans: 34
|
total_plans: 34
|
||||||
completed_plans: 30
|
completed_plans: 31
|
||||||
percent: 88
|
percent: 91
|
||||||
---
|
---
|
||||||
|
|
||||||
# Project State
|
# Project State
|
||||||
@@ -26,17 +26,17 @@ See: .planning/PROJECT.md (updated 2026-09-16)
|
|||||||
## Current Position
|
## Current Position
|
||||||
|
|
||||||
Phase: 06 (http-routing-auth-groups-and-rate-limiting) — EXECUTING
|
Phase: 06 (http-routing-auth-groups-and-rate-limiting) — EXECUTING
|
||||||
Plan: 2 of 11
|
Plan: 3 of 11
|
||||||
Status: Ready to execute
|
Status: Ready to execute
|
||||||
Last activity: 2026-09-20
|
Last activity: 2026-09-20
|
||||||
|
|
||||||
Progress: [█████████░] 88%
|
Progress: [█████████░] 91%
|
||||||
|
|
||||||
## Performance Metrics
|
## Performance Metrics
|
||||||
|
|
||||||
**Velocity:**
|
**Velocity:**
|
||||||
|
|
||||||
- Total plans completed: 30
|
- Total plans completed: 31
|
||||||
- Average duration: 21 min
|
- Average duration: 21 min
|
||||||
- Total execution time: 104 min
|
- Total execution time: 104 min
|
||||||
|
|
||||||
@@ -76,6 +76,7 @@ Progress: [█████████░] 88%
|
|||||||
| Phase 06 P05 | 13 min | 3 tasks | 13 files |
|
| Phase 06 P05 | 13 min | 3 tasks | 13 files |
|
||||||
| Phase 06 P06 | 1h 29m | 2 tasks | 3 files |
|
| Phase 06 P06 | 1h 29m | 2 tasks | 3 files |
|
||||||
| Phase 06 P07 | 12 min | 1 tasks | 4 files |
|
| Phase 06 P07 | 12 min | 1 tasks | 4 files |
|
||||||
|
| Phase 06 P08 | 1h 20m | 1 tasks | 3 files |
|
||||||
|
|
||||||
## Accumulated Context
|
## Accumulated Context
|
||||||
|
|
||||||
@@ -177,6 +178,8 @@ Recent decisions affecting current work:
|
|||||||
- [Phase 06]: Place throttle:fonoteka-api-token before inv.scope:read in the personal-token middleware declaration. — Missing and invalid credentials must consume the 60/minute per-IP deny-path budget before InvScope returns its PHP-compatible 401 response.
|
- [Phase 06]: Place throttle:fonoteka-api-token before inv.scope:read in the personal-token middleware declaration. — Missing and invalid credentials must consume the 60/minute per-IP deny-path budget before InvScope returns its PHP-compatible 401 response.
|
||||||
- [Phase 06]: Replace the split limiter store protocol with one atomic Attempt operation. — Expiry, threshold comparison, admitted increment, and retry duration must share one mutex critical section so concurrent callers cannot bypass Max.
|
- [Phase 06]: Replace the split limiter store protocol with one atomic Attempt operation. — Expiry, threshold comparison, admitted increment, and retry duration must share one mutex critical section so concurrent callers cannot bypass Max.
|
||||||
- [Phase 06]: Use one inline:domainless namespace plus trusted-proxy ClientIP for every anonymous inline throttle. — Host and inline throttle text must not let anonymous callers rotate rate-limit buckets; authenticated requests retain u:<principal id> isolation.
|
- [Phase 06]: Use one inline:domainless namespace plus trusted-proxy ClientIP for every anonymous inline throttle. — Host and inline throttle text must not let anonymous callers rotate rate-limit buckets; authenticated requests retain u:<principal id> isolation.
|
||||||
|
- [Phase 06]: isReservedOrPrivate owns Addr.Unmap and recursively applies the ordinary IPv4 table to supported transition embeddings — Direct helper callers and the production dial hook must share one normalization and private/reserved policy.
|
||||||
|
- [Phase 06]: A 64:ff9b:1::/48 address with a non-zero RFC 6052 u octet fails closed — Malformed local-use NAT64 must not fall through as apparently public native IPv6.
|
||||||
|
|
||||||
### Pending Todos
|
### Pending Todos
|
||||||
|
|
||||||
@@ -198,6 +201,6 @@ Items acknowledged and carried forward from previous milestone close:
|
|||||||
|
|
||||||
## Session Continuity
|
## Session Continuity
|
||||||
|
|
||||||
Last session: 2026-09-20T15:11:34.184Z
|
Last session: 2026-09-20T18:59:30.178Z
|
||||||
Stopped at: Completed 06-07-PLAN.md
|
Stopped at: Completed 06-08-PLAN.md
|
||||||
Resume file: None
|
Resume file: None
|
||||||
|
|||||||
Reference in New Issue
Block a user