docs(phase-12.2): add validation strategy
This commit is contained in:
@@ -0,0 +1,92 @@
|
|||||||
|
---
|
||||||
|
phase: "12.2"
|
||||||
|
slug: "admin-form-fields-date-file-upload-relation-editing-with-def"
|
||||||
|
# status lifecycle: draft (seeded by plan-phase) → validated (set by validate-phase §6)
|
||||||
|
# audit-milestone §5.5 distinguishes NOT-VALIDATED (draft) from PARTIAL (validated + nyquist_compliant: false) (#2117)
|
||||||
|
status: draft
|
||||||
|
nyquist_compliant: false
|
||||||
|
wave_0_complete: false
|
||||||
|
created: "2026-10-02"
|
||||||
|
---
|
||||||
|
|
||||||
|
# Phase 12.2 — Validation Strategy
|
||||||
|
|
||||||
|
> Per-phase validation contract for feedback sampling during execution.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## Test Infrastructure
|
||||||
|
|
||||||
|
| Property | Value |
|
||||||
|
|----------|-------|
|
||||||
|
| **Framework** | go test + testify, testcontainers-go Postgres (`-short` skips DB tests); vitest 3.2.7 + @vue/test-utils + happy-dom for the admin SPA |
|
||||||
|
| **Config file** | `modules/lagoon/postgres_test.go`, `modules/cabana/auth_test.go` (TestMain); `admin/vitest.config.ts` |
|
||||||
|
| **Quick run command** | `go vet ./... && go test -short ./modules/cabana/... ./modules/lagoon/... ./modules/conga/...` (plus `npm --prefix admin test -- tests/form tests/relation` when the SPA changed) |
|
||||||
|
| **Full suite command** | `go vet ./... && go test ./... && npm --prefix admin run typecheck && npm --prefix admin test && scripts/check-admin-openapi.sh --check && scripts/check-admin-dist.sh && go test ./cmd/summer -run TestDocsTree && go run ./cmd/summer docs:build --check` |
|
||||||
|
| **Estimated runtime** | ~240 seconds (Docker up) |
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## Sampling Rate
|
||||||
|
|
||||||
|
- **After every task commit:** Run the quick run command
|
||||||
|
- **After every plan wave:** Run the full suite command
|
||||||
|
- **Before `/gsd-verify-work`:** Full suite must be green
|
||||||
|
- **Max feedback latency:** 240 seconds
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## Per-Task Verification Map
|
||||||
|
|
||||||
|
Task IDs are filled in once PLAN.md files exist. The behaviour-to-command map from RESEARCH.md is the contract:
|
||||||
|
|
||||||
|
| Area | Success criterion | Threat Ref | Secure Behavior | Test Type | Automated Command | File Exists | Status |
|
||||||
|
|------|-------------------|------------|-----------------|-----------|-------------------|-------------|--------|
|
||||||
|
| datepicker compile | SC-1 | — | unknown key / mode-type mismatch fails boot | unit | `go test -short ./modules/cabana -run TestDatepicker` | ❌ W0 | ⬜ pending |
|
||||||
|
| Date / TimeOfDay / Fill | SC-1 | — | N/A | unit + PG | `go test ./modules/lagoon -run 'TestDate\|TestTimeOfDay\|TestFillText'` | ❌ W0 | ⬜ pending |
|
||||||
|
| date bounds | SC-1 | — | min/max enforced server-side (422) | integration | `go test ./modules/cabana -run TestDatepickerBounds` | ❌ W0 | ⬜ pending |
|
||||||
|
| attach.Store | SC-2 | upload | size/MIME/image guard, polyglot refused | unit + PG | `go test ./modules/lagoon/attach -run TestStore` | ❌ W0 | ⬜ pending |
|
||||||
|
| fileupload routes | SC-2 | upload | MaxBytesReader 413, maxFiles, deferred bind | integration | `go test ./modules/cabana -run TestFileupload` | ❌ W0 | ⬜ pending |
|
||||||
|
| protected file download | SC-2 | IDOR | 404 for other parent / other admin's pending file; nosniff | security | `go test ./modules/cabana -run TestProtectedFile` | ❌ W0 | ⬜ pending |
|
||||||
|
| relation child CRUD | SC-3 | mass assign | toolbarButtons gate, pivot whitelist | integration | `go test ./modules/cabana -run TestRelationChild` | ❌ W0 | ⬜ pending |
|
||||||
|
| parent scoping (D-15) | SC-3 | IDOR | child of another parent → 404 | security | `go test ./modules/cabana -run TestRelationChildScope` | ❌ W0 | ⬜ pending |
|
||||||
|
| deferred commit | SC-4 | session replay | foreign admin key ignored; rollback keeps bindings; double submit serialized | integration | `go test ./modules/cabana -run TestDeferredCommit` | ❌ W0 | ⬜ pending |
|
||||||
|
| purge | SC-4 | storage DoS | expired bindings + orphans removed, blobs after commit | integration | `go test ./modules/lagoon -run TestPurgeDeferred` | ❌ W0 | ⬜ pending |
|
||||||
|
| framework schedule | SC-4 | — | N/A | unit | `go test -short ./modules/conga -run TestFrameworkSchedule` | ❌ W0 | ⬜ pending |
|
||||||
|
| route inventory + OpenAPI | SC-3/4 | — | every route permission-checked | contract | `go test -short ./modules/cabana -run 'TestPhase09PermissionMatrix\|TestPhase09ContractInventory\|TestOpenAPI'` | ✅ | ⬜ pending |
|
||||||
|
| SPA fields + modals | SC-1/2/3 | — | session key header sent | SPA unit | `npm --prefix admin test -- tests/form tests/relation` | ❌ W0 | ⬜ pending |
|
||||||
|
| docs checker | SC-5 | — | N/A | docs | `go test ./cmd/summer -run TestDocsTree && go run ./cmd/summer docs:build --check` | ✅ | ⬜ pending |
|
||||||
|
|
||||||
|
*Status: ⬜ pending · ✅ green · ❌ red · ⚠️ flaky*
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## Wave 0 Requirements
|
||||||
|
|
||||||
|
- [ ] `modules/cabana/testdata/` fixture plugin: parent model (attach owner + attach relations), hasMany child with nullable FK, belongsToMany with pivot form, `config_relation.yaml` using `manage.form` / `pivot.form`
|
||||||
|
- [ ] `phase09Routes` in `modules/cabana/security_coverage_test.go` extended in the same commit as each new route
|
||||||
|
- [ ] `admin/tests/fixtures/` entries for the new schema fields and file list
|
||||||
|
|
||||||
|
*No framework install needed.*
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## Manual-Only Verifications
|
||||||
|
|
||||||
|
| Behavior | Requirement | Why Manual | Test Instructions |
|
||||||
|
|----------|-------------|------------|-------------------|
|
||||||
|
| Datepicker keyboard / a11y and visual fit with Direction C | SC-1 | Visual and interaction quality | Open a form with each mode in the admin SPA; navigate the calendar by keyboard; check against UI-SPEC |
|
||||||
|
| Drag reorder and upload progress feel | SC-2 | Pointer interaction | Upload several images to an attachMany field on an unsaved record, reorder, save, reload |
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## Validation Sign-Off
|
||||||
|
|
||||||
|
- [ ] All tasks have `<automated>` verify or Wave 0 dependencies
|
||||||
|
- [ ] Sampling continuity: no 3 consecutive tasks without automated verify
|
||||||
|
- [ ] Wave 0 covers all MISSING references
|
||||||
|
- [ ] No watch-mode flags
|
||||||
|
- [ ] Feedback latency < 240s
|
||||||
|
- [ ] `nyquist_compliant: true` set in frontmatter
|
||||||
|
|
||||||
|
**Approval:** pending
|
||||||
Reference in New Issue
Block a user