docs(12.1): create phase plan

This commit is contained in:
Jakub Zych
2026-10-04 19:41:08 +02:00
parent ea0fc6f191
commit 9cbce01b46
13 changed files with 3224 additions and 15 deletions

View File

@@ -643,16 +643,30 @@ Plans:
**Success Criteria** (what must be TRUE):
1. Users, User Groups and Organisations each have a list (columns, search, filters as in the PHP `config_filter.yaml`) and a create/update form ported from the PHP model YAML, reachable from admin navigation and gated by backend permissions.
2. A user's groups and an organisation's members are managed through relation managers.
2. A user's groups are managed through a relation field on the user form and an organisation's members through a relation manager.
3. The user actions activate, unban, unsuspend and delete, plus the list bulk actions, behave as in PHP `Users.php`.
4. Threat T-12-18 is revisited: the admin form is the first writer of `users_groups`, and only a backend user holding the required permission can change group membership.
5. The new code has unit tests, delivered in the phase's last plan.
**Open questions (discuss-phase):** impersonate user in or out of scope (security-sensitive); a separate permission for granting the `admin` group (it makes a site admin); whether convert-guest is needed for the application's data.
**Plans:** 0 plans
**Plans:** 5 plans
Plans:
- [ ] TBD (run /gsd-plan-phase 12.1 to break down)
**Wave 1**
- [ ] 12.1-01-PLAN.md — Framework actions (summercms.go): declared bulk actions, record actions, row state and `cabana.ForbiddenError` (403), with READMEs, docs, OpenAPI, TS types, `dist/` and the neutral `acme` fixture
**Wave 2** *(blocked on Wave 1 completion)*
- [ ] 12.1-02-PLAN.md — Framework preview and form seams (summercms.go): preview context, `permissioneditor`, `password`, form virtual fields, per-operation rules, writable foreign key, locked relation options, `invisible` columns, `preset`; ends with the tag v0.1.3
**Wave 3** *(blocked on Wave 2 completion)*
- [ ] 12.1-03-PLAN.md — Plugin foundation and the Users screen (sm-user-plugin): additive migrations, permissions, navigation, list, filters, preview, form, bulk and record actions, delete semantics, password and invite, avatar, frontend permission resolver, `last_seen`, and the takeover guard for members of privileged groups (D-30)
**Wave 4** *(blocked on Wave 3 completion)*
- [ ] 12.1-04-PLAN.md — User Groups and Organisations screens, the `members` relation manager, the privileged-group guard on every `users_groups` write path (T-12-18), and the application's parity allow-list entry and submodule pointer on framework v0.1.3
**Wave 5** *(blocked on Wave 4 completion)*
- [ ] 12.1-05-PLAN.md — Unit tests last: full coverage in both repos, `scripts/check-phase12.1.sh`, the security review and the validation sign-off, then the plugin push (only when v0.1.3 is on origin)
### Phase 12.2: Admin form fields: date, file upload, relation editing with deferred binding (INSERTED)