docs(13-01): reword Phase 13 and 14 criteria for the locked boundary

- Phase 13 repos name sm-user-plugin and summercms.go
- wishlist match/apply-release, the credential /test routes and the CSV
  Discogs pick move to Phase 14 (D-01, D-02); notifications drop prune,
  a Phase 14 console command (D-06); CSV and digest job bodies are Phase 14
- API-03, API-04, API-06, INTG-01 and INTG-02 follow; statuses untouched
This commit is contained in:
Jakub Zych
2026-10-03 06:37:11 +02:00
parent 2b94dfd2d2
commit aa2786470a
2 changed files with 12 additions and 12 deletions

View File

@@ -699,14 +699,14 @@ Plans:
**Goal**: The remaining core API surface — wishlist, notifications, CSV import/export, per-user/org credentials, and onboarding/public/invitation routes — is ported with byte-compatible shapes and their own public rate-limit buckets.
**Mode:** mvp
**Depends on**: Phase 11, Phase 12
**Repos:** fonoteka.go
**Repos:** fonoteka.go; sm-user-plugin (submodule at fonoteka.go/plugins/golem15/user, D-09/D-11 additive exports); summercms.go (13-01 framework gaps)
**Requirements**: API-03, API-04, API-05, API-06, API-07
**Success Criteria** (what must be TRUE):
1. Wishlist items, subscriptions, `public-wishlist/{token}` views, reservations (`wishlist/albums/{id}/reserve|reveal`) and purchase/digest triggers pass the parity diff.
2. Notifications list/mark-read/prune endpoints pass the parity diff (the realtime token endpoint itself is owned by the websockets plugin, ported in Phase 11).
3. CSV import runs as a multi-step session (store, show/poll, mapping patch, per-row edit, commit, cancel) and CSV export works on both authenticated groups, all passing the parity diff.
4. Per-user and per-org Discogs/AI credentials CRUD store encrypted values, honor the org-lock flag, and resolve env-to-org-to-user correctly.
1. Wishlist items, subscriptions, `public-wishlist/{token}` views, reservations (`wishlist/albums/{id}/reserve|reveal`) and purchase/digest triggers pass the parity diff. The wishlist Discogs `match`/`apply-release` routes move to Phase 14 (D-01), and the digest trigger queues its job here while the digest job body is Phase 14 (JOBS-03).
2. Notifications list, unread count and mark-read (one and all) pass the parity diff; pruning is the Phase 14 `fonoteka:prune-notifications` console command, not a route (D-06). The realtime token endpoint itself is owned by the websockets plugin, ported in Phase 11.
3. CSV import runs as a multi-step session (store, show/poll, mapping patch, per-row edit, commit, cancel) and CSV export works on both authenticated groups, all passing the parity diff. Commit and mapping enqueue the CSV import and match jobs, whose bodies are Phase 14 (JOBS-02).
4. Per-user and per-org Discogs/AI credentials CRUD store encrypted values, honor the org-lock flag, and resolve env-to-org-to-user correctly. The live `ai-credential/test` and `discogs-credential/test` routes move to Phase 14 (D-02).
5. Onboarding, public and invitation-inspection routes, including the anonymous collection views `public/{token}`, `public/{token}/albums` and `public/{token}/albums/{id}`, are reachable without auth and enforce their own public rate-limit buckets.
**Plans:** 6 plans
@@ -743,8 +743,8 @@ Plans:
1. The CSV import write job and the self-redispatching Discogs match job (240s timeout, self-redispatching with a delay on a Discogs rate-limit error) both complete correctly.
2. The wishlist digest job coalesces a 30-minute window and deletes its queue row on completion.
3. The `reindex` command asserts zero `collection_id`-0 documents before and after and can drop the legacy index.
4. The Discogs client enforces its proactive rate threshold, bounded wait budget, retry-after fallback and host-locked cover fetch, and the `albums/{id}/cover-price/discogs` route passes the parity diff.
5. AI cover recognition works through both Anthropic and OpenAI-compatible adapters with per-credential model/base-URL overrides.
4. The Discogs client enforces its proactive rate threshold, bounded wait budget, retry-after fallback and host-locked cover fetch, and the `albums/{id}/cover-price/discogs` route, the wishlist `wishlist/albums/{id}/match` and `apply-release` routes, `discogs-credential/test` and the CSV row-edit Discogs pick (`selected_discogs_id`) pass the parity diff.
5. AI cover recognition works through both Anthropic and OpenAI-compatible adapters with per-credential model/base-URL overrides; `ai-credential/test` passes the parity diff, and the AI resolver's admin tier uses the backend global vision model.
6. Feedback submissions and sitemap output work; the ported `oauth-client`/`prune-notifications`/`reindex` commands all run correctly.
**Plans**: TBD