docs(07-01): complete framework auth primitives plan
This commit is contained in:
@@ -3,14 +3,14 @@ gsd_state_version: 1.0
|
||||
milestone: v1.0
|
||||
milestone_name: milestone
|
||||
status: executing
|
||||
stopped_at: Phase 7 context gathered
|
||||
last_updated: "2026-09-22T10:39:04.511Z"
|
||||
last_activity: 2026-09-22 -- Phase 7 planning complete
|
||||
stopped_at: Completed 07-01-PLAN.md
|
||||
last_updated: "2026-09-22T11:43:03.651Z"
|
||||
last_activity: 2026-09-22
|
||||
progress:
|
||||
total_phases: 15
|
||||
completed_phases: 6
|
||||
total_plans: 43
|
||||
completed_plans: 37
|
||||
completed_plans: 38
|
||||
percent: 40
|
||||
---
|
||||
|
||||
@@ -21,16 +21,16 @@ progress:
|
||||
See: .planning/PROJECT.md (updated 2026-09-16)
|
||||
|
||||
**Core value:** An existing WinterCMS-shaped app can be ported plugin by plugin to a single Go binary without its frontend noticing: the PHP version's API contract is the acceptance test.
|
||||
**Current focus:** Phase 7 — user plugin and authentication
|
||||
**Current focus:** Phase 07 — user-plugin-and-authentication
|
||||
|
||||
## Current Position
|
||||
|
||||
Phase: 7
|
||||
Plan: Not started
|
||||
Phase: 07 (user-plugin-and-authentication) — EXECUTING
|
||||
Plan: 2 of 6
|
||||
Status: Ready to execute
|
||||
Last activity: 2026-09-22 -- Phase 7 planning complete
|
||||
Last activity: 2026-09-22
|
||||
|
||||
Progress: [██████████] 100%
|
||||
Progress: [█████████░] 88%
|
||||
|
||||
## Performance Metrics
|
||||
|
||||
@@ -81,6 +81,7 @@ Progress: [██████████] 100%
|
||||
| Phase 06 P09 | 4 min | 1 tasks | 2 files |
|
||||
| Phase 06 P10 | 3h 15m | 1 tasks | 2 files |
|
||||
| Phase 06 P11 | 12h 30m | 1 tasks | 1 files |
|
||||
| Phase 07 P01 | 12 min | 3 tasks | 20 files |
|
||||
|
||||
## Accumulated Context
|
||||
|
||||
@@ -191,6 +192,7 @@ Recent decisions affecting current work:
|
||||
- [Phase 06]: Assert exact denial bytes before JSON shape checks — Whitespace normalization would hide response-contract regressions.
|
||||
- [Phase 06]: Retain all four earlier accepted risks unchanged; T-06-23 through T-06-27 are mitigated, not accepted or deferred. — Both repositories' authoritative race and vet gates passed, and each new threat has concrete source and named regression evidence.
|
||||
- [Phase 06]: Anonymous inline limiter identity is documented only as inline:domainless|<ClientIP>, excluding policy text and request or forwarded Host inputs. — The production resolver and three executed regressions prove Host rotation and inline-parameter changes cannot create fresh anonymous budgets while authenticated principals keep isolated u:<id> keys.
|
||||
- [Phase 07]: Blacklist storage expiry follows PHP jwt-auth (later of exp and iat+refreshTTL, plus one minute). — Using the raw access exp would drop a logged-out token that is still inside the refresh window.
|
||||
|
||||
### Pending Todos
|
||||
|
||||
@@ -212,6 +214,6 @@ Items acknowledged and carried forward from previous milestone close:
|
||||
|
||||
## Session Continuity
|
||||
|
||||
Last session: 2026-09-21T22:24:22.108Z
|
||||
Stopped at: Phase 7 context gathered
|
||||
Resume file: .planning/phases/07-user-plugin-and-authentication/07-CONTEXT.md
|
||||
Last session: 2026-09-22T11:42:50.114Z
|
||||
Stopped at: Completed 07-01-PLAN.md
|
||||
Resume file: None
|
||||
|
||||
Reference in New Issue
Block a user