docs(09-02): complete backend identity lifecycle plan
- Record the migration, JWT lifecycle, and admin command results
This commit is contained in:
@@ -4,16 +4,16 @@ milestone: v1.0
|
||||
current_phase: 09
|
||||
current_phase_name: Backend admin authentication and schema pipeline
|
||||
status: executing
|
||||
stopped_at: Completed 09-01-PLAN.md
|
||||
last_updated: "2026-09-24T15:22:53.884Z"
|
||||
stopped_at: Completed 09-02-PLAN.md
|
||||
last_updated: "2026-09-24T15:59:20.547Z"
|
||||
last_activity: 2026-09-24
|
||||
last_activity_desc: Phase 09 execution started
|
||||
state_head: 18b2e851063f3a50b7a13c87413ac4ae3ece9998
|
||||
state_head: 5f218977e4cc61b103a3be4e459fe5aa6962006f
|
||||
progress:
|
||||
total_phases: 15
|
||||
completed_phases: 8
|
||||
total_plans: 67
|
||||
completed_plans: 56
|
||||
completed_plans: 57
|
||||
milestone_name: milestone
|
||||
---
|
||||
|
||||
@@ -29,7 +29,7 @@ See: .planning/PROJECT.md (updated 2026-09-16)
|
||||
## Current Position
|
||||
|
||||
Phase: 09 (Backend admin authentication and schema pipeline) — EXECUTING
|
||||
Plan: 2 of 12
|
||||
Plan: 3 of 12
|
||||
Status: Ready to execute
|
||||
Last activity: 2026-09-24 — Phase 09 execution started
|
||||
|
||||
@@ -110,6 +110,7 @@ Progress: [██████████] 100%
|
||||
| Plan | Duration | Tasks | Files |
|
||||
|------|----------|-------|-------|
|
||||
| Phase 09 P01 | 26min | 2 tasks | 26 files |
|
||||
| Phase 09 P02 | 22 min | 3 tasks | 14 files |
|
||||
|
||||
## Accumulated Context
|
||||
|
||||
@@ -272,6 +273,9 @@ Recent decisions affecting current work:
|
||||
- [Phase 09]: Frontend verification accepts PHP tokens that omit aud and rejects any other explicit audience
|
||||
- [Phase 09]: Backend JWTs require aud=backend, use admin.jwt.secret, and omit the PHP user prv hash
|
||||
- [Phase 09]: Cabana mounts from BuildRouter only when a plugin registers admin controllers; an empty admin.jwt.secret fails that assembly
|
||||
- [Phase 09]: Admin jti rows live in backend_jwt_blacklist and cabana does not republish the frontend BlacklistStore — Refresh and logout must not revoke frontend tokens or be revoked by them.
|
||||
- [Phase 09]: backend_user_roles.code is indexed and not unique so Winter rows can repeat a code — admin:create rejects zero or many matches instead of a unique constraint the cutover table does not have.
|
||||
- [Phase 09]: tokens_valid_after is a nullable additive column used to revoke admin JWTs on password reset — The guard already honors Principal.TokensValidAfter and Winter's required columns stay unchanged.
|
||||
|
||||
### Pending Todos
|
||||
|
||||
@@ -294,6 +298,6 @@ Items acknowledged and carried forward from previous milestone close:
|
||||
|
||||
## Session Continuity
|
||||
|
||||
Last session: 2026-09-24T15:22:53.442Z
|
||||
Stopped at: Completed 09-01-PLAN.md
|
||||
Last session: 2026-09-24T15:59:20.134Z
|
||||
Stopped at: Completed 09-02-PLAN.md
|
||||
Resume file: None
|
||||
|
||||
Reference in New Issue
Block a user