docs(09-02): complete backend identity lifecycle plan

- Record the migration, JWT lifecycle, and admin command results
This commit is contained in:
Jakub Zych
2026-09-24 17:59:31 +02:00
parent 5f218977e4
commit af3312aa92
3 changed files with 257 additions and 10 deletions

View File

@@ -4,16 +4,16 @@ milestone: v1.0
current_phase: 09
current_phase_name: Backend admin authentication and schema pipeline
status: executing
stopped_at: Completed 09-01-PLAN.md
last_updated: "2026-09-24T15:22:53.884Z"
stopped_at: Completed 09-02-PLAN.md
last_updated: "2026-09-24T15:59:20.547Z"
last_activity: 2026-09-24
last_activity_desc: Phase 09 execution started
state_head: 18b2e851063f3a50b7a13c87413ac4ae3ece9998
state_head: 5f218977e4cc61b103a3be4e459fe5aa6962006f
progress:
total_phases: 15
completed_phases: 8
total_plans: 67
completed_plans: 56
completed_plans: 57
milestone_name: milestone
---
@@ -29,7 +29,7 @@ See: .planning/PROJECT.md (updated 2026-09-16)
## Current Position
Phase: 09 (Backend admin authentication and schema pipeline) — EXECUTING
Plan: 2 of 12
Plan: 3 of 12
Status: Ready to execute
Last activity: 2026-09-24 — Phase 09 execution started
@@ -110,6 +110,7 @@ Progress: [██████████] 100%
| Plan | Duration | Tasks | Files |
|------|----------|-------|-------|
| Phase 09 P01 | 26min | 2 tasks | 26 files |
| Phase 09 P02 | 22 min | 3 tasks | 14 files |
## Accumulated Context
@@ -272,6 +273,9 @@ Recent decisions affecting current work:
- [Phase 09]: Frontend verification accepts PHP tokens that omit aud and rejects any other explicit audience
- [Phase 09]: Backend JWTs require aud=backend, use admin.jwt.secret, and omit the PHP user prv hash
- [Phase 09]: Cabana mounts from BuildRouter only when a plugin registers admin controllers; an empty admin.jwt.secret fails that assembly
- [Phase 09]: Admin jti rows live in backend_jwt_blacklist and cabana does not republish the frontend BlacklistStore — Refresh and logout must not revoke frontend tokens or be revoked by them.
- [Phase 09]: backend_user_roles.code is indexed and not unique so Winter rows can repeat a code — admin:create rejects zero or many matches instead of a unique constraint the cutover table does not have.
- [Phase 09]: tokens_valid_after is a nullable additive column used to revoke admin JWTs on password reset — The guard already honors Principal.TokensValidAfter and Winter's required columns stay unchanged.
### Pending Todos
@@ -294,6 +298,6 @@ Items acknowledged and carried forward from previous milestone close:
## Session Continuity
Last session: 2026-09-24T15:22:53.442Z
Stopped at: Completed 09-01-PLAN.md
Last session: 2026-09-24T15:59:20.134Z
Stopped at: Completed 09-02-PLAN.md
Resume file: None