From af588aee2dcdbb6eb88fdcb7395cf37fae0462a2 Mon Sep 17 00:00:00 2001 From: Jakub Zych Date: Sun, 4 Oct 2026 22:53:28 +0200 Subject: [PATCH] docs: record quick task 261004-rou --- .../261004-rou-PLAN.md | 59 +++++++++++++++++++ .../261004-rou-SUMMARY.md | 40 +++++++++++++ 2 files changed, 99 insertions(+) create mode 100644 .planning/quick/261004-rou-move-user-api-tokens-from-fonoteka-plugi/261004-rou-PLAN.md create mode 100644 .planning/quick/261004-rou-move-user-api-tokens-from-fonoteka-plugi/261004-rou-SUMMARY.md diff --git a/.planning/quick/261004-rou-move-user-api-tokens-from-fonoteka-plugi/261004-rou-PLAN.md b/.planning/quick/261004-rou-move-user-api-tokens-from-fonoteka-plugi/261004-rou-PLAN.md new file mode 100644 index 0000000..1565bf3 --- /dev/null +++ b/.planning/quick/261004-rou-move-user-api-tokens-from-fonoteka-plugi/261004-rou-PLAN.md @@ -0,0 +1,59 @@ +--- +phase: quick-261004-rou +plan: 01 +type: execute +wave: 1 +depends_on: [] +autonomous: true +requirements: [QUICK-261004-rou] +files_modified: + - ../fonoteka.go/plugins/golem15/user/** + - ../fonoteka.go/plugins/golem15/fonoteka/** + - ../fonoteka.go/config/** + - ../fonoteka.go/parity/** + - ../sm-bm-app/plugins/golem15/user + - ../sm-bm-app/plugins/jz/bm/** + - ../sm-bm-app/plugins/jz/bm + - .planning/STATE.md + - .planning/quick/261004-rou-move-user-api-tokens-from-fonoteka-plugi/** +--- + +# Quick 261004-rou: Move User API Tokens to sm-user-plugin + +## Objective + +Make `golem15.user` the single owner of personal API-token persistence, minting, authentication, scope checks, management commands/routes, and user permission grants. Fonoteka and BM must consume the same token credential so one token can reach multiple plugin APIs, with each plugin still enforcing its own domain access and the authenticated user's group permissions. + +Existing Fonoteka `inv_` tokens, OAuth links, MCP route names, response shapes, collection pins, and PHP parity must remain valid. The uncommitted BM management-API work is preserved, but its plugin-local `bm_` table, model, guard, and token commands are replaced rather than committed as a second token system. + +## Tasks + +### Task 1: Add shared API-token ownership to sm-user-plugin + +- Add the `user_api_tokens` model and migration, token manager/guard, shared `user.api_token` middleware, `user.scope:` factory, generic token management routes and `user:token:*` commands. +- Load user-group permission JSON into `bouncer.Principal.PermissionGrants` for both JWT and API-token authentication, and cover grant parsing/authentication/scope/management behavior with tests. +- Keep token secrets one-time-only and SHA-256 hashed, preserve expiry/revocation/last-use metadata, support configurable prefixes, and retain the Fonoteka extension columns needed for compatibility. +- Update the plugin README and configuration reference. + +### Task 2: Migrate Fonoteka to the shared token credential without breaking parity + +- Replace the Fonoteka-owned token model/guard/manager with aliases or calls into sm-user-plugin; keep `inv_token` and `inv.scope:*` as compatibility middleware names. +- Add a data migration from `golem15_fonoteka_api_tokens` to `user_api_tokens`, preserving IDs, hashes, scopes, collection pins, OAuth client links, timestamps, and refresh-token foreign keys. +- Keep Fonoteka's existing token-management and OAuth endpoints byte-compatible while using the shared row/guard underneath; configure `inv_` as this application's minting prefix. +- Update direct SQL/tests/fixtures and run focused plus full Fonoteka tests. + +### Task 3: Refactor BM management API to consume shared user tokens + +- Preserve the current uncommitted management endpoints, but remove the plugin-local API-token model, migration, guard, and `bm:token:*` commands. +- Protect BM management routes with `user.api_token` and `user.scope:*`; enforce BM permission codes from the authenticated user's group-derived grants. +- Update BM's sm-user-plugin submodule pointer and app/plugin tests, ensuring a token minted once by the user plugin authenticates the BM API. +- Commit code atomically in each affected repository, then write the quick-task summary and update `.planning/STATE.md` without disturbing unrelated working-tree changes. + +## Verification + +- `gofmt` clean in all touched Go trees. +- `GOWORK=off go test ./...` and `go vet ./...` in sm-user-plugin. +- Focused token, migration, OAuth, route, and parity tests in Fonoteka; then its full relevant suite. +- Focused management API and plugin tests in sm-bm-plugin, plus application build/test gates available in sm-bm-app. +- No live token secret is persisted or logged; old Fonoteka tokens authenticate after migration; one shared token authenticates both Fonoteka and BM plugin routes subject to scopes and user permissions. + diff --git a/.planning/quick/261004-rou-move-user-api-tokens-from-fonoteka-plugi/261004-rou-SUMMARY.md b/.planning/quick/261004-rou-move-user-api-tokens-from-fonoteka-plugi/261004-rou-SUMMARY.md new file mode 100644 index 0000000..fa89212 --- /dev/null +++ b/.planning/quick/261004-rou-move-user-api-tokens-from-fonoteka-plugi/261004-rou-SUMMARY.md @@ -0,0 +1,40 @@ +--- +phase: quick-261004-rou +plan: 01 +status: complete +completed: 2026-10-04 +commits: + sm-user-plugin: 0fe5b91 + fonoteka: d1abcab +--- + +# Quick 261004-rou Summary + +`golem15.user` now owns application-wide API tokens: persistence, minting, +authentication, scopes, management routes/commands, and current user-group +permission grants. Raw secrets remain one-time-only and only SHA-256 hashes +are persisted. + +Fonoteka now uses that shared model and guard while preserving its `inv_` +prefix, `inv_token`/`inv.scope:*` middleware contracts, collection pins, +OAuth behavior, and existing endpoints. Its transition migration preserves +legacy hashes and metadata, handles ID collisions, repoints OAuth refresh-token +foreign keys, and supports a lossless rollback. + +BM's management API was refactored to consume `user.api_token`, `user.scope:*`, +and current group permissions. Per user direction, BM and Quizzes were not +committed; the tested BM changes and User submodule bump remain in the BM +working tree for its dedicated dev-agent to review and commit. + +## Verification + +- sm-user-plugin: `GOWORK=off go test ./...`, `GOWORK=off go vet ./...` +- Fonoteka application: `go test ./...`, `go vet ./...` +- Fonoteka plugin: `go test ./...`, `go vet ./...` +- BM plugin handoff: `GOWORK=off go test ./...`, `GOWORK=off go vet ./...`, `git diff --check` +- Migration test covers legacy-token data, an ID collision, OAuth FK retarget, + and reverse rollback. +- BM end-to-end test proves the same shared token follows live group-permission + grants and revocation. + +No SummerCMS framework change was required.