docs(12): create phase plan
This commit is contained in:
@@ -23,7 +23,7 @@ created: "2026-10-02"
|
||||
| **Config file** | none (`parity/parity_test.go` TestMain starts Postgres) |
|
||||
| **Quick run command** | `cd fonoteka.go && go test ./plugins/golem15/fonoteka/... -short -count=1` |
|
||||
| **Full suite command** | `cd fonoteka.go && go vet ./... && go test ./... -count=1`, plus `cd summercms.go && go vet ./... && go test ./... -count=1` for framework changes |
|
||||
| **Parity command** | `cd fonoteka.go && go test ./parity -run 'TestParityCorpus|TestBroadcastGoldens|TestNuxtFlow' -count=1` |
|
||||
| **Parity command** | `cd fonoteka.go && go test ./parity -run 'TestParityCorpus|TestBroadcastGoldens|TestFonotekaNuxtFlows' -count=1` |
|
||||
| **Estimated runtime** | ~180 seconds (full suite, both repos, with containers) |
|
||||
|
||||
---
|
||||
@@ -39,15 +39,26 @@ created: "2026-10-02"
|
||||
|
||||
## Per-Task Verification Map
|
||||
|
||||
Seeded from RESEARCH.md by requirement; task IDs are filled in once PLAN.md files exist.
|
||||
Task IDs are `<plan>-T<task>`. Framework commands run from `summercms.go`; application commands use `go -C ../fonoteka.go`. Plan 12-05 Task 3 replaces the Status and File Exists columns with run evidence and `scripts/check-phase12.sh --named` runs every named test by exact name.
|
||||
|
||||
| Task ID | Plan | Wave | Requirement | Threat Ref | Secure Behavior | Test Type | Automated Command | File Exists | Status |
|
||||
|---------|------|------|-------------|------------|-----------------|-----------|-------------------|-------------|--------|
|
||||
| TBD | 01 | 1 | framework | — | beachcomber `found`/weights, tide multipart + URL mask, Laravel-semantics validator + catalogs, attach URL export | unit | `cd summercms.go && go test ./modules/... -count=1` | ❌ W0 | ⬜ pending |
|
||||
| TBD | 02 | 2 | API-01 | T-12-01, T-12-03, T-12-04, T-12-05 | Collections, switch, me/context, realtime/channels, share replays; token pin and narrowing | parity + integration | `go test ./parity -run TestParityCorpus/.*collection` | ❌ W0 | ⬜ pending |
|
||||
| TBD | 03 | 3 | API-01 | T-12-06, T-12-07 | Invite mail enqueued in tx, absent on rollback; token encrypted in job args, never logged | integration + parity flow | `go test ./parity -run TestNuxtFlow/nuxt-collections` | ❌ W0 | ⬜ pending |
|
||||
| TBD | 04 | 4 | API-02 | T-12-02, T-12-09, T-12-10, T-12-11 | Album CRUD, rating, photos, bulk, stats/value/missing/sync, search, lookups; upload guard; SSRF guard | parity + integration | `go test ./parity -run 'TestParityCorpus/.*albums|TestBroadcastGoldens'` | ❌ W0 | ⬜ pending |
|
||||
| TBD | 05 | 5 | API-01, API-02 | T-12-01..T-12-11 | D-18 leak test (5 cases + total), request-DTO fuzz, route-table single-scope test | security + fuzz + unit | `go test ./plugins/golem15/fonoteka/... -run 'TestSearchLeak|TestRouteTable|FuzzWriteEndpoints' -count=1` | ❌ W0 | ⬜ pending |
|
||||
| 12-01-T1 | 12-01 | 1 | API-01, API-02 | T-12-14, T-12-15 | Laravel 9 request validation (implicit stop, wildcards, size-typed messages, pl/en catalogs); lagoon.Validate min/between fix keeps user-api bodies | unit | `go test ./modules/lagoon -run '^(TestValidateRequest.*\|TestValidate.*Message.*)$' -count=1 -v` | ❌ W0 | ⬜ pending |
|
||||
| 12-01-T2 | 12-01 | 1 | API-01, API-02 | T-12-16, T-12-17 | Winter upload URLs (URL, PublicURL), webp decode, tide multipart parts with sha256, upload URL and publication date masks | unit | `go test ./modules/lagoon/attach ./modules/tide -run '^(TestFileURLWinterLayout\|TestThumbWebP\|TestMultipart.*\|TestNormalizeUploadURL.*\|TestNormalizePublication.*)$' -count=1 -v` | ❌ W0 | ⬜ pending |
|
||||
| 12-01-T3 | 12-01 | 1 | API-01, API-02 | T-12-28, T-12-18 | beachcomber SearchPage found and query_by_weights; user groups additive (user-api payload unchanged) | unit + integration | `go test ./modules/beachcomber/... -run '^(TestSearchPage.*\|TestTypesenseSearchPage.*)$' -count=1 -v && go -C ../fonoteka.go test ./plugins/golem15/user/updates -run '^(TestUserGroups.*)$' -count=1 -v` | ❌ W0 | ⬜ pending |
|
||||
| 12-01-T4 | 12-01 | 1 | API-01, API-02 | — | ROADMAP/REQUIREMENTS reworded per D-03, D-04, D-06, D-19, D-20 | docs check | `grep -q 'realtime/channels' .planning/ROADMAP.md && grep -q 'realtime/channels' .planning/REQUIREMENTS.md` | ✅ | ⬜ pending |
|
||||
| 12-02-T1 | 12-02 | 2 | API-01 | T-12-01, T-12-03, T-12-12 | Token-aware resolver, AccessibleBy narrowing, one-time provisioning under locks, collections list on both groups, per-route scopes (D-26) | integration + parity | `go -C ../fonoteka.go test ./plugins/golem15/fonoteka -run '^(TestCollectionsIndexBothGroups\|TestResolveProvisionsOnce)$' -count=1 -race -v` | ❌ W0 | ⬜ pending |
|
||||
| 12-02-T2 | 12-02 | 2 | API-01 | T-12-05, T-12-29, T-12-30, T-12-19 | Collection CRUD, per-album delete (D-26), photos and image uploads, switch with Winter 404 page | integration + parity | `go -C ../fonoteka.go test ./plugins/golem15/fonoteka -run '^(TestCollectionDeleteRemovesAlbumsOneByOne\|TestCollectionPhotoUpload\|TestCollectionSwitchRefusals)$' -count=1 -race -v` | ❌ W0 | ⬜ pending |
|
||||
| 12-02-T3 | 12-02 | 2 | API-01 | T-12-04, T-12-08, T-12-13 | me/context flags (site admin via groups), realtime/channels, owner-only share with crypto/rand token | integration + parity | `go -C ../fonoteka.go test ./plugins/golem15/fonoteka -run '^(TestMeContextFlags\|TestRealtimeChannelsName\|TestShareTokenAlphabet\|TestShareOwnerOnly)$' -count=1 -race -v` | ❌ W0 | ⬜ pending |
|
||||
| 12-03-T1 | 12-03 | 3 | API-01 | T-12-06, T-12-07, T-12-22 | Invite mail job enqueued in tx with encrypted token, absent on rollback; accept adds editor and notification | integration + parity | `go -C ../fonoteka.go test ./plugins/golem15/fonoteka -run '^(TestInvitationMailEnqueuedInTx\|TestInvitationAcceptAddsEditor)$' -count=1 -race -v` | ❌ W0 | ⬜ pending |
|
||||
| 12-03-T2 | 12-03 | 3 | API-01 | T-12-31, T-12-32, T-12-21 | Owner-only household management, member removal repairs context, pending-invitation 409 guard, single accept under concurrency | integration + parity | `go -C ../fonoteka.go test ./plugins/golem15/fonoteka -run '^(TestRemoveEditorRepairsContext\|TestPendingInvitationGuard\|TestConcurrentAcceptSingleEditor)$' -count=1 -race -v` | ❌ W0 | ⬜ pending |
|
||||
| 12-03-T3 | 12-03 | 3 | API-01 | T-12-20 | nuxt-collections flow replay; ValidationException envelopes; no raw invitation token in the corpus | parity flow | `go -C ../fonoteka.go test ./parity -run '^(TestFonotekaNuxtFlows\|TestParityCorpus\|TestCheckCorpus.*)$' -count=1 -v` | ❌ W0 | ⬜ pending |
|
||||
| 12-04-T1 | 12-04 | 4 | API-02 | T-12-11, T-12-23 | Album create on both groups, single created event, album_added notifications, created golden asserted | integration + parity | `go -C ../fonoteka.go test ./plugins/golem15/fonoteka -run '^(TestAlbumStoreSingleCreatedEvent\|TestAlbumAddedNotifiesHousehold\|TestAlbumWriteHelpersMatchPHP)$' -count=1 -race -v` | ❌ W0 | ⬜ pending |
|
||||
| 12-04-T2 | 12-04 | 4 | API-02 | T-12-33, T-12-09, T-12-10, T-12-24 | Album CRUD, ratings, uploads with image guard, SSRF-guarded cover fetches after commit, bulk single summary, stats/value/missing/sync | integration + parity | `go -C ../fonoteka.go test ./plugins/golem15/fonoteka -run '^(TestCoverImportAfterCommit\|TestManualCoverReasons\|TestAlbumPhotoUpload\|TestBulkSingleSummaryEvent\|TestRatingUpsertConcurrent\|TestAlbumValueFormatting)$' -count=1 -race -v` | ❌ W0 | ⬜ pending |
|
||||
| 12-04-T3 | 12-04 | 4 | API-02 | T-12-02, T-12-34 | Search SQL escaping and Scout-exact recount, lookups, nuxt-albums flow, 99 ported routes | integration + parity | `go -C ../fonoteka.go test ./plugins/golem15/fonoteka -run '^(TestAlbumSearchSQLEscaping\|TestAlbumSearchTypesenseRecount)$' -count=1 -race -v && go -C ../fonoteka.go test ./parity -run '^(TestFonotekaNuxtFlows\|TestParityCorpus\|TestBroadcastGoldens)$' -count=1 -v` | ❌ W0 | ⬜ pending |
|
||||
| 12-05-T1 | 12-05 | 5 | API-02 | T-12-02, T-12-28 | D-18 leak test (5 cases) with D-19 total and cap on both groups | security | `go -C ../fonoteka.go test ./plugins/golem15/fonoteka -run '^TestSearchLeak$' -count=1 -race -v` | ❌ W0 | ⬜ pending |
|
||||
| 12-05-T2 | 12-05 | 5 | API-01, API-02 | T-12-01..T-12-34 | Route-table one-scope test (D-10, D-26), request-DTO fuzz over every write endpoint (C-02), one subtest per threat | security + fuzz | `go -C ../fonoteka.go test ./plugins/golem15/fonoteka -run '^(TestRouteTablePhase12\|FuzzWriteEndpoints\|TestPhase12Threats)$' -count=1 -race -v` | ❌ W0 | ⬜ pending |
|
||||
| 12-05-T3 | 12-05 | 5 | API-01, API-02 | T-12-25, T-12-26, T-12-27 | Full unit coverage (80% floor per package), fail-closed gate with removal mutations, security review and validation sign-off | unit + gate | `scripts/check-phase12.sh --self-test && scripts/check-phase12.sh --all` | ❌ W0 | ⬜ pending |
|
||||
|
||||
*Status: ⬜ pending · ✅ green · ❌ red · ⚠️ flaky*
|
||||
|
||||
@@ -55,10 +66,10 @@ Seeded from RESEARCH.md by requirement; task IDs are filled in once PLAN.md file
|
||||
|
||||
## Wave 0 Requirements
|
||||
|
||||
- [ ] Re-record the HttpException cases under `APP_DEBUG=false` (accept 410, switch 404, household/members 404, invitations 404, token 404) — D-21
|
||||
- [ ] tide request `body_file` (multipart) + `url`/`thumb_url` disk-name normalizer + publication date masking (framework)
|
||||
- [ ] Seed hooks or flows for a second user and an outsider (reuse `id:outsider` from Phase 11)
|
||||
- [ ] Fake `beachcomber` engine with scripted ids and `found` for D-18/D-19
|
||||
- [ ] Re-record the HttpException cases under `APP_DEBUG=false` (accept 410, switch 404, household/members 404, invitations 404, guard 409) — D-21 (12-02-T2, 12-03-T1, 12-03-T2)
|
||||
- [ ] tide request multipart `parts` + `url`/`thumb_url` disk-name normalizer + publication date masking (framework) — 12-01-T2
|
||||
- [ ] Seed hook `fonoteka` with alice, bob (editor), an outsider and personal tokens (reuse the `id:outsider` recipe from Phase 11) — 12-02-T1
|
||||
- [ ] Fake `beachcomber` engine with scripted ids and `found` for D-18/D-19 — smoke in 12-04-T3, full suite in 12-05-T1
|
||||
|
||||
---
|
||||
|
||||
|
||||
Reference in New Issue
Block a user