docs(06): reopen phase after verification gaps
This commit is contained in:
@@ -53,10 +53,10 @@ Requirements for v1 (the Płytarium port). Each maps to roadmap phases. "User" b
|
|||||||
- [x] **HTTP-01**: Plugins register route groups on net/http ServeMux with typed params and regex constraints; unknown and malformed ids both return 404 on ownership-scoped resources
|
- [x] **HTTP-01**: Plugins register route groups on net/http ServeMux with typed params and regex constraints; unknown and malformed ids both return 404 on ownership-scoped resources
|
||||||
- [x] **HTTP-02**: Plugins register named middleware that other plugins reference by name; the pipeline order is recover, CORS, locale, auth group, must-change-password, org context, rate limit, handler
|
- [x] **HTTP-02**: Plugins register named middleware that other plugins reference by name; the pipeline order is recover, CORS, locale, auth group, must-change-password, org context, rate limit, handler
|
||||||
- [x] **HTTP-03**: Three mutually exclusive auth groups share the same handlers with different route subsets: JWT under /_fonoteka/api/v1, personal scoped token under /api/v1/fonoteka, and public groups (onboarding, public/{token}, public-wishlist/{token}, invitation inspection)
|
- [x] **HTTP-03**: Three mutually exclusive auth groups share the same handlers with different route subsets: JWT under /_fonoteka/api/v1, personal scoped token under /api/v1/fonoteka, and public groups (onboarding, public/{token}, public-wishlist/{token}, invitation inspection)
|
||||||
- [x] **HTTP-04**: A rate limiter supports named buckets keyed by a resolver (token id, IP, route param), stacking two limiters on one route, and ports Płytarium's five named buckets and inline throttles 1:1
|
- [ ] **HTTP-04**: A rate limiter supports named buckets keyed by a resolver (token id, IP, route param), stacking two limiters on one route, and ports Płytarium's five named buckets and inline throttles 1:1
|
||||||
- [x] **HTTP-05**: An auth guard registry lets plugins add guards (JWT, personal token, OAuth bearer) that all resolve to the same current-user accessor
|
- [x] **HTTP-05**: An auth guard registry lets plugins add guards (JWT, personal token, OAuth bearer) that all resolve to the same current-user accessor
|
||||||
- [x] **HTTP-06**: Response conventions are preserved: empty arrays serialize as [], timestamps as +00:00, tri-state booleans keep null, conditional keys are omitted not nulled, and no blanket envelope or error middleware wraps OAuth routes
|
- [ ] **HTTP-06**: Response conventions are preserved: empty arrays serialize as [], timestamps as +00:00, tri-state booleans keep null, conditional keys are omitted not nulled, and no blanket envelope or error middleware wraps OAuth routes
|
||||||
- [x] **HTTP-07**: A guarded outbound fetch helper enforces host allow-lists, byte caps and timeouts for user-supplied URLs (manual cover URL, Discogs cover)
|
- [ ] **HTTP-07**: A guarded outbound fetch helper enforces host allow-lists, byte caps and timeouts for user-supplied URLs (manual cover URL, Discogs cover)
|
||||||
- [x] **HTTP-08**: OpenAPI is generated from swaggo/swag annotations on handlers and openapi-typescript produces the admin SPA's types
|
- [x] **HTTP-08**: OpenAPI is generated from swaggo/swag annotations on handlers and openapi-typescript produces the admin SPA's types
|
||||||
- [x] **HTTP-09**: CORS and JSON body size limits match the PHP deployment
|
- [x] **HTTP-09**: CORS and JSON body size limits match the PHP deployment
|
||||||
|
|
||||||
@@ -188,8 +188,8 @@ Which phases cover which requirements. Updated during roadmap creation.
|
|||||||
| HTTP-03 | Phase 6 | Complete |
|
| HTTP-03 | Phase 6 | Complete |
|
||||||
| HTTP-04 | Phase 6 | In Progress |
|
| HTTP-04 | Phase 6 | In Progress |
|
||||||
| HTTP-05 | Phase 6 | Complete |
|
| HTTP-05 | Phase 6 | Complete |
|
||||||
| HTTP-06 | Phase 6 | Complete |
|
| HTTP-06 | Phase 6 | In Progress |
|
||||||
| HTTP-07 | Phase 6 | Complete |
|
| HTTP-07 | Phase 6 | In Progress |
|
||||||
| HTTP-08 | Phase 6 | Complete |
|
| HTTP-08 | Phase 6 | Complete |
|
||||||
| HTTP-09 | Phase 6 | Complete |
|
| HTTP-09 | Phase 6 | Complete |
|
||||||
| AUTH-01 | Phase 7 | Pending |
|
| AUTH-01 | Phase 7 | Pending |
|
||||||
|
|||||||
@@ -18,7 +18,7 @@ Decimal phases appear between their surrounding integers in numeric order.
|
|||||||
- [x] **Phase 3: First vertical slice — genres end to end** - `GET /_fonoteka/api/v1/genres` passes the parity diff through every layer (completed 2026-09-17)
|
- [x] **Phase 3: First vertical slice — genres end to end** - `GET /_fonoteka/api/v1/genres` passes the parity diff through every layer (completed 2026-09-17)
|
||||||
- [x] **Phase 4: CLI scaffolding, i18n and mail** - Scaffolding commands, translated/pluralized strings, mail templates (completed 2026-09-18)
|
- [x] **Phase 4: CLI scaffolding, i18n and mail** - Scaffolding commands, translated/pluralized strings, mail templates (completed 2026-09-18)
|
||||||
- [x] **Phase 5: Data layer full fidelity** - All 25 models and their squashed migrations with fillable/hidden/cast/soft-delete discipline (completed 2026-09-18)
|
- [x] **Phase 5: Data layer full fidelity** - All 25 models and their squashed migrations with fillable/hidden/cast/soft-delete discipline (completed 2026-09-18)
|
||||||
- [x] **Phase 6: HTTP routing, auth groups and rate limiting** - Three auth groups, named rate buckets, OAuth-safe middleware structure (completed 2026-09-20)
|
- [ ] **Phase 6: HTTP routing, auth groups and rate limiting** - Three auth groups, named rate buckets, OAuth-safe middleware structure
|
||||||
- [ ] **Phase 7: User plugin and authentication** - Registration, login, JWT, organizations, personal tokens, must-change-password
|
- [ ] **Phase 7: User plugin and authentication** - Registration, login, JWT, organizations, personal tokens, must-change-password
|
||||||
- [ ] **Phase 8: OAuth2.1 authorization server** - zitadel/oidc server for fonoteka-mcp and the ChatGPT connector
|
- [ ] **Phase 8: OAuth2.1 authorization server** - zitadel/oidc server for fonoteka-mcp and the ChatGPT connector
|
||||||
- [ ] **Phase 9: Backend admin authentication and schema pipeline** - Admin roles, fields.yaml/columns.yaml, relation manager
|
- [ ] **Phase 9: Backend admin authentication and schema pipeline** - Admin roles, fields.yaml/columns.yaml, relation manager
|
||||||
@@ -414,7 +414,7 @@ Phases execute in numeric order: 1 → 2 → 3 → 4 → 5 → 6 → 7 → 8 →
|
|||||||
| 3. First vertical slice — genres end to end | 4/4 | Complete | 2026-09-17 |
|
| 3. First vertical slice — genres end to end | 4/4 | Complete | 2026-09-17 |
|
||||||
| 4. CLI scaffolding, i18n and mail | 4/4 | Complete | 2026-09-18 |
|
| 4. CLI scaffolding, i18n and mail | 4/4 | Complete | 2026-09-18 |
|
||||||
| 5. Data layer full fidelity | 6/6 | Complete | 2026-09-18 |
|
| 5. Data layer full fidelity | 6/6 | Complete | 2026-09-18 |
|
||||||
| 6. HTTP routing, auth groups and rate limiting | 6/6 | Complete | 2026-09-20 |
|
| 6. HTTP routing, auth groups and rate limiting | 6/6 | Gaps found | - |
|
||||||
| 7. User plugin and authentication | 0/TBD | Not started | - |
|
| 7. User plugin and authentication | 0/TBD | Not started | - |
|
||||||
| 8. OAuth2.1 authorization server | 0/TBD | Not started | - |
|
| 8. OAuth2.1 authorization server | 0/TBD | Not started | - |
|
||||||
| 9. Backend admin authentication and schema pipeline | 0/TBD | Not started | - |
|
| 9. Backend admin authentication and schema pipeline | 0/TBD | Not started | - |
|
||||||
|
|||||||
@@ -8,10 +8,10 @@ last_updated: "2026-09-20T11:32:44.614Z"
|
|||||||
last_activity: 2026-09-20
|
last_activity: 2026-09-20
|
||||||
progress:
|
progress:
|
||||||
total_phases: 15
|
total_phases: 15
|
||||||
completed_phases: 6
|
completed_phases: 5
|
||||||
total_plans: 29
|
total_plans: 29
|
||||||
completed_plans: 29
|
completed_plans: 29
|
||||||
percent: 40
|
percent: 33
|
||||||
---
|
---
|
||||||
|
|
||||||
# Project State
|
# Project State
|
||||||
@@ -27,7 +27,7 @@ See: .planning/PROJECT.md (updated 2026-09-16)
|
|||||||
|
|
||||||
Phase: 06 (http-routing-auth-groups-and-rate-limiting) — EXECUTING
|
Phase: 06 (http-routing-auth-groups-and-rate-limiting) — EXECUTING
|
||||||
Plan: 6 of 6
|
Plan: 6 of 6
|
||||||
Status: Ready to execute
|
Status: Gaps found
|
||||||
Last activity: 2026-09-20
|
Last activity: 2026-09-20
|
||||||
|
|
||||||
Progress: [██████████] 100%
|
Progress: [██████████] 100%
|
||||||
@@ -36,7 +36,7 @@ Progress: [██████████] 100%
|
|||||||
|
|
||||||
**Velocity:**
|
**Velocity:**
|
||||||
|
|
||||||
- Total plans completed: 28
|
- Total plans completed: 29
|
||||||
- Average duration: 21 min
|
- Average duration: 21 min
|
||||||
- Total execution time: 104 min
|
- Total execution time: 104 min
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user