docs(06): create phase plan

This commit is contained in:
Jakub Zych
2026-09-19 16:58:48 +02:00
parent 6a9f5e1b47
commit c4f406bb64
8 changed files with 2071 additions and 26 deletions

View File

@@ -223,7 +223,25 @@ Plans:
4. The guarded outbound fetch helper rejects a non-allow-listed host and enforces a byte cap and timeout on a user-supplied cover URL fetch (manual cover URL, Discogs cover).
5. OpenAPI is generated from swaggo/swag annotations on handlers and `openapi-typescript` produces valid TypeScript types from it; CORS and JSON body-size limits match the PHP deployment.
**Plans**: TBD
**Plans**: 5 plans
Plans:
**Wave 1** *(parallel)*
- [ ] 06-01-PLAN.md — Auth-groups slice: router verb/factory growth, bouncer guard registry, real inv_token guard + inv.scope, genres shared under both auth groups
- [ ] 06-04-PLAN.md — SSRF-guarded outbound fetch helper (framework primitive, independent of the other three plans)
**Wave 2** *(blocked on 06-01)*
- [ ] 06-02-PLAN.md — Rate limiting: fixed-window Store/Limiter, trusted-proxy client IP, five fonoteka buckets, PublicShareHeaders, remaining route groups declared
**Wave 3** *(blocked on 06-02)*
- [ ] 06-03-PLAN.md — Contract surface: raw-group enforcement + route table + route:list, wire response helpers, swag/openapi-typescript pipeline, path-scoped CORS, body limits (blocking human-verify checkpoint for production body-size numbers), oauth group declared raw
**Wave 4** *(blocked on 06-01..06-04)*
- [ ] 06-05-PLAN.md — Full unit coverage across both repos, full route-table mutual-exclusivity test, 06-SECURITY-REVIEW.md
### Phase 7: User plugin and authentication