docs(06): create phase plan
This commit is contained in:
@@ -223,7 +223,25 @@ Plans:
|
||||
4. The guarded outbound fetch helper rejects a non-allow-listed host and enforces a byte cap and timeout on a user-supplied cover URL fetch (manual cover URL, Discogs cover).
|
||||
5. OpenAPI is generated from swaggo/swag annotations on handlers and `openapi-typescript` produces valid TypeScript types from it; CORS and JSON body-size limits match the PHP deployment.
|
||||
|
||||
**Plans**: TBD
|
||||
**Plans**: 5 plans
|
||||
|
||||
Plans:
|
||||
**Wave 1** *(parallel)*
|
||||
|
||||
- [ ] 06-01-PLAN.md — Auth-groups slice: router verb/factory growth, bouncer guard registry, real inv_token guard + inv.scope, genres shared under both auth groups
|
||||
- [ ] 06-04-PLAN.md — SSRF-guarded outbound fetch helper (framework primitive, independent of the other three plans)
|
||||
|
||||
**Wave 2** *(blocked on 06-01)*
|
||||
|
||||
- [ ] 06-02-PLAN.md — Rate limiting: fixed-window Store/Limiter, trusted-proxy client IP, five fonoteka buckets, PublicShareHeaders, remaining route groups declared
|
||||
|
||||
**Wave 3** *(blocked on 06-02)*
|
||||
|
||||
- [ ] 06-03-PLAN.md — Contract surface: raw-group enforcement + route table + route:list, wire response helpers, swag/openapi-typescript pipeline, path-scoped CORS, body limits (blocking human-verify checkpoint for production body-size numbers), oauth group declared raw
|
||||
|
||||
**Wave 4** *(blocked on 06-01..06-04)*
|
||||
|
||||
- [ ] 06-05-PLAN.md — Full unit coverage across both repos, full route-table mutual-exclusivity test, 06-SECURITY-REVIEW.md
|
||||
|
||||
### Phase 7: User plugin and authentication
|
||||
|
||||
|
||||
Reference in New Issue
Block a user