docs(06-09): update plan tracking

This commit is contained in:
Jakub Zych
2026-09-20 21:08:54 +02:00
parent 158df899f6
commit c9909ce412
3 changed files with 15 additions and 11 deletions

View File

@@ -55,7 +55,7 @@ Requirements for v1 (the Płytarium port). Each maps to roadmap phases. "User" b
- [x] **HTTP-03**: Three mutually exclusive auth groups share the same handlers with different route subsets: JWT under /_fonoteka/api/v1, personal scoped token under /api/v1/fonoteka, and public groups (onboarding, public/{token}, public-wishlist/{token}, invitation inspection) - [x] **HTTP-03**: Three mutually exclusive auth groups share the same handlers with different route subsets: JWT under /_fonoteka/api/v1, personal scoped token under /api/v1/fonoteka, and public groups (onboarding, public/{token}, public-wishlist/{token}, invitation inspection)
- [x] **HTTP-04**: A rate limiter supports named buckets keyed by a resolver (token id, IP, route param), stacking two limiters on one route, and ports Płytarium's five named buckets and inline throttles 1:1 - [x] **HTTP-04**: A rate limiter supports named buckets keyed by a resolver (token id, IP, route param), stacking two limiters on one route, and ports Płytarium's five named buckets and inline throttles 1:1
- [x] **HTTP-05**: An auth guard registry lets plugins add guards (JWT, personal token, OAuth bearer) that all resolve to the same current-user accessor - [x] **HTTP-05**: An auth guard registry lets plugins add guards (JWT, personal token, OAuth bearer) that all resolve to the same current-user accessor
- [ ] **HTTP-06**: Response conventions are preserved: empty arrays serialize as [], timestamps as +00:00, tri-state booleans keep null, conditional keys are omitted not nulled, and no blanket envelope or error middleware wraps OAuth routes - [x] **HTTP-06**: Response conventions are preserved: empty arrays serialize as [], timestamps as +00:00, tri-state booleans keep null, conditional keys are omitted not nulled, and no blanket envelope or error middleware wraps OAuth routes
- [x] **HTTP-07**: A guarded outbound fetch helper enforces host allow-lists, byte caps and timeouts for user-supplied URLs (manual cover URL, Discogs cover) - [x] **HTTP-07**: A guarded outbound fetch helper enforces host allow-lists, byte caps and timeouts for user-supplied URLs (manual cover URL, Discogs cover)
- [x] **HTTP-08**: OpenAPI is generated from swaggo/swag annotations on handlers and openapi-typescript produces the admin SPA's types - [x] **HTTP-08**: OpenAPI is generated from swaggo/swag annotations on handlers and openapi-typescript produces the admin SPA's types
- [x] **HTTP-09**: CORS and JSON body size limits match the PHP deployment - [x] **HTTP-09**: CORS and JSON body size limits match the PHP deployment

View File

@@ -251,7 +251,7 @@ Plans:
- [x] 06-07-PLAN.md — Make limiter admission atomic and remove attacker-controlled Host from inline keys - [x] 06-07-PLAN.md — Make limiter admission atomic and remove attacker-controlled Host from inline keys
- [x] 06-08-PLAN.md — Reject private IPv4 embedded in NAT64 and 6to4 dial addresses - [x] 06-08-PLAN.md — Reject private IPv4 embedded in NAT64 and 6to4 dial addresses
- [ ] 06-09-PLAN.md — Buffer route responses so partial-write panics yield clean raw/house 500s - [x] 06-09-PLAN.md — Buffer route responses so partial-write panics yield clean raw/house 500s
- [ ] 06-10-PLAN.md — Restore exact no-newline InvScope 401/403 wire bodies - [ ] 06-10-PLAN.md — Restore exact no-newline InvScope 401/403 wire bodies
**Wave 7** *(gap closure; blocked on 06-07..06-10)* **Wave 7** *(gap closure; blocked on 06-07..06-10)*
@@ -425,7 +425,7 @@ Phases execute in numeric order: 1 → 2 → 3 → 4 → 5 → 6 → 7 → 8 →
| 3. First vertical slice — genres end to end | 4/4 | Complete | 2026-09-17 | | 3. First vertical slice — genres end to end | 4/4 | Complete | 2026-09-17 |
| 4. CLI scaffolding, i18n and mail | 4/4 | Complete | 2026-09-18 | | 4. CLI scaffolding, i18n and mail | 4/4 | Complete | 2026-09-18 |
| 5. Data layer full fidelity | 6/6 | Complete | 2026-09-18 | | 5. Data layer full fidelity | 6/6 | Complete | 2026-09-18 |
| 6. HTTP routing, auth groups and rate limiting | 8/11 | In Progress| | | 6. HTTP routing, auth groups and rate limiting | 9/11 | In Progress| |
| 7. User plugin and authentication | 0/TBD | Not started | - | | 7. User plugin and authentication | 0/TBD | Not started | - |
| 8. OAuth2.1 authorization server | 0/TBD | Not started | - | | 8. OAuth2.1 authorization server | 0/TBD | Not started | - |
| 9. Backend admin authentication and schema pipeline | 0/TBD | Not started | - | | 9. Backend admin authentication and schema pipeline | 0/TBD | Not started | - |

View File

@@ -3,15 +3,15 @@ gsd_state_version: 1.0
milestone: v1.0 milestone: v1.0
milestone_name: milestone milestone_name: milestone
status: executing status: executing
stopped_at: Completed 06-08-PLAN.md stopped_at: Completed 06-09-PLAN.md
last_updated: "2026-09-20T18:59:52.988Z" last_updated: "2026-09-20T19:08:04.262Z"
last_activity: 2026-09-20 last_activity: 2026-09-20
progress: progress:
total_phases: 15 total_phases: 15
completed_phases: 5 completed_phases: 5
total_plans: 34 total_plans: 34
completed_plans: 31 completed_plans: 32
percent: 91 percent: 33
--- ---
# Project State # Project State
@@ -26,11 +26,11 @@ See: .planning/PROJECT.md (updated 2026-09-16)
## Current Position ## Current Position
Phase: 06 (http-routing-auth-groups-and-rate-limiting) — EXECUTING Phase: 06 (http-routing-auth-groups-and-rate-limiting) — EXECUTING
Plan: 3 of 11 Plan: 4 of 11
Status: Ready to execute Status: Ready to execute
Last activity: 2026-09-20 Last activity: 2026-09-20
Progress: [█████████░] 91% Progress: [█████████░] 94%
## Performance Metrics ## Performance Metrics
@@ -77,6 +77,7 @@ Progress: [█████████░] 91%
| Phase 06 P06 | 1h 29m | 2 tasks | 3 files | | Phase 06 P06 | 1h 29m | 2 tasks | 3 files |
| Phase 06 P07 | 12 min | 1 tasks | 4 files | | Phase 06 P07 | 12 min | 1 tasks | 4 files |
| Phase 06 P08 | 1h 20m | 1 tasks | 3 files | | Phase 06 P08 | 1h 20m | 1 tasks | 3 files |
| Phase 06 P09 | 4 min | 1 tasks | 2 files |
## Accumulated Context ## Accumulated Context
@@ -180,6 +181,9 @@ Recent decisions affecting current work:
- [Phase 06]: Use one inline:domainless namespace plus trusted-proxy ClientIP for every anonymous inline throttle. — Host and inline throttle text must not let anonymous callers rotate rate-limit buckets; authenticated requests retain u:<principal id> isolation. - [Phase 06]: Use one inline:domainless namespace plus trusted-proxy ClientIP for every anonymous inline throttle. — Host and inline throttle text must not let anonymous callers rotate rate-limit buckets; authenticated requests retain u:<principal id> isolation.
- [Phase 06]: isReservedOrPrivate owns Addr.Unmap and recursively applies the ordinary IPv4 table to supported transition embeddings — Direct helper callers and the production dial hook must share one normalization and private/reserved policy. - [Phase 06]: isReservedOrPrivate owns Addr.Unmap and recursively applies the ordinary IPv4 table to supported transition embeddings — Direct helper callers and the production dial hook must share one normalization and private/reserved policy.
- [Phase 06]: A 64:ff9b:1::/48 address with a non-zero RFC 6052 u octet fails closed — Malformed local-use NAT64 must not fall through as apparently public native IPv6. - [Phase 06]: A 64:ff9b:1::/48 address with a non-zero RFC 6052 u octet fails closed — Malformed local-use NAT64 must not fall through as apparently public native IPv6.
- [Phase 06]: Use one unexported bufferedResponse for house and raw recovery — A shared transactional writer keeps panic-before-write and panic-after-write behavior identical while preserving raw versus house fallback bodies.
- [Phase 06]: Keep bufferedResponse Flush as a no-op — Recovery must never unwrap, hijack, flush, or otherwise expose the destination writer before handler success.
- [Phase 06]: Success commit replaces only route-owned header keys — Unrelated headers already placed on the destination by outer wrappers such as path-scoped CORS must survive.
### Pending Todos ### Pending Todos
@@ -201,6 +205,6 @@ Items acknowledged and carried forward from previous milestone close:
## Session Continuity ## Session Continuity
Last session: 2026-09-20T18:59:30.178Z Last session: 2026-09-20T19:07:03.593Z
Stopped at: Completed 06-08-PLAN.md Stopped at: Completed 06-09-PLAN.md
Resume file: None Resume file: None