docs(07-07): complete the user-api parity gap plan

Record the PHP-does-blacklist finding, the accepted Go 401 after logout,
and the 22-ported corpus so later phases do not revive the harness artifact.

Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
Jakub Zych
2026-09-23 00:01:18 +02:00
parent 31634f706f
commit d20f99f2e6
4 changed files with 168 additions and 17 deletions

View File

@@ -3,15 +3,15 @@ gsd_state_version: 1.0
milestone: v1.0
milestone_name: milestone
status: executing
stopped_at: Completed 07-06-PLAN.md
last_updated: "2026-09-22T18:41:15.559Z"
last_activity: 2026-09-22 -- Phase 07 planning complete
stopped_at: Completed 07-07-PLAN.md
last_updated: "2026-09-22T21:58:58.925Z"
last_activity: 2026-09-22
progress:
total_phases: 15
completed_phases: 6
completed_phases: 7
total_plans: 44
completed_plans: 43
percent: 40
completed_plans: 44
percent: 47
---
# Project State
@@ -25,10 +25,10 @@ See: .planning/PROJECT.md (updated 2026-09-16)
## Current Position
Phase: 07 (user-plugin-and-authentication) — EXECUTING
Plan: 6 of 6
Status: Ready to execute
Last activity: 2026-09-22 -- Phase 07 planning complete
Phase: 07 (user-plugin-and-authentication) — PLANS COMPLETE
Plan: 7 of 7
Status: All 7 plans have SUMMARYs. Ready for `$gsd-verify-work 7` — do not auto-advance.
Last activity: 2026-09-22 -- Completed 07-07-PLAN.md
Progress: [██████████] 100%
@@ -87,6 +87,8 @@ Progress: [██████████] 100%
| Phase 07 P04 | 75m | 3 tasks | 16 files |
| Phase 07 P05 | 45 | 3 tasks | 45 files |
| Phase 07 P06 | 40 min | 3 tasks | 8 files |
| Phase 07 P07 | 3h 15m | 3 tasks | 28 files |
| Phase 07-user-plugin-and-authentication P07 | 3h 15m | 3 tasks | 28 files |
## Accumulated Context
@@ -198,7 +200,9 @@ Recent decisions affecting current work:
- [Phase 06]: Retain all four earlier accepted risks unchanged; T-06-23 through T-06-27 are mitigated, not accepted or deferred. — Both repositories' authoritative race and vet gates passed, and each new threat has concrete source and named regression evidence.
- [Phase 06]: Anonymous inline limiter identity is documented only as inline:domainless|<ClientIP>, excluding policy text and request or forwarded Host inputs. — The production resolver and three executed regressions prove Host rotation and inline-parameter changes cannot create fresh anonymous budgets while authenticated principals keep isolated u:<id> keys.
- [Phase 07]: Blacklist storage expiry follows PHP jwt-auth (later of exp and iat+refreshTTL, plus one minute). — Using the raw access exp would drop a logged-out token that is still inside the refresh window.
- [Phase 07]: user_throttle and jwt_blacklist are allowed schema diffs — The frozen PHP snapshot predates the user plugin. jwt_blacklist is Go-only because PHP logout does not blacklist.
- [Phase 07]: user_throttle and jwt_blacklist are allowed schema diffs — The frozen PHP snapshot predates the user plugin. jwt_blacklist is also the production PHP path: logout calls JWTAuth::invalidate(true) and blacklist_enabled defaults true. The earlier "PHP does not blacklist" note was a harness artifact of CACHE_DRIVER=array.
- [Phase 07]: Fetch after logout stays 401 in Go — Re-recorded PHP with file cache still returned 200 on a reused token (show_black_list_exception default 0). That case is kept on disk but is not a ported corpus case.
- [Phase 07]: Already-activated activate/activate-by-code is Winter 500 HTML — User::attemptActivation throws when the user is already active; Go keys that path on IsAlreadyActivated, not wrong-code.
### Pending Todos
@@ -220,6 +224,6 @@ Items acknowledged and carried forward from previous milestone close:
## Session Continuity
Last session: 2026-09-22T17:21:05.484Z
Stopped at: Completed 07-06-PLAN.md
Last session: 2026-09-22T21:58:58.910Z
Stopped at: Completed 07-07-PLAN.md
Resume file: None