docs(12-01): update state and roadmap progress after plan 12-01

This commit is contained in:
Jakub Zych
2026-10-02 11:50:43 +02:00
parent ce72e60491
commit d7388af564
2 changed files with 45 additions and 16 deletions

View File

@@ -613,12 +613,12 @@ Plans:
4. Artists/genres/styles lookup endpoints used by the Albums UI pass the parity diff.
5. A request-DTO-level fuzz over every write endpoint asserts unknown and server-owned keys are never persisted (inherits the HTTP half of Phase 5 criterion 3; the HTTP layer does not exist until Phase 6/12).
**Plans**: 5 plans
**Plans**: 1/5 plans executed
Plans:
**Wave 1**
- [ ] 12-01-PLAN.md — Framework gaps (summercms.go): Laravel-semantics request validator with pl/en catalogs, attach URL/webp, tide multipart and upload masks, beachcomber found/weights; user groups in the Go user plugin sm-user-plugin (D-25); ROADMAP/REQUIREMENTS rewording
- [x] 12-01-PLAN.md — Framework gaps (summercms.go): Laravel-semantics request validator with pl/en catalogs, attach URL/webp, tide multipart and upload masks, beachcomber found/weights; user groups in the Go user plugin sm-user-plugin (D-25); ROADMAP/REQUIREMENTS rewording
**Wave 2** *(blocked on Wave 1 completion)*
- [ ] 12-02-PLAN.md — Active context, collections and share: token-aware resolver, AccessibleBy, provisioning, gates, collection serializer, collections routes, me/context, realtime/channels, collection/share, per-route scopes and per-album delete (D-26)
@@ -632,6 +632,28 @@ Plans:
**Wave 5** *(blocked on Wave 4 completion)*
- [ ] 12-05-PLAN.md — Unit tests last: D-18 leak test with D-19 totals, route-table scope test, request-DTO fuzz, T-12 threat tests, coverage, check-phase12.sh, security review and validation sign-off
### Phase 12.1: User plugin admin screens (INSERTED)
**Goal:** Backend admins manage frontend users, user groups and organisations in the admin SPA without SQL, so the PHP backend is not needed for user administration after cutover. The Users, User Groups and Organisations screens of the PHP user plugin are ported to `golem15.user`, driven by its `fields.yaml`/`columns.yaml`.
**Mode:** mvp
**Requirements**: TBD
**Depends on:** Phase 12 (user groups tables and the `Groups` relation from 12-01)
**Repos:** `sm-user-plugin` (mounted in fonoteka.go at `plugins/golem15/user`); `summercms.go` only if the admin pipeline is missing a feature the screens need
**Ordering:** independent of Phase 13; must land before Phase 15 (cutover)
**Success Criteria** (what must be TRUE):
1. Users, User Groups and Organisations each have a list (columns, search, filters as in the PHP `config_filter.yaml`) and a create/update form ported from the PHP model YAML, reachable from admin navigation and gated by backend permissions.
2. A user's groups and an organisation's members are managed through relation managers.
3. The user actions activate, unban, unsuspend and delete, plus the list bulk actions, behave as in PHP `Users.php`.
4. Threat T-12-18 is revisited: the admin form is the first writer of `users_groups`, and only a backend user holding the required permission can change group membership.
5. The new code has unit tests, delivered in the phase's last plan.
**Open questions (discuss-phase):** impersonate user in or out of scope (security-sensitive); a separate permission for granting the `admin` group (it makes a site admin); whether convert-guest is needed for the application's data.
**Plans:** 0 plans
Plans:
- [ ] TBD (run /gsd-plan-phase 12.1 to break down)
### Phase 13: Płytarium API — wishlist, notifications, CSV, credentials, public routes
**Goal**: The remaining core API surface — wishlist, notifications, CSV import/export, per-user/org credentials, and onboarding/public/invitation routes — is ported with byte-compatible shapes and their own public rate-limit buckets.
@@ -704,7 +726,7 @@ Phases execute in numeric order: 1 → 2 → 3 → 4 → 5 → 6 → 7 → 8 →
| 11. Jobs, realtime and search infrastructure | 8/8 | In Progress| |
| 11.1. SummerCMS documentation for humans and AI agents | 7/7 | In Progress| |
| 11.2. summercms.io Alpha 0.1 landing page on SummerCMS | 3/3 | In Progress| |
| 12. Płytarium API — Collections and Albums | 0/5 | Planned | - |
| 12. Płytarium API — Collections and Albums | 1/5 | In Progress| |
| 13. Płytarium API — wishlist, notifications, CSV, credentials, public routes | 0/TBD | Not started | - |
| 14. Domain jobs and external integrations | 0/TBD | Not started | - |
| 15. Cutover | 0/TBD | Not started | - |

View File

@@ -4,16 +4,16 @@ milestone: v1.0
current_phase: 12
current_phase_name: Płytarium API — Collections and Albums
status: executing
stopped_at: Completed 11.2-03-PLAN.md
last_updated: "2026-10-02T06:40:05.378Z"
last_activity: 2026-10-01
last_activity_desc: Phase 09 re-verified and marked complete (review fixes applied)
state_head: d97b4292a3473b1b83e45ac15425a27320db43ff
stopped_at: Completed 12-01-PLAN.md
last_updated: "2026-10-02T09:50:35.349Z"
last_activity: 2026-10-02
last_activity_desc: Phase 12 execution started
state_head: ce72e60491ae639ea7c4d3ec1e8773635167b2d0
progress:
total_phases: 19
total_phases: 20
completed_phases: 10
total_plans: 101
completed_plans: 96
completed_plans: 97
milestone_name: milestone
---
@@ -24,14 +24,14 @@ milestone_name: milestone
See: .planning/PROJECT.md (updated 2026-09-16)
**Core value:** An existing WinterCMS-shaped app can be ported plugin by plugin to a single Go binary without its frontend noticing: the PHP version's API contract is the acceptance test.
**Current focus:** Phase 11.2 — summercms.io Alpha 0.1 landing page on SummerCMS (INSERTED)
**Current focus:** Phase 12 — Płytarium API — Collections and Albums
## Current Position
Phase: 12 (Płytarium API — Collections and Albums) — READY TO EXECUTE
Plan: 3 of 3
Phase: 12 (Płytarium API — Collections and Albums) — EXECUTING
Plan: 2 of 5
Status: Ready to execute
Last activity: 2026-10-02 - Completed quick task 261002-esz: Extract golem15.user into its own repo sm-user-plugin
Last activity: 2026-10-02 — Phase 12 execution started
Progress: [██████░░░░] 60%
@@ -151,6 +151,7 @@ Progress: [██████░░░░] 60%
| Phase 11.2 P01 | 12 min | 3 tasks | 35 files |
| Phase 11.2 P02 | 22min | 5 tasks | 36 files |
| Phase 11.2 P03 | 13 min | 3 tasks | 11 files |
| Phase 12 P01 | 39 min | 4 tasks | 57 files |
## Accumulated Context
@@ -164,6 +165,7 @@ Progress: [██████░░░░] 60%
- Phase 11.2 edited: edited fields: title, goal, repos, design source, success_criteria — reshaped into the Alpha 0.1 landing page (Nuxt 4 on SummerCMS, nginx + supervisor deploy); newsletter moved to 11.3
- Phase 11.3 inserted after Phase 11.2: Newsletter plugin and signup on summercms.io (split out of the original 11.2)
- Phase 11.3 deferred to the backlog as Phase 999.1 (2026-10-02): the Journal plugin and delivering Płytarium take priority
- Phase 12.1 inserted after Phase 12: User plugin admin screens (sm-user-plugin): Users, User Groups, Organisations admin, before Phase 15 cutover
### Decisions
@@ -427,6 +429,11 @@ Recent decisions affecting current work:
- [Phase 11.2]: 11.2-02: the terminal check's clone override clones into the page's directory (git clone <override> summercms) so the page's cd summercms works with a local path
- [Phase 11.2]: 11.2-03: the gate's --built stage builds in release mode only when the framework checkout build.sh uses has v0.1.0, else a dev build
- [Phase 11.2]: 11.2-03: plugin route coexistence is tested with the plugin's real patterns from surf.BuildRouter(...).Routes() beside cabana's admin patterns on one ServeMux
- [Phase 12]: 12-01: lagoon.ValidateRequest follows Laravel exactly, including that a wildcard rule with nothing to expand adds no attribute; Go expectations are cross-checked against the real Winter validator from the PHP vendor tree
- [Phase 12]: 12-01: lagoon.ErrorKeys(errs, rules) rebuilds the PHP message-bag key order from the rule table, since a Go map carries none
- [Phase 12]: 12-01: exists:table,column compares CAST(column AS TEXT) with the PHP string form of the value, so bad input is a 422, never a Postgres error
- [Phase 12]: 12-01: beachcomber.PageSearcher is optional and SearchPage falls back to SearchIDs, so Engine and existing fakes stay unchanged; Typesense pages are capped at 250
- [Phase 12]: 12-01: sm-user-plugin user groups are additive (migration 202610020001_create_user_groups, User.Groups never serialized); commits are local because the orchestrator forbade pushing
### Pending Todos
@@ -475,6 +482,6 @@ Items acknowledged and carried forward from previous milestone close:
## Session Continuity
Last session: 2026-10-01T14:40:46.600Z
Stopped at: Completed 11.2-03-PLAN.md
Last session: 2026-10-02T09:50:21.962Z
Stopped at: Completed 12-01-PLAN.md
Resume file: None