docs(12-01): update state and roadmap progress after plan 12-01

This commit is contained in:
Jakub Zych
2026-10-02 11:50:43 +02:00
parent ce72e60491
commit d7388af564
2 changed files with 45 additions and 16 deletions

View File

@@ -613,12 +613,12 @@ Plans:
4. Artists/genres/styles lookup endpoints used by the Albums UI pass the parity diff.
5. A request-DTO-level fuzz over every write endpoint asserts unknown and server-owned keys are never persisted (inherits the HTTP half of Phase 5 criterion 3; the HTTP layer does not exist until Phase 6/12).
**Plans**: 5 plans
**Plans**: 1/5 plans executed
Plans:
**Wave 1**
- [ ] 12-01-PLAN.md — Framework gaps (summercms.go): Laravel-semantics request validator with pl/en catalogs, attach URL/webp, tide multipart and upload masks, beachcomber found/weights; user groups in the Go user plugin sm-user-plugin (D-25); ROADMAP/REQUIREMENTS rewording
- [x] 12-01-PLAN.md — Framework gaps (summercms.go): Laravel-semantics request validator with pl/en catalogs, attach URL/webp, tide multipart and upload masks, beachcomber found/weights; user groups in the Go user plugin sm-user-plugin (D-25); ROADMAP/REQUIREMENTS rewording
**Wave 2** *(blocked on Wave 1 completion)*
- [ ] 12-02-PLAN.md — Active context, collections and share: token-aware resolver, AccessibleBy, provisioning, gates, collection serializer, collections routes, me/context, realtime/channels, collection/share, per-route scopes and per-album delete (D-26)
@@ -632,6 +632,28 @@ Plans:
**Wave 5** *(blocked on Wave 4 completion)*
- [ ] 12-05-PLAN.md — Unit tests last: D-18 leak test with D-19 totals, route-table scope test, request-DTO fuzz, T-12 threat tests, coverage, check-phase12.sh, security review and validation sign-off
### Phase 12.1: User plugin admin screens (INSERTED)
**Goal:** Backend admins manage frontend users, user groups and organisations in the admin SPA without SQL, so the PHP backend is not needed for user administration after cutover. The Users, User Groups and Organisations screens of the PHP user plugin are ported to `golem15.user`, driven by its `fields.yaml`/`columns.yaml`.
**Mode:** mvp
**Requirements**: TBD
**Depends on:** Phase 12 (user groups tables and the `Groups` relation from 12-01)
**Repos:** `sm-user-plugin` (mounted in fonoteka.go at `plugins/golem15/user`); `summercms.go` only if the admin pipeline is missing a feature the screens need
**Ordering:** independent of Phase 13; must land before Phase 15 (cutover)
**Success Criteria** (what must be TRUE):
1. Users, User Groups and Organisations each have a list (columns, search, filters as in the PHP `config_filter.yaml`) and a create/update form ported from the PHP model YAML, reachable from admin navigation and gated by backend permissions.
2. A user's groups and an organisation's members are managed through relation managers.
3. The user actions activate, unban, unsuspend and delete, plus the list bulk actions, behave as in PHP `Users.php`.
4. Threat T-12-18 is revisited: the admin form is the first writer of `users_groups`, and only a backend user holding the required permission can change group membership.
5. The new code has unit tests, delivered in the phase's last plan.
**Open questions (discuss-phase):** impersonate user in or out of scope (security-sensitive); a separate permission for granting the `admin` group (it makes a site admin); whether convert-guest is needed for the application's data.
**Plans:** 0 plans
Plans:
- [ ] TBD (run /gsd-plan-phase 12.1 to break down)
### Phase 13: Płytarium API — wishlist, notifications, CSV, credentials, public routes
**Goal**: The remaining core API surface — wishlist, notifications, CSV import/export, per-user/org credentials, and onboarding/public/invitation routes — is ported with byte-compatible shapes and their own public rate-limit buckets.
@@ -704,7 +726,7 @@ Phases execute in numeric order: 1 → 2 → 3 → 4 → 5 → 6 → 7 → 8 →
| 11. Jobs, realtime and search infrastructure | 8/8 | In Progress| |
| 11.1. SummerCMS documentation for humans and AI agents | 7/7 | In Progress| |
| 11.2. summercms.io Alpha 0.1 landing page on SummerCMS | 3/3 | In Progress| |
| 12. Płytarium API — Collections and Albums | 0/5 | Planned | - |
| 12. Płytarium API — Collections and Albums | 1/5 | In Progress| |
| 13. Płytarium API — wishlist, notifications, CSV, credentials, public routes | 0/TBD | Not started | - |
| 14. Domain jobs and external integrations | 0/TBD | Not started | - |
| 15. Cutover | 0/TBD | Not started | - |