docs(12): record post-research decisions and validation strategy

This commit is contained in:
Jakub Zych
2026-10-02 08:04:23 +02:00
parent 77f8b371cf
commit d97b4292a3
2 changed files with 92 additions and 0 deletions

View File

@@ -91,6 +91,16 @@ Repo: `fonoteka.go`. Framework changes in `summercms.go` only where a gap is fou
- Which errors per route need a recording and which a Go test with bodies from PHP source, where recording a case is impractical (e.g. a mid-transaction race). Recording is the default.
- Plan count and split, subject to the plan-count checkpoint, "unit tests are the last plan" and the security-review agent (this phase touches authorization and public tokens).
### Post-research decisions (2026-10-02, confirmed at the plan-count checkpoint)
- **D-19:** Supersedes D-16 point 3. `meta.total`/`last_page` mirror Scout v10.25.0 `Builder::getTotalCount`: re-fetch up to `min(found, 1000)` ids from the engine and count them in SQL with the same access gating. The total is therefore re-gated and capped at 1000; stale/foreign ids still shorten the page. The D-18 leak test also asserts the total never counts a leaked row.
- **D-20:** `GET realtime/channels` (`{"data":{"collection":"collection:<id>"}}`) is ported in this phase. `me/context` returns only its recorded flags (AI, org, Discogs, currency) and no channel. API-01 and success criterion 1 are reworded at plan time.
- **D-21:** Error bodies are reproduced as PHP serves them in production (`APP_DEBUG=false`), including Winter HTML error pages where PHP throws `HttpException` (switch, household, invitations, accept). The existing accept 410 fixture is re-recorded under `APP_DEBUG=false`; the invitation `ValidationException` envelopes are recorded.
- **D-22:** Photo and attachment URLs match PHP (`/storage/app/uploads/public/<partition>/<disk>`). The Go attach URL prefix is fixed in this phase, restoring P5 D-16.
- **D-23:** The raw invitation token in River job args is encrypted with the app key and decrypted only inside the mail job. Amends D-13: the raw token never appears in plain text in `river_job.args`, logs or `summer_jobs.metadata`.
- **D-24:** The image guard accepts webp as PHP does. `golang.org/x/image` is bumped to v0.46.0 and its webp decoder registered (named here as the phase decision that authorises the dependency bump).
- **D-25:** The site-admin check in `me/context` reads user groups. User groups (`users_groups` and the groups relation) are added to the Go user plugin as an **additive, non-breaking** change; its existing contract is unchanged. The user signed off on this core-plugin change on 2026-10-02.
- **D-26:** Research-found bugs fixed in this phase: the token group applies exactly one `inv.scope:read|write` per route as PHP does (not `read` at group level), and deleting a collection removes its albums one by one so each album gets its Typesense removal and `deleted` broadcast, as PHP does.
</decisions>
<canonical_refs>