diff --git a/.planning/phases/15-journal-plugin/15-VALIDATION.md b/.planning/phases/15-journal-plugin/15-VALIDATION.md new file mode 100644 index 0000000..90c4c1c --- /dev/null +++ b/.planning/phases/15-journal-plugin/15-VALIDATION.md @@ -0,0 +1,87 @@ +--- +phase: "15" +slug: "journal-plugin" +status: draft +nyquist_compliant: false +wave_0_complete: false +created: "2026-10-06" +--- + +# Phase 15 — Validation Strategy + +> Per-phase validation contract for feedback sampling during execution. + +--- + +## Test Infrastructure + +| Property | Value | +|----------|-------| +| **Framework** | Go `testing` + testcontainers-go v0.44.0 (Postgres) | +| **Config file** | none — `go test ./...` | +| **Quick run command** | `go test ./... -short -count=1` in `sm-journal-plugin` + host `go test ./... -short -count=1` | +| **Full suite command** | `go test ./... -count=1` in `sm-journal-plugin`, host, and `summercms.go` only if framework files change | +| **Estimated runtime** | ~60 seconds (short); longer with Postgres + race on last plan | + +--- + +## Sampling Rate + +- **After every task commit:** Run `go test ./... -short -count=1` in the repo that changed +- **After every plan wave:** Run `go vet ./...` and `go test ./... -count=1` in that repo +- **Before `$gsd-verify-work`:** Plugin + host suites must be green +- **Max feedback latency:** 60 seconds (short) + +--- + +## Per-Task Verification Map + +| Task ID | Plan | Wave | Requirement | Threat Ref | Secure Behavior | Test Type | Automated Command | File Exists | Status | +|---------|------|------|-------------|------------|-----------------|-----------|-------------------|-------------|--------| +| 15-W0-01 | 01 | 0 | D-01 | — | Tables `golem15_journal_posts\|categories\|tags` after migrate | integration | `go test ./updates -run TestJournalTables -count=1` | ❌ Wave 0 | ⬜ pending | +| 15-W0-02 | 02 | 0 | D-10 | — | Post Translatable list + MorphName PHP string | unit | `go test ./models -run TestPostTranslatable -count=1` | ❌ Wave 0 | ⬜ pending | +| 15-W0-03 | 02 | 0 | D-11 | — | `type: mlmarkdown` compiles on posts form | unit | `go test ./... -run TestPostsFormCompiles -count=1` | ❌ Wave 0 | ⬜ pending | +| 15-W0-04 | 03 | 0 | D-12 | T-15-SC | Gate off → zero search HTTP on Post save | unit | `go test ./... -run TestSearchGateOff -count=1` | ❌ Wave 0 | ⬜ pending | +| 15-W0-05 | 02 | 0 | D-13 | — | Commands registered `journal:export-posts` / `journal:import-posts` | unit | `go test ./... -run TestJournalCommands -count=1` | ❌ Wave 0 | ⬜ pending | +| 15-W0-06 | 03 | 0 | D-14 | — | GET `/_journal/api/v1/posts` anonymous 200 | integration | `go test ./... -run TestJournalPublicList -count=1` | ❌ Wave 0 | ⬜ pending | +| 15-W0-07 | 03 | 0 | D-15 | T-15-01 | POST posts without Bearer 401 `Authentication required` | integration | `go test ./... -run TestJournalWriteUnauthenticated -count=1` | ❌ Wave 0 | ⬜ pending | +| 15-W0-08 | 03 | 0 | D-17 | — | Buckets named `journal-public-api` and `journal-api` Max 120 | unit | `go test ./... -run TestJournalBuckets -count=1` | ❌ Wave 0 | ⬜ pending | +| 15-W0-09 | 01 | 0 | D-17 | — | Host CORS includes `_journal/api/*` | unit | host `go test ./... -run TestCORS -count=1` | ❌ Wave 0 | ⬜ pending | +| 15-W0-10 | 01 | 0 | D-19 | — | Host Activate 3 plugins including `golem15.journal` | smoke | host `go test ./... -run TestBootUserTranslateJournal -count=1` | ❌ Wave 0 | ⬜ pending | +| 15-W0-11 | 04 | 0 | JOURNAL-005 | T-15-02 | Draft show 404 to stranger | integration | `go test ./... -run TestJournal005DraftShow -count=1` | ❌ Wave 0 | ⬜ pending | +| 15-W0-12 | 04 | 0 | JOURNAL-006 | T-15-03 | Media upload 403 without `access_posts`; path prefix | integration | `go test ./... -run TestJournal006MediaUpload -count=1` | ❌ Wave 0 | ⬜ pending | +| 15-W0-13 | 04 | 0 | JOURNAL-001/002 | T-15-04 | Tag/Category fillable | unit | `go test ./models -run TestFillable -count=1` | ❌ Wave 0 | ⬜ pending | + +*Status: ⬜ pending · ✅ green · ❌ red · ⚠️ flaky* + +--- + +## Wave 0 Requirements + +- [ ] `sm-journal-plugin` module and all test files listed above +- [ ] Host boot_test updated for three plugins + CORS +- [ ] Plugin Postgres harness (copy translate/user TestMain / testcontainers) +- [ ] No new test framework install +- [ ] PHPUnit XSS template tests deferred to Phase 16; FormatHTML unsafe-tag tests substitute this phase + +--- + +## Manual-Only Verifications + +| Behavior | Requirement | Why Manual | Test Instructions | +|----------|-------------|------------|-------------------| +| Gitea remotes exist | D-18, D-22 | Requires network + credentials already used | Confirm `git ls-remote git@git.golem15.com:golem15/sm-journal-plugin.git` and the proof-host remote | +| Posts/Categories/Tags admin in the proof-host SPA | D-19, SC-1 | Needs running host + admin login | Boot `sm-grzybyfunkcjonalne-app`; sign in as an administrator holding `golem15.journal.*`; open Journal nav; list/create/edit a post with `mlmarkdown` | + +--- + +## Validation Sign-Off + +- [ ] All tasks have `` verify or Wave 0 dependencies +- [ ] Sampling continuity: no 3 consecutive tasks without automated verify +- [ ] Wave 0 covers all MISSING references +- [ ] No watch-mode flags +- [ ] Feedback latency < 60s +- [ ] `nyquist_compliant: true` set in frontmatter + +**Approval:** pending